Even though the use of Internet-facing ICS is not inherently dangerous, many
of the systems shown in the figure above were not password protected or kept
up-to-date with the latest security patches, needlessly exposing them to attacks.
A Trend Micro study detailed that Internet-facing ICS suffer daily attacks. Data
shows that over a period of 28 days, a total of 39 attacks from 14 different
countries were recorded. Out of these 39 attacks, 12 were unique and could
be classified as “targeted” while 13 were repeated by several of the same
actors over a period of several days and could be considered “targeted” and/or
“automated.”4
Country Reports on Cybercrime
All of the information in this section came from reports submitted by OAS
Member States.
Cybercrime Trends in Chile
In 2012, the number of cyber incidents that led to investigation and response
in Chile decreased by 33%, as reported by the cybercrime unit of the Federal
Police Department. The number of Internet-based wire fraud incidents, which
often consisted of phishing and pharming attacks, decreased by 122% overall.
Authorities attributed the decrease in this type of incident, which made up a
large portion the country’s criminal web traffic, to the dismantling of a notorious
syndicate responsible for large-scale malware distribution often used in
defrauding banks and individuals. Chile noted that many crimes now involve
elements of Internet exploitation, as drug dealers and other criminals use the
web to facilitate their activities. The prevalence of Internet-based crime there
highlighted difficulties in international cooperation, which was cited in Chile as
the biggest hindrance to cyber incident response, investigation, and deterrence.
Cybercrime Trends in Colombia
According to colCERT, which is Colombia’s national CSIRT, the country
recorded fewer cyber incidents in 2012 than in 2011, pairing it with Chile as
one of the few Latin American countries with that distinction. It was unclear,
however, whether this was due to a real decrease in the number of incidents,
better security management on the part of government agencies that colCERT
served, or the implementation of policies that changed the scope of assistance
Colombia’s response teams rendered.
In any case, fraud was the most prevalent type of cyber incident reported
by colCERT in 2012. One notable contributor to this number was prolific
cybercriminal, Jorge Maximilian “Pacho” Viola, who was captured in Colombia
last year. Dubbed the “Tsar of Cloning,” Viola had committed fraud in at least
seven Latin American countries and was eventually arrested with over 8,000
cloned credit cards and US$9 million in his possession.5
Various types of hacking and website spoofing followed in Colombia’s list
of most prevalent cyber incidents. Hacktivist attacks, which most frequently
targeted state and military entities and financial institutions, were widely reported
by the country’s response teams.
4
5
http://www.trendmicro.com/cloud-content/us/pdfs/security-intelligence/white-papers/wp-whosreally-attacking-your-ics-equipment.pdf
http://latinamericacurrentevents.com/head-of-major-credit-card-cloning-ring-arrested-incolombia/18040/
PAGE 6 | Latin American and Caribbean Cybersecurity Trends and Government Responses