A story straight out of a tabloid: an enterprising Australian pensioner spent nearly 7 years laundering money from victims of phone scams—so-called "tech support" fraud that ended with their files being encrypted.

Whether he did it knowingly will soon be decided by a court, and ANZENA, a data protection company, reminds us never to give remote "technicians" access to our devices when we never requested their help.

Like an action movie

On July 7, police in the Australian state of Queensland arrested a 75-year-old man suspected of laundering money extorted through ransomware. This concerns transfers totaling one million Australian dollars (about EUR 230,000), which the Australian made between 2010 and 2017 to the accounts of a foreign company supposedly servicing computers. How did their cooperation come about?

In 2010, a representative of that company contacted the pensioner, looking for a local representative for its business in Australia. The role of such a person was to accept payments from the company's clients locally and forward them to the foreign headquarters. In reality, the company—or whoever was posing as it—did not repair computers at all, although its activity grotesquely brushed against "IT support." Posing as telephone tech support, the scammers convinced victims that their computers contained dangerous errors, and then, under the guise of providing remote assistance, installed their own ransomware on the machines. When planning the scheme, the criminals knew that the "IT technician" scam was an old tactic, so they looked for a foreign "mule" who would divert any potential suspicion from law enforcement. It worked.

When the 75-year-old agreed to cooperate, the ransom note displayed on victims' monitors included the account number of a bank in the Australian town of Mackay. Transferring the funds to the indicated address was supposed to result in the recovery of the encrypted data. Whether it did—is unknown. What is certain, however, is that the money ended up there and then traveled to the extortionists' accounts through three of the pensioner's companies: JC Enterprising, JC Web Creations, and ITZ Services. Assuming his activity lasted from January 2010 until the scheme was stopped, the 75-year-old transferred abroad an average of 30,000 zlotys per month. What percentage of those amounts did he collect for his intermediation?

Fraud on a large scale?

ANZENA notes that although in open cooperation, ransomware creators and distributors may split profits even fifty-fifty, here 10% for the intermediary (unwitting?) would already be a very optimistic variant. Even so, a more realistic 3% profit would still bring in nearly 900 zlotys per month. Although the 75-year-old might have spent it, for example, on needed medicines, it is rather doubtful that during the trial he would find understanding from scam victims who, lacking a data backup, paid the ransom to recover it.

- The places and circumstances of malicious encryption change, but the antidote to ransomware remains the same: regularly creating backups - warns Krystian Smętek, a systems engineer for ShadowProtect SPX solutions - In the case of an encrypting infection, it is enough to restore the last backup file and calmly resume the interrupted work, leaving the extortionists with nothing. Regardless of whether we already have a backup or are only planning to buy one, we should never let ourselves be drawn into phone conversations or email correspondence about technical problems that we ourselves had not previously reported - that is asking for trouble.

Perpetrator or victim?

It is possible that the unlucky Australian was only one of many links forming an international network of scammers (fraudsters exploiting victims' trust). According to data from ESET from October 2016, the number of fake attacks intended to convince users that their computers contained dangerous software increased by 10%. One would like to write that the number of people creating backups increased by the same amount, but in practice people usually start creating one only after losing data. More "IT technician" attacks also mean a greater threat to companies, which can lose much more from malicious encryption than individual users. Just a few days of a disconnected database is enough for clients to drift away to competitors while filing claims against their former provider.

ANZENA notes that there is another disturbing thread in the whole case. It concerns the ease with which older people around the world can be recruited into a criminal network (and probably are). As in Poland, in Australia men finish work at age 65. It is easy to calculate that the protagonist of this text received his "business opportunity" at the age of 68. A coincidence? Older, rather little aware of online threats, and probably not very satisfied with his pension benefit, he perfectly met the criteria for a "mule" sought by scammers. Today, even for averagely savvy cybercriminals, profiling a chosen target poses no problem at all. This may have reassured the extortionists that they had found their man in Australia. The following years of good fortune only confirmed their decision, which must have been shaken only by Friday's arrest. The first hearing of the unlucky 75-year-old will take place on August 3.