Showing posts with label disaster and charity scams. Show all posts
Showing posts with label disaster and charity scams. Show all posts

Saturday, May 24, 2008

China earthquake and Burma (Myanmar) cyclone inspire another round of charity fraud!


(Photo courtesy of IslamicReliefUSA at Flickr)

Last weekend, I lamented that the Western media wasn't reporting the expected fraud activity in the wake of the China earthquake and the Burma (Myanmar) cyclone.

Most of the scam activity, associated with the earthquake, was being reported out of China.

Having been extremely busy in my day job, I didn't get the chance to follow-up and see if this trend would continue. It did not and as expected, inboxes are being targeted with come-ons designed to take away from those, who would really benefit from our charitable impulses.

As expected, we are now seeing fraudsters, using their favorite technique (spam) to trick people out of their hard-earned money and (possibly) their personal and financial details.

The reason, I mention personal and financial details being stolen (identity theft) is because malware is being dropped on systems when unsuspecting people click on a link regarding a plea for financial assistance. Sadly, this more technical means of stealing information is becoming more and more commonplace. Not very intelligent criminals (my opinion) can easily buy all the software necessary to do it -- which sometimes comes with technical support -- right over the Internet.

Of course, identity theft, might not be the only intent in dropping the malware. Frequently, the intent is to take over your system and turn it into a member of a botnet so it can be used as a spam spewing zombie. Most of the time, the owner isn't aware their computer (zombie) is being used to flood cyberspace with spam e-mails.

Internet security firms are reporting suspicious e-mails asking for help and marketable domain names are fetching premium prices.

Sophos went on record that they had detected malicious software attached to some of these spam mails. McAfee also reported malware attached to electronic documents referencing the earthquake. The FBI issued an alert on this subject, also.

As a discaimer, at first sight, it can be hard to determine if a request for a donation is legitimate or not. Charity is a often practiced social-engineering ploy used by fraudsters and associated internet ghouls to steal money.

Besides using the Internet, charity fraudsters also use the telephone, snail mail, or even go door to door. Text messaging is another tool being used to commit charity fraud, also. This surfaced in the activity reported in China last week.

The best thing to do -- before handing over your hard earned money for an honorable cause -- is to make sure the entity receiving it is legitimate. Taking the time to check things out will help ensure the money goes where it is supposed to.

It might also be wise to give directly to an organization. Besides fraudsters, a lot of telemarketing types sell their services to charities and take a cut of the action. Simply stated, this means that less money will reach the people you are trying to help.

Listed below are some places, where you can cut out the middle-man, or avoid handing over your money to a scam artist. Please note, these organizations, might or might not be involved in the current earthquake and cyclone efforts. Current events often dictate the disaster come-on currently being used by fraudsters.

The United Way, http://national.unitedway.org/, 800 272-4630.

American Red Cross, http://www.redcross.org/, 800-HELP-NOW

Salvation Army, http://www.salvationarmyusa.org/, 800-SAL-ARMY

Network for Good, http://www.networkforgood.org/.

Habitat for Humanity, http://www.habitat.org/, 800-HABITAT.

Samaritan’s Purse, http://www.samaritanspurse.org/, 800 665-2843.

Save the Children, http://www.savethechildren.org/, 800 728-3843.

Humane Society of America, http://www.hsus.org/, 888 259-5431.

Feed the Children, http://www.feedthechildren.org/, 800-525-7575.

America’s Second Harvest, http://www.secondharvest.org/, 800 771-2303.

Additionally, if you are interested in charities that do a lot of work in Asia, here is another list:

Doctors without Borders
Mobilizing to provide medical assistance, blankets, water, sleeping mats and tents.

International Federation of Red Cross and Red Crescent Societies
Dispatching teams to assess damages and the needs of victims.

International Rescue Committee
Assessing immediate needs on the ground and preparing emergency response.

Mercy Corps
On the ground providing emergency relief, including water and tents.

Oxfam
On the ground assessing the response effort and responding to victims.

UNICEF
Sending emergency staff to distribute aid and make further assessments of the damage.

In more general terms, there are some excellent sites to check out, whether a charity is legitimate or not:

Better Business Bureau Wise Giving Alliance, http://www.bbb.org/charity/.

Charity Navigator, http://www.charitywatch.org/.

American Institute for Philanthropy, http://www.guidestar.org/.

Last, but not least - I would like to provide some resources to report suspected fraud activity.

If it is cyber related, report it to the Internet Crime Complaint Center.

For more general complaints, fraud can be reported to the Federal Trade Commisssion, here.

Sunday, May 18, 2008

Chinese Red Cross Site hacked to steal donations!

Whenever a disaster occurs, there are always dishonest people trying to steal the proceeds of charitable contributions.

This is always sad because it takes away from the people, who are in need.

Heike over at the Dark Visitor is reporting that a Red Cross site has been hacked with the intent of "electronically" removing money intended to help the earthquake victims in China:

Verified by the Ministry of Public Security, a section of the official Red Cross website has been illegally hacked. According to the report, criminal elements gained access to the section of the website that held the special accounts for earthquake disaster relief donations.

An individual named Li Bujiu, had opened four fraudulent bank accounts to steal the funding.

Full story with more details from the Dark Visitor Site (Inside the World of Chinese Hackers), here.

Thus far, we haven't seen the flood of phishing, fake charity websites and the like come about as the result of the earthquake in China, or the cyclone in Myanmar reported in the West? Even this story isn't up on Google News yet.

Reuters did recently report that fraud is occurring inside China as a result of the earthquake disaster:
Police issued a warning after a flurry of text messages hit mobile phones, soliciting disaster assistance in emotional appeals, only asking that funds be deposited in private accounts.

The Reuters story -- which does mention that the Red Cross was shut down because of too many vistors (?) and had a page listing bank accounts to contribute to (??) -- can be seen, here.

The story in Reuters references the site, http://www.crcf.org.cn, which as of this writing appears to be up and running.

Not sure why more news on disaster fraud from China isn't being seen? It could be attributed to the "Great Firewall of China," or the fact that hacking and committing fraud carries far more serious consequences in China than it does here in the West.

Generally, if caught, offenses like hacking can mean the death penalty in China. In 2006, China carried out ten times more executions than the next country who still uses captial punishment. Generally, they use one round from an assault rifle (hollow-point) to the back of the head.

Of course, that doesn't mean that there isn't a lot of hacking coming from China. We see stories all the time about Chinese hackers committing corporate and government espionage. The Dark Visitor is an excellent site, run by a former intelligence type, about the mysterious world of hacking in the People's Republic.

I guess the difference on whether you get a bullet in the head, or not depends on whether certain authorities approve of your activity (my opinion). Of course, they are not beyond setting an example from time to time if certain political conditions exist.

Last year, China executed their former food and safety chief (Zheng Xiaoyu) for taking bribes in the wake of all the news stories about defective and dangerous products being exported from China.

With all the humans rights violations, fraud, hacking and deception that occur in the People's Republic, it's amazing that so many companies in the West continue doing business with them.

Sadly enough, some believe this has been at the expense of many people in their own countries. Given the human rights violations, it is also at the expense of a lot of Chinese people, also!

Perhaps, I'm old fashioned, but I sometimes wonder when people will come first?

Sadly enough, greed often gets in the way of this concept.

Tuesday, April 08, 2008

2007 Internet Crime Report shows dollar loss at all time high!



According to what many consider a reputable source, the FBI, Internet scams have set a new dollar record ($240 million).

Here is what they wrote about it in the press release (courtesy of the FBI site):

Pets, romance, and secret shoppers.

They’re each among the top ruses used by Internet scam artists in 2007, according to a comprehensive report on online crime just issued by the Internet Crime Complaint Center, or IC3.

Here is how the FBI described the most prevalent scams:

Pet Scams

- You see an online (or offline) ad selling a pet and send in your money, plus a little extra for delivery costs. But you never get the pet; the scam artist simply takes your money and runs. - You’re selling a pet. You’re sent a check that’s actually more than your asking price. When you ask about the overpayment, you’re told it’s meant for someone else who will be caring for the pet temporarily. You’re asked to deposit the check and wire the difference to this other person. But the check bounces and you lose the money you sent to what turns out to be a fraudster.

Secret Shoppers and Funds Transfer Scams

- You’ve been hired via the web to rate your experiences while shopping or dining. You’re paid by check and asked to wire a percentage of the money to a third party. Like the pet scam, the check is bad and you’re out the money you sent. As part of the scam, the fraudsters often use (illegally) real logos from legitimate companies.
- While renting out a property, you’re sent a check that is more than your rental fee and asked to wire the difference to someone else (are you seeing a trend here?). Or you take a job that requires you to receive money from a company and redistribute funds to affiliates via wire.

Adoption and Charity Frauds

- You get a spam e-mail that tugs on your heartstrings, asking for a pressing donation to a charity and often using the subject header, “Urgent Assistance is Needed.” The name of a real charity is generally used, but the money is really going to a con artist. One set of scams in 2007, for example, used the name of a legitimate British adoption agency to ask for money for orphaned or abandoned children.

Romance Fraud

- You encounter someone in an online dating or social networking site who lives far away or in another country. That person strikes up a relationship with you and then wants to meet, but needs money to cover travel expenses. Typically, that’s just the beginning—the person may end up in the hospital during the trip or get mugged and need more money, etc.

Fraud stats. The report provides a complete breakdown of statistics on Internet crime in 2007. For the year, total complaints were down slightly with 206,884 submissions, but total losses were at their highest level ever, nearly $240 million. See the report for plenty more details about victims, perpetrators, and common categories of complaints.

Full report, here.

Please remember that these reports are only as accurate as the data they compile. Often, I find that a lot of scam victims have no idea, where to report activity to. Because of this, I will end this post with information from the release on where to report Internet scam activity (highly recommended):

Logging a complaint is easy: just go to the IC3 website, click on “File a Complaint,” type in the details, and hit “next.” Review your information and click on “submit” when you’re ready to send. The good folks at IC3 will take it from there.

Friday, October 26, 2007

As Southern California burns, watch out for charity scams!

A sad commentary on how some people react to a disaster are the amount of scams that surface as a result of them.

The Postal Inspectors are warning us that we are likely to see a lot of these scams appear as a result of the Southern California fires.

If you are one of the good people out there, who intends to lend some financial support, it is a wise thing to make sure your hard-earned money is going where it is supposed to.

From the USPIS release:

Our charitable nature leaves us vulnerable to charity fraud schemes. Most charities are legitimate organizations that support good causes. Some, however, are run by swindlers. With more than 700,000 federally recognized charities soliciting for charitable contributions, the U.S. Postal Inspection Service reminds everyone it pays to be cautious when making a donation.

Disasters bring out the best in people who truly desire to help those impacted by these situations. Unfortunately, disasters also bring out the worst; scammers take advantage of the circumstances by stealing the charitable donations intended to help victims of the disaster. Postal Inspectors saw numerous charity scams emerge in the days following the devastation of Hurricane Katrina, the 2004 Southeast Asia earthquake and tsunami, and the September 11th terrorist attacks.

The recent California firestorm offers a new opportunity for fraudsters to perpetrate charity scams. If you're considering a contribution to help with relief efforts, it's important to know where your donation dollars will go. California Charities can be researched on the Attorney Generalwebsite, http://ag.ca.gov/charities or at the Better Business Bureau's Wise Giving Alliance, http://www.give.org/.

The Postal Inspectors are also offering some general tips on how to avoid these scams:

-- Give donations to known charities, or research new or unfamiliar charities first.

-- Refuse high-pressure appeals. Legitimate fundraisers won't push you to give on the spot. -- Be suspicious of solicitors who say they can only accept a cash donation.

-- Always make checks out to the name of the charity, never to an individual.

-- Be wary of "sound-alike" charities, many scammers use names that sound similar to names of legitimate charities.

-- Be skeptical if someone thanks you for a pledge you don't remember making. This is a tactic scammers use to lull victims into sending "additional" funds.

-- Ask for ID. For-profit fundraisers must disclose the name of the charity requesting the donation --- it's the law. Many states require paid fundraisers to identify themselves as such and to name the charity for which they're soliciting. If the solicitor refuses to tell you, hang up and report it to law enforcement officials. Also ask how much of your donation goes to those in need and how much goes to the fund raiser.

Last, but not least -- if you spot one of these scammers, you can help terminate their activities by reporting them to the Postal Inspectors.

You can find your local Postal Inspector by calling 877-876-2455. If you are of a more technical nature and prefer to report illegal activity online, you may do so, by clicking here.

USPIS release, here.

Although, Arnold isn't taking calls from bloggers this morning, I'm sure he supports terminating this type of activity, also.


The people in Southern California will need a lot of money to help them recover. Wasting monetary resources on scams will not help the situation.

PS: I'm dedicating this post to Paul Young, a noted Southern California blogger and friend, who writes Prying1.

I've enjoyed reading his investigative insights on issues, which are obtained, by digging a little deeper than the mainstream media.

Wednesday, April 18, 2007

Are Charity Fraudsters (Phishermen and Pharmers) preparing to exploit the Virginia Tech Disaster?

Internet criminals use disasters to get nice people to donate their hard-earned money to them, personally. Recent examples where this occurred have been the Katrina hurricane, Tsunami disaster and London bombings.

According to the Sans Internet Storm Center, we can probably expect the same activity to occur in the wake of the Virginia Tech Disaster.

Here is what they are reporting in their Handler's Diary:
There has been a flurry of domain registrations related to the Virginia Tech tragedy, as reported by GoDaddy and other registrars. While some of these are undoubtedly well-intentioned organizations joining in the outpouring of support for the friends and family of the victims, others are likely to be opportunists who want to cash in on the suffering of others.

Be on the lookout for a rash of spam & phishing coming from these leeches. If you receive a plea for donations, check the organization out closely before opening up your e-gold, Paypal, Visa or other account or providing any personal information. In some cases the phishers may use voice, fax, email and websites to dupe generous and thoughtful victims into disclosing valuable information.
Full diary post (with potential domains being grabbed), here.

As the SANS post aptly points out, giving out any personal, or financial information to one of these fraudsters (leeches) can have more consequences than giving your money away to the wrong place (identity theft).

Here are some investigative (due diligence) resources someone might take advantage of to make sure they are donating their money to a worthy cause:

Better Business Bureau Wise Giving Alliance

Charity Navigator

American Institute for Philanthropy

The Federal Trade Commission (FTC) has some information on how to make sure your money goes to the cause you intend it for, here. Also contained on this page is where you can report fraudulent activity to them, which is highly recommended.

Sunday, March 04, 2007

Should recent prosecutions for fraud in Katrina remind us of something?

Bruce Alpert, of the Times Picayune did an excellent article about a lot of recent prosecutions for fraud in the aftermath of the hurricane disasters.

One woman, LaWanda Williams collected $267,377.15 in an identity theft scheme using several other people's information.

I wonder if any of the people (who had their information stolen) were denied benefits, as a result of LaWanda's activities?

And LaWanda is just one example of people's greed. FEMA and Army Corps of Engineers officials, Red Cross employees and many others took advantage of the situation.

In fact, fraud was being committed as far away as California, where 71 cases have been documented.

Bruce Alpert's article, here.

Bruce's article points out that this isn't the first time fraud occurred after a disaster. Similar fraudulent claims occurred after 9-11 and the Tsunami disaster.

The money lost to fraud is a symptom of the larger problem, which was a disaster preparedness system that failed. The resulting confusion enabled a lot of fraud to occur, and probably made it too easy to commit.

I doubt any of the people now being prosecuted thought they were going to be caught.

As the old saying goes - "an ounce of prevention is worth a pound of cure." Our focus needs to be towards preventing this from happening again.

If you would like to learn more about the hurricane disaster - and how how people are still being "cured" two years after the fact - Beyond Katrina has a lot of information on the subject.

Sunday, April 30, 2006

California Predicts the Top Ten Scams for 2006

Much of the legislation to curb Fraud, Phishing and Financial Misdeeds enacted worldwide can be traced to laws in California. This is probably because of the amount of fraud that the Golden State has suffered in recent times.

Based on this, it would make sense to pay attention to what California predicts when it comes to fraud.

Here is what California predicts for 2006, courtesy of the Department of Corporations:

Senior Investment Fraud. The elderly are targeted for fraud for several reasons, such as older Californians are most likely to have a nest egg, own their own home or have excellent credit-all of which the con artist will try to tap into. As seniors plan for retirement, they may fall victim to such investment schemes as oil and gas, real estate, and annuities. They should be careful when solicited by mailers, telephone, and through free lunch or dinner seminars. In the past year, DOC assisted with a Southern California district attorney's office to bring criminal charges against three perpetrators for selling promissory notes offering a 12 percent annual return and then absconding with seniors' money. The defendants were charged with 850 felony counts of senior fraud.

Mortgage Fraud. Predatory mortgage lending involves a wide array of abusive practices and usually takes place in the subprime market, targeting borrowers with weak or blemished credit records. The most common lending abuses include excessive fees, abusive prepayment penalties, loan flipping, and other shady practices. In addition, foreclosure schemes are on the rise in which the prepetrators mislead the homeowners into believing that they can save their homes in exchange for a transfer of deed and up-front fees. The perpetrator profits from these schemes by remortgaging the property or pocketing fees paid by the homeowner. DOC, as part of a California task force comprised of local district attorneys and the California Attorney General filed a judgment in 2006 against a major subprime lender to resolve predatory lending allegations against the company, which will provide consumers $295 million in restitution and require sweeping reforms of the firm's business practices.

Affinity Fraud. These scams exploit the trust and friendship that exist in groups of people who have something in common, such as religious or ethnic communities, the elderly, military servicemembers, or professional groups. The fraudsters who promote affinity scams frequently are-or pretend to be-members of the group and enlist respected community or religious leaders from within the group to unwittingly spread the word about the scheme. In 2005, DOC brought enforcement actions against perpetrators of investment scams affecting members of the African American and the Korean American communities in Southern California, and a foreign currency scheme targeted at the Chinese American community in the Bay Area.

Identity Theft/Phishing. Identity theft is a trend that is often aided by technology and is the criminal activity of stealing someone's personal information for financial gain. More often than not, it involves "phishing," where Internet users believe that they are receiving e-mail from a specific, trusted source, or that they are securely connected to a trusted Web site, when that is not the case. As more investment and banking accounts, as well as 401(k) plans, are accessible online, thieves may attempt to obtain your access codes and passwords so they can transfer all of the assets out of accounts.

Online Escrow Fraud. In 2005, DOC enforcement actions to crack down on online escrow fraud increased by 16 percent from 2004. Escrow services fraud involves a perpetrator proposing the use of a third-party escrow service to facilitate the exchange of money and merchandise. The buyer sends payment to a phony escrow site that closely resembles a legitimate escrow service. Or, the seller sends merchandise to the bogus buyer, and waits for the payment through the escrow site, which is never received because it is a sham.

Commodities/Foreign Currency. Consumers should take special care to protect themselves from the many types of commodities fraud. They might be selling precious metals, such as silver or gold, or foreign currency, such as Euros, Yen or Deutschmarks. Be wary of any firm that offers to sell commodities or commodity futures or options, particularly if a firm promises high profits and low risks, or claims that they have made profits for all of their customers. The commodities and futures markets are very risky, and investors can lose their entire investment very quickly. In 2005, DOC took enforcement action against a firm and sales representatives in San Diego County who were not registered with the Commodity Futures Trading Commission to sell foreign currency contracts. Investors were not aware that the promoter had been barred from the National Futures Association, the self-regulatory organization for the futures industry, and a principal had been ordered by the NASD to pay damages in two separate incidents. Oil and Gas Scams. With oil prices at record levels and continued Middle East instability, DOC is concerned about the increase in oil and gas scams that it is experiencing. Perpetrators lure investors into unsuitable or fraudulent oil and gas ventures promising quick profits on a low risk investment. A San Diego scam using five different company names touted a 90 to 95 percent probability of striking oil in oil wells and returning investors' principal investment within a few years, which some customers never received. At least seven California residents invested more than $770,000 in the scam. The perpetrators failed to disclose prior convictions of mail fraud and wire fraud and that at least seven other states had taken administrative action against the sales agents for securities fraud.

Ponzi/Pyramid Schemes. Named for swindler Charles Ponzi, the premise is simple: use money from later investors to pay early investors. Instead of investing customers' funds, the operator pays dividends to initial investors using the principal amounts invested by subsequent investors. The scheme generally falls apart when the operator flees with all of the proceeds, or when a sufficient number of new investors cannot be found to allow the continued payment of dividends. Another very old form of fraud, a pyramid scheme, promises consumers or investors large profits based primarily on recruiting others to join their program, not based on profits from any real investment or real sale of goods to the public. A product may be used to hide the pyramid structure if the company's incentive program force recruits to buy more products than they could ever sell, or the sales occur only between the people inside the pyramid structure or to new recruits joining the structure, not to consumers out in the general public.

Military Fraud. There has been heightened concern at the federal and state government levels about the financial vulnerabilities of servicemembers and their families, particularly in light of recent deployments to Iraq and Afghanistan. Money woes can be especially difficult for National Guard and Reserve soldiers, who often have to make a rapid switch from civilian to military life when they get called up. DOC created the California Troops Against Predatory Scams (TAPS) program to provide financial education and consumer protection tips, supported by an effective and timely consumer enforcement program.

Disaster and Charity Scams. Scammers will attempt to capitalize on the aftermath of Hurricane Katrina and other disasters. Be careful of investment fraud scams which claim to be trading programs that guarantee high returns, with a portion going to aid relief efforts. Others promote businesses that stand to profit from relief and rebuilding efforts. Be cautious of the influx of Web sites soliciting for charitable donations to avoid phishing and identity theft.

It never ceases to amaze me at the lack of moral fiber fraudsters have. If California is correct, they will target the elderly, charities, people's homes, their identities, their retirement savings and even the military in time of war.

Besides supporting legislation to put these people away (for a long time), the most effective tool against fraud is awareness. It is a kind thing to share awareness to protect those, who might fall into harm's way by an activity that is becoming epidemic in nature.

I would like to thank the State of California for sharing this with us all.

Press Release link, here.