May 27, 2015 By Shane Schick 2 min read

Social media services are connecting people in ways once unimaginable, but based on the recently released report from the Internet Crime Complaint Center (IC3) and the FBI, they are also attracting a huge amount of malicious activity that cost the U.S. economy $8 billion last year.

The U.S. Computer Emergency Readiness Team (CERT) recommended the findings of the IC3 Internet Crime Report be reviewed to help technology users better protect themselves. While the 22,000 complaints to the IC3 received each month were varied, the study noted that 12 percent were in some way related to the use of social media by cybercriminals. This included clickjacking, or hiding malware within legitimate content online; pharming, or tricking users to visit a phony website that steals their data; and doxing, where an individual’s personal information is released without his or her permission.

If social media-related complaints have quadrupled over the last five years, as the IC3 Internet Crime Report indicates, it may be because they offer more sophisticated ways to play with potential victims’ emotions. NBC News reported the FBI noticed a rise in fraudsters posing as military personnel seeking romance online via sites such as Facebook. Such scams scored cybercriminals more than $14,000 on average, according to the report.

Understandably, average consumers are becoming increasingly worried about what they’re sharing online and with whom they’re interacting. As security firm Sophos noted on its blog, Naked Security, the IC3 Internet Crime Report follows a recent Pew Research Center study that showed the potential fallout as a result of social media activity is a major concern for 69 percent of Americans. The data from the FBI will likely only reinforce some of those fears, but hopefully it will make people more careful about what they post and click on.

Other worrisome trends in the IC3 Internet Crime Report included the growth of email scams and other attacks targeting businesses rather than consumers as a whole. V3 pointed out that the FBI research may fan the flames of a debate between the Obama administration and major tech firms such as Apple, Microsoft and Google, which issued a joint letter urging the government to relax policies that could limit the encryption of corporate data. Whatever the strategy, one thing is clear: The IC3 can’t afford to get much busier.

More from

SoaPy: Stealthy enumeration of Active Directory environments through ADWS

10 min read - Introduction Over time, both targeted and large-scale enumeration of Active Directory (AD) environments have become increasingly detected due to modern defensive solutions. During our internship at X-Force Red this past summer, we noticed FalconForce’s SOAPHound was becoming popular for enumerating Active Directory environments. This tool brought a new perspective to Active Directory enumeration by performing collection via Active Directory Web Services (ADWS) instead of directly through Lightweight Directory Access Protocol (LDAP) as other AD enumeration tools had in the past.…

Smoltalk: RCE in open source agents

26 min read - Big shoutout to Hugging Face and the smolagents team for their cooperation and quick turnaround for a fix! Introduction Recently, I have been working on a side project to automate some pentest reconnaissance with AI agents. Just after I started this project, Hugging Face announced the release of smolagents, a lightweight framework for building AI agents that implements the methodology described in the ReAct paper, emphasizing reasoning through iterative decision-making. Interestingly, smolagents enables agents to reason and act by generating…

4 ways to bring cybersecurity into your community

4 min read - It’s easy to focus on technology when talking about cybersecurity. However, the best prevention measures rely on the education of those who use technology. Organizations training their employees is the first step. But the industry needs to expand the concept of a culture of cybersecurity and take it from where it currently stands as an organizational responsibility to a global perspective.When every person who uses technology — for work, personal use and school — views cybersecurity as their responsibility, it…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today