Chicago Yacht Club Reports Credit and Bank Account Security Breach

Chicago Yacht Club computer was reportedly compromised by Malware that exposed bank account and credit card information to rogue hackers Forensicon was provided a copy of this letter sent to certain members of the Chicago Yacht Club.   Anyone who has conducted financial transactions with the Chicago Yacht Club in the last few years should closely audit their bank statements…

Microsoft Stops Supporting Windows XP

On April 8, 2014, Microsoft stopped supporting its Windows XP operating system. Users will no longer receive technical assistance or updates. Windows XP was supported for 12 years and discontinuing its support allows Microsoft to focus its resources on Windows 8 which is currently being supported until 2023. While you can still use Windows XP, you won’t be able to…

What Are the Chances of Recovering Deleted Data?

Forensicon’s president Lee Neubecker describes factors that impact the potential for recovering deleted data.  Key factors such as the size and type of media, as well as the percentage of used versus free space available on the hard drive are discussed.  Other factors impacting the prospects for recovery include the level of usage of the device and volume of data…

US Government Spies on Cubans via Twitter Like App

In an effort to tap into the local sentiment of average Cubans, the U.S. Government sponsored the development of a social media application for cell phones called, ZunZeo. ZunZeo offered users free SMS messaging and was an alternative news outlet to many. U.S. Agency for International Aid (USAID), the U.S. Government’s outreach entity focused on fostering economic development and well…

Capture Image of FileVault2 Encrypted Media With Recovery Key

Objective The purpose of this walkthrough is to demonstrate how to successfully decrypt and gain access to a FileVault® 2 protected volume when the recovery key or passphrase is known in order to capture a forensic image for analysis. Tools Used EnCase® v6.18 MacQuisition™ FTK® Imager Mac OS® Terminal Note: MacQuisition 2013 R2 now supports auto-detection of FV2 protected volumes…

Proposed Non-Compete Agreement Act of Illinois

State laws all vary as to whether employees are by default at will employment, by agreement, or another variation of the two.  In all states, employees could be contracted to do work.  Generally, the higher level the employee the more likely that the employer will include a “non-compete agreement” as part of the employee contract. A non-compete agreement can be…

Coming Soon: Major Changes to E-Discovery Rules

In 2014, we may find ourselves teetering on the edge of some major amendments to the discovery provisions of the Federal Rules of Civil Procedure. Just this month, the United States Courts’ Advisory Committee on Civil Rules voted to send proposed amendments to its Standing Committee on Rules and Practice and Procedure. Their recommendation is that these proposed amendments be…

How to Overcome Google’s Failure to Respond to Foreign Subpoenas

Despite having an active litigation matter where discovery of Google Drive (formally Google Docs) or Gmail is needed to complete discovery, you may have recently received a notice from Google that says they will not respond to your subpoena unless it is served upon them in their local jurisdiction. This might have you and your client questioning if it is…

Voters Beware of Potential Electronic Voting Fraud

As voters head to the polls to vote, Forensicon Inc’s President, Lee Neubecker, advises those to select a paper ballot if afforded the opportunity.  While reviewing Cook County, Illinois’ Request For Proposal (RFP) for a Forensic Audit of Election Equipment last year, Forensicon identified potential weaknesses in the current electronic voting equipment used by Cook County, Illinois for elections. There…

Cell Phone & Email Forensics Investigation Cracks NYC Times Square Car Bombing Case

NEW YORK CITY: May 4th, 2010: Faisal Shahzad thought he was doing a pretty good job covering his tracks as he began his quest to detonate a homemade bomb in Times Square on a busy Saturday evening. Shahzad took a number of steps including removing the VIN number from the Nissan Pathfinder he purchased on Craigslist. Authorities were able to…