Showing posts with label cyber crime. Show all posts
Showing posts with label cyber crime. Show all posts

Tuesday, February 03, 2009

Increase in Scams Attributed to Economy

I just finished reading an interesting article in the Wall Street Journal by M. P. McQueen, which suggests that the bear market is creating a bull market for fraudsters. According to the numerous experts cited in the article, the reason for this is economic gloom and doom with a healthy dose of anxiety.

This shouldn't be surprising because gloom, doom, and anxiety make effective social engineering tools that can be used to part people and businesses from their money.

The article references phishing expeditions that lead to fake Web sites — which often spoof a financial institution or government entity — and entice people into giving up enough of their personal details to drain their financial resources. It also mentions that some of these sites leave behind malicious software on a person's machine, which steal all these details automatically.
Also mentioned is the use of VoIP (Voice over Internet Protocol), caller-ID spoofing and cell phone technology to mount texting and vishing attacks. Vishing is merely another method of tricking people to give up personal and financial information via the telephone. In these attacks, the caller ID is spoofed to make it appear as if it is coming from a legitimate institution.

Apparently telephone technology is being used to commit other types of crimes, too. Many of our 911 centers cannot identify spoofed calls coming from computers using VoIP technology. This has led to S.W.A.T. teams being tricked into deploying in full battle gear to residential neighborhoods when no emergency existed. Of course, businesses use the same technology to trick people who have caller ID into picking up their telephones. You can even buy a card to do this at will from any telephone right over the Web.

It sometimes amazes me how much irresponsible technology there is out there, which is being sold legally. There are even Web sites, with disclaimers, that specialize in making this technology available to the general public. Of course, there are also complete DIY (do-it-yourself) phishing kits being sold over the Internet. Some of these even come with tech support. The phishing kits are illegal, but can be found for sale in chat rooms if you know where to look for them. Sadly, the truth is that these chat rooms aren't very hard to find. The fine line between legitimate enterprise and scams is often a little blurry.

The WSJ article quotes a lot of experts, including Gartner, the FBI and the National White Collar Crime Center, who all seem to agree that scams are on the rise. An interesting phenomenon called out were small fraud charges being found on accounts. I guess taking small amounts, which might be mistaken for bank fees, is a good way to stay under the radar. A lot of people don't realize how many small fees are being charged to their account and it can be quite confusing at times. I guess the crooks are trying to make themselves look like bankers (speculation) and it's probably a good time for all of us to review our statements, carefully.

Speaking of fees, which are used as revenue streams by a lot of businesses, the WSJ put out another article this entitled, "In the Fight Against Bill Creep, Every Extra Fee Is the Enemy." Besides being on the look out for cyber scammers, this article points out other reasons it is smart to review our financial statements with a keen eye these days.

Another notable trend in the past 12 months is executives being targeted. In this trend, specific people within organizations are being targeted and tricked into downloading malicious software on machines. In one of these scams last April, the targets were led to believe they were being subpoenaed to testify in federal court.

Last, but not least, the article points out that job scams are on the rise. It's a well established fact that job sites from Monster to Craigslist have scammers operating on them to recruit people to launder money, cash bogus financial instruments or give up all their personal and financial information. Adding fuel to this fire, it was disclosed recently that Monster.com had been hacked.

Capping off this interesting article — which is a pretty good recap of recent scam activity — is Pam Dixon of the World Privacy Forum pointing out that scammers have learned how to use "spell check." In the past, one of the best ways to identify a scam was it's lack of proper spelling and grammar. While the scammers might have have learned to use spell check, it might also point out that there are more and more people out of work (with better grammar skills), who are becoming scammers.

The WSJ quoted a lot of experts that agree with them that scam activity is on the rise. Another interesting read supporting this (not mentioned in their article) is the recent report that was commissioned by McAfee. This report points to all the unsecured data out there that is fueling the rise in cyber crime. They estimate, at this point, that the financial implications have reached $1 trillion. They also have some interesting information about social engineering and how it is being currently used to commit scams in the current economic environment in another set of articles on their main site.

In my opinion, it makes sense that scams of all kinds are on the rise. There is a lot of confusion going on and people are getting desperate. It might be desperation that is causing more people to get involved in scams on both sides of the fence. For the majority of us, who just want to ride these times out and survive the mayhem, the best thing to probably do is be extra diligent in our financial matters and use a little good old fashioned common sense.

Having dealt with a few scammers in my life, I've found that most of them aren't the most intelligent people around. The best thing to do is to think carefully before jumping in anything of a financial nature these days.

Tuesday, October 07, 2008

How Using Pirated Software Turns People into Internet Crime Victims

The Business Software Alliance's October report called Online Software Scams: A Threat to Your Security reveals the dangers of buying or downloading pirated software. Sadly, pirated software doesn't always advertise that it is counterfeit and often appears to be the "real thing" to the untrained eye. This poses a clear and present danger to anyone shopping for software, whether it be on a e-commerce site, peer to peer (P2) site or at a more traditional shopping venue.

In the report's introduction it points to an actual example of how a misguided employee of the Wagner Resource Group of McLean Virginia used his office computer to download video and music files using Limewire and exposed the entire corporation to the dark side of the Internet. "In this case, the Wagner employee’s action set off a terrible chain reaction, opening up the firm’s computers to outsiders and exposing the names, dates of birth, and Social Security numbers of about 2,000 of the firm’s clients, including US Supreme Court Justice Stephen Breyer, according to the report.

Although many view downloading a video or music file as a victimless crime, the consequences can become personal when cyber criminals add a little malicious software (often referred to as crimeware) to the mix. Specifically, it can lead to identity (information) theft or turn a user's machine into a zombie, which is controlled remotely and used to commit other misdeeds on the Internet.

It is estimated that one-third of all software is counterfeit. In 2008, a study was conducted that revealed that if software piracy could be reduced by 10 percent in the United States it would generate 32,000 new jobs, 41 billion in economic growth and 7 billion in tax revenues.

A lot of pirated software is sold via downloads. When this occurs, the normal form of payment is a credit or debit card. This means that the person, who buys pirated software is providing this information to a criminal, who in turn might use it again or sell it to a third party. Like pirated software, credit/debit card information is sold on the Internet in underground chat rooms.

The report also covers another area, where Internet crime is known to flourish, or auction sites. In 2005, a study was done on software sold on eBay and roughly 50 percent of the items purchased had malicious/unwanted elements or had been tampered with.

While auction sites have worked with outside industries on preventing theft and abuse, they generally disclaim any responsibility for what occurs on their site. Additionally, there is little to no protection for the consumer buying these products (my opinion).

Because of this, the BSA is calling for auction sites to assume responsibility, step up the warning process on their sites and slow the process down by eliminating the "buy it now" process, which makes monitoring illegal sales nearly impossible.

The software industry isn't the only industry calling out issues with auction sites. In August, two bills were introduced to combat crime on auction sites, which were largely supported by the National Retail Federation. The sale of stolen or counterfeit goods in general has long been an issue on these sites. A good resource to learn about the danger of counterfeit goods in general is the International Anticounterfeting Coalition.

The BSA offers a lot of tips for consumers on how to avoid becoming a victim in their recently released report. It also offers a more visual means of learning by offering a video on the subject.

Suspected piracy can also be reported at http://www.bsacybersafety.com/ or by calling 1-888-NO-PIRACY.

Sunday, June 15, 2008

Send Dad a "Phishy" E-Card for Father's Day

In case you forgot to send a Father's Day card, here are some free ones courtesy of the fine folks at the Federal Trade Commission designed to educate him about phishing, which is a leading cause of identity theft on the Internet.

These were sent to me courtesy of Alvaro Puig from the Federal Trade Commission’s Division of Consumer and Business Education in Washington , D.C.

Please note that most of the consumer awareness materials from the FTC are available in both English and Espanol.

Avaro wrote:

With Father’s Day right around the corner, I wanted to let you know about our Father’s Day phishing e-card. This e-card, which is available at www.ftc.gov/dad (and www.ftc.gov/padre in Spanish) gives “Dear Old Dad” some useful tips on how to recognize and avoid phishing emails and protect his personal information. The e-card also links to our newly released “Phishy” videos that are designed to create awareness of phishing in a humorous way.

The FTC and their government agency partners provide a lot of free educational resources about fraud, phishing and financial misdeeds on the Internet at OnGuardOnline.gov. A lot of these presentations are visual and great tools to learn, or spread the word!

In the war against fraud, there is no more powerful tool than communication. The reason for this is that no matter how good a scam is -- human beings are less likely to fall for it if they are aware of the consequences.

More consumer awareness information can be obtained on the FTC's website and it is available in both English and Espanol.

Friday, June 06, 2008

Spam ruse promising money for being an Internet crime victim spoofs IC3's name


(Picture courtesy of the FBI)

"The Internet Crime Complaint Center (IC3) is a partnership between the Federal Bureau of Investigation (FBI), the National White Collar Crime Center (NW3C), and the Bureau of Justice Assistance (BJA)," according to their website.

In their own words it provides a "vehicle to receive, develop, and refer criminal complaints regarding the rapidly expanding arena of cyber crime."

According to a recently released press release from the FBI's Cyber Division, the good name of IC3 is being spoofed (impersonated) to lure people into become victims of identity theft and financial crimes. In this instance, the specific come-on is a claim that they are passing out money to the victims of cyber crime.

Besides being devious - they obviously have a "sick sense of humor."

From the press release:

The FBI is asking the public to be aware of e-mail schemes containing various versions of fraudulent refund notifications claiming to be from the Internet Crime Complaint Center (IC3) and the government of the United Kingdom. The e-mails falsely state that refunds are being made available to compensate the recipients for their losses as victims of Internet fraud.

The perpetrators of this fraud use the names of people not associated with the Internet Crime Complaint Center, but give them titles in an attempt to make the e-mails appear official. The perpetrators use IC3’s logo and the former name of IC3, the Internet Fraud Complaint Center (IFCC), as well as the names of the Bank of England and the Metropolitan Police (U.K.) in the e-mails.

According to the FBI, the intended victim is required to sign a wire transfer release form in order to receive their refund. In actuality the scammers behind this will probably use the release form to have the bank wire all the money out of an account to them.

I haven't seen one of these spam e-mails yet. They could use different come-ons, or even drop malicious software on your system. When this occurs malware steals all the information from your computer, automatically.

If you would like to learn about cyber scams, the FBI site has a lot of relevant information. They are also requesting that if you spot one of these scams to report it directly to the "real" IC3 site.

Press release on this matter, here.

Saturday, January 05, 2008

DOJ charges 11 in pump and dump stock spamming operation

The Department of Justice has just announced the arrests of 11 spammers involved in a pump and dump stock spam scheme.

Pump and dump schemes victimize people -- lured by the expectation of too good to be true money -- who buy the stocks at artificially inflated prices. They normally lose money when the value suddenly drops because the people behind the scheme sell off their artificially inflated shares.

One of those arrested, an Alan Ralsky is considered one of the biggest spammers around by Spamhaus, which is an organization dedicated to tracking spam.

From the press release:

A federal grand jury indictment was unsealed today in Detroit charging 11 persons, including Alan M. Ralsky, his son-in-law Scott K. Bradley, and Judy M. Devenow, of Michigan, and eight others, including a dual national of Canada and Hong Kong and individuals from Russia, California, and Arizona, in a wide-ranging international fraud scheme involving the illegal use of bulk commercial e-mailing, or "spamming."

This investigation was conducted over a three year period conducted by the FBI, Postal Inspectors and the Internal Revenue Service. The people involved used all the standard spam diversions including falsified domains and e-mail headers, social engineering lures and good old false advertising.

The release also states that they (tried?) to use botnets to send the spam:

The indictment also alleges that the defendants tried to send their spam by utilizing a cybercrime tool known as a “botnet,” which is a network of “robot” computers that have been infected with malicious software code that in turn would instruct the infected computers to send spam. The indictment charges that the defendants earned profits when recipients responded to the spam and purchased the touted products and services. Hui’s primary role in the scheme was to act as a conduit for Chinese companies who wanted their stocks pumped by the scheme. Ultimately, investigators estimate that the defendants earned approximately $3 million during the summer of 2005 alone as a result of their illegal spamming activities.

Recently, the FBI arrested a lot of Internet misfits in what they termed Operation Bot Roast and Operation Bot Roast II.

Botnets have become a major vehicle in which spam is circulated using zombie computers taken over using spam e-mail containing malicious software. Because the owner of the computer normally isn't aware their computer has been turned into a "spam spewing zombie," it also confuses investigative efforts to track the spam to it's source.

It should also be noted that here again, we see another "Chinese connection" in cybercrime. It's pretty interesting that publically held Chinese companies were working with these spammers to have the price of their stock artifically inflated.

Russian nationals were also arrested in this recent case. Eastern European types seem to be heavily involved in the world of cybercrime.

Here are a list of the laws the government is using to bring the spammers to justice:

The 41-count indictment covers three distinct, but interrelated, conspiracies to capture this evolution in their business practices. The indictment charges the defendants with the commission of several federal criminal offenses, including conspiracy, fraud in connection with electronic mail (CAN SPAM), computer fraud, mail fraud, wire fraud, and money laundering. It also charges the defendants with criminal asset forfeiture, as well as charging one defendant with making false statements to law enforcement.

Sadly enough, spammers have been bold enough to spoof all three investigative agencies involved in this case in the recent past. These spamming incidents normally are what are known as phishing attempts, where the intent of the spammer is to steal personal and financial information using social engineering techniques or malicious software.

The FTC released a report on spam a few days ago. One of the findings was that the people behind this activity are best addressed by agencies that have go after criminal activity.

This action and Operation Bot Roast indicate that these actions are already underway.

On the DOJ site right below the header on this press release is a warning about the DOJ itself being impersonated (spoofed).

A lot of people view spam as an annoying phenomenon in their inbox. If you really examine it, spam is the vehicle for just about every annoying and illegal activity on the Internet.

The full press release, including all the names of the spammers being charged can be seen, here.

Friday, November 30, 2007

Operation Bot Roast II snares bot herders, worldwide!


Official FBI photo for Bot Roast II (Globe in a laptop)

This morning I read that a teenager in New Zealand had been arrested for allegedly being the kingpin behind an international cyber-crime network.

Because he was a juvenile when the crimes were being committed, the authorities aren't releasing his real name, but on the Internet he is known as "AKILL."

The Associated Press is reporting:

Police arrested the suspected teenage kingpin of an international cyber crime network accused of infiltrating 1.3 million computers and skimming millions of dollars from victims' bank accounts, officials said.

Working with the FBI and police in the Netherlands, New Zealand police arrested the 18-year-old in the North Island city of Hamilton, said Martin Kleintjes, head of the police electronic crime center. The suspect's name was not immediately available.

Kleintjes charged that the ring was responsible for stealing at least $20 million using bank account and login details detected by their illegal spyware.
I decided to do a little digging on this and the FBI announced on their site that this is part of Operation Bot Roast II.

It appears that more than a teenager is being taken down for victimizing millions of people, worldwide.

From the announcement on the FBI site:

In June, we announced the first phase of Operation Bot Roast, which pinpointed more than a million victimized computers and charged a number of individuals around the country with various cyber-related crimes.

Today, we’re announcing part two of this operation, with more results:

Three new indictments, including two this past month. In one case, we uncovered a denial of service attack on a major university in the Philadelphia area and then knocked out much of the botnet by disrupting its ability to talk to other computers.

Two previously charged criminals who pled guilty, including a California man who is a well known member of the botnet underground.

The sentencing of three others, including a pair of men who launched a major phishing scheme targeting a Midwest bank that led to millions of dollars in losses.
I discovered more information on Operation Bot Roast II in a FBI press release:

The FBI today announced the results of the second phase of its continuing investigation into a growing and serious problem involving criminal use of botnets. Since Operation 'Bot Roast' was announced last June, eight individuals have been indicted, pled guilty, or been sentenced for crimes related to botnet activity. Additionally, 13 search warrants were served in the U.S. and by overseas law enforcement partners in connection with this operation. This ongoing investigative effort has thus far uncovered more than $20 million in economic loss and more than one million victim computers.

FBI Director Robert S. Mueller, III said, "Today, botnets are the weapon of choice of cyber criminals. They seek to conceal their criminal activities by using third party computers as vehicles for their crimes. In Bot Roast II, we see the diverse and complex nature of crimes that are being committed through the use of botnets. Despite this enormous challenge, we will continue to be aggressive in finding those responsible for attempting to exploit unknowing Internet users."

The press release also has detail on the most current arrests:

1. Ryan Brett Goldstein, 21, of Ambler, Pennsylvania, was indicted on 11/01/07 by a federal grand jury in the Eastern District of Pennsylvania for botnet related activity which caused a distributed denial of service (DDoS) attack at a major Philadelphia area university. In the midst of this investigation the FBI was able to neutralize a vast portion of the criminal botnet by disrupting the botnet's ability to communicate with other botnets. In doing so, it reduced the risk for infected computers to facilitate further criminal activity. This investigation continues as more individuals are being sought.

2. Adam Sweaney, 27, of Tacoma, Washington, pled guilty on September 24, 2007 in U.S. District Court, District of Columbia, to a one count felony violation for conspiracy fraud and related activity in connection with computers. He conspired with others to send tens of thousands of email messages during a one-year period. In addition, Sweaney surreptitiously gained control of hundreds of thousands of bot controlled computers. Sweaney would then lease the capabilities of the compromised computers to others who launched spam and DDoS attacks.

3. Robert Matthew Bentley of Panama City, Florida, was indicted on 11/27/07 by a federal grand jury in the Northern District of Florida for his involvement in botnet related activity involving coding and adware schemes. This investigation is being conducted by the U.S. Secret Service.

4. Alexander Dmitriyevich Paskalov, 38, multiple U.S. addresses, was sentenced on 10/12/2007 in U.S. District Court, Northern District of Florida, and received 42 months in prison for his participation in a significant and complex phishing scheme that targeted a major financial institution in the Midwest and resulted in multi-million dollar losses.

5. Azizbek Takhirovich Mamadjanov, 21, residing in Florida, was sentenced in June 2007 in U.S. District Court, Northern District of Florida, to 24 months in prison for his part in the same Midwest bank phishing scheme as Paskalov. Paskalov established a bogus company and then opened accounts in the names of the bogus company. The phishing scheme in which Paskolov and Mamadjanov participated targeted other businesses and electronically transferred substantial sums of money into their bogus business accounts. Immigrations Customs Enforcement, Florida Department of Law Enforcement, and the Panama City Beach Police Department were active partners in this investigation.

6. John Schiefer, 26, of Los Angeles, California, agreed to plead guilty on 11/8/2007 in U.S. District Court in the Central District of California, to a four felony count criminal information. A well-known member of the botnet underground, Schiefer used malicious software to intercept Internet communications, steal usernames and passwords, and defraud legitimate businesses. Schiefer transferred compromised communications and usernames and passwords and also used them to fraudulently purchase goods for himself. This case was the first time in the U.S. that someone has been charged under the federal wiretap statute for conduct related to botnets.

7. Gregory King, 21, of Fairfield, California, was indicted on 9/27/2007 by a federal grand jury in the Central District of California on four counts of transmission of code to cause damage to a protected computer. King allegedly conducted DDoS attacks against various companies including a web based company designed to combat phishing and malware.

8. Jason Michael Downey, 24, of Dry Ridge, Kentucky, was sentenced on 10/23/2007 in U.S. District Court, Eastern District of Michigan, to 12 months in prison followed by probation, restitution, and community service for operating a large botnet that conducted numerous DDoS attacks that resulted in substantial damages. Downey operated Internet Relay Chat (IRC) network Rizon. Downey stated that most of the attacks he committed were on other IRC networks or on the people that operated them. Downey's targets of DDoS often resided on shared servers which contained other customer's data. As a result of DDoS to his target, innocent customers residing on the same physical server also fell victim to his attacks. One victim confirmed financial damages of $19,500 as a result of the DDoS attacks.
Recently, I did a post, Botnet owner faces 60 years in prison and a $1.75 million fine, which is about about John Schiefer (above).

The amount of damage bot herders have caused millions of people on the Internet is astounding. Even when you consider the amount of spam, the average Internet user has to deal with on a daily basis, these current arrests are good news for the Internet community. Spam is the vehicle in which most scams, misleading advertising and counterfeit goods are spread in the electronic world.

The FBI press release mentioned some great resources where the average person can learn how to avoid becoming the victim of a bot herder.

In closing, I would like to pass them on:

http://www.fbi.gov/
http://www.onguardonline.gov/
http://www.lookstoogoodtobetrue.com/
http://www.uscert.gov/
http://www.ic3.gov/

One not mentioned that is great (my opinion) is http://www.fakechecks.org/. A lot of the scams involving counterfeit checks start with a spam e-mail AND most spam is spread using botnets.

AP article on New Zealand teenage bot herder, here.

FBI press release on Bot Roast II, here.

Sunday, July 29, 2007

The Coalition Against Domain Name Abuse seeks to disable Cybersquatting

Cybersquatting is where people, who may have less than honorable intentions, set up a website with a domain name that appears to be a trusted brand, or organization.

Often, these domains are then used to commit financial crimes on the Internet.

In most of the recent disasters, most notably the Katrina hurricane, some of these look alike domain names were sold for a lot of money.

Sadly, these look-alike domain names, which victimize people and businesses, are being sold legally.

These look alike domain names are used in phishing scams, also. If you ever want to see a lot of fake websites, that appear to be real, visit Artists Against 419 and go to their Lad Vampire page.

Dibya Sarkar of the Washington Post is reporting about a coalition lobbying Congress to stop making this activity (like most crime on the Internet) too easy to accomplish:

Well-known companies such as Dell Inc., Yahoo Inc. and Marriott International Inc. are lobbying Congress for tougher laws targeting online scammers who profit from their brand names.

United as the Coalition Against Domain Name Abuse, 10 companies have hired the law firm Alston and Bird LLP to persuade federal lawmakers of the need to crack down against those who claim Web addresses, or domain names, that include _ or even resemble _ a legitimate company's trademark.

Washington Post story, here.

The coalition has set up a website, that anyone can join:

The Coalition Against Domain Name Abuse

The Post article failed to mention all the businesses backing the coalition. The entire list is located, here.

Saturday, July 28, 2007

iPhone hacked under laboratory conditions

There is no doubt that the iPhone, Apples new entry in the smart phone market, has received a lot of attention. I just had the opportunity to use one and they are truly an amazing toy, especially when compared to what else is out there.

Whenever something is popular, Internet outlaws normally try to figure out an angle on how to exploit it for their personal (probably financial) gain. In the interest of getting one step ahead of the bad guys - some of the good guys are trying to discover some of the potential issues with the iPhone before they occur.

Read a post written by Mike Gikas on the Consumer Reports Electronic Blog, which stated:

This week Independent Security Evaluators (ISE), a U.S. independent testing lab, dramatized the looming danger by piercing the defenses of the much-vaunted iPhone. (ISE is the lab whose help Consumer Reports seeks for our evaluations of security software. See our report on how we test antivirus software and look for our 2007 State of the Net report, which posts to ConsumerReports.org in early August.)

Apparently, ISE was able to hack New York Times reporter's iPhone by having it visit a website, which downloaded malware (malicious software) on the phone and gave the testers access to files and iPhone functions.

A visual presentation of this evaluation has been posted on YouTube:



Please note this was done under lab conditions and we've yet to see any hacking of the iPhone done in the wild (at least to my knowledge).

Nonetheless, hacking smart phones might become a new trend that people need to be made aware of. Just about any device can be hacked if hackers are motivated enough to do so.

My personal theory is that as smart phones become more common, we will see them exploited more often.

Perhaps, common sense when using any device that connects to the Internet is the best defense out there. Here are the tips offered from the electronic's blog:
1. Only visit Web sites you know.
2. Only use Wi-Fi networks you trust.
3. Don’t open Web links from e-mails.


And of course, don't fall for anything that is too good to be true, or doesn't make sense. Social engineering techniques (confidence tricks, fraud) normally are what lures anyone into a technology exploit.

Here is a previous post on some controversial software being sold that can invade someone's privacy (my opinion) by loading it on their smart phone. Thus far, they are not advertising software that is compatible with the iPhone.

FlexiSpy - software that spies on people via their smart phone

Full post from Mike Gikas on the Electronics Blog (Consumer Reports), here.

Tuesday, November 07, 2006

Russian Expert Cites 99 Percent of Internet Brides are a Scam

Romance scams happen on the Internet, daily. Here is a story, which indicates that despite "Internet legends" not all of them start in Nigeria.

Mosnews (a Russian publication) reports:

All online dating sites suffer from dating scammers, 99 percent of the emails are hoaxes designed by professional Internet criminals says Elena Petrovathe founder of Russian Brides Cyber Guide, Prweb.com Website reports.

Internet criminals use sophisticated scripts and custom-built software to contact thousands of male users of Internet personals, creating fake Russian women identities and requesting money for airplane tickets.

Link, here.

Interestingly enough, they mentioned one group making a million dollars off these scams AND that in one instance involving "Russian brides," it was an American that was behind the scam.

While I was reading this story - I happened to see another one that claims that a senior Russian prosecutor claims that corruption in Russia amounts to 240 billion a year, read here.

Russian organized crime seems to have it "claws" in a lot of illicit activities - including cybercrime. The U.S. Department of Justice published a document going into great detail about it, here.

I started this post with the comment that despite "Internet legend" not all fraud originates in Nigeria. I will close with that all of it doesn't come from Russia either. In fact, according to the Anti-Phishing Working Group, there are more malicious websites "hosted" in the United States than anywhere else in the world.

Of course, I could go on and on about this - but the bottom line is that Internet criminals can come from anywhere and so can "good people," who are doing their best to fight it.

Monday, November 06, 2006

If You've Really Won the Lottery - Why Are They Asking You to Send Money?

I've written a lot about the various Advance Fee scams out there - and judging from my inbox - the lottery variation of the scam is huge.

I sometimes get four or five notifications that I've won a lottery, or sweepstakes, daily.

Last evening, I read an article written by Linda Leatherdale of the Toronto Sun about a grandmother losing a lot of her hard-earned money as a result of falling for them.

Linda Leatherdale writes:

But more than anything, she wanted to pay for a university education for her three grandchildren. So she entered the sweepstakes.

Lo and behold, a few months later she received a letter that she had won. Ecstatic, she read what she believed to be an authentic lottery letter, which asked her to send
in $25 to collect her prize.

CASH MAILED OFF

Not trusting giving out personal financial information, via cheques or credit cards, she sent cash. Then other letters arrived -- from the U.S., Australia, New Zealand and other parts of the world. Some invited her to play a new lottery, others said she'd won and to send money to collect her prize.


Toronto Sun story, here.

I've seen the lottery scams, where a high-dollar financial instrument is mailed to the "intended victim," along with instructions to wire the money back - but mailing the smaller amounts ($25 to $50) was an activity that was new to me.

With Spam software that sends these "winner notifications" by the millions - I can see, where this could be a lucrative enterprise for the fraudsters behind this.

I guess the moral of the story is to look for the behavior. I've never won the lottery (I play Mega Millions sometimes) - but if I did - I doubt anyone would be asking me to send money.

It would probably be the other way around, or they would be sending me money!

Linda's article mentions "Phonebusters" as a good resource to educate people on Internet scams. I agree and you can link to them, here.

Down here in the U.S., another good resource is the FTC, link here.

Please note that these "lottery scams" cross borders with the click of a mouse.

You can also report these scams at both of these sites, which is something I highly recommend!

Doing so might save another grandmother out there!

For another post about lottery scams and the sheer amount of spam circulating "winner notifications," link here.

Tuesday, October 17, 2006

Answer a "Too Good to be True" Work-at-Home Ad and Take the Rap for the Phishermen

Ryan Naraine of eWeek did an interesting story about how the phishermen launder their ill-gotten proceeds:

"The dramatic rise in phishing and identity theft attacks includes a well-organized offline component—the not-so-innocent "money mule" recruited by fraudsters to launder stolen money across the globe."

"The ads appear innocently on all the major employment listing sites, offering stay-at-home positions titled "shipping manager," "private financial receiver" or "sales representative."

eWeek story, here.

In the article, they responded to a Craiglist Ad - where after being prompted to submit personal and financial information to the Russian Mob - a base salary of $2000.00 a month was offered, plus $50.00 for each wire transfer and or shipment successfully received by them.

I agree with the article that people involved in this "aren't always so innocent," but since all the stolen money and merchandise will be sent to the new employee -- guess where law enforcement is going to trace it to?

Here is where anyone accepting these jobs could end up.








Also mentioned in the article was that prospective employees for these mobsters are required to submit a lot of personal and financial information about themselves to "hired." My guess is that this will be used to commit even more crimes without the knowledge of the employee (identity theft).

Trust me, Boris and his merry band of "Vlads" are expert at this.

Here is a story about a Better Business Worker caught up in one of these job scams:

BBB Worker Takes Job Processing Fraudulent eBay Transactions

Wednesday, July 19, 2006

Criminals Using Text Messaging to Commit Cybercrime

If you receive a "text message" saying you've been signed up for a dating service (automatically billed to your cell phone) "take a deep breath" before following their instructions.

The Internet Crime Complaint Center (IC3) is reporting:

The FBI has been alerted to a newly discovered malware located at http://www.irrealhost.com. Malware is software designed to infiltrate or damage a computer system without the owner's consent.

The identified malware lures victims to the site through the receipt of an SMS message on their cellular phone. An SMS message is a Short Message Service that permits the sending of short messages, also known as text messages. The message thanks the recipient for subscribing to a dating service, which is fictitious, and states the subscription fee of $2.00 per day will be automatically charged to their cellular phone bill until their subscription is canceled at the online site.

Recipients visiting the site http://www.irrealhost.com to cancel their subscription are redirected to a screen where they are prompted to enter their mobile phone number, then given the option to run a program which is supposed to remove their subscription to the dating service.

When the run option is selected on the Web site, the executable adds several files to the host and changes registry settings to open a backdoor port and lower Windows security settings. The host file is modified to prevent the victim from browsing to popular anti-virus Web sites. The executable also turns the infected computer into a "zombie" network, which can be remotely controlled by the hackers.

For the alert link, here.

In case, you are like me and need clarification on some of the "technical terms," here are descriptions. New terms for computer fraud, such as "vishing" come about all the time and it's hard for the average person to keep up.

Wikipedia is probably the best (most up to date) reference (for new IT terms), I have found, thus far.

Malware is sometimes called crimeware and zombie networks (botnets) are known to be used by cybercriminals for nefarious purposes.

A keylogger could even be installed by visiting one of these "rogue websites." These programs record all the "keystrokes" on a computer and send them (electronically) to the person who installed them on a system. Keyloggers are actually legal and marketed as a means to spy on your loved ones, or anyone else. Criminals use them to record your access information to financial accounts and then steal the money out of them.

If you spot this activity - besides taking a deep breath and not following through with the request - the best thing to do is report it. You can report it to the Internet Crime Complaint Center (IC3), here.

The sad thing is that those of us who know - often just ignore the attempt - which leaves those of us (who don't know) vulnerable.

Monday, July 17, 2006

Armed Robbers Pose as Craigslist Customers

This story reaffirms something we should all know, which is be wary of anyone you know only from the Internet. In a story released on SFGate.com, a seller on Craigslist, selling "hooded jackets" was talked into meeting someone at a local mall. When they arrived for the meeting, they were relieved of their merchandise at gunpoint.

The good news is that the only loss was the "hooded jackets!"

For the full story on SFGate.com, link here.

In my opinion, Craig and Craigslist - who provide a "mostly" free service - have been extremely honest and proactive about protecting their "users" from crime.

Although, I could find nothing about this (new and frightening scam) - here is a link to their warnings about some of the scams attempted on their site. Hopefully this one will make their list soon.

The dangers of meeting someone that you have met only over the Internet have been well documented. Although primarily written in the context of "romance encounters," anyone meeting someone they meet on the Internet needs to be careful and verify (via a trusted source) who they are dealing with before proceeding.

For a resource from the University of Oklahoma (The Police Notebook), which covers this subject - link here.

Thursday, June 01, 2006

Phishermen are Trolling MySpace for Victims

If your children use MySpace - or you use it yourself - here is a warning from Websense:

"Websense® Security Labs™ has discovered a phishing attack that attempts to steal the account information of MySpace.com users. A hyperlink is first delivered to victims via AOL Instant Messenger. Users who follow this link are taken to a fraudulent website that spoofs the MySpace.com login page. This page captures their MySpace account information and then forwards the user to the actual MySpace.com website."

"The fraudulent site also sets a cookie on the victim's computer, which prevents the phishing attack from being displayed on any subsequent visits."

The phishing site is located in California and was up at the time of this alert.

For the full alert, along with a screen shot of the phishing site, link here.

MySpace is a hugely popular site (and when anything becomes popular) it attracts what I refer to as the cyber-scum element.

Here is an interesting article from MSNBC and Rob Stafford. If you are a user of MySpace, or care about someone who is a user, this is a great resource with information on how to navigate the waters of MySpace safely.

Why parents must mind MySpace - Dateline NBC - MSNBC.com

While I'm not sure what the intention is in "phishing" the waters at MySpace, a smart person is extremely careful before giving out any personal information on the Internet!

Here is a recent post, I wrote about how these "Internet Child Abusers" are going to be targeted through their financial transactions:

Catching Child Predators by following the Money Trail

In case anyone is unfamiliar with Phishing, here is a place to start learning:

Internet Crimes are On the Rise and Deadlier than Ever

Tuesday, May 23, 2006

Virtual Task Force Nets 565 Cyber Criminals

An international (virtual) task force dubbed "Operation Global Con" has netted 565 cyber criminals that have victimized approximately 3 million people.

Attorney General Alberto Gonzalez, who was joined by FTC Chairman Deborah Majoras, Chief Postal Inspector Lee Heath and Costa Rica's Attorney General Francisco Dall’ Anese Ruiz issued a prepared statement:

Over the past 15 months, United States and foreign law enforcement agencies have targeted international fraudulent mass-marketing schemes in the largest enforcement operation of its kind. The results of Operation Global Con have been dramatic – with 565 arrests, both here and abroad.

We all know the annoyance of phone calls, junk mail, and spam and pop-up ads that bombard us with seemingly incredible financial offers. For millions of Americans, these intrusions have been more than a nuisance.

Operation Global Con targeted international mass-marketing schemes. These criminals used telemarketing, the Internet, and mass mailings, to cheat unsuspecting people through bogus investments, fake lotteries and sweepstakes schemes, phony credit cards, and tax frauds.

In Miami, Florida, for instance, two defendants allegedly duped investors in the United States and Europe for more than $3 million dollars. Investors in Discovery Capital believed it to be legitimate because the defendants would occasionally use funds received from new investors to send out purported interest and dividends. Allegedly, the rest of the money went to fancy cars and million-dollar homes for the defendants.

Link to prepared statement, here.

The effort was done with the partnership and support of several countries, including Canada, Costa Rica, Spain, the Netherlands, the United Kingdom, New Zealand and Nigeria.

Also released on the DOJ site was a fact sheet, which gives more detail on this operation.

This is positive news, but my best guess (based on extensive study of the subject) is that there are plenty more cyber-criminals still in business out there. The positive part of it is the fact that we are now seeing signs of "international cooperation" into what has been dubbed a "borderless" problem.

If you think you have spotted one of these scams - or are a victim - the best thing to do is report it.

Here are some good places to do so:

Federal Trade Commission

Internet Crime Complaint Center

If you are Canadian, Phonebusters is the place to go to report activity, or seek help.

Saturday, May 20, 2006

India Seeing a Problem with Cloned Payment Cards

Skimming, cloning, counterfeiting of debit/credit cards (lately debit seems to be preferred) has been a major problem in North America and Europe. India (a new giant in the technology field) is now seeing this type of criminal activity hit home.

IBN is reporting:

One swipe is all it takes. When you hand over your credit card to make a payment in a shop or insert it into an Automated Teller Machine (ATM), you could run the risk of being the next victim of an international crime called "skimming".

And this could drain your account of all your money. Skimming is the latest fraud that has hit India hard.

The cyber crime cell of the Chennai Police recently arrested four people for withdrawing money from ATMs through forged credit cards. The police recovered 160 fake international credit cards through which they had planned to withdraw Rs 15 crore.

Link, here.

Interestingly enough, the authorities are blaming this activity as being tied into a gang from the UK, which uses a device (easily available on the Internet) known as a "skimmer."

If this activity continues to grow in India, we are likely to see "skimming devices" attached to ATM machines, likes the ones, reported in other countries.

Card skimming is growing at alarming rates, seems to be highly organized and now the evidence shows that it is becoming a global problem. It will continue to grow as long as the cards can be easily counterfeited with legal devices, which anyone can purchase.

Here is an earlier post on why technology crimes have become too easy:

Are We Addressing Cyber Crime from the Wrong End

Friday, March 31, 2006

Counterfeit Travelers Express (MoneyGram) Money Orders Showing Up in Internet Scams

Got a comment on an old post today about a reader being scammed by cashing counterfeit Travelers Express money orders. The reader was duped into thinking they were working as a Secret Shopper and has lost $7,000.00. Here is the previous post, I am referring to:

Secret Shoppers Scammed

Did a little checking via some of my sources and found that counterfeit Travelers Express money orders are showing up in all sorts of internet scams in the past week.

Thus far, these money orders are showing up mostly in Advance fee fraud (419) scams.

The Advance Fee scam is where a ruse is used to get a victim to send them money (nowadays normally wire-transfer) in anticipation of riches (or sometimes love) to come. The best known is the "Nigerian Letter," but the activity has mutated into romance, lottery, auction, check cashing, work at home and reshipping (as mentioned below) scams.

In a lot of the more recent Advance Fee activity, the victim is tricked into involving themselves in criminal activity, whether it be forwarding stolen merchandise, or negotiating bogus financial transactions and sending the funds elsewhere.

Please note that cashing counterfeit items is illegal and people have been arrested for passing them.

Here is information on how to verify Travelers Express Money Orders from their site:

"If you have retained your money order number, MoneyGram offers 24-hour automated money order status information by calling 1-800-542-3590. MoneyGram customer service representatives are also available from 7 a.m.-8 p.m. CST Monday-Friday and 8 a.m.-5 p.m. CST Saturdays."

There is more information on their site, which can be viewed by clicking on the title of this post.

Please note that automated systems aren't always accurate and that money orders are notoriously high risk instruments. Most money order companies leave themselves with an "out" in case the instrument is later discovered to be bad.

The old saying is "Caveat emptor," or "let the buyer beware." If it seems to good to be true, it probably isn't.

Friday, November 18, 2005

Secret Shoppers Scammed

I'm sure we've all seen advertisements on how you can make a lot of money, get free merchandise and meals and even take cruises as a "Secret Shopper." We've also seen numerous services (questionable) that will sell you information on how to do it.

Although, there are numerous companies, who do this for legitimate businesses, very few people make much money by being a secret shopper. So far as the services selling you a package to do it, I would recommend that you stay away from them. Quite simply, they aren't necessary and you are probably paying for something that you could have got for free. All one needs to do is look up the companies, (Secret Shopper) online and apply directly to the company.

On a much scarier note, I read a report from the Minneapolis Star Tribune that "Secret Shopping" is the latest ploy to attract victims into Advance fee fraud (419 scams).

Here is how this latest scam works as reported in the Minneapolis Star Tribune:

"John McCullough, business coordinator for the Financial Crimes Task Force, said the perpetrators ran an ad in the Star Tribune classified section last month luring readers with an offer to be "Secret Shoppers" for "$100/hr. guaranteed" and "no experience necessary."

People who responded to the ad were sent a letter congratulating them on being selected and instructing them to cash a $2,830 check at their bank or other institution, to keep $200 for themselves, and to send most of the rest to the Canadian address. The check-cashing task is described in the letter as an "assignment" to "evaluate the effectiveness and efficiency of a payment system called 'Moneygram' which is available at all Wal-Mart (sic)."

Moneygram and Western Union offer wire transfer services, which aren't insured by the FDIC. In many advance fee scams, the ploy is to get someone else to cash a fraudulent instrument and wire the money (normally overseas) before the instrument is discovered as a fraud.

"The letterhead is topped with the Web address (secretshopper.ca) of an apparently legitimate operation in Canada that employs people to shop and evaluate retail establishments. Other legitimate operations include secretshoppercompany.com in Gainesville, Ga., and secretshopper.com in Minneapolis."

As I am constantly saying, Advance Fee is a continuously mutating animal. The Secret Shopper twist is new and if history proves correct, we will see this version of the scam travel quickly in the borderless environment of the internet.

Some good advice from the article is, "beware of checks made out for more than the selling price of an advertised item, checks delivered via overnight delivery service, checks drawn on an account in a name that is different from the person buying the item, and instructions to wire money to a large U.S. city or to another country such as Canada, England or Nigeria.

Other things to watch for are payment of a "commission" for facilitating money transfers through personal accounts, and e-mails requesting the receiver to "confirm, update or provide" personal banking account information."

Note that people, who fall victims to these scams are normally held financially responsible. In some instances, some of them have even been arrested for attempting to pass fraudulent financial instruments.

Should you suspect you are being solicited on any internet scam, the best thing to do is to report it to the authorities. There are numerous links throughout this blog and in my "links" on how to do so!