Skip to main content

This ain’t CSI: How the FBI hunts down cyber criminals around the globe

FBI Cybercrime
FBI
Cyber-attacks are ten a penny now, and the FBI and other authorities that investigate these crimes around the world have many hurdles to cross if they want to catch a hacker. Police forces can often be hindered by the dark web and anonymizing tools used by cyber-criminals to cover their tracks, but there are also political barriers in arresting cyber-criminals in other countries as well as lengthy trials and investigations into home-grown perpetrators. A couple of high profile cases from recent years have shined a light on how cyber-crime cases are carried out.

There is now a growing underground economy for cyber-crime. It is no longer the preserve of just the hacker elite. The market is thriving, said Symantec in one of its most recent threat reports. More cyber-criminals, whether sophisticated or glorified script kiddies, means more work for authorities as they try desperately to keep up with a flood of international attacks.

International cyber arrests

Many of the world’s most active hackers are dotted across the globe, from Russia to China, from the UK to Australia. The FBI’s most wanted cyber-crime list includes numerous foreign nationals. The most recent hacker snagged from across the pond was British man Lauri Love, who is charged with infiltrating US government computers and now faces extradition.

Blackshades group
FBI

American authorities encounter many hurdles when trying to capture and extradite an international cyber-criminal. Recently, they scored a rare win with the extradition of alleged hacker Ercan Findikoglu, a Turkish man who’d been arrested in Germany in 2013 and had been sitting in prison there since. Findikoglu, 33, is accused of leading a criminal group that hacked ATMs in New York and 23 other countries, stealing over 50 million dollars. Findikoglu had been described as one of the most wanted cyber crooks in the world, and if convicted he could face life behind bars — in the form of a 247 year prison sentence.

A Swedish man named Alex Yucel, who led the Blackshades group, was convicted by a New York court in June and sentenced to four years and nine months for developing and selling malware. He had been arrested in Moldova in 2013 and successfully extradited following years of creating remote access tools that could gain control of victims’ computers. His software is believed to have infected over 500,000 computers.

Yucel pleaded guilty and Judge P. Kevin Castel described him and other cyber-criminals as “spreading misery” across the world’s internet users. “The message must go forth that this is a serious crime worthy of a serious punishment,” said the judge. “Yucel’s computer hacking days are now over,” said Preet Bharara, US Attorney for the Southern District of New York.

Forming cross border bonds

There are many wanted hackers in Europe that are of interest to American authorities. One of the most notorious is Nicolae Popescu, a Romanian national, wanted for orchestrating an Internet fraud scheme.

Local Romanian authorities take the threat of hackers very seriously, says Alexandru Catalin Cosoi, chief security strategist at Romanian security software company Bitdefender.

Academics, the security industry, and governments need to form bonds to carry out international efforts.

“[Authorities are] in the underground forums, they’re doing a lot of arrests,” he says. “I know that there are a lot of specialists in the law enforcement agencies that are very skilled and are very eager to solve these issues.”

Academics, the security industry, and governments need to form bonds to carry out international efforts, adds Dr. Bhavani Thuraisingham, director of the Cyber Security Research Center at the University of Texas, Dallas. “We need not just technical solutions, we need political solutions,” she says.

In Europe, organizations like Europol and the private security sector work together to investigate and eventually arrest cyber-criminals, says Ilias Chantzos, senior director of government affairs EMEA at Symantec.

“We will work together, collect intelligence to understand what is the criminal infrastructure we want to go after,” says Chantzos, who also sits on Europol’s Cybercrime Centre (EC3) advisory group. “What will happen, will be an effective, regular interaction between corporations and law enforcement, exchanging information, and when there’s a green light, the operation will take place.”

ShroudedHorizonMap1300
Image used with permission by copyright holder

Europol also collaborates with the FBI, as seen recently in the shuttering of dark web forum Darkode, which included Romanian authorities, for example. The operation was led by the FBI and included law enforcement agencies from 20 countries. “Obviously jurisdiction is an issue,” explains Chantzos, but effective communication and collaboration makes a difference.

“We need to know that the criminal is in a territory that we can do the arrest or that we know that some of the criminal infrastructure we’re going to disrupt is in a territory that we can exercise jurisdiction. Some of it will not be there and we need to accept that so often the effectiveness will be as good as it possibly can be.”

Safe in Russia?

The top man on the FBI’s most wanted cyber-crime list is the Russian hacker Evgeniy Mikhailovitch Bogachev, with a three million dollar bounty on his head, the highest reward of anyone else on the list.

The FBI says he’s likely still at his residence in Anapa, Russia on the Black Sea, which poses immense challenges for investigators. The US doesn’t have a formal extradition treaty with Russia, unlike Sweden, Turkey, and Germany, and diplomatic relations between the countries are fraught. Russia’s decision to grant asylum to Edward Snowden in 2013 worsened relations between Russia and the US on this matter.

We will use every available legal and diplomatic means to bring all cyber-criminals to justice wherever they reside.

“We will use every available legal and diplomatic means to bring all cyber-criminals to justice wherever they reside,” said David Hickton, US Attorney for the Western District of Pennsylvania, where the charges were filed.

Bogachev (AKA “lucky12345″ and “slavik”) was formally indicted last year under his real name for developing strains of ransomware and coordinating the GameOver Zeus botnet, an attack network that could be used to siphon off online banking details. His malware is believed to have infected at least one million computers globally and raked in an estimated $100 million.

The Russian’s charges are exhaustive and include computer fraud, bank fraud, conspiracy, and aggravated identity theft. He’s considered a major threat to the US banking industry and the possible head of a cybercrime “gang” working out of Russia and Ukraine, which has made him a high priority.

There are rumors that Russian authorities have willingly turned a blind eye. According to a Telegraph report from last year, he is even seen as a hero of sorts among the residents of his hometown. That makes catching him much more difficult — though it’s still not impossible.

EVGENIY MIKHAILOVICH BOGACHEV
Image used with permission by copyright holder

“Cybercriminals like normal people like to travel,” says Chantzos. “[Russians] might go to Cyprus for holiday. Well, guess what, there’s a European arrest warrant waiting for him. The moment he arrives in Cyprus, he’s going to get picked up.”

Many hackers, regardless of nationality, are known to have traveled in the hopes of evading capture, but it may give the FBI a chance. Latvian Alexsey Belan, wanted for hacking US ecommerce companies, was last known to be in Greece. Peteris Sahurovs, who allegedly sold fraudulent security software, may still be in Latvia. These hackers, if picked up in their travels, can be extradited regardless of nationality.

An unsolved mystery

As criminals like Bogachev have proven, there are still major gaps in international cyber-crime enforcement, and a smart hacker can exploit them to operate with near impunity.

Nevertheless, international stings have become more commonplace, and much more intensive. In recent news, the FBI is seeking the extradition of two Israeli suspects following their arrest over the JPMorgan hack. And in June, Europol successfully shut down a major cyber-crime organization in Ukraine.

“There’s a lot of countries that will not extradite. That will not stop us from pressing forward and charging those individuals and making it public,” Robert Anderson, the FBI’s Executive Assistant Director of the Criminal, Cyber, Response, and Services Branch, told a conference in May, promising more arrests under his tenure.

Bogachev may still be in Russia, but with a $3m incentive for his arrest, hacktivists and online sleuths could end up being the FBI’s friend. Countries across the globe are well aware of the threat foreign hackers can pose, and are working together to tighten the noose. Today’s Internet at times feels a bit like the wild west, it will in all likelihood be tamed. Eventually.

Topics
Jonathan Keane
Former Digital Trends Contributor
Jonathan is a freelance technology journalist living in Dublin, Ireland. He's previously written for publications and sites…
Power up your tech game this summer with Dell’s top deals: Upgrade for a bargain
Dell Techfest and best tech on sale featured.

One of the best times to upgrade your tech stack, be it your desktop, a new laptop, or some high-resolution monitors, is when great deals are to be had. Well, I'm here to share that thanks to Dell's top deals, you can power up your tech game and have most of the summer to make it happen. Maybe you're happy with your current system or setup. That's excellent, but you're likely considering upgrading somewhere, and that's precisely what these deals are all about. Dell has a smorgasbord of deals on laptops, desktops, gaming desktops, monitors, accessories, and so much more. We'll call out a few of our favorite deals below, but for now, know that you should be shopping this sale if you're interested in anything tech-related.

 
What summer tech should you buy in Dell's top deals?

Read more
I love the MacBook Pro, but this Windows laptop came surprisingly close
Apple MacBook Pro 16 downward view showing keyboard and speaker.

There are some great machines in the 15-inch laptop category, which has recently been stretched to include the more common 16-inch laptop. The best among them is the Apple MacBook Pro 16, which offers fast performance for tasks like video editing and the longest battery life.

The Lenovo Yoga Pro 9i 16 is aimed not only at other 16-inch Windows laptops but also at the MacBook Pro 16. It offers many of the same benefits but at a lower price. Can it take a place at the top?
Specs and configurations

Read more
How to set an ‘Out of Office’ message in Microsoft Teams
Person using Windows 11 laptop on their lap by the window.

Many people use Microsoft Teams regularly to communicate with colleagues both inside of the office and remotely. It is considered one of the most efficient ways to ensure you can stay in contact with the people on your team, but what if you need to let people know you’re not readily available? Microsoft Teams has a method for you to set up an "Out of Office" status for your profile to let staff members know when you’ll be gone for the afternoon, for several days on vacation, or for an extended period.
Where do I go to set up my ‘Out of Office’ status for Teams?
It is important to note that your Microsoft Teams and Outlook calendars are synced. This includes your out-of-office status and automatic replies. So, whatever you set up in Microsoft Teams will reflect in Outlook. Similarly, you can set up your out-of-office status in Outlook, and it will be reflected in Teams; however, the former has a more straightforward instruction.

First, you can click on your profile icon in Teams and go directly to Schedule an out of office, as a shortcut. This will take you to the settings area where you can proceed. You can also click the three-dot icon next to your profile icon, then go to Settings > General, then scroll down to the bottom of the page. There, you'll find out-of-office settings and click Schedule.

Read more