Technology Sectors

Market Sectors

Symantec's "Black Market Tour" takes visitors into a criminal nether world

Symantec's Travis Wilkins,
a Black Market tour guide

The black market in which criminal hackers steal credit card and bank account information from hundreds or thousands of innocent victims, and sell that data to thieves throughout the world, has undergone a dramatic transformation in recent years.

"It's not about becoming famous, or destroying your information, like in the old days," explained Travis Wilkins, a product marketing manager with Symantec Corp., who served as a guide at the "Black Market Tour" assembled by Symantec and transported to cities across the U.S., including Washington, DC, where this reporter saw it. "It's now all about making money."

The Black Market Tour attempts to recreate a hacker's "lair," where the evil-doer might use phishing software to fool victims into allowing key-logging software to track their computer's keystrokes. The hacker might then grab their victims' account numbers, passwords, security codes and the answers to a slew of security questions, all in an effort to assemble marketable "personal identities" which can be sold in bundles to nefarious buyers via the Internet.

Another portion of the tour presents on flat-screen monitors precisely the type of online chat-room dialogue that criminal sellers of personal data and criminal buyers of this data might engage in when they first meet each other, before adjourning to more-private conversations elsewhere on the Internet to consummate their illegal transactions.

Identity theft attacks, such as these, tend to originate primarily in the United States, Russia, China, Eastern Europe and Brazil, explained Wilkins. The home bases for the hackers are somewhat concentrated, but the victims can be located anywhere in the world. Hackers don't care who you are, or where you are located, said Wilkins. They are only interested in assembling and selling large bundles of complete personal identities. The only characteristic that might be noteworthy would be the credit limit on the credit card itself, because a very high credit limit might fetch a premium price for that specific card in the black market.

Typically, a buyer of personal identities will not pay cash for the ill-gotten identities, said Kevin Haley, another Symantec guide. Instead, the purchaser might compensate the seller via PayPal, Western Union, using the Web site at e-gold.com, or trading products or services. "They might trade 10 banking credential for 100 credit cards," said Haley.

Symantec has received a terrific reception for its educational exhibit when the Black Market Tour turned up in Toronto, New York City, Washington, Tokyo, London and Mountain View, CA, where Symantec and its Norton unit are headquartered.

Asked if the "good guys" are making much headway in finding, arresting and convicting the "bad guys" around the world, Haley sounded realistic. "We'll probably never shut this problem down," he lamented. "But we're working hard to keep a lid on it."

  

 

Recent Videos

It's been a banner year for the Whitestone Group, according to John Clark, CEO of the facility security, asset/force protection and investigations...
Jeff Horne explains that Denver, CO-based Accuvant , Inc has two different businesses – the Value Added Reseller (VAR) side, in which it is one of...
GSN caught up with Dave Natelson for a quick interview at the Cocktail Reception at the 2011 Awards Dinner, before he learned that Nasatka had earned...
Ann Pickren discusses MIR3’s Mass Notification System that was awarded a Winner’s Trophy in GSN’s 2011 Homeland Security Awards Program. She explains...
Former Coast Guard Commandant Thad Allen, who served through a long and distinguished career in the United States Coast Guard and later answered the...

Upcoming Events

Event Details Dates of Event
SANS Monterey 2012 Jan 30 - Feb 4
2012 Adobe Government Assembly Feb 8
SANS Phoenix 2012 Feb 13 - 18
SANS Secure India 2012 Feb 20 - 25
The Airport Law Enforcement Symposium Feb 23-24, 2012 Feb 23 - 24
Physical Security: Introductory Applications and Technology Feb 27 - Mar 1
Conducting Corporate Investigations Feb 27 - 28
ISC CHINA 2012 (International Security Conference & Exposition CHINA) Feb 27 - 29
RSA Conference 2012 Feb 27 - Mar 2
SAP Public Sector Partner Exchange Feb 28 - 28
SANS Secure Singapore 2012 Mar 5 - 17
SANS Germany 2012 Mar 5 - 10
Homeland Security Finance Forum 2012 Mar 6 - 6
Basic Hands-On CAMEO Training Mar 12 - 14
ASIS Assets Protection Course: Principles of Security (APC I) Mar 12 - 15
SANS Mobile Device Security Summit 2012 Mar 12 - 15
Aviation Week's Innovation Challenge Showcase Mar 13 - 14
Symantec Government Technology Summit Mar 20 - 20
STI at SANS 2012 Mar 23 - 30
SANS 2012 Mar 23 - 30
The 9th Two Day Conference On Indian Medical Devices & Plastics Disposables Industry 2012 Mar 23 - 24
SANS Northern Virginia 2012 Apr 15 - 20
Active Shooter Apr 18 - 19
SANS AppSec 2012 Apr 24 - May 2
SANS Cyber Guardian 2012 Apr 30 - May 7
Telework Exchange Spring 2012 Town Hall Meeting May 2 - 2
5th Sample Prep - Sample Preparation for Virus, Toxin, & Pathogen Detection & Identification May 3 - 4
SANS Security West 2012 May 10 - 18
SANS Toronto 2012 May 14 - 19
Counter Terror Expo US May 16 - 17
CEIC 2012 (Computer and Enterprise Investigations Conference) May 21 - 24
SANS Rocky Mountain 2012 Jun 4 - 9
Data Center Brainstorm 2012 Jun 19 - 19
SANS Forensics and Incident Response Summit 2012 Jun 21 - 27
Vanguard Security & Compliance 2012 Jun 25 - 28
SANS Canberra 2012 Jul 2 - 10