Showing posts with label al qaeda. Show all posts
Showing posts with label al qaeda. Show all posts

Thursday, October 09, 2008

Yahoo Software Engineer Accused of using Hacking Techniques in Terrorist Bomb Plots

In July, an Islamic terrorist group sent e-mail messages claiming responsibility for bombings in Indian cities before the acts took place. The messages were sent by hacking into unsecured wireless networks and one suspect in the case has been identified as software engineer, Mohammed Asghar Mansoor Peerbhoy, who is a Yahoo employee.

Peerbhoy allegedly made several work related trips to the U.S., while employed by Yahoo. It is alleged that he, along with two other Indian software engineers, were part of a media terror cell. One of the engineers has been identified as Atiq Iqbal and Mobin Kader Chaikh and Asif Basrudding Shaikh have been named as the techie connections in the case. One worked for an IT firm and the other was a qualified mechanical engineer. Fifteen people have been arrested in the case thus far.

One of the emails which the hackers sent can be viewed on deshgujarat.com.

The Times of India alleged that Peerbhoy admitted in an interrogation to attending a hacking course, where two foreigners were present. This was an ethical hacking course designed for training internet security workers. Ethical hacking courses are offered all over the place and given that India is part of the global economy, the tie between foreigners and terrorist activity is questionable.

The Indian authorities are stating that the wireless networks were hacked using a fairly well-known technique often referred to as wardriving. Once they secured an unsecured network (pardon the pun), they programmed the e-mails to be sent shortly before the blasts, according to the authorities.

Wardriving is a pretty simple hacking method where someone drives around until they find an unsecured signal. Most wireless cards have the capability of sniffing out available networks. Once an unsecured network is found - getting on it normally only requires the click of a mouse. Teen age hackers are known to engage in this activity for fun. In most cases, any wireless network can be made "hacker proof" by simply password protecting by using the instructions you get when you buy the router. Wardriving has recently been made a felony in the United States.

This story illustrates that you don't have to be very sophisticated to commit crime or terrorism with a computer. Quite often, pretty simple techniques can equate to devastating results. Much more sophisticated do-it-yourself hacking kits, which sometimes come with technical support, are easily obtained on the Internet black market.

Saying that, the end result in this case is tragic.

India has suffered a rash of bombings in recent history. The specific terrorist group behind the incidents in question is known as the Indian Mujahideen, known locally as the IM. It is believed to be affiliated with another Indian terrorist group known as Student Islamic Group of India (SIMI). The Indian government suspects SIMI has been penetrated by Al Qaeda.

Initial arrests in this case were made when Indian authorities tracked down suspects in the case after discovering cell phone numbers the group used and investigating them.

Sunday, June 15, 2008

Credit Card fraud used to fund Terrorist Organization

Here is an example of cyber crime being used to fund terrorism. Fortunately, the person behind this is now behind bars.

The Sri Lanka Ministry of Defence website reported:

The mastermind behind the international credit card fraud for funding the LTTE terrorist organization has been arrested by the Special Task Force (STF) personnel while conducting a search operation in the Wellawatta area on Friday, June 13.

The suspect Anandan, alias Neshanadan Muruganandan, was in a super luxury apartment in Wellawatta at the time he was arrested by the special police team, sources said. He had a large number of Personal Identification Numbers (PIN) and bank receipts issued by both local and foreign banks, amounting to a massive sum of money, over Rs. 100 million, in his possession when he was arrested.

This isn't the first time a tie between payment (credit/debit) card fraud and funding terrorism has been suggested. In the past, it's been widely reported that Al Qaeda training manuals teach their minions to use credit card fraud as a way to survive in foreign lands.

There has also been speculation that organized crime and terrorists mingle in the underground economy when it suits their needs. In another story, also found on Sri Lanka's Ministry of Defence site, it mentions that 130,000 passports were stolen and that some of them were provided to the highest bidder (Al Qaeda).

Also mentioned in the interesting story is other ways this terrorist group, the Tamil Tigers, obtain their funding.

While I doubt organized criminals, and or terrorists are going to admit they are taking advantage of stolen personal and financial information in public, it could be a bigger problem than we realize (?).

Here in the West, Suad Leija and her husband have been trying to get this message out to everyone on their site (Paper Weapons). If you are interested in understanding how paper (and sometimes plastic) weapons might be used by people with twisted political objectives, I highly recommend visiting their site.

Wednesday, January 31, 2007

Paper weapons (counterfeit documents) enable more serious crimes than illegal immigration and identity theft

Suad Leija

Counterfeit (forged) documents are used by illegal immigrants, financial crime artists (fraudsters) and even terrorists. 9/11 proved this a few years back - when it was discovered that several of the hijackers (terrorists) used forged documents to obtain legitimate state-issued driver's licenses.

And this can't be the only time terrorists have used counterfeit documents - jihadist training materials teach their disciples to use these documents to blend into our society, as well as to pay for their expenses. Al Qaeda's training manual (courtesy of Frontline) illustrates this, here.

Several months ago, I saw one of the first stories about Suad Leija and wrote about her. Since then I've mentioned her in a couple of posts. This led to her husband making contact with me, and eventually speaking to Suad, herself.

Suad Leija is trying to educate the public that counterfeit documents pose a serious problem to our safety and national security. And who would know better than Suad, who was raised around one of the biggest organized crime groups providing counterfeit documents to anyone willing to pay for them.

Suad is the step-daughter of Manuel Leija Sanchez, described as the "boss" of the Chicago cell of the Castorena Leija-Sanchez crime family. The ICE press release about his recent arrest can be seen, here.

Mr. Leija-Sanchez has been arrested in the past for selling counterfeit documents (several times), narcotics and assault. He is currently serving a one-year sentence in Illinois for this latest arrest. More details about how he ended up only getting one-year sentence are on Suad's YouTube videos, which can be seen on her Paper Weapons site (highly recommended and linked to further down in this post).

I asked Suad about her bodyguards - mentioned in other articles about her - reported as being Polish. She told me that they were represented to her as Polish, but didn't really know. Interestingly enough, they taught Suad to speak a little Russian.

This made me reflect on speculation that Eastern European organized crime is involved in all the major data-breaches involving the theft of personal and financial data. They would need resources to turn their information into counterfeit devices.

Eastern European organized crime is (also) known to be involved in human smuggling and there are illegal immigrants of Eastern European origin all over the world. Sometimes, we need to remember that illegal immigrants aren't only from Mexico.

Law enforcement officials from Canada and Great Britain have voiced their concerns in public about connections between organized crime and terrorism in the recent past.

Of course, the FBI has been saying the same thing for awhile (since 2002), here.

I asked Suad how many people she thought used counterfeit identification to obtain legitimate documents and she told me that was why items, such as utility bills are popular. Suad describes these items as "feeder documents," which are then used to obtain more legitimate identification.

As long as feeder documents are acceptable to prove legal status, putting security features on legitimate documents will do little to stop the problem. This is especially true, when some of the documents used as feeder documents might come from anywhere in the world.

Hazardous material licenses are even forged - allowing hazardous materials to be illegally transported. Besides the possibility of a freak accident occurring (if used in an intentional manner) a lot of innocent people could be hurt, or killed because of a forged hazmat license.

Counterfeit documents can be used to cross borders, board airplanes and it seems (more recently) obtain access to sensitive government facilities.

ICE recently arrested quite a few illegal aliens working at some of these secure government facilities.

Suad is currently in hiding (under the protection of her husband) - there are reports that her step-father has threatened her life after he is released. Manuel Leija-Sanchez and Pedro Castorena are both in custody - but there is no telling for how long - and their organizations still appear to in business.

ICE press release on Pedro Castorena's arrest, here.

According to Suad's website Paper Weapons:

The Castorena Leija-Sanchez crime organization is the major supplier of counterfeit documents/paper weapons in the United States. They are based in Mexico and have been operating in the United States for 17 years. They are in every major US city and earn approximately 300 million dollars per year.

Paper Weapons site, here.

The site has a chilling flash presentation showing pictures of 9-11 terrorists and members of the Castorena Leija-Sanchez family on fake counterfeit identification.

Suad's story has been covered by the mainstream media (Lou Dobbs, Paula Zahn, CBS, Univision), here.

Her personal story (in her own words) can also be seen in a series of YouTube presentations, along with the stories from the mainstream media.

Some other items were pointed out to me as a result of this conversation. There are 15 million illegal immigrants in the country today, and the reason they are here is to make money. If the jobs weren't readily available (and they seem to be), the problem wouldn't be anywhere as big as it is now.

The motivation of most of these people is to escape poverty - and believe it or not - people on public assistance in the United States live like "kings" in comparison to how they live in their own countries.

Then there is the matter of how any program could be administered. Embassies across the world are already overwhelmed with visa requests and how would these people be effectively screened?

It was also pointed out to me that if a guest worker program were implemented, it probably wouldn't be long before the required identification to be a guest worker was being counterfeited, also.

Documents being counterfeited is nothing new (counterfeiting has been around for centuries). But with recent advances in technology, it's becoming pretty easy to do. The quality of the documents is getting better and security features are being compromised quicker than ever before.

The problem of counterfeit documents goes far beyond poor people doing menial labor (jobs that no one seems to really want). In fact, they are enabling much more serious activity, and this is where we need to direct our focus.

Monday, June 12, 2006

Are Terrorists Probing Our Computer Systems?

I read a pretty alarming article by Barton Gellman of the Washington Post, stating that terrorists might already be planning cyber-attacks:

"Late last fall, Detective Chris Hsiung of the Mountain View, Calif., police department began investigating a suspicious pattern of surveillance against Silicon Valley computers. From the Middle East and South Asia, unknown browsers were exploring the digital systems used to manage Bay Area utilities and government offices. Hsiung, a specialist in high-technology crime, alerted the FBI's San Francisco computer intrusion squad."

"Working with experts at the Lawrence Livermore National Laboratory, the FBI traced trails of a broader reconnaissance. A forensic summary of the investigation, prepared in the Defense Department, said the bureau found "multiple casings of sites" nationwide. Routed through telecommunications switches in Saudi Arabia, Indonesia and Pakistan, the visitors studied emergency telephone systems, electrical generation and transmission, water storage and distribution, nuclear power plants and gas facilities."

The article also reports another issue, which is a big problem:

"New public-private partnerships are helping, but the government case remains a tough sell. Alan Paller, director of research at the SANS Institute in Bethesda, said not even banks and brokerages, considered the most security-conscious businesses, tell the government when their systems are attacked. Sources said the government did not learn crucial details about September's Nimda worm, which caused an estimated $ 530 million in damage, until the stricken companies began firing their security executives."

"Experts said public companies worry about the loss of customer confidence and the legal liability to shareholders or security vendors when they report flaws."

For the full story, link here.

If the observations in this article are accurate, we can no longer afford to "keep the lid" on cyber-attacks in the interest of protecting bottom lines. Being worried about consumer confidence and legal liability should take second place to the safety and welfare of all concerned.

Here are some previous posts, I written on this subject:

Mounties Lack Resources to Fight Organized Crime and Cite Ties to Terrorism

Do Financial Crimes and Internet Fraud Fund Terrorism

Sunday, May 14, 2006

Mounties Lack Resources to Fight Organized Crime and Cite Ties to Terrorism

The Canadian Press is reporting:

The head of the RCMP says his agency is increasingly concerned about evidence that organized crime groups are helping to fund terrorist gangs.

Giuliano Zaccardelli's observations Monday may come as a shock to some, but not to those who monitor trends in law enforcement.
Almost every conceivable type of organized crime helps to finance terrorist groups whose chief goal is killing Westerners, said one expert in the field.
That can mean the proceeds from hashish baggies being peddled on street corners, cocaine trafficking, prostitution, pick-pocketing, knock-off designer items and credit card fraud.
Zaccardelli wasn't quite that specific during his appearance before a Senate committee Monday. But he said the evidence is clear, and continually mounting.
Here are some specific examples backing up this claim made by John Thompson of the Mackenzie Institute, which is a Toronto Think Group:
Almost all terrorist groups around the world use organized crime to pay for their operations.
Al-Qaeda and Osama bin Laden are no different.
The bombers who blew up Madrid's rail system in 2004, injuring 192 people and wounded 2,050, financed their operation by selling hashish.
Hashish from the Middle East, heroin from...Afghanistan and Pakistan, cocaine, it all at some point goes through the hands of terrorists on its way down to the street.
The basic training for al-Qaeda recruits includes at least four major components: handling firearms, making bombs, ideological reinforcement, and supporting yourself through credit-card fraud.
He points to ex-Montrealer Ahmed Ressam, who was convicted of trying to blow up Los Angeles airport on New Year's Eve 1999.
Ressam also planned to set up a side business to help fund his terrorist jihad.
"He was going to try and set up a shop so they could access people's credit cards and start counterfeiting them.''

Link to full story, here.

The saddest part of all this is that the RCMP, who are known for "getting their man" are admitting they only have the resources to address about one-third of this activity.

For another article by the National Post on current RCMP resources and their border problem, link here.

Perhaps, we in the United States should take notice - while we focus on the border to the South - here is another reason, "We Can No Longer Allow Criminals to Control Our Borders."

It seems the Canadians are coming to the same conclusion.

Here is a previous post, I did on this problem:

Do Financial Crimes and Internet Fraud Fund Terrorism

Friday, April 28, 2006

Do Financial Crimes and Internet Fraud Fund Terrorism

Many of us wonder exactly how terrorism is funded. Here is a story from the AP, which might lead some to believe that financial crimes (fraud) is a source of funding.

"Five relatives of a U.S. citizen suspected of being a senior Al Qaida operative were arrested in California and Utah on charges of defrauding banks of hundreds of thousands of dollars."

"The FBI said Omar's relatives netted $327,000 from fraudulent bank loans and bad mortgages in Utah, and Bretzing said some of the money wound up in Jordan with Omar's relatives.

Omar, a 44-year-old Kuwaiti native with U.S. and Jordanian citizenship, has been indicted in Jordan with Iraq insurgent leader Abu Musab al-Zarqawi in an aborted chemical attack on the Jordanian intelligence agency."

Full story by the AP courtesy of MSNBC, here.

Of course, the FBI says the matter is still under investigation and won't speculate. Please note, I can't blame them for not doing so in an ongoing case.

BUT here is evidence that the FBI takes the ties between fraud and terrorism seriously. Here are excerpts from a speech delivered by Grant Ashley, Executive Assistant Director of the FBI to the International Association of Financial Crimes Investigators in 2004:

It has often been said that money is the root of all evil. I don't know if that's the case, but I do know that it is the root of terrorism. Terrorists rely on money to fund their training and operations. They disguise their fundraising activities as legitimate charity organizations. They resort to white-collar crime to raise money. Money laundering is no longer exclusive to sophisticated criminals, but is now routine for terrorists.

Money can also be the fruit of terrorism and crime. Today's terrorists and criminals use sophisticated business practices to achieve their goals, not unlike those of legitimate multinational corporations. Criminals today are not just stealing funds, they are stealing credit card information, social security numbers - entire identities - and selling them for profit. Those who traffic in humans, drugs, or weapons are motivated and rewarded by money.

Link to Assistant Director Ashley's speech, here.

Although it rarely makes it in the news, it appears that the FBI sees a connection between financial crimes (fraud) and terrorism.

If there are some of you out there that are leery of government sources, the Washington Post did a story on Imam Samudra, the terrorist behind the Bali Night Club bombings in Indonesia. Samudra published a book with a chapter entitled "Hacking, Why Not?"

There, Samudra urges fellow Muslim radicals to take the holy war into cyberspace by attacking U.S. computers, with the particular aim of committing credit card fraud, called "carding." The chapter then provides an outline on how to get started.

Samudra, 34, is among the most technologically savvy members of Jemaah Islamiah, an underground Islamic radical movement in Southeast Asia that is linked to al Qaida. He sought to fund the Bali attacks in part through online credit card fraud, according to Indonesian police. They said Samudra's laptop computer revealed an attempt at carding, but it was unclear whether he had succeeded.

Samudra was quoted in the article:

"It would not be America if the country were secure. It would not be America if its computer network were impenetrable," he writes at the beginning of the hacking chapter. He continues by urging fellow militants to exploit this opening: "Any man-made product contains weakness because man himself is a weak creature. So it is with the Americans, who boast they are a strong nation."

Here is a link to the story by the Washington Post.

Interestingly enough, we have seen some major hacking activity in the recent past, where large numbers of credit and debit card numbers have been compromised. There have also been a large number of data breaches, most of which seem never to have been solved.

In testimony before Congress, Dennis M. Lormel, Chief, Financial Crimes Section, FBI said:

Because most of these are never solved, we as average people can only speculate as to what the source of this activity is.

After all, (Terrorist 007) Irhabi 007, the so-called Al Qaida hacker, who was spreading terrorist propaganda on the Internet used stolen credit cards to set up his ISP connections.

In testimony before Congress, Dennis M. Lormel, Chief, Financial Crimes Section, FBI stated:

Another pattern of terrorist financing involves funding of terrorist cell activities through various criminal activity. Al Qaida has been known to encourage and instruct terrorist cells in terrorist training camps in Afghanistan in ways they can fund their terrorist activities through various criminal activity. For example, Ahmed Ressam, the Algerian extremist convicted in the terrorist plot to place bombs at Los Angeles International Airport among other locations, was instructed in these camps to engage in criminal activity such as bank robberies and fraud schemes to fund his terrorist activities. As another example, investigation has identified a terrorist cell based in Spain with ties to Al Qaida that used stolen credit cards in fictitious sales scams and for numerous other purchases for the cell. They kept purchases below amount where identification would be presented. They also used stolen telephone and credit cards for communications back to Pakistan, Afghanistan, Lebanon, etc. Extensive use of false passports and travel documents were used to open bank accounts where money for the mujahadin movement was sent to and from countries such as Pakistan, Afghanistan, etc. In addition, the cell relied upon street crimes such as home burglary, car theft, and car burglary to fund their cell activities.

We live in a new and more dangerous world since the 9-11 attacks. This new world requires that we take another look at issues, such as financial crimes and illegal immigration. These issues, which were not priorities in the past, have become increasingly important in the quest to ensure our safety and security.

Unfortunately, there are too many out there, who want things to remain the same and are now exercising their political voices to prevent the necessary changes.

Perhaps, they should go out and watch "United 93" to refresh their memories of why we can no longer allow tolerate loose financial controls and allow criminals and terrorists easy access to our borders.