Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Hackers Steal $150,000 With Malicious Job Application
PC World ^ | January 19, 2011 | Robert McMillan

Posted on 01/19/2011 6:00:48 PM PST by decimon

Small businesses have a new scam to worry about: criminal job applicants who want to hack into online bank accounts.

The U.S. Federal Bureau of Investigation issued a warning Wednesday about a new twist on a long-running computer fraud technique, known as Automated Clearing House fraud.

With ACH fraud, criminals install malicious software on a small business' computer and use it to log into the company's online bank account. They set up bogus fund transfers, adding fake employees or payees, and then move the money offshore.

Scammers can move hundreds of thousands of dollars in a matter of hours using this technique. They often target small businesses that use regional banks or credit unions, which often don't have the resources to identify and block the fraudulent transfers.

In this latest twist on the scam, the criminals are apparently looking for companies that are hiring online and then sending malicious software programs that are doctored to look like job applications.

An unnamed U.S. company recently lost $150,000 in this way, according to the FBI's Internet Crime Complaint Center. "The malware was embedded in an e-mail response to a job posting the business placed on an employment website," the FBI said in a press release. The malware, a variant of the Bredolab Trojan, "allowed the attacker to obtain the online banking credentials of the person who was authorized to conduct financial transactions within the company."

(Excerpt) Read more at news.yahoo.com ...


TOPICS: Computers/Internet
KEYWORDS: microsofttax; technology

1 posted on 01/19/2011 6:00:50 PM PST by decimon
[ Post Reply | Private Reply | View Replies]

To: decimon

The ever fertile criminal mind. Wow


2 posted on 01/19/2011 6:04:55 PM PST by JimSEA
[ Post Reply | Private Reply | To 1 | View Replies]

To: decimon; ShadowAce
"a variant of the Bredolab Trojan"

We scan all incoming mail, even from our own website. Spammers(and worse) love to abuse web pages, especially those with online forms. I see this particular piece of malware blocked, at least several times per week. I'll have to check the logs to see if it's coming from our HR forms/online apps.

3 posted on 01/19/2011 6:14:24 PM PST by KoRn (Department of Homeland Security, Certified - "Right Wing Extremist")
[ Post Reply | Private Reply | To 1 | View Replies]

To: decimon
"The malware was embedded in an e-mail response to a job posting the business placed on an employment website," the FBI said in a press release.

I recently applied for a 'warehouse' job. Soon after, I got a GAZILLION personalized emails requesting that I jump into some hiring pool for a warehouse position. JUST CLICK HERE! Not a chance.

4 posted on 01/19/2011 6:46:17 PM PST by Libloather (The epitome of civility.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: KoRn

Innerestin’.


5 posted on 01/19/2011 7:24:02 PM PST by martin_fierro (< |:)~)
[ Post Reply | Private Reply | To 3 | View Replies]

To: All

It’s sad, but no AV is able to keep track of the flow of Windows malware. New vulnerabilities are found every week. They are exploited within hours by bandits. No protection software can keep up.

Antivirus software is protecting against yesterday’s threats only.

If you are a business and you access your bank account from a Windows PC that is not entirely dedicated and isolated from your network, you WILL get infected by malware.

Use a Mac or a Linux desktop.


6 posted on 01/19/2011 9:51:30 PM PST by FrogBurger (Always compare news articles from different sources. When they fully agree, you can be sure it's BS.)
[ Post Reply | Private Reply | To 5 | View Replies]

To: rdb3; Calvinist_Dark_Lord; GodGunsandGuts; CyberCowboy777; Salo; Bobsat; JosephW; ...

7 posted on 01/20/2011 7:02:32 AM PST by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 1 | View Replies]

To: RikaStrom

Ping for MSAN.


8 posted on 01/20/2011 7:48:59 AM PST by SeaDragon ("Life is tough ..... It's even tougher if you're stupid." - John Wayne)
[ Post Reply | Private Reply | To 2 | View Replies]

To: FrogBurger

Why haven’t I been impacted then...been online for years with windows.

Quit spreading FUD about things...as if Mac or Linux don’t have issues.


9 posted on 01/20/2011 8:07:41 AM PST by for-q-clinton (If at first you don't succeed keep on sucking until you do succeed)
[ Post Reply | Private Reply | To 6 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson