Showing posts with label account takeovers. Show all posts
Showing posts with label account takeovers. Show all posts

Monday, October 08, 2007

The continuing saga of Vladuz and Phishing on eBay

Here is an update to the ongoing saga of Vladuz versus eBay. Apparently, Vladuz, or someone claiming to be him, accessed eBay's servers and suspended some eBay accounts.

Ina Steiner reports on the AuctionBytes blog:

eBay confirmed that a known fraudster had limited access to a very small number of eBay accounts on the eBay.com site and the company appeared to have reacted quickly to block him on Friday. eBay spokesperson Nichola Sharpe said, "At no point did the fraudster get any access to financial information or other sensitive information." In a strange twist, some users reporting the incident said they had been openly critical of a hacker calling himself Vladuz and had been suspended briefly during the incident.
It is strange that some of the people suspended were openly critical of Vladuz?

Notably, this is the first time eBay has admitted Vladuz accessed their servers.

In another development, eBay, PayPal and Yahoo are joining forces to combat phishing. Phishing is a phenomenon that has caused a lot of eBay and PayPal account holders a lot of grief. Experts maintain that eBay and PayPal are the two most phished brands out there.

Phishing is where an account holder is duped into giving up their access information via social engineering (trickery).

The intent of the phishermen, who target eBay/PayPal accounts is normally to take the account over and commit even more fraud.

This activity gets more sophisticated all the time with crimeware (malware) being used (which steals the information automatically), and DIY (do-it-yourself) phishing and hacking kits being marketed in underground Internet forums.

Reuters, courtesy of the Washington Post is reporting:
EBay and PayPal have upgraded their computer systems to support an emerging technology standard known as DomainKeys invented by Yahoo that authenticates e-mail senders are who they say they are, allowing Yahoo to block fake e-mails.

The technology upgrade will be made available to Yahoo Mail users worldwide over the next several weeks, the company said.
If you are interested in how bad the phishing phenomenon is getting, the National Consumers League has a very well written and informative paper on the subject, here.

They also have an interesting document, which although is a little dated, shows the increase in auction fraud and calls out that eBay severed their ties with them.

It should be noted that auction fraud doesn't only occur on eBay. It can and does happen on all the auction sites. The reason we hear more about it on eBay is because they are the used by more people than the other sites.

For the scammers that means there are more potential victims to harvest there.

NCL article on auction fraud, here.

AuctionBytes blog post on this, here.

Reuters story on eBay/PayPal's efforts to combat phishing, here.

Here is my most recent post about Vladuz allegedly raising his head again:

Did Vladuz hack eBay, or is stockpiled stolen information being used to make it look like he did?

Thursday, September 27, 2007

eBay responds to the alleged Vladuz hacking incident

eBay is responding to the latest (alleged) attack on their site by Vladuz by confirming that the account information was valid, however the credit card numbers were not.

Here is what the Chatter (eBay's blog team) has to say regarding their investigation:

I've been in touch with our operations and security teams, and I have more information I can share with you about yesterday's incident on the Trust & Safety discussion forum. In brief, very early yesterday morning, a fraudster posted contact information and alleged credit card numbers for about 1,200 members on our Trust & Safety discussion forum on eBay.com.

While the issue was very unfortunate, it was clearly falsified to cause public concern. Early on eBay's teams verified that the credit card "data" did not match anything on file for these members on eBay or PayPal. After more investigation, including phone conversations with many of the members, it appears that these numbers were not valid at all.

Each of these accounts was the victim of an Account Take Over, most likely through a successful phishing campaign. eBay has been in contact by phone with many of these members, and there is a My Messages email going out to impacted accounts to further our reach.

1200 successful account-takeovers is a fairly large asset for a criminal to part with, even if the credit card numbers were no good. In the hand of the wrong people, 1200 eBay and PayPal accounts can be used to commit a lot of crime.

Here is a description of how account-takeovers are sometimes used from my original post on this latest incident:

Account-takeovers enable criminals to scam others, using someone else's information. They can also be used to fence (sell) stolen merchandise with a high degree of anonymity. It should also be noted that stolen payment (credit/debit) card details are often used to purchase the merchandise, which is then fenced.

To cover their tracks, the scammers often dupe people into laundering the proceeds of these sales in work-at-home (job) scams and wiring the money, normally across a border.


Although eBay is stating that the credit card numbers in this case were no good, they are for sale, along with account-takeover information on the Internet. Because this information is sold over the Internet, the criminals are able to buy and sell this information (globally) without ever actually meeting each other in person.

As I stated in my earlier post, phishing is a method, where a lot of personal and financial information is stolen, also.

Thus far, all anyone can do is speculate as to how the accounts were compromised. It will be interesting to see if anyone gets to the bottom of what actually occurred.

The Anti-Phishing Working Group tracks phishing activity and many experts claim that eBay and PayPal are the most frequently phished brands. They also have some excellent information on how to avoid being a victim and what to do if you think you've become one.

Auction fraud doesn't only occur on eBay and can happen on any of the auction sites out there. The criminals behind this activity tend to go after what is the most popular, which probably has more to do with why they target eBay than anything else.

If you get phishy e-mails that ask you to provide your eBay, or PayPal account numbers, the Chatter recommends you report them to spoof@ebay.com or spoof@paypal.com. They also recommend to go to their Security & Resolution Center if you encounter a problem.

Another place to report phishy e-mails is CastleCop's PIRT Phishing Incident Reporting and Termination Squad. Please note you can also report this activity on the Anti-Phishing Working Group's site, also.

Reporting a phishing attempt might prevent someone else from becoming a victim. Sadly enough, if you have an e-mail address, you probably see phishing attempts on a daily basis.

Post from the Chatter, here.

Wednesday, September 26, 2007

Did Vladuz hack eBay, or is stockpiled stolen information being used to make it look like he did?


(Picture courtesy of Yahoo Group, eBay_scamkillers)

There is a lot of speculation that eBay was hacked once again, and that Vladuz might be behind the latest episode.

Vladuz, who takes his name from a famous Romanian prince, Vlad Tepes, has plagued eBay with a string of hacking attacks in the past. Vlad Tepes was the inspiration for the novel, Dracula. In Internet folklore, Romanian scammers are often referred to as "Vlads."

Of course, eBay is denying that they were actually hacked. I'll let the reader form their own opinion.

Auction Bytes (Ina Steiner) is reporting:

eBay closed its Trust & Safety discussion board for hours on Tuesday after threads began appearing listing the names and addresses of eBay members. eBay spokesperson Nichola Sharpe said, "We think the fraudster obtained the eBay User names and IDs from previous account takeovers." The credit card information that was published alongside 1,200 names, User IDs and addresses were not associated with the financial information on file for those users at eBay or PayPal, Sharpe said.

Unfortunately, with the amount of account-takeovers caused by Phishing, eBay can suggest other ways the information might have been stolen. Phishing is where users are tricked into giving up their personal details, or downloading malware (crimeware), which steals it right off their hard drive.

I don't know which is worse, that they were hacked in this incident, or that all this information was compromised a long time ago? If it were compromised a long time ago, as eBay states, how much more compromised eBay information is out there?

The Cappnonymous Buds Blog has put together a pretty visual demonstration that makes a pretty good argument that eBay was hacked.

Account-takeovers enable criminals to scam others, using someone else's information. They can also be used to fence (sell) stolen merchandise with a high degree of anonymity.

It should also be noted that stolen payment(credit/debit) card details are often used to purchase the merchandise, which is then fenced.

To cover their tracks, the scammers often dupe people into laundering the proceeds of these sales in work-at-home (job) scams and wiring the money, normally across a border.

Whether Vladuz is behind this latest attack remains to be seen. But the fact remains, that there is a lot of fairly organized crime targeting eBay (my opinion) and other auction sites, on a daily basis.

Previous posts, I've written about eBay and auction fraud can be read, here.

In case anyone is interested in the graphic photo at the top, here is a post I did about a Yahoo Group that call themselves the eBay_scamkillers.

They are an all volunteer group, many of whom have impressive credentials, that are responsible for putting a lot of eBay scammers, where the sun don't shine (prison).

Saturday, April 07, 2007

buySAFE takes on the issue of counterfeit (knock off) merchandise

buySAFE bonds sellers after verifying they are reputable and honest. They also contribute their time to protecting the average person in the sometimes murky waters of e-commerce. Recently, buySAFE has been taking on the (huge) issue of counterfeit merchandise.

Consumers are protected when they buy from a merchant bearing the buySAFE seal. Not a very bad deal for the consumer! Bonding isn't free, but many merchants experience higher sales volumes after being accepted by buySAFE. Trust can drive a lot of sales! buySAFE is also a viable means for a merchant to protect their assets.

The Association of Certified Fraud Examiners noted in their last report to the nation that small businesses suffer "disproportionate fraud losses," when they are victimized by fraud. Large merchants can afford experts to deal with their fraud problems, however the cost is hiring experts can be restrictive for smaller merchants.

Of the numerous fraud issues found on auction sites, complaints about counterfeit goods rank pretty high. People buy items believing they are the "real deal," only to discover the item is a (knock-off) counterfeit.

Companies, who sell respected and trusted brands, are impacted by a loss of sales and consumer trust in their products, also. Some of them have already filed civil litigation against eBay because of the amount of knock-off (counterfeit) merchandise being sold on the site.

Even though auction sites offer seller rating systems, these ratings are often compromised when seller accounts are hijacked (taken over). eBay and PayPal (by most accounts) are recognized as the two most phished brands out there.

The intent of most of these Phishing schemes is to obtain personal/financial information to steal money (and or) take over legitimate accounts.

This can also happen when malware (crimeware) is inserted into an unprotected system and personal/financial details are stolen, normally using key logging software. Sadly enough, the criminal element has found it pretty easy to remain anonymous on auction sites, and few of them seem to get caught.

Whenever the Anti Phishing Working Group (APWG) releases a new report, both of these activities seem to set a new record that surpasses the previous one.

Recently, eBay seems to be taking the fraud problem a lot more seriously, but someone using the name of "Vladuz" is intent on proving their systems are easily compromised. A good place to keep up on the Vladuz saga is firemeg.com.

Although a good information source, I'm not certain that bashing Meg is the solution to fraud on auction sites.

Being the largest auction site, eBay is targeted by fraud all the time because of their popularity.

Fraud has already migrated to other auction sites, but they will always target the most popular.

The reason for this is simple (and it's only business for them) - there are more victims to harvest in popular places.

The term "Vlad" was based on a Romanian historical figure, Vlad Tepes, who inspired the novel, Dracula. In recent times, the term has come to signify fraudsters from Romania, who are well established and organized in the world of auction fraud.

Besides, protecting merchants and consumers, buySAFE makes a lot of contributions to addressing fraud issues on auction sites. Most recently, Jeff Grass (buySAFE CEO) has posted a lot of educational information on his blog about the counterfeit problem, here.

Jeff also appeared on the Today show, when they did a piece on counterfeit goods.You can view a clip of the show, here.

And the Today show isn't the only place that considers buy Safe’s views on the counterfeit problem important. The French government recently included buySAFE as part of a U.S. delegation (including government experts) to discuss the problem of counterfeit goods.

The INTERNATION ANTICOUNTERFEITING COALITION (a non-profit) sums up the problem when they state:

Counterfeiting is big business.It is estimated that counterfeiting is a $600 billion a year problem. In fact, it's a problem that has grown over 10,000 percent in the past two decades, in part fueled by CONSUMER DEMAND.

The real truth is people who purchase counterfeit merchandise risk funding nefarious activities, contributing to unemployment, creating budget deficits and compromising the future of this country in the global economy.

IACC site, here.

Part of the reason the activity has grown 10,000 percent is probably due to the explosion in e-commerce, especially on auction sites.

buySAFE seems to be doing a little more than just selling a product. In fact, they seem to be exercising some corporate responsibility by educating the public on fraud trends in the rapidly growing world of e-commerce.

Consumers can become a member of their Smart Buyer's Club, which leads you to a lot of good deals (safe to buy), here. Club members accumulate points, which can be redeemed for goods, or services (listed on the site).

Anyone claiming to be a buySAFE merchant can be verified, which can be done on the site, also.

Thursday, January 11, 2007

Will competition make it harder to write off fraud costs on auction sites?

Perhaps market forces will be what it takes to better protect buyers and sellers from fraud on auction sites? Competition dictates that the auction providers will have to offer a "better deal" to attract and maintain their customer base.

Internet auctions have become a "very" popular way to buy and sell goods, but they've also attracted a lot of fraud. And fraud seems to be motivating some changes at the most popular auction site, eBay.

eBay is limiting what types of transactions they protect and is banning Google's Checkout on it's site. In addition to this, they are increasing the dollar amount protected with PayPal.

Ina Steiner of AuctionBytes wrote:

eBay will double PayPal Buyer Protection on its site, offering up to $2,000 of coverage for qualified transactions on eBay.com, but is eliminating buyer-protection for non-PayPal transactions. The move is a dramatic effort by eBay to push buyers to use its PayPal online-payment service at a time when it faces increasing competition from Google Checkout, a method it prohibits sellers from accepting on its site.
AuctionBytes story, here.

The story also mentions that eBay no longer protects transactions with financial instruments, such as wire transfers, money orders and checks. Scams using these now "unprotected" financial instruments have been well documented in the auction world.

The message is that if you don't use PayPal, or a credit-card - you aren't protected on eBay.

Not sure if eBay is trying to limit it's own fraud exposure, or if they are marketing fraud protection?

Even though buyers might be getting "slightly" more protection - sellers seem to be more at risk of losing money from fraud than they were before. They are either going to have to limit their "accepted payment methods," or take the chance of losing more money.

And so far as credit cards - "sellers" still are and "always have been" at risk of receiving chargebacks from the financial institution involved.

It will be interesting to see how this progresses and how auction users react.

The auction business is getting more "competitive," and writing off the cost of fraud is going to become "increasingly more difficult."

Here are some previous posts, I've written on auction fraud:

Romanian Second-Chance eBay Scammers Busted

California Issues Alert on Emerging eBay Fraud Trend

How to Spot a Counterfeit on eBay

Bid Reaper, "TELLING IT LIKE IT IS" on eBay

Auction Fraud and the Romanian Connection

How to Protect Yourself on eBay

BBB Worker Takes Job Processing Fraudulent eBay Transactions

Wednesday, June 28, 2006

California Issues Alert on eBay Fraud Trend

The California Office of the Attorney General is issuing a consumer alert about fraudsters - who pose as sellers on eBay (after assuming a legitimate sellers identity) - and lure them into paying for something they will never receive.
Account takeovers and identity theft are nothing new on eBay. In most instances, they are accomplished by "phishing" legitimate members of the eBay community; who are tricked into giving up their information as a result of a seemingly legitimate e-mail.
Here is the consumer alert:

Scam Artists Posing As Sellers on eBay

Consumers should be on the alert for scam artists posing as sellers on eBay, the California-based Internet auction site, who victimize bidders through bogus second chance offers. To avoid falling victim to this scam, we offer some tips and precautions below.
In the emerging fraud scheme, scam artists try to lure bidders interested in a product away from the e-Bay web site by using “My Message,” which allows seller and buyers to communicate on the auction site. Through posted messages, legitimate sellers are able to build a positive reputation from customer ratings, product reviews and favorable reports on business transactions.
Manipulating the eBay messaging system, the scam artist posing as the seller contacts bidders to announce the winning bid fell through and offers a second chance to buy the product by wiring the purchase price to the non-eBay email address provided. The scam artist is counting on consumers being tricked into a direct sale and being lured by the positive feedback seen on eBay.
However, the message is actually from a con artist who assumed the identity of the legitimate seller who already sold the item to the winning bidder. The second chance bidder who falls for this scam is left empty handed, paying for a product that will never arrive.
For the full consumer alert, link here.
Here are two resources to seek help, if you become a victim:

Attorney Generals Office Complaint Form and Federal Trade Commission Complaint Form.

These resources are only applicable in California and the United States, here is a list where you can find victim assistance worldwide:
Here are some other tips on how to avoid fraud on eBay:
Here is a post about how accounts are taken over on eBay:

Sunday, January 29, 2006

How Much Fraud Can eBay's Customers Endure

Fraud on eBay is making news again, this time for upset customers being sold counterfeit goods. Here is an article by Katie Hafner of the New York Times:

"A year ago Jacqui Rogers, a retiree in southern Oregon who dabbles in vintage costume jewelry, went on eBay and bought 10 butterfly brooches made by Weiss, a well-known maker of high-quality costume jewelry in the 1950s and 1960s.

Rogers thought she had snagged a great deal. But when the jewelry arrived from a seller in Rhode Island, her well-trained eye told her all the pieces were knockoffs. Even though Rogers received a refund after she confronted the seller, eBay refused to remove hundreds of listings for identical "Weiss" pieces. It said it had no responsibility for the fakes because it was nothing more than a marketplace that links buyers and sellers.

That stance — the heart of eBay's business model — is being challenged by eBay users such as Rogers who are starting to notify other unsuspecting buyers of fakes on the site. And it is being tested by a jewelry seller with far greater resources than Rogers: Tiffany & Co., which has sued eBay for facilitating the trade of counterfeit Tiffany items on the site.

If Tiffany wins, other lawsuits would follow and eBay's business model would be threatened because it would be nearly impossible for the company to police a site that has 180 million members and 60 million items for sale at any time."

For the full story, read: eBay users fed up with fakes.

eBay hasn't only been in the news recently for being a marketplace for counterfeit goods. In a recent post, I covered the problem of stolen goods being sold and merchandise being purchased with fraudulent financial instruments.

Also covered in this post is the growing problem of buyer/seller accounts being hijacked. This normally occurs when a seller becomes a victim of phishing, or is tricked into giving up their account information to a seemingly legitimate eBay request via e-mail. The e-mail links them to an official looking eBay site, where they are asked to "validate" their account information. Should someone fall for this, the criminal has all the information necessary to hijack the account and use it (the account) to conduct fraudulent business.

Although, eBay's official policy is to support law enforcement requests without a subpoena, it takes them 10-20 days to honor these requests. If criminals have access to multiple accounts and fraudulent financial tools, the trail is likely to be pretty cold in 10-20 days.

Here is my post on that activity: Better Teamwork is an Opportunity.

eBay is also getting a reputation for Advance fee fraud (419) activity. On auction sites, fraudulent buyers offer to buy something and send a financial instrument to the seller for more than the asking price. They then dupe the seller into negotiating the instrument, which is counterfeit and wiring the excess money (less a commission for the seller) overseas. When the instrument is discovered to be fraudulent (often much later), the seller is held accountable and could even be charged with a crime.

Counterfeit Postal Money Orders, Cashiers Checks and a new type of instrument, OChex (checks ordered electronically over the internet) have all been used in these frauds, which are becoming collectively known as auction scams.

Over the Christmas season, we saw another scam, where XBox packaging was being sold as the real thing: XBox Latest Lure in Auction Scams.

I wrote this in a recent post, eBay Needs to Protect Those that Line it's Pockets:

"My message to the folks at eBay is that they better take a look at upgrading their "authentication systems" and hire some extra security staff. Blogs like mine and many others are trying to educate the very people, who are making them billions and they blame for allowing themselves to be scammed. eBay is no longer the only the only game out there and if they fail to protect those who line their pockets, they are likely to go elsewhere."

Perhaps a few legal actions will wake eBay up?