Showing posts with label ebay. Show all posts
Showing posts with label ebay. Show all posts

Wednesday, December 03, 2008

How to Legally Buy Hot Merchandise


(Courtesy of PropertyRoom.com)

Auction sites like eBay and Craigslist are frequently criticized for the amount of stolen and counterfeit items being sold on their sites. Even worse, stories about their customers being scammed have become Internet folklore.

Now there is a site that openly advertises that it is selling stolen merchandise. Even better, when you buy hot merchandise off this site, you need not worry about the authorities showing up at your door in the wee hours of the morning with a search warrant. The reason for this is that the site is stocked by over 1500 Police Departments and is run by former law enforcement types.

The site, PropertyRoom.com is an e-version of the more traditional auctions held by Police departments to get rid of unclaimed stolen property. "With distribution and service centers nationwide, PropertyRoom.com specializes in the auction of stolen, seized, found and surplus goods and vehicles. Serving over 1,100 law enforcement agencies nationwide, we offer a fraud-free marketplace with superior customer support." according to the "about us" page on the site.

I decided to surf the site and it contains a wide array of goodies at cheaper prices than what I've seen being fenced (speculative) on other Internet auction sites. For instance, desktop computers being auctioned were being bid at well under $100, laptops were showing bids of $100 to $400 and iPods were being bid anywhere from about $16 to $150. Of course computers aren't the only items available on the site, which hawks all kinds of electronics, watches, jewelry, tools, cameras, cars and a host of other high theft items.

It is well known that criminals like to steal high value items that are easy to transport. They also tend to go after items that are popular and easy to sell (fence). If you are looking for popular items, this site is a good place to buy them at an almost too good to be true price, legally.

PropertyRoom.com also is in the fund raising business and will help charitable organizations raise money. All the costs of putting on the event are covered by PropertyRoom.com. I should also mention that some of the proceeds of the sales on the site help fund law enforcement agencies, who like the rest of us, are dealing with ever-dwindling financial resources.

They also maintain the only nationwide registry available to the general public for recovering lost or stolen goods. This service is completely free. You can register items that were stolen already, or your high value items that might be stolen at a later date. If they receive an item that matches what you have registered — your property will be returned to you. Try doing this at any of the other auction sites!

The Internet has opened new avenues for criminals to fence stolen merchandise. This has made it easier to sell stolen merchandise and there are many who believe that it contributes to the problem. The most recent survey by the National Retail Federation estimates that Organized

Retail Crime is a $30 billion a year issue. Their most most recent Organized Crime Survey showed that e-fencing on traditional auction sites has grown by six percent. In response to this, they are even pushing bills in Congress to force the auction sites to allow more access to law enforcement and retailers, who are attempting to shut down this activity.

Even the government has found some of their stolen merchandise available for sale on eBay and Craigslist.

Please remember this doesn't even take into account the billions of dollars of property stolen from ordinary people. It also doesn't take into account the ordinary people who are scammed on auction sites, either. I wouldn't worry about getting scammed on PropertyRoom.com — I'm pretty sure they cooperate with law enforcement to the fullest extent.

We all know money is tight this Christmas season and there are a lot of people trying to stretch their limited resources. PropertyRoom.com is a place where you can do it and be certain that you are not contributing to a growing problem.

Sunday, August 03, 2008

Bills Introduced to Combat Organized Crime on Auction Sites

While stories of individual people getting scammed on auction sites are legendary, individuals aren't only ones victimized on these sites. Large retailers and brand owners are victimized when their stolen or counterfeit merchandise is sold on these sites, also.

In response to this, two bills are being introduced to combat this problem in the halls of Congress.

The reason this has become a growing issue is that criminals can net 70 percent of the value of stolen merchandise on an auction site versus the going 30 percent received on street corners, flea markets and pawn shops. So far as all the knock-off (counterfeit) goods being sold on auction sites, it's hard to put a dollar loss to it, but many believe it's substantial.

According to the International Anticounterfeting Coalition, counterfeiting costs U.S. businesses $200 to $250 billion a year. Counterfeiting and e-fencing pose safety risks to the public-at-large, also. Outdated or merchandise that isn't what it is advertised to be could potentially poison people, or cause bodily harm when it doesn't work like it's supposed to.

Simply stated auction sites, provide an anonymous marketing environment to sell both stolen and counterfeit goods.

“By hiding behind the anonymity of the Internet, they can make more money with less risk of getting caught than selling to a stranger on a street corner who might turn out to be a police officer. This bill would lift that cloak and help law enforcement put on-line criminals where they belong – behind bars,” according to Joe LaRocca, the National Retail Federations Vice President of Loss Prevention.

To address this problem, a federal bill (H.R. 6713, the E-Fencing Enforcement Act of 2008) is being introduced by Representative Bobby Scott, chairman of the House Judiciary Committee’s Subcommittee on Crime, Terrorism and Homeland Security.

The bill will require on-line auction operators to maintain information about high-volume sellers and provide the information to a person with "standing" once a police report is filed. The definition of a person of standing would be a law enforcement officer or a representative from a company, who has an interest in the merchandise being illegally sold on an auction site.

This is the second bill introduced recently to combat organized retail crime, which costs retailers anywhere from $15 to 30 billion a year. On July 15th, H.R. 6491, the Organized Retail Crime Act of 2008, was introduced by Representative Brad Ellsworth, a former county sheriff, along Representative Jim Jordan, as the lead co-sponsor. The bill establishes that unless auction site owners can show specific steps to prove goods being sold were not being obtained by theft or fraud, they could be viewed as "facilitating" the activity. This bill will also require site operators to cooperate with the police and organizations with a stake in stopping the activity. In certain instances, it will also allow merchants to initiate civil actions over stolen merchandise being sold on an auction site.

In the past, auction operators have been criticized for not effectively cooperating with companies and law enforcement when they made an inquiry into suspected criminal activity on their sites. It has also been established that smaller (individual) victims and merchants often receive little to no assistance after being victimized in an Internet auction deal.

E-fencing, phishing, counterfeit goods and the use of fraudulent financial instruments to buy merchandise from unsuspecting customers have all victimized countless people and organizations on auction sites.

Criminals often lure people to do their dirty work, also. Recruits are normally harvested off the Internet, sometimes from job sites, and offered work to reship stolen merchandise and or launder money from fraudulent transactions. Much of this activity involves sending money, or hot merchandise across an International border --making it extremely difficult to track.

A lot of criminal activity is facilitated on auction sites by what is known as phishing. Phishing is where an account owner is tricked into giving up their account details, either via social engineering, or more and more often, after downloading some malicious sofware. The stolen account details are then used to take-over the account and use it for illicit purposes.

In fact, eBay and PayPal accounts are frequently the most phished brands out there.

Phishing, normally facilitated by spam e-mails, is another ever-growing criminal activity on the Internet. Recent studies by the Anti Phishing Working Group show that it is becoming more automated and malicious software (crimeware) used to automatically steal information is becoming more prevalent.

There is little doubt that a lot of the criminal activity on auction sites is sophisticated and reeks of organized crime.

For anyone investigating fraud on an auction site, the only way to effectively do so, is to have access to information quickly and with as little red tape as possible. A lot of these crimes cross over borders quickly and by the time and investigator gets what they need, the trail is often pretty cold.

When auction site owners -- who suffer no financial liability and collect a lot of revenue in fees from this activity -- don't cooperate or move too slowly, it only ensures that criminals will be laughing all the way to the bank.

Even the government has had their stolen inventory sold on eBay and Craigslist. In April, the GAO issued a report that military items, including F-14 components, were being sold on auction sites. In August of last year, a U.S. Attorney was quoted as saying that stamps being stolen from self service vending machines with cloned payment cards were being sold on auction sites. At the time, I ran a simple search query and found some pretty good deals on stamps. As of today, these great deals still exist. Many of them are being sold below cost and the last I checked the Postal Service still offers credit. Why would someone sell stamps below cost?

In my opinion, both of the bills don't only serve the large merchants out there, but have the potential to protect everybody from fraud on auction sites. While both of these bills are being driven by the National Retail Federation, I see a lot of benefits to passing them for everyone concerned with fraud on auction sites.

I highly recommend that these other people, join in with the NRF and the Congressmen involved, and support getting these bills passed.

Friday, April 18, 2008

Vladuz busted, according to eBay

Vladuz, the mysterious hacker, who seemed to take great pleasure in hacking eBay has been arrested, according to eBay.

Ina Steiner reports on the AuctionBytes blog:

A cyber-criminal who embarrassed eBay for nearly a year with claims he had hacked the site was arrested on Thursday, according to eBay. "Vladuz" had harassed eBay with his taunting from December 2006 through October 2007, when he accessed eBay servers and gained limited access to a very small number of eBay accounts on the eBay.com site. (eBay said at the time that at no point did the fraudster get any access to financial information or other sensitive information.).
Thus far only eBay is confirming the arrest:

eBay spokesperson Nichola Sharpe said local Romanian law enforcement officials would have to confirm details, as they considered the case confidential until a conviction was made. Asked why eBay had issued a press release, Sharpe said eBay wanted to thank all of the law enforcement agencies involved who collaborated in the case. She also said that the community was aware of Vladuz, and said, "This is obviously great news."
eBay states that Vladuz never accessed any financial information, but I’m not certain that was his intention in the first place.

There are some, who believe his intention was to point out the massive amount of fraud occurring on auction sites and show weaknesses that could be exploited in eBay’s system.

After all, unless he is mentally disturbed, why would he make his effort so public otherwise? Most criminals prefer to remain anonymous when they are committing financial crimes. They make a lot more money that way.

Here is a previous post, I did on the mysterious, Vladuz:

Did Vladuz hack eBay, or is stockpiled stolen information being used to make it look like he did?

Friday, April 11, 2008

eBay/Craigslist praised by Congressman for efforts to curb sales of stolen military equipment on their sites (?)

I've written a few things about scams and fencing stolen merchandise on auction sites. Recently, the GAO discovered that items stolen from the military are for sale on eBay and Craigslist.

Even more interesting were the results of narrowly focused hearings (my opinion) on this matter in Washington, which can be seen at the bottom of this post. The reason I believe they were "narrowly focused" is because there is no shortage of fraud, phishing and financial misdeeds on auction sites.

Of course, there is also no shortage of ordinary citizens and businesses that have been taken to the cleaners on an auction site. Stolen government items are only a small part of the overall problem.

From the GAO report:

GAO found numerous defense-related items for sale to the highest bidder on eBay and Craigslist. A review of policies and procedures for these Web sites determined that there are few safeguards to prevent the sale of sensitive and stolen defense-related items using the sites. During the period of investigation, GAO undercover investigators purchased a dozen sensitive items on eBay and Craigslist to demonstrate how easy it was to obtain them. Many of these items were stolen from the U.S. military. According to the Department of Defense (DOD), it considers the sensitive items GAO purchased to be on the U.S. Munitions List, meaning that there are restrictions on their overseas sales. However, if investigators had been members of the general public, there is a risk that they could have illegally resold these items to an international broker or transferred them overseas.
Apparently, body armor, MRE (meals ready to eat), uniforms, night vision goggles, NBC (Nuclear Biological Chemical) equipment and even F-14 components were some of the items purchased on eBay and Craiglist by undercover investigators.

The obvious concern would be terrorists, or other not very friendly people getting their hands on some of this stuff.

Given the organized effort on a lot of auction sites to fence stolen merchandise via some pretty sophisticated methods, it's not surprising that the GAO found military equipment for sale on the sites. Many have speculated that these sites are used as a means of fencing the proceeds of what is known as organized retail crime. Of course, less organized criminals obviously sell their goods on auction sites, also.

Organized retail crime obtains their goods by a variety of methods from common theft to using stolen financial instruments. A lot of stolen financial instruments are used to purchase items on auction sites and e-commerce sites. Of course, they are used in more traditional store settings for the same purpose, also.

On eBay, account credentials and payment accounts (PayPal) are phished all the time, enabling an additional layer of anonymity to the schemes. In fact, over the years, many experts have stated that eBay and PayPal are the two most phished brands out there.

One thing not mentioned in the report is that people don't always get what was advertised on these sites. It isn't inconceivable that a complete fighter jet might be put up for sale, paid for and in the end a toy, or "nothing at all" is received by the buyer.

Trust me, this wouldn't be the first time something like this has happened on an auction site.

A lot of counterfeit (knock-off) merchandise is sold on the sites, advertised as the "real thing," also.

Our leaders in Congress reacted by calling Jim Buckmaster (Craigslist) and Tod Cohen (eBay) in to speak with them on the matter.

Anne Broache (CNet) writes:

By calling Craigslist CEO Jim Buckmaster and eBay government relations chief Tod Cohen to Washington for the hearing, the subcommittee seemed to be preparing to place those executives in the hot seat. But the tone of that questioning was actually quite cordial. At the end of the panel, Tierney even praised the companies for "trying very hard" to keep sensitive military goods off their sites and acknowledged the rules of the road aren't the most clear.

Based on her article, which reports that Buckmaster and Cohen were treated with "kid gloves" during the session, my prediction is that little is going to be done to regulate the sale of stolen goods on auction sites as a result of this.

Meanwhile, everyone running for office is saying they will be the one doing something about the problem of special interests in Washington.

On a closing note, I want to commend the GAO for their efforts to expose a problem. I'm just saying it's a shame that no one listened to what they were saying, very carefully.

HTML version of the GAO report, here.

PDF version, here.

Friday, March 21, 2008

OCCRP reports on Eastern European/Eurasian organized crime


(Photo courtesy of the OCCRP site)

Eastern European/Eurasian organized groups seem to have their hands in a wide variety of organized criminal activity. They are often mentioned when referring to anything from auction fraud to payment (credit/debit) card skimming and computer crimes.

eBay claims there are entire towns in Romania making a living via auction fraud on it's well known site.

A new site called the Organized Crime and Corruption Reporting Project has been launched by a group of journalists to cover this activity, which seems to have to have a global reach.

In their own words, here is their vision:

The Organized Crime and Corruption Reporting Project (OCCRP) is a joint program of the Center for Investigative Reporting in Sarajevo, Romanian Center for Investigative Journalism, Bulgarian Investigative Journalism Center, Media Focus, the Caucasus Media Investigation Center, Novaya Gazeta and a network of investigative journalists in Montenegro, Albania, Moldova, Ukraine, Macedonia and Georgia.

Our goal is to help the people of the region better understand how organized crime and corruption affect their lives. OCCRP seeks to provide in-depth investigative stories as well as the latest news pertaining to organized crime and corruption activities in the Eastern Europe and Eurasia. In addition to the stories, OCCRP is building an online resource center of documents related to organized crime including court records, laws, reports, studies, company records, etc that will be an invaluable resource center for the journalists and public alike.
The site has been given financial support by the Foundation Open Society Institute (FOSI) and the United Nations Democracy Fund.

Although many of the journalists aren't well known in Western Europe and North America, they have been recognized as putting out some award winning work:

Recently, the program’s first project on energy traders was awarded the Global Network of Investigative Journalists “Global Shining Light Award” for quality investigative journalism under adverse conditions. The project was done in cooperation with SCOOP.

Journalists who have participated in projects published on this website have included Stanimir Vaglenov, Alison Knezevich, Boris Mrkela, Sorin Ozon, Eldina Pleho, Beth Kampschror, Stefan Candea, Roman Shleynov, Mirsad Brkić, Michael Mehen, Mubarek Asani, Paul Cristian Radu, Milorad Ivanović, Vitalie Calugareanu, Vlad Lavrov, Michael Mehen and Altin Raxhimi. The Editors are Rosemary Armao, Paul Radu and Drew Sullivan.
The site covers a wide variety of organized criminal activity (besides what I mentioned above) coming out the the area. Some of these activities include narcoterrorism, illegal arms sales, shell companies and even tobacco smuggling.

Interestingly enough, by reading through the site, I discovered that organized crime even has it's hands in the energy business in the region.

This subject, or the underlying causes of it aren't covered in depth when we read about this phenomenon in the West. Normally, we hear rumors pointing to mysterious Eastern European gangs associated with a sophisticated scam that has surfaced in our own back yard.

In scam circles, some of these people are referred to as "Vlads," which refer to Vlad Tepes, who as the inspiration for the Dracula story. Recently, a person who goes by the name of "Vladuz" has given eBay and the authorities considerable grief when hacking into their system.

Given that this activity reaches far beyond Eastern Europe and Eurasia, this has always amazed me. If you live in any major city in North America or Western Europe, Eastern European/Eurasian organized crime groups are probably operating not very far from where you live.

As the site matures, my guess is that it will provide evidence to ties between these groups and terrorist organizations, also. In fact, if you read what is on the site, some of the evidence I mention is already being written about.

The OCCRP is an excellent and well-written resource for the lay person and professional writer to learn more about a problem, which has become International in nature. Furthermore, since it is written by journalists from the Region, it is a great research tool for anyone interested in the subject.

OCCRP site, here.

Sunday, February 24, 2008

On eBay, the buyer better beware!

Despite a lot of publicity that eBay is going after fraud, the bottom line is that the buyer better BEWARE when they purchase something on eBay, or for that matter, any digital auction site.

This morning, I read a story from Wales, where a person just got caught selling laptops that didn't exist.

From the Evening Leader:

Christopher Malcolm Amos, from Green Lane, Shotton, admitted swindling customers of the online auction site out of thousands of pounds to fuel his gambling addiction.

Under the user name 'Whitefruit,' the 22-year-old accepted payments from 130 bidders wanting to buy laptop computers.

Some used eBay's PayPal facility, while others transferred the cash directly into Amos's bank account, but nobody ever received their orders.

Please note that at least some of the fraud victims used eBay's preferred method of payment, PayPal.

And Mr. Whitefruit, who I gather is a gambling addict, didn't get into very much trouble for swindling about 100 people. He was ordered to pay some restitution and got a 12 month suspended sentence.

I'm sure eBay fraudsters around the world are quivering in their boots!

I ran into another story in the ChronicleHerald (Halifax, Canada) describing a significantly larger operation involving selling neat "tech toys" that never existed:

Police said Wednesday several complaints about alleged electronic commerce crimes have come in during the past week to 10 days. Customers are from such countries as Australia, Sweden, Norway, the United States, Italy and Estonia. Const. Jeff Carr, a spokesman with Halifax Regional Police, said Canadian EBay users have allegedly been victimized as well, but there are no complaints from the Maritimes.
The person behind this, who hasn't been caught yet was selling laptops that didn't exist.

The story also indicates that PayPal was used on some of these transactions:

He said one complaint, from PayPal of San Jose, Calif., includes more than 100 alleged victims. PayPal, which was acquired by EBay in 2002, is an online money-sending service that provides users worldwide an opportunity to buy and sell goods without sharing personal financial information.

Even when you get the merchandise you paid for on an auction site, you are taking the chance that it is a cheap "knock off," or might be some of the stolen merchandise being fenced on some of these digital marketplaces.

Knock off merchandise can be dangerous when it doesn't work as well as the item it is passing itself off does. Buying stolen merchandise poses certain moral issues, also.

When buying something on an auction site, it is up to the buyer to make sure (beware) they are getting what they paid for. This can include using some good old "horse sense," and being able to realize when the deal you seem to be getting is a "little too good to be true."

Previous posts, I've written about fraud on eBay, can be seen, here.

Evening leader story, here.

I've also written about a company called buySAFE, who certifies sellers and guarantees what they sell. The seller pays for this -- and while I suppose the cost is included in their cost of goods sold -- this might be a good way to avoid fraud without having to do a lot of homework.

buySAFE's CEO, Steve Swoda does a blog, which I read from time to time can be seen by clicking, here.

Friday, December 21, 2007

$500 reward for eBay pirates selling super cheap (counterfeit) software

The Software & Information Industry Association is willing to pay up to $500.00 to anyone, who inadvertantly buys pirated software off an auction site.

Software piracy is a huge problem. The International Anticounterfeiting Coalition estimates that counterfeiting is a $600 billion a year problem. They also estimate that the problem has grown 10,000 percent in the past two decades.

More specific to the counterfeit software part of the all of this was revealed in a Business Software Alliance (BSA) and IDA white paper released in May estimating the problem at $40 billion a year.

Pirated software might not work as well as it is supposed to and it might even contain malicious software, which is often referred to as crimeware. The person, who puts this on their system is likely to have all the personal and financial details stolen and become an identity theft statistic.

Microsoft has a site to help consumers identify counterfeit software. Earlier this month, they filed 52 lawsuits and referred 22 cases for criminal investigation based on an investigation -- jointly conducted with the FBI and Chineses authorities -- into a counterfeiting syndicate based out of China.

Microsoft has also worked with eBay and information is also available on their site on how to avoid buying counterfeit software, here.

A lot of pirated software is sold on auction sites. The Software & Information Industry Association (SIIA) has launched a campaign to go after this problem on auction sites because they believe a lot of auction consumers are being defrauded when pirated software is sold as the real McCoy.

From the SIIA press release on this campaign:

“The sale of pirated software doesn’t only hurt the software industry,” said Keith Kupferschmid, Senior VP Intellectual Property Policy & Enforcement. “It also hurts consumers. Consumers feel “taken” when they buy software, only to find out when it arrives that the software is a fake -- they did not get an instruction manual or can’t get support from the software company. The Don’t Get Mad, Get Even program is a way for unsuspecting buyers to get even with auction sellers who rip them off by selling them counterfeit software.”

SIIA press release on reward, here.

Counterfeiting is a huge problem which hurts economies (takes jobs) and funds organized criminal and some say (terrorist?) activity. It also puts the person, who inadvertantly buys it at a fair amount of personal risk. Everyone can help fight it by reporting it to the SIIA, or the other links I've included in this post.

Despite what some people believe, counterfeiting is far from a victimless crime!

SIIA home page, here.

BSA and IDA white paper on counterfeit software, here.

Sunday, November 11, 2007

Digital gangsters can buy everything they need to commit fraud right on the Internet!

There is a lot of technology with questionable applications being sold on the Internet. Of course, this is merely my opinion, but I have my reasons for believing this.

Robert McMillan, IDG News Service wrote an INTERESTING article about spyware being sold on eBay that has questionable applications.

From his article:

Think your wife may be cheating on you? Wondering who your boss might be talking to? "Learn the truth. Spy today."

So reads an ad for "Bluetooth Spy Pro-Edition," one of nearly 200 mobile phone spyware products currently listed for sale on eBay.

The software, which costs as little as US$3.99, can be used to view photographs, messages and files on the phone, listen into phone conversations, and even make calls from the phone being spied upon.

Security experts are concerned, because while these products aren't illegal, installing them without authorization to spy on someone else most definitely is.
Of course, eBay wasn't able to be reached for comment.

In August, I did a post called, Self service stamp machines targeted by credit card thieves. When writing it, I saw a quote that some of the stolen stamps were being sold on eBay and decided to see for myself. What I found was a lot of stamps for sale for what seemed to be too good to be true prices.

To be completely fair, eBay isn't the only one selling questionable merchandise on the Internet. The problem exists on auction sites in general and there are e-commerce companies that specialize in selling devices, which are marketed specifically as tools to violate other people's privacy.

In the wrong hands, these devices can be used for more sinister purposes, also.

A good example of this is keylogging software, which is is a favorite tool of cybercriminals to steal people's personal and financial information. Keylogging software is legal and easy to purchase in a variety of places, including the Internet.

Another example, which is similar to Robert McMillan's story concerns a company called FlexiSpy. I did a post on this company, who sells technology designed to spy on Smart Phone users.

In the post, I wrote:

There is already a lot of "buzz" that mobile phones, especially those of the smarter variety will be targeted for their "information value."

A product called "FlexiSPY" is being legally sold, which allows anyone (with the money to buy it) to invade the privacy of someone, who uses a smart phone.

Despite all the controversy at the time, FlexiSpy seems to be alive and selling their product to anyone with the money to buy it.

To end this post, I will refer to the worst site of this type (my opinion) out there. Hackershomepage.com is a one stop e-commerce shop selling technology and a host of manuals that could be used to commit a host of financial crimes.

I covered this website in a post entitled:

It is no wonder why skimming (credit/debit card fraud) is becoming a nasty problem!

Here is the websites legal disclaimer:

We WILL NOT answer emails from anyone asking about illegal activities, or how to use our products for illegal activities...they will automatically be deleted. All products are designed for testing and exploring the vulnerabilities of CUSTOMER-OWNED equipment, and no illegal use is encouraged or implied. We WILL NOT knowingly sell to anyone with the intent of using our products for illegal activities or uses. It is your responsibility to check the applicable laws in your city, state, and country.

Hackershomepage.com, who has the motto "they make it we break it" is up and running at the time of this writing and boasting they've been in business for eleven years.

While there might be legitimate uses for some of this technology being marketed on the Internet, you would think at the VERY least we might want to put a few controls on who it is being sold to?

When I say some of this technology MIGHT have legitimate uses, there is also some that I can think of no legitimate use for!

Unfortunately, until laws are enacted that hold the sellers accountable, little can be done about this.

One thing to remember is that even though the sellers aren't being held accountable, the buyers will be if they are caught using them in a manner deemed to be illegal. Just because it appears easy to buy doesn't mean that using it won't land a person in a lot of trouble.

It's safe to say that we could find people in correctional institutions that could attest to this fact.

IDG News Service story (courtesy of PC World), here.

Botnet owner faces 60 years in prison and a $1.75 million fine

Until recently, botnet owners seemed to be able to trash people's systems without having to face very many consequences. And in a lot of instances, more than a system gets trashed when it is compromised by a botnet owner.

Friday, the Central California U.S. Attorney's office announced the prosecution of one of these botnet owners. Of interest, the botnet owner, John Schiefer admitted to compromising up to 250,000 computers with malware (malicious software).

In the first prosecution of its kind in the nation, a well-known member of the “botnet underground” was charged today with using “botnets” – armies of compromised computers – to steal the identities of victims across the country by extracting information from their personal computers and wiretapping their communications.

The criminal information and plea agreement filed this morning in United States District Court in Los Angeles outline a series of schemes in which Schiefer and several associates developed malicious computer code and distributed that code to vulnerable computers. Schiefer and the others used the illicitly installed code to assemble armies of up to 250,000 infected computers, which they used to engage in a variety of identity theft schemes. Schiefer also used the compromised computers to defraud a Dutch advertising company.

According to the press release, Schiefer and crew seemed to prefer harvesting eBay and PayPal information:

In his plea agreement, Schiefer acknowledged installing malicious computer code, or “malware,” that acted as a wiretap on compromised computers. Because the users of those compromised computers were unaware that their computers had been turned into “zombies,” they continued to use their computers to engage in commercial activities. Schiefer used the malware, which he called a “spybot,” to intercept electronic communications being sent over the Internet from those zombie computers to www.paypal.com and other websites. Once in possession of those intercepted communications, Schiefer and the others sifted through the data to mine usernames and passwords. With Paypal usernames and passwords, Schiefer and the others accessed bank accounts to make purchases without the consent of the true owners. Schiefer also acknowledged in the plea agreement that he transferred both the wiretapped communications and the stolen Paypal information to others. It is the first time in the nation that someone has been charged under the federal wiretap statute for conduct related to botnets.

It appears that the FBI's Cyber Division might have had something to do with catching Mr. Schiefer and crew.

In June, they announced a nationwide initiative against botnet owners called Operation Bot Roast.

Mr. Schiefer isn't mentioned in the release about Operation Bot Roast, but it appears that the FBI is starting to take this activity seriously and is making it more dangerous for botner owners to operate.

When Schiefer pleads guilty to all of this on November 28th, he will face a statutory maximum sentence of 60 years in federal prison and a fine of $1.75 million.

Full press release from the United States Attorney's Office Central District of California, here.

If you have been a victim of a botnet owner, who turned your computer into a zombie you can assist the FBI by reporting the matter at the Internet Crime Complaint Center.

They also have some information on how to avoid having your computer turned into a zombie, here.

Sunday, November 04, 2007

eBay shoppers crack QVC fraud case

eBay and auction sites are found to have HOT merchandise being sold on them too frequently (my opinion). I ran across a story in the Register, written by Dan Goodin, where two eBay customers cracked a $412,000 fraud case being committed against QVC.

As reported by Dan Goodin:

A woman has pleaded guilty to fleecing the QVC home-shopping networking of more than $412,000 by exploiting a gaping hole in its website that allowed her to receive merchandise without paying for them.

Quantina Moore-Perry ordered handbags, jewelry and electronics and then immediately canceled the transactions. The flaw allowed the North Carolina woman to take delivery of more than 1,800 items without being billed. Moore-Perry would then sell the booty on eBay, according to the Associated Press, which cited authorities.
I wonder if QVC offered a reward to the two eBay shoppers, who discovered this flaw in their system?

This would also make me wonder if this woman was the only one who has defrauded QVC in this manner?

There is a lot of controversy surrounding the sale of stolen merchandise on eBay and other auction sites. I've heard that some companies now have a dedicated person in their security departments to watch these sites for stolen merchandise.

Register story, here.

For other posts, I've written concerning stolen merchandise on auction sites, click here.

Friday, October 19, 2007

How much money is lost by businesses due to coupon fraud?

Here is an interesting blurb about an Arby's employee, who stole $14,524 by using coupons to conceal the fact he was dipping into the till.

NBC10.com (Philadelphia) is reporting:

A fast-food restaurant employee was charged with theft after police said he was skimming the cash register by using coupons.

Curtis Smith, 32, of Coatesville, was an employee at the Arby's store located on Concord Pike for several years, police said.

Police said Smith used $1 off coupons at the register and would then take that money from the register. He obtained between $50 and $150 at a time, police said.

The investigation started because of declining revenues at the restaurant.

Coupon fraud can be a huge problem for companies, who use them as marketing tools. A few years ago, Subway discontinued a promotion because too many coupons were being reproduced and sold on auction sites.

CouponInfo.com has some pretty good descriptions of the types of coupon fraud going on out there. According to the site, there is even an underground market in counterfeit coupons.

They state that coupon fraud costs companies millions of dollars a year.

After reading this, I decided to go on eBay and see if I could find coupons for sale. After going to the site, I was able to find quite a selection. If you want to take a look, click here.

Because everyone always picks on eBay, I decided to see what Google had to say. After doing this, I was amazed at the market out there in selling coupons.

No wonder CouponInfo.com couldn't put an exact figure to the losses caused by coupon fraud. It would be pretty hard to figure out!

Going back to the story about the Arby employee, the article doesn't state where he got the $14,523 in coupons. Of course, it's hard to say, but it wouldn't be hard to find them by doing a little surfing on the Internet.

Maybe this is something that businesses, who issue and redeem coupons should watch a little more carefully?

NBC.com story, here.

Monday, October 08, 2007

The continuing saga of Vladuz and Phishing on eBay

Here is an update to the ongoing saga of Vladuz versus eBay. Apparently, Vladuz, or someone claiming to be him, accessed eBay's servers and suspended some eBay accounts.

Ina Steiner reports on the AuctionBytes blog:

eBay confirmed that a known fraudster had limited access to a very small number of eBay accounts on the eBay.com site and the company appeared to have reacted quickly to block him on Friday. eBay spokesperson Nichola Sharpe said, "At no point did the fraudster get any access to financial information or other sensitive information." In a strange twist, some users reporting the incident said they had been openly critical of a hacker calling himself Vladuz and had been suspended briefly during the incident.
It is strange that some of the people suspended were openly critical of Vladuz?

Notably, this is the first time eBay has admitted Vladuz accessed their servers.

In another development, eBay, PayPal and Yahoo are joining forces to combat phishing. Phishing is a phenomenon that has caused a lot of eBay and PayPal account holders a lot of grief. Experts maintain that eBay and PayPal are the two most phished brands out there.

Phishing is where an account holder is duped into giving up their access information via social engineering (trickery).

The intent of the phishermen, who target eBay/PayPal accounts is normally to take the account over and commit even more fraud.

This activity gets more sophisticated all the time with crimeware (malware) being used (which steals the information automatically), and DIY (do-it-yourself) phishing and hacking kits being marketed in underground Internet forums.

Reuters, courtesy of the Washington Post is reporting:
EBay and PayPal have upgraded their computer systems to support an emerging technology standard known as DomainKeys invented by Yahoo that authenticates e-mail senders are who they say they are, allowing Yahoo to block fake e-mails.

The technology upgrade will be made available to Yahoo Mail users worldwide over the next several weeks, the company said.
If you are interested in how bad the phishing phenomenon is getting, the National Consumers League has a very well written and informative paper on the subject, here.

They also have an interesting document, which although is a little dated, shows the increase in auction fraud and calls out that eBay severed their ties with them.

It should be noted that auction fraud doesn't only occur on eBay. It can and does happen on all the auction sites. The reason we hear more about it on eBay is because they are the used by more people than the other sites.

For the scammers that means there are more potential victims to harvest there.

NCL article on auction fraud, here.

AuctionBytes blog post on this, here.

Reuters story on eBay/PayPal's efforts to combat phishing, here.

Here is my most recent post about Vladuz allegedly raising his head again:

Did Vladuz hack eBay, or is stockpiled stolen information being used to make it look like he did?

Thursday, September 27, 2007

eBay responds to the alleged Vladuz hacking incident

eBay is responding to the latest (alleged) attack on their site by Vladuz by confirming that the account information was valid, however the credit card numbers were not.

Here is what the Chatter (eBay's blog team) has to say regarding their investigation:

I've been in touch with our operations and security teams, and I have more information I can share with you about yesterday's incident on the Trust & Safety discussion forum. In brief, very early yesterday morning, a fraudster posted contact information and alleged credit card numbers for about 1,200 members on our Trust & Safety discussion forum on eBay.com.

While the issue was very unfortunate, it was clearly falsified to cause public concern. Early on eBay's teams verified that the credit card "data" did not match anything on file for these members on eBay or PayPal. After more investigation, including phone conversations with many of the members, it appears that these numbers were not valid at all.

Each of these accounts was the victim of an Account Take Over, most likely through a successful phishing campaign. eBay has been in contact by phone with many of these members, and there is a My Messages email going out to impacted accounts to further our reach.

1200 successful account-takeovers is a fairly large asset for a criminal to part with, even if the credit card numbers were no good. In the hand of the wrong people, 1200 eBay and PayPal accounts can be used to commit a lot of crime.

Here is a description of how account-takeovers are sometimes used from my original post on this latest incident:

Account-takeovers enable criminals to scam others, using someone else's information. They can also be used to fence (sell) stolen merchandise with a high degree of anonymity. It should also be noted that stolen payment (credit/debit) card details are often used to purchase the merchandise, which is then fenced.

To cover their tracks, the scammers often dupe people into laundering the proceeds of these sales in work-at-home (job) scams and wiring the money, normally across a border.


Although eBay is stating that the credit card numbers in this case were no good, they are for sale, along with account-takeover information on the Internet. Because this information is sold over the Internet, the criminals are able to buy and sell this information (globally) without ever actually meeting each other in person.

As I stated in my earlier post, phishing is a method, where a lot of personal and financial information is stolen, also.

Thus far, all anyone can do is speculate as to how the accounts were compromised. It will be interesting to see if anyone gets to the bottom of what actually occurred.

The Anti-Phishing Working Group tracks phishing activity and many experts claim that eBay and PayPal are the most frequently phished brands. They also have some excellent information on how to avoid being a victim and what to do if you think you've become one.

Auction fraud doesn't only occur on eBay and can happen on any of the auction sites out there. The criminals behind this activity tend to go after what is the most popular, which probably has more to do with why they target eBay than anything else.

If you get phishy e-mails that ask you to provide your eBay, or PayPal account numbers, the Chatter recommends you report them to spoof@ebay.com or spoof@paypal.com. They also recommend to go to their Security & Resolution Center if you encounter a problem.

Another place to report phishy e-mails is CastleCop's PIRT Phishing Incident Reporting and Termination Squad. Please note you can also report this activity on the Anti-Phishing Working Group's site, also.

Reporting a phishing attempt might prevent someone else from becoming a victim. Sadly enough, if you have an e-mail address, you probably see phishing attempts on a daily basis.

Post from the Chatter, here.

Wednesday, September 26, 2007

Did Vladuz hack eBay, or is stockpiled stolen information being used to make it look like he did?


(Picture courtesy of Yahoo Group, eBay_scamkillers)

There is a lot of speculation that eBay was hacked once again, and that Vladuz might be behind the latest episode.

Vladuz, who takes his name from a famous Romanian prince, Vlad Tepes, has plagued eBay with a string of hacking attacks in the past. Vlad Tepes was the inspiration for the novel, Dracula. In Internet folklore, Romanian scammers are often referred to as "Vlads."

Of course, eBay is denying that they were actually hacked. I'll let the reader form their own opinion.

Auction Bytes (Ina Steiner) is reporting:

eBay closed its Trust & Safety discussion board for hours on Tuesday after threads began appearing listing the names and addresses of eBay members. eBay spokesperson Nichola Sharpe said, "We think the fraudster obtained the eBay User names and IDs from previous account takeovers." The credit card information that was published alongside 1,200 names, User IDs and addresses were not associated with the financial information on file for those users at eBay or PayPal, Sharpe said.

Unfortunately, with the amount of account-takeovers caused by Phishing, eBay can suggest other ways the information might have been stolen. Phishing is where users are tricked into giving up their personal details, or downloading malware (crimeware), which steals it right off their hard drive.

I don't know which is worse, that they were hacked in this incident, or that all this information was compromised a long time ago? If it were compromised a long time ago, as eBay states, how much more compromised eBay information is out there?

The Cappnonymous Buds Blog has put together a pretty visual demonstration that makes a pretty good argument that eBay was hacked.

Account-takeovers enable criminals to scam others, using someone else's information. They can also be used to fence (sell) stolen merchandise with a high degree of anonymity.

It should also be noted that stolen payment(credit/debit) card details are often used to purchase the merchandise, which is then fenced.

To cover their tracks, the scammers often dupe people into laundering the proceeds of these sales in work-at-home (job) scams and wiring the money, normally across a border.

Whether Vladuz is behind this latest attack remains to be seen. But the fact remains, that there is a lot of fairly organized crime targeting eBay (my opinion) and other auction sites, on a daily basis.

Previous posts, I've written about eBay and auction fraud can be read, here.

In case anyone is interested in the graphic photo at the top, here is a post I did about a Yahoo Group that call themselves the eBay_scamkillers.

They are an all volunteer group, many of whom have impressive credentials, that are responsible for putting a lot of eBay scammers, where the sun don't shine (prison).

Thursday, September 20, 2007

DIY (do it yourself) crimeware kits designed to steal personal information are for sale on eBay

Do it yourself (DIY) crimeware kits being sold on the Internet make it easy for non-technical criminals to commit fairly sophisticated (technical) crimes.

DIY crimeware kits have been credited with fueling the information (identity) theft crisis.

Ran into this interesting post on Cappnonymous (The Modern Day Beatnik Refuses to Die), which quotes a press release from PC Tools about crimeware for sale on eBay. The original press release from PC Tools points to eBay links, which have been deactivated.

Fortunately for those of us, who might be interested in taking a look at this, Cappnonymous was able to recreate a visual demonstration (screenshots) showing this illicit software being sold on eBay.

From the original press release from PC Tools:

Online auction site, eBay, is unwittingly selling software that is used to hack eBay user accounts and steal personal information, according to research from online security experts PC Tools.

A number of software items for sale on the world’s leading online auction site contain a variety of programs including keyloggers, trojans and other malware making devices that are aimed at helping users hack computers, websites and even individual user accounts.
The release quotes Mike Greene, VP Product Strategy at PC Tools as saying:

It is ironic that something intended ultimately to steal a consumer’s identification and financial information is being sold via what is one of the world’s number one targets for the ID theft.
Cappnonymous added his own sage comment:

Note a couple of the hilarities such as payment via Paypal and the Square Trade seal.

The seller’s feedback is 100%, so he/she must have some very happy buyers.

Cappnonymous post, which contains an excellent visual demonstration of this problem, here.

Although, eBay is frequently the subject of fraud articles, I'd like to point out that tools to commit cybercrime might be for sale on a variety of auction sites.

They are also being sold in a lot of other places on the Internet. Because the sellers are motivated to sell as many of them as they can, they will migrate to the best places to market their seedy products.

Some of them even provide technical support.

The Anti Phishing Working Group issued a detailed report last October regarding this problem, which can be seen, here.

Saturday, August 11, 2007

Self service stamp machines targeted by credit card thieves


Photo courtesy of Leff at Flickr

New scams are invented daily. Here is one, where self-service stamp machines (the kind that accept payment cards) are being targeted at Post Offices.

David Bowermaster at the Seattle Times is reporting:

In mid-July, three men left their homes near Los Angeles and traveled to Seattle to buy postage stamps.
But these were no ordinary collectors. Armed with at least 27 stolen credit-card numbers, federal prosecutors say, Artem Danilov, Stephan Melkonyan and Karapet Kankanian fraudulently purchased more than 3,200 books of stamps worth nearly $24,000 from Seattle-area post offices in just more than a week. A federal grand jury Thursday charged the men with an assortment of crimes.

Following a pattern that Postal Service investigators have uncovered in at least five Western states, the men made mass purchases of stamps after normal working hours from automated postal machines, which are accessible 24 hours a day in the lobbies of many post offices around the country, prosecutors allege.
While these three were caught (two Russians and an Armenian), it appears this activity has been occurring throughout the Western United States.

The illegal stamp-buying scheme appears to be a novel breed of identity theft, one that blends high-tech thievery, online commerce and the retro currency of the U.S. mail.

James Vach, a spokesman for the U.S. Postal Inspection Service in Seattle, said investigators first encountered a wave of fraudulent stamp buys in the Los Angeles area late last year.

Since then, the Postal Service has uncovered illegal stamp-buying schemes in Washington, Oregon, Arizona and Colorado.

The Postal Inspectors suspect a larger ring is involved and some of the stolen credit card numbers used have been traced to a car wash in Southern California.

According to the article, here is how the suspects were using the stolen credit card numbers:

Danilov, Melkonyan and Kankanian allegedly used a credit-card reader to embed the stolen credit-card numbers onto the magnetic strips of gift cards from a variety of retailers, Brown said, a process that allows the gift cards to function like credit cards.

They then used the adulterated gift cards to repeatedly buy books of stamps from postage machines in one post office after another. Customers used to be able to buy dozens of books of stamps per transaction from the automated postage machines, but the Postal Service has since limited the number to try to fight such fraud.

Although the authorities don't know where all the stamps were being sold, according to a assistant U.S. Attorney, some of them are being fenced on eBay.

A lot of stolen merchandise is fenced on eBay and other auction sites. A lot of this stolen merchandise is purchased with fraudulent credit/debit card information.

Out of curiousity, I decided to see if new stamps (the kind used for postage) could be found on eBay. Amazingly enough, I found what I consider a large selection with offers of free shipping and discounted prices. What I found can be seen, here.

Of course, at a glance, it can be hard to tell what is legitimate and what is not on an auction site.

A lot of stolen gift cards (used in this instance to clone the cards used) are also fenced on auction sites. I wonder if the value on them had already been used, or if our suspects lifted them at a retailer before a dollar value was loaded on them at a point-of-sale (register)?

Seattle Times story, here.

If you spot this type of activity during a visit to the Post Office, you can report it to the Postal Inspectors, here.

Although two of the suspects apprehended were Russian, the U.S. resident was an Armenian from Southern California. Recently, Armenians (from Southern California) have been tied into similar type activity. The previous posts, I've done on these stories can be seen, here.

Friday, July 06, 2007

If your car gets stolen, eBay might be a good place to look for it!

If your car was recently stolen, it might be a good idea to check out the listings on eBay, according to Dariusz Grabowski, a.k.a (also known as) as the "eBay king of stolen cars."

Rick Hepp at the Star-Ledger reports:

Grabowski and his crew would buy junked or damaged vehicles at auctions and look for similar newer cars to steal. Once they found a car they wanted, they would get its vehicle identification number, usually found in sales ads or right on the car's windshield.

Today's newer car keys can only be duplicated if their computer chips are programmed according to the vehicle identification numbers. Car owners who lose their keys and want duplicates generally go to locksmiths who program the new keys by getting "key codes" from database companies hired by auto manufacturers.

Posing as a locksmith, Grabowski got these codes from the database companies and then made brand new keys. His crew took the keys and simply drove off with the cars.

Before selling the cars, they made them look legitimate by switching the vehicle identification numbers with the ID numbers of the junked cars they had bought.

Grabowski learned how to do all of this by surfing websites that provide technical assistance to locksmiths, and interestingly enough, buying any hardware he needed, on eBay:

You go online, you find anything you need," Grabowski told the investigators in the videotaped interview. "You can go on eBay at this point and purchase any of the equipment you need. Of course, I might pick this up easier than other people.
From there, Grabowski got a business license, which he made on a computer "real quick" and lavished special attention on a female owner of a company licensed to provide locksmiths with the necessary code to clone keys.

Grabowski and crew have all been convicted, but their victims are still paying the price for their misdeeds. New Jersey State Investigator, Jeffrey Lorman was quoted in the article as saying:

The buyers were happy with the cars, they got a great deal. Then we found out about Dariusz and the stolen cars were recovered. Some of these people are still paying for cars they no longer have.
The article mentioned that Grabowski was affiliated with a lot of other Polish nationals, involved in the business of stealing cars, also.

Our friend Dariusz, might or might not be the eBay king of stolen cars. If he is, he isn't alone, at least according to Google. A simple Google search reveals a large amount of information related to scams involving automobiles on eBay, here.

Fraud, Phishing and Financial Misdeeds a.k.a. (sometimes) FraudWar has a lot of information on auction fraud (if anyone is interested), here.

My advice is to be extremely cautious when buying a car on an auction site! If you choose to be cautious a good place to perform due diligence is CarBuyingTips.com, which can be seen, here.

The word is caveat emptor, latin for "buyer beware."

Star-Ledger article, here.

Thursday, June 28, 2007

eBay sends high-tech care package to Romanian cops

Romanian fraudsters are known as Vlads. Vlad Tepes, a Romanian prince, was the inspiration for the original Dracula story. Interestingly enough, some Romanians consider him a a folk-hero, who drove away invading armies. Photo courtesy of Flickr.

We hear a lot about Romanian organized crime being involved in fraud on auction sites. They are also well known in the world of payment (credit/debit) card skimming.

One of the more infamous Romanian fraudsters goes by the name of Vladuz. Vladuz openly mocked eBay for awhile, publically hacking the site and creating an uproar, but he seems to be laying low, recently.

Apparently, eBay is now providing Romanian law enforcement with technical resources. Ed Sutherland (AHN News) reports:

EBay is assisting Romanian law enforcement to detect and stop fraud targeting losing auction bidders. For months, the auction giant said a large portion of online fraud was coming from the Eastern European nation.

First noticed in 2005, criminals in Romania are taking advantage of a gap in the tech knowledge of local police to prey on eBay users that are outbid in auctions.

"The fraudster can see that a user that didn't win was prepared to spend $145 on a particular item," Matt Henley, part of eBay's Fraud Investigations Team, told News.com. The fraudsters knew most people used their email account name for their eBay username. The criminals would contact the losing bidder by email away from eBay, offering a second chance to obtain the item.

Since uncovering the fraud, eBay began hiding user names when bids exceed $80.


AHN story, here.

Here is a post, I did on a group that fights Romanian fraud on a volunteer level (although I hear they provide a lot of useful intelligence to law enforcement, also):

Auction Fraud and the Romanian Connection

Firemeg.com is also a good place to keep up on eBay fraud happenings, or other rants about eBay. Their site can be viewed, here.

For a lot of information on auction fraud, click here.

AOL has a collection of videos showing some of the hacking/fraud activity on auction sites, here.

Friday, May 04, 2007

You never know who might be selling hot merchandise on eBay

Normally, I avoid writing about petty crime, but this one is too good to pass up.

From SF Gate:

A Hillsboro mother found her daughter's missing winter coat on eBay, and now a teacher at the girl's elementary school faces charges of theft and computer crimes.

The teacher, who was placed on administrative leave pending the outcome of her trial, claims she found the jacket in the lost and found.

Of course, Mom claims she had already checked there!

With all the alleged fencing that occurs on auction sites, this person is either very unlucky, or doesn't cover her tracks very well. I would have to recommend, she sticks with teaching elementary students.

A couple of days ago, I wrote about what might happen to credit cards and identification left haphazardly in a lost and found:

Airline employees and correctional officer arrested for credit card fraud

Full story from SF Gate, here.

Saturday, April 07, 2007

buySAFE takes on the issue of counterfeit (knock off) merchandise

buySAFE bonds sellers after verifying they are reputable and honest. They also contribute their time to protecting the average person in the sometimes murky waters of e-commerce. Recently, buySAFE has been taking on the (huge) issue of counterfeit merchandise.

Consumers are protected when they buy from a merchant bearing the buySAFE seal. Not a very bad deal for the consumer! Bonding isn't free, but many merchants experience higher sales volumes after being accepted by buySAFE. Trust can drive a lot of sales! buySAFE is also a viable means for a merchant to protect their assets.

The Association of Certified Fraud Examiners noted in their last report to the nation that small businesses suffer "disproportionate fraud losses," when they are victimized by fraud. Large merchants can afford experts to deal with their fraud problems, however the cost is hiring experts can be restrictive for smaller merchants.

Of the numerous fraud issues found on auction sites, complaints about counterfeit goods rank pretty high. People buy items believing they are the "real deal," only to discover the item is a (knock-off) counterfeit.

Companies, who sell respected and trusted brands, are impacted by a loss of sales and consumer trust in their products, also. Some of them have already filed civil litigation against eBay because of the amount of knock-off (counterfeit) merchandise being sold on the site.

Even though auction sites offer seller rating systems, these ratings are often compromised when seller accounts are hijacked (taken over). eBay and PayPal (by most accounts) are recognized as the two most phished brands out there.

The intent of most of these Phishing schemes is to obtain personal/financial information to steal money (and or) take over legitimate accounts.

This can also happen when malware (crimeware) is inserted into an unprotected system and personal/financial details are stolen, normally using key logging software. Sadly enough, the criminal element has found it pretty easy to remain anonymous on auction sites, and few of them seem to get caught.

Whenever the Anti Phishing Working Group (APWG) releases a new report, both of these activities seem to set a new record that surpasses the previous one.

Recently, eBay seems to be taking the fraud problem a lot more seriously, but someone using the name of "Vladuz" is intent on proving their systems are easily compromised. A good place to keep up on the Vladuz saga is firemeg.com.

Although a good information source, I'm not certain that bashing Meg is the solution to fraud on auction sites.

Being the largest auction site, eBay is targeted by fraud all the time because of their popularity.

Fraud has already migrated to other auction sites, but they will always target the most popular.

The reason for this is simple (and it's only business for them) - there are more victims to harvest in popular places.

The term "Vlad" was based on a Romanian historical figure, Vlad Tepes, who inspired the novel, Dracula. In recent times, the term has come to signify fraudsters from Romania, who are well established and organized in the world of auction fraud.

Besides, protecting merchants and consumers, buySAFE makes a lot of contributions to addressing fraud issues on auction sites. Most recently, Jeff Grass (buySAFE CEO) has posted a lot of educational information on his blog about the counterfeit problem, here.

Jeff also appeared on the Today show, when they did a piece on counterfeit goods.You can view a clip of the show, here.

And the Today show isn't the only place that considers buy Safe’s views on the counterfeit problem important. The French government recently included buySAFE as part of a U.S. delegation (including government experts) to discuss the problem of counterfeit goods.

The INTERNATION ANTICOUNTERFEITING COALITION (a non-profit) sums up the problem when they state:

Counterfeiting is big business.It is estimated that counterfeiting is a $600 billion a year problem. In fact, it's a problem that has grown over 10,000 percent in the past two decades, in part fueled by CONSUMER DEMAND.

The real truth is people who purchase counterfeit merchandise risk funding nefarious activities, contributing to unemployment, creating budget deficits and compromising the future of this country in the global economy.

IACC site, here.

Part of the reason the activity has grown 10,000 percent is probably due to the explosion in e-commerce, especially on auction sites.

buySAFE seems to be doing a little more than just selling a product. In fact, they seem to be exercising some corporate responsibility by educating the public on fraud trends in the rapidly growing world of e-commerce.

Consumers can become a member of their Smart Buyer's Club, which leads you to a lot of good deals (safe to buy), here. Club members accumulate points, which can be redeemed for goods, or services (listed on the site).

Anyone claiming to be a buySAFE merchant can be verified, which can be done on the site, also.