Showing posts sorted by relevance for query bbb phishing. Sort by date Show all posts
Showing posts sorted by relevance for query bbb phishing. Sort by date Show all posts

Wednesday, February 14, 2007

Spoofed (counterfeit) BBB e-mails contains virus

If you get an e-mail from the Better Business Bureau stating you have received complaints don't click on the link to view them.

Annys Shinn (Washington Post) is reporting:

The Better Business Bureau network was the target of a "spoofing" scam yesterday in which thousands of businesses in the United States and Canada received e-mails encouraging them to download what is thought to be a computer virus.

The e-mails, using the name of the 95-year-old network of nonprofit groups that looks into consumer complaints, told businesses that they were the subject of a complaint and included a link to view related documents. Clicking on the link, however, accessed the address book of an infected computer and distributed the counterfeit e-mail to more recipients, said Steve Cox, spokesman for the Council of Better Business Bureaus.

Washington Post article, here.

Wandering to the BBB site to see what they had to say, I found a little more information. Apparently, if you click on the link, it downloads an executable file, believed to contain a virus.

The BBB and others are calling this a phishing attempt, but in phishing the intent is normally to get the user to provide personal, and or financial information to the sender. Since this doesn't seem to be the case, and no one is saying exactly what the executable file (virus) is, this doesn't appear to be phishing.

It will be interesting to see exactly what this executable file does, but some computer viruses (crimeware and malware) download keyloggers, which log a person's keystrokes and are used to steal personal and financial information.

Other computer viruses might turn a computer into a zombie, which allows someone else to use it for their own purposes (sending spam or denial of service attacks). Zombie computers are formed into what is known as botnets (groups of zombie computers), which are used for illicit purposes by their "controller."

You can download a lot of nasty things by clicking on something from someone you don't know. And the people behind it like to spoof well known entities, such as the BBB. Organizations from eBay to the FBI have been spoofed in the past.

Example of spoofed e-mail from the BBB site:

From: operations@bbb.org [mailto:operations@bbb.org]
Sent: Tuesday, February 13, 2007 6:06 AM To: XXXX
Subject: BBB Case #263621205 - Complaint for XXXX

Dear Mr./Mrs. XXXX

You have received a complaint in regards to your business services. The complaint was filled by Mr. XXXX on 02/05/2007/

Use the link below to view the complaint details:

DOCUMENTS FOR CASE #263621205

Complaint Case Number: 263621205
Complaint Made by Consumer Mr. XXXX Complaint
Registered Against: Company XXXX
Date: 02/05/2007

Instructions on how to resolve this complaint as well as a copy of the original complaint can be obtained using the link below:

DOCUMENTS FOR CASE #263621205

Disputes involving consumer products and/or services may be arbitrated. Unless they directly relate to the contract that is the basis of this dispute, the following claims will be considered for arbitration only if all parties agree in writing that the arbitrator may consider them:
- Claims based on product liability;
- Claims for personal injuries;
- Claims that have been resolved by a previous court action, arbitration, or written agreement between the parties.

The decision as to whether your dispute or any part of it can be arbitrated rests solely with the BBB.

The BBB offers its members a binding arbitration service for disputes involving marketplace transactions. Arbitration is a convenient, civilized way to settle disputes quickly and fairly, without the costs associated with other legal options.

Tuesday, June 05, 2007

Spear phishermen target executives to steal company information

Shamus McGillicuddy of CIO News highlights an interesting fact, which is you never know, who is going to fall for a phishing scam.

The phishermen normally send out a lot of bait (spam) in the hopes of hooking a few phish.

Shamus writes:

Over the last week and a half, spam messages purported to be from the Internal Revenue Service and the Better Business Bureau have been specifically targeting senior-level corporate executives with phishing scams.

Experts say these targeted phishing attacks, sometimes called "spear phishing," are nothing new, but they illustrate that spammers are getting more adept at targeting sophisticated email users who have access to the most sensitive data within their companies.
Spear phishing is simply a more focused form of phishing, which uses more personal touches, such as a person's real name, and or title.

With all the information plastered over the Internet, or available for sale; it isn't hard for phishermen to get what they need (personal information) to go spear phishing.

Many private companies and government organizations recognize the danger phishing poses in the workplace. To counter this, and raise awareness; they are phishing their own employees.

Recently, I did a post about this, which revealed more employees fall for this, than many would like to admit:

Technology alone isn't going to stop phishermen and other cyber ghouls on the Internet

There seems to be more and more phishing out there, which might be inspired by DIY (do it yourself) kits being sold over the Internet. DIY kits make it easy for not very sophisticated criminals to become expert phishermen.

The only good news about phishing is that with a little awareness, most people can spot this activity, because the phishing ploy doesn't make much sense, or is too good to be true.

CIO News story, here.

BBB Alert, here.

IRS Alert, here.

Saturday, September 02, 2006

CastleCops PIRT Reports New Version of eBay Phishing

Castle Cops, PIRT-Phishing Incident Reporting and Termination Squad is reporting a new type of phishing attempt with an eBay lure:

CastleCops PIRT has received a new email which tries to get people's full personal information including name, age, location, telephone numbers, gender and marital status on the offer of getting paid to work from home online for a company called "eBay Small Business Limited". Its business is in "manufacturing and selling textiles and fabrics". The email tries to goad you into giving up your personal information with the promise of making easily $300 to $1,000 per week simply by collecting payments on behalf of the Company (all for 3-7 hours per week).

Link, here.

Besides a new type of phishing attempt - this could turn into what is termed a "check cashing scam." In a "check cashing, or job scam," a person is recruited to handle "accounts receivables," which are in reality tied into fraudulent transactions.

The new employee's job is to negotiate transactions sent to them, and wire the money to a far-away locale. The fraudsters (in most instances) instruct the "new employee" to use Western Union, or MoneyGram, which aren't protected by the FDIC.

The transactions are normally "account takeovers" on eBay - also caused by phishing. In an "account takeover" a legitimate eBay user gives up their information as a result of a "phishy e-mail." The Phishermen then take over their account and sell items, which are paid for, but (normally) never received.

Towards the end of the fraud cycle, the fraudsters might also get their employee to negotiate (cash) totally bogus financial instruments. Of course, when the bottom falls out of this, the fraudsters can then steal the identity of the employee involved - having gathered all the information to do so via the employment process.

For the person - who falls for this - although they get the generous commission at first - they are likely going to be hounded for a long time by collection agencies and in some cases, law enforcement.

Believe it, or not - a Better Business Bureau employee fell for this scam. Here is the post, I did on that:

BBB Worker Takes Job Processing Fraudulent eBay Transactions

By the way, PIRT is a great place to "take a bite out of phishing." You can report suspected "phishy e-mails" to them by forwarding them to PIRT@CastleCops.com. After verifying the "phish," they make sure it gets to all the right people!

Tuesday, November 20, 2007

DOJ is the latest badge of authority phishermen are using to net victims


This is the DOJ banner used in the screenshot of the phishy e-mail Websense is reporting. Please note, in this instance, I merely copied it right from the DOJ website. With minimal knowledge, just about anyone can do this with any picture from a website.

Apparently, Websense deserves credit for discovering a Trojan downloader pretending to be a e-mail from the Department of Justice (DOJ). Clicking on this attachment is likely to turn your computer into a zombie (part of a botnet) used to send more spam, or even worse used to steal information stored on your computer.

This might turn you into an identity theft statistic, depending what personal and financial information you store on your computer.

Here is the alert from Websense:

Websense® Security Labs™ has discovered a new email attack variant similar to attacks previously launched on the IRS and Better Business Bureau. The spoofed email claims to be from the United States Department of Justice (USDOJ). We have been tracking these attacks and have previously reported on them on our site.

The message claims that a complaint to the USDOJ has been filed against the recipient's company. The email informs the reader that a copy of the original complaint has been attached to the email.

The attached "complaint" is a Trojan Downloader .scr file with an MD5 of aeb784bc17c4c7e6edc5f1faaa9ed24f.

None of the major anti-virus vendors detected the malicious code.

Websense Security customers are protected from this threat.

In the e-mail Websense used as an example, it refers to a specific company. This means that this attack is possibly directly targeting people, who are associated with this company. This type of more directed attack has is now being referred to as spear phishing.

Spoofing (impersonating) government agencies is nothing new. The Phishermen use the badge of authority the name of these agencies invoke to trick people into clicking on the attachments in their spam e-mails.

The warning from Websense mentions that the IRS (Internal Reveue Service),BBB (Better Business Bureau) and many others have had had their badges of authority used to lure victims into the Phishermen's web.

I was unable to find a recent press release on this directly from DOJ, however a press release on a similiar attack using DOJ's name was released in June.

In it they speak to the fact that DOJ would never send a communication of this nature via e-mail:

The Department of Justice did not send these unsolicited email messages—and would not send such messages to the public via email. Similar hoaxes have been recently perpetrated in the names of various governmental entities, including the Federal Bureau of Investigation, the Federal Trade Commission, and the Internal Revenue Service. Email users should be especially wary of unsolicited warning messages that purport to come from U.S. governmental agencies directing them to click on file attachments or to provide sensitive personal information.

These spam email messages are bogus and should be immediately deleted. Computers may be put at risk simply by an attempt to examine these messages for signs of fraud. It is possible that by “double-clicking” on attachments to these messages, recipients will cause malicious software – e.g., viruses, keystroke loggers, or other Trojan horse programs – to be launched on their computers.

Do not open any attachment to such messages. Delete the e-mail. Empty the deleted items folder.

If you have received this, or a similar hoax, please file a complaint at http://www.ic3.gov/.
In this memo, they also offered some educational resources, which I highly recommend if you are unfamiliar with how the dark side of the Internet works:

Consumers can learn more about protecting themselves from malicious spyware and bogus e-mails at OnGuardOnline.gov, a Web site created by the Department of Justice in partnership with other federal agencies and the technology industry to help consumers stay safe online. The site features modules on spyware and phishing, at http://onguardonline.gov/spyware.html and http://onguardonline.gov/phishing.html.

Current Websense alert, here.

June alert from DOJ on similar attack, here.

Tuesday, February 05, 2019

Better Business Bureau Tool to Track, Report and Educate the Common Person on Scams

The BBB Scam Tracker is a robust interactive tool to track fraudulent activity in throughout North America. The data I viewed from Mexico seems to be minimal at this point, although this might be because Mexico was added after the United States and Canada.

The site collects data from users, who were the victims of a scam, or from smart people who figured out someone was trying to scam them.

The tool enables the user to search potential fraudulent activity by keyword, type of scam, location, and time frame. Please note that scams are most successful when they hit a new geographical area because the "word is not out yet." Because of this, scammers frequently travel and even rotate the particular scam in order to catch innocent people/businesses off guard. Just because the particular scam is not showing up in your geographical area doesn't mean that it won't knock on your doorstep tomorrow.

The scam activities tracked include home repair, tree trimming, tax, advance fee, job, lottery, collection, counterfeit checks, bogus credit cards, vishing, phishing, and identity theft. There is even an "other" category to cover anything that is a previously unknown activity. New scams are hatched all the time. The main thing all scams have in common is that they are "too good to be true."

The data collected is provided to the National Cyber-Forensics and Training Alliance, who in turns shares it with law enforcement, 

Here is a link to the BBB Scam Tracker. Scammers count on people not taking the time to report their activity (assuming they do not fall for it). Reporting it is a good deed because it protects other people.

The BBB also has a video on YouTube on this tool, if you would like to watch it.

Thursday, April 13, 2006

BBB Worker Takes Job Processing Fraudulent eBay Transactions

A Better Business Bureau worker was recently involved in eBay fraud by taking a part-time (work-at-home job) processing account receivables for criminals from Eastern Europe. According to her, she even checked them out before accepting the job and found nothing that would suggest a scam.

The job was to process payments (primarily from eBay transactions) and wire the money to her employers.

These scams, known as check-cashing schemes solicit people to process fraudulent financial instruments and wire the money to a far-away locale. Their employers normally prefer the use of Western Union, or Money Gram, which offer little to no protection once the money is sent.

News clip from 9News.com in Denver, here.

There is also another version of the work-at-home scam, which entails receiving the stolen merchandise and then reshipping it.

In work-at-home (check cashing) schemes, the worker is normally instructed to set up an account (using their information and good credit) to process the financial instruments. Quite often, they are held financially responsible after the financial instruments are discovered fraudulent and they have wired the money.

No matter what the scam entails, the fraudsters always prefer "unprotected" methods of wiring money. I would highly recommend NEVER wiring money to someone you don't know, or haven't done a lot of business with for a LONG TIME.

To add to the confusion many auction fraud victims buy merchandise from seemingly highly rated sellers when their account is taken over. Account takeovers are normally accomplished via phishing, where a legitimate account holder is duped into giving up their account information.

Phishy e-mails from eBay and PayPal are circulating the internet at a record rate.

Interesting that the BBB worker was savvy enough to do a little "due diligence" on the scam company, which revealed nothing. When I looked at their site, I found two articles that describe activity very similiar to this.

Work-at-Home Schemes

Work-At-Home-Schemes Now Peddled On-Line

I wasn't able to find an article on the BBB regarding "check cashing schemes," but in reality this scam is nothing more than a "mutation" of the "work at home" scheme.

I'd offer to write it for them, but after writing this post, I doubt they will solicit my services.

It's becoming quite common for organized gangs to set up fraudulent businesses as a front for the various scams out there. They are often complete with office space, telephones and even web sites.

I guess the moral of the story is that when a business has no verifiable track record a prudent person should dig a little deeper? I stole that one from my friend Paul, who writes prying1.

Let's face it, processing proceeds from auctions using your own account and wiring the money to Eastern Europe seems a little risky. At least to me, it does.

Sunday, June 04, 2006

Cyber Gangs Luring Children to Launder Money

In Australia, a Triad (Chinese Organized Crime Gang) with ties to Malaysia and Russia recruited children to launder money, stolen as a result of "phishing" schemes. Teenagers and a few "20 something" types were recruited to receive the stolen funds in their own bank accounts. They would then turn over the money (minus a commission) to low level members of the gang, who would wire the money overseas.

Unfortunately, it appears from the article I read in the Sydney Herald by Frank Walker that no one at the higher echelons of the gang was apprehended.

For the full story from the Sydney Herald, link here.

Please note that the Australian authorities are prosecuting the individuals involved.

Criminal gangs involved in cyber-crime recruit people to launder the money from financial crimes all the time, and it doesn't only happen in Australia. In fact, evidence shows it is a worldwide issue that is getting worse all the time.

I recently wrote a post about a BBB (Better Business Bureau) employee, who was recruited to do pretty much the same thing:

BBB Worker Takes Job Processing Fraudulent eBay Transactions

Cyber crooks recruit people in chat rooms and even surf jobs sites like Monster.com looking for what they consider "dupes" to take all the "risks" for them. It appears (from this story) that they aren't above using our children to commit their "foul deeds."

Before accepting any job offers from an unknown source on the Internet, it's smart to do your homework. This is especially true, if you are asked to use your own financial resources to negotiate any financial transaction. Furthermore, if any of the above factors "ring true" and you are asked to "wire" money run away from the deal as fast as you can.

Here is a pretty good resource to educate yourself (and others) on Job Scams:

World Privacy Forum

Wednesday, July 07, 2010

Phony Collectors Want Your Credit/Debit Card Information

About a week ago, I was made aware of a fraud group operating from a Tampa, Florida number, who were calling people and using some pretty heavy-handed tactics to collect (steal) money. Interestingly enough, the person that let me know about this had never done business with the company being impersonated.

Please note, there might be a reason for alarm even if you don't think you owe a debt and a collector calls. With more and more people becoming identity theft victims, a call from a collector could be the first notification a person gets that someone else is using their information. Of course, in this instance, since the calls were bogus, it was not the case. In fact, if you give these scammers any information they can use, you will likely become an identity theft victim yourself.

The person who provided me with this information also provided me with the number she was called from. I called the number and, after a slight delay, I got a person with a Indian accent, who identified himself as "William Scott" from ACS, Inc. Leading him on, I told him my wife was always getting us into trouble by borrowing money — and that we had received a message to call them. He asked me for my wife's name and I made one up. He then told me to wait a minute, while he looked up the file. After about a minute, he said he had located the file and that she owed $500.00, and said this was a "serious legal issue we needed to get cleared up right away." He even offered to settle for $300.00, if I paid that day with a debit/credit card.

During my conversation with William, I could hear the chatter of other calls being made. Listening carefully, I noted that all the people, "chattering" in the background seemed to have Southern Asian (probably Indian) accents. This leads me to believe that the call was being forwarded, possibly overseas. This is not hard to do and there are a lot of legitimate call centers where callers are forwarded from a local number, all over the world.

I gave him an e-mail address so he could send me a payment authorization form and he told me to fill it out, sign it and e-mail it back to him. About an hour later. I got the form coming from an e-mail address, acscorpusa@gmail.com. It asked for personal identifiers, the card number, billing address, zip code, expiration date and CVC number. There is very little doubt in my mind if I had sent the form back to him the account I gave them would have been promptly cleaned out.

I ran the number (813-434-4611) on a site called PhoneValidator.com, which tells you what company a number belongs to and if it is a cell phone or a landline. This number belongs to a PaeTec Communications in Tampa, Florida. PhoneValidator.com offers two additional tools after you run the number. One is primarily a paid search (how they make money), but they offer Google results, also. When I ran the Google results, it identified the same scam, I had run into. One site, 800notes.com, had quite a few comments about it.

The payment authorization letter listed a fax number of 646-786-4401. I ran that number and it went to a landline in New York. Again, I ran the Google results, which revealed more people getting faux collection calls. Besides the fax number on the authorization letter — designed to clean out a payment card — was another number (813-435-1963) to call them back. Although, it was another Tampa number, it went to different telecom outfit. By running the Google results, lo and behold, more complaints about phony collection calls were found, some of which stated that some pretty crude and disgusting comments were made by some of these fake collectors.

Based on the comments I found, it appeared that this activity had been going for a long time, and the Indian accents seems to be a common theme. I did report this to the authorities — but besides getting an initial call back — I haven't heard anything from them since then.

It is not uncommon for scammers to set up legitimate sounding numbers, either. As long as the bill gets paid, very little due diligence is conducted by telecom types to ensure a number actually belongs to what it says it does. Sometimes the numbers are paid for with stolen financial instruments, and it is not uncommon to call one back a week later and find it has been disconnected.

I did more research on this activity and discovered that the BBB had an interesting write-up about similar (if not the same) fraudulent collection activity. The report lists 67 complaints they had received. Another write-up in August of 2009 from the BBB suggested that the scammers had so much personal information about the victims — a data breach was suspected. In this case, it was reported that the people behind this had social security numbers, addresses and knew how to contact their victim's relatives. It also stated that people were being threatened with criminal prosecution, if they did not pay.

If you are called by a collector and you do not know anything about the debt they are talking about, you should always ask them to send you documentation proving that you owe the debt. The Federal Trade Commission (FTC) has information on their site on what your rights are and the specific laws that legitimate collection agencies have to follow. You can also file an online complaint (highly recommended if you suspect abuse) and even watch a video on how to do it properly. They also provide a number (1-877-FTC-HELP (1-877-382-4357); TTY: 1-866-653-4261) if you want to speak with a live human being.

The phenomenon of fraud by telephone is becoming more and more common. Officially dubbed "vishing," which is phishing by telephone, the people behind it spoof financial institutions to gather personal and financial details to commit identity theft and financial crimes. Cheap long distance — enabled by VoIP (Voice over Internet Protocol) — and caller ID spoofing (which is legal) have made vishing pretty easy to accomplish.

If you get a phone call that doesn't make sense, take a deep breath and then make sure the person calling you is legitimate before proceeding!

Wednesday, June 20, 2007

FTC name impersonated to phish (steal information) from corporate executives

Spammers love to impersonate official agencies to hook their victims (phish). Recently, the attacks have become more specific targeting people by name, and or title. Here is a warning from the Federal Trade Commission (FTC):

Consumers, including corporate and banking executives, appear to be targets of a bogus e-mail supposedly sent by the Federal Trade Commission but actually sent by third parties hoping to install spyware on computers. The bogus e-mail poses as an acknowledgment of a complaint filed by the recipient, and includes an attachment. Consumers who open the attachment to this e-mail unleash malicious spyware onto their computer. The agency warns consumers who get this e-mail that purports to be from the FTC:

Don’t open the attachment.
Delete the e-mail.
Empty the deleted items folder.

The hoax e-mail is personalized, and contains the name of the recipient and their business. The bogus message explains how the complaint will be used, who will have access to it and states, “Attached you will find a copy of your complaint. Please print a hard copy of the complaint for your records in the upcoming investigation.” Opening the attachment downloads the malicious spyware.


The press release doesn’t specify exactly what the malicious spyware is.

Recently, the IRS and Better Business Bureau names were being used in a similar manner. In this attack, corporate executives were being specifically targeted, also. This type of attack is known as spear phishing.

Here is a post on the attack spoofing (impersonating) the IRS and BBB:

Spear phishermen target executives to steal company information

FTC release on this attack, here.

Tuesday, October 31, 2006

Panda Labs Detects Organized Job Scam in Progress

Fraudulent job offers on the Internet that are "too good to be true" are nothing new. Quite simply, they are an attempt by cybercriminals to get someone "else" to launder the proceeds of financial crimes (Internet fraud) for them.

A press release from Computer News is warning:

PandaLabs has detected the mass-mailing of messages with lucrative job offers, aimed at recruiting 'mules'. In Internet slang, 'mules' are people used to launder stolen money, mainly originating from phishing or other online fraud.
What is different about this attack is that it is "highly organized" and therefore dangerous:

According to data from PandaLabs, this is a large-scale attack, using at least 10 Internet domains, and at least seven Web servers in countries including Korea, the United States, Canada, Belgium and Spain.
A Panda employee sums up what could happen to a person getting involved in this activity:

According to Luis Corrons, director of PandaLabs: "Users should treat these supposed job offers with great caution, as they could have serious consequences, including jail sentences. Once the victim has forwarded the money, the trail leading to the real criminals is lost and the mule will be left as the sole accused in any proceedings."
Link, here.

I've written about this activity before if anyone is interested in learning more about it:

Answer a "Too Good to be True" Work-at-Home Ad and Take the Rap ...

Internet Criminals Love to Have Money Wired to Them

Cyber Gangs Luring Children to Launder Money

BBB Worker Takes Job Processing Fraudulent eBay Transactions

Tuesday, October 17, 2006

Answer a "Too Good to be True" Work-at-Home Ad and Take the Rap for the Phishermen

Ryan Naraine of eWeek did an interesting story about how the phishermen launder their ill-gotten proceeds:

"The dramatic rise in phishing and identity theft attacks includes a well-organized offline component—the not-so-innocent "money mule" recruited by fraudsters to launder stolen money across the globe."

"The ads appear innocently on all the major employment listing sites, offering stay-at-home positions titled "shipping manager," "private financial receiver" or "sales representative."

eWeek story, here.

In the article, they responded to a Craiglist Ad - where after being prompted to submit personal and financial information to the Russian Mob - a base salary of $2000.00 a month was offered, plus $50.00 for each wire transfer and or shipment successfully received by them.

I agree with the article that people involved in this "aren't always so innocent," but since all the stolen money and merchandise will be sent to the new employee -- guess where law enforcement is going to trace it to?

Here is where anyone accepting these jobs could end up.








Also mentioned in the article was that prospective employees for these mobsters are required to submit a lot of personal and financial information about themselves to "hired." My guess is that this will be used to commit even more crimes without the knowledge of the employee (identity theft).

Trust me, Boris and his merry band of "Vlads" are expert at this.

Here is a story about a Better Business Worker caught up in one of these job scams:

BBB Worker Takes Job Processing Fraudulent eBay Transactions