Showing posts with label credit card fraud. identity theft. Show all posts
Showing posts with label credit card fraud. identity theft. Show all posts

Friday, May 11, 2007

British citizens accused of child porn found to be fraud victims

Information (identity) theft sometimes leads to innocent people being charged with a crime. Recently, I've been reading about how British citizens were accused of viewing child pornography, when they were actually victims of credit card fraud.

The Guardian did an excellent article about this, explaining how the porn industry supplements it's income with payment (debit/credit) card fraud. This explains how innocent people, who are victims of credit card fraud, get accused of crimes they didn't commit:


One method used from 1999 by criminals, including the Gambino mafia family in the US, was to offer free tours, or access for a credit card payment as small as $1.95, to adult sex sites. Customers had to provide name, address, card details, and email address and password. The criminals then reused the data or traded them online with other fraudsters.

Operating out of Indonesia, Russia or Brazil, many of the webmasters linked via Landslide appear to have obtained and swapped lists of stolen cards and charged them up through different portals, usually for amounts of less than $50 - small enough that unwary people might not spot them on a credit card statement.


The current arrests stem from a larger investigation, where a U.S. based child porn website (Landslide Inc.) was investigated, revealing 250,000 credit card numbers (used on the site), belonging to card holders, worldwide.

Copies of the hard drives were provided to British law enforcement. Subsequently, thousands of British citizens were investigated, as a result of having their credit card number show up as having paid for Landslide's seedy services.

The investigation began in 1999 and was conducted by the United States Postal Inspection Service and Dallas Police Department. It exposed how the Internet is used to commit this disgusting crime (child pornography), globally, with the click of a mouse.

The investigation tracked activity to 60 different countries. 120 people were eventually arrested in the United States. Pete Townsend, the Who's guitarist was arrested for viewing child porngraphy in this investigation, also.

54,348 of the credit card numbers discovered in the U.S. search warrant were identified as having been stolen from Levenger Incorporated, a luxury goods company. Of course, Levenger declined to comment on how the information was stolen.

The Guardian article makes a clear argument that many more of the numbers taken in the search warrant could have been stolen (in a lot of places) and used on the Landslide site.

The sheer amount of stolen information and fraudulent payment devices circulating via the Internet is victimizing innocent people, and more than likely giving guilty people, plausible deniability.

Not everyone caught in this was a victim of credit card fraud. Exploiting children is one of the most disgusting crimes I can think of. People, who exploit children, deserve to be punished, severely.

It's apparent that our inability to address the source(s) of crime on the Internet is having VERY severe consequences on the people, who are victimized by it.

Innocent, or guilty, 39 people have committed suicide over this. Wouldn't it be nice if some of these child pornographers/credit card fraudsters could be charged with murder, or at least manslaughter?

USPIS press release on Operation Avalanche, here.

Suspected crimes against children can be reported to the National Center for Missing and Exploited Children, here.

Well researched article from the Guardian, here.

Friday, May 04, 2007

TSA loses 100,000 employee records and discloses the matter, immediately


For the first time, I can remember a data-breach is being reported the day after it was discovered by an agency entrusted to protect and serve the public at large. Here is part of the press release from the Transportation Security Agency (TSA):


Yesterday the Transportation Security Administration (TSA) became aware of a potential data security incident involving approximately 100,000 archived employment records of individuals employed by the agency from January 2002 until August 2005. An external hard drive containing personnel data (including name, social security number, date of birth, payroll information, bank account and routing information) was discovered missing from a controlled area at the TSA Headquarters Office of Human Capital. It is unclear at this stage whether the device is still within headquarters or was stolen. TSA immediately reported the incident to senior DHS and law enforcement officials and launched an investigation.


Of note, the information compromised here is everything an identity thief would need to completely assume another person's identity, sometimes referred to in carder forums as a "full."

Carder forums (chatrooms) are where a lot of stolen personal and financial information is sold, right over the Internet.

Their press release on this unfortunate matter states they have extensive data protection protocols, which I would hope include the fact that the data (stored on a portable device) was encrypted.

I'm sure some are going to try to bash TSA for this incident, however I am going to take a different stance, which is they appear to be handling the matter a lot more responsibly than many organizations that have breached, recently. In my humble opinion, the TSA is taking this seriously and handling this matter the best way possible. Data breaches embarrass a lot of organizations -- too many of them would rather avoid the negative publicity -- instead of doing the right thing to protect their (in this case OUR) most valuable asset, people.
I'm not thrilled with this data breach -- or that information continues to be left where it shouldn't be -- but disclosure (being more honest) goes a long way towards fixing the overall problem.

Recently, a TSA employee caught a culprit with 43 different driver's licenses and a lot of bogus payment devices. We need to remember that the people compromised by this, protect all of us!

I really liked their statement about what they intend to do about it - if wrongdoing is discovered:

TSA has extensive data protections protocols and training in place for its employees regarding data privacy. TSA has zero tolerance for employees not following policies on data protection and will take swift disciplinary action, including dismissal, against individuals found to be in violation of our procedures.


I'm not able to comment on TSA's data privacy procedures (never seen them), but one person with access, who violates any data privacy procedure can do a lot of damage.
If anyone knows something about this data-breach, information can be submitted to the FBI (investigating agency), here.

Data breaches have happened at a lot of places. If you are interested in reading more about them and where they occurred, the Privacy Rights Clearinghouse maintains a chronology, here.

A lot of data breaches occur when information is stored on portable (easily stolen) devices. Some claim that even if encryption is present on the device, the wrong person can still (sometimes) access the information.

The full press release can be read, here. They also link to the new government site on identity theft (worth a read if you haven't seen it yet), here.

Wednesday, April 18, 2007

Are Charity Fraudsters (Phishermen and Pharmers) preparing to exploit the Virginia Tech Disaster?

Internet criminals use disasters to get nice people to donate their hard-earned money to them, personally. Recent examples where this occurred have been the Katrina hurricane, Tsunami disaster and London bombings.

According to the Sans Internet Storm Center, we can probably expect the same activity to occur in the wake of the Virginia Tech Disaster.

Here is what they are reporting in their Handler's Diary:
There has been a flurry of domain registrations related to the Virginia Tech tragedy, as reported by GoDaddy and other registrars. While some of these are undoubtedly well-intentioned organizations joining in the outpouring of support for the friends and family of the victims, others are likely to be opportunists who want to cash in on the suffering of others.

Be on the lookout for a rash of spam & phishing coming from these leeches. If you receive a plea for donations, check the organization out closely before opening up your e-gold, Paypal, Visa or other account or providing any personal information. In some cases the phishers may use voice, fax, email and websites to dupe generous and thoughtful victims into disclosing valuable information.
Full diary post (with potential domains being grabbed), here.

As the SANS post aptly points out, giving out any personal, or financial information to one of these fraudsters (leeches) can have more consequences than giving your money away to the wrong place (identity theft).

Here are some investigative (due diligence) resources someone might take advantage of to make sure they are donating their money to a worthy cause:

Better Business Bureau Wise Giving Alliance

Charity Navigator

American Institute for Philanthropy

The Federal Trade Commission (FTC) has some information on how to make sure your money goes to the cause you intend it for, here. Also contained on this page is where you can report fraudulent activity to them, which is highly recommended.

Tuesday, November 14, 2006

Ever Wonder How Well the Credit Card Companies Protect Your Personal Information?

Ever wonder how well your personal information is protected by credit card issuers? If you are like most people - your mailbox is filled with pre-approved credit card offers.

In April, I did a post on how easy it was to tape together a ripped up credit card application, change the address and telephone number (a cell phone was used) and get a brand new credit card.

NBC News did basically the same thing that Rob - Cockeyed.com blogger did - and got similar results:

From the NBC News story:

You think ripping up those credit card applications is enough to prevent identity theft? Think again.

Getting the credit card applications has never been the problem. It's what to do after they pile up that's the real consumer dilemma.

We've been warned for years-- if you don't want 'em, destroy 'em. However, ripping and tearing may no longer seem like enough.

With five applications, and a little muscle, we started ripping. Scotch taped them back together. And wrote around the tape- filling out the application the way an identity thief might if he'd been digging in our garbage.


NBC News story, here.

And the results were a 60 percent success rate, or they got 3 brand new credit cards.

The official responses to how this happened by the credit card companies were:

In a statement, chase card services says it has "rigorous policies" for handling applications and a "special handling process" for the rare torn applications. In this case, however, "it is clear to us our procedures were not entirely followed for this particular application...and we are investigating."

For the two cards it issued, Bank of America, which merged with MBNA, says the applications "both went through the proper verification processes" and that "the signature, social security number and birth date matched" a (current) customer with excellent credit.

The company added that it sometimes sends cards to unrelated addresses as a convenience customers have requested.


Many of these institutions are claiming they have a "zero liability" for fraud - the reality is that we are all paying for it in the form of increased fees and interest rates.

After all - how would they stay in business otherwise?

A lot of them are also selling "identity theft products," which adds another revenue stream to their coffers. Some believe they have helped create this industry by not protecting their customer's information in a "responsible manner."

The conclusion of the NBC article was to "opt out" and of course - buy a good shredder.

You can opt out by calling 1-888-5-opt-out.

It's a shame that we all need to buy shredders and "opt out" to protect ourselves from "marketing practices" that victimize innocent people.

Here is a recent post, I did on how credit cards can (getcha):

A Hidden Cost of Identity Theft - "Credit Card Gotchas"

Wednesday, October 18, 2006

Fraudsters Impersonate Bank Security Departments to obtain CVCs

You get a call from your credit card company's security department and they already have your credit card number. Does that mean you should trust what they are saying?

Probably, not a good idea!

The Sussex Sun is reporting:

A new credit card scam has emerged and police are cautioning people to be leery of phone callers saying they represent a credit card company.

The twist to this latest scam is that the caller does not ask for a credit card number, but for the three-digit security number on the back of the card.

According to police, the caller identifies himself or herself as an employee of VISA or MasterCard working in the security and fraud department.


Sussex Sun Story, here.

The "telephone fraudster" then brings up an "alleged" fraud purchase and when the intended victim claims to have never made it - they are conned into giving up the three-digit number (CVC) on the back of their card.

A lot of e-commerce companies are now requiring this CVC (Card Verification Code) to make online, or telephone purchases.

CVC is an extra layer of protection, common in the credit and debit card industry.

Unfortunately, there is a lot of credit card information being bought and sold in "carder" rooms. From the "carder" perspective, cards with the CVC included are worth a lot more than cards without them.

Link to my most recent post about this, here.

The Sussex article recommends you call your credit card company and report the attempt. I agree with them this since - if you get a call like this - the crooks already have your number!

It's also probably a good idea to take a look at your credit report and make sure they aren't already compromising your information. If they are - I have a lot of links on this site on where to go and seek help.

This activity is also sometime known as "Vishing," Wikipedia already has a good article on this, here.

Tuesday, October 17, 2006

Answer a "Too Good to be True" Work-at-Home Ad and Take the Rap for the Phishermen

Ryan Naraine of eWeek did an interesting story about how the phishermen launder their ill-gotten proceeds:

"The dramatic rise in phishing and identity theft attacks includes a well-organized offline component—the not-so-innocent "money mule" recruited by fraudsters to launder stolen money across the globe."

"The ads appear innocently on all the major employment listing sites, offering stay-at-home positions titled "shipping manager," "private financial receiver" or "sales representative."

eWeek story, here.

In the article, they responded to a Craiglist Ad - where after being prompted to submit personal and financial information to the Russian Mob - a base salary of $2000.00 a month was offered, plus $50.00 for each wire transfer and or shipment successfully received by them.

I agree with the article that people involved in this "aren't always so innocent," but since all the stolen money and merchandise will be sent to the new employee -- guess where law enforcement is going to trace it to?

Here is where anyone accepting these jobs could end up.








Also mentioned in the article was that prospective employees for these mobsters are required to submit a lot of personal and financial information about themselves to "hired." My guess is that this will be used to commit even more crimes without the knowledge of the employee (identity theft).

Trust me, Boris and his merry band of "Vlads" are expert at this.

Here is a story about a Better Business Worker caught up in one of these job scams:

BBB Worker Takes Job Processing Fraudulent eBay Transactions