2020-07-30
Added · Updated
The Financial Crimes Enforcement Network (FinCEN) issued this advisory to alert financial institutions to cybercrime and cyber-enabled crime schemes exploiting the COVID-19 pandemic. The document details red flag indicators for malicious activities including remote identity manipulation, phishing, malware, extortion, and business email compromise targeting healthcare and municipal sectors. FinCEN requires institutions to reference specific key terms and select designated fields when filing Suspicious Activity Reports to facilitate the detection and reporting of these illicit transactions.
FINCEN published 5 documents in the last 30 days — get each new one by email the day it lands.
FIN-2020-A005 July 30, 2020
Advisory on Cybercrime and Cyber-Enabled Crime Exploiting the Coronavirus Disease 2019 (COVID-19) Pandemic Detecting, preventing, and reporting illicit transactions and cyber activity will help protect legitimate relief efforts for the COVID-19 pandemic and help protect financial institutions and their customers against malicious cybercriminals and nation-state actors. This Advisory should be shared with:
Financial Red Flag Indicators of Cybercrime and Cyber-Enabled Crime Exploiting COVID-19 This advisory addresses the primary means by which cybercriminals and malicious state actors are increasingly exploiting the COVID-19 pandemic in cyber-enabled crime through malware and phishing schemes, extortion, business email compromise (BEC) fraud, and exploitation of remote applications, especially against financial and healthcare systems.1
applications and virtual environments to steal sensitive information, compromise financial activity, and disrupt business operations.3
3. For information related to publicly disclosed cybersecurity vulnerabilities and exposures, see U.S. Department of
Commerce, National Institute for Standards and Technology (NIST), “National Vulnerability Database;” MITRE, “Common Vulnerabilities and Exposures: CVE List Home;” and FBI IC3 Public Service Announcements, “Cyber Actors Take Advantage of COVID-19 Pandemic to Exploit Increased Use of Virtual Environments,” (April 1, 2020) and “Increased Use of Mobile Banking Apps Could Lead to Exploitation,” (June 10, 2020). See also FinCEN Director Kenneth A. Blanco’s, prepared remarks delivered at the Consensus Blockchain Conference, “Consensus Blockchain Conference (Virtual),” (May 13, 2020). Remote identity processes4
4. For the purposes of this advisory, “remote identity processes” include remote processes for customer onboarding and
identity verification, as well as authentication of customers for account access purposes. For more information on digital identity standards, see NIST, “Digital Identity Guidelines,” (December 1, 2017), and the Financial Action Task Force (FATF), “Guidance on Digital Identity,” (March 6, 2020). also face significant risks, which may include:
Phishing, Malware, and Extortion
FinCEN and U.S. law enforcement have observed significant increases in broad-based and targeted phishing campaigns that are attempting to lure companies, especially healthcare and pharmaceutical providers, with offers of COVID-19 information and supplies.8
8. The U.S. Secret Service (USSS) and DHS CISA have noted an increase in malware, phishing, and extortion campaigns
related to COVID-19. See USSS Press Release, “Secret Service Issues COVID-19 (Coronavirus) Phishing Alert,” (March 9, 2020). Phishing scams target individuals with communications appearing to come from legitimate sources to collect victims’ personal and financial data and potentially infect their devices by convincing the target to download malicious programs.9
9. See DHS CISA and U.K. NCSC Joint Alert (AA20-099A), “COVID-19 Exploited by Malicious Cyber Actors,” (April 8,
2020); and DHS, “Common Scams: Know How to Spot a Fake.”
Cybercriminals usually send these phishing communications by email but may also use phone calls or text messages. In these new schemes, phishing scammers will often reference COVID-19 themes, such as payments related to the Coronavirus Aid, Relief, and Economic Security (CARES) Act,10
10. Pub. L. 116–136, 116th Congress (2020).
in the subjects and bodies of emails. Some phishing emails lure victims by advertising ways to make money, such as through investing in convertible virtual currencies (CVCs) or via domain names that mimic names of organizations, including those that provide or enable teleworking capabilities.11
11. Since January 2020, tens of thousands of new domains have been registered with terms related to COVID-19 and/or
disaster and healthcare response efforts (e.g., “quarantine,” “vaccine,” and “CDC”), many including or mimicking names of companies that provide or enable teleworking capabilities. U.S. law enforcement agencies have disrupted hundreds of malicious domains used to exploit the pandemic. See FinCEN Advisory, FIN-2020-A003, “Advisory on Imposter Scams and Money Mule Schemes Related to Coronavirus Disease 2019 (COVID-19),” (July 7, 2020). See also, FBI Press Release, “FBI Expects a Rise in Scams Involving Cryptocurrency Related to the COVID-19 Pandemic,” (April 13, 2020). Cybercriminals
are also distributing malware,12
12. Malware can enable criminals to access compromised computers and computer systems to steal credentials, exfiltrate
sensitive information through mechanisms like screenshots or keylogging, alter account information, and conduct fraudulent transactions. including ransomware, through phishing emails, malicious websites and downloads, domain name system (DNS) hijacking or spoofing attacks, and fraudulent mobile applications. These techniques can be applied in broader campaigns involving social media, such as the recent exploit targeting Twitter and prominent users of the platform.13
13. See FinCEN Alert, FIN-2020-Alert001, “FinCEN Alerts Financial Institutions to Convertible Virtual Currency Scam
Involving Twitter,” (July 16, 2020).
Financial institutions dealing in CVC should be especially alert to the potential use of their institutions to launder proceeds affiliated with cybercrime, illicit darknet marketplace activity, and other CVCrelated schemes and take appropriate risk mitigating steps consistent with their BSA obligations. FinCEN assesses that instances of extortion will also continue to grow in the wake of the COVID-19 pandemic. So far in 2020, FinCEN has received numerous suspicious activity reports (SARs) involving ransomware14
14. Ransomware, a specific type of malware, typically encrypts data on systems in the interest of extorting ransom
payment from victims in exchange for decrypting the information and giving victims access to their systems again. targeting medical centers and municipalities. Much of this ransomware was delivered by exploiting the COVID-19 lures described above. We expect criminals to continue targeting entities that are vulnerable due to their involvement in pandemic response, such as researchers working on medical treatments or manufacturers of personal protective equipment. In other instances of extortion, criminals are threatening to expose victims and their families to COVID-19 if they do not pay the extortion fee. In almost all cases, criminals require ransomwarerelated extortion payments to be made in CVC.15
15. Financial institutions dealing in CVC should be especially alert to the laundering of proceeds affiliated with
cybercrime, illicit darknet marketplace activity, and other CVC-related schemes. See FinCEN Advisory, FIN-2019-003, “Advisory on Illicit Activity Involving Convertible Virtual Currency,” (May 9, 2019). Financial red flag indicators of this sort of activity may include the following:
Information technology enterprise activity related to transaction processes or information is connected to cyber indicators that have been associated with possible illicit activity. Malicious cyber activity may be evident in system log files, network traffic, or file information.
16. Because cyber indicators are helpful red flag indicators that financial institutions can use to identify related suspicious
financial activity, FinCEN, DHS CISA, and the U.S. Department of the Treasury’s Office of Cybersecurity and Critical Infrastructure Protection (OCCIP) offer a broad range of helpful cyber indicator resources, including, but not limited to: FinCEN’s Cyber Indicator Lists (CILs), shared through the FinCEN Secure Information Sharing System; OCCIP’s CILs and circulars, available upon request; and DHS CISA’s cyber analytic products and services, including a comprehensive list of COVID-19-related indicators of compromise in CSV or STIX-formatted XML formats, the Cyber Information Sharing and Collaboration Program (CISCP), and the Automated Indicator Sharing (AIS) program. Public-private and industry partnerships, such as the Financial Services Information Sharing and Analysis Center, and open source and commercial cyber threat feeds can also be useful resources.
Business Email Compromise (BEC) Schemes
Cybercriminals have increasingly exploited the COVID-19 pandemic by using BEC schemes, particularly targeting municipalities and the healthcare industry supply chain. A common BEC scheme involves criminals convincing companies to redirect payments to new accounts, while claiming the modification is due to pandemic-related changes in business operations. BEC criminals often use spoofed or compromised email accounts to communicate these urgent, last-minute payment changes. In the COVID-19 environment, criminals insert themselves into communications by impersonating a critical player in a business relationship or transaction, typically posing as providers of healthcare supplies, to intercept or fraudulently induce a payment for critically needed supplies.17
17. See FBI Press Release, “FBI Anticipates Rise in Business Email Compromise Schemes Related to the COVID-19
Pandemic,” (April 6, 2020). See also Europol Press Release, “Corona Crimes: Suspect Behind €6 Million Face Masks and Hand Sanitisers Scam Arrested Thanks to International Police Cooperation,” (April 6, 2020). Financial red flag indicators of this sort of activity may include the following:18
18. For general BEC-scheme financial red flag indicators, see FinCEN Advisories, FIN-2016-A003, “Advisory to Financial
Institutions on E-mail Compromise Fraud Schemes,” (September 6, 2016), and FIN-2019-A005, “Updated Advisory on Email Compromise Fraud Schemes Targeting Vulnerable Business Processes,” (July 16, 2019).
Information on Reporting Suspicious Activity
Suspicious Activity Report (SAR) Filing Instructions SAR reporting, in conjunction with effective implementation of due diligence requirements by financial institutions, is crucial to identifying and stopping financial crimes, including those related to the COVID-19 pandemic. Financial institutions should provide all pertinent available information in the SAR and narrative. Adherence to the filing instructions below will improve FinCEN and law enforcement’s ability to effectively identify and pull actionable SARs and information from the FinCEN Query system to support COVID-19-related cases.
“other” box the COVID-19-related cyber event), and SAR fields 44(a)-(j), (z), including email or CVC wallet addresses, malicious domains or URLs, and any other known cyber event indicators.
Read the rest free
Source: Financial Crimes Enforcement Network — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works