Jun 6, 2019

How a phone scam tied up a Maryland police call center

In a previously unreported event demonstrating both the risks all organizations face from threats to the telephone system and how to mitigate them, an Arabic-speaking phone scammer tied up the nonemergency police call centers in Maryland's Howard County with a flood of calls over two days in August, briefly disrupting services.

Why it matters: The scam was against the phone company, not against Howard County, a target picked at random. So while the county didn't lose money, it briefly lost use of its nonemergency call center.

Background: Howard County normally gets between 300 and 400 calls a day to the nonemergency number. That's where citizens might be routed "if there's a cat stuck in a tree, but the cat's not on fire," said James Cox, the county's network-server team manager.

  • Suddenly, in August, the call center started receiving 2,500 direct calls a day. That call volume made it impossible for legitimate callers to reach the system.
  • "We got to the point we had to actually turn off the numbers," Cox said.

Howard County was fortunate. It had a relationship in place with a security group that could help mitigate and investigate the attack, in this case, Cisco.

  • Cisco recommended a telephone firewall provider to thwart the attack, and Cisco's Talos research group, in conjunction with the police, determined that the caller was taking advantage of a loophole in the international phone system.
  • When calls transfer from one network to another, the connecting network exacts a fee. In this case, the caller and the phone network had a kickback agreement to share that fee while placing as many calls as possible. The caller made pennies on the dollar in the scam, between $2,000 and $3,000 total.
  • While the calls appeared to be from the U.S., they were actually being routed through Europe.
  • Talos was able to help in the investigation by piecing together evidence the police had already collected and providing additional services, including an Arabic linguist, according to Matt Olney, Talos threat detection and interdiction manager.

The intrigue: Cox will publicly discuss the event for the first time at the upcoming Talos Threat Research Summit on June 9. He says there are a few important lessons.

  • Don't expect help from the phone company or social media networks to research an attack without a warrant. That makes mitigating the attack without a security expert near impossible — you need to know what an attacker is trying to do to prevent it.
  • Have a plan in place before the attack happens. Know at what call volume you can afford to expand operations to handle on the fly — or if you can live without phones for the duration of an attack.

Go deeper: A look inside a Nigerian email scam group active since 2008

Go deeper

America's rundown roads add to farmers' struggles

Illustration: Sarah Grillo/Axios

American farmers are struggling to safely use the roads that cut through their fields; decades of neglect and lack of funding have made the routes dangerous.

The big picture: President Trump has long promised to invest billions in rural infrastructure, and his latest proposal would allocate $1 trillion for such projects. Rural America, where many of Trump's supporters live, would see a large chunk of that money.

South Korea and Italy see spikes in coronavirus cases

Data: The Center for Systems Science and Engineering at Johns Hopkins, the CDC, and China's Health Ministry. Note: China numbers are for the mainland only and U.S. numbers include repatriated citizens.

The novel coronavirus continues to spread to more nations, and the U.S. reports a doubling of its confirmed cases to 34 — while noting those are mostly due to repatriated citizens, emphasizing there's no "community spread" yet in the U.S. South Korea's confirmed cases jumped from 204 on Friday to 433 on Saturday, while Italy's case count rose from 3 to 62 as of Saturday.

The big picture: COVID-19 has now killed at least 2,362 people and infected more than 77,000 others, mostly in mainland China. New countries to announce infections recently include Israel, Lebanon and Iran.

Go deeperArrowUpdated 4 hours ago - Health

Centrist Democrats beseech 2020 candidates: "Stand up to Bernie" or Trump wins

Bernie Sanders rallies in Las Vegas, Nevada on Feb. 21. Photo: Mario Tama/Getty Images

Center-left think tank Third Way urgently called on the Democratic front-runners of the 2020 presidential election to challenge Sen. Bernie Sanders on the South Carolina debate stage on Feb. 25, in a memo provided to Axios' Mike Allen on Saturday.

What they're saying: "At the Las Vegas debate ... you declined to really challenge Senator Sanders. If you repeat this strategy at the South Carolina debate this week, you could hand the nomination to Sanders, likely dooming the Democratic Party — and the nation — to Trump and sweeping down-ballot Republican victories in November."