To the casual observer, there was little to distinguish the Java Bean Internet cafe in Wembley, north London, from the hundreds of others dotted around the British capital. But to surveillance officers staking it out month after month, this unremarkable venue was the key to busting a remarkable and sophisticated network of cyber criminals.
From the bank of computers inside, a former pizza bar worker ran an international cyber “supermarket” selling stolen credit card and account details costing the banking industry tens of millions of pounds.
Renukanth Subramaniam, 33, was revealed on Jan. 14 as the founder and a major “orchestrator” of the secret DarkMarket Web site, where elite fraudsters bought and sold personal data, after it was infiltrated by the FBI and the US Secret Service.
Membership was strictly by invitation. But once vetted, its 2,000 vendors and buyers traded everything from card details, obtained through hacking, phishing and ATM skimming devices, to viruses with which buyers could extort money by threatening company Web sites.
The top English language cybercrime site in the world, it offered online tutorials in account takeovers, credit card deception and money laundering. Equipment — including false ATM and pin machines and everything needed to set up a credit card factory — was available.
It even featured breaking-news-style updates on the latest compromised material available, while criminals could buy banner adverts to promote their wares.
So vast was its reach, with members in the UK, Canada, US, Russia, Turkey, Germany and France, the UK’s Serious Organised Crime Agency (SOCA), which helped bust it, said it was “impossible” to put a figure on how much it cost banks worldwide.
Subramaniam, who used the online nickname JiLsi, was remanded in custody at his own request at Blackfriars crown court in London yesterday after pleading guilty to conspiracy to defraud and five counts of furnishing false information. Judge John Hillen said it was “inevitable” he faced a “substantial custodial sentence.”
A British citizen, Subramaniam was a former member of ShadowCrew, DarkMarket’s forerunner, which was uncovered by the US Secret Service in 2004.
“JiLsi was one of the highest in cybercrime in this country with what he managed to achieve setting up a forum globally. No JiLsi, no DarkMarket,” one Soca investigator said.
Its 2,000 members never met in real life. Quality, not quantity, was the key. DarkMarket was fastidious in banning “rippers” who would cheat other criminals. Honor among thieves was paramount.
It operated an “escrow” service, with payments and goods exchanged through a third party — “like a PayPal for criminals,” the judge said, and an arbitration service resolved disputes. To keep off the radar, the rules were strict: no firearms, drugs or counterfeit currency.
Built on a pyramid structure, administrators decided who joined, moderators ran specific site sections and reviewers vetted wannabes — each demanding 5 percent, or £250 (US$405) per transaction, as a fixer’s fee.
To get on, criminals had to present details of 100 compromised cards free of charge — 50 to one reviewer, 50 to another. Reviewers would test the cards and write an online review of customer satisfaction — just like eBay customers.
“If the cards did what they were supposed to, and if they got the money, they would be recommended. If not they weren’t allowed in,” the investigator said.
Payment was via accounts on WebMoney, or E-Gold.
“It was the QuickTime method of paying, sending money anywhere in the world,” the investigator said.
Subramaniam was one of the top administrators. He kept his operating system on memory sticks. But when one was stolen, costing him £100,000 in losses and compromising the site’s security, he was downgraded to reviewer. Surveillance officers caught him logging on to the Web site as JiLsi unaware the fellow criminal MasterSplyntr he was talking to was, in fact, an FBI agent called Keith Mularski.
Considerable money was exchanged, though transactions took place away from the site for security reasons. One buyer spent £250,000 on stolen personal information in just six weeks.
Described as “a very quiet man,” Subramaniam worked in low profile jobs at Pizza Hut and as a dispatch courier.
“He owned three houses but was largely itinerant ... never staying in one place for long,” said Sharon Lemon, Soca deputy director.
He is charged alongside John McHugh, 66, or “Devilman,” also a reviewer who has pleaded guilty to conspiracy to defraud and at whose Doncaster home a credit card-making factory was found. The two will be sentenced later. But for investigators, the battle against cyber fraud continues.
“This was one of the top 10 sites in the world, but there are more than 100 we know of globally, and another 100 we don’t yet know of,” the investigator said.
A cyber crime price list
Trusted vendors on DarkMarket offered a smorgasbord of personal data, viruses and card-cloning kits at knockdown prices. Going rates were:
— Dumps Data from magnetic stripes on batches of 10 cards. Standard cards: US$50; Gold/platinum: US$80; Corporate: US$180.
— Card verification values. Information needed for online transactions. US$3 to US$10 depending on quality.
— Full information/change of billing Information needed for opening or taking over account details. US$150 for account with US$10,000 balance. US$300 for one with US$20,000 balance.
— Skimmer Device to read card data. Up to US$7,000.
— Bank logins. Two percent of available balance.
— Hire of botnet Software robots used in spam attacks. US$50 a day.
— Credit card images. Both sides of card. US$30 each.
— Embossed card blanks US$50 each.
China has not been a top-tier issue for much of the second Trump administration. Instead, Trump has focused considerable energy on Ukraine, Israel, Iran, and defending America’s borders. At home, Trump has been busy passing an overhaul to America’s tax system, deporting unlawful immigrants, and targeting his political enemies. More recently, he has been consumed by the fallout of a political scandal involving his past relationship with a disgraced sex offender. When the administration has focused on China, there has not been a consistent throughline in its approach or its public statements. This lack of overarching narrative likely reflects a combination
Behind the gloating, the Chinese Nationalist Party (KMT) must be letting out a big sigh of relief. Its powerful party machine saved the day, but it took that much effort just to survive a challenge mounted by a humble group of active citizens, and in areas where the KMT is historically strong. On the other hand, the Democratic Progressive Party (DPP) must now realize how toxic a brand it has become to many voters. The campaigners’ amateurism is what made them feel valid and authentic, but when the DPP belatedly inserted itself into the campaign, it did more harm than good. The
US President Donald Trump’s alleged request that Taiwanese President William Lai (賴清德) not stop in New York while traveling to three of Taiwan’s diplomatic allies, after his administration also rescheduled a visit to Washington by the minister of national defense, sets an unwise precedent and risks locking the US into a trajectory of either direct conflict with the People’s Republic of China (PRC) or capitulation to it over Taiwan. Taiwanese authorities have said that no plans to request a stopover in the US had been submitted to Washington, but Trump shared a direct call with Chinese President Xi Jinping (習近平)
Workers’ rights groups on July 17 called on the Ministry of Labor to protect migrant fishers, days after CNN reported what it described as a “pattern of abuse” in Taiwan’s distant-water fishing industry. The report detailed the harrowing account of Indonesian migrant fisher Silwanus Tangkotta, who crushed his fingers in a metal door last year while aboard a Taiwanese fishing vessel. The captain reportedly refused to return to port for medical treatment, as they “hadn’t caught enough fish to justify the trip.” Tangkotta lost two fingers, and was fired and denied compensation upon returning to land. Another former migrant fisher, Adrian Dogdodo