Saturday, August 23, 2008
Cost Plus Customers Compromised in Data Security Incident
On July 22nd, the company announced that after a thorough investigation they learned the Electronic Funds Transfer devices (PIN pads) might have been been compromised at eight Southern California stores by unauthorized third parties.
Since then three additional stores have been identified as being compromised.
The first hint of trouble was in June when two employees reported unauthorized transactions on their debit cards. By early July, the banks were reporting a unusual amount of fraud accounts that had one thing in common, they had been used at Cost Plus.
I picked up this story in an article on SignonSanDiego.com published yesterday (08/22/08). The only other mention of it, I could find was in a report by FOX News on 7/22/08.
Both the SignonSanDiego.com article and the official press release state that only debit and not credit cards have been reported compromised. Given that the hardware compromised accepts both credit and debit cards for payment, my humble guess is that credit card information might have been compromised, also. The reality is that you need both a card number and a PIN to get cash. The other reality is that card numbers can often be used without a PIN. My guess is that (at least so far) the crooks behind this were after fast cash.
Cost Plus is working with their payment card processors and the banks to identify customers, who might have been compromised. They have also brought in a external data security vendor (Verizon Business/Cybertrust) to analyze their systems. PIN pads are being replaced in all their stores, nationwide.
Compromises involving PIN pads have become more frequent in recent years. Cases are now being seen despite the fact that the retailer was compliant with payment card industry security standards. Speculation is that this is done when the information is being transmitted internally before it is transmitted to a payment card processor. Once the internal system is compromised, the hackers use sniffer programs to gather all the information and a data compromise is born.
In the early reports of PIN pad compromises, the actual PIN pads were being replaced. The crooks would later come back and in and retrieve the PIN pad to gather the payment card information or pick up via a wireless connection.
Since then my speculation is that the hacking methods being used have become more sophisticated and PCI data protection standards -- designed to protect merchants from data compromises -- might no longer be 100 percent effective.
Data compromises cost the victim affected, the retailer and the financial institutions issuing the payment cards.
I tend to write on behalf of the victim and I wanted to point to an excellent article by Tom Fragala, where he analyzes the protections offered when using credit and debit cards. General consensus is that it is a lot safer to use a credit card from a consumer point-of-view. Note I'm saying this from a security point-of-view because too much credit card debt isn't always a good thing, but that's a whole other subject.
Tom is a fellow blogger, and the CEO of a privacy friendly identity theft protection service (Truston) that just won another in what is becoming a long string of awards. They also offer a 45 day (completely) free trial to use their services.
As long as there is a lot of money to be stolen from payment cards, criminals are going to be motivated to defeat security fixes.
The recent news that one of these retail hacking rings were caught and put behind bars probably will go a lot farther in preventing data compromises than security fixes, which seem to be counter-fixed, fairly frequently.
The eleven Cost Plus Stores known to have been compromised were San Diego (372 Fourth Avenue, San Diego, CA 92101); Oceanside (2140 Vista Way, Oceanside, CA 92054); La Jolla (8657 Villa La Jolla Drive Suite 117, La Jolla, CA 92037); Mission Viejo (28341 Marquerite Parkway, Mission Viejo, CA 92692); San Dimas (638 West Arrow Highway, San Dimas, CA 91773); Valencia (25676 North The Old Road, Valencia, CA 91381); Palm Desert (44-439 Town Center Way, Palm Desert, CA 92260); Oxnard (221 Esplanade Drive, Oxnard, CA 93030); Westlake Village (Thousand Oaks) (160 Promenade Way, Westlake Village, CA 91362); Tucson East (5975 E. Broadway, Tucson, AZ 85711); and Tucson (4821 North Stone Avenue Tucson, AZ 85704).
Cost Plus also has a FAQ page for people, who think they may have been compromised.
Wednesday, August 06, 2008
Largest Identity Theft Ring in History Indicted
Allegedly, the group is responsible for stealing and selling more than 40 million credit and debit card numbers. The credit and debit card numbers were intercepted electronically at nine retailers, who transmitted their unprotected financial information using wireless networks. Once they hacked into the wireless networks, the group would install sniffer packets to capture card numbers and PIN numbers.
TJX, who was severely criticized for their breach of approximately 8.5 million records wasn't the only retailer being compromised. BJ’s Wholesale Club, OfficeMax, Boston Market, Barnes & Noble, Sports Authority, Forever 21 and DSW were being compromised, also. The restaurant chain Dave and Busters was also compromised by having "sniffer packets" installed on their point of sale terminals by the group.
Merchants have been under fire for not meeting PCI data security standards, which were developed by the payment card industry to protect systems against compromises. The National Retail Federation has fired back at the payment card industry for forcing merchants to store sensitive information, which can easily be stolen. In a recent data breach involving the theft of 4.2 million card numbers, Hannaford Brothers had been certified as being PCI compliant, which led a lot people to speculate that PCI data security standards might be outdated, themselves.
Sniffer packets are used to monitor information in a network and can be used to gather a lot of sensitive information. Detecting a sniffer packet on a wireless network is known to be extremely difficult. A practice known as "wardriving" is when people drive around and try to pick up wireless signals from unprotected networks. Computer security experts highly recommend making wireless networks secure, including those of the home variety, by password protecting them. Software to assist people, who do this, is freely available on the Internet.
After the information was stolen it was stored on encrypted computer servers in Eastern Europe and the United States. Some of the stolen data was sold to other information criminals via the Internet. The group also counterfeited their own cards and used them to steal money from ATMs.
Recently, Finjan, a computer security company, announced finding servers with a lot of stolen information on the Internet. At least one the crimeservers found by Finjan wasn't even password protected. Finjan reported finding these crimeservers using simple Google searches.
The money was laundered using internet based currencies and by moving funds through banks in Eastern Europe.
Three executives at E-Gold, which is a internet based currency, recently pleaded guilty to allowing criminal activity of this nature (money laundering) using their service.
The criminal activity started in 2003 and went right up to the present time. Albert "Segvec" Gonzalez, of Miami, one of the main players in the group was previously arrested for similar activity in 2003. During the current investigation, the Secret Service discovered Gonzalez was working as a government informant and involved in the criminal activity at the same time.
Also charged in the indictments yesterday were Maksym "Maksik" Yastremskiy, of Kharkov, Ukraine, and Aleksandr "Jonny Hell" Suvorov, of Sillamae, Estonia. Hung-Ming Chiu and Zhi Zhi Wang, of the People's Republic of China were also charged. Sergey Pavolvich, of Belarus and Ukranians Dzmitry Burak and Sergey Storchak were also named in the indictment. Two U.S. citizens Christopher Scott and Damon Patrick Toey, finished up the long list of names from all over the world involved in this organized criminal enterprise.
The range of the activity took place in numerous countries, including the United States, Ukraine, Belarus, Estonia, the People’s Republic of China, the Philippines and Thailand.
These indictments are the result of a three-year investigation conducted by the Secret Service. As the case progresses, it is being reported that they will be working closely with the IRS, on the money laundering aspect of the case.
Friday, June 20, 2008
Wawa gas pumps latest target of payment card skimming devices!
Unfortunately their self service pumps are the latest targets of payment card (credit/debit) skimming devices. Just about any self service machine that accepts payments, or dispenses money (ATM machines) can have a skimming device mounted to it.
CBS 3 Philadephia reports:
With gas prices rising and the state of the economy in disarray, even thieves are resorting to more creative measures. At least two Wawa filling stations in the Philadelphia area have fallen victim to a string of recent credit card skimming scams.
"Just like any identity theft, until you see it on your credit card or bank statements, it's really important to check for any usual transactions," said Ela Voluck of AAA.
Thieves place a device over the card reader and can instantly record the information on the card.
Unfortunately, no pictures of the devices at Wawa seem to be available.
Recently, Redbox, a company that dispenses movies at self-service kiosks were the target of skimming devices. I have to commend them for being transparent and proactive by letting the public see exactly how this occurs.
They provided a warning on their website, along with some interesting pictures.
The only defense a person has is to carefully inspect these devices at self service places, such as the gas pumps at Wawa. Some of them are pretty bad and will literally fall off if handled too roughly.
Here are some pictures of skimming devices:


Skimmers are mounted on ATM machines, or any remote self service device. There are also portable ones that dishonest employees use to skim a card when they take it for payment.
Google has a neat sampling of pictures, which can be seen, here.
Sunday, June 15, 2008
Credit Card fraud used to fund Terrorist Organization
The Sri Lanka Ministry of Defence website reported:
The mastermind behind the international credit card fraud for funding the LTTE terrorist organization has been arrested by the Special Task Force (STF) personnel while conducting a search operation in the Wellawatta area on Friday, June 13.
The suspect Anandan, alias Neshanadan Muruganandan, was in a super luxury apartment in Wellawatta at the time he was arrested by the special police team, sources said. He had a large number of Personal Identification Numbers (PIN) and bank receipts issued by both local and foreign banks, amounting to a massive sum of money, over Rs. 100 million, in his possession when he was arrested.
This isn't the first time a tie between payment (credit/debit) card fraud and funding terrorism has been suggested. In the past, it's been widely reported that Al Qaeda training manuals teach their minions to use credit card fraud as a way to survive in foreign lands.
There has also been speculation that organized crime and terrorists mingle in the underground economy when it suits their needs. In another story, also found on Sri Lanka's Ministry of Defence site, it mentions that 130,000 passports were stolen and that some of them were provided to the highest bidder (Al Qaeda).
Also mentioned in the interesting story is other ways this terrorist group, the Tamil Tigers, obtain their funding.
While I doubt organized criminals, and or terrorists are going to admit they are taking advantage of stolen personal and financial information in public, it could be a bigger problem than we realize (?).
Here in the West, Suad Leija and her husband have been trying to get this message out to everyone on their site (Paper Weapons). If you are interested in understanding how paper (and sometimes plastic) weapons might be used by people with twisted political objectives, I highly recommend visiting their site.
Sunday, June 08, 2008
NRF Survey shows Organized Retail Crime activity is growing!
Also mentioned in the survey are shady e-commerce sites being put up on the Internet to fence the proceeeds of ORC.
In case you've never heard the term, Organized Retail Crime, here is a good description of the activity:
Organized retail crime (ORC) refers to groups, gangs and sometimes individuals who are engaged in illegally obtaining retail merchandise through both theft and fraud in substantial quantities as part of a commercial enterprise. These crime rings generally consist of “boosters” who methodically steal merchandise from retail stores and fence operators who convert the product to cash or drugs, as part of the criminal enterprise. Some of the more sophisticated criminals engage in changing the UPC bar codes on merchandise so they ring up differently at checkout, this is commonly called “ticket switching.” Others use stolen or cloned credit cards to obtain merchandise or produce fictitious receipts to return products back to retail outlets.
The report acknowledges that these groups are using cloned credit cards to steal merchandise and or get the necessary receipts to refund the merchandise for cash.
In the wake of the TJX data breach, where up to 94 million personal and financial records were hacked, a group was caught in Florida using data from the breach (cloned cards) to buy a reported $8 million worth of gift cards.
Please note that TJX is hardly the only retailer, or financial services institution that has had personal and financial records hacked from their systems in recent history. Attrition.org does a good job of recording the known breaches on their Data Loss Database - Open Source .
Although not addressed in the current report, I suspect the use of fraudulent checks are used to obtain merchandise and receipts, also.
This could be fueled by another organized crime activity. Portable technology has made the counterfeiting of identification documents another growing trend. Over the past two years or so, I've had the pleasure of being able to speak with Suad Leija and her husband about this organized criminal activity on a semi-regular basis. Suad, the step-daughter of one of the top players in this game was recruited in an intelligence operation and eventually exposed a cartel operating throughout North America to the government. Prosecution of members of the cartel is ongoing in this case and Suad is currently working on a book.
These documents, which are available throughout the United States, can be easily used to support both check and refund fraud by using names that get past the data bases designed to protect retailers from these types of fraudulent activity.
Portable technology is also being used to clone payment cards and some of it is easily found on auction, or shady e-commerce sites set up to sell these devices. As of this writing, I was easily able to find credit card encoders for sale on eBay. A site called HackersHomePage.com provides an array of devices that could be used to steal and produce payment (credit/debit) cards. They also provide tools to make counterfeit checks and even, paper for fake prescriptions. They do have a "disclaimer" stating that none of their products are to be used for illegal purposes, but it is pretty obvious someone could.
There is no doubt that there is a lot of technology that is enabling a lot of criminal activity out there!
NRF's Vice President of Loss Prevention, Joe LaRocca, made what I consider a sage comment on this activity:
“Law enforcement and retailers alike are fed up with organized retail crime rings and are stepping up efforts to stop them in their tracks,” said NRF Vice President of Loss Prevention Joseph LaRocca. “The brazen and unethical behavior of organized retail crime suspects results in possible health risks for consumers, adds unnecessary fees to consumers’ purchases and funds criminal enterprises, including the mob and terrorist organizations around the world.”
When I stated that this activity hurts all of us, the reason is that retailers have to make up the $30 billion they are losing to this activity somewhere. This normally equates to higher prices, or in extreme circumstances (especially in tight economic times) cutting payroll. Simply stated, people might be losing their jobs because of this activity.
So far as health risks, the report sums up the obvious risks rather well:
For example, criminals may not keep stolen merchandise in a temperature-controlled environment, so merchandise like baby formula and over-the-counter medicines can easily spoil. When criminals sell these items online through third party auction sites consumers are left with no way to guarantee they are getting safe and reliable healthy and beauty products.
I decided to see if I could find baby formula on eBay. As you can see - there seems to be a lot of it for sale on the site at discounted prices. At the time I checked 26 pages of it were for sale on the site.
Actual cases in the report that support how organized this activity has become are a $60-$100 million dollar case in Florida involving health, beauty, cosmetic products and over-the-counter medicines. Another case mentioned involved a high ranking member Gambino Crime Family and a sophisticated ticket/UPC switching case and extortion. In this case, a planted employee was making up the labels and providing temporary credit cards to move the merchandise through point-of-sale systems.
Recent initiatives to combat Organized Retail Crime include launching LerpNET, which is a crime database available to both retailers and law enforcement. Also highlighted was legislation against ORC throughout the country to "reduce the rewards and increase the risk" to the groups involved in it. Several States have already passed this legislation and more are considering it.
Full 2008 ORC Survey, here.
Thursday, May 29, 2008
TJX shoots the messenger reporting potential identity theft issues!

(Picture courtesy of b d solis at Flickr)
One would assume after compromising an estimated 94 million people's information, a company would become a model of information security for the rest of us to aspire to. Sadly, if the following story is true, this is NOT the case at TJX.
Ran into this disturbing example of a messenger getting shot for trying to report sloppy security on Sans Newsbites:
TJX Companies has fired an employee from a Lawrence, Kansas TJ Maxx store for making posts to a forum about the company's lax security practices, even after the notable breach. The employee, Nick Benson, said in several posts that except for a period of time following the breach disclosure when a strong password policy was enforced, the employee password at his store's server was set to blank. In addition, at one point a store server was running in administrator mode. When Benson began work at TJX, his password was the same as his user name. TJX says Benson was fired for disclosing confidential company information. -http://www.theregister.co.uk/2008/05/23/tjx_fires_whistleblower/print.html-http://computerworld.co.nz/news.nsf/scrt/3A2C5453A05F8C31CC257454006CE111
Reading a little further by linking to the article written by Dan Goodin in the Register, I discovered that the act of posting in forums came about AFTER the employee tried to resolve the problem, internally:
Other security issues included a store server that was running in administrator mode, making it far more susceptible to attackers. He said he brought the security issues to the attention of a district loss prevention manager name Allen in late 2006, and repeatedly discussed them with store managers. Except for a stretch when IT managers temporarily tightened password policies, the problems went unfixed.
After posting on the forum (http://sla.ckers.org/forum/read.php?13,15148,page=1), the boss of one of the people Benson reported the matter to summoned him into the office and terminated him.
I suppose we could all argue that posting this information in a public forum is dangerous. Saying that, Benson did try to report the matter through his internal chain of command and nothing was done?
Maybe it is because the people, he reported it to aren't IT savvy enough to realize how vulnerable TJX's systems are when they are left unprotected like this?
Even if a hacker didn't compromise the system, it is feasible that a dishonest employee could gather quite of bit of information and sell it? Carder forums -- where personal and financial details are bartered over cyberspace -- are well known and not very hard to find.
Please note, I wrote IF a hacker didn't compromise the system. I'm just pointing out stealing information wouldn't take a very sophisticated hacking job given the opportunities described in this instance.
They might even post (anonymously), how easily they got the information in hacker forums. Sadly if Mr. Benson had been more anonymous, he would probably still be employed. I guess it doesn't pay to be honest in cases like these?
My post just before this was about another revelation (pun intended) that not all data breaches are being reported. I tied this post into two stories. One was about the lack of reporting, and other one was recent reports about Finjan finding crimeservers via simple searches that contain a lot of information that could be used to commit a host of financial crimes.
Interestingly enough, the crimeservers (available to anyone on the Internet) weren't "password protected," either.
So far as Mr. Benson is concerned, I wonder if TJX was required to maintain a confidential hot-line and if he ever reported the matter there? Although, I'm not a lawyer, I also have to wonder if federal laws protecting "whistleblowers" apply here. More information on whistleblower laws can be seen on whistleblower.com.
It's a crying shame that the powers that be at TJX didn't value the fact that an employee was trying to show them where they might receive a lot more unfavorable public exposure by compromising their customer information.
I'll close with a supportive comment from the editor at SANS:
[Editor's Note (Schultz): Once again TJX is proving itself to be a villain. Interestingly, I still sometimes shop at a TJ Maxx or Marshalls store, but I always pay cash--I would never use a credit card because of TJX's huge security deficiencies. And if Nick Benson reads this comment, I would encourage him to contact me, because I will do everything in my power to help him find another job. ]
PS: I would like to add that I'm pretty sure there are companies out there that would value an employee, who brought matters like these to their attention. They might save them millions of dollars in the end when you consider the cost of recovering from a data breach.
As a disclaimer, TJX's side of the story is unknown, but according to the Register article when they were asked they would not comment on the matter.
Wednesday, March 19, 2008
Security vendor removes Hannaford as a client on their site after data breach is revealed!
From the blog post on geeksaresexy.net:
Instead, Rapid7 scrubbed all mentions of Hannaford from their client list. Rapid7 obviously didn’t want to be associated with one of the largest data loss incidents in history, and they certainly didn’t want to sully the name of their flagship appliance, the “neXpose” which is a vulnerability scanning device.
This information is from Attrition.Org, an online security community that has been around since the predawn of the dot-com boom. They have an outstanding article, with screenshots here, where they are much less kind to Rapid7 in light of their cowardly actions.
Atttition.org is one of the trusted sources on data breaches, so I decided to see what they had found:
You are a security vendor. You sell the mightiest security doohickey the world has ever seen. It does it all, including "...ensuring your network is safe from hackers..." and amazingly it "...scans for Web site and database vulnerabilities that hackers can use to capture credit card information without you being aware". Since your doohickey does what no others have ever successfully managed to do, you can tout your client list proudly, and pimp your customer implementations liberally.
Attrition.org did an excellent job showing (complete with compelling screenshots) how Rapid7 removed all the information on the Internet showing they were Hannaford's cyber-guardians.
To see all the evidence, which is convincingly presented on Attrition.org, I've provided a link:
Abandon Ship! Data Loss Ahoy!
As of this writing, Rapid7 has replaced the information on their site showing Hannaford as a client.
I decided to run a query on Google News and discovered that so far the Boston Globe is one of the few mainstream e-rags reporting this so far.
The Boston Globe was able to get a comment from the marketing VP at Rapid7. Here is the "official explanation" from the article:
Was it damage control? Embarrassment about being linked to the breach? An admission that its software failed?
A Rapid7 executive says none of the above.
David Precopio, the company's vice president of marketing, said Hannaford asked Rapid7 to remove its name from the site once the data breach was made public. But after some sharp-eyed observers spotted the deletion (including the security website attrition.org) Precopio said Rapid7 asked Hannaford to let it repost the company’s name.
The Boston Globe was unable to get a comment from Hannaford about this matter.
I guess I'll have to leave it to the reader's imagination what the true intention in all of this was?
Tuesday, March 18, 2008
Hannaford Brothers data breach might reveal current security standards are outdated
Whenever a data breach of this magnitude occurs, there are a lot of victims.
This breach occurred despite that fact Hannaford Bros. had met the payment card industry (PCI) standards for data protection and were not using wireless technology to transmit unencrypted data. Both of these factors were said to have caused the now infamous TJX breach, where approximately 98 million records were compromised.
This time only a reported 4.2 million records have been stolen, but it's still early in the game and historically these estimates tend to blossom with time.
A press release from Hannaford revealed that no personal information was stolen in this occurrence and that only payment card (credit/debit) card numbers are at risk.
Additionally, there have been 1800 reported cases of fraud tied into this data breach thus far.
Today, the AP was able to get a comment from their corporate headquarters:
It was during the card approval process that more than 4 million customer accounts at grocery stores in the Northeast and Florida were exposed to fraud, even though the company meets the latest standards for data security, a spokeswoman said Tuesday.
Hannaford Bros. Co. doesn't yet know how the breach — which began Dec. 7 and ended March 10 — occurred, said Carol Eleazer, vice president of marketing for Hannaford, based in Scarborough.
About 4.2 million credit and debit card numbers were exposed and at least 1,800 stolen during the seconds it takes for that information to travel to credit card companies for approval after customers swiped their cards in checkout-line machines, Eleazer said.
Brian Krebs of the Washington Post, who does the Security Fix blog quoted an industry expert, Bryan Sartin at Cybertrust as stating:
"I would say a trend we're seeing hitting a lot of retailers right now is that these organizations can be [compliant with the credit card industry security standards] and still have customer data stolen," Sartin said. "The data in transit is allowed to traverse private links and internal infrastructure without being encrypted, and the attackers are taking advantage of that."If the theory in Security Fix is pans out (probably will), some precedents might exist for the basic method the hackers used. The incidents, I will reference don't sound as sophisticated as what Mr. Sartin is describing, but they happened about a year ago and hacking methods tend to mature with age.
Once these systems have been compromised, Sartin said, the attackers typically eavesdrop on the network using "sniffer" programs that can extract credit and debit card data as it moves across the wire, before it even leaves the store's network.
Stop and Shop was the subject of a data breach a little over a year ago. In this case, PIN pads were being replaced with "look-alike" devices that captured all the payment card details. This hardware was later removed to download all the information that had been captured when unsuspecting customers swiped their cards.
Shortly thereafter, another compromise of this type was reported in Edmonton, Canada. In this case, a blue tooth device was used to transmit the information to a waiting car in the parking lot.
The trend with PIN pad replacement continued with a smaller breach at a grocer in the San Francisco Bay area, Albertsons in April of 2007. At the time, I had the pleasure of speaking with Blanca Torres, who was doing an article on the story.
Interestingly enough, up North in Canada, where payment card skimming has increased six-fold in recent years, an announcement was made that they plan to introduce a smart card. This technology, which is known as "chip and PIN" is already in use in Great Britain and France.
The AHN story about this by Vittorio Hernandez included (what I consider) a sage comment:
But Peter Woolford of the Retail Council of Canada is wary that although the smart cards appear to be effective in reducing incidents of fraud, sinister minds may one day find a way to hack the smart chips. "Anything the human brain puts together, another human brain can take apart," Woolford pointed out.Sadly, once this all pans out, it will likely reveal that PCI data protection standards can and will be compromised in the future. The reason, I say sad is because a lot of retailers have spent a lot of money becoming compliant.
Throw in all the finger pointing and litigation between the different parties in all these breaches and I fear we're going to be fighting a very costly battle over what is becoming a too common item in the news.
I'll sum this post up with a rant, I wrote when the TJX breach was attracting a lot of attention:
While everyone sues TJX, the criminals are laughing all the way to the bank
Press release from Hannaford about the breach, here. They list a telephone number on it, where more information can be obtained if you think you've become a statistic.
Sunday, March 09, 2008
When will we realize how serious the problem of counterfeit devices has become?
From the press release:
Queens District Attorney Richard A. Brown, joined by Police Commissioner Raymond W. Kelly, today announced that a forged credit card and identity theft ring based in Queens County and with roots in the Far East has been successfully dismantled following the indictment this week of thirty-eight individuals. The ring was allegedly responsible for stealing the personal credit information of scores of American consumers and costing these individuals, financial institutions and retail businesses more than $1 million in losses over the past year.Counterfeit identification documents to match the counterfeit financial devices were being produced, also.
DA Brown explains why this is of greater concern than mere financial crime:
Many of the defendants charged today are accused of going on nationwide shopping sprees, purchasing tens of thousands of dollars worth of high-end electronics, handbags and jewelry with forged credit cards that contained the account information of unsuspecting consumers. Particularly disturbing is the fact that, in a number of cases, the defendants are charged with using bogus documents to purchase airline tickets and then using those documents as identification to board commercial aircraft. In the hands of terrorists such documents could have easily undermined the efforts of homeland security and other law enforcement officials intent on keeping our borders and citizens safe.
Given that the scope of this crime potentially crosses three continents, it probably demonstrates different organized crime groups are working together. The potential these items might be sold to people with twisted political and or religious motives isn't too far a stretch.
It has been reported that Al Qaeda training manuals teach their minions to use credit card fraud as a means of financing their activities.
I doubt if most of these criminals could care less, who they are selling them to. Even if they did, the full intent of the purchaser might not be readily apparent.
Suad Leija -- who has been providing information on a major counterfeiting cartel to the government -- says that this was the reason she turned on her family members running the cartel.
This latest example shows that despite a lot of focus on security to prevent terrorist attacks, counterfeit documents are a clear threat to all of us.
Prior to Suad turning against her family, her husband says he tried to get the cartel to let the government use their database as a tool to identify potential terrorists, who might have already crossed our border.
I'm sad to report that the database was never accessed and that the criminal case against the cartel is facing some serious challenges at the present time.
This series of indictments also shows how the Internet is being used to fence a lot of stolen merchandise. Normally, we hear about it happening on auction sites, such as eBay or Craigslist; however in this instance this group had an e-commerce website of their own. This website, Easttrades.com, is still up and running at the time I am writing this.
I decided to run the domain through "Whois" and it’s registered right here in the United States.
Maybe it’s just me, but it appears that we need to take the counterfeiting problem a little more seriously. They appear to be easy to produce and are available to too many people.
They are a gateway for criminals, or worse to commit all sorts of illegal activity. I would love to ask the political candidates running in the current election what they think about this problem.
Unfortunately, my guess is that no one is going to ask them and that this is an issue they would rather not talk about.
Queens District Attorney press release on this, here.
Sunday, February 17, 2008
Is identity theft on the rise, or declining?

(Sign above DMV trash can in LA courtesy of willnorris at Flickr)
Identity theft is making the news again with the FTC's release of their statistics for 2007.
From the press release:
The FTC today released the list of top consumer fraud complaints received by the agency in 2007. The list, contained in the publication “Consumer Fraud and Identity Theft Complaint Data January-December 2007,” showed that for the seventh year in a row, identity theft is the number one consumer complaint category. Of 813,899 total complaints received in 2007, 258,427, or 32 percent, were related to identity theft.Broken down a little further, the report stated that credit card fraud was the most prevalent form of identity theft (23 percent). Utilities and employment fraud followed at 18 percent and 14 percent respectively. Bank fraud was at the bottom of the big 4 at 13 percent.
I found it interesting that utilities fraud and employment fraud ranked in the top four identity theft complaints. Maybe starting to hold employers accountable to match a social security number to an actual name is starting to take a toll on the statistics? In the past -- anyone has been able to use any SSN for employment purposes -- even if the number was made up out of thin air.
Enforcement of no match social security numbers is currently being held up in federal court, but a few States are already taking matters into their own hands.
It’s going to be interesting to see how much of an effect this has on identity theft if full enforcement is implemented. There are a lot of people, who believe the problem of illegal immigration is primarily caused by the people hiring them to hold down their labor costs.
In the current FTC report, Arizona came out #1 in identity theft (again) and is one of the States taking matters into their own hands.
So far as utilities fraud, I remembered a series of conversations I had with Suad Leija and her husband. In case you've never heard of Suad -- she is the stepdaughter of one of the main players of a counterfeit documents cartel -- who has been assisting the government in identifying and going after members of the cartel. Saud told me that in the world of counterfeit documents, utility bills are considered feeder documents. Feeder documents are used by people to establish more legitimate identities, which is normally the goal of people, who need to establish an identity other than their own.
I tried to find something in the current report about this, but I couldn't find anything that suggested why one category was higher than another.
In all fairness -- with all the financial crimes stemming from identity theft and all the crime that hides itself in illegal immigration -- it's extremely difficult to track any of the categories to a particular reason. With all the variables, identity theft isn't a very transparent subject.
There are a lot of people writing about the report. Martin Bosworth (Consumer Affairs) added some telling commentary that supports the contention I made in the above paragraph that the reasons behind identity theft aren't always very transparent.
The agency offered a caveat in its report that the data was not from a survey, but from unverified self-reported complaints.Martin also commented on something, I also noted that was inconsistent for those of us, who follow the identity theft phenomenon:
The FTC's surveys and complaint reports have acted as a counterpoint to claims from the financial industry that identity theft and related fraud are on the decline. A new survey released by Javelin Research & Strategy, and funded in part by Visa, claimed that identity theft dropped by 12 percent from previous years, even as costs of individual cases rose to $691 per affected victim.The dollar amount seems inconsistent between the two reports, either. Javelin says it is $691 per incident and the FTC states the cost is $349.
Whatever report you want to believe, the fact remains that identity theft continues to be a problem and I strongly suspect we have a long way to go before it no longer is an issue.
FTC press release, here.
Full report, here.
The FTC also has some great free resources for people, who want to learn more, or recover from identity theft:
FTC's Identity Theft
OnGuard Online
Fraud: Recognize It. Report It. Stop It.
Wednesday, February 06, 2008
Consumers Union launches Valentine's Day campaign against unfair credit card fees!

Consumers Union is launching a campaign for Valentine's Day to let Congress know that despite overwhelming evidence that credit card companies seem to be gouging a lot of people, very little has been done to correct the problem.
From their website:
Just before the start of this holiday season, the GAO released a scathing assessment of the credit card marketplace and its regulation. Click here for the report itself. See Consumers Union's response to the report and to the problems faced by Consumers. With a national spotlight on an out-of-control industry, its time now to push this to the top of the agenda as a new Congress reconsiders its priorities for Americans.
Many more examples of a LOT of evidence that consumers are due some relief, here.
In their own words, here is a description of the campaign:
Kiss them goodbye--send the Valentine's Day card at right to each of your lawmakers, asking them to pass real reforms for you. As the economy tightens, you need fair credit, not "gotchas." Our goal: 100,000 cards ready for delivery by February 14th.
I'll provide a link to the campaign (in case anyone is interested in an easy platform to voice their opinion), here.
There is no doubt that we are facing an impending crisis with bad debt. Please note that this doesn't only apply to credit card debt. In case you haven't noticed, a lot of people are facing the loss of their homes because of what many consider irresponsible lending practices.
Part of this is caused by fraud, which is what I normally write about. Fraud has been enabled by extremely loose marketing procedures designed to drive selling credit cards, as well as, other financial products.
Whenever a company has losses they have to pass it on in their cost of goods to the people buying their product.
I've often suspected that there is a direct correlation between all the bad debt caused by not very responsible lending practices and some of these hidden fees that keep getting charged to people, who are trying to be responsible and pay their bills.
Is it fair for the people trying to pay their bills to subsidize a lot of bad debt caused in part by irresponsible marketing practices?
Here is one of my favorite posts, which shows how bad debt is enabled by a rush to market a credit card in a not very responsible manner (my humble opinion):
Ever wonder how well you are protected from credit card fraud?
Previous posts, I've written about Consumers Union and their efforts to bring a little sanity to this problem, here.
If you take time to look at these previous posts you will notice that effective action keeps getting blocked before anything is done about this problem. This is probably the best reason (I can think of) to let politicians know that this is an important issue to the people, who will be deciding whether they should remain employed in their current positions.
My guess is that these fees can pay for a lot of special interests to block any meaningful legislation from being passed.
USA Today did an interesting editorial about how much money (an estimated $74 million in the past two decades) has been donated by the card issuers to political campaigns, which might point to the reason why legislation keeps getting blocked.
Thursday, December 06, 2007
Word of mouth is fraud's worst enemy!
In a world, where fraud victims have a hard time getting anyone to even talk to them this saying makes a lot of sense.
FraudAid was conceived by a woman by the name of Annie McGuire, who fell victim to a fraud scheme, herself. Her personal story, which is told in great detail on the site proves that just about ANYONE can become a fraud victim.
In my personal dealings with victims, you would be surprised who has been scammed.
The problem is that most people -- especially those who think they should have known better -- rarely report that they have become a victim of fraud. FraudAid strives to educate all of us that the lack of communication enables fraudsters to victimize people (who if they have been made AWARE) might not be have been taken in by a fraud scheme.
Thus, the reason there seems to be so much fraud and the experts compiling all the statistics disagree on how much fraud exists. After all, "Silence is fraud's best friend."
The FTC just released their estimate of identity theft victims, which has raised a lot of speculation about how accurate their number is.
I have no doubt that the FTC did the best they could, but if fraud isn't reported, it's hard to quantify.
The FraudAid site is a wealth of information for someone, who is trying to seek help after becoming a victim. Of the greatest importance (in my opinion) is how to deal with the authorities.
One page on the site shows the average person how to write a narrative that will get the Police interested in going after your case.
It also goes into great detail on what law enforcement agency specializes in what type of fraud. This can be confusing for someone dealing with being victimized for the first time.
The site also addresses a growing phenomenon, which is how to avoid getting arrested after becoming a victim. With all the auction fraud and stolen financial information being sold wholesale, fraudsters have developed a need to launder the proceeds of their illicit transactions.
The way they do this is by tricking people to do it for them. This is accomplished by hiring them under "false pretenses" to negotiate all their illicit transactions and wire the money to them. This scam is often referred to as a work-at-home, job, or check-cashing scam.
Another variation, known as a reshipping-scam, tricks people into reshipping stolen merchandise.
In reality the victim is taking all the risk for the scammer -- and more and more often -- the rap for them when they get caught. Sadly enough, the end result is almost certain financial ruin and possibly being charged with a host of crimes including, check fraud, money laundering and receiving stolen goods.
Some of detailed information on the different scams that can be found on FraudAid include investment, Nigerian (419), sweetheart/romance, lottery sweepstakes, lottery, work-at-home, visa/green card, counterfeit check/money order and reshipping/package processing scams.
Also covered on the site is how to protect yourself and recover from identity theft. Many fraud victims later become a victim of identity theft when a fraudster sells all the information they've data-mined off them.
The site even contains information on child safety and human trafficking.
Backing all this up are a host of research tools for fraud, where to report it and how to take political action.
Annie is now backed up by a group of volunteers, one of whom, Karrie Brothers, assisted me with a lot of information on the current going-ons at FraudAid.
To grow this effort, Karrie and Annie are actively seeking volunteers to assist them. Being one of the few resources where a victim can turn to, they are getting a lot of business!
FraudAid gives a good explanation of why volunteers are needed and they are trying to grow their organization:
Fraud, by every measure, is one of biggest and fastest growing industries in the world.
One study values worldwide corporate fraud at over two trillion dollars. This is not counting consumer and Internet frauds for which there is no reliable assessment. Another study estimates that 6% of global product is laundered money.
The fraud industry is run by many, many skilled professionals. The anti-fraud industry is small and, by comparison, run by very few skilled professionals.
That's why if you have the skills you can make a real difference!
Fraud Aid, Inc. is a volunteer anti-fraud organization. We, as all other anti-fraud organizations, are out-numbered and need your help.
We have the frauds. Do you have the time?
To grow the organization, they are recruiting a wide range of volunteers with law enforcement, legal, IT and education experience. There are also opportunities for people with no experience, also.
Even if you think you are aware of all the fraud schemes out there, FraudAid is a great place to learn more about them. After all, if people weren't being taken in by the schemes, fraud would probably disappear pretty quickly!
If you want to learn more about FraudAid, the site can be seen, here.
Wednesday, November 28, 2007
Search warrant of credit card fraudster's house reveals 185,000 stolen social security numbers from the VA

(DMV photo of Kim from the OC Register)
Not sure what's wrong with this picture, but it was recently discovered that a suspected gang member (Tae Kim) got himself a job as an auditor at the Veteran's Administration, despite the fact he had a criminal record, and stole 185,000 social security numbers.
The stolen social security numbers were discovered when a search warrant was done at his house after he was implicated for using stolen (skimmed) credit card information at a jewelry store.
One of the credit cards used contained the skimmed information of Marlon Wayans, a well-known actor.
Erika M. Torres of the OC Register reports:
A man who purchased $5,600 in jewelry at a store in Tustin using three fraudulent credit cards, one belonging to actor Marlon Wayans, was arrested Thursday in Los Angeles after a months-long investigation, said Tustin police Lt. John Strain.
The investigation also uncovered from his home computer about 1.8 million Social Security numbers from the U.S. Department of Veteran Affairs, where Kim had been employed as an auditor. Veterans Affairs' officials have said only 185,000 numbers are at risk because many were repeated in the file.
Apparently Kim quit his job at the Veteran's Administration after finding out that they planned to do a criminal background check on him.
Pretty scary that a federal agency doesn't vet their employees before hiring them and then gives them access to personal and confidential information.
While data breaches are daily staples in the news, this story might suggest there are many smaller ones that no one knows about.
Given that Kim is suspected of being a member of the Koreatown gangsters and was caught using counterfeit credit cards, I wonder if he was intentionally planted at the VA for the purpose of stealing information?
In the information theft world, it wouldn't be the first time a criminal outfit planted someone in an organization with the intent of stealing information.
Bob Sullivan at MSNBC did an article in 2004 quoting studies that showed that a large amount of the information stolen was due to insider theft, here.
Another more recent story in the news is an employee at Certegy, who is now pleading guilty to stealing 2.5 million peoples information, here.
OC Register Story on Mr. Kim, here.
This isn't the first time the Veteran's Administration has been the subject of sloppy security:
In May of 2006, they lost a laptop with 26.5 million people's information from an employee's house. It was later found and the FBI stated they were pretty sure that none of the information had been used.
In August of 2006, it was reported that one of their vendors lost a laptop with 38,000 people's information on it.
Wednesday, November 21, 2007
Too good to be true employment opportunities
The problem, I'm referring to is people being recruited (some might say duped) to assume the risk involved in collecting the proceeds of Internet crime.
With all the fraud occuring on auction and e-commerce sites -- criminals need a way to move they money they are stealing. This activity is often referred to as money laundering.
They accomplish this with money transfer scams, which are sometimes referred to as job scams.
These scams are nothing more than a way to trick people into negotiating bogus financial instruments, or launder the proceeds of auction fraud!
We've all probably seen a spam e-mail, or two (I get several daily) with job offers that seem a little too good to be true. Most of these jobs seek a financial representative to handle payments for a foreign company. In reality -- the person is moving stolen money overseas -- where it disappears into thin air.
Besides being offered in spam e-mails, people are also recruited off job sites and sometimes even from the classifed sections of newspapers and magazines.
A sister scam to money transfer scams is referred to as a reshipping scam. The difference is in this job a person reships hot merchandise (normally from auction sites) to their bosses.
In most of these scams, they prefer you use Western Union or MoneyGram to send them their money. Once the money is picked any efforts to recover it will most likely be useless. Please note that there are many e-cash venues that are used, also.
While these jobs might have fancy titles, a lot of people refer to someone doing this as a "mule."

(courtesy of mattcoz at Flickr)
In Patrick's post, he reveals another twist to this activity, which are websites set-up to make these jobs appear to be legitimate.
Here is a screen shot (courtesy of the Sunbelt blog) of the site Patrick discovered:

He also lists some other sites to avoid from the same IP in his post, which can be seen, here.
Most of these scams are pretty easy to discover because they are offering too much money for too little work.
These job offers are nothing more than a way for criminals to get other people to take all the risk, while they reap the rewards of their illegal efforts!
Besides facing almost certain financial ruin, some of these employees are ending up living in new digs:
Sunday, November 11, 2007
Major cybercrime and identity theft group smashed in NYC
The New York/New Jersey Electronic Crimes Task Force and a host of other agencies assisted in the investigation, also.
From the DANY press release:
Manhattan District Attorney Robert M. Morgenthau announced today the indictment of seventeen individuals and one corporation on charges related to global trafficking in stolen credit card numbers, cybercrime, and identity theft. Three defendants will be arraigned today.
The three defendants to be arraigned today are VADIM VASSILENKO, YELENA BARYSHEVA and JOHN WASHINGTON.
Six other defendants – TETYANA GOLOBORODKO, DOUGLAS LATTA, ANGELA PEREZ, KOSTAS KAPSIS, LYNDON ROACH and KEITH CUMMINGS – were arraigned earlier. Two defendants, EDUARD KHOLSTININ and OLEKSIY YARNE, are in custody in other states on unrelated charges and six other defendants are still being sought.
Also indicted is WESTERN EXPRESS INTERNATIONAL, INC., a corporation formerly headquartered in mid-town Manhattan at 555 Eighth Avenue. Western Express’s corporate officers are VADIM VASSILENKO and YELENA BARYSHEVA. TETYANA GOLOBORODKO was the manager of WESTERN EXPRESS.
Although not specified in the press release, most of the surnames of the indivduals involved appear to be Russian, or Eastern European. Most experts concede that Russian and Eastern European organized crime organizations are the major players in the stolen payment card information business.
The activity involved in this appears to highly organized, and technically sophisticated:
The Western Express Cybercrime Group carried out its criminal operations through a structure consisting of “vendors,” “buyers,” “cybercrime services providers,” and “money movers.” The “vendors” were individuals who sold large volumes of stolen credit card numbers and other personal identifying information through the internet. The “buyers” used the internet to purchase that information from the “vendors,” for the purpose of committing additional crimes such as larceny and identity theft. The “cybercrime services providers” promoted, facilitated, and aided in the purchase, sale and fraudulent use of stolen credit card numbers and other personal identifying information through various computer services that they provided to the “vendors” and the “buyers.” Finally, other defendants operated as “money movers.” Those defendants provided financial services and conducted financial transactions for other participants in the criminal enterprise in order to move funds and launder the proceeds of criminal activity. The “money movers” relied on anonymous digital currencies, such as Egold and Webmoney, to buy, sell, and launder the proceeds of criminal transactions, and conducted their business online, using websites, instant messaging, and email. Some of the defendants charged in the indictment played more than one role.
Those involved in the Western Express Cybercrime Group interacted and communicated through “carding” websites – that is, websites devoted to trafficking in stolen credit card and personal identifying information. They relied on the use of nicknames, false identities, anonymous instant messenger accounts, anonymous email accounts, and anonymous digital currency accounts to conceal the existence and purpose of the criminal enterprise, to avoid detection by law enforcement and regulatory agencies, and to maintain their anonymity.
The entire operation was set up under a business in Manhattan known as Western Express. This business appears to have been nothing more than a sophisticated money laundering operation:
The corporate defendant WESTERN EXPRESS INTERNATIONAL, INC., through its managerial agents VADIM VASSILENKO, YELENA BARYSHEVA, and TETYANA GOLOBORODKO, provided financial services designed to conceal the source and destination of funds earned through the trafficking of stolen credit card numbers and other personal identifying information, as well as the identity of individuals engaged in such transactions. They used conventional banks and money transmitters to move large sums of money for their clients, thus permitting their clients to remain anonymous and insulated from reporting requirements. They also provided information and assistance to other members of the group through the WESTERN EXPRESS websites Dengiforum.com and Paycard2000.com.
Apparently, this business had about $35 million flow through it's various accounts and is responsible for a known $4 million in credit card fraud. The investigation also revealed that they trafficked over 95,000 credit card numbers.
The press release stipulates that this is only what has been identifed thus far.
In February 2006, Western Express was also indicted for running an illegal check cashing/wire transfer service. Through it's various websites it offered one-stop financial services enabling Eastern European customers to do business in the United States and vice-versa.
This business was also a front for laundering the proceeds of a lot of fraud activity:
The investigation has revealed that their clients were involved in widespread illegality beyond the mere receipt of funds under fictitious aliases and addresses, including a variety of cyber-crimes such as “re-shipping” schemes and “phishing,” “spoofing” and spamming.DANY press release, here.
Friday, October 05, 2007
Retailers call for a level playing field on data security
Thus far, we've seen legislation introduced to hold retailers responsible and calls for PCI data security standards. Legislation has been passed in Minnesota and is awaiting Governor Schwarzenegger's signature in California.
In any disagreement, there are two sides to a story -- and now the National Retail Federation (NRF) is bringing up what I consider is a valid point -- which is if they weren't required to store all this information, it would be harder to steal.
Under current rules, they are required to maintain too much information for 18 months, or face what are known as chargebacks.
Chargebacks are when a customer requests a refund from their card issuer, normally because of fraud. Please note that some dishonest customers claim fraud, when it never occurred. Additionally, the payment card industry sets the due diligence standards when accepting their cards and actively promotes their use.
The bottom line is -- merchants can accept payments, follow all the rules, and if they can't provide the required information -- they get charged for it, anyway.
With all the fraud that results from payment cards, this could get pretty expensive for a retailer, if they fail to control it.
Saying all this, we need to consider the bigger picture, which is the best way to protect data is to limit how many places it is being stored. This principle should be considered in a lot of other places besides retailers, also.
Mark Jewell of the AP is reporting:
The National Retail Federation on Thursday urged a card industry organization to stop requiring retailers to keep customers' card numbers for up to 18 months.In the article, Mr. Hogan brings up the very reason that retailers have been holding on to what some consider, too much information:
The stored data helps track product returns and disputed or suspicious transactions. But retailers say the data would be more secure if only credit card companies and banks that issue the cards stored it.
"It makes more sense for credit card companies to protect their data from thieves by keeping it in a relatively few secure locations than to expect millions of merchants scattered across the nation to lock up their data for them," David Hogan, the retail federation's chief information officer, said in a strongly worded letter.
Hogan said in an interview that retailers routinely hold onto information because credit card companies ask them to produce data from transactions as old as 18 months to verify product returns and protect against fraud. If retailers can't produce data showing the product was legitimately purchased, they can end up reimbursing banks and card companies, Hogan said.Only 44 percent of large retailers are now PCI compliant. This month, the larger retailer's banks will start facing fines for failing to become compliant. Banks that service medium size retailers will start facing fines in January.
This doesn't even take into account smaller merchants, who often are victimized the most by fraud, and chargebacks.
In case you don't understand how chargebacks can be a burden to a merchant, I've included a YouTube video at the bottom of this post, where a small merchant rants about chargebacks from PayPal.
The frustration expressed in this video is the same one felt by a lot of merchants (retailers).
The basic issue in all this is who will end up paying for it. Since no business remains solvent if they are losing money, the costs are going to end up being passed on to the consumer.
So far as the NRF's point, I think it is entirely valid. If retailers didn't have to store all this data, it would be one less place, where criminals could access it.
After all, while data breaches at retailers have gotten a lot of attention recently, they are not the only place they are occurring.
If you are interested in seeing what I mean by this the Privacy Rights Clearinghouse, PogoWasRight and Attrition.org all try to keep track of as many of them as they can.
All of them will tell you that their efforts only document the known breaches. There are probably many more that no one knows about -- and the last I heard -- the criminals behind them keep this a closely guarded secret.
After all, disclosure of a data breach impacts their bottom lines, also.
My personal solution is for everyone to get together and go after the real people behind this problem, or the criminals. Everyone would benefit from this!
My guess is they (the criminals) could care less, who ends up paying for all the damage they are causing.
AP story, here.
National Retail Federation (NRF) press release, here.
Here is the YouTube video (mentioned above), which reflects a small merchant's frustrations with the chargeback process. Please note that smaller merchants are bound to have a stake in what becomes of this controversy, also.
(YouTube video courtesy of Terry)
Saturday, August 11, 2007
Self service stamp machines targeted by credit card thieves

Photo courtesy of Leff at Flickr
New scams are invented daily. Here is one, where self-service stamp machines (the kind that accept payment cards) are being targeted at Post Offices.
David Bowermaster at the Seattle Times is reporting:
In mid-July, three men left their homes near Los Angeles and traveled to Seattle to buy postage stamps.
But these were no ordinary collectors. Armed with at least 27 stolen credit-card numbers, federal prosecutors say, Artem Danilov, Stephan Melkonyan and Karapet Kankanian fraudulently purchased more than 3,200 books of stamps worth nearly $24,000 from Seattle-area post offices in just more than a week. A federal grand jury Thursday charged the men with an assortment of crimes.While these three were caught (two Russians and an Armenian), it appears this activity has been occurring throughout the Western United States.
Following a pattern that Postal Service investigators have uncovered in at least five Western states, the men made mass purchases of stamps after normal working hours from automated postal machines, which are accessible 24 hours a day in the lobbies of many post offices around the country, prosecutors allege.
The illegal stamp-buying scheme appears to be a novel breed of identity theft, one that blends high-tech thievery, online commerce and the retro currency of the U.S. mail.
James Vach, a spokesman for the U.S. Postal Inspection Service in Seattle, said investigators first encountered a wave of fraudulent stamp buys in the Los Angeles area late last year.
Since then, the Postal Service has uncovered illegal stamp-buying schemes in Washington, Oregon, Arizona and Colorado.
The Postal Inspectors suspect a larger ring is involved and some of the stolen credit card numbers used have been traced to a car wash in Southern California.
According to the article, here is how the suspects were using the stolen credit card numbers:
Danilov, Melkonyan and Kankanian allegedly used a credit-card reader to embed the stolen credit-card numbers onto the magnetic strips of gift cards from a variety of retailers, Brown said, a process that allows the gift cards to function like credit cards.
They then used the adulterated gift cards to repeatedly buy books of stamps from postage machines in one post office after another. Customers used to be able to buy dozens of books of stamps per transaction from the automated postage machines, but the Postal Service has since limited the number to try to fight such fraud.
Although the authorities don't know where all the stamps were being sold, according to a assistant U.S. Attorney, some of them are being fenced on eBay.
A lot of stolen merchandise is fenced on eBay and other auction sites. A lot of this stolen merchandise is purchased with fraudulent credit/debit card information.
Out of curiousity, I decided to see if new stamps (the kind used for postage) could be found on eBay. Amazingly enough, I found what I consider a large selection with offers of free shipping and discounted prices. What I found can be seen, here.
Of course, at a glance, it can be hard to tell what is legitimate and what is not on an auction site.
A lot of stolen gift cards (used in this instance to clone the cards used) are also fenced on auction sites. I wonder if the value on them had already been used, or if our suspects lifted them at a retailer before a dollar value was loaded on them at a point-of-sale (register)?
Seattle Times story, here.
If you spot this type of activity during a visit to the Post Office, you can report it to the Postal Inspectors, here.
Although two of the suspects apprehended were Russian, the U.S. resident was an Armenian from Southern California. Recently, Armenians (from Southern California) have been tied into similar type activity. The previous posts, I've done on these stories can be seen, here.
Saturday, August 04, 2007
Celebrities, including Paris Hilton become identity theft victims

(Courtesy of Flickr) Only the photographer knows who is behind the mask.
No one's identity is safe these days. It's just been reported that a lot of celebrity types, including Paris Hilton have had their identities jacked (stolen).
Tampa Bay's 10.com reports:
Investigators busted a massive identity theft ring allegedly operating out of a row home in Northeast Philadelphia Friday.Allegedly, a couple of fraudsters used change of address forms and had mail diverted to a Philadelphia address. They then used the information from the stolen mail to order checks and credit cards.
Police said the list of targeted victims includes celebrity names like Donovan McNabb, his mother Wilma, Jennifer Lopez, Paris Hilton, Whitney Houston, Patti LaBelle, Michael Vick and Microsoft founder Paul Allen.
The article also states that one of the fraudsters was a former IRS employee, and that some of the information might have been stolen from their computers.
Considering the names they were using, one might wonder why no one noticed at the banks, credit card companies, or the post office when this scheme was first hatched?
In case any of these famous people are wondering why it was so easy to use such recognizable names, it might be because issuing credit cards, checks and (I'm guessing) address changes are approved by computers.
To demonstrate this, they might want to read a previous post I wrote:
Ever Wonder How Well the Credit Card Companies Protect Your Personal Information?
I did another post, where a cat was issued a credit card, also:
Should cats be issued credit cards?
According to the article, this case is still being investigated and the list of people compromised is likely to grow.
It will be interesting to see, if it is ever disclosed, how long this went on and how much money was stolen as a result of this!
10.com article, here.
Tuesday, July 31, 2007
Correctional Officers steal credit cards from prisoners
John-John Williams IV of the Baltimore Sun reports:
Two corrections officers from the Central Booking and Intake Center were arrested yesterday and charged with stealing credit cards of people under arrest.The authorities investigating the case aren't commenting because the investigation is still underway.
Lontona Maria Webb, 38, of the 3600 block of Clarinth Road and Latoya Renee James, 24, of the 1300 block of Dalton Road each face multiple counts of credit card fraud, identity theft and misconduct in office, according to charging documents.
It also appears that the Baltimore Sun and an attorney, who was arrested (charges later dropped) are responsible for alerting the authorities that their jail needs a little cleaning up:
Nicholas Panteleakis, 34, a city public defender, said that his credit card was used to make nearly $1,000 in fraudulent purchases at McDonald's, Target and a gas station.
Panteleakis said that his credit card company took care of all of the fraudulent charges.
The Sun detailed Panteleakis' claims of fraud at Central Booking in February. At that time, Panteleakis said he discovered that someone had used his credit card within six hours of his release from Central Booking. He said he believes the card was stolen after his wallet was checked as property at the facility when he was arrested on one count of loitering, a charged later dropped. He immediately canceled his credit card.
"If it wasn't for my access to the media and other avenues, I don't think anything would have become of it," he said. "People would still be having their stuff stolen from them."
As a result of this, officials at the jail have had video surveillance cameras installed to watch the area, where personal property is inventoried.
It's sad when we discover those, who have taken a sacred oath to uphold the law, violate it. They damage the reputation of their profession, and all the fine people, who take this oath seriously!
Unfortunately, this isn't the first time, I've done a post, where a correctional officer (and some Jet Blue employees) were stealing credit cards:
Airline employees and correctional officer arrested for credit card fraud
Baltimore Sun story, here.
Saturday, July 28, 2007
Certegy reveals their data breach is a lot larger than originally reported
Now the number of records (people compromised) has risen significantly after Certegy filed a report with the Securities and Exchange Commission.
The Tampa Bay Business Journal Reports:
An ongoing investigation has determined that about 8.5 million consumer records were stolen, according to a July 25 Securities and Exchange Commission filing by Fidelity National Information Services Inc. (NYSE: FIS), the Jacksonville-based parent company of St. Petersburg-based Certegy.According to Fidelity, Certegy's parent company the investigation is continuing and this number could grow.
Florida Attorney General Bill McCollom listed some useful information for victims in a press release, which said:
For more information, consumers may call Certegy at 866-498-9916 or may visit their website at http://www.certegy.com. Affected consumers are encouraged to take the precautionary steps outlined in the Certegy letter, including obtaining a free fraud alert from one of the credit reporting agencies. Furthermore, if consumers believe at any time they are victims of identity theft, they should report this to the police and request that the national credit bureaus place a fraud alert on their credit reports. Consumers should also notify banks and creditors involved of questionable charges or accounts, keep records of all telephone calls and follow up in writing with credit bureaus, banks and creditors.
If you received a letter from Certegy and you continue to receive marketing calls that you suspect result from this data breach, please report this activity to the Attorney General’s Citizens Services Hotline at 1-866-9-No SCAM (1-866-966-7226). Additional information about protecting yourself from identity theft is available online at http://www.myfloridalegal.com/identitytheft.
I've received a lot of comments on my original post, including some (anonymous) claiming their information was used for fraud. Unfortunately, I cannot verify this information, but someone with the e-mail address LPLong@Yahoo.com claims to be collecting victims to file a class action law suit.
My original post with comments, here.
Press release from Florida Attorney General (Bill McCollom), here.
Note this is probably the right place to verify information, if you receive a letter. If you believe you are fraud victim based on the Certegy breach, I would let them know about it, also.
Tampa Bay Business Journal article, here.
