InfoSecurity Europe 2005
InfoSecurity Europe 2005
R E L A T E D   C O N T E N T
ADVERTISEMENT

Most computer hacking an 'inside job'

Biggest threat from current or former employees, warns Met Police

Iain Thomson at InfoSec in London, vnunet.com 26 Apr 2005
ADVERTISEMENT

The vast majority of computer hacking is done by current and former employees, according to the Metropolitan Police.

In a panel session at this year's InfoSecurity Europe conference, Detective Inspector Chris Simpson of the Metropolitan Police Computer Crime Unit told delegates that one of the first steps in any investigation is to check employee details.

"In the vast majority of cases we investigate the culprits are current or former employees," he said.

"They are not hacking into systems using flaws in software. Instead they are using flaws in the security procedures of the company to carry out their attack."

Simpson added that electronic crime is definitely on the rise and outlined the main threat vectors.

Online organised crime is originating predominantly from eastern Europe, while the biggest spammers are found in the US, China and Germany. Script kiddies are predominantly from the US, Canada or Britain and their numbers are on the rise thanks to the popularity of virus creation kits.

Meanwhile the Crown Prosecution Service (CPS) is gearing up for more computer crime.

"We have come to the conclusion that computer crime is here to stay," said Ester George, policy advisor to the CPS.

"Computers now touch almost every case, hacking or otherwise. The convergence of phones and PDAs is increasing this."



George cited two non-hacking events where computers were crucial to the case. In one a man went berserk and attacked passers by, claiming diminished responsibility. But his internet logs showed that he'd been researching his likely sentence online before carrying out the attacks.

In the other case a child was brought into hospital and died of pneumonia. The parent was charged after internet logs showed that sites had been visited that identified factors in catching the infection.

To prepare for this, the CPS has set up a training scheme which teaches barristers how to handle high-tech cases. To date 110 prosecutors have attended the course.

See also:

IT managers increasingly worried about spywareMore worrying than spam, phishing and hacking, say IT managers  11 May 2005
InfoSecurity Europe 2005Companies losing out by hiding behind firewalls  27 Apr 2005
InfoSecurity Europe 2005Perimeter security no longer enough  26 Apr 2005
InfoSecurity Europe 2005Providers 'missing a sales opportunity', claim experts  26 Apr 2005
SecurityThe latest wave of cyber-crimes and acts of vandalism have demonstrated once again that many systems are still vulnerable to attack.  15 Apr 2004

All Hacking

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
Reading, Berkshire, United Kingdom | EDS
Position - EA Integrator Location - Reading Job Description: A skilled System Integrator to integrate application Test Harnesses to support business requirements. The Candidate will possess specific experience of enterprise systems, component validation and integrating ... more >
Inverness, United Kingdom | NHS Scotland
CORPORATE SERVICES E-HEALTH DEPARTMENT  RAIGMORE HOSPITAL INVERNESS TECHNICAL DEVELOPMENT TEAM IT TECHNICAL SPECIALIST  £24,103 to £32,653 PA An exciting opportunity has arisen to join the technical development team within the eHealth Department. We are looking ... more >
Sandiacre, Nottinghamshire, United Kingdom | NHS Midlands
Workstream Lead Requirement, Design, Build and Test (Business Analyst) Strategic IM&T - Delivery   Band 7:      £29,091 - £38,352 per annum Hours:       37.5 per week Base:         Octavia House, Sandiacre Job Ref:     973 - 080810   ... more >
Reading, Berkshire, United Kingdom | EDS
Job Description: A skilled System Integrator to integrate application hosting environments to support business requirements. The Candidate will possess specific experience of enterprise systems, component validation and integrating technical Infrastructures and system management facilities within ... more >
More job opportunities