Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
How Cybercriminals Clean Their Dirty Money
Oldest First  |  Newest First  |  Threaded View
SchemaCzar
50%
50%
SchemaCzar,
User Rank: Strategist
1/23/2019 | 12:12:54 PM
Lots of dicey brick and mortar operations could be laundering money too
When you drive past a strip mall and see a business with few customers and wonder how it's paying the rent, I think I have an idea.
Alexon Bell
50%
50%
Alexon Bell,
User Rank: Author
1/23/2019 | 1:12:01 PM
Re: Lots of dicey brick and mortar operations could be laundering money too
Absolutely, real estate is a popular vector for money laundering. If you're interested in an overview of the issue, you can check out my article on it here: https://moneyinc.com/my-neighbor-is-a-shell-company/
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
1/23/2019 | 1:29:41 PM
Solutions in sight?
With new technologies and services being offered every day I can only see that Cisco's prediction will become more and more common as the years progress. Is there anything that can be done to stop the bleeding of money laundering?
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
1/23/2019 | 1:37:21 PM
Re: Lots of dicey brick and mortar operations could be laundering money too
I'm always curious on how some smaller shops remain open for as long as they do. I think its probably more common that they are hemorrhaging debt rather than perfoming nefarious acts. Not saying thats never the case, but its surprising how long a company can compound their debt until they are forced out.
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
1/23/2019 | 1:39:47 PM
Re: Lots of dicey brick and mortar operations could be laundering money too
@Alexon, this is very interesting and nicely complements the previous point made by SchemaCzar. This is definitely a very complex problem that has multiple challenges to contemplate.
Alexon Bell
50%
50%
Alexon Bell,
User Rank: Author
1/24/2019 | 3:16:38 PM
Re: Solutions in sight?
There's actually a lot that can be done but it requires a coordinated effort between financial institutions, government and law enforcement. AI is helping to present an unprecedented level of context around data points so we're not having to use old methods that rely on triggers criminals are wise to and are already actively avoiding. By combining disparate data sets, we able to uncover the actual networks of money laundering rather than just spotting the odd transaction here and there. More on how we're doing exactly that at Quantexa: https://www.quantexa.com/solutions/anti-money-laundering/
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
1/24/2019 | 5:19:55 PM
Re: Solutions in sight?
Thank you for this information. I look forward to diving into it.
CameronRobertson
50%
50%
CameronRobertson,
User Rank: Moderator
2/11/2019 | 1:12:16 AM
How are we going to catch them
I reckon that with the whole entire cryptocurrency business, it's gotten a lot harder to detect people who are doing all of these illicit activities. But where there's a will, there's a way, and that's why so many of them are still getting away with millions tucked away in storage somewhere...
MarkSindone
50%
50%
MarkSindone,
User Rank: Moderator
2/18/2019 | 11:36:10 PM
Increase and improve
They need to be really good at their line of work to clean up the mess that they have created. Should they leave just a single trace of evidence, it would be easy to nail them. As we evolve alongside tech advances, we are able to witness just how upgraded hacking techniques have emerged too. Hence, the level of security that we need to put in place needs to be tightened as well.


COVID-19: Latest Security News & Commentary
Dark Reading Staff 7/13/2020
Omdia Research Launches Page on Dark Reading
Tim Wilson, Editor in Chief, Dark Reading 7/9/2020
Russian Cyber Gang 'Cosmic Lynx' Focuses on Email Fraud
Kelly Sheridan, Staff Editor, Dark Reading,  7/7/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Special Report: Computing's New Normal, a Dark Reading Perspective
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
The Threat from the Internetand What Your Organization Can Do About It
The Threat from the Internetand What Your Organization Can Do About It
This report describes some of the latest attacks and threats emanating from the Internet, as well as advice and tips on how your organization can mitigate those threats before they affect your business. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-20907
PUBLISHED: 2020-07-13
In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pax lacks header validation.
CVE-2020-14174
PUBLISHED: 2020-07-13
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view titles of a private project via an Insecure Direct Object References (IDOR) vulnerability in the Administration Permission Helper. The affected versions are before version 7.13.6, from version 8.0.0 before 8.5....
CVE-2019-20901
PUBLISHED: 2020-07-13
The login.jsp resource in Jira before version 8.5.2, and from version 8.6.0 before version 8.6.1 allows remote attackers to redirect users to a different website which they may use as part of performing a phishing attack via an open redirect in the os_destination parameter.
CVE-2019-20898
PUBLISHED: 2020-07-13
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to access sensitive information without being authenticated in the Global permissions screen. The affected versions are before version 8.8.0.
CVE-2019-20899
PUBLISHED: 2020-07-13
The Gadget API in Atlassian Jira Server and Data Center in affected versions allows remote attackers to make Jira unresponsive via repeated requests to a certain endpoint in the Gadget API. The affected versions are before version 8.5.4, and from version 8.6.0 before 8.6.1.