.

Robber Uses Craigslist to Pull Off Bank Heist

<<

don

User avatar

Administrator
Administrator

Posts: 4226

Joined: Sun Aug 28, 2005 10:47 pm

Location: Chicago

Post Thu Mar 19, 2009 10:07 am

Robber Uses Craigslist to Pull Off Bank Heist

I hadn't heard of this story until a classmate mentioned it at SANS 2009. Thought I'd share it with you as another example of electronically assisted social engineering. Basically, he placed a false ad on Craigslist to create a crowd around a bank truck to make himself less visible. Get the low-tech details at either of these 2 links:

http://arstechnica.com/old/content/2008 ... s-away.ars

http://news.cnet.com/bank-robber-hires- ... ools-cops/

Don
Last edited by don on Thu Mar 19, 2009 10:09 am, edited 1 time in total.
CISSP, MCSE, CSTA, Security+ SME
<<

timmedin

User avatar

Sr. Member
Sr. Member

Posts: 469

Joined: Thu Feb 05, 2009 11:18 pm

Post Thu Mar 19, 2009 11:19 am

Re: Robber Uses Craigslist to Pull Off Bank Heist

I laughed out loud when I first read this story. A real life blue colar Thomas Crown affair.

I hadn't heard the part about the "getaway inner tube" though. Classic!
twitter.com/timmedin | http://blog.securitywhole.com
<<

mmurray

User avatar

Newbie
Newbie

Posts: 17

Joined: Fri Jul 25, 2008 11:03 am

Location: Fremont, CA

Post Thu Mar 19, 2009 1:24 pm

Re: Robber Uses Craigslist to Pull Off Bank Heist

This is why I always make the argument that SE attacks are really attacks of the imagination - this is the kind of thing that makes SE very difficult to defend against.  Predictable controls are easily circumvented by an unpredictable attacker.
--
Mike Murray
MAD Security / The Hacker Academy

Email - mmurray@thehackeracademy.com
Phone - 773-360-0658
Twitter: http://www.twitter.com/mmurray
<<

LSOChris

Post Thu Mar 19, 2009 1:30 pm

Re: Robber Uses Craigslist to Pull Off Bank Heist

very well put Mike!
<<

jason

User avatar

Hero Member
Hero Member

Posts: 1013

Joined: Sat Jun 21, 2008 6:23 pm

Location: USA

Post Thu Mar 19, 2009 8:04 pm

Re: Robber Uses Craigslist to Pull Off Bank Heist

Ya, I remember reading about this one a bit back. Very slick solution  8)
<<

former33t

Full Member
Full Member

Posts: 226

Joined: Sat Feb 14, 2009 12:33 am

Post Thu Mar 19, 2009 8:56 pm

Re: Robber Uses Craigslist to Pull Off Bank Heist

I hadn't heard of that, but it reminds me a lot of the movie Inside Man where most of the robbers in a bank heist get away by dressing everyone (including themselves) in painters' uniforms and masks and running out of the building with all the hostages.  This didn't even require hostages, just a lot of unemployment and some people willing to believe they would make $28/hr for manual labor...
Certifications: CREA, MCSE: Security, CCNA, Security+, other junk
<<

MicroJay

User avatar

Full Member
Full Member

Posts: 101

Joined: Wed Feb 04, 2009 4:19 pm

Post Fri Mar 20, 2009 6:01 am

Re: Robber Uses Craigslist to Pull Off Bank Heist

It just tells you that anything can be possible!  If you can think, you can achieve.
GSEC - GCIH - GSNA - GPEN

Return to Social Engineering

Who is online

Users browsing this forum: No registered users and 0 guests

.
Powered by phpBB® Forum Software © phpBB Group.
Designed by ST Software