[ad_1]
Comment this story
Comment
Welcome to Cybersecurity 202! Argument: A perfectly ripe mango is the fruit of the lotus in The Odyssey. Also, we were off on Friday, so after today, see you next week.
Below: Critics challenge a database of money transfer information, and Royal Mail is taking over some international operations in response to a cyberattack. First:
A new power and a new team play a role in the battle of Bitzlato
The Biden administration yesterday launched a new power to tackle Russian cybercrime and rolled out the first major public move of a new government team dedicated to combating the illicit use of cryptocurrency.
Both moves were part of an international effort to punish Bitzlato, a cryptocurrency exchange that US authorities say has helped criminals profit from ransomware attacks and drug trafficking.
The arrest of the founder of the exchanges. The disconnection of this exchange from the American financial system.
It’s really obvious that they’re not only deploying new soldiers, but also new weapons against fraud or crypto crime, John Melican, chief legal officer at blockchain analytics firm Elliptic, told me.
Representative William R. Keating (D-Mass.) recently changed the new power into law that the administration used on Wednesday. I hope today’s action stimulates other activities, he told me.
Hong Kong-registered Bitzlato has received $2.5 billion in cryptocurrency since 2019, according to blockchain data firm Chainalysis. More than a quarter of them came from illicit sources, the company said.
The main sources of illicit cryptocurrency sent to Bitzlato were addresses associated with crypto scams, dark net markets and sanctioned entities such as high-risk exchange Garantex, which was designated last year, said the company in a blog post.
The Treasury Department named Conti, a Russian-based ransomware gang that as of January raised more than $150 million, according to the FBI, as one of the companies that used Bizlatos to facilitate transactions. illicit.
The Justice Department announced it had arrested Russian national Anatoly Legkodymov on Tuesday night in Miami, accusing him of running a business that funneled illicit funds without meeting U.S. regulatory safeguards, including anti-money laundering requirements. silver. Legkodymov, who the Justice Ministry says lives in China, faces a maximum of five years if convicted, but prosecutors have warned they could still charge him with other crimes.
Today’s actions send a clear message: whether you’re breaking our laws from China or Europe or abusing our financial system from a tropical island, you can expect to be held accountable for your crimes in US court. , Deputy Attorney General Lisa Monaco said in a news release announcing the arrest.
It is the first public enforcement action by the department’s National Cryptocurrency Enforcement Team, which was announced in October 2021 and assigned a director in February 2022.
When the Department of Justice set up the team, we said the NCET would investigate those who enable the use of digital assets to facilitate crime, with a particular focus on exchanges and services of virtual currencies, Assistant Attorney General Kenneth Polite Jr. said in prepared remarks at a press conference on Wednesday.
And we said NCET would strengthen departments’ collaboration with domestic and foreign partners in the aggressive investigation and prosecution of crimes involving cryptocurrency, Polite said.
It was also the first time the Treasury Department had used the tougher powers Congress gave it in 2020 to crack down on Russian money laundering.
The Financial Crimes Enforcement Network agencies identified Bitzlato as a major money laundering concern, which under the Fiscal Year 2021 Defense Authorization Act allows the Treasury to take action against entities linked to Russian illicit finance. These steps are similar to imposing sanctions, but they also have advantages for US authorities:
Punishment can be administered through an order, instead of having to go through a slower rule-making process, as the department explained. The punishment can go on indefinitely, Melican said, rather than needing to be renewed or extended.
The new power is focused on money laundering, and Keating said he had cryptocurrency fraud and ransomware in mind when drafting the provision to update it into law. defense authorization for the 2022 financial year.
These are people who act with impunity, he said. You really want to do some damage because otherwise it’s a mole. You can chase one individual, then another will appear. But if you’re aiming for the money, you’re hitting the heart of things.
You can read more about the government’s action against Bitzlato in this story from my colleagues Perry Stein, Devlin Barrett and Douglas MacMillan.
Although Bitzlato may not be a household name to most people, the cryptocurrency exchange has been on our radar for years, Andrew Fierman, head of sanctions strategy at Chainalysiss, told me via email. . If cybercriminals cannot reliably convert the cryptocurrency generated by their activities into cash, the incentives to commit these crimes drop. Today’s action reiterates the [U.S.] the commitment of governments to shut down those services that enable criminals, similar to previous sanctions against Suex and Chatex.
Wednesday’s government crackdown on Bitzlato also continues a trend of increasing pressure on crypto-related crimes.
The US wheels of crypto regulation have been a bit slow to get going, Melican said. It was a show of strength, and an interesting one at that.
Critics condemn money transfer database that shares data with law enforcement
The nonprofit Transaction Record Analysis Centers (TRAC) database allows law enforcement across the country to monitor the flow of money transfers, Wall Street Journals Dustin Volz and Byron Tau report. But it raises a host of privacy and surveillance issues with critics, who say it allows law enforcement to easily obtain bulk data on money transfers, which aren’t regulated as heavily as the banks.
TRAC allows the US government to serve an all-you-can-eat buffet of US personal financial data while circumventing normal American privacy protections, Sen. Ron Wyden (D-Ore.) told The Wall Street Journal in a statement. Wyden asked the Justice Department watchdog to investigate FBI and DEA ties to the TRAC. When Wyden asked the Department of Homeland Security watchdog about the TRAC, they told Wyden that he was reviewing immigration and customs enforcement programs to combat drug trafficking.
The American Civil Liberties Union obtained documents on TRAC. They show that any authorized law enforcement agency can interrogate the data without a warrant to examine the transactions of people inside the United States for evidence of money laundering and other crimes, write Volz and Tau.
TRAC Director Rich Lebel told the Wall Street Journal that this is a law enforcement investigative tool and we don’t release it to the world, but we don’t leak it. nor do we hide it. He also said that bulk data must be tracked to find crimes because the money transfer industry is less regulated. TRAC has a minimum transfer threshold of $500, so it does not capture benign transfers, and the organization has never found any instances of improper access or database breaches. He declined to comment on its funding; Wyden said TRAC is funded by the federal government.
Royal Mail resumes some services amid apparent ransomware attack
The company says it is now accepting letters for international delivery, after telling customers not to send such items following an apparent ransomware attack, Reuters reports Sachin Ravikumar. The UK’s largest mail delivery service has been grappling with the cyberattack for more than a week. The hack highlights the importance and vulnerabilities of messaging services.
LockBit, a Russian-linked ransomware gang, is believed to be behind the attack.
Our initial focus will be to clean up mail that has already been processed and is waiting to be dispatched, Royal Mail said in a statement. The company is still working with regulators and cybersecurity experts as it responds to the hack, she said.
A Democratic state senator asks federal and state prosecutors to investigate problems with voting machines in New Jersey County (New Jersey Globe)
Too many ‘admin1234’ default passwords increase risk to industrial systems, research finds (CyberScoop)
Over 100 Mailchimp accounts accessed via social engineering cyberattack (The Record)
Ukraine links data erasure attack on news agency to Russian hackers (Bleeping Computer)
CISA’s Chief Technology Officer Steps Down Much Earlier Than Expected (FCW)
CISA Hires Navy Cyber Expert to Help Oversee Vulnerability Management (FCW)
ShmooCon Hacking Conference Runs Friday-Sunday in DC
Thanks for reading. Until tomorrow.
|
Sources 2/ https://news.google.com/__i/rss/rd/articles/CBMibGh0dHBzOi8vd3d3Lndhc2hpbmd0b25wb3N0LmNvbS9wb2xpdGljcy8yMDIzLzAxLzE5L2NyeXB0by1leGNoYW5nZS1jcmFja2Rvd24tdXMtZ292ZXJubWVudC1kZWJ1dHMtdHdvLXRvb2xzL9IBAA?oc=5 The mention sources can contact us to remove/changing this article |
[ad_2]