Criminals Target Tech Students With Job Offers
An anonymous reader writes "BBC News is running a story on criminal gangs targeting tech students. Some of these outfits offer to pay for an education in exchange for the student's employment on graduation in criminal hacking activities." From the article: " As the number of criminal gangs looking to move into cyber crime expanded, it got harder to recruit skilled hackers, said Mr Day. This has led criminals to target university students all around the world. 'Some students are being sponsored through their IT degree,' said Mr Day. Once qualified, the graduates go to work for the criminal gangs. As well as the direct route of targeting students, some organised crime gangs were trading on the glamour surrounding the 'hacker' label to help them recruit impressionable youngsters..."
it's a better job offer than the other offers most kids are going to get, and it appeals to their interests... why are people surprised?
Does this mean that legitimate companies, to keep up, will have to do the same thing?
Maybe they could even get into bidding wars over potential students/employees! This could only be a good thing...right?
Everything I need to know about copyrights I learned from Slashdot.
how do i sign up?
This isn't anything new really. I mean I even feel redundant saying this. Where there's commerce, there's crime. Where there's crime, there's organization. Gangs have simply moved on from convincing kids on street corners to steal some stuff into convincing kids in chatrooms to hack into some websites. It was only a matter of time.
I'm currently doing an IT internship for the Gambino family. The pay is good, I get medical & dental, and if anyone mods me down, they'll find out about some of the other perks of working in the industry.
No! No! No! Any hacker with even an ounce of skill is more than capable of setting up shop on his own. What you gotta do is offer the guy something he would never EVER get legitimately. What these criminal types REALLY ought to do is come on slashdot here and promise they can arrange regular *private* meetings with our favorite adult performers from the pr0n we all download.
Stay sentient. Don't drink bad milk.
Say what you will, hacking (cracking, don't throw a fit) isn't exactly easy nowadays. Can anyone here honestly tell me that they can get me access to a given business's clients database in the next 48 hours ? Didn't think so. So what are the gangs getting out of this ? Are they getting on a hype bandwagon ?
This seems like a monumentally stupid way to recruit hackers. Let's see, leave a public record of you funding a student (rather than cold cash), then when he graduates, tell him, oops, you want him to break several laws. "Oh really? Well, thanks for the free education. Hey feds, over here!" *gets witness protection* *gets guaranteed income for life* *eliminates obligation to employer*
... er, why do you need to pay for his education again?
In order for this to work, you'd have to credibly threaten or capture a loved one. But if you've got the techie that way,
Apology to Ubuntu forum.
Wal-Mart. Big huge massive retail company. How much do you think it would be worth to K-Mart, or Target, or various other retailers, for Wal-Mart to just be down for a few days? Easily into tens of millions, if not hundreds of millions of dollars.
Sad part is, the person at the top doesn't even have to know what's going on. They just say "Hey write a program that will do this, and propogate. We'll give you a cool 100Gs." Kid says hells yea, takes a few hours, whatever, writes it, and gives it to them, collects.
Two weeks later, Wal-Mart plant sticks the little nasty into the Wal-Mart mainframe, and it gets disseminated to every single store in the company. The plant is nice and safe (removed by organization, or perhaps just left to fend for themselves, whatever), many of the people involved will never be caught, and the person that wrote it may not even know they were responsible!
Perhaps I should take off my tin-foil hat, but still, it's a helluva "What-If".
A close friend of mine and I were offered "work" for a criminal organization years ago when we were fresh out of high school (we developed quite a rep, did some stupid things like send all the account usernames and passwords for the district to the main laser in the library. Nobody knew who did it till a friend ratted us out. That's another story though.)
The offer was nice, new machines and $10,000 each for a weeks work attacking ADT's system so they could stage a b&e spree.
Scared the crap out of me, I had friends that ran with those people, one was a runner who shortly there after went missing after he embezzled. I left the city (for other reasons) no idea what happened to Jamie...
There are other things to consider other than renumeration, like physical safety.
- The Google Toolbar has a spell checker button AND it works, consider that before hitting submit next time k?
Back in The Day, Slashdot listed only the day and date, which if I gave a shit, would be sufficient to narrow it down to the year. However, sometime in the last 2 years I was pleasantly surprised to see they started putting the year as well attached to every post.
Don't believe me? Read everything to the right of my name on this post.
Of course, I suppose I could be lying too.
I like music
Criminal gangs should be able to offer some very "creative" fringe benefit packages. You want $200,000 a year? Or maybe $150,000 and a two hookers / week? Tax that!
Only boring people are ever bored.
Oh yeah, they have a dental plan... Tony, gimme the pliers.
-- Home is where you eat your heart out.
I kind of see your point...but doesn't the military already do this? They offer to pay for college, you agree to serve for 6 years or whatever. Does it make a difference if it's a private company?
:)
I know that some companies will help pay for your education if you agree to continue working for them for a certain amount of time after your education is complete. It's not so different, right? This is just getting them younger.
Of course, my original comment was more of a joke
Everything I need to know about copyrights I learned from Slashdot.
SCO is hiring? I'm so in there...
I like big butts and I cannot lie.
And what's their motto?
:P
DO evil?
True, but only to an extent.
Many companies offer benefits in return for service (as you mention), the difference isn't in really in what the companies offer, it's in what they do.
If we just looked at offers - then there is not much difference between a lobbyist giving a politician large sums of money and someone donating to charity. Both are giving money away right? But the law looks at more than action - it looks at intent (thankfully). Which means that accepting money from a criminal enterprise is very different than accepting money from a legitimate company.
There is always a frontier where there is an open and willing mind
The point is, you can set a date format that includes the year in your Slashdot preferences (in the homepage section).
Ludwig Wittgenstein
The people who get caught by the RIAA are the "low hanging fruit" most of the time. They're either hitting ten year olds or they're hitting the superseeders (or the guys who run the sites). People with IT degrees who pirate would use safer, and harder to trace, methods. Even just using PeerGuardian or pirating via proxy (or stealing wireless) is going to help you a great deal in terms of not getting caught. Additionally, they "stay in the middle" in terms of threat level.
Same for these hackers. They're semi-safe because they're smarter than the average script-kiddie, and they're not quite as dangerous as the guys who hack the Pentagon or whatever. Law enforcement will feel two pressures: Go after the major crimes and close a lot of cases. They close the easy cases quickly, and catch the high-profile cases for the headlines. These guys probably feel safe since they're neither.
That said, the reason crime doesn't pay is that a cops only needs to get lucky once, but the criminal needs to be lucky everytime.
Did anybody notice that this BBC story is based entirely on a report, "McAfee Virtual Criminology Report http://www.softmart.com/mcafee/docs/McAfee%20NA%20 Virtual%20Criminology%20Report.pdf and an interview with one of its authors?
This report -- from 2005 -- doesn't have anything that you couldn't have already read on Slashdot or the newspapers.
The BBC didn't check McAfee's claims with another source. The McAfee report doesn't say anything about criminals paying tuition for students to study computer science. The McAfee security analyst didn't give any details. The BBC didn't ask him the obvious question, "How do you know?" Did he talk to a student like this? Did he find it in court records? Or did he hear it from another security expert after a few drinks?
Has McAfee been reliable in the past?
Three years ago, Wired had an article written by a guy who does tech support for the Mafia.
Can anyone tell me how to set my sig on Slashdot?
What we *had* here was a failure to communicate.
:-P"
1 237124/ref=ase_mitnicksecuri-20/103-6052457-813506 9?v=glance&s=books
...
That seems to be clearing up, somewhat.
If you remember just a few, scant years ago, this discussion would be full of:
* "Your a moran"
"How about that tin foil hat"
"You watch too much TV"
"I guess you are a leet hacker dude
and so on.
Perhaps Kevin (TM) has helped us understand what has been perpetrated on us for years (witting or unwitting social engineering).
The Art of Deception: Controlling the Human Element of Security
http://www.amazon.com/exec/obidos/tg/detail/-/047
So the internet does make us smarter, eh?
For example:
The Kennedy assassination made the word "conspiracy" a knee jerk, almost unconscientious reaction to discount whatever followed as ludicrous.
As an exercise let me roll this past you.
If the Japanese in WWII could have attacked every home in the US by way of their radio set top box (a "brown note" for electronics), to start fires in every home
http://www.schmarder.com/radios/crystal/
http://en.wikipedia.org/wiki/Brown_note
do you think they would have conspired with College (engineering) students to help them?
Criminals are now MBAs, Engineers and Rocket Scientists.
Your desktop could be mocking you.
* [yes, it's misspelled]
~hylas