meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, December 14th 2018

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 14 December 2018

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Fake E-Mail Bomb Threats; Phishing Via Non-Delivery Notices;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Friday, December 14th, 2018 edition of the Sansonet Storm Center's Stormcast. My name is Johannes Ulrich.

0:09.2

And today I'm recording from Washington, D.C. Today, numerous organizations reported that they received

0:17.8

email bomb threats that asked for Bitcoin Ransom.

0:22.6

Now, all of these emails appear to come from the same source.

0:26.8

They're very similar in their wording, if not identical.

0:30.6

They all mention a very specific chemical for the bomb,

0:35.5

but that chemical actually changes from email to email, and they all ask for

0:40.3

exactly $20,000 worth of ransom to be paid in Bitcoin. The Bitcoin addresses appear to differ,

0:49.9

however, from email to email. So overall, this looks very much like fake bomb threats and I don't think at least as far as

0:59.7

I can tell from the samples that I have received that anybody has paid the ransom yet.

1:05.1

However, it has caused some disruption based on the fact that organizations typically have fairly strict protocols

1:12.7

in how to deal with bomb threats and to take bomb threats seriously.

1:18.6

Of course, it's difficult to tell why these emails were sent.

1:21.7

The obvious reason would be just to make money with the ransom and it's possible that a couple

1:27.1

of organizations paid the ransom,

1:29.6

but bomb threats are often being executed in order to disrupt the target organizations,

1:36.2

knowing that there's typically some form of evacuation of buildings happening and such,

1:41.6

which, of course, can take a while until the bomb thread itself is resolved.

1:47.2

If you have any samples of these emails, please forward them to us. We received a couple, but

1:52.0

not really a large number. It appears that these emails are at least somewhat targeted, so

1:58.4

not every organization is receiving them, but the only fairly selected

2:03.0

target group of organizations appears to be receiving them. Over the next days, I also expect

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.