Top IT Security Bloggers

Krebs on Security
  • Credit Card Breach at Mandarin Oriental

    Krebs on Security
    In response to questions from KrebsOnSecurity, upscale hotel chain Mandarin Oriental Hotel Group today confirmed that its hotels have been affected by a credit card breach.
  • Hospital Sues Bank of America Over Million-Dollar Cyberheist

    Krebs on Security
    A public hospital in Washington state is suing Bank of America to recoup some of the losses from a $1.03 million cyberheist that the healthcare organization suffered in 2013.

    In April 2013, organized cyber thieves broke into the payroll accounts of Chelan County Hospital No. 1 , one of several hospitals managed by the Cascade Medical Center in Leavenworth, Wash. The crooks added to the hospital's payroll account almost 100 "money mules," unwitting accomplices who'd been hired to receive and forward money to the perpetrators.
  • Natural Grocers Investigating Card Breach

    Krebs on Security
    Sources in the financial industry tell KrebsOnSecurity they have traced a pattern of fraud on customer credit and debit cards suggesting that hackers have tapped into cash registers at Natural Grocers locations across the country. The grocery chain says it is investigating "a potential data security incident involving an unauthorized intrusion targeting limited customer payment card data."
  • Spam Uses Default Passwords to Hack Routers

    Krebs on Security
    In case you needed yet another reason to change the default username and password on your wired or wireless Internet router: Phishers are sending out links that, when clicked, quietly alter the settings on vulnerable routers to harvest online banking credentials and other sensitive data from victims. Sunnyvale, Calif. based security firm Proofpoint said it recently detected a four-week spam […]
  • Webnic Registrar Blamed for Hijack of Lenovo, Google Domains

    Krebs on Security
    Two days ago, attackers allegedly associated with the fame-seeking group Lizard Squad briefly hijacked Google's Vietnam domain (google.com.vn). On Wednesday, Lenovo.com was similarly attacked. Sources now tell KrebsOnSecurity that both hijacks were possible because the attackers seized control over Webnic.cc, the Malaysian registrar that serves both domains and 600,000 others.
  • FBI: $3M Bounty for ZeuS Trojan Author

    Krebs on Security
    The FBI this week announced it is offering a USD $3 million bounty for information leading to the arrest and conviction of one Evgeniy Mikhailovich Bogachev, a Russian man the government believes is responsible for building and distributing the ZeuS banking Trojan.

    So much of the intelligence gathered about Bogachev and his alleged accomplices has been scattered across various court documents and published reports over the years, but probably just as much on this criminal mastermind and his associates has never seen the light of day. What follows is a compendium of knowledge -- a bit of a dossier, if you will -- of Bogachev and his trusted associates.
  • TurboTax’s Anti-Fraud Efforts Under Scrutiny

    Krebs on Security
    Two former security employees at Intuit -- the makers of the popular tax preparation software and service TurboTax -- allege that the company has made millions of dollars knowingly processing state and federal tax refunds filed by cybercriminals. Intuit says it leads the industry in voluntarily reporting suspicious returns, and that ultimately it is up to the Internal Revenue Service to develop industry-wide requirements for tax preparation firms to follow in their collective fight against the multi-billion dollar problem of tax refund fraud.
  • The Rise in State Tax Refund Fraud

    Krebs on Security
    Scam artists stole billions of dollars last year from the U.S. Treasury by filing phony federal tax refund requests on millions of Americans. But as Uncle Sam has made this type of fraud harder for thieves to profit from, the crooks have massively shifted their focus to conducting refund fraud at the state level. Or at least according to Intuit Inc., the makers of TurboTax: The company says it believes that shift is responsible for a whopping 3700 percent increase in fraudulent state tax refund filings this year in some states.
  • ‘Spam Nation’ Wins PROSE Award

    Krebs on Security
    I am pleased to announce that my new book, Spam Nation: The Inside Story of Organized Cybercrime, from Global Epidemic to Your Front Door, has been honored with a 2015 PROSE Award in the Media & Cultural Studies category.
  • The Great Bank Heist, or Death by 1,000 Cuts?

    Krebs on Security
    I received a number of media requests and emails from readers over the weekend to comment on a front-page New York Times story about an organized gang of cybercriminals pulling off “one of the largest bank heists ever.” Turns out, I reported on this gang’s activities in December 2014, although my story ran minus many of the superlatives in the Times piece.