Глава 1
The Digital Battlefield: Our Vulnerable Technological Future
Marc Goodman's journey into high-tech crime began almost by accident in 1995, when his LAPD lieutenant assigned him a computer crime case simply because he could spell-check in WordPerfect. Since then, he's watched criminals consistently outpace law enforcement in adopting emerging technologies. While Mexican cartels built encrypted nationwide telecommunications systems, most police departments were still using typewriters. Today, Goodman's warnings about technological vulnerabilities have become required reading in security circles, with tech luminaries like Ray Kurzweil and Peter Diamandis praising his foresight. "Future Crimes" has become the go-to resource for understanding how our increasingly connected world creates unprecedented security risks-a book Bill Gates called "terrifying but necessary" and one that landed on Mark Cuban's recommended reading list for entrepreneurs who want to understand tomorrow's threats.
Глава 2
The Connected Life: How Convenience Creates Vulnerability
In 2012, tech journalist Mat Honan experienced every digital citizen's nightmare. A teenage hacker who simply wanted Honan's three-letter Twitter handle managed to destroy his entire digital life in minutes. The attack required no sophisticated hacking-just exploiting interconnected accounts and customer service vulnerabilities at Apple and Amazon. Using only Honan's billing address and the last four digits of his credit card (information easily found online), the hacker gained access to his iCloud account, remotely wiped his iPhone, iPad, and MacBook, erased irreplaceable baby photos, deleted eight years of Gmail messages, and hijacked his Twitter account to send racist messages.
This devastating attack illustrates how our increasingly connected digital lives rest on surprisingly fragile foundations. The technological evolution that's brought remarkable benefits-doubled human lifespans, tripled per capita income, free education through platforms like Khan Academy-has created dangerous dependencies. Our electrical grids, air traffic control, emergency services, and daily conveniences all rely on vulnerable computer systems.
Traditional national borders that once controlled the movement of people and goods are meaningless in cyberspace. Unlike physical bank robberies where jurisdiction is clear and evidence tangible, digital heists create jurisdictional nightmares. When Vladimir Levin stole $10.7 million from Citibank in 1994, investigators faced a criminal who could route attacks through multiple countries, hopping virtually from one compromised network to another.
The scale of malware has become staggering-security companies identify nearly 200,000 new malicious programs daily. Even if these numbers were inflated by 75%, that's still 50,000 new viruses created every day. Despite global security software spending approaching $94 billion annually, our defenses are failing spectacularly. When researchers tested 82 new viruses against major antivirus engines, the initial detection rate was a dismal 5%. The "time-to-detection" continues growing-the sophisticated Flame malware operated undetected for five years.
Once hackers target a network, they penetrate it within minutes 75% of the time, yet the average breach takes 210 days to discover. Worse, 92% of breaches are discovered not by internal security teams but by law enforcement or angry customers. As we rush toward connecting a trillion new devices to the internet, these vulnerabilities will multiply exponentially, threatening not just our data but potentially our physical world.
Глава 3
Critical Infrastructure: When Systems Fail
In Lodz, Poland, a fourteen-year-old computer prodigy created an infrared remote transmitter that could control all junctions on the city's tram line. After months studying the rail system, he hacked switches throughout town, causing a collision between two trams that injured over a dozen passengers. The teen admitted he did it "just for the lulz," but the incident raised a chilling question: if a teenager acting alone could cause such havoc, what might criminals, terrorists, or hostile nations accomplish?
We've connected everything that plugs into a wall to the global information grid without adequate security measures. Our critical infrastructures-electricity grid, gas pipelines, 911 dispatch, air traffic control, stock markets, water systems-all depend on vulnerable technology. SCADA systems that control physical equipment were never designed with security in mind, yet are increasingly connected to the internet. Nearly 70% of critical infrastructure companies suffered security breaches disrupting operations in a 2014 study.
The threats are real and varied: hackers have already attacked water treatment facilities in South Houston, severed communications at an FAA control tower, caused millions of liters of raw sewage to spill in Australia, and repeatedly probed our aging electrical grid. The U.S. Department of Energy reports that 70% of grid components are over 25 years old, using outdated technologies that are constantly targeted. Intelligence officials confirm that foreign spies have already mapped America's electrical network so it "could be taken out" during a conflict.
To understand technological threats, we must know our adversaries. The cast of cyber enemies includes nation-states, neighborhood thugs, transnational crime groups, foreign intelligence services, hacktivists, military personnel, cyber warriors, state-sponsored proxies, script kiddies, and disgruntled insiders. These diverse actors often use similar tactics with varying sophistication, benefiting from technology's asymmetric nature-defenders need perfect security while attackers need find only one vulnerability.
China reportedly maintains an army of 180,000 cyber spies launching 90,000 attacks annually against U.S. defense networks alone. They've stolen blueprints for advanced weapons systems including the F-35 Joint Strike Fighter, Patriot missiles, and Black Hawk helicopters. Chinese hackers have also targeted media organizations like the New York Times, with attacks traced to Unit 61398 of the People's Liberation Army operating from a 12-story building in Shanghai.
Beyond China, at least 108 nations maintain dedicated cyber-attack units. Iran has emerged as a particularly aggressive actor, with groups like "Cutting Sword of Justice" launching devastating attacks against Saudi Aramco that destroyed data on 75% of the company's 30,000 computers. Iranian hackers also targeted major U.S. financial institutions with unprecedented distributed-denial-of-service attacks.
Глава 4
Moore's Outlaws: Exponential Growth in Crime
We're witnessing exponential rather than linear technological growth, with the internet expanding from 360 million users in 2000 to over 1 billion by 2005, and another billion just six years later. This acceleration follows Moore's Law, named after Intel's Gordon Moore who predicted in 1965 that transistor density would double yearly (later revised to every 18-24 months). This principle now applies broadly to all circuit-based technologies.
The difference between linear and exponential growth is profound-taking 30 linear steps might cross a room, but 30 exponential steps (doubling with each step) would reach the moon. Today's iPhone has more processing power than NASA had for the Apollo 11 mission, being "a million times cheaper and a thousand times faster than a supercomputer of the '70s."
Humans evolved to think linearly, which served us well when calculating escape routes from predators on the Serengeti, but leaves us ill-equipped to intuitively grasp exponential change. We're building a civilization that's deeply interconnected yet technologically insecure-essentially wiring the world for crime.
Traditional crime was limited by physical constraints-even the most efficient robber could only victimize perhaps five or six people daily. Technology revolutionized this limitation, beginning with train robberies that enabled criminals like Jesse James to rob hundreds simultaneously. Today's exponential technologies have enabled unprecedented criminal scale: the 2007 T.J. Maxx hack affected 45 million customers; the 2011 Sony PlayStation breach compromised 77 million accounts costing $1 billion; the 2013 Target hack stole data from 110 million accounts; and in 2014, Russian hackers gathered 1.2 billion credentials from 420,000 websites.
As humanity connects everything to the Internet, we're becoming both omniscient (with instant access to all knowledge) and omnipotent (able to control objects remotely). But this transformation introduces tremendous complexity. Modern systems require millions of lines of code-Microsoft Office uses 45 million, cars need 100 million, and Healthcare.gov reportedly contained 500 million, compared to just 145,000 for the Apollo 11 guidance computer.
This complexity creates vulnerabilities, with typical commercial software containing 20-30 bugs per thousand lines of code. System failures can be catastrophic, as seen in the 2003 Northeast blackout and the Deepwater Horizon disaster. Worse, weaponized malware can be repurposed by criminals after initial deployment. The sobering reality is that no computer system created has proven unhackable-when everything is connected, everyone is vulnerable.
Глава 5
The Surveillance Economy: You Are the Product
Sites that appear to serve noble purposes often hide darker business models. PatientsLikeMe.com, created to help people with serious illnesses connect with others facing similar challenges, grew to host 200,000 patients with 1,500 unique diseases. The site became a lifeline for people like Bilal Ahmed, who found support for his depression and anxiety. However, users later discovered Nielsen's BuzzMetrics had been scraping their private forum data, and PatientsLikeMe routinely sold users' medical information to pharmaceutical companies-a fact buried in their terms of service.
Americans spend over five hours daily online, leaving behind massive digital exhaust trails with every interaction. Most users don't understand the true bargain they've made with free services like Google. Founded in 1998 by Stanford PhD students Larry Page and Sergey Brin, Google evolved from a simple search engine into a data-collection behemoth offering dozens of "free" products-Gmail, Maps, Calendar, Drive, Android OS-each designed to extract more personal information. The company's true business model isn't providing services but harvesting user data to sell to advertisers.
Google tracks everything: your searches, emails (which it electronically reads), contacts, locations, phone calls, and even voice messages. When Google merged data across its seventy products in 2012, it created unprecedented unified profiles of users. Despite its "Don't be evil" motto and friendly branding, Google has faced numerous lawsuits for privacy violations.
Facebook, with 1.2 billion monthly active users, has mastered the art of getting people to voluntarily share unprecedented personal details. The social network collects everything from sexual orientation and relationship status to education history, family connections, and political views. Beyond profile information, Facebook tracks users across the entire web through its omnipresent Like button and login credentials used on other sites.
Data brokers like Acxiom, Epsilon, and Datalogix form a $156 billion industry-twice the size of the US intelligence budget. Acxiom alone operates 23,000 servers processing 50 trillion data transactions yearly, with profiles on 700 million consumers worldwide containing 1,500+ traits per person. They collect data from ISPs, credit cards, phone companies, retailers, and social media to segment consumers into marketing clusters. These profiles are sold to major financial institutions, telecoms, and insurers. Some brokers even sell disturbing lists of rape survivors, domestic violence victims, and people with dementia.
Our daily digital exhaust-phone records, texts, browser histories, GPS data, emails-creates an infinite data trail that companies analyze to target us with unprecedented precision. When you search for flights to Miami and then buy a swimsuit, that data combination makes you valuable to Miami hotels who can bid in real time to show you relevant ads. By analyzing your pattern of life, Google can determine intimate details-like where you sleep each night and with whom.
Глава 6
Digital Dangers: When Your Data Becomes a Weapon
The 2008 Mumbai terrorist attacks provide a chilling example of how our digital footprints can be weaponized. When terrorists stormed the Taj Mahal Palace hotel, they captured businessman K.R. Ramamoorthy, who falsely claimed to be "just an innocent schoolteacher." The terrorists relayed his name to their command center in Pakistan, where operators quickly conducted an internet search revealing Ramamoorthy was actually the chairman of one of India's largest banks. After confirming his identity through physical characteristics found in online photos, the terrorist commanders ordered their operatives to kill him.
Our data creation never sleeps. Every digital process, sensor, mobile phone, and social media interaction generates information at an unprecedented rate. The World Economic Forum has dubbed data "the new oil," with companies like IBM, Microsoft, Facebook and Google becoming the modern-day Rockefellers and Gettys of this resource. But unlike oil, our data protection is woefully inadequate. While we wouldn't leave 100 million barrels of oil unguarded, we routinely leave 100 million customer records poorly defended.
Human trafficking generates approximately $32 billion annually for Crime, Inc., with online technologies dramatically expanding its reach. In the United States alone, nearly 200,000 children are sex-trafficked, with pimps earning $150,000-$200,000 per child annually. About 70% of child trafficking survivors report being advertised online and forced into up to 20 sexual encounters daily.
A gruesome black market for human organs thrives online, with kidneys fetching up to $200,000, hearts $120,000, livers $150,000, and even eyeballs $1,500. These parts come from both the dead (through grave robbing and corrupt mortuaries) and the living poor, who are targeted online. With over 100,000 Americans waiting for kidney transplants, wealthy patients seek overseas "donors" through organ brokers who connect buyers and sellers across continents.
Modern burglars have evolved beyond watching for piled-up newspapers or darkened porch lights to identify vacant homes. Today's tech-savvy criminals monitor social media for vacation announcements and location check-ins to identify prime targets-a practice dubbed "Burglary 2.0." In Nashua, New Hampshire, police uncovered a crime ring that monitored Facebook updates before executing over 50 break-ins, stealing nearly $200,000 in property. A UK study found 78% of convicted burglars admitted using Facebook, Twitter, and Foursquare to identify targets, while also employing Google Street View to scout properties and plan escape routes.
Metadata embedded in online photos presents another vulnerability. Images posted on platforms like Craigslist or eBay often contain hidden GPS coordinates showing exactly where the photo was taken-typically the seller's home. One Indiana couple learned this lesson the hard way when they posted photos of electronics they were selling online, then announced on Facebook they'd be attending a concert. Thieves used this information to time their break-in, stealing the advertised items plus additional valuables while knowing the owners would be away for hours.
Глава 7
Mobile Vulnerabilities: The Snitch in Your Pocket
Our mobile phones have become our most intimate computing devices-and our most vulnerable. As security expert Evgeny Morozov notes, they're "one of the most insecure devices that were ever available." The tragic case of 13-year-old murder victim Milly Dowler illustrates this vulnerability, when reporters from Rupert Murdoch's News of the World hacked her voicemail after her disappearance, deleting messages and giving false hope to her family.
Mobile phones have become our computers of choice while simultaneously being our most vulnerable devices. These "snitches in our pockets" broadcast our activities and locations constantly. Their software is easily subverted, risks poorly understood, and protection systems underdeveloped. Modern malware can activate microphones, cameras (without indicator lights), and location tracking without user knowledge. By 2014, McAfee had identified nearly four million distinct pieces of mobile malware-a 614% increase in just one year.
Criminal organizations have infiltrated app stores, creating malicious applications that steal user data. Despite hosting over a million apps each, both Google's Android and Apple's App Store rely primarily on automated algorithms rather than human verification for security screening. By 2013, more than 42,000 apps in Google's store contained spyware and Trojans targeting financial information. Banking malware exploded from just 67 Trojans in 2012 to over 1,300 by 2013, targeting customers of major institutions like Citibank, HSBC, and Barclays.
Seemingly innocent apps often serve as data theft mechanisms. That popular flashlight app requesting access to your contacts, location, and other unrelated permissions is likely harvesting your personal information. In Android's ecosystem, users can't deny specific permissions while installing an app-it's all or nothing. Most users blindly accept these permissions without considering the implications. Criminal developers exploit this to commit fraud, particularly through premium-rate SMS scams. Three-quarters of all cell-phone malware sends fraudulent premium messages costing users $10 each.
GPS tracking capabilities make mobile phones valuable tools for criminals and stalkers. Location-based dating apps like Tinder have exposed security vulnerabilities allowing users' real-time locations to be pinpointed within five feet. Such precise location data, whether leaked through legitimate apps or harvested by malicious ones like "Girls Around Me," provide dangerous tools for stalkers, rapists, and child predators. Australian police have specifically warned about pedophiles exploiting these location-tracking features to target potential victims.
Cloud computing has fundamentally changed how we store our most sensitive data. Rather than keeping information on local hard drives, we now entrust our emails to Google, photos to Instagram, and documents to Dropbox. This massive aggregation of data creates a perfect target for criminals-instead of hacking individual computers, they can now focus on a single repository holding millions of accounts.
Глава 8
The Internet of Vulnerable Things
The Internet of Things (IoT) represents a fundamental shift where the physical and digital worlds merge completely. MIT researcher Kevin Ashton coined the term in 1999, envisioning objects equipped with identifiers and wireless connectivity that could communicate with each other and be managed by computers. The scale of this transformation is staggering. IPv6 has expanded the Internet's addressable space from 4.3 billion connections to 340 undecillion possible addresses-enough to assign unique addresses to every atom on Earth with plenty left over. By 2020, Cisco estimates 50 billion things will be connected to the Internet, creating what McKinsey predicts will generate $6.2 trillion in economic value by 2025.
While this connectivity creates tremendous possibilities, it also introduces significant vulnerabilities. The rapid expansion of connected devices has created an enormous attack surface with billions of potential entry points for hackers. Many of these devices are being rushed to market with minimal security testing, creating what security experts call "the Internet of Vulnerable Things." As everyday objects become networked computers, they inherit all the security challenges of traditional computing while adding new risks unique to their physical functions.
Modern cars have transformed from mechanical vehicles into computers on wheels, with 70-100 onboard computers managing everything from engine performance to entertainment systems. These electronic control units contain nearly 100 million lines of code (compared to just 1.7 million in an F-22 fighter jet) and account for 50% of a new vehicle's cost. While these systems provide conveniences like BMW's self-diagnosing TeleServices and GM's OnStar emergency response, they create serious privacy and security concerns. Cars continuously track your location, speed, seatbelt use, and driving habits. As Ford's VP admitted, "We know everyone who breaks the law, we know when you're doing it."
The real danger comes from hackers. Nearly half of London's 89,000 stolen vehicles in 2013 were electronically hacked using devices available on criminal marketplaces. More alarmingly, security researchers have demonstrated how attackers can remotely seize control of moving vehicles through various entry points-from MP3 files to Bluetooth connections. With just a $30 device plugged into a car's diagnostic port, hackers can control lights, locks, steering and brakes from anywhere in the world.
The smart home market is booming with Apple's HomeKit allowing users to control lights, locks and thermostats through voice commands to Siri. While convenient, these systems introduce unprecedented security risks-70% of IoT devices contain an average of 25 unique security flaws. Hackers can exploit these vulnerabilities to access your home network, lock you in or out demanding ransoms, or spy through cameras. Even toys aren't safe, with Wi-Fi enabled dolls being hacked for surveillance. Smart lighting systems like Philips Hue can be remotely controlled by attackers, and devices like the Conversnitch lamp can secretly record conversations.
Глава 9
Organized Crime, Inc.: The Business of Digital Theft
Modern cyber-criminal organizations mirror legitimate corporate structures with sophisticated management hierarchies. According to undercover operations and security intelligence firms, these criminal enterprises operate with remarkable business efficiency.
The CEO provides the vision and seed capital, connecting various criminal elements without directly participating in attacks. Supporting executives include the CFO (tracking metrics, managing finances and money laundering), CIO (maintaining bulletproof servers and encrypted communications), and CMO (creating effective criminal advertising).
Middle management oversees operations and the criminal workforce, while "worker bees" distribute malware and deploy credit card skimmers. An R&D department hunts for exploitable software vulnerabilities, while skilled coders and engineers develop the malware, ransomware and scareware that powers their operations.
Quality assurance teams test malware against antivirus programs using tools like avcheck.ru to ensure undetectability. When security firms identify their malware, QA receives alerts to quickly modify code and maintain effectiveness.
The backbone of these operations are affiliate networks (called "Partnerkas" in Russia) that drive traffic to criminal websites through spam, social media, and chat forums. These affiliates can earn up to $5,000 daily or $300,000 monthly. Technical support helps both employees and affiliates with operational issues, while HR recruits criminal talent through underground portals and even legitimate job sites, sometimes hiring unwitting "mules" through ads promising flexible work-from-home opportunities.
To access the digital underground's hidden marketplaces like Silk Road, users need specialized tools that mask their identity. Tor (The Onion Router) serves as this digital passport, routing connections through thousands of global servers to hide users' locations and identities. While originally developed by the U.S. Naval Research Laboratory to help political dissidents communicate safely, criminals have overwhelmingly adopted Tor for illicit purposes. Studies suggest between 50-85% of Tor's hidden services involve criminal activity, with approximately 300,000 criminals using the network daily.
Bitcoin, invented in 2009 by the mysterious "Satoshi Nakamoto," has become the digital underground's currency of choice. Limited to 21 million coins total and created through complex mathematical "mining," Bitcoin allows anonymous transactions without fees. Though legitimate businesses increasingly accept it, Bitcoin's pseudonymous nature makes it ideal for criminal transactions across the Dark Web.
Crime, Inc. has mastered automation, allowing criminals to gain the same efficiencies and cost savings that legitimate businesses achieve through technology. This automation enables hackers to rob not just one person but 100 million simultaneously, as seen in the Sony PlayStation and Target breaches. Exploit kits like Blackhole and SpyEye commit crimes "automagically" with minimal human intervention, dramatically reducing costs while pursuing the "long tail" of opportunity-millions of small thefts that victims rarely report and law enforcement cannot track.
Глава 10
Surviving Progress: Building a Secure Future
Despite the overwhelming scale of cyber threats, there's hope in one fact: good people vastly outnumber the bad. This advantage remains largely untapped. While Crime, Inc. expertly crowdsources attacks-like the 2013 ATM heist netting $45 million through 36,000 transactions across 27 countries in just 10 hours-we lack equivalent public safety responses.
Security researcher Dan Kaminsky observes we're "living through Code in the Age of Cholera." While perfect software is impossible, we're only at 50% of where we could be according to expert Charlie Miller. Even improving to 70-80% would dramatically enhance computer security.
Incentives need realignment. Currently, hackers who find vulnerabilities can either sell them on the black market for significant profit or report them to vendors for little reward while risking prosecution. Bug bounty programs exist but pay far less than criminal markets. Creating well-funded vulnerability reporting systems would help minimize damage from rushed, insecure code.
When you click "accept" on those lengthy terms of service, you agree to use software "as is" with all liability falling on you. Companies use language like "you will hold harmless and indemnify us" from any claims arising from their services. Unlike automobiles that can be sued for faulty parts causing crashes, software companies have carved out an exception from responsibility. This isn't about creating excessive regulation, but drawing a line against reckless disregard for consequences of knowingly releasing vulnerable software.
Passwords can no longer protect us. Even complex 25-digit passwords with mixed characters offer limited protection, and most people don't bother-"123456" and "password" remain the most popular choices. Fifty-five percent of people use the same password across websites, and 40% don't use any password on their smartphones. With advanced computing power and crimeware, over 90% of passwords can be cracked within hours. Crime organizations like Russia's CyberVor have amassed over 1.2 billion credentials. Our username/password system is utterly broken.
We face a technical literacy crisis. In our gadget-filled world, only a tiny portion of the population understands how these technologies actually work. Those who can code will hold power over those who can't, just as literacy separated classes in previous centuries. While not everyone needs to become a programmer, citizens need basic technological understanding to protect themselves. Simple knowledge-like covering a webcam with a Post-it note-could prevent devastating privacy violations.
Cybersecurity is fundamentally a people problem. No technical solution can overcome human error-whether it's writing passwords on sticky notes, falling for Nigerian prince scams, or oversharing vacation plans on social media. According to IBM Security Services, 95% of security incidents involve human error. The human factor can undermine all technological security measures. Even the NSA's sophisticated systems were subverted by Edward Snowden, and Iran's air-gapped nuclear facility at Natanz was compromised when someone plugged in an infected USB drive.
The future of technological threats is already here-in hackers' laptops, foreign government buildings, and the hands of malicious actors worldwide. But all is not lost. When we ignore these problems, they only grow larger. The challenges extend beyond hacked accounts or stolen photos to the very foundation of our technological future. Tomorrow's hacks will target cars, medical devices, smart homes, and personal-care bots. We lack viable models for truly trustworthy computing-a critical failure for a computer-dependent society. By mobilizing citizens to reclaim control of our devices, we can use these tools for maximum good. Creating a better technological future requires tremendous intention and effort, but with this work, we can not just survive progress but thrive beyond imagination.