Last year, the U.K. dissolved the National High-Tech Crime Unit (NHTCU), the agency responsible for investigating computer crime. The unit was folded into the Serious Organized Crime Agency (SOCA), a new organization that investigates fraud, drug trafficking and immigration-related crime. Critics charged that online crime would become a lower priority.
Law enforcement agencies prior to the formation of SOCA were "not achieving the kind of long-term impact on serious and organized crime ... that's needed," said William Hughes, SOCA's director general, at the International e-Crime Congress in London on Tuesday.
The agency has a 94 percent conviction rate and made 684 arrests from April 2006 through February, mostly for drug trafficking but also including some e-crime, Hughes said. However, online banking fraud in the U.K. continues unabated. Online banking fraud losses in the U.K. rose to £33.5 million ($44.5 million) in 2006, up from £23.2 million in 2005 and £12.2 million in 2004, according to the Association for Payment Clearing Services, a payments trade group,
Sharon Lemon, a 30-year police veteran who headed the NHTCU, is now in charge of the e-crime unit within SOCA. She spoke on the sidelines of the e-crime conference on how the new unit has been running since becoming part of SOCA last year. What follows is an edited transcript of the interview:
IDG News Service: Given the growth in online crime, how do you prioritize cases?
Sharon Lemon: It's such a big area that we've had to really regroup and consider what our priorities are. To enable that, we need to be informed, so we've got a comprehensive knowledge base. We're not just randomly chasing people who happen to attract our attention. We've got a quite significant assessments team who assess the crime on the Internet and assess the threat, look at the new approaches. As a result, we'll consider the best operation. So it's much more focused and thought through.
IDGNS: How significant is the amount of money lost as part of an incident?
Lemon: If you have a look at the combined effect of many, many low-level amount frauds, that's organized crime. By attacking some 300,000 people for a small amount, it's the same as one person losing £300,000. We look at emerging trends, what's happening on the criminal forums and then decide what's the best approach. It's not always traditional prosecution. We've got to look at different approaches. Traditional prosecutions always have a place, but they are very long and complex, and by the time we get to court, the cyber criminals have come up with something new. So we need to be as flexible and responsive as they are.
IDGNS: What types of online crimes has the unit focused its energy on?
Lemon: Most of our investigations have been around fraud, which I summarize as lying to get your money. A lot of traditional investigation techniques apply but just online. I think we get a bit intoxicated by the IT element of it. It's just normal crime. That's why we need our international partners, because with this type of crime it's not the person next door, it could be the person on the other end of the world.
IDGNS: Can you describe the backgrounds of investigators in the unit?
This whitepaper explains the terminology and concepts behind Data Replication technologies and establishes some sizing rules through worked examples. Learn the new paradigm in disaster tolerance—protect data anywhere.
Download now »Server virtualization is a popular option for dealing with mounting datacenter costs. Another equally promising approach is the use of an Application Delivery Controller. Citrix NetScaler provides a low-cost way for organizations to reduce their server count and accrue cost savings from a reduction in space, cooling, power and personnel.
Download now »
The emergence of WLANs has created a new breed of security threats to enterprise networks.
Included in HP ProCurve WLAN solutions is security technology that alleviates threats from WLANs through:
* Monitoring wireless activity inside and out of the enterprise
* Classifying WLAN transmissions into harmful and harmless
* Preventing transmissions that pose a security threat to the enterprise network
* Locating participating devices for physical remediation
Effectively address data protection challenges, implementing solutions that help store and protect businesscritical data while cutting costs and improving efficiency and reliability.
Download now »
Sign up to receive Security Resource Alerts
This white paper provides guidance on how to develop a strategic approach to managing and monitoring logs, a key function required for compliance with many regulatory mandates and a critical defense against security threats.
Download now! »Learn about the processes and technologies that support security information management (SIM) operations, as well as the business case for SIM. The series examines different options for implementing SIM and gives you evaluation criteria for selecting the best option for your organization.
Download now! »Learn the strategies, actions, and capabilities that Best-in-Class organizations employ and technologies they choose to obtain superior performance against various security performance metrics. This report provides guidelines for identifying which security solutions to consume as a MSS and defines best practices for choosing and managing MSSPs.
Download now! »