NZ Herald
  • Home
  • Latest news
  • Video
  • New Zealand
  • Sport
  • World
  • Business
  • Entertainment
  • Podcasts
  • Quizzes
  • Opinion
  • Lifestyle
  • Travel
  • Viva
  • Weather forecasts

Subscriptions

  • Herald Premium
  • Viva Premium
  • The Listener
  • BusinessDesk

Sections

  • Latest news
  • New Zealand
    • All New Zealand
    • Crime
    • Politics
    • Education
    • Open Justice
    • Scam Update
    • The Great NZ Road Trip
  • On The Up
  • World
    • All World
    • Australia
    • Asia
    • UK
    • United States
    • Middle East
    • Europe
    • Pacific
  • Business
    • All Business
    • MarketsSharesCurrencyCommoditiesStock TakesCrypto
    • Markets with Madison
    • Media Insider
    • Business analysis
    • Personal financeKiwiSaverInterest ratesTaxInvestment
    • EconomyInflationGDPOfficial cash rateEmployment
    • Small business
    • Business reportsMood of the BoardroomProject AucklandSustainable business and financeCapital markets reportAgribusiness reportInfrastructure reportDynamic business
    • Deloitte Top 200 Awards
    • CompaniesAged CareAgribusinessAirlinesBanking and financeConstructionEnergyFreight and logisticsHealthcareManufacturingMedia and MarketingRetailTelecommunicationsTourism
  • Opinion
    • All Opinion
    • Analysis
    • Editorials
    • Business analysis
    • Premium opinion
    • Letters to the editor
  • Sport
    • All Sport
    • OlympicsParalympics
    • RugbySuper RugbyNPCAll BlacksBlack FernsRugby sevensSchool rugby
    • CricketBlack CapsWhite Ferns
    • Racing
    • NetballSilver Ferns
    • LeagueWarriorsNRL
    • FootballWellington PhoenixAuckland FCAll WhitesFootball FernsEnglish Premier League
    • GolfNZ Open
    • MotorsportFormula 1
    • Boxing
    • UFC
    • BasketballNBABreakersTall BlacksTall Ferns
    • Tennis
    • Cycling
    • Athletics
    • SailingAmerica's CupSailGP
    • Rowing
  • Lifestyle
    • All Lifestyle
    • Viva - Food, fashion & beauty
    • Society Insider
    • Royals
    • Sex & relationships
    • Food & drinkRecipesRecipe collectionsRestaurant reviewsRestaurant bookings
    • Health & wellbeing
    • Fashion & beauty
    • Pets & animals
    • The Selection - Shop the trendsShop fashionShop beautyShop entertainmentShop giftsShop home & living
    • Milford's Investing Place
  • Entertainment
    • All Entertainment
    • TV
    • MoviesMovie reviews
    • MusicMusic reviews
    • BooksBook reviews
    • Culture
    • ReviewsBook reviewsMovie reviewsMusic reviewsRestaurant reviews
  • Travel
    • All Travel
    • News
    • New ZealandNorthlandAucklandWellingtonCanterburyOtago / QueenstownNelson-TasmanBest NZ beaches
    • International travelAustraliaPacific IslandsEuropeUKUSAAfricaAsia
    • Rail holidays
    • Cruise holidays
    • Ski holidays
    • Luxury travel
    • Adventure travel
  • Kāhu Māori news
  • Environment
    • All Environment
    • Our Green Future
  • Talanoa Pacific news
  • Property
    • All Property
    • Property Insider
    • Interest rates tracker
    • Residential property listings
    • Commercial property listings
  • Health
  • Technology
    • All Technology
    • AI
    • Social media
  • Rural
    • All Rural
    • Dairy farming
    • Sheep & beef farming
    • Horticulture
    • Animal health
    • Rural business
    • Rural life
    • Rural technology
    • Opinion
    • Audio & podcasts
  • Weather forecasts
    • All Weather forecasts
    • Kaitaia
    • Whangārei
    • Dargaville
    • Auckland
    • Thames
    • Tauranga
    • Hamilton
    • Whakatāne
    • Rotorua
    • Tokoroa
    • Te Kuiti
    • Taumaranui
    • Taupō
    • Gisborne
    • New Plymouth
    • Napier
    • Hastings
    • Dannevirke
    • Whanganui
    • Palmerston North
    • Levin
    • Paraparaumu
    • Masterton
    • Wellington
    • Motueka
    • Nelson
    • Blenheim
    • Westport
    • Reefton
    • Kaikōura
    • Greymouth
    • Hokitika
    • Christchurch
    • Ashburton
    • Timaru
    • Wānaka
    • Oamaru
    • Queenstown
    • Dunedin
    • Gore
    • Invercargill
  • Meet the journalists
  • Promotions & competitions
  • OneRoof property listings
  • Driven car news

Puzzles & Quizzes

  • Puzzles
    • All Puzzles
    • Sudoku
    • Code Cracker
    • Crosswords
    • Cryptic crossword
    • Wordsearch
  • Quizzes
    • All Quizzes
    • Morning quiz
    • Afternoon quiz
    • Sports quiz

Regions

  • Northland
    • All Northland
    • Far North
    • Kaitaia
    • Kerikeri
    • Kaikohe
    • Bay of Islands
    • Whangarei
    • Dargaville
    • Kaipara
    • Mangawhai
  • Auckland
  • Waikato
    • All Waikato
    • Hamilton
    • Coromandel & Hauraki
    • Matamata & Piako
    • Cambridge
    • Te Awamutu
    • Tokoroa & South Waikato
    • Taupō & Tūrangi
  • Bay of Plenty
    • All Bay of Plenty
    • Katikati
    • Tauranga
    • Mount Maunganui
    • Pāpāmoa
    • Te Puke
    • Whakatāne
  • Rotorua
  • Hawke's Bay
    • All Hawke's Bay
    • Napier
    • Hastings
    • Havelock North
    • Central Hawke's Bay
    • Wairoa
  • Taranaki
    • All Taranaki
    • Stratford
    • New Plymouth
    • Hāwera
  • Manawatū - Whanganui
    • All Manawatū - Whanganui
    • Whanganui
    • Palmerston North
    • Manawatū
    • Tararua
    • Horowhenua
  • Wellington
    • All Wellington
    • Kapiti
    • Wairarapa
    • Upper Hutt
    • Lower Hutt
  • Nelson & Tasman
    • All Nelson & Tasman
    • Motueka
    • Nelson
    • Tasman
  • Marlborough
  • West Coast
  • Canterbury
    • All Canterbury
    • Kaikōura
    • Christchurch
    • Ashburton
    • Timaru
  • Otago
    • All Otago
    • Oamaru
    • Dunedin
    • Balclutha
    • Alexandra
    • Queenstown
    • Wanaka
  • Southland
    • All Southland
    • Invercargill
    • Gore
    • Stewart Island
  • Gisborne

Media

  • Video
    • All Video
    • NZ news video
    • Business news video
    • Politics news video
    • Sport video
    • World news video
    • Lifestyle video
    • Entertainment video
    • Travel video
    • Markets with Madison
    • Kea Kids news
  • Podcasts
    • All Podcasts
    • The Front Page
    • On the Tiles
    • Ask me Anything
    • The Little Things
    • Cooking the Books
  • Cartoons
  • Photo galleries
  • Today's Paper - E-editions
  • Photo sales
  • Classifieds

NZME Network

  • Advertise with NZME
  • OneRoof
  • Driven Car Guide
  • BusinessDesk
  • Newstalk ZB
  • What the Actual
  • Sunlive
  • ZM
  • The Hits
  • Coast
  • Radio Hauraki
  • The Alternative Commentary Collective
  • Gold
  • Flava
  • iHeart Radio
  • Hokonui
  • Radio Wanaka
  • iHeartCountry New Zealand
  • Restaurant Hub
  • NZME Events

SubscribeSign In
Advertisement
Advertise with NZME.
Home / World

The man behind the biggest cyberscam the world has seen

Daily Telegraph UK
9 Jun, 2014 06:49 AM7 mins to read

Subscribe to listen

Access to Herald Premium articles require a Premium subscription. Subscribe now to listen.
Already a subscriber?  Sign in here

Listening to articles is free for open-access content—explore other articles or learn more about text-to-speech.
‌
Save

    Share this article

Like many computer scams, GOZ works by sending unsolicited emails containing an infected file, often a receipt or shipping confirmation. Photo / Thinkstock

Like many computer scams, GOZ works by sending unsolicited emails containing an infected file, often a receipt or shipping confirmation. Photo / Thinkstock

His FBI "most wanted" page shows a grinning, shaven-headed figure, accused of a string of very grand thefts across America. With a total haul estimated at more than US$100 million, and tricks that ran rings around the police, the case against Evgeniy Bogachev could form yet another sequel to the Oceans 11 heist movies.

But the man named last week as the biggest new threat to America's banking system has never needed a gun, nor is he even thought to have set foot in the United States. Instead, under the code name "Lucky 12345", he carried out his entire operation via strokes of a keyboard from his house on Russia's Black Sea coast, masterminding what is thought to be the most sophisticated cybercrime network the world has seen.

Using so-called "malware" - malicious software that "enslaves" computers and steals user names and passwords, the 30-year-old and his gang allegedly hacked into hundreds of thousands of bank accounts, emptying up to $7 million at a time from unsuspecting firms across America. Most were unaware that the attacks, from a program called GameOver Zeus, or GOZ, had even happened.

A second program, known as "ransomware", would freeze victims' computer files and threaten to destroy them unless an online ransom was paid. It targeted not just businesses, but home computer users - freezing precious online family photo albums and even children's school projects. To US law enforcement's considerable embarrassment, one victim was a police station in Massachusetts, which had to pay up to retrieve its database of mug shots.

Read more:
• Computer users warned over virus pandemic

Advertisement
Advertise with NZME.
Advertisement
Advertise with NZME.

Yet, even after a massive global operation to dismantle his network last weekend, in which a dozen national police forces, including Britain's, shut down hijacked servers and "freed" up to 300,000 computers, the malware remains a threat. For one, Bogachev still appears to be at large in Russia, where officials have shown little interest in helping the FBI in the wake of the sanctions slapped on Moscow over its annexation of Crimea. And for another, it is only a matter of time before the network is up and running again, hitting not just the US, but Britain as well.

On Monday, police said that some 15,000 British computer users had already been infected with the GOZ virus, and gave warning that within a fortnight it would have hijacked new servers. Having identified victims from one infected server, police urged them to install anti-virus software before it was too late.

"Nobody wants their personal financial details, business information or photographs of loved ones to be stolen or held to ransom by criminals," said Andy Archibald, the deputy director of the National Crime Agency's cybercrime unit.

Advertisement
Advertise with NZME.

Most victims would not be happy either at the way Bogachev was hailed as a hero last week by fellow Russians in his home town of Anapa, a balmy beach resort 112 kilometres from Crimea. Using details in the US indictment unsealed against him last week, The Sunday Telegraph visited his last known address at Lermontova, a skyscraper of £150,000 a-time flats.

There, neighbours remembered a quiet, affable figure, who sailed a yacht at the local marina, and whose only involvement in cyber-activity was the bumper sticker on his ageing Volvo sedan, which advertised his services for "computer repairs". When told, though, of how he was now a public enemy No 1 in the US, many were delighted.

"What a talented guy," said Mikhail, 23, who recognised Bogachev's FBI photo as the man he would see in the lobby with his wife and nine-year-old daughter. "Sitting at his computer at home, he broke into our enemies' camp, but did not harm his fellow Russians."

"What a great dude," added Vazgen Atanasov, a taxi driver. "Judging by what Americans do to other people, what Bogachev is said to have done to them serves them right."

Discover more

Business

Google swamped with calls to remove links

18 May 05:00 PM
Opinion

Pat Pilcher: Are Windows XP security threats overhyped?

18 May 09:30 PM
Employment

FBI hits a 'weed' problem in cyber-war

22 May 03:47 AM
Business

Security breach at eBay a reminder of damage cyber criminals can wreak

23 May 08:45 PM

While not voiced by all of Bogachev's neighbours, such comments show how the anti-Americanism that has lain dormant in Russia since the end of the Cold War has re-erupted since the confrontation with the West over Ukraine. As lone agents exposing holes in US cyber-defences, Russian cyberhackers are seen as combining the cunning of a KGB spy with the brains of a scientist.

Whether the Kremlin shares that view of Bogachev is unclear. But right now, there seems little sign of him facing a court. Russian law forbids the extradition of its citizens abroad - a policy that prevented suspects in the poisoning of the ex-KGB spy, Alexander Litvinenko, being brought to Britain.

And while Washington said last week that it had sought Russia's help in tracking Bogachev down, the fact that the FBI simultaneously issued a "wanted" poster of him suggests that help has not been forthcoming. Asked for clarification a US Department of Justice spokesman declined to comment, as did Russia's interior ministry.

However, neighbours said they had seen no police activity at Bogachev's home. And from the attitude of officers at Anapa's central police station, just 200 yards down the road, it seems likely to remain that way. Refusing to say whether they had been asked to arrest Bogachev, one policeman added: "I'd pin a medal on the guy."

So, too, did the FBI in a backhanded way, describing GOZ last week as "the most sophisticated" cyberscam that it had ever seen. "Bogachev and his criminal network implemented the kind of cybercrimes that you might not believe if you saw them in a science fiction movie," said Leslie Caldwell, a lawyer on the case.

Like many computer scams, GOZ works by sending unsolicited emails containing an infected file, often a receipt or shipping confirmation. Clicking on it allows the user's computer to be accessed remotely by the hackers. They then wait until the user logs into online banking systems and other sensitive websites, stealing their passwords to empty their accounts.

Advertisement
Advertise with NZME.

The scam's particular genius was that if a user logged on to a website requiring just a password, the hackers could add additional security questions asking for social security numbers, credit cards, and all manner of sensitive data.

The FBI believes that a million computers worldwide are now infected with the GOZ virus, with losses of about $100 million in America alone. While the victims' full identities have not been revealed, they include a Florida bank that lost nearly $7 million, and a plastics firm in Pennsylvania that lost $375,000 in a single day.

Arguably crueller still, was the "ransomware", which confounds the notion of hackers as "Robin Hoods" who only target big institutions. "The criminals effectively held for ransom every private email, business plan, child's science project, or family photograph," said Mr Caldwell.

The ransomware, known as "CryptoLocker", would encrypt all data on the victims' computer and demand a ransom of around $750 to decrypt it. It would be payable in "Bitcoins", the internet currency. While the ransoms themselves were relatively small, vast numbers of people paid up, told that their data would be destroyed if they did not meet a deadline. US officials believe CryptoLocker earned nearly $15 million a month.

Bogachev faces multiple charges of computer hacking, bank fraud, and money laundering, along with several other accomplices still only known by pseudonyms, such as Chingiz 911 (Ghengis 911), and Mr Kykyprky.

But with no chance of him being handed over to the FBI, the real question now is what Russia will do with him. "The former Soviet Union has long been fertile ground for cybercrime due to a volatile mixture of technical expertise, a tough job market, and tensions with the West," said Kenneth Geers, a US military computer expert now at internet security firm FireEye. "It is unlikely that there has been no collaboration between the state and non-state cyber attacks, especially if the attacks favour Russian national interests."

Advertisement
Advertise with NZME.

So does Mr Geers think that Bogachev will remain free? That, he says diplomatically, will be a "cost-benefit calculation for Russia". Which, given relations with America, may mean "Lucky 12345" stays lucky for some time yet.

Save

    Share this article

Latest from Technology

Premium
Business|markets

Allbirds predicts turnaround - finally - if lucky break on tariffs holds true

09 May 12:23 AM
Premium
Business|personal finance

‘Rip-off’: App developer and Consumer say fees will stifle open banking

08 May 11:00 PM
World

Google shares plunge 7% as Apple exec cites AI competition

07 May 06:37 PM

“Not an invisible footprint”: Why technology supply chains need optimising

sponsored
Advertisement
Advertise with NZME.

Latest from Technology

Premium
Allbirds predicts turnaround - finally - if lucky break on tariffs holds true

Allbirds predicts turnaround - finally - if lucky break on tariffs holds true

09 May 12:23 AM

PLUS: Waterproof Allbirds - and some "professional" sneakers for the office.

Premium
‘Rip-off’: App developer and Consumer say fees will stifle open banking

‘Rip-off’: App developer and Consumer say fees will stifle open banking

08 May 11:00 PM
Google shares plunge 7% as Apple exec cites AI competition

Google shares plunge 7% as Apple exec cites AI competition

07 May 06:37 PM
Nostalgia flows as Skype shuts down for good

Nostalgia flows as Skype shuts down for good

06 May 07:29 AM
Deposit scheme reduces risk, boosts trust – General Finance
sponsored

Deposit scheme reduces risk, boosts trust – General Finance

NZ Herald
  • About NZ Herald
  • Meet the journalists
  • Newsletters
  • Classifieds
  • Help & support
  • Contact us
  • House rules
  • Privacy Policy
  • Terms of use
  • Competition terms & conditions
  • Our use of AI
Subscriber Services
  • NZ Herald e-editions
  • Daily puzzles & quizzes
  • Manage your digital subscription
  • Manage your print subscription
  • Subscribe to the NZ Herald newspaper
  • Subscribe to Herald Premium
  • Gift a subscription
  • Subscriber FAQs
  • Subscription terms & conditions
  • Promotions and subscriber benefits
NZME Network
  • The New Zealand Herald
  • The Northland Age
  • The Northern Advocate
  • Waikato Herald
  • Bay of Plenty Times
  • Rotorua Daily Post
  • Hawke's Bay Today
  • Whanganui Chronicle
  • Viva
  • NZ Listener
  • What the Actual
  • Newstalk ZB
  • BusinessDesk
  • OneRoof
  • Driven CarGuide
  • iHeart Radio
  • Restaurant Hub
NZME
  • About NZME
  • NZME careers
  • Advertise with NZME
  • Digital self-service advertising
  • Book your classified ad
  • Photo sales
  • NZME Events
  • © Copyright 2025 NZME Publishing Limited
TOP