In a previously unreported event demonstrating both the risks all organizations face from threats to the telephone system and how to mitigate them, an Arabic-speaking phone scammer tied up the nonemergency police call centers in Maryland's Howard County with a flood of calls over two days in August, briefly disrupting services.

Why it matters: The scam was against the phone company, not against Howard County, a target picked at random. So while the county didn't lose money, it briefly lost use of its nonemergency call center.

Background: Howard County normally gets between 300 and 400 calls a day to the nonemergency number. That's where citizens might be routed "if there's a cat stuck in a tree, but the cat's not on fire," said James Cox, the county's network-server team manager.

  • Suddenly, in August, the call center started receiving 2,500 direct calls a day. That call volume made it impossible for legitimate callers to reach the system.
  • "We got to the point we had to actually turn off the numbers," Cox said.

Howard County was fortunate. It had a relationship in place with a security group that could help mitigate and investigate the attack, in this case, Cisco.

  • Cisco recommended a telephone firewall provider to thwart the attack, and Cisco's Talos research group, in conjunction with the police, determined that the caller was taking advantage of a loophole in the international phone system.
  • When calls transfer from one network to another, the connecting network exacts a fee. In this case, the caller and the phone network had a kickback agreement to share that fee while placing as many calls as possible. The caller made pennies on the dollar in the scam, between $2,000 and $3,000 total.
  • While the calls appeared to be from the U.S., they were actually being routed through Europe.
  • Talos was able to help in the investigation by piecing together evidence the police had already collected and providing additional services, including an Arabic linguist, according to Matt Olney, Talos threat detection and interdiction manager.

The intrigue: Cox will publicly discuss the event for the first time at the upcoming Talos Threat Research Summit on June 9. He says there are a few important lessons.

  • Don't expect help from the phone company or social media networks to research an attack without a warrant. That makes mitigating the attack without a security expert near impossible — you need to know what an attacker is trying to do to prevent it.
  • Have a plan in place before the attack happens. Know at what call volume you can afford to expand operations to handle on the fly — or if you can live without phones for the duration of an attack.

Go deeper: A look inside a Nigerian email scam group active since 2008

Go deeper

Updated 1 hour ago - Politics & Policy

Coronavirus dashboard

Illustration: Sarah Grillo/Axios

  1. Global: Total confirmed cases as of 7 p.m. ET: 19,734,428— Total deaths: 728,612 — Total recoveries — 12,001,537Map.
  2. U.S.: Total confirmed cases as of 7 p.m. ET: 5,036,387 — Total deaths: 162,851 — Total recoveries: 1,656,864 — Total tests: 61,792,571Map.
  3. Politics: Pelosi says states don't have the funds to comply with Trump's executive order on unemployment — Mnuchin says Trump executive orders were cleared by Justice Department.
  4. Public health: Ex-FDA head: U.S. will "definitely" see 200,000 to 300,000 virus deaths by end of 2020 — Fauci says chances are "not great" that COVID-19 vaccine will be 98% effective.
  5. Schools: Nine test positive at Georgia school where photo showing packed hallway went viral — How back-to-school is playing out in the South as coronavirus rages on.
2 hours ago - World

Protests erupt in Belarus after "Europe's last dictator" claims election victory

A man lies on the ground in front of riot police in Minsk. Photo: Sergei Gapon/AFP via Getty Images

Demonstrations broke out across Belarus on Sunday after a government exit poll predicted that President Aleksander Lukashenko, an authoritarian who has ruled the Eastern European country since 1994, had swept to overwhelming victory over a pro-democracy opposition candidate.

Why it matters: It's a precarious moment for the former Soviet republic, where decades of repression and a complete disregard for the coronavirus pandemic now threaten to topple "Europe's last dictator."

Scoop: Inside Trump's debate prep

Trump and Christie. Photo: Jim Watson/AFP via Getty Images

Two weekends ago, President Trump met with a group of his closest aides in the conference room of his Bedminster golf club to discuss a subject that has been weighing heavily on his mind: the three scheduled debates with Joe Biden.

Behind the scenes: In the room with Trump were his son-in-law Jared Kushner, campaign manager Bill Stepien, senior adviser Jason Miller, and former New Jersey Gov. Chris Christie, who role-played Hillary Clinton in Trump's 2016 debate prep sessions.