Panda Security Reveals Alarming Findings From Multi-Year Security Assessment of Business Services for U.S. Immigrants
Posted on: Thursday, 11 December 2008, 07:00 CST
According to U.S. Immigration Support, it is estimated that worldwide
remittances amount to more than
The Findings and Threats
The results are alarming and deduce that these businesses, numbering approximately 66,000 in the U.S. alone, are at very high risk for cybercrime security breaches and theft. Surprisingly, the computers present in these offices are typically consumer grade Dell personal computers with very few enhancements or software additions. In repeated visits over the past two years, Panda Security consistently found that trial antivirus software on these machines had long since expired and any kind of proactive security measure was viewed as an unnecessary business expense. At least 30 percent of the 1500 computers directly observed had outdated antivirus software and an alarming 60 percent were actively infected.
In addition, employees at these businesses are frequently minimum wage young adults who spend time chatting, using peer-to-peer networks and visiting chat sites on the very same computers that store sensitive data such as social security numbers, DMV records, tax records and credit card information. This combination of lack of maintenance, low security consciousness and end user behavior result in highly vulnerable systems that are very easy for cybercriminals to infiltrate.
Since approximately 80 percent of the machines that Panda Security studied
are being used for remittances and money transfer to immigrants' home
countries, analysis of the security assessments conducted over a two year
period found that each network computer is at extremely high risk for
cybercriminal activity. All of these risk exposures significantly increase the
probability for criminals to successfully intercept authorized remittances to
beneficiaries in
-- A Trojan / Keylogger can be installed on the target computer (either through a targeted phishing attack or other means of malware infection) capable of capturing screen information and/or taking details directly from the browser session via a sophisticated HTML injection. This would be facilitated by high-risk behavior of the people who operate the terminals and poor security standards, such as trial antivirus software and infrequent system maintenance.
-- A terminal operator who authenticates with a Web-based transfer system
can then initiate a wire transfer on behalf of the client (who has appeared in
person at the location in the
-- False identification bearing the name of the recipient or beneficiary can be created in a matter of minutes and a mule with false identification can be sent to pick up the funds. Due to advanced dye sublimation card printing technologies and corrupt government employees, high quality false documents made with real substrate can be available in mere minutes. In one popular wire transfer service that makes wire pickup available in a large Mexican national bank the beneficiary does not even need to pick up at the designated branch.
"By targeting businesses geared towards immigrants' needs, cybercriminals
are picking an easy target and taking advantage of computer systems that have
little to no barriers to entry," said
Preventing and Protecting
For all businesses geared towards U.S. immigrants whose systems are vulnerable to attack, Panda Security recommends the following protocol:
1. Make sure you have an up-to-date anti-malware suite and set it to scan regularly.
2. Make yourself aware of the security practices put into place before conducting your business. Panda Security suggests using FDIC accredited banks or Western Union because they have higher security standards than most multiservice businesses.
Panda Security is offering complimentary security consultation and certification for businesses in need of assistance. For businesses affected by these security problems (this includes check cashing and money transfer locations), please visit http://us.pandasecurity.com/criticalalert/ to receive assistance from the Panda Security Critical Situation Line. In addition businesses can scan and disinfect their PCs for free with Panda ActiveScan 2.0; please visit this website for the free services: http://www.pandasecurity.com/activescan/index/?track=89124.
About Panda Security
Panda Security is one of the world's leading IT security providers, with millions of clients around the globe and products available in over twenty languages. Our mission is to keep our customers' information and IT assets safe from security threats, giving them the most effective protection with the minimum resource consumption.
Every day, thousands of new malicious codes are created. To combat this threat, Panda Security has developed an innovative and unique security model which can automatically analyze and classify thousands of new malware samples. This model is collective intelligence and ensures that Panda Security solutions can protect against far more threats than the products of any other company. The exceptional detection capacity of collective intelligence can be put to the test at the Infected or Not website (http://www.infectedornot.com).
For more information and evaluation versions of all Panda Security solutions, visit our website at: http://www.pandasecurity.com/
(1) http://www.usimmigrationsupport.org/immigrants_send_money_home.html
SOURCE Panda Security
Source: PR Newswire
Related Articles
- VillageEDOCS Sells Tailored Business Solutions to Harris Computer Systems
- Global Payments Enters Into Agreement to Sell Its Money Transfer Businesses
- CA Security Management Business Leader Dave Hansen to Deliver Keynote at RSA Europe Conference 2009
- Check Point Software Technologies' Acquisition of Nokia's Security Appliance Business Completed
- Nokia Signs Agreement to Sell Security Appliance Business to Check Point Software Technologies
- Maxis Unveils Cell Phone Money Transfer
- Spectrum Computer Forensics & Risk Management LLC Provides Pivotal Evidence in Federal Judge's Opinion in Fraud Case
- Security Researchers Say Worm Could Destroy Computer Files
- Business Software Transfer Association(TM) Announces Used Software License Exchange at Annual IAITAM Conference in Orlando
User Comments (0)

RSS Feeds