Understanding identity theft and its repercussions is information security's greatest challenge for companies and consumers alike in 2005. Hackers are making use of a combination of technology, social engineering and the clear profit a stolen identity, or parts of it offer.
While the techniques to steal an identity online or offline are neither new, sophisticated or ultimately 100 percent effective, the fact remains that identity theft is now seen internationally as an organized and profitable business run by people who are motivated by one thing alone. Profit.
Australian High Tech Crime Centre managing director Graham Ingram said the revolution that has taken place in the online world is that organized crime groups have recognized the opportunity to illicit financial gain through various forms of electronic identity theft and a high rate of innovation and attack capabilities have evolved as a result.
Ingram added that the growth in networks and e-commerce have changed the overall landscape of the Internet which has in turn led to an increase in the number of potential targets to attack.
"Organized crime is not new but the opportunities now emerging for online ID theft are a driver ... if I were to categorize what we are seeing it would be as an attack system - a number of components that form an end-to-end attack capability," Ingram said.
"The drivers are the targets and vulnerabilities in systems as we see the Internet as not necessarily the most robust place for financial transactions and e-commerce.
"Some of these people [those stealing identities online] can reasonably and safely conduct attacks in Australia and globally with little chance of being prosecuted or even traced back to their home country. Criminals are benefiting from this revolution and currently they are winning.
Identity theft is not a problem specific to banking but "one that undermines the basis of trust for the information economy", he said, adding the task of identity theft has more in common with information warfare due to the fact successful identity theft, today, involves multiple attackers with a common purpose.
"Organized crime has effectively bought three elements into one system - hackers, spammers and fraudsters with dedicated skills, well resourced and organized that live and breathe to achieve financial gains. Fame has nothing to do with it as what they do is designed to be under the radar and not detectible.
"We see more or less an arms race because as soon as we counter one move they [the bad guys] improve and it doesn't stop," Ingram said. "The reason why I think technologists have been unsuccessful in this type of attack is that they have not been doing it for money; organized crime knows how to move money, then put technology in front to make a system."
Ingram said it appears from his conversations with law enforcement agencies that such groups have child pornography, digital copyrighting, DDoS (distributed denial of service) extortions and phishing as business lines, and things like money laundering and counter intelligence works to support the business of getting money.
While no one doubts the insidious nature of identity theft, some experts have questioned who is hit hardest. Information security director at Vectra, Jo Stewart-Rattray, said identity theft is the current security buzzword, adding the real concern for companies in regard to identity theft is the irreparable damage to the company just one confirmed instance of theft makes, especially to a smaller enterprise or small business.
Stewart-Rattray said the theft of an ID, whether from an internal employee or customer, is difficult to put a value on especially when it comes to corporate reputation.
"There are issues around reporting information security breaches - look at the Australian High Tech Crime Centre statistics which had 181 respondents to the last survey. These 181 respondents may have a bigger proportion of the budget to spend on security than a smaller organization - it is very different for smaller organizations to report incidents of data theft and they are not encouraged to do it," Stewart-Rattray said.
"There are concerns we don't have a full understanding of what happens in the SME or SMB space, except by anecdotal evidence." Tales of large-scale organized identity theft have been surfacing for the past year. In February this year US data collector ChoicePoint (rumoured to have information on every living adult in the US) had to front up and admit to some 145,000 customers that they have become potential identity fraud targets after ChoicePoint were "tricked" into selling personal information to identity thieves posing as legitimate customers. In early March, hackers were found to have stolen information on at least 32,000 people held in databases owned by the LexisNexis Seisint division. Seisint collects data on individuals, which is used by law enforcement and private companies for debt recovery and fraud detection.
The hackers stole social security and drivers' licence numbers of legitimate customers, as well as passwords, names and addresses. The Bank of America also admitted to losing credit card details of 1.2 million federal employees, as well as 60 US senators, after using a commercial flight to transfer digital tapes, which were "lost", containing the private data.
Read up on the latest ideas and technologies from companies that sell hardware, software and services. Wireless LANs: Is my enterprise at risk?
Gaining Competitive Advantage Through Enterprise Planning
Cutting printer costs
CRM your salespeople will love
Solve Exchange Mailbox Storage Issues Once and for All
Know thy self: Reduce costs, secure data and ensure compliance with identity management
Email Archiving Implementation: Five Costly Mistakes to Avoid
Achieving the impossible: Unlimited application scalability
Zones provide focussed content from Computerworld and leading technology partners.Discover how SOA can create smarter outcomes for your business.
Attend and learn:
- How SOA is helping leading companies to become more agile
- Where you should be applying SOA processes in your company
- The top SOA implementation mistakes to avoid
Click here for more information.
- +
Computerworld Live Podcast #97: The Future of Enterprise Networking 25/07/2008 09:45:36
This week CW Live chats with Mark Thompson, global sales and marketing manager for HP ProCurve, on the future of the enterprise networking. Mark discusses the trends we can expect to see in the near future and how the right infrastructure can ensure your enterprise network is secure. - +
Computerworld Live Podcast #96: Security at the Edge 11/06/2008 09:22:22
CW Live speaks with Amol Mitra, HP ProCurve Director of Marketing for Asia Pacific and Japan. Today's topic: how enterprises are starting to shift away from simply controlling security via server logins, firewalls and moving to more adaptive security frameworks. - +
Data Management Edition #10: Multi-Petascale Systems 02/05/2008 09:12:33
This week we look at sustainability and the development of multicore technologies to build multi-petascale systems. - +
IT Security Edition #11: How to poison the Storm botnet 01/05/2008 08:51:55
This week CW Live presents a case study on how to poison the notorious Storm botnet . Plus we take a look at Cisco's plans for Ironport. - +
IT Security Edition #10: Cyber-battles fought and won 24/04/2008 11:09:47
Vendors bow to end user pressure to improve product security, and we take a look at the latest concepts shaping the cyber-battlefield of the future.
PGP and Ponemon Institute Unveil Inaugural Australian Data Breach Study 2008 2008-11-20 17:34:00+11
Symantec Cloud Services Transform Data Centre Operations Through Proactive Management 2008-11-20 12:06:00+11
Verizon Business Offers Tips to Building a Successful Unified Communications and Collaboration Plan 2008-11-20 12:04:00+11
AARNet Brings 4K Digital Cinema to Australia: First 4K HD Video Signal delivered into Australia by AARNet 2008-11-20 12:02:00+11
NetApp Named 2008 Citrix Ready Solution of the Year by Citrix Systems 2008-11-20 11:33:00+11
Radicati Market Quadrant 2008 on Corporate Web Security
An Analysis of the Market for Corporate Web Security Solutions, revealing Top Players, Mature Players, Specialists and Trail Blazers. Read on to discover who makes the grade.









