You are here: silicon.com > Software > Security Strategy

Security Strategy

Extortion scams 'heading your way'

First the bookies, then big business and now smaller firms are threatened with denial of service...

By Will Sturgeon

Published: 21 April 2004 15:55 GMT

Extortion scams threatening distributed denial of service (DDoS) attacks against sites that don't pay a ransom fee are becoming far more common than was feared when it was believed that larger bookmakers were the major target.

Blamed largely on the Russian mafia by security experts, the blackmail scams threaten to cripple businesses with overwhelming amounts of site traffic unless the company pays up. According to Cable & Wireless, the number and nature of companies targeted is changing rapidly.

Rob Thomas, head of product marketing and C&W, said: "We've seen a significant increase in DDoS attacks with the increase in broadband. The amount of traffic which can now be created through these always-on connections has increased and these attacks are becoming far more sophisticated."

Furthermore, he warned that only 20 per cent of companies are likely to have measures in place to prevent them falling foul of such scams.

Thomas said the attacks, which were originally aimed largely at gambling sites, are starting to target other businesses.

Thomas said: "Online retailers are all vulnerable to attack in this way, as is anybody who is generating significant revenue online."

Inevitably this means that smaller companies may find themselves in the firing line - once all the largest targets have been hit or have put in place measures to safeguard themselves.

"Organised criminals may now be targeting companies who don't have the resources in place to guard against these attacks," said Thomas, citing a couple of smaller C&W customers who have reported problems of this nature.

A great many businesses have rushed online, according to Thomas, and many are now paying for having "not hardened the platform" prior to launch nor planning their security needs appropriately.

And although he agreed that it is an issue in danger of being over-hyped at the moment, Thomas says it is a very real concern for many businesses - though he said firms must be aware of which threats are most relevant to them and must have proper planning in place to establish the level of risk and guard against it.

These scams clearly pose more of a threat to the likes of Ladbrokes and Bet365.com than they do to small independent e-tailers but all companies must cater for their relative exposure, according to Thomas.

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Bob Tarzey Why you must rein in your power users When they do damage, it can be catastrophic to your business

Jon Collins Is losing a mobile device really such a big deal? How to minimise the damage to your business


  • Jobs
PMO Programme Controls and Planning Manager

Rationalisation Plan with IT Services and Architecture while ensuring that milestone planning, templates and standards all adhere to PMO standards, ...

Senior Software Engineer

These next-generation threats attack on multiple levels of the network infrastructure. CompanyMcAfee creates best-of-breed computer security ...

Information Security Analyst (Attack Monitoring/Data Leakage/CISSP/CEH)

Information Security Analyst (Attack Monitoring/Data Leakage/CISSP/CEH)A highly risk-aware Attack Monitoring Analyst is required for a leading global ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: