Friday, March 6, 2015

Three Defendants Charged with One of the Largest Reported Data Breaches in U.S. History



One Of The Defendants Has Already Pleaded Guilty

An indictment was unsealed yesterday against two Vietnamese citizens who resided in the Netherlands, for their roles in hacking email service providers throughout the United States.  The guilty plea of one of the defendants was also unsealed at the same time.  In addition, a federal grand jury returned an indictment this week against a Canadian citizen for conspiring to launder the proceeds obtained as a result of the massive data breach.

Assistant Attorney General Leslie R. Caldwell of the Criminal Division, Acting U.S. Attorney John A. Horn of the Northern District of Georgia, Special Agent in Charge J. Britt Johnson of the FBI’s Atlanta Field Office, Special Agent in Charge Reginald Moore of the United States Secret Service’s (USSS) Atlanta Field Office and Special Agent in Charge Veronica F. Hyman-Pillot with the Internal Revenue Service-Criminal Investigation’s (IRS-CI) made the announcement.

“These men — operating from Vietnam, the Netherlands, and Canada — are accused of carrying out the largest data breach of names and email addresses in the history of the Internet,” said Assistant Attorney General Caldwell.   “The defendants allegedly made millions of dollars by stealing over a billion email addresses from email service providers.  This case again demonstrates the resolve of the Department of Justice to bring accused cyber hackers from overseas to face justice in the United States.”

“This case reflects the cutting-edge problems posed by today’s cybercrime cases, where the hackers didn’t target just a single company; they infiltrated most of the country’s email distribution firms,” said Acting U.S. Attorney Horn.  “And the scope of the intrusion is unnerving, in that the hackers didn’t stop after stealing the companies’ proprietary data—they then hijacked the companies’ own distribution platforms to send out bulk emails and reaped the profits from email traffic directed to specific websites.”

“Large scale and sophisticated international cyber hacking rings are becoming more problematic for both the law enforcement community that is faced with the challenges of identifying them and laying hands on them, but also the fortune 500 companies that are so often their targets,” said Special Agent in Charge Johnson.  “The federal indictments, apprehensions and extraditions in this case represents several years of hard work as the FBI and its cadre of cyber trained agents and technical experts acted quickly to stop the ongoing damage to the numerous victim companies as a result of these individuals’ hacking activities.  In August 2012, the FBI, with the assistance of its legal attaches stationed abroad and in conjunction with Dutch law enforcement officials, executed a search warrant in the Netherlands that disrupted continued compromises of those companies while allowing U.S. authorities to advance its investigation.  That investigation targeted not only the hackers but the businesses that helped monetize the data that was stolen from those victim companies.  This case further reflects the productive partnership of the FBI and the U.S. Secret Service in aggressively addressing this 21st century crime problem.”

“Our success in this case and other similar investigations is a result of our close work with our law enforcement partners,” said Special Agent in Charge Moore.  “The Secret Service worked closely with the Department of Justice and the FBI to share information and resources that ultimately brought these cyber criminals to justice.  This case demonstrates there is no such thing as anonymity for those engaging in data theft and fraudulent schemes.”

“Those individuals who line their pockets with money gained through deceiving others should know they will not go undetected and will be held accountable,” said Special Agent in Charge Hyman-Pillot.  “IRS Criminal Investigation is committed to unraveling financial transactions to ensure that those who engage in these illegal activities are vigorously investigated and brought to justice.”

According to allegations in the indictments, between February 2009 and June 2012, Viet Quoc Nguyen, 28, a citizen of Vietnam, allegedly hacked into at least eight email service providers (ESPs) throughout the United States and stole confidential information, including proprietary marketing data containing over one billion email addresses.  Nguyen, along with Giang Hoang Vu, 25, also a citizen of Vietnam, then allegedly used the data to send “spam” to tens of millions of email recipients.  The data breach was the largest in U.S. history and was the subject of a Congressional inquiry in June 2011.

David-Manuel Santos Da Silva, 33, of Montreal, Canada, was also indicted by a federal grand jury on March 4, 2015, for conspiracy to commit money laundering for helping Nguyen and Vu to generate revenue from the “spam” and launder the proceeds.

According to allegations in the indictments, Da Silva, the co-owner, president and a director of 21 Celsius Inc., a Canadian corporation that ran Marketbay.com, entered into an affiliate marketing arrangement with Nguyen that allowed the defendants to generate revenue from the computer intrusions and data thefts.

As an affiliate marketer, Nguyen allegedly received a commission on sales generated from Internet traffic that he directed to websites promoting specific products.  Nguyen allegedly used the information stolen from the ESPs to send “spam” emails to tens of millions of customers and provided hyperlinks to allow the purchase of the products.  These products were marketed by Da Silva’s Marketbay.com.

Between approximately May 2009 and October 2011, Nguyen and Da Silva received approximately $2 million for the sale of products derived from Nguyen’s affiliate marketing activities.

Vu was arrested by Dutch law enforcement in Deventer, Netherlands, in 2012 and extradited to the United States in March 2014.  On Feb. 5, 2015, Vu pleaded guilty to conspiracy to commit computer fraud.  He is scheduled to be sentenced on April 21, 2015, before U.S. District Judge Timothy C. Batten Sr. of the Northern District of Georgia.  Nguyen is a fugitive.

Da Silva was arrested based upon charges set forth in a criminal complaint at Ft. Lauderdale International Airport on Feb. 12, 2015, and is scheduled to be arraigned today in Atlanta before Magistrate Judge E. Clayton Scofield III.

The charges contained in an indictment are merely accusations, and defendants are presumed innocent unless and until proven guilty.

This case is being investigated by the FBI with the assistance of the USSS and IRS-CI.  Law enforcement in the Netherlands and the Criminal Division’s Office of International Affairs also provided valuable assistance.  This case is being prosecuted by Trial Attorney Peter Roman of the Criminal Division’s Computer Crime and Intellectual Property Section and Assistant U.S. Attorney Steven D. Grimberg of the Northern District of Georgia.

Faster Data, Better Law Enforcement



The National Institute of Justice (NIJ) recently awarded a grant to fund software and other tools to make it easier to store and process data for criminal investigations.  This NIJ solicitation and award responds to a high demand by law enforcement regarding harnessing big data, and the technology behind the award could find applications in federal government and the private sector.

Cybercom Chief: Cyber Threats Blur Roles, Relationships



By Cheryl Pellerin
DoD News, Defense Media Activity

WASHINGTON, March 6, 2015 – Over five years of U.S. Cyber Command operations, global movement of threat activity through cyberspace has blurred roles and relationships among government agencies, as well as between the public and private sectors and the real and virtual worlds, the Cybercom commander told a House panel.

Navy Adm. Michael S. Rogers testified March 4 before the House Armed Services Committee on cyber operations and improving the military’s cybersecurity posture.

“There is no Department of Defense solution to our cybersecurity dilemmas,” Roger said in written testimony. “The global movement of threat activity in and through cyberspace blurs the U.S. government’s traditional understanding of how to address domestic and foreign military, criminal and intelligence activities.”

Similarly, he said, the public and private sectors need each other’s help.

Responding to Cyber Attacks

“The U.S. government, the states and the private sector can’t defend their information systems on their own against the most powerful cyber forces,” the admiral said.

“We saw in the recent hack of Sony Pictures Entertainment that we have to be prepared to respond to cyber attacks with concerted actions across the whole of government,” he added, “using our nation’s unique insights and complete range of capabilities in cooperation with the private sector.”

Cyberspace is more than a challenging environment, Rogers said.

“It is now part of virtually everything we in the U.S. military do in all domains of the battle space and each of our lines of effort,” he said. “There is hardly any meaningful distinction to be made now between events in cyberspace and events in the physical world, as they are so tightly linked.”

Cybercom is growing and operating at the same time, he said, performing many tasks across a diverse and complex mission set.

Guarding DoD Networks

Three years ago, the command lacked capacity, Rogers said. Today, new teams are guarding DoD networks and are prepared to help combatant commands deny freedom of maneuver to adversaries in cyberspace, he added.

Cybercom’s Cyber Mission Force, or CMF, was formed to turn strategy and plans into operational outcomes, the admiral said.

“With continued support from Congress, the administration and the department,” Rogers said, “Cybercom and its service cyber components are now about halfway through the force build for the CMF, [and] many of its teams are generating capability today.”

He added, “We have a target of about 6,200 personnel in 133 teams, with the majority achieving at least initial operational capability by the end of fiscal year 2016.”

Cybercom has been normalizing its operations in cyberspace, he said, to provide an operational outlook and attitude to running the department’s 7 million networked devices and 15,000 network enclaves.

Implementing the Joint Information Environment

The department’s legacy architecture, created during times when security was not a core design element, is being transitioned to a more secure and streamlined architecture that is part of what ultimately will be the Joint Information Environment, or JIE.

“While the JIE is being implemented,” Rogers said, “our concerns about our legacy architecture collectively have spurred the formation of our new Joint Force Headquarters to defend the department’s information networks.”

The Joint Force Headquarters recently achieved initial operational capability, the admiral added, working at the Defense Information Systems Agency under Rogers’ operational control at Cybercom. Its mission is to oversee the day-to-day operation of DoD networks, he added, “and mount an active defense of them, securing their key cyber terrain and being prepared to neutralize any adversary who manages to bypass their perimeter defenses.”

Managing Risk

“It gets us closer to being able to manage risk on a systemwide basis across DoD,” Rogers added, “balancing warfighter needs for access to data and capabilities while maintaining the overall security of the enterprise.”

The admiral said the new headquarters is a stopgap measure while the department migrates its systems to a cloud architecture that’s more secure and facilitates data sharing across the enterprise.

As network security has advanced, so has the maturity of the cyber force, which has gained what Rogers called priceless experience in cyberspace operations.

“That experience has given us something even more valuable -- insight into how force is and can be employed in cyberspace. We have had the equivalent of a close-in fight with an adversary that taught us how to maneuver and gain the initiative that means the difference between victory and defeat,” he explained.

Every Conflict Has a Cyber Dimension

Such insight is increasingly urgent, because every conflict in the world has a cyber dimension, the admiral said, adding that the command sees patterns in cyber hostilities that indicate four main trends:

-- Autocratic governments that view the open Internet as a lethal threat to their regimes;

-- Ongoing campaigns to steal intellectual property;

-- Disruptions by a range of actors that range from denial-of-service attacks and network traffic manipulation to the use of destructive malware; and

-- States that develop capabilities and attain system access for potential hostilities, perhaps with the idea of enhancing deterrence or as a beachhead for future cyber sabotage.

“We believe potential adversaries might be leaving cyber fingerprints on our critical infrastructure, partly to convey a message that our homeland is at risk if tensions ever escalate toward military conflict,” Rogers said.

Heartbleed and Shellshock

For instance, he told the House panel, “I can tell you in some detail how Cybercom and our military partners dealt with the Heartbleed and Shellshock vulnerabilities that emerged last year.”

The Heartbleed Bug is a serious vulnerability that allows attackers to steal information, usually encrypted, that’s used to secure the Internet for applications such as Web, e-mail and instant messaging, among others. Attackers can eavesdrop on communications, steal data directly from the services and users, and impersonate services and users.

Shellshock is a vulnerability that gives attackers the ability to run remote commands on a system.

The admiral said these serious flaws inadvertently were left in the software that millions of computers and networks in many nations depend on.

Responsible developers discovered both security holes, Rogers said. They kept their findings quiet and worked with trusted colleagues to develop software patches that system administrators could use to get a jump on those who read the same vulnerability announcements and devised ways to identify and exploit unpatched computers, he said.

Checking for Vulnerabilities

“We at Cybercom and [the National Security Agency] learned of Heartbleed and Shellshock at the same time that everyone else did,” the admiral said.

Military networks are probed for vulnerabilities thousands of times an hour, he added, so it wasn’t long before they detected new probes checking their websites and systems for vulnerabilities.

“By this point, our mission partners had devised ways to filter such probes before they touched our systems,” Rogers explained. “We were sheltered while we pushed out patches across DoD networks and monitored implementation,” directing administrators to start with the most vulnerable systems.

“Thanks to the efforts we have made in recent years, our responses … were comparatively quick, thorough and effective, and in both cases they helped inform corresponding efforts on the civilian side of the federal government,” the admiral added.

“We also know that other countries, including potential adversaries, struggled to cope with the Heartbleed and Shellshock vulnerabilities,” he noted.

Cyber Military Capabilities

Rogers said this operational approach must be built in many more places.

“The nation’s government and critical infrastructure networks are at risk as well,” he said, “and we are finding that computer security is really an enterprisewide project.”

The admiral added, “We in the U.S. government and DoD must continue learning and developing new skills and techniques … [and] the nation must continue to commit time, effort and resources to building cyber military capabilities.”

Thursday, March 5, 2015

Special Program emerges to combat cyber insider threats

by Justin Oakes
66th Air Base Group Public Affairs


3/5/2015 - HANSCOM AIR FORCE BASE, Mass. -- It's not often that the public gets to hear about the Air Force's inner workings when pertaining to highly-classified networks. However, a Special Programs team from Hanscom AFB's Command, Control, Communications, Intelligence and Networks Directorate has recently emerged and made its presence known.

"We have developed an agile and efficient process for delivering solutions that protect against the cyber insider threat," said Lt. Col. Richard Howard, Materiel Solutions Analysis chief. 

Unlike other teams within the Special Programs Division, the Materiel Solutions Analysis section, or MSA for short, is the only one that functions outside the classified realm.

The team's mission is to rapidly identify and test government and commercial-off-the-shelf hardware and software, and if viable, transition it to the classified arena. However, combating the cyber insider threat on secure networks quickly became one of MSA's primary focuses.

In January 2014, the Special Programs unit stood up the MSA Lab, where the team tests and scrutinizes commercial and government technologies that could potentially function on a secure network, and at the same time, serve as a deterrent for insider attacks. The MSA Lab consists of three sections: Level 1, a robust unclassified area used to test incoming technologies; Level 2, which has the potential to perform classified tests; and Level 3, which is a virtual demonstration room.

Since MSA's inception it has fielded more than 100 proposals on insider threat mitigation technologies from commercial companies, both large and small.

"The MSA Lab is unique, and by design, highly specialized on the needs of a select classified community," said Paul Krueger, MSA chief engineer. "Being co-located at Hanscom AFB with the Hanscom Collaboration and Innovation Center is important so that when necessary, we can take advantage of its infrastructure for massive joint and multi-nation coalition warfighting experiments and demonstrations."

Upon significant amounts of testing, the Air Force partnered with MIT Lincoln Laboratory and began to notice a common misconception within industry.

"We saw a disturbing trend emerging from companies -- that there is a single solution fix to insider attacks," Howard said. "The cyber insider threat is complex, and to believe a single technology exists that will prevent malicious insiders from stealing, altering or destroying sensitive information is inaccurate."

To better understand and depict the intricacies of this problem, MSA engineers devised a model known as the Insider Threat Universe, also known as the ITU.

The ITU concept is comprised of layers that convey how certain technologies protect in part -- but not in all -- the Air Force's secure networks.

Confidentiality, integrity and availability make up the basis of the ITU with information serving as the core. Procedures, policies and monitoring are other items that directly impact information concerns. Specific areas such as data-at-rest encryption and role-based access controls represent technology layers also used to protect information.

The MSA team realized the need to socialize the ITU concept and generate open communication among other Department of Defense agencies also faced with growing insider threat problems.

Last month, the MSA office hosted the first Cyber Insider Threat Workshop at Hanscom.

More than 100 cyber, security and acquisition professionals from more than 30 organizations attended. Representatives from the MSA office, Air Combat Command, Air Force Research Laboratory, 24th Air Force, Carnegie Mellon University, C3I Infrastructure Division, MIT Lincoln Laboratory and MITRE discussed current mitigation efforts and how they fit into the ITU model.

According to MSA officials, there were two main takeaways from the event.

"The cyber insider threat is complicated, difficult to define and a challenge to defend against," Krueger said. "The ITU model is a useful tool that can be used to help define these threats, but it is a constantly evolving concept."

Krueger also called for more effective communication across the Air Force, government, and other agencies throughout the DOD.

"Communication is the only way synergy can be developed across the board," he said. "Making the community aware of currently used technologies, as well as equipment and software that's being tested and fielded by facilities like the MSA Lab, is critical to solving this problem."

During the last year, the demand for MSA-vetted technologies has increased exponentially. In order to keep up with testing and analysis, the lab increased from two to seven engineers plus support from MIT Lincoln Laboratory, MITRE and various contractors.

This week, Maj. Gen. Craig Olson, C3I and Networks Directorate program executive officer, presented MSA's areas of interest to industry during the annual 2015 New Horizons event in Newton, Mass.

"Not only is this a great opportunity to bring our efforts to light outside of DOD agencies, but it will also allow us to gather valuable feedback on how our industry partners deal with insider cyber threats," said Olson.

Since the Materiel Solutions Analysis team was created, it has stood up a testing lab, developed a threat model and organized a forum fostering dialogue among other DOD agencies -- all in the name of cyber security.

"In order for us to successfully mitigate the cyber insider threat problem, organizations across the DOD must work together; technological, physical and administrative solutions should be leveraged across the DOD IT enterprise," said Col. Jeffrey Kligman, Special Programs Division senior materiel leader. "Communication and innovation are key to securing our computing environment."