Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

2/7/2018
04:45 PM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
50%
50%

US, International Law Enforcement Shut Down Massive Cybercrime Marketplace

The Infraud Organization was responsible for over $500 million in losses to institutions and individuals worldwide, the US Department of Justice says.

US law enforcement authorities in collaboration with their counterparts in over a dozen nations have taken down a major cybercrime organization that was responsible for some $530 million in losses over the past seven years.

Thirty-six individuals from 17 countries have been charged in connection with their alleged roles in the so-called Infraud Organization, including five from the US. Thirteen of the 36 individuals have been arrested so far. Eight of them are awaiting extradition to the United States. More arrests are expected to follow.

In a media call announcing the arrests Wednesday morning, Deputy Assistant Attorney General David Rybicki described the Infraud Organization as a global forum for buying and selling stolen payment card data, financial information, Social Security numbers, personal identity data, malware, and other products.

"Infraud was truly the premier one-stop shop for cybercriminals worldwide," Rybicki said. "Over the course of the Infraud Organization's seven-year history, its members targeted more than 4.3 million credit cards, debit cards, and bank accounts held by individuals around the world and in all 50 states."

The 50-page indictment unsealed today does not allege that Infraud members committed any actual data breaches. But those operating on the forum offered tools and services that certainly would have facilitated those activities, Rybicki said.

According to the indictment, Svyatoslav Bondarenko, 34, of Ukraine, founded Infraud in 2010. Over the years, it became the premier destination on the Internet for crooks looking to transact business with stolen credit card, financial, banking, and identity information. In addition to providing a platform that cybercriminals could safely use to sell stolen data, Infraud also provided an escrow service that members could use to transact business using digital currencies.

As of last March, Infraud had over 10,900 members, making it one of the largest such operations on the Internet prior to its takedown this week. The group's members included individuals from the US, Ukraine, Russia, Australia, United Kingdom, Pakistan, Kosovo, and Bangladesh. The five individuals who have been arrested in the US are from New York, San Diego, Los Angeles, and Alabama.

As has become common with other cybercrime operations these days, Infraud had a formal hierarchy in place with defined roles for members, according to the indictment papers. "Administrators" were responsible for strategic planning operations as well as for managing day-to-day operations. They were also responsible for approving and monitoring membership, and for meting out rewards and punishments to members. Individuals with subject-matter expertise in different areas were assigned "Super Moderator" roles, while "Moderators" were responsible for one or two subforums within their specific areas of expertise, the DOJ indictment noted. The forum also had "vendors" who sold stolen goods, and malware and "members" and "VIP members" worked to facilitate various criminal activities.

"Today's indictment and arrests mark one of the largest cyber fraud enterprise prosecutions ever undertaken by the Department of Justice,” said John Cronin, acting assistant attorney general of the DOJ's criminal division.

"Infraud operated like a business to facilitate cyber fraud on a global scale," Cronin said, noting that the losses the group attempted to cause totaled more than $2.2 billion.

The charges in the case are the result of a joint investigation spearheaded by the US Immigration and Customs Enforcement's Homeland Security Investigations unit and the Henderson Police Department in Nevada.

The case itself is being prosecuted by the prosecutor's office in Nevada because of its familiarity with the details and the fact than 9,000 of Infraud's victims are from the state, said US Attorney Dayle Elieson of the District of Nevada during the media call.

The indictment charges the 36 individuals with racketeering, fraud, and seven other charges. They face a maximum of 20 years in federal prison on the racketeering charges and 10 years for each of the additional counts, Elieson said.

The Infraud takedown continues a string of major law-enforcement successes against cybercrime in recent years. Last year, the FBI and other US law enforcement agencies led an international operation that resulted in the takedown of the AlphaBay and Hansa criminal marketplaces. In December, the FBI, Europol, and others took down Avalanche, a massive malware operation involving 460 attack botnets.

Related content:

  

Jai Vijayan is a seasoned technology reporter with over 20 years of experience in IT trade journalism. He was most recently a Senior Editor at Computerworld, where he covered information security and data privacy issues for the publication. Over the course of his 20-year ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 9/21/2020
Hacking Yourself: Marie Moe and Pacemaker Security
Gary McGraw Ph.D., Co-founder Berryville Institute of Machine Learning,  9/21/2020
Startup Aims to Map and Track All the IT and Security Things
Kelly Jackson Higgins, Executive Editor at Dark Reading,  9/22/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Special Report: Computing's New Normal
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
How IT Security Organizations are Attacking the Cybersecurity Problem
How IT Security Organizations are Attacking the Cybersecurity Problem
The COVID-19 pandemic turned the world -- and enterprise computing -- on end. Here's a look at how cybersecurity teams are retrenching their defense strategies, rebuilding their teams, and selecting new technologies to stop the oncoming rise of online attacks.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-13991
PUBLISHED: 2020-09-24
vm/opcodes.c in JerryScript 2.2.0 allows attackers to hijack the flow of control by controlling a register.
CVE-2020-15160
PUBLISHED: 2020-09-24
PrestaShop from version 1.7.5.0 and before version 1.7.6.8 is vulnerable to a blind SQL Injection attack in the Catalog Product edition page with location parameter. The problem is fixed in 1.7.6.8
CVE-2020-15162
PUBLISHED: 2020-09-24
In PrestaShop from version 1.5.0.0 and before version 1.7.6.8, users are allowed to send compromised files. These attachments allowed people to input malicious JavaScript which triggered an XSS payload. The problem is fixed in version 1.7.6.8.
CVE-2020-15843
PUBLISHED: 2020-09-24
ActFax Version 7.10 Build 0335 (2020-05-25) is susceptible to a privilege escalation vulnerability due to insecure folder permissions on %PROGRAMFILES%\ActiveFax\Client\, %PROGRAMFILES%\ActiveFax\Install\ and %PROGRAMFILES%\ActiveFax\Terminal\. The folder permissions allow "Full Control" t...
CVE-2020-17365
PUBLISHED: 2020-09-24
Improper directory permissions in the Hotspot Shield VPN client software for Windows 10.3.0 and earlier may allow an authorized user to potentially enable escalation of privilege via local access. The vulnerability allows a local user to corrupt system files: a local user can create a specially craf...