On the occasion of the 6th edition of the X1redmassegura conference, an interview was conducted with Selva Orejón, in which she was asked about the challenges of CYBERINVESTIGATION into scams, onBRANDING’s role in investigating them, and public-private collaboration.
Company objectives/purpose
onBRANDING was created to provide tailored solutions to reputational loss problems caused by poor management of communication, privacy, and security, resulting in financial and legal losses and the need for crisis management action.
Ignorance is the mother of all evils. And we have a team of specialists by sector and professional field who train clients so they can take an active role in resolving their issues.
– What are the main characteristics of cybercrime? The main difficulties in prosecuting such conduct.
As with any crime committed in potentially “apparent” international territory, the first difficulty is knowing where the crime was committed. Where the IPs that appear are from, but… and what happens when you have the IP or IPs, the ISP, and the address of the apparent offender… that most of the time, when it comes to crimes committed “randomly” and therefore not a crime “targeted” at someone because they are so-and-so or because they are a celebrity, an ex-partner, an ex-business partner… the person who committed it will probably have taken certain security and anonymity measures such as using at least a VPN, a proxy, browsing with TOR, changing their machine’s user agent and using a browser they do not normally use, using a fake GPS if on mobile and therefore the IP will not be personal data, nor the MAC address of their device, nor the email created on a GuerrillaMail, Ten Minute Mail, YOP, Proton, or any other temporary email service.
On the other hand, criminals are often very lazy; they find it hard to keep using different infrastructures continuously—it is tiring… 😉 and they also copy and paste texts they know work, and of course they recycle images.
Therefore, as is evident, the perfect crime does not exist,
– Difficulty in prosecuting scams.
The victim themselves is sometimes a difficulty, let me explain: they destroy evidence, delete proof, out of fear, pain, a desire to move on, anger, and/or lack of knowledge. And if there is no evidence, it is harder to prove the crime. Not impossible, though.
In addition, if we add everything explained above, it will not always be easy to find the scammer, but laziness, ego, greed, the desire to make quick money, drug use, and Freudian slips work in our favor. We also have criminal psychologists and profilers who help us build the profile of the attacker (male or female) and the typical victim profile, and together with our detectives, we end up catching them, sooner or later.
– Is there a lack of knowledge in the judicial world regarding aspects related to new information and communication technologies?
As a general rule, yes—specialized prosecutors are not, and in fact we are very fortunate to have true experts such as Jorge Bermúdez, Paco Sánchez, Roberto Valverde, and Javier Tejada..
We also have outstanding professionals in the field of ICT CRIMINAL LAW, but if we refer to the average level of knowledge among juvenile prosecutors, courts of first instance, VIDO courts, or even the police officers who take complaints, yes, we have a significant problem of lack of knowledge.
– How does public-private collaboration work in cybercrime?
Actively, out of necessity: the information security community, forensic IT experts, digital identity specialists, cyber intelligence analysts… go to court or police headquarters at least a couple of times a week. At cybersecurity conferences, people work side by side, and there is both occasional and ongoing collaboration between public and private organizations.
Is there an alliance between the public and private sectors to prevent and combat cybercrime?
Police academies, public security institutes, and universities and faculties that offer security degrees, master’s programs, and postgraduate programs in cybersecurity and cyber intelligence include professionals from both spheres, and there is undoubtedly fluid communication. Therefore, yes, there is a contact network.
– How should this collaboration be improved?
I think it should continue as it is; perhaps the law enforcement agencies could have a greater presence in institutes and universities. In my case, for example, they did not even visit us to present the public sector as a possible career path. I believe they were at the education fair at the time, but I could not confirm whether they still are.
From a young age we are taught that if something happens to us we should go to the police, but they must be well trained—not only divided into specialties—because in the end police stations become bottlenecks, backlogs build up, citizens do not see their cases being investigated, and the social belief is generated that “why report it if they will not do anything,” and if they do not act it is often because there are very few specialists and because, unfortunately, sometimes the attackers’ IPs are in countries with which there are no international treaties and therefore little or nothing can be done. As a result, we are left with prevention through training, as well as self-protection and increasing human resources in the security forces.
And even so, there are great professionals in public security; in my experience, we are in good hands. I believe that in Spain we have the mistaken notion that the security forces are poorly prepared, and what the public does not know is how lucky we are: there are truly remarkable people, highly capable, very motivated, and who work out of genuine vocation. We should take a look at some police forces in countries we consider more advanced than ours to realize how well we are doing. Obviously everything can be improved, and I personally am very combative, nonconformist, and I will always defend aiming higher—both in the military and police forces, and as a society and as a country.
– What are the most common scams?
The scams that are working best are those in which social engineering plays the main role. The search for a bargain—whether as a person or as a product—makes us fall for deception, because if there is no deception, there is no scam.
It is very interesting to see how many people fall for scams via Facebook ads: they see “Rayban offer from €199 to €19.99, one day only, RUN, limited units, visit the official Rayban website at RyBn.com” with the Rayban logo and a URL that looks similar to how the word RayBan might be shortened, and they fall for it.
What do they have in common at a minimum?
1) Limited offer—you are the smart one because you found it.
2) Urgency: a unique opportunity, hurry.
3) Official (logo, the word “official,” and a shortened website).
4) A page crowned as the official one; the only difference is the payment platform—and you will NEVER receive anything.
Except for the good scammers, who already have, on the landing page itself, a registration form with a payment platform with VISA, “PayPal,” and whatever else you like. And of course, they already send an email with a confirmation link and a purchase confirmation email.
“Romance” scams have always existed, as have abusers and those who abuse trust, and psychopathy is nothing new. But in recent times we have been fortunate to have the brave testimony of victims who portray their attackers perfectly—people who, thanks to the sum of their experiences and the positioning this generates on the Internet, make it a bit more
difficult for scammers because by making their modus operandi public, along with the digital, mobile, and analog identities they have used, they themselves burn their own infrastructures.
– How does collaboration with the police work in this type of crime?
Each company has its communication channels; they usually begin in “networking” spaces where members of the State security forces and employees of private companies or self-employed professionals attend as participants or speakers. In these spaces, synergies and working relationships are created, experiences and doubts are shared, and little by little a network of trusted people and professionals is woven.