FBI embeds cyber-investigators in Ukraine, Estonia
IDG News Service - Hoping to catch cybercrooks, the FBI has begun embedding agents with law enforcement agencies in Estonia, the Ukraine and the Netherlands.
Over the past few months, the agents have begun working hand in hand with local police to help crack tough international cybercrime investigations, said Jeffrey Troy, chief of the FBI's Cyber Division, in an interview at the RSA Conference in San Francisco. Because virtually all cybercrime crosses international borders, this type of cooperation is crucial, law enforcement experts say.
The embedding was inspired by a successful operation in Romania, begun in 2006, which led to close to 100 arrests. "We looked at that and said, 'Where else can we do this,'" said Troy, who heads up FBI cybercrime operations.
The FBI has a history of embedding its agents with international police. In the 1980s, U.S. agents worked with Italian law enforcement to crack mob cases that involved the two countries. "This is not a new model, but it's certainly new to cyber," Troy said.
Troy wouldn't comment on what cases the agents were working, but he said, "those countries were selected for a reason."
Currently, there is one embedded agent in each of the three countries, and one remains in Romania, Troy said.
Security experts say the Ukraine is home to a large number of online scammers and the creators of bank-account-emptying malware such as the Zeus Trojan. "Ukraine's a huge problem," said Paul Ferguson, a researcher with Trend Micro. "I would rank it above Russia right now."
Traditionally, securing law enforcement cooperation with Ukrainian police has been a problem, however. "It's encouraging that they have someone embedded there," Ferguson said. "I hope it's more than just a token presence."
Ferguson had no comment on why the FBI might be in Estonia, but his company has linked a widespread rogue-antivirus operation to an unnamed Estonian company that displayed 1.8 million scam "You are infected" messages to Web surfers in July 2009.
The third FBI agent is stationed in The Hague, the Netherlands.
Back in the U.S., agents have also created an in-house botnet expert group of technically savvy agents who can help the FBI's local law enforcement teams investigate botnet-related cases, Troy said. Now more than ever, scammers are using botnet-infected computers to steal banking credentials from victims and move that money offshore.
Recently, the FBI helped shut down a massive botnet, called Mariposa, which had infected millions of computers worldwide.
Troy called botnets "a significant threat."
"There are zillions of botnets out there," he said.
- Security execs express surprise over CISO's firing following RSA talk
- Security industry faces attacks it cannot stop
- Pennsylvania fires CISO over RSA talk
- Google attacks, Web 2.0 fuel FUD at RSA
- Analysis: Does the storm over cloud security mean opportunity?
- Microsoft's tax-for-hacks 'horrible' idea, say security experts
- FBI Director: Hackers have corrupted valuable data
- CISOs rain on cloud-computing parade at RSA
- FBI embeds cyber-investigators in Ukraine, Estonia
- Tweet this: Social network security is risky business



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Virtualizing Government Infrastructure
- All server virtualization solutions are not created equal. The more-with-less agenda for government agencies is tailor-made for server virtualization, which is evolving into...
- Overcome Top 7 Admin Challenges of Active Directory
- As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
- Insiders Can Ruin Your Company. Take Action.
- Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
- Top Solutions and Tools to Prevent Devastating Malware
- Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
- Streamline Compliance and Increase ROI
- Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will... All IT in Government White Papers
- Optimizing Networks for the Cloud
- Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
- Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
- Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
- Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
- Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and...
- Customer Spotlight: How IPC The Hospitalist Company Implemented Oracle on VMware
- Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn...
- Virtualize Business-Critical Applications with Confidence
- Virtualizing business-critical applications has become a key focus for organizations as they move along their virtualization journey. With the launch of VMware vSphere®... All IT in Government Webcasts
