Krebs on Security

March 17, 2016

Spammers Abusing Trust in US .Gov Domains

This post was originally published on this site Spammers are abusing ill-configured U.S. dot-gov domains and link shorteners to promote spammy sites that are hidden behind short links ending in”usa.gov”. Spam purveyors are taking advantage of so-called “open redirects” on several U.S. state Web sites to hide the true destination to which users will be taken if they click the link.  Open redirects are potentially dangerous because they let spammers abuse the reputation of the site hosting the redirect to get users to visit malicious or spammy sites without realizing it. For example, South Dakota has an open redirect: http://dss.sd.gov/scripts/programredirect.asp?url= …which spammers are abusing […]
March 21, 2016

Carders Park Piles of Cash at Joker’s Stash

This post was originally published on this site A steady stream of card breaches at retailers, restaurants and hotels has flooded underground markets with a historic glut of stolen debit and credit card data. Today there are at least hundreds of sites online selling stolen account data, yet only a handful of them actively court bulk buyers and organized crime rings. Faced with a buyer’s market, these elite shops set themselves apart by focusing on loyalty programs, frequent-buyer discounts, money-back guarantees and just plain old good customer service. An ad for new stolen cards on Joker’s Stash. Today’s post examines […]
March 22, 2016

Hospital Declares ‘Internal State of Emergency’ After Ransomware Infection

This post was originally published on this site A Kentucky hospital says it is operating in an “internal state of emergency” after a ransomware attack rattled around inside its networks, encrypting files on computer systems and holding the data on them hostage unless and until the hospital pays up. A streaming red banner on Methodisthospital.net warns that a computer virus infection has limited the hospital’s use of electronic web-based services. Click to enlarge. Henderson, Ky.-based Methodist Hospital placed a scrolling red alert on its homepage this week, stating that “Methodist Hospital is currently working in an Internal State of Emergency […]
March 24, 2016

Phishing Victims Muddle Tax Fraud Fight

This post was originally published on this site Many U.S. citizens are bound to experience delays in getting their tax returns processed this year, thanks largely to more stringent controls enacted by Uncle Sam and the states to block fraudulent tax refund requests filed by identity thieves. A steady drip of corporate data breaches involving phished employee W-2 information is adding to the backlog, as is an apparent mass adoption by ID thieves of professional tax services for processing large numbers of phony refund requests. According to data released this week by anti-fraud company iovation, the Internal Revenue Service is taking up to […]