How to react when you have been hit by a cyber attack.
Fear, uncertainty and doubt – or any combination of those feelings – usually let cybercriminals off the hook.
A January report from the U.S. Joint Council on Information Age Crime shows that 36% or less of organizations polled report computer-related crimes to law enforcement. Yet law enforcement officials and IT security experts agree that taking the proper steps after malicious activity will help secure breached networks, prevent future attacks – and even identify and punish criminals.
Sidebar: Advanced technologies aim to protect network assets
Main index: Profiling cybercrime: Network threats and defense strategies
So, what should you do if you are the victim of cybercrime? Here are 10 key reactions.
Report
Experts urge IT managers to resist going into hiding and advise them to report the cybercrime incident to all or one of the following groups, depending on the circumstances of the crime.
1. Contact law enforcement agencies: The FBI, the U.S. Secret Service and the Federal Trade Commission (FTC) each track, investigate and prosecute cybercrime, depending on the act. For example, the FBI and Secret Service investigate cases dealing with hacking, intellectual property theft, piracy and password trafficking, and the FTC deals with cases of Internet fraud and spam.
“Victims must report the crime as soon as they learn about it. The earlier they report it, the more likely we can solve it,” says Gail Marcinkiewicz, a spokeswoman for the FBI’s Boston field office.
2. Reach out to industry organizations: Groups such as Carnegie Mellon University Software Engineering Institute’s CERT Coordination Center, the Internet Fraud Complaint Center and the Anti-Phishing Working Group would like to be informed of cybercrimes and malicious computing activity such as viruses, worms and distributed denial-of-service (DoS) attacks.
“There are advantages when people are willing to even just report the activity, without seeking prosecution or publicity,” says Marty Lindner, a senior member of the technical staff at U.S. CERT. “The experience can be pushed out to others so they know what to look for.”
3. Inform other potential victims: Even if a company or an individual wants to keep quiet about an attack, it is wise – and in some cases required by law – to alert others at risk.
For example, the University of California at Berkeley recently revealed that a hacker attack might have exposed the personal data of more than a million state residents. Under the state’s SB1386 anti-identity theft law, passed in 2003, state agencies and businesses maintaining computerized data are required to report any breach of security that could have compromised personal data such as Social Security or license numbers or name and addresses coupled with credit card information.
“It is a corporate responsibility to report corporate-level fraud,” says Erik Laykin, director of IT investigations practice for Navigant Consulting.
Investigate
Proper steps need to be taken to understand what happened and how to prevent it from happening again.
4. Don’t shut off the computer/network/ infected area: Shutting down the system could wipe out data needed to determine the source of the attack. Also, depending on the afflicted area, whether it is a server, firewall or router, powering down could cause further problems and IT service disruptions for the company.
“Disconnecting the computer from the network could wipe out evidence,” CERT’s Lindner says.
5. Don’t tamper with potential evidence: Internal IT staff should not attempt to access, say, the firewall suspected as the weak link in an attack or the hard drive of a disgruntled employee. FBI and other law enforcement officials know the processes to take when collecting digital data, and third-party security forensics firms are also familiar with the chain of evidence and how evidence must be maintained for use in a court of law.
“Evidence is one of the biggest challenges in prosecuting cybercrimes,” says Laykin, whose firm helps companies investigate malicious activity. “Computers give up their secrets in a predictable manner, but if the wrong people access them during an investigation, the evidence could be considered tainted.”
6. Don’t forget to document the process of collecting evidence: Digital evidence remains a gray area in many courts, and companies must collect the information in a manner that will be admissible in court.
“Don’t rely on the data itself. Create records of the process and log who did what to prove in court that the proper steps were taken to secure the evidence,” says Steven Branigan, president of CyanLine and cybercrime author. “If it goes to court and the other side challenges your statements, having something written down goes a long way.”
Prosecute/remediate
The investigation is complete, the evidence is collected, and now the victimized company must decide on a course of action. Law enforcement officials recommend prosecution.
7. Prove motive: Cybercrime experts say in many cases the malicious activity is difficult to prosecute because the motive is unclear. It could be considered mischievous to hack into a network but not necessarily a crime.
If the motive is clear, such as monetary gain or revenge, experts say it is easier to prove the attack had malicious intent.
“You need to prove that a person knew they weren’t supposed to be doing something they did and that their actions caused damage, not just disruption of business as usual,” says Edward Stroz, former FBI agent and president of computer forensics consulting firm Stroz Friedberg.
8. Take cautious internal action: Intent also comes into play when looking to remove a suspected attacker from the company’s payroll. In many cases, companies will want to immediately remove the alleged attacker, but a rash firing could lead to a lawsuit against the company.
“If there aren’t clear policies, it will be hard to justify firing an individual that happened to access an area reportedly restricted,” Stroz says. “The person can always claim he didn’t know it was restricted.”
9. Rebuild security infrastructure: Because most responses to attacks are reactionary, many companies consider putting tools in place to help them either better handle attacks or prevent them altogether (see related story).
For Corey Mandell and the IT team at Authorize. net, a provider of payment-processing services for e-commerce companies, the last distributed DoS attack the company suffered in September forced them to re-evaluate their security infrastructure.
10. Establish security policies and practices: Industry organizations recommend meeting with local law enforcement agencies, insurance companies, lawyers and computer science forensic experts to define network use and access policies, and the processes needed to prosecute when those policies are violated.
Internal policies such as authorized access lists for specific servers or applications with customer data will make it easier to prove actions taken were known violations.
Who ya gonna call? When cybercrime strikes, there is a myriad of agencies and contacts there to help. Local agencies, which can be gleaned from these central locations, are your first line of contact. | |
United States Secret Service (cyberincident reports) | U.S. CERT online reporting for technicians The Internet Fraud Complaint Center National Association of Attorney General’s Computer Crime Point of Contact List (all state-related cyber questions) |
| There is a more complete list of all crimes (including international trafficking and so on) and where to report at: www.cybercrime.gov/reporting.htm. | |




