Idan Aharoni

Idan Aharoni

Idan Aharoni is Head of Cyber Intelligence at RSA where he is responsible for leading the team which gathers, analyzes and reports intelligence findings on worldwide cybercrime and fraud activity. Mr. Aharoni joined Cyota (later acquired by RSA) in February 2005 as an analyst at the Anti-Fraud Command Center. During his service, he founded the FraudAction Intelligence team, which he leads today. Between his work at the Anti-Fraud Command Center, as well as the unique insight he has gained by the intelligence and discoveries gathered by his team, Mr. Aharoni offers vast expertise into the underground fraud economy and how cybercriminals operate. Subscribe to Idan's RSS feed

New Service in the Underground Offers to Secure Fraudsters’ Infrastructure – Because Fraudsters Need InfoSec Too

Whether it is to Phish, to infect, or to sell credentials, cybercriminals have always required an infrastructure to commit their crimes – servers, PHP scripts, vulnerabilities and more. Many of the trends in recent years, such as the explosion of botnets and credit card stores, have led to the rapid expansion of this infrastructure.

The Natural Selection of Fraud

Evolution isn’t just about making things better but to adjust living creatures to their ever changing surroundings. Fraud in that sense is also adapting, but instead of searching for food like a giraffe, it adapts to obtaining as much money as possible. If money from one fraud chain depletes, it would adapt and create a different one.

Decoding Service for Audio-Skimmed Credit Card Data Offered in the Underground

A new service recently launched in the underground, offering cybercriminals to decode track 2 data (raw information of the magnetic stripe) that was captured in audio format by ATM skimmers.

Living Under Watchful Eyes as a Fraudster

The fallout from the news of the Global Payments breach may be just subsiding, but one thing can already be said – this probably isn’t the last processor that will be breached.

The Return of the Mega-Boards: Is the Underground Economy Returning to its Former Glory?

They say history repeats itself, or perhaps this is the story of a community recovering from a catastrophe. Either way, the underground is returning to its former glory, and not just in how much business is being conducted – but how it is conducted.

Localization in the Fraud Underground: When Fraudsters from the Same Locale Get Together

Everybody knows that the Russian fraudsters are more sophisticated than their English-speaking counterparts. However, this isn’t the only geographic-related difference between fraudsters.

Vishing: To Have Your Identity Stolen, Press One

Of all the terms describing identity theft methods, “Vishing” (which stands for “Voice Phishing”) is perhaps the most ambiguous one. A simple Google query for the definition of the term shows just some of its multiple interpretations. But why are fraudsters using this type of attack?

Revisited: The Optimist’s Cybercrime Predictions for 2011

Around this time last year you may have read my SecurityWeek article, The Optimist’s Cybercrime Predictions for 2011. Now that the year is drawing to an end, I thought it would be an interesting opportunity to look back to my 2011 predictions and see how each of them panned out.

Where do Fraudsters Learn About New Attacks? From the Good Guys

Looking to maximize their profits, fraudsters need to do a whole lot of learning. They can either learn techniques of areas they have not focused on thus far, learn better techniques in the field they already specialize in, or learn new cover stories to improve the techniques they already use. A lot of this learning is done through trial and error. That’s how fraudsters discover vulnerabilities in banks’ processes that allow them to cash out a lot of money with relatively little effort.

Underground Forums Open Official Credit Card Stores

In the short time I’ve been blogging, I’ve written relatively often about automated CC stores. These websites offer fraudsters an automatic way of buying stolen credit cards – simply fund an account with e-currency, choose which type of card you would like, pay and receive the full credential. Their popularity has reached such a fever pitch. Recently, we’ve encountered a new development in the underground in regards to these sites – forums opening “official” stores.