Share

Your credit card could fund cybercrime

Cape Town - Stolen credit card credentials make up the most common method that cyber criminals use to pay for internet hosting services, says a security company.

In order to facilitate the spread of malware online, cyber criminals rely on bullet proof hosting services (BPHS) in an underground economy.

"Cyber criminals can use stolen credit card credentials to finance their BPHS use. Cyber criminals can purchase stolen credentials underground," Max Goncharov, a researcher at Trend Micro, told Fin24.

Hackers who hit cheating website AshleyMadison.com, for example, publicly posted online around 9.7GB of data that included names and credit card details.

Goncharov said it is easy for criminals to obtain personal and financial data from unsuspecting users.

"It's possible for them to do further targeted social engineering to pry more information out of credit card owners. They can call them up, request copies of their IDs, or falsify email confirmations to complete the data they need so they can use the credit card credentials for malicious purposes."

Improved technology

BPHS are essential to the underground cybercrime industry because they allow criminals to host child pornography as well as malware and botnet command and control software in servers located mainly in China, Bolivia, Iran, and the Ukraine.

BPHS costs start at around $2 per month and climb to $300, depending on the sensitivity of the content being hosted.

The financial industry should invest in improved technology to limit the ability of cyber criminals to operate with BPHS, said Goncharov.

"It's best for the financial industry to invest more in personal identification to avoid these kinds of fraud."

In South Africa, the Electronic Communications and Transactions Act of 2002 makes it illegal for providers to host malicious content, and Goncharov said that there was no direct evidence that SA was a hub for these kinds of services.

However, he warned that the government should actively collaborate with international partners to limit the ability of cyber criminals to operate.

"Governments should still have fast and assured implementations against BPHS. They should work closely with other law enforcement agencies that concentrate on taking down these types of services."


- Follow Duncan on Twitter

We live in a world where facts and fiction get blurred
Who we choose to trust can have a profound impact on our lives. Join thousands of devoted South Africans who look to News24 to bring them news they can trust every day. As we celebrate 25 years, become a News24 subscriber as we strive to keep you informed, inspired and empowered.
Join News24 today
heading
description
username
Show Comments ()
Rand - Dollar
19.12
+0.4%
Rand - Pound
23.77
-0.3%
Rand - Euro
20.46
-0.0%
Rand - Aus dollar
12.38
-0.0%
Rand - Yen
0.12
+0.4%
Platinum
923.40
-0.8%
Palladium
1,027.50
+1.2%
Gold
2,318.78
-0.4%
Silver
27.14
-0.2%
Brent Crude
87.00
-0.3%
Top 40
68,071
+0.9%
All Share
74,030
+0.7%
Resource 10
59,635
-2.1%
Industrial 25
102,751
+1.7%
Financial 15
15,918
+1.9%
All JSE data delayed by at least 15 minutes Iress logo
Company Snapshot
Editorial feedback and complaints

Contact the public editor with feedback for our journalists, complaints, queries or suggestions about articles on News24.

LEARN MORE
Government tenders

Find public sector tender opportunities in South Africa here.

Government tenders
This portal provides access to information on all tenders made by all public sector organisations in all spheres of government.
Browse tenders