session 12 · north korean cybercrime, crypto-hacking and money laundering case study and insights...

47
North Korean Cybercrime, Crypto-Hacking and Money Laundering Case Study and Insights from Law Enforcement Friday, 8/7, 10:00 – 11:30 AM ET Session 12

Upload: others

Post on 24-Sep-2020

1 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Session 12 · North Korean Cybercrime, Crypto-Hacking and Money Laundering Case Study and Insights from Law Enforcement Friday, 8/7, 10:00 –11:30 AM ET Session 12

North Korean Cybercrime, Crypto-Hacking and Money Laundering

Case Study and Insights from Law Enforcement

Friday, 8/7, 10:00 – 11:30 AM ET

Session 12

Page 2: Session 12 · North Korean Cybercrime, Crypto-Hacking and Money Laundering Case Study and Insights from Law Enforcement Friday, 8/7, 10:00 –11:30 AM ET Session 12

A Step Ahead of Financial Crime and the Competition

This is the best training out there right now. You guys are making an

effort to keep it that way.

Senior Director Compliance;Financial Services

“”

ACFCS membership equips individuals and organizations with first-class practical tools, information and education that improve results in financial crime detection and prevention.

10% Off With Code Fincrime10

Page 3: Session 12 · North Korean Cybercrime, Crypto-Hacking and Money Laundering Case Study and Insights from Law Enforcement Friday, 8/7, 10:00 –11:30 AM ET Session 12

Join the Next Generation of Financial Crime Fighters with CFCS Certification

10% Off With Code Fincrime10

Page 4: Session 12 · North Korean Cybercrime, Crypto-Hacking and Money Laundering Case Study and Insights from Law Enforcement Friday, 8/7, 10:00 –11:30 AM ET Session 12

4

• Complete fun and exciting missions to earn points

• Multiple winners announced every day…grand prizes on Friday

• Checkout the game tracker to see who’s in the lead and photos of completed missions

• Download GooseChase appGame Code: ACFCS

Scavenger Hunt – Let’s Go on a Goose Chase

Page 5: Session 12 · North Korean Cybercrime, Crypto-Hacking and Money Laundering Case Study and Insights from Law Enforcement Friday, 8/7, 10:00 –11:30 AM ET Session 12

Exhibit Booths – Take a Virtual Walk

5

• Visit the exhibitors and enter the booths by clicking on their name (not logo)

• Gain access to 50+ free downloadable resources

• Learn about their solutions by attending a Product Demo session (on agenda)

Page 6: Session 12 · North Korean Cybercrime, Crypto-Hacking and Money Laundering Case Study and Insights from Law Enforcement Friday, 8/7, 10:00 –11:30 AM ET Session 12

More Resources – Yes, I Want More!

6

• Exclusive takeaway tools including presentations, recordings and more resources

• Go to your profile in Grip and scroll down to the ‘Exclusive Access’ field

• Click YES to gain access to the toolkit and receive sponsor communications

Page 7: Session 12 · North Korean Cybercrime, Crypto-Hacking and Money Laundering Case Study and Insights from Law Enforcement Friday, 8/7, 10:00 –11:30 AM ET Session 12

Go Social – Make Meaningful Connections

Chat privately and schedule video meetings on Grip

View your recommendations

Continue the conversation on social media

#fincrimevirtualweek

Page 8: Session 12 · North Korean Cybercrime, Crypto-Hacking and Money Laundering Case Study and Insights from Law Enforcement Friday, 8/7, 10:00 –11:30 AM ET Session 12

Boring but Important Things – Event Logistics

8

• Daily reminder emails to let you know what’s on tap

• Most sessions being recorded, available until August 14

• Certificates of participation • Attend 80% of the session• Fill out the survey – Triggers at end, available

throughout

Page 9: Session 12 · North Korean Cybercrime, Crypto-Hacking and Money Laundering Case Study and Insights from Law Enforcement Friday, 8/7, 10:00 –11:30 AM ET Session 12

Boring but Important Things – Troubleshooting

9

Audio/visual/other issues: • Try REFRESHING BROWSER as first step• If issues persist, close out and rejoin• Chrome and Firefox recommended

For customer support: • [email protected]• 786-591-1346

Page 10: Session 12 · North Korean Cybercrime, Crypto-Hacking and Money Laundering Case Study and Insights from Law Enforcement Friday, 8/7, 10:00 –11:30 AM ET Session 12

Meet the Experts

10

Zia Faruqui

Assistant U.S. Attorney

U.S. Attorney’s Office for the District of Columbia

Page 11: Session 12 · North Korean Cybercrime, Crypto-Hacking and Money Laundering Case Study and Insights from Law Enforcement Friday, 8/7, 10:00 –11:30 AM ET Session 12

Meet the Experts

11

Chris Janczewski

Special Agent, Cyber Crimes Unit

IRS-CI

Page 12: Session 12 · North Korean Cybercrime, Crypto-Hacking and Money Laundering Case Study and Insights from Law Enforcement Friday, 8/7, 10:00 –11:30 AM ET Session 12

12

Where have Zia and Chris not been to:

A. Seychelles

B. West Bank, Palestinian Territory

C. North Korea

D. Vatican

Poll Question

Page 13: Session 12 · North Korean Cybercrime, Crypto-Hacking and Money Laundering Case Study and Insights from Law Enforcement Friday, 8/7, 10:00 –11:30 AM ET Session 12

13

Page 14: Session 12 · North Korean Cybercrime, Crypto-Hacking and Money Laundering Case Study and Insights from Law Enforcement Friday, 8/7, 10:00 –11:30 AM ET Session 12

Who are we and why are we here?

Zia Faruqui

Assistant United States Attorney

Threat Finance Unit

[email protected]

14

Chris Janczewski

Special Agent

IRS-CI’s Cyber Crimes Unit

[email protected]

Page 15: Session 12 · North Korean Cybercrime, Crypto-Hacking and Money Laundering Case Study and Insights from Law Enforcement Friday, 8/7, 10:00 –11:30 AM ET Session 12

Washington, D.C. USAO

Threat Finance Unit

Notable cases:

North Korean Sanctions

Tanker seizures

Antiquities

15

Page 16: Session 12 · North Korean Cybercrime, Crypto-Hacking and Money Laundering Case Study and Insights from Law Enforcement Friday, 8/7, 10:00 –11:30 AM ET Session 12

IRS – Criminal Investigation

D.C. Cyber Crimes Unit

Notable cases:

Welcome to Video

Dark Scandals

AlphaBay

Helix

Twitter hack

BTC-e

Two federal agents that stole from Silk Road

Buyersclub

Eastern Metals Securities

16

Page 17: Session 12 · North Korean Cybercrime, Crypto-Hacking and Money Laundering Case Study and Insights from Law Enforcement Friday, 8/7, 10:00 –11:30 AM ET Session 12

IRS C

rimin

al In

ve

stiga

tion

Cyb

er C

rime

s

17

Is it a good idea to let your colleagues edit a Power Point Presentation without your review?

A. Yes

B. No

Poll Question

Page 18: Session 12 · North Korean Cybercrime, Crypto-Hacking and Money Laundering Case Study and Insights from Law Enforcement Friday, 8/7, 10:00 –11:30 AM ET Session 12

IRS C

rimin

al In

ve

stiga

tion

Cyb

er C

rime

sIRS – Criminal Investigation

D.C. Cyber Crimes Unit

Notable cases:

Welcome to Video

Chris is FAMOUS.

18

Page 19: Session 12 · North Korean Cybercrime, Crypto-Hacking and Money Laundering Case Study and Insights from Law Enforcement Friday, 8/7, 10:00 –11:30 AM ET Session 12

IRS – Criminal Investigation

D.C. Cyber Crimes Unit

19

Page 20: Session 12 · North Korean Cybercrime, Crypto-Hacking and Money Laundering Case Study and Insights from Law Enforcement Friday, 8/7, 10:00 –11:30 AM ET Session 12

IRS C

rimin

al In

ve

stiga

tion

Cyb

er C

rime

s

20

Do you know what Bitcoin is?

A. Yes

B. No

Poll Question

Page 21: Session 12 · North Korean Cybercrime, Crypto-Hacking and Money Laundering Case Study and Insights from Law Enforcement Friday, 8/7, 10:00 –11:30 AM ET Session 12

IRS C

rimin

al In

ve

stiga

tion

Cyb

er C

rime

s

21

•Bitcoin is, at its essence, a

computer program.

•The program is open-

source, meaning that the

code is available for anyone

to review.

• Any user anywhere in the

world can access the Bitcoin

“protocol.”

Page 22: Session 12 · North Korean Cybercrime, Crypto-Hacking and Money Laundering Case Study and Insights from Law Enforcement Friday, 8/7, 10:00 –11:30 AM ET Session 12

IRS C

rimin

al In

ve

stiga

tion

Cyb

er C

rime

s

Ways to Obtain Bitcoin

22

Sell Goods/Services for Bitcoins

Accept bitcoins as payment for goods or services through

the normal course of business.

2

Business

Mine Bitcoins

As noted earlier, miners are rewarded for solving the

complex equations that verify transactions. When a miner

successfully confirms transactions, he or she is rewarded

with bitcoins.

3Mining

Use Bitcoin Exchanges

Exchanges allow users to convert fiat currencies to

bitcoins. Some examples include: Coinbase, Bitstamp,

and itBit. LocalBitcoins provides users with the ability to

exchange currencies in person.

1

Exchange $

Page 23: Session 12 · North Korean Cybercrime, Crypto-Hacking and Money Laundering Case Study and Insights from Law Enforcement Friday, 8/7, 10:00 –11:30 AM ET Session 12

IRS C

rimin

al In

ve

stiga

tion

Cyb

er C

rime

s

23

Do you now or have you ever owned Bitcoin?

A. Yes

B. No

C. No comment. I don’t want to be the subject of your next PowerPoint.

Poll Question

Page 24: Session 12 · North Korean Cybercrime, Crypto-Hacking and Money Laundering Case Study and Insights from Law Enforcement Friday, 8/7, 10:00 –11:30 AM ET Session 12

IRS C

rimin

al In

ve

stiga

tion

Cyb

er C

rime

s

Bitcoin Blockchain

24

RECIPIENT

(Public Key

ONLY)

SENDER

(Private and

Public Keys)

Page 25: Session 12 · North Korean Cybercrime, Crypto-Hacking and Money Laundering Case Study and Insights from Law Enforcement Friday, 8/7, 10:00 –11:30 AM ET Session 12

IRS C

rimin

al In

ve

stiga

tion

Cyb

er C

rime

s

Ways to Store your Bitcoin

25

Paper Wallets

QR Codes There’s an app for that…

Hardware Wallets

Page 26: Session 12 · North Korean Cybercrime, Crypto-Hacking and Money Laundering Case Study and Insights from Law Enforcement Friday, 8/7, 10:00 –11:30 AM ET Session 12

Transaction Hash

Signatur

e

Wallet

Input Bitcoin address Input Private

Key

Bitcoin Amount

Date/Timestamp

Output Bitcoin address

Page 27: Session 12 · North Korean Cybercrime, Crypto-Hacking and Money Laundering Case Study and Insights from Law Enforcement Friday, 8/7, 10:00 –11:30 AM ET Session 12

IRS C

rimin

al In

ve

stiga

tion

Cyb

er C

rime

s

Peel Chain

27

Page 28: Session 12 · North Korean Cybercrime, Crypto-Hacking and Money Laundering Case Study and Insights from Law Enforcement Friday, 8/7, 10:00 –11:30 AM ET Session 12

28

What is your favorite cryptocurrency:

A. Coinye

B. Potcoin

C. [Venezuelan] Petro

D. Loonie

Poll Question

Page 29: Session 12 · North Korean Cybercrime, Crypto-Hacking and Money Laundering Case Study and Insights from Law Enforcement Friday, 8/7, 10:00 –11:30 AM ET Session 12

IRS C

rimin

al In

ve

stiga

tion

Cyb

er C

rime

s

29

Page 30: Session 12 · North Korean Cybercrime, Crypto-Hacking and Money Laundering Case Study and Insights from Law Enforcement Friday, 8/7, 10:00 –11:30 AM ET Session 12

IRS C

rimin

al In

ve

stiga

tion

Cyb

er C

rime

s

30

If a potential customer with high net worth is concerned about your bank’s security and sends you a questionnaire, how should you respond?

A. Fil l it out truthfully.

B. Fil l it out, but avoid discussing problem areas.

C. Don’t respond and lose the client.

Poll Question

Page 31: Session 12 · North Korean Cybercrime, Crypto-Hacking and Money Laundering Case Study and Insights from Law Enforcement Friday, 8/7, 10:00 –11:30 AM ET Session 12

IRS C

rimin

al In

ve

stiga

tion

Cyb

er C

rime

s

31

Page 32: Session 12 · North Korean Cybercrime, Crypto-Hacking and Money Laundering Case Study and Insights from Law Enforcement Friday, 8/7, 10:00 –11:30 AM ET Session 12

IRS C

rimin

al In

ve

stiga

tion

Cyb

er C

rime

s

32

Page 33: Session 12 · North Korean Cybercrime, Crypto-Hacking and Money Laundering Case Study and Insights from Law Enforcement Friday, 8/7, 10:00 –11:30 AM ET Session 12

IRS C

rimin

al In

ve

stiga

tion

Cyb

er C

rime

s

33

Page 34: Session 12 · North Korean Cybercrime, Crypto-Hacking and Money Laundering Case Study and Insights from Law Enforcement Friday, 8/7, 10:00 –11:30 AM ET Session 12

IRS C

rimin

al In

ve

stiga

tion

Cyb

er C

rime

s

34

Exchanges

Did they collect KYC?

U.S. v. Harmon defined

BTC as money and

applied BSA. 19-cr-395.

Page 35: Session 12 · North Korean Cybercrime, Crypto-Hacking and Money Laundering Case Study and Insights from Law Enforcement Friday, 8/7, 10:00 –11:30 AM ET Session 12

IRS C

rimin

al In

ve

stiga

tion

Cyb

er C

rime

s

35

Page 36: Session 12 · North Korean Cybercrime, Crypto-Hacking and Money Laundering Case Study and Insights from Law Enforcement Friday, 8/7, 10:00 –11:30 AM ET Session 12

36

Page 37: Session 12 · North Korean Cybercrime, Crypto-Hacking and Money Laundering Case Study and Insights from Law Enforcement Friday, 8/7, 10:00 –11:30 AM ET Session 12

IRS C

rimin

al In

ve

stiga

tion

Cyb

er C

rime

s

37

Page 38: Session 12 · North Korean Cybercrime, Crypto-Hacking and Money Laundering Case Study and Insights from Law Enforcement Friday, 8/7, 10:00 –11:30 AM ET Session 12

IRS C

rimin

al In

ve

stiga

tion

Cyb

er C

rime

s

Victim Collection

Low cost

Free email

VOIP for audio

Mass emailer

Translation

Email footer

38

Phishing campaign

Celas LLC

Developer

Prospective Client

Page 39: Session 12 · North Korean Cybercrime, Crypto-Hacking and Money Laundering Case Study and Insights from Law Enforcement Friday, 8/7, 10:00 –11:30 AM ET Session 12

IRS C

rimin

al In

ve

stiga

tion

Cyb

er C

rime

s

39

Page 40: Session 12 · North Korean Cybercrime, Crypto-Hacking and Money Laundering Case Study and Insights from Law Enforcement Friday, 8/7, 10:00 –11:30 AM ET Session 12

IRS C

rimin

al In

ve

stiga

tion

Cyb

er C

rime

s

40

Page 41: Session 12 · North Korean Cybercrime, Crypto-Hacking and Money Laundering Case Study and Insights from Law Enforcement Friday, 8/7, 10:00 –11:30 AM ET Session 12

IRS C

rimin

al In

ve

stiga

tion

Cyb

er C

rime

s Exchange 2

November 2017

17% of total assets

41

Page 42: Session 12 · North Korean Cybercrime, Crypto-Hacking and Money Laundering Case Study and Insights from Law Enforcement Friday, 8/7, 10:00 –11:30 AM ET Session 12

IRS C

rimin

al In

ve

stiga

tion

Cyb

er C

rime

s

Exchange 3

November 27, 2019

342,000 ETH

($48.5 mil)

42

Page 43: Session 12 · North Korean Cybercrime, Crypto-Hacking and Money Laundering Case Study and Insights from Law Enforcement Friday, 8/7, 10:00 –11:30 AM ET Session 12

43

Page 44: Session 12 · North Korean Cybercrime, Crypto-Hacking and Money Laundering Case Study and Insights from Law Enforcement Friday, 8/7, 10:00 –11:30 AM ET Session 12

IRS C

rimin

al In

ve

stiga

tion

Cyb

er C

rime

s

44

DOJ and Treasury Take Concurrent Action

Page 45: Session 12 · North Korean Cybercrime, Crypto-Hacking and Money Laundering Case Study and Insights from Law Enforcement Friday, 8/7, 10:00 –11:30 AM ET Session 12

IRS C

rimin

al In

ve

stiga

tion

Cyb

er C

rime

s

Conclusion and Questions

45

Page 46: Session 12 · North Korean Cybercrime, Crypto-Hacking and Money Laundering Case Study and Insights from Law Enforcement Friday, 8/7, 10:00 –11:30 AM ET Session 12

Questions?

Page 47: Session 12 · North Korean Cybercrime, Crypto-Hacking and Money Laundering Case Study and Insights from Law Enforcement Friday, 8/7, 10:00 –11:30 AM ET Session 12

THANK YOU!

Last session!Open Secrets

12:00 PM ET