Security experts are warning of a new hacking technique that attempts to extort money by encoding files on a victim's PC then demanding payment for a tool to decode the information.
In a case highlighted today by Websense Security Labs, a user was infected with a virus that used a known vulnerability in Internet Explorer. Microsoft had provided a patch which the user had failed to install.
The virus contacted a website that hosted an application to encode files on the user's hard disk. The process makes the data illegible unless the user breaks the encryption or enters a decryption key.
The attackers left a message on the affected system offering to provide a decryption key for $200. The money was to be paid into an online E-Gold account.
Cyber-extortion is a well-documented issue for enterprises. Criminals have tried to blackmail companies by threatening to launch a denial of service attack, or by stealing company databases and demanding money to prevent an embarrassing disclosure of the company's lax security.
The case highlighted by Websense, however, is the first time that internet criminals have targeted consumers on a wide scale.
Colindale (C1905), United Kingdom | NHS Blood and Transplant
Operations Engineer, £28,313 - £37,326 pa plus High Cost Area Supplement, Colindale (C1905) About us The National Blood Service is an integral and vital part of the NHS. Our two million volunteer donors contribute 1.6 ... more >
Business Relationship Manager (Finance), Based at Civic Offices, £ 41,790 - £ 44,373 (PO 7) Fixed Term to 31st March 2009 The IT service has four Business Relationship Managers (BRM); each one responsible for delivering and developing ... more >
Site Systems Integration Manager, London, United Kingdom Shell Downstream encompasses all the activities necessary to transform crude oil into petroleum products and petrochemicals, and deliver them around the world. Our Downstream businesses refine, supply, ... more >
About EDS EDS provides a broad portfolio of business and technology solutions to help its clients worldwide improve their business performance. EDS' core portfolio comprises information-technology and business process outsourcing services, as well as information-technology ... more >More job opportunities