US citizens lose millions in complex hacking web: what is spearfishing?


Through a complex web of hacking techniques, a Nigerian man and his gang of criminals successfully hacked US companies, stealing millions.

Kingsley Uchelue Utulu hacked into US-based tax preparation companies in 2019.

These businesses help people and companies to prepare and file their income tax returns.

ADVERTISEMENT

Income tax returns include a significant amount of sensitive information, such as Social Security Numbers, details about income, information about businesses, and personal information such as addresses and other financial data.

protect-information-while-traveling
Niamh Ancell BW jurgita justinasv Marcus Walsh profile
Don't miss our latest stories on Google News

This is extremely valuable information for hackers, who can use it for financial fraud or even identity theft.

The gang managed to access the tax preparation business through spearphishing emails targeting specific victims within an organization.

Spearphishing emails are highly personalized and often impersonate a trusted organization to get the victim to hand over sensitive information about the person or company.

Once they were in the company’s systems, the criminal gang stole tax and other identifying information from the business’s customers.

Cybercriminals invest in businesses
Image by Cybernews.
ADVERTISEMENT

But it didn’t stop there. The criminals hacked into multiple US tax businesses, spanning from New York to Texas, stealing the information of thousands of people.

After they had harvested all this personal information, they filed fake tax returns with the Internal Revenue Service and relevant state tax authorities.

They filed enough fraudulent tax returns and sought roughly $8.4 million, of which they successfully received approximately $2.5 million.

And the criminals didn’t just stop at tax returns. They also used the stolen identities to claim on the Small Business Administration’s Economic Injury Disaster Loan program.

Threat hunting hacker trap
Image by Cybernews.

They gained a further $819,000 in fraudulent payouts, until one of the criminals was arrested while being in the UK and was later extradited to the US.

Utulu has been sentenced to more than five years in prison and forced to pay back millions in restitution.