Back
Craig Gibson
EVice President of Global Sales & Account Management, CONCENTRIX CORP

The secret world of cybercrime | Craig Gibson | TEDxMississauga

🎥 Feb 08, 2019 📺 TEDx Talks ⏱ 17m 👁 39281 views
Craig Gibson uncovers the secret world of cybercrime, and what we're going to fight it. This talk was given at a TEDx event using ...
Watch on YouTube

About Craig Gibson

In a 2019 TEDxMississauga talk, Craig Gibson described the structure of international telecom and cybercrime operations, stating that they are "international sophisticated groups sometimes hundreds of people who have multiple tiers of org chart." He said that cybercrime "makes more money than drug trade today in the world" and that individuals who would have invested in drug trafficking now invest in cybercrime. Gibson discussed a case in Spain where 20 luxury homes were used as criminal call centers, with workers who were "very low paid very low rights sort of positions." He claimed that victims who lose all their money and are elderly "tend to kill themselves." Gibson argued that 5G technology, managed by artificial intelligence and a "security Orchestrator," could prevent such frauds, stating "when these frauds are performed and you know all these people died it was totally preventable if we had 5G." He also encouraged the public to report phishing attempts to the government, saying that doing so helps authorities "know how to allocate funding how to provide support for law enforcement." Gibson described cybercrime as "a really misunderstood or a very secret class of crime" that is often downplayed or not tracked by large companies.

Source: AI-verified profile updated from Craig Gibson's recent appearances. Browse all interviews →

Transcript (1 segments)
C
Craig Gibson0:09
I'd like to invite you to imagine a world in which you are not interrupted during supper by telemarketers. I don't have to cross my fingers. Just for a little bit of audience participation, you might have to hold up your hand for as much as 30 seconds. How many of you received an email from a Nigerian prince? How many of you received a voicemail saying that you have won a cruise? You're left out, you're the only one though. And I received, just the day before yesterday I think it was, how many have received a human calling you and offering you free duct cleaning? Everybody that groaned would have put up their hand. So you were, especially in the case of the third one, contacted by international telecom criminals. So often these are referred to as scams, but in my mind that makes you think about an individual working in their basement stealing a hundred dollars here and there, a clever hoodie-wearing hacker. But these are international sophisticated groups, sometimes hundreds of people who have multiple tiers of org chart, some of whom are working in almost a call center level, which we'll see some pictures of, who are also working at higher levels of cartel-like infrastructure. When they actually begin these attacks, they don't stop until they get everything you have. So the more vulnerable you are, the more you go for this kind of trick, the more likely it is that they will actually get all of your home equity, all of the balance of your credit card, all of the money in your bank accounts, and then add you to a database that they then sell to other criminals so they can hit you with the next attack. So why does this keep happening? Well, I have a switchboard here for no special reason except to say that there's IT security architecture and telecom security architecture. Large customers pay a lot for IT security architecture but almost never ask for telecom security architecture. So IT security architecture is very advanced, intelligence agency level. Telecom security architecture is somewhere around here. So generally with telecom crime, it follows, as far as I understand, there's 400 different kinds plus or minus of telecom crime. So what we talked about earlier, especially the duct cleaning, is called phishing, and if it's voice phishing in the case of duct cleaning, it would be called vishing or voice phishing. And there's smishing and all kinds of other things too. So how it starts: a hacker will do one of these techniques, they'll make a virus or a worm, or call you, or use a fake cell tower to actually intercept your radio from you coming from your devices. And if you're renting things like Internet of Things, so cellular-empowered drones or self-driving vehicles or smart televisions or smart fridges or any of these things that might be considered IoT, all of these attacks are even better on those because they don't complain. The attack will hit them, it'll hit them again, it'll go on until somebody gets a bill for 2 million dollars. And 2 million is just an example of somebody that broke into a conference bridge some time ago, the corporate conference bridge. So the hacker gets into the victim, the victim for instance a company with a conference bridge or somebody with a phone line, paying the telco for the fact that they generated a huge amount of traffic which then gets sub-paid into the hacker. Perhaps the telco doesn't know that they're colluding with criminals, maybe the telco is in another country where this is actually part of their telephone business model working with customs. The organized crime is serious. Cybercrime, specifically the IT cybercrime, makes more money than drug trade today in the world. So the individuals that would have invested in drug trade crime now invest in cybercrime. Cybercrime has lots of vendors working in this space, so now they're starting to move into telecom cybercrime or cybercrime. You probably can't read the small white writing on this gun, but it's a Desert Eagle. And because of the stealthiness of these attacks, you would never ever fire this gun unless there was actually police already trying to arrest you. The point that it's a Desert Eagle is it's a 50 caliber handgun capable of piercing police body armor, so they're assuming that they'll be dealing with SWAT. You may not have seen this logo before, but the thing that may give it away is the Great Wall of China down here at the bottom. Without getting into any kind of political issues, the Chinese government for the purpose of today's presentation gave permission for this logo to be in this presentation. And one of the reasons that you might consider telecom crime to be important is they consider this a very, very, very severe issue. Rather than give you some of this fluffy stuff that I've just mentioned, I'll go into a concrete description of one of the largest cyber stings that has ever happened to date recently. Thousands or tens of thousands of calls terminated in China. Not everybody reported them, so it took a little while for the Chinese National Police to know that there was actually an attack. Many, many people, thousands in this case, lost all of their money. And in some cases, in the case of older people hit by this kind of crime who lose all of their money in countries that don't have the social safety net of Canada, when they have no money and they're very old, their face was living on the street. Well, if their face was living on the street, they tend to kill themselves. So the Chinese National Police worked with Chinese telecom and Chinese phone companies and identified these calls were originating from Spain. But national police agencies can't work with the police agencies of other countries unless their legal systems are very similar, so they have to walk through United Nations entities like Interpol or Europol, which is a group that I'm an adviser of through my role. Once they created the formal relationship with National Police of Spain, the Spanish police identified that in fact the calls were originating from Spanish phone companies and actually were not being bounced through multiple countries. So that led us to believe that the actual crimes were actually originating from Spain. So in working with the phone companies in Spain, it was identified that there were 20 luxury homes. This is a Spanish luxury home, a villa, and they fit a particular profile. So not only is the house physically big, it's on a large lot, meaning that there's a physical distance between the building and the hedge or fence. The fences and hedges are very tall. So what that means is that in these 20 villas in three cities within Spain, there were 10 to 20 criminals per house working as members of a criminal call center. It was distributed through the 20 locations. Those individuals, those 10 to 20 people per house, never left. They went in at night for instance and never stepped near a window, never went outside. And there was one person only that brought food in and out of this house. So that model, if you think about it, works in Europe, obviously would probably work in Canada, and would certainly work in any other wealthy neighborhood because wealthy neighborhoods by nature have low police presence. So what does this tell you? What does this picture tell you? It tells you at least some of the criminals were tricked into taking this job. They're eating off the floor, they're sleeping on the floor. They're not glamorous, they're not driving Lamborghinis. Out of the many people working in those 20 locations, almost all of them were call center staff, what we would consider very low paid, very low rights sort of positions. If you've been called by duct cleaning, you may have heard somebody in the background speaking behind the person that was speaking to you. That person that was speaking to you and the person sitting beside them were likely sitting in a call center like this. So these are folding chairs, folding tables, cardboard boxes with soundproofing foam on them, and cell phones. And the cell phones were used to hide the fact that they were all physically sitting in one house. Like any call center, they had targets. Hourly, each morning, each day, they were expected to achieve a certain number of dollars in fraud or dollars in lives destroyed. Who is it that does these crimes? Well, as you can imagine, there's certainly higher, more well-paid criminals. Most of the people involved tend to be people that can't get normal jobs, maybe they have a criminal record that prevents them from getting a normal job. They tend to be almost refugee-like. And certainly in the case of the individuals in all these call centers, once they got on the plane from their home country, the criminal agency that they worked for had no cause to pay them and give them a flight back, and would punish them if they spoke to the neighbor or anything similar of that kind. So there is a solution for all of this, luckily. So when we talked about Internet of Things and calls that impact people, there are actually inefficiencies in 4G, landline networks, long distance, and so on. And those inefficiencies actually limit how much fraud can be done, and so they have to rely on things like these physical houses to sit in. Those inefficiencies were one of the ways by which they were traced. So in this particular operation, this international cyber sting, filled the wall ultimately through the three cities, the 20 locations, the three law enforcement agencies. There were 50 Chinese National Police involved, 200 Spanish National Police involved, and 300 Interpol officers involved that hit all 20 locations, arresting 300 people. Those 300 people all spoke Chinese, and this is one of the reasons that the Chinese National Police were involved, to function as translators. And they were all then deported. So there's inefficiencies in 4G that don't exist in 5G. 5G at its highest level is managed by a kind of artificial intelligence called 5G ML or 5G machine learning. And because it's an AI-based system and it has a kind of bodyguard called a security orchestrator, that security orchestrator, which is very, very rules-based, is supremely good at not only enforcing security rules like anti-fraud rules, but also preventing new frauds from occurring as long as it identifies what that common chain of value is. So if it says, for instance, one kind of fraud is it originates from one central point and hits many, many targets, that's a one-to-many relationship. Anytime at a telecom level you see a one-to-many relationship, it's quite likely non-human, let's say. So it's likely an automated system. Human traffic is very, very many-to-many, so it's families talking to each other and trading a variety of different kinds of traffic. A fraud system will be one kind of traffic and will probably be of one kind of cruiser or something similar. So at a telecom level, that's very easily traceable. That's one of the 400 different kinds of fraud that get executed in telecom. But all of the 400 different kinds of fraud were actually invented thousands of years ago. They were actually invented for the most part in places like Mesopotamia, where they were used by individuals to steal grain silos out of other people's grain. So when you execute those artificial intelligence security rules in a 5G machine learning environment, the forward-looking threat research group has identified that you can bring this fraud not only down, but you can bring it to zero. You can bring it to zero. So when these frauds are performed and you know all these people died, it was totally preventable if we had 5G. So I have two calls to action. The one call to action is for everybody in the room that didn't report this crime. So when you received all these different kinds of phishing, when you report them, it goes to the government. The government knows how to allocate funding, how to provide support for law enforcement. And in that way, everybody knows exactly how severe this is. When I was an architect in telco, I had one specific phishing event which was "You have won a cruise" years ago, which is still going on today, that was generating 57 million calls a month under one telco. That being the case, I told the federal government over beer one day, and they were very surprised because they only had 3,000 reports. So luckily, here in Canada, you can report this to the Canadian Anti-Spam Center, and they will know exactly how much you care about this topic. The other call to action is for law enforcement. So national law enforcement either here in Canada or on YouTube, if YouTube is watching, national law enforcement of any country can approach the Europol EC3, European Cybercrime Center, and through it approach the Cyber Working Group, which I'm the adviser of for all the law enforcement and all the telcos in Europe. That being the case, any law enforcement agency, and you know the Chinese National Police are looking to join this group even though it's Europol, any national agency can attempt to join this group. And if they do join the group and pass the vetting process, we can then share criminology on all these 400 different types of crime. We can talk about which groups are actually committing the crime, which phone numbers are generating the crime, which kinds of machines generate the crime, and therefore what you can look for at a very low technical signaling kind of level. And we can share all of this detailed kind of information with law enforcement agencies in such a way that we can accelerate the kind of collaboration I described during this sustained one. One thing I will say is that this is a really misunderstood or a very secret class of crime. It's often misunderstood, it's often downplayed, it's often considered to be a non-issue. Many systems in large-scale companies don't even track it. So the criminals are just walking away with your money and nobody's even complaining. But I hope what I've done through this talk today is done a little bit to demystify this topic. And my hope is that you will share this talk with people you're sitting at having lunch with for Christmas and anybody that might be in law enforcement, telecom, or receive this kind of crime so they know what it is. So thank you.