Attacks/Breaches

4/17/2018
11:00 AM
Steve Zurier
Steve Zurier
Slideshows
Connect Directly
Twitter
RSS
E-Mail
100%
0%

8 Ways Hackers Monetize Stolen Data

Hackers are craftier than ever, pilfering PII piecemeal so bad actors can combine data to set up schemes to defraud medical practices, steal military secrets and hijack R&D product information.
Previous
1 of 9
Next

Image Source: Ginger_Cat via Shutterstock

Image Source: Ginger_Cat via Shutterstock

We are long past the era of the 14-year old teenage hacker trying to spoof a corporate or defense network for the fun of it, just because they can. While that still happens, it’s clear that hacking has become big business.

From China allegedly stealing billions of dollars annually in intellectual property to ransomware attacks estimated to top $5 billion in 2017, data breaches and the resulting cybercrime are keeping CISO and rank-and-file security managers on their toes.

Security teams need to be aware of the full range of what hackers do with this stolen data. The crimes range from stolen IP to filing fraudulent tax rebates to the IRS to setting up a phony medical practice to steal money from Medicare and Medicaid patients and providers.

"Hackers will often start by selling data on military or government accounts," says Mark Laliberte, an information security analyst at WatchGuard Technologies. "People are also bad at choosing passwords for individual services and often reuse passwords, which lets hackers try those passwords on the other websites their victims use."

Paul Calatayud, chief security officer, Americas, at Palo Alto Networks, says medical data has become especially vulnerable because many hospitals and medical practices use the same cloud-based ERP or human resources systems and hackers can piece together information and eventually enter a billing or patient information system.

For this slideshow, we explain how hackers monetize the stolen data. The following list is based on phone interviews with Laliberte and Calatayud.

 

Steve Zurier has more than 30 years of journalism and publishing experience, most of the last 24 of which were spent covering networking and security technology. Steve is based in Columbia, Md. View Full Bio

Previous
1 of 9
Next
Comment  | 
Print  | 
More Insights
Comments
Oldest First  |  Newest First  |  Threaded View
ChristianP468
50%
50%
ChristianP468,
User Rank: Apprentice
4/17/2018 | 1:44:07 PM
Informative story
This article is very informative and knowing what hackers do with stolen data can help prevent these types of attacks in the future. It is very interesting that hackers sales stolen data that no longer have any value. This set the point that once consumers have been noticed of data breaches that they should take them seriously and change all associated information. Now many companies will force a password change after a data breach (Bonnington, 2018). One thing that was pointed out was how thefts will target elders with small medical bills that elderly people would be most likely to pay.

 

Bonnington, C. (2018). The MyFitnessPal Hack Affects 150 Million Users. It Could've Been Even Worse.Slate Magazine. Retrieved 17 April 2018, from https://slate.com/technology/2018/03/myfitnesspal-hack-under-armour-data-breach.html
szurier210
50%
50%
szurier210,
User Rank: Apprentice
4/17/2018 | 1:56:46 PM
Re: Informative story
Thanks very much for your comments. Yes, I'm always very concerned that our seniors are vulnerable to hacking attacks and social scams over the phone as well. We do what we can to help people out. 
bwagner62
50%
50%
bwagner62,
User Rank: Apprentice
4/23/2018 | 4:46:00 PM
Re: Informative story
More than once in this article, it is stated that users do not choose or create strong passwords and we all know why passwords are not strong, why they are used over and mishandled. But when will we (especially companies) figure out the investment in MFA pays off? So many companies do not want to make an investment in access control or they cheap out with a solution that requires accessing a third party vendor's network. I can only assume that it is more profitable to continue using passwords that we all know are weak.
jeremy_wittkop
50%
50%
jeremy_wittkop,
User Rank: Author
4/27/2018 | 6:38:55 PM
Interesting Read
Interesting read. Some of the methods are well known, but there are others that are less apparent until you sit down and think about what could be done with the information being stolen. I think GDPR and other regulations around the world signify that consumers are waking up to the risks associated with thei personal data. The sun is setting on idea that once we give a company our information that they can keep it in perpetuity and sell it to whomever they choose and somehow it will remain safe as it propogates. With so many ways to capitalize on stolen information, it's no wonder why these things continue to happen.
Election Websites, Back-End Systems Most at Risk of Cyberattack in Midterms
Kelly Jackson Higgins, Executive Editor at Dark Reading,  8/14/2018
Oh, No, Not Another Security Product
Paul Stokes, Founder & CEO of Prevalent AI,  8/9/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-13106
PUBLISHED: 2018-08-15
Cheetahmobile CM Launcher 3D - Theme, wallpaper, Secure, Efficient, 5.0.3, 2017-09-19, Android application uses a hard-coded key for encryption. Data stored using this key can be decrypted by anyone able to access this key.
CVE-2017-13107
PUBLISHED: 2018-08-15
Live.me - live stream video chat, 3.7.20, 2017-11-06, Android application uses a hard-coded key for encryption. Data stored using this key can be decrypted by anyone able to access this key.
CVE-2017-13108
PUBLISHED: 2018-08-15
DFNDR Security Antivirus, Anti-hacking & Cleaner, 5.0.9, 2017-11-01, Android application uses a hard-coded key for encryption. Data stored using this key can be decrypted by anyone able to access this key.
CVE-2017-13100
PUBLISHED: 2018-08-15
DistinctDev, Inc., The Moron Test, 6.3.1, 2017-05-04, iOS application uses a hard-coded key for encryption. Data stored using this key can be decrypted by anyone able to access this key.
CVE-2017-13101
PUBLISHED: 2018-08-15
Musical.ly Inc., musical.ly - your video social network, 6.1.6, 2017-10-03, iOS application uses a hard-coded key for encryption. Data stored using this key can be decrypted by anyone able to access this key.