Is Mark from IT really “Mark from IT”?
Let the investigation begin.
Your customer told you “Mark from IT” told them to do it. To send the payment, share the code, install the new update. You don’t even have a Mark in IT. Who even is “Mark”? Apparently, he called your controller about a payment that didn’t go through. He’s been emailing an employee a link to fix their remote access. “Mark” is a threat actor targeting your customers, and he bought everything he needed for the job on the Dark Web. “Mark” takes his job very seriously — his margins are thin, and he’s just trying to keep up. But your fraud stack can’t even tell he’s there. Who even is he?
Register once
One form. On the case for the month.
Over October we’ll show you the exhibits, hear the testimony, assess the new toolkit, and ask the budget question underneath all of it: can you afford not to tell the Marks apart?
Testimony
We’ll be speaking about threat actors like “Mark” gaining access to business accounts and customer computers, and the consequences of a single “Mark.” Throughout the month we’ll introduce the different techniques and strategies threat actors like “Mark from IT” are using. Register once and you’re signed up for everything. If you want to have the conversation in person, meet us at ABA.
6 Oct · 11:00 a.m. ETWebinar
The “Mark” who calls: business account takeover and how the social engineering actually works
From the first message to the wire. What a compromised business account sells for relative to a consumer one, what an OTP bot service costs, and where the human step in the attack sits.
Robert Villanueva, EVP and founder, and Jess, cyber threat expert, Q6 Cyber, with a member of the U.S. Secret Service Cyber Fraud Task Force joining us.
Register once →Tue 13 Oct · 11:00–11:45 a.m. · Arlington, VAPanel
One email could cost you millions: why banks must rethink BEC controls now
The “Mark” who emails. Our CEO on the ABA Fraud & AML program, with the Secret Service and a bank fraud strategy lead, on why the controls built for the last version of business email compromise keep clearing the payment. Concurrent Sessions I. Find us at the booth the rest of the week.
Eli Dominitz, CEO, Q6 Cyber, with Alan Ottarson, technical special agent, U.S. Secret Service, and Beau Stubbs, senior director, enterprise fraud strategy, Arvest Bank. Moderated by Darrin McLaughlin, EVP and chief AML and sanctions officer, Flagstar Bank. Conference registration is through the American Bankers Association.
ABA event page →22 OctWebinar
The “Mark” who connects: remote monitoring software as an attack tool
How legitimate RMM software is used to take control of a victim’s computer, what that looks like from the institution’s side, and where the access gets sold afterward. For CISOs and fraud leaders together.
Dima Khrustalov, cyber threat intelligence team, presenting. Moderated by Jake Kruse, CISO, Q6 Cyber.
Register once →Exhibits
Q6 Cyber sits deep inside the restricted financial fraud channels, forums and storefronts that supply “Mark” with everything he needs to do his job. That means “Mark” doesn’t need to be good at this. The below exhibits are recreations directly from the Dark Web of how “Mark” gets the code, skips the call, and becomes “Mark from IT.”
Item 01 · encrypted channel
How “Mark” gets the code
unlimited calls. pay in crypto, access in 10 min.03:14
Item 02 · vendor storefront
How “Mark” skips the call
Item 03 · encrypted channel
How “Mark” gets the number and the words
delivery instant, no subscription.21:45
Item 04 · vendor storefront
How “Mark” becomes “Mark from IT”
Item 05 · encrypted channel
How “Mark” chooses who to call
escrow fine. free replacement if any are dead in 24h.11:08
Illustrative recreations. Halverton Bank, JuicyBanks4U and the channels shown are placeholders; handles, order numbers and seller ratings are invented. No real client, account, seller or channel is shown.
Chronology
We work the case backward, the way an investigator would. We start where it lands — the customer who was talked out of the money — then trace how the access was gained, how the machine was compromised, where that compromise was bought, and finally who “Mark” turns out to be.
Registrants get each item the morning it publishes.
The financial impact
Can you afford not to tell the Marks apart?
Q6 Cyber is an expert in tracking and stopping “Mark from IT.” We are best in class at looking at things from a threat actor’s perspective, which means we see the intention, the planning and the strategy well before others do. That critical time advantage is worth, on average, 15x ROI to our customers.
Check out our guide, designed to answer the most common objections and break down that ROI. Because nobody should be left wondering: is Mark from IT really “Mark from IT”?
A buyer’s guide to budgeting for Dark Web fraud intelligence
- What the free lists don’t show you
- Results by institution size
- Working the return, step by step
- The objections, answered
- The ROI model, worked through in the report
Working table of contents; final section titles may change.
Send it to meCan you afford not to tell the Marks apart? We can help.
Register once for every session, the guide, and the findings, delivered as each one is released.
Register oncePrior case files
Recording · 16 Sep
The Fraud Bazaar
Nicole Rosenzvaig and Robert Villanueva on how stolen financial data is packaged, priced and sold. A primer for the 6 October testimony.
Watch the recording →Report
Zero-Click to Full Access
How account access is obtained without the victim doing anything, and what it sells for once it is.
Read the report →Toolkit · CISA
Cybersecurity Awareness Month materials
CISA and the National Cybersecurity Alliance publish a free toolkit for staff and members each October. Use it alongside anything here.
Open the toolkit →