Brian Krebs
Brian Krebs (born in Alabama in 1972) is an American journalist and investigative reporter. Krebs is the author of KrebsOnSecurity.com, a daily blog on computer security and cybercrime. From 1995 to 2009, Krebs was a reporter for The Washington Post, where he covered tech policy, privacy and computer security, and authored the Security Fix blog [1]
Contents |
[edit] History
Krebs started his career at The Washington Post in the circulation department. From there obtained a job as a copy aide in the Post newsroom, where he split his time between sorting mail and taking dictation from reporters in the field. Krebs also worked as an editorial aide for the Editorial Department and the Financial Desk. In 1999, Krebs went to work as a staff writer for Newsbytes.com, a technology newswire owned by The Washington Post.
When the Post sold Newsbytes in 2002, Krebs transitioned to Washingtonpost.com in Arlington, VA. as a full-time staff writer. Krebs's stories appeared in both the print edition of the paper and Washingtonpost.com. In 2005, Krebs launched the Security Fix blog, a daily blog centered around computer security, cyber crime and tech policy. In Dec. 2009, Krebs left Washingtonpost.com and launched KrebsOnSecurity.com.
Krebs earned a B.A. in International Relations from George Mason University in 1994.
[edit] Career
Most recently, Krebs has focused his reporting on the fallout from the activities of several organized cybercrime groups operating out of Eastern Europe that have stolen tens of millions of dollars from small to mid-sized businesses through online banking fraud[2]. Krebs has written more than 75 stories about small businesses and other organizations that were victims of online banking fraud, an increasingly costly and common form of cybercrime.
He is perhaps best known for a series of investigative stories that culminated in the disconnection or dissolution of several Internet service providers that experts said catered primarily to cyber criminals. In August 2008, a series of articles Krebs wrote for The Washington Post's Security Fix blog led to the unplugging of a Northern California based hosting provider known as Intercage or Atrivo[3].
During that same time, Krebs published a two-part investigation on illicit activity at domain name registrar EstDomains, one of Atrivo's biggest customers, showing that the company's president, Vladimir Tsastsin, recently had been convicted of credit card fraud, forgery and money laundering[4]. Two months later, the Internet Corporation for Assigned Names and Numbers (ICANN), the entity charged with overseeing the domain registration industry, revoked EstDomains' charter, noting that Tsastsin's convictions violated an ICANN policy that prohibits officers of a registrar from having a criminal record[5]. In Nov. 2011, Tsastin and five other men would be arrested by Estonian authorities and charged with running a massive click-fraud operation with the help of the DNS Changer Trojan[6].
In November 2008, Krebs published an investigative series that led to the disconnection of McColo, another Northern California hosting firm that experts said was home to control networks for most of the world's largest botnets[7]. As a result of Krebs' reporting, both of McColo's upstream Internet providers disconnected McColo from the rest of the Internet, causing an immediate and sustained drop in the volume of junk e-mail sent worldwide. Estimates of the amount and duration of the decline in spam due to the McColo takedown vary, from 40 percent to 70 percent, and from a few weeks to several months[8].
More recently, Krebs is credited[9] with being the first journalist to report on the malware that would later become known as Stuxnet[10].
[edit] Selected articles from The Washington Post
- "The Long and the Short of Microsoft's Patches", January 16, 2006
- "Paris Hilton Hack Started with Old-Fashioned Con", May 19, 2005
- "Hackers Found Hilton's Phone An Easy Target", May 19, 2005
- "Data Thefts May Be Linked: Warrants served in LexisNexis Account Breach", May 20, 2005
- "Hijacking a MacBook in Sixty Seconds" August 2, 2006
- "Internet Explorer Unsafe for 284 Days in 2006", January 4, 2007
- "Tracking the Password Thieves", March 14, 2007
- "They Told You Not to Reply", March 21, 2007
- "Mapping the Russian Business Network", October 13, 2007
- "Report Slams U.S. Host As Major Source of Badware", August 28, 2008
- "EstDomains: A Sordid History and a Storied CEO", September 8, 2008
[edit] Awards and recognition
- 2011 Security Bloggers Network, "Blog That Best Represents the Industry" [11]
- 2010 SANS Institute Top Cybersecurity Journalist Award[12]
- 2010 Security Bloggers Network, "Best Non-Technical Security Blog"[13]
- 2009 Winner of Cisco Systems' 1st Annual "Cyber Crime Hero" Award[14]
- 2005 CNET News.com listed Security Fix as one of the top 100 blogs, saying "Good roundup of significant security issues. The Washington Post's Brian Krebs offers a userful, first-person perspective".[15]
- 2004 Carnegie Mellon CyLab Cybersecurity Journalism Award of Merit[16]
[edit] Recent media appearances
Krebs is a frequent speaker on computer security and cybercrime topics. In Oct. 2011, he gave keynote addresses at Govcert.nl in Rotterdam[17]; Secure 2011 in Warsaw, Poland[18]; SecTor 2011, in Toronto, Canada[19]; and FIRST 2011 in Vienna, Austria[20].
[edit] References
- ^ http://voices.washingtonpost.com/securityfix
- ^ http://krebsonsecurity.com/category/smallbizvictim
- ^ http://voices.washingtonpost.com/securityfix/2008/08/report_slams_us_host_as_major.html
- ^ http://voices.washingtonpost.com/securityfix/2008/09/estdomains_a_sordid_history_an.html
- ^ http://voices.washingtonpost.com/securityfix/2008/10/icann_de-accredits_estdomains.html
- ^ http://www.justice.gov/usao/nys/vladimirtsastsin.html
- ^ http://voices.washingtonpost.com/securityfix/2008/11/major_source_of_online_scams_a.htm
- ^ http://cbl.abuseat.org/mccolo.html
- ^ //www.vanityfair.com/culture/features/2011/04/stuxnet-201104
- ^ http://en.wikipedia.org/wiki/Stuxnet
- ^ https://365.rsaconference.com/blogs/security-blogger-meetup/2011/01/10/and-the-winners-are
- ^ http://www.sans.org/top-journalists/
- ^ ttps://365.rsaconference.com/blogs/security-blogger-meetup/2010/03/04/theyre-all-winners
- ^ http://www.cisco.com/en/US/prod/collateral/vpndevc/cisco_2009_asr.pdf
- ^ News.com's Blog 100 | CNET News.com
- ^ 2004 Cybersecurity Journalism Awards :: CyLab
- ^ http://www.govcert.nl/symposium/Symposium+2011/Programme/day1.html
- ^ http://www.secure.edu.pl/en/agenda.php
- ^ http://sector.ca/schedule.htm
- ^ http://conference.first.org/2011/program/index.aspx"