Sunday, August 03, 2008
Bills Introduced to Combat Organized Crime on Auction Sites
In response to this, two bills are being introduced to combat this problem in the halls of Congress.
The reason this has become a growing issue is that criminals can net 70 percent of the value of stolen merchandise on an auction site versus the going 30 percent received on street corners, flea markets and pawn shops. So far as all the knock-off (counterfeit) goods being sold on auction sites, it's hard to put a dollar loss to it, but many believe it's substantial.
According to the International Anticounterfeting Coalition, counterfeiting costs U.S. businesses $200 to $250 billion a year. Counterfeiting and e-fencing pose safety risks to the public-at-large, also. Outdated or merchandise that isn't what it is advertised to be could potentially poison people, or cause bodily harm when it doesn't work like it's supposed to.
Simply stated auction sites, provide an anonymous marketing environment to sell both stolen and counterfeit goods.
“By hiding behind the anonymity of the Internet, they can make more money with less risk of getting caught than selling to a stranger on a street corner who might turn out to be a police officer. This bill would lift that cloak and help law enforcement put on-line criminals where they belong – behind bars,” according to Joe LaRocca, the National Retail Federations Vice President of Loss Prevention.
To address this problem, a federal bill (H.R. 6713, the E-Fencing Enforcement Act of 2008) is being introduced by Representative Bobby Scott, chairman of the House Judiciary Committee’s Subcommittee on Crime, Terrorism and Homeland Security.
The bill will require on-line auction operators to maintain information about high-volume sellers and provide the information to a person with "standing" once a police report is filed. The definition of a person of standing would be a law enforcement officer or a representative from a company, who has an interest in the merchandise being illegally sold on an auction site.
This is the second bill introduced recently to combat organized retail crime, which costs retailers anywhere from $15 to 30 billion a year. On July 15th, H.R. 6491, the Organized Retail Crime Act of 2008, was introduced by Representative Brad Ellsworth, a former county sheriff, along Representative Jim Jordan, as the lead co-sponsor. The bill establishes that unless auction site owners can show specific steps to prove goods being sold were not being obtained by theft or fraud, they could be viewed as "facilitating" the activity. This bill will also require site operators to cooperate with the police and organizations with a stake in stopping the activity. In certain instances, it will also allow merchants to initiate civil actions over stolen merchandise being sold on an auction site.
In the past, auction operators have been criticized for not effectively cooperating with companies and law enforcement when they made an inquiry into suspected criminal activity on their sites. It has also been established that smaller (individual) victims and merchants often receive little to no assistance after being victimized in an Internet auction deal.
E-fencing, phishing, counterfeit goods and the use of fraudulent financial instruments to buy merchandise from unsuspecting customers have all victimized countless people and organizations on auction sites.
Criminals often lure people to do their dirty work, also. Recruits are normally harvested off the Internet, sometimes from job sites, and offered work to reship stolen merchandise and or launder money from fraudulent transactions. Much of this activity involves sending money, or hot merchandise across an International border --making it extremely difficult to track.
A lot of criminal activity is facilitated on auction sites by what is known as phishing. Phishing is where an account owner is tricked into giving up their account details, either via social engineering, or more and more often, after downloading some malicious sofware. The stolen account details are then used to take-over the account and use it for illicit purposes.
In fact, eBay and PayPal accounts are frequently the most phished brands out there.
Phishing, normally facilitated by spam e-mails, is another ever-growing criminal activity on the Internet. Recent studies by the Anti Phishing Working Group show that it is becoming more automated and malicious software (crimeware) used to automatically steal information is becoming more prevalent.
There is little doubt that a lot of the criminal activity on auction sites is sophisticated and reeks of organized crime.
For anyone investigating fraud on an auction site, the only way to effectively do so, is to have access to information quickly and with as little red tape as possible. A lot of these crimes cross over borders quickly and by the time and investigator gets what they need, the trail is often pretty cold.
When auction site owners -- who suffer no financial liability and collect a lot of revenue in fees from this activity -- don't cooperate or move too slowly, it only ensures that criminals will be laughing all the way to the bank.
Even the government has had their stolen inventory sold on eBay and Craigslist. In April, the GAO issued a report that military items, including F-14 components, were being sold on auction sites. In August of last year, a U.S. Attorney was quoted as saying that stamps being stolen from self service vending machines with cloned payment cards were being sold on auction sites. At the time, I ran a simple search query and found some pretty good deals on stamps. As of today, these great deals still exist. Many of them are being sold below cost and the last I checked the Postal Service still offers credit. Why would someone sell stamps below cost?
In my opinion, both of the bills don't only serve the large merchants out there, but have the potential to protect everybody from fraud on auction sites. While both of these bills are being driven by the National Retail Federation, I see a lot of benefits to passing them for everyone concerned with fraud on auction sites.
I highly recommend that these other people, join in with the NRF and the Congressmen involved, and support getting these bills passed.
Wednesday, June 25, 2008
Retailers Honor Sleuths Who Smashed $100 Million Organized Retail Crime Ring
The National Retail Federation is recognizing a couple of individuals, both from law enforcement and within their own ranks, for their contributions in smashing a $100 million organized retail crime ring. These crime fighters are being honored at the NRF Loss Prevention Conference & EXPO in Orlando, Florida.
The two being honored are Detective Ostojic, of the Polk Country Sheriff's Department, and Ron Averette from the loss prevention department at Publix Supermarkets. In June 2007, the two began comparing notes on a group that was stealing large amounts of merchandise. Subsequently, Detective Ostojic was able to tie in cases at other retailers and Averette (along with Ostojic) presented the pattern of activity to the Florida Department of Law Enforcement and Florida State Attorney's Office. This led to a task force being formed under the leadership of Special Agent Telly Sands from the Florida Department of Law Enforcement.The result of the task force's efforts were that 18 people were identified as being involved in the ring and subsequently arrested.
The FBI estimates that organized retail crime costs retailers an estimated $30 billion dollars a year. To date, this is the largest documented case where organized retail crime was identified as being the cause.
These rings use flea markets, Internet auction sites like eBay and Craigslist, rogue e-commerce sites, and even seedy merchants to sell their goods. Some retail loss prevention departments have dedicated personnel to investigate stolen merchandise on auction sites.
In this case, a lot of the stolen merchandise were health and beauty aids. Some of these products have expiration dates, which might lead to health and safety concerns for the end user.
Mark Albright wrote an article about this case in the Saint Petersburg Times, where he mentioned specific brands the group deemed desirable for resale. By doing a search on eBay, I found a wide selection of Gillette razor blades, Prilosec, Crest WhiteStrips, and Oil of Olay available on the site. Please note that I have no way of telling if these items were the result of organized retail crime or obtained legitimately. I do know that large companies generally frown on having their products sold on auction sites and I saw some extremely good prices listed for these products.
According to the article in the Saint Petersburg Times some of the shoplifters (boosters) involved have rap sheets (criminal records) ranging from sex crimes to armed robbery and attempted murder.
A recent survey indicated that retailers are seeing an increase in organized retail crime activity. The cost of this type of crime is eventually added into the cost of the product being stolen, which means we all end up paying for it.
This activity has been known to run smaller businesses bankrupt. Even at larger retail organizations, out of control losses often dictate that operating budgets need to be trimmed. Since payroll is often the largest operating cost in an organization, this leads to reductions in hours and positions to keep a company afloat. Simply stated, activity like this can cost people their jobs.
Legislation has been passed in many states and more is forthcoming to make organized retail crime penalties stiffer.
Sunday, June 08, 2008
NRF Survey shows Organized Retail Crime activity is growing!
Also mentioned in the survey are shady e-commerce sites being put up on the Internet to fence the proceeeds of ORC.
In case you've never heard the term, Organized Retail Crime, here is a good description of the activity:
Organized retail crime (ORC) refers to groups, gangs and sometimes individuals who are engaged in illegally obtaining retail merchandise through both theft and fraud in substantial quantities as part of a commercial enterprise. These crime rings generally consist of “boosters” who methodically steal merchandise from retail stores and fence operators who convert the product to cash or drugs, as part of the criminal enterprise. Some of the more sophisticated criminals engage in changing the UPC bar codes on merchandise so they ring up differently at checkout, this is commonly called “ticket switching.” Others use stolen or cloned credit cards to obtain merchandise or produce fictitious receipts to return products back to retail outlets.
The report acknowledges that these groups are using cloned credit cards to steal merchandise and or get the necessary receipts to refund the merchandise for cash.
In the wake of the TJX data breach, where up to 94 million personal and financial records were hacked, a group was caught in Florida using data from the breach (cloned cards) to buy a reported $8 million worth of gift cards.
Please note that TJX is hardly the only retailer, or financial services institution that has had personal and financial records hacked from their systems in recent history. Attrition.org does a good job of recording the known breaches on their Data Loss Database - Open Source .
Although not addressed in the current report, I suspect the use of fraudulent checks are used to obtain merchandise and receipts, also.
This could be fueled by another organized crime activity. Portable technology has made the counterfeiting of identification documents another growing trend. Over the past two years or so, I've had the pleasure of being able to speak with Suad Leija and her husband about this organized criminal activity on a semi-regular basis. Suad, the step-daughter of one of the top players in this game was recruited in an intelligence operation and eventually exposed a cartel operating throughout North America to the government. Prosecution of members of the cartel is ongoing in this case and Suad is currently working on a book.
These documents, which are available throughout the United States, can be easily used to support both check and refund fraud by using names that get past the data bases designed to protect retailers from these types of fraudulent activity.
Portable technology is also being used to clone payment cards and some of it is easily found on auction, or shady e-commerce sites set up to sell these devices. As of this writing, I was easily able to find credit card encoders for sale on eBay. A site called HackersHomePage.com provides an array of devices that could be used to steal and produce payment (credit/debit) cards. They also provide tools to make counterfeit checks and even, paper for fake prescriptions. They do have a "disclaimer" stating that none of their products are to be used for illegal purposes, but it is pretty obvious someone could.
There is no doubt that there is a lot of technology that is enabling a lot of criminal activity out there!
NRF's Vice President of Loss Prevention, Joe LaRocca, made what I consider a sage comment on this activity:
“Law enforcement and retailers alike are fed up with organized retail crime rings and are stepping up efforts to stop them in their tracks,” said NRF Vice President of Loss Prevention Joseph LaRocca. “The brazen and unethical behavior of organized retail crime suspects results in possible health risks for consumers, adds unnecessary fees to consumers’ purchases and funds criminal enterprises, including the mob and terrorist organizations around the world.”
When I stated that this activity hurts all of us, the reason is that retailers have to make up the $30 billion they are losing to this activity somewhere. This normally equates to higher prices, or in extreme circumstances (especially in tight economic times) cutting payroll. Simply stated, people might be losing their jobs because of this activity.
So far as health risks, the report sums up the obvious risks rather well:
For example, criminals may not keep stolen merchandise in a temperature-controlled environment, so merchandise like baby formula and over-the-counter medicines can easily spoil. When criminals sell these items online through third party auction sites consumers are left with no way to guarantee they are getting safe and reliable healthy and beauty products.
I decided to see if I could find baby formula on eBay. As you can see - there seems to be a lot of it for sale on the site at discounted prices. At the time I checked 26 pages of it were for sale on the site.
Actual cases in the report that support how organized this activity has become are a $60-$100 million dollar case in Florida involving health, beauty, cosmetic products and over-the-counter medicines. Another case mentioned involved a high ranking member Gambino Crime Family and a sophisticated ticket/UPC switching case and extortion. In this case, a planted employee was making up the labels and providing temporary credit cards to move the merchandise through point-of-sale systems.
Recent initiatives to combat Organized Retail Crime include launching LerpNET, which is a crime database available to both retailers and law enforcement. Also highlighted was legislation against ORC throughout the country to "reduce the rewards and increase the risk" to the groups involved in it. Several States have already passed this legislation and more are considering it.
Full 2008 ORC Survey, here.
Friday, April 11, 2008
eBay/Craigslist praised by Congressman for efforts to curb sales of stolen military equipment on their sites (?)
Even more interesting were the results of narrowly focused hearings (my opinion) on this matter in Washington, which can be seen at the bottom of this post. The reason I believe they were "narrowly focused" is because there is no shortage of fraud, phishing and financial misdeeds on auction sites.
Of course, there is also no shortage of ordinary citizens and businesses that have been taken to the cleaners on an auction site. Stolen government items are only a small part of the overall problem.
From the GAO report:
GAO found numerous defense-related items for sale to the highest bidder on eBay and Craigslist. A review of policies and procedures for these Web sites determined that there are few safeguards to prevent the sale of sensitive and stolen defense-related items using the sites. During the period of investigation, GAO undercover investigators purchased a dozen sensitive items on eBay and Craigslist to demonstrate how easy it was to obtain them. Many of these items were stolen from the U.S. military. According to the Department of Defense (DOD), it considers the sensitive items GAO purchased to be on the U.S. Munitions List, meaning that there are restrictions on their overseas sales. However, if investigators had been members of the general public, there is a risk that they could have illegally resold these items to an international broker or transferred them overseas.Apparently, body armor, MRE (meals ready to eat), uniforms, night vision goggles, NBC (Nuclear Biological Chemical) equipment and even F-14 components were some of the items purchased on eBay and Craiglist by undercover investigators.
The obvious concern would be terrorists, or other not very friendly people getting their hands on some of this stuff.
Given the organized effort on a lot of auction sites to fence stolen merchandise via some pretty sophisticated methods, it's not surprising that the GAO found military equipment for sale on the sites. Many have speculated that these sites are used as a means of fencing the proceeds of what is known as organized retail crime. Of course, less organized criminals obviously sell their goods on auction sites, also.
Organized retail crime obtains their goods by a variety of methods from common theft to using stolen financial instruments. A lot of stolen financial instruments are used to purchase items on auction sites and e-commerce sites. Of course, they are used in more traditional store settings for the same purpose, also.
On eBay, account credentials and payment accounts (PayPal) are phished all the time, enabling an additional layer of anonymity to the schemes. In fact, over the years, many experts have stated that eBay and PayPal are the two most phished brands out there.
One thing not mentioned in the report is that people don't always get what was advertised on these sites. It isn't inconceivable that a complete fighter jet might be put up for sale, paid for and in the end a toy, or "nothing at all" is received by the buyer.
Trust me, this wouldn't be the first time something like this has happened on an auction site.
A lot of counterfeit (knock-off) merchandise is sold on the sites, advertised as the "real thing," also.
Our leaders in Congress reacted by calling Jim Buckmaster (Craigslist) and Tod Cohen (eBay) in to speak with them on the matter.
Anne Broache (CNet) writes:
By calling Craigslist CEO Jim Buckmaster and eBay government relations chief Tod Cohen to Washington for the hearing, the subcommittee seemed to be preparing to place those executives in the hot seat. But the tone of that questioning was actually quite cordial. At the end of the panel, Tierney even praised the companies for "trying very hard" to keep sensitive military goods off their sites and acknowledged the rules of the road aren't the most clear.
Based on her article, which reports that Buckmaster and Cohen were treated with "kid gloves" during the session, my prediction is that little is going to be done to regulate the sale of stolen goods on auction sites as a result of this.
Meanwhile, everyone running for office is saying they will be the one doing something about the problem of special interests in Washington.
On a closing note, I want to commend the GAO for their efforts to expose a problem. I'm just saying it's a shame that no one listened to what they were saying, very carefully.
HTML version of the GAO report, here.
PDF version, here.
Monday, December 10, 2007
SIRAS offers guarantee that it will reduce retail crime
SIRAS tracks an inanimate object (merchandise) instead of a customer's personal information.
Now they are now offering a "guarantee" the technology will add dollars to a organization's bottom line by reducing fraudulent returns.
In their own words from the press release regarding this matter:
Electronic Product Registration, is putting its money where its mouth is with a unique Return On Investment (ROI) Guarantee for any company using SIRAS’s product registration and Smart Return service to manage their product returns and warrantees. The program, designed to eliminate any risk for companies interested in implementing SIRAS’s technology, guarantees that over the course of a year companies will save more money through deflected product returns than it spends in transaction fees.
In case you haven't had to refund any merchandise in a long time, most retailers require you to give them your personal statistics before they approve your return.
This information is all maintained in a database, where it might be exposed to a hacker, or probably more frequently, dishonest employee. Information is worth a lot of money to anyone, who knows where to sell it.
A dishonest Certegy employee recently got caught selling 8.5 million people's information to an undisclosed data-broker. Since the mysterious data-broker still hasn't been identified -- despite being listed as a co-conspirator in court filings -- we really aren't sure where these records went?
Certegy provides check verification services for a lot of merchants.
Personal and financial information is marketed in carder forums (chat rooms) on the Internet. Anonymous payment methods, such as wire transfers, PayPal and eGold add to the problem. They make it relatively easy to buy and sell stolen information.
It also isn't unknown for criminal organizations to plant, or recruit employees to steal information from within an organization.
The press release quotes Peter Junger (SIRAS CEO) as saying, "And in all cases, regardless of ROI, clients retain all of the valuable POS data collected."
This POS data also serves another important purpose. If the merchandise is found in a fencing operation, or on an auction site, it can still be tracked to the point-of-compromise.
This opens up opportunities to recover stolen merchandise and makes it more dangerous for the criminals fencing it.
Mesa Police Department tested these capabilities with SIRAS and FOX News did a story on it, which can be seen, here.
The technology, when deployed properly with a point-of-sale system can also identity fraudulent means of tender used to purchase merchandise.
SIRAS technology can be deployed by a merchant, or at the factory, itself.
They already makes their database available to law enforcement free-of-charge.
With all the identity theft and counterfeit ID available, using SIRAS reduces the possibility that an innocent customer will be wrongfully identified as an "undesirable" in a refund database.
Saying that, who knows how much of the information in these databases is one-hundred percent accurate anymore? With retail crime becoming more and more organized, the possibility exists that it is NOT.
One of the systems targeted in the TJX data-breach was their refund database. The information in this database is probably worth more than simple financial information because it contains the elements necessary to assume a person's identity.
It's relatively easy to shut down a bank account, or credit card number. Once a person's statistics are compromised, they can be at risk of identity theft for a long time.
Data breaches are becoming more expensive. TJX claimed a loss of $118 million in their second quarter earnings. Estimates vary widely on exactly how expensive data-breaches will become, but everyone agrees the cost of them is going up.
SIRAS seems more effective in resolving property crimes because it tracks the property, itself. It also protects customer privacy and protects a merchant from becoming the victim of a data-breach.
I doubt that SIRAS would make this guarantee if they weren't absolutely certain of the results. If they were wrong, I doubt they would be in business very long.
Press release from SIRAS, here.
Thursday, November 22, 2007
Gift card due diligence 101
Retail criminals use fraudulent credit cards, debit cards and checks to buy large amounts of gift cards. Since a lot of sites exist, where anyone can sell these cards, criminals can turn them into cash fairly easily.
Shortly after the much talked about TJX data breach -- where 90 million personal and financial records were compromised -- a group was caught in Florida buying $8 million in gift cards using credit card numbers stolen in the data breach.
In another method to commit fraud, cards are picked up off a display and taken to a more private location in the store. The numbers and PINs are then recorded -- either with a portable card skimmer, or written down by hand. The people doing this then simply call in to check the value of a particular card, and use them when they discover they've been activated.
I've seen articles written on this that recommend buying cards from behind a counter. While this may be safer, we have to remember that most retailers have a problem with dishonest employees. This is more prevalent during the holiday season, when retailers hire a lot of temporary help.
In wouldn't be too far fetched to have a dishonest employee skim the details of these cards and drain them when they are activated.
There have also been reports of employees stealing credit card numbers and then using them to activate gift cards.
A couple days ago, TwinCities.com did a story about a Target employee stealing $19,500 in gift cards.
Since gift cards can be purchased on the Internet, fraudulent payment devices are used to purchase them on websites, also.
I would be extremely wary of buying any gift card on an auction, or gift card site. These sites rarely offer very much protection for people using them. It is a lot safer to visit the site that issues the cards, if you prefer shopping on the Internet.
Simply stated, a gift card purchased on a third-party website might not work, might not have the advertised value, or you might never receive what you bought.
I'm not saying not to buy gift cards. Being a lazy shopper, I buy them myself. Saying that, here are some tips to make sure you are getting what you pay for:
Make sure you buy them from a reputable retailer.
Keep your receipt and if possible, use a credit card to purchase them. Credit cards offer a little extra protection if there is a problem.
Inspect any card you buy for signs that it has been tampered. If the card is in a cardboard holder remove it and inspect it, the PIN should be protected up with a plastic coating that has to be scratched off.
Please note that if you work at a reputable retailer be wary of people returning gift cards. Stolen blank cards are often replaced for the cards that were previously activated.
I haven't seen anything come out about gift card fraud from the National Retail Federation (NRF) this year yet, but here is an interesting press release they released on the matter last year.
Sunday, November 04, 2007
eBay shoppers crack QVC fraud case
As reported by Dan Goodin:
A woman has pleaded guilty to fleecing the QVC home-shopping networking of more than $412,000 by exploiting a gaping hole in its website that allowed her to receive merchandise without paying for them.I wonder if QVC offered a reward to the two eBay shoppers, who discovered this flaw in their system?
Quantina Moore-Perry ordered handbags, jewelry and electronics and then immediately canceled the transactions. The flaw allowed the North Carolina woman to take delivery of more than 1,800 items without being billed. Moore-Perry would then sell the booty on eBay, according to the Associated Press, which cited authorities.
This would also make me wonder if this woman was the only one who has defrauded QVC in this manner?
There is a lot of controversy surrounding the sale of stolen merchandise on eBay and other auction sites. I've heard that some companies now have a dedicated person in their security departments to watch these sites for stolen merchandise.
Register story, here.
For other posts, I've written concerning stolen merchandise on auction sites, click here.
Saturday, September 08, 2007
SIRAS PI - tracking theft to the source

Graphic demonstration of anti-theft technology courtesy of SIRAS.com.
Criminals, who steal goods, whether with bogus financial instruments, or by more physical means might be in for a little surprise if the merchandise is protected by SIRAS PI.
Last week, SIRAS made this announcement in a press release:
SIRAS.com, the pioneer in Point-Of-Sale Electronic Product Registration used by leading manufacturers and retailers, has announced the nationwide launch of SIRAS P.I., a groundbreaking initiative to aid law enforcement officials in determining whether products they recover are, in fact, stolen, and if so, from where. Piloted by the Mesa, Arizona Police Department, SIRAS’s P.I. (Product Information) Database has already proven to be effective in helping law enforcement officials identify stolen items, report suspicious items, and apprehend and convict thieves. The database will be available, free of charge, to police and law enforcement agencies nationwide.
The way SIRAS works is simple, but effective. It tracks a product by recording the UPC (Universal Product Code) and the product serial number. SIRAS has the capability to determine where merchandise was stolen, whether from a merchant, manufacturer, or individual.
Earlier this year, SIRAS did some testing that revealed a substantial reduction in TV and MP3 player losses on products, where their technology was being used.
If deployed properly at the merchant level -- it could also determine how an item was purchased, and whether or not -- the method of payment used was legitimate. In theory, a merchant could also use the technology to impact credit card chargeback and fraud check losses.
I say "deployed properly" and "in theory" because the information to accomplish this (sales data) belongs to the company using SIRAS technology. Because of this, the capability to track sales information would have to be implemented inside the company. At most larger companies, this information is already tracked and analyzed to prevent and detect dishonest activity.
For years, most high-theft (shrink) merchandise has been secured so a thief can't merely pick it up from a shelf. When high-theft merchandise that was secured is stolen, it's normally because of one of two reasons. It was purchased with a bogus financial instrument, or an insider was involved in the theft.
Other reasons for secured merchandise being stolen might be a theft, directly from the manufacturer, or a theft during the shipping (transport) process. In these instances, if the merchandise was registered at the manufacturer, SIRAS can identify the point of compromise, also.
Technology has made it a lot easier for criminals to obtain and use fraudulent forms of payment. Information being compromised (data breaches) and anonymous places to communicate like Internet chat rooms, have given a lot of common criminals access to bogus financial instruments.
Along with the increased availability of fraudulent forms of payment, obtaining counterfeit identification documents has become fairly easy, and the identity used on them normally belongs to someone else. This has made it easy for a lot of retail criminals to operate as someone else.
Because of these new trends, current systems that record personal information to prevent fraud are becoming less effective than they use to be. I often wonder (no one probably really knows) how much of the information contained in them is incorrect.
In the recent data breach at TJX, one of the systems compromised was their refund database. Stories have circulated recently about the wrong people being pegged as frequent refunders, or bad check writers after their identities were stolen.
Neither one of these situations fosters good will, or trust with customers. Besides that, data breaches are becoming costly. The last I heard TJX has spent approximately $256 million dealing with the breach. With pending litigation, the cost is liable to keep going up.
With SIRAS, using personal information isn't necessary to determine, whether or not, a return is legitimate. SIRAS already has proven to be highly effective in reducing refund fraud without asking for one item of personal information.
An example of how some of the TJX data was used in a retail theft scenario can be seen, here.
Given that criminals that steal merchandise want to turn it into money, two methods are normally used. They either refund it somewhere, or fence it. Auction sites provide an easy and when combined with account-takeover activity (anonymous) venue for criminals to fence merchandise.
In the auction world, seller accounts are taken over all the time. This normally occurs when seller accounts are compromised by a phenomenon known as phishing. Phishing occurs when a person is tricked into giving up their access information after receiving a spam e-mail.
Compromised seller accounts are sold on the Internet the same way financial information is, and there is a trend in DIY (do-it-yourself) phishing kits being sold that enable non-technical criminals to get into the game.
eBay and PayPal are two of the most heavily phished brands. Once these accounts are compromised (taken over), they are used by criminals to fence merchandise and launder the monetary proceeds of their illicit sales.
Another growing trend related to phishing is when malware, also sometimes known as crimeware is used to steal information. The difference here is information is stolen from systems automatically (normally by keylogging software) and social engineering (trickery) is no longer necessary to get people to give up information.
Malware is often picked up by a computer system by clicking on a spam e-mail link, or by visiting a website designed to inject the software on a system. PC World recently did one of the many stories floating around about malware being sold on the Internet in the form of DIY kits.
In the story they wrote:
The global market for criminal malware now operates like a supermarket, complete with special offers and volume discounts, a security company has discovered.
Here again, this capability enables not very technically inclined criminals to get into the game. This has become a growing problem and I expect it to get worse before it gets better.
With the availability of all this personal and financial information, being sold on an economy of scale, current fraud protection systems are routinely being compromised by a lot of criminals.
There is an old saying in the investigations world, which is if you want to solve a crime, the easiest way is to follow the money.
SIRAS takes this one step further by tracking both the merchandise and can track the money ( if programmed to do so by the user). When you do this, the odds are far greater that the true culprit will be identified. They are normally associated with either the money, and or the merchandise.
Since the technology records both physical and UPC information, the database can determine exactly where the merchandise was compromised (stolen). Given that many merchants use digital video systems -- which are capable of storing video footage for a long time, it's also possible to obtain video evidence of the original transaction -- when sales information has been programmed to tie into the technology.
SIRAS has been used by select manufacturers and merchants for several years now -- however a new initiative, SIRAS PI, which was tested with Mesa PD -- makes the database available to law enforcement agencies free of charge.
Law enforcement can access the database either via the Internet, or by telephone. They can also add items to the database when they are reported stolen. If someone later tries to refund the merchandise at a participating retailer, the transaction can be automatically flagged.
Although a lot of fencing now occurs on the Internet, the technology is equally as effective in investigating more traditional property crimes, also. The bottom line is once merchandise is discovered, it can be tracked by SIRAS, if the item has been registered.
Recently, Chris Hansen (MSNBC), did a story about iPod theft. When Apple was approached about tracking the merchandise using Apple's registration database, they decided not to cooperate with MSNBC.
Undaunted by this, MSNBC purchased a bunch of iPods and engineered the registration disc to send them the information when the iPod was registered. They then left the iPods (new in the box) unattended, let them get stolen and tracked them to the crooks once the iPod was registered.
Chris Hansen made an excellent point on how databases can track stolen merchandise -- but in this instance, brand new iPods had to be left in public places to be stolen -- then registered to make the point.
If Apple used SIRAS technology to protect their merchandise -- it would have already been traceable, even if it was stolen from an individual -- who didn't provide the thief with the registration disc. It also would eliminate privacy concerns, which might be why Apple didn't want to cooperate with the MSNBC investigation?
When registering any product, a lot of personal information is normally asked for.
In any event, most criminals of the smarter variety aren't going to provide their personal information in the registration process. Most of them shy away from doing things, which might get them caught.
It would be interesting to have MSNBC, or another investigative news source do the same story with merchandise protected by SIRAS. The story might expose more than people, who stole because of an almost "too good to be true" opportunity was provided to them.
MSNBC iJacking story, here.
This brings up another potential benefit to this technology. Expensive portable electronics and other expensive toys like mountain bikes are stolen from the people who buy them (customers) all the time. Using SIRAS technology might even be a selling point that instills customer trust in the product they are purchasing.
This technology has prevention/investigation applications for corporations, law enforcement agencies and individuals, alike. It also doesn't require using people's personal information, which isn't as effective as it used to be, and is becoming more unpopular all the time.
In my opinion, this technology has the ability to make it a lot harder to get away with stealing merchandise and converting it into money.
Of course, the more it is used, the more effective it will become. Databases have a tendency to do this, or become more useful as they contain more information.
There are a lot of anti-theft/fraud technologies that claim to prevent theft/fraud. Very few of them also claim to be able to go after and hold the criminals committing the fraud/theft personally accountable.
The last I heard, most criminals still fear getting caught!
If you would like more information on the organized trade in counterfeit identification documents, the story of Suad Leija can be seen, here.
Suad's story has been covered extensively in the media, including by Lou Dobbs. Currently, she is writing a book and I keep in touch with her occasionally.
More information about bogus financial instruments can be seen, here and here.
A chronology of data breaches is compiled by the Privacy Rights Clearinghouse, here.
The best source on phishing is the Anti-Phishing Working Group and if you are interested in learning even more about phishing and want to see some totally fake banking sites, Artists Against 419 is another good place to visit.
Last, but not least, if you are interested in learning more about SIRAS PI, you can do so by visiting their site, here.
Sunday, July 22, 2007
LA Gangs take a vacation in Hawaii using funny (counterfeit) money
Looks like some of them have gone West (Hawaii) to enjoy a little vacation financed with "funny money."
The HawaiiChannel.com is reporting:
Thousands of dollars worth of counterfeit $100 bills are flowing into Hawaii, most likely from Los Angeles-based gangs, according to Secret Service officials.
For the last week or so, $2,000 to $2,500 a day in counterfeit $100 bills have been passed at retail stores in Waikiki and across the islands, the Secret Service said.
Some high-end Hawaii retailers are taking a hit.
Apparently, the members of the Bloods and Crips involved in this (didn't know they were hanging out together) sometimes buy merchandise and then refund it a short while later. Refund fraud is a common way criminals launder money, or turn it into disposable income.
According to the article, counterfeit (funny) money is also being passed by members of the military coming back from the Middle East.
HawaiiNewsChannel.com article, here. There is a pretty good video on how to detect counterfeit money to the left of the article.
The article confirms what I've seen a lot of in the past couple of years, which is that a lot of the counterfeit money in circulation are five dollar bills washed into hundred bills. Because of this, the counterfeit detection pens, which most merchants use don't work.
The best way to detect them is to hold them up to the light and if the hologram is Abraham Lincoln instead of Benjamin Franklin, it is a counterfeit. The embedded strips will also state that they are five dollar bills, if they are counterfeit.
If you are in the money business, I recommend teaching your employees how to visually inspect money. Counterfeit detection devices are not 100 percent reliable.
The Money Factory (government site) has a lot of good information on how to detect counterfeit money, here.
The United States Secret Service also has a page on their site with a lot of information, here.
Tuesday, June 26, 2007
RFID sniffing could be used by spies and criminals to commit all kinds of dastardly deeds!
Apparently, truckers will be particularly vulnerable to being "sniffed" (compromised). Of course, if you use a little imagination, sniffing RFID might put more than "truckers" at risk, also.
From the story in Dark Reading:
That means your competitor could use this information for intelligence purposes. "He could get an idea of what you are shipping and how much, and how often," Perrymon says, adding that an attacker could also write to those tags, either disabling or changing them if you don't apply the proper authorization and passwords to your EPC system. That's PacketFocus's next step in its research.
And sniffing the truck's payload could also provide criminals with intelligence they wouldn’t otherwise be able to get very easily, thus helping them target their holdups or other heists, he says. "Unless they had a lot of inside information, they don't have enough information to rob that truck. Now they can scan it if it's not secure -- they don't want to rob that toilet paper truck, but if it's got plasma TVs with surround sound, [that's their] target."
RFID has been pushed by retailers, such as Walmart, and the military (not mentioned in the Dark Reading article). The Department of Defense now uses RFID to monitor it's supply management system.
Stealing shipments of plasma TVs is one thing, but on a personal level, I'm a little more worried about how some of this technology might be used by those with more sinister intentions than stealing high-tech merchandise.
So far as the passwords mentioned in the article -- easily compromised by the Packet Focus folks, they can be made more secure -- but passwords are hacked by software and more social methods, fairly frequently.
All it takes is one dishonest person with access to one, or even a honest person, who is tricked into giving up one to compromise an entire system.
Hacking for Dummies has an interesting write-up on how passwords are hacked, here.
Besides that, the bad guys are always coming up with new exploits to defeat security fixes.
Interestingly enough, according to Wikipedia, RFID's predecessor was invented by a Soviet inventor as a tool to commit espionage. It also was used the World War II era for a lot of military applications.
Perhaps, in this case, history (or the original intent) should give us a little perspective on RFID?
In the recent past, government experts have seen China show an interest in stealing (hacking) logistics (supply) information. Here is a post, I wrote about that:
How Dangerous is China
Dark Reading's interesting article, here.
I've written a few posts about RFID and it's potential abuses, which can be seen, here.
Dark Reading got it's information for the article from PacketFocus Security Solutions, which is a company that performs what is known as "ethical hacking" for the public at large. Ethical hacking is where good guys test vulnerabilities in technology to stay ahead of the bad guys.
There might very well be some useful applications for RFID, but we need to slow down, and consider the safety implications before continuing to have this technology take over our daily lives.
It's not worth the money a very few people are making off it!
Saturday, June 16, 2007
Will counterfeit Visa Traveler Cheques be the latest bogus financial instrument spread in Internet Scams?
(Photo courtesy of Flickr)In the past few years, counterfeit U.S. Postal Money Orders, MoneyGram Money Orders, and American Express Gift Cheques have all been circulated by Internet fraud activity.
If history repeats itself, we will see counterfeit Visa Travelers Cheques show up outside the United States, also.
These instruments have been passed in a lot of work-at-home (job) scams. They are also passed in secret shopper, romance, lottery and auction scams.
These advance fee (419) type scams all have a common theme. A lure (scam) -- which plays on greed is offered to entice someone into cashing these items -- and wiring the money back to the fraudster behind the scheme.
The lure (scam) is always too good to be true and makes no sense.
Since it is against the law to pass a counterfeit financial instrument, people are sometimes arrested when they present these items. Even if they aren't arrested, they are held liable, when the fraud is discovered.
Unfortunately, banks often give credit to their customers on these items. Tellers have even told their customers the items are legitimate, which doesn't make any difference (for the customer) when they return. Of course, the bank isn't liable for any of this.
These items are also being presented to merchants. Retail criminals use them to purchase items, get the balance in cash, then refund the merchandise. Of course, if they are unable to refund the items, they will probably try to get gift cards or fence the merchandise. There is a lot of stolen merchandise being fenced (pretty easily) on Internet auction sites.
Intelligence indicates these many of these items are being printed overseas, then distributed in bulk, worldwide. Once received in bulk, they are broken down and distributed to the criminals, who then use them in the manners listed above.
Visa recommends that you do the following to verify if one of the Travelers Cheques are real:
Can you see a watermark in the cheque?
Can you see the holographic thread embedded in the cheque?
Is the customer present?
Have the cheques been countersigned in your presence?
Does the original signature match the countersignature?
Has valid identification been presented and the details recorded along with the customer name on the back of the cheques?
Here are some of my previous posts on counterfeit instruments circulating via the Internet:
Counterfeit MoneyGram Money Orders being passed via Internet Scams
Counterfeit Cashier's Checks Fuel Internet Crime
American Express Gift Cheques Being Circulated in Internet Scams
Counterfeit Postal Money Orders Showing Up in IScams Again
Friday, April 06, 2007
Retailers and the FBI band together to fight organized crime
The retail industry realizes this and in partnership with the FBI is launching a secure tool that businesses and law enforcement can use to communicate criminal activity with each other. A simple, but powerful principle.
Here is the information on this new tool from the NRF site:
In response to an alarming rise in organized retail crime, the National Retail Federation and the Retail Industry Leaders Association, in collaboration with the Federal Bureau of Investigation, have teamed up to launch the Law Enforcement Retail Partnership Network (LERPnet), a secure national database that will allow retailers to share information through its unique web-based design. With LERPnet, retailers and law enforcement will be able to fight back against illegal activity including organized retail crime, burglaries, robberies, counterfeiting, and online auction fraud. The database will launch on April 9, 2007.
Full NRF press release, here.
More information on this tool can be seen by linking, here.
The Washington Post also did a good story covering this.
A lot of other industries and law enforcement agencies should follow this example. Developing better tools to communicate could help resolve the current epidemic, currently being seen in all types of financial crimes.
There is some evidence that the bad guys communicate with each other, regularly (carder forums). The good guys should do no less!
To close, Joe LaRocca, NRF vice president of loss prevention is saying:
“With this system, retailers are banding together with law enforcement to send a clear message to criminals: We will not tolerate your behavior and we will stop you.”
Thursday, March 22, 2007
SIRAS – Smart technology that protects profit and privacy

At most merchants today, refunds are tracked with personal information. While this was effective 10 years ago, the information in the current databases might not be as accurate as it once was.
Personal and financial information is stolen and sold in a lot of places, most notably over the Internet. A perfect example is the recent compromise of consumer data at TJX stores. This information is turned into fraudulent identification and financial instruments and sold to criminals.
It is likely that criminals can assume multiple identities, using other people’s information to refund merchandise. In fact, payment (credit/debit) card and bad check fraudsters already demonstrate this ability on a daily basis.
With the negative publicity surrounding data breaches and identity theft, honest customers are nervous when asked to surrender their personal details. Recently, privacy groups and Senator Chuck Schumer have been openly critical of current systems, which gather personal information.
The SIRAS system captures the UPC and serial number of a product at the point-of-sale and creates an electronic receipt. This enables a merchant to determine exactly when and where it was sold AND how it was paid for.
SIRAS can tell when the merchandise was never purchased (stolen), or if it was purchased at another retailer. It also can identify counterfeit merchandise, price switching and altered/counterfeit receipts. Because it ties into a sales transaction, the system could also identify fraudulent forms of payment used to purchase the merchandise, or if the item has been a chargeback issue.
SIRAS makes it pretty hard do a fraudulent refund. Getting series of numbers to match can be extremely difficult, if not almost, impossible.
The data is compiled into customized reporting tools, which can be leveraged to determine risk factors when merchandising products. These tools also have extremely useful applications from an intelligence (analysis) and investigation perspective.
Besides organized retail crime, the largest losses suffered by merchants are caused by internal theft. Fraudulent refunds, “sweetheart returns,” enable dishonest employees to steal cash, or issue credit to payment cards. Like their external counterpart, internal criminals now have to use personal information to prompt a point-of-sale system to issue a refund. Again, this information (which might not be accurate) corrupts a lot of the current databases.
Dishonest employees are going to have a hard time being able to match UPC/serial number to a legitimate sale. This will prevent employees from attempting to commit refund fraud, and should they decide to do so, the custom reporting tools (when used properly) would identify the culprits, with ease.
SIRAS can track and identify retail theft a long way past the refund counter. With its unique ability to track merchandise to a sale, SIRAS can be used to identify merchandise sold in fencing operations (and more likely) via Internet auctions.
In fact, SIRAS has been used to help prove criminal cases, or to obtain search warrants by law enforcement.
The system can also be used to identify counterfeit goods, wherever they might be appear for sale.
Other benefits include being able to better manager warranty programs and in the case of call centers (crucial in e-commerce), it provides their employees with direct access to the original purchase information.
An effective merchandising application, I noted was the ability (via analysis) to identify products that have a high rate of being defect rate, or that aren’t as easy to use, as advertised.
SIRAS has applications that go far beyond fraud at the refund counter.
The system is easily incorporated with patented technology into current point of sale systems and employee training is minimal. Being that it replaces many labor intensive tasks, payroll can be better spent in other areas.
SIRAS applications are beneficial not only to manufacturers and traditional retailers, but the system is equally effective in e-commerce applications.
This technology is already being used by several major retailers and manufacturers. You can view a list of them on their website (listed below).
With privacy becoming a bigger issue all the time, SIRAS provides a smart way to protect assets and not expose customer information. SIRAS makes it harder to commit fraud in a retail environment, while making it easier (customer friendly) to return an item without a paper receipt.
More information about SIRAS and who uses their services can be viewed at:
Wednesday, March 21, 2007
(Update: TJX data confirmed as used in Florida Case) Is the information being sold in carder forums being used in organized retail crime?
Here is an example of how this stolen information might be used by criminals. I happened to run across a good example of this in the News-Press (Southwest Florida):
Six people suspected of using stolen credit cards to purchase an estimated $8 million in WAL-MART and Sam’s Club gift cards were arrested in by Gainesville Police in a four-month ongoing investigation, according to a report released Monday by the Florida Department of Law Enforcement.The bogus credit-cards were being used to purchase high-end electronic merchandise and gift cards.
News-Press story, here.
*Update (3/23/07): An article from InfoWorld is stating that the data used in this scheme is part of the TJX data breach. InfoWorld story, here. It still isn't clear how the culprits obtained the information, or how they, had the information made into counterfeit instruments.
Symantec's report covers all the different methods information is being stolen. One of the more common methods is referred to as phishing. This normally happens when a person clicks on a link from a spam e-mail sending them to a fake site (requesting personal information).
Note that sometimes the fake sites only ask for your personal and financial details (referred to as social-engineering), but more and more, computers are infected with malware when someone is tricked into clicking on a link they shouldn't have.
Malware records people's personal details (automatically) and sends them back to the scammers.
Symantec's press release on their report, here.
If you are wondering why the retail crooks were buying gift cards. Here is a previous post, I did on that subject:
Why Buying Gift Cards on Auction Sites isn't a Good Idea
Sunday, March 04, 2007
Organized retail criminals sell their ill-gotten proceeds in many places
Some estimates (RILA) reflect that this could be a $34 billion a year problem.
I've seen a lot of recent stories about merchandise being fenced on auction sites. Although, this is a big problem, stolen goods are fenced in other places, also.
WKYC news (Ohio) is reporting that 19 homes and business were recently raided, illustrating how organized some of this activity can be.
Very interesting video, here.
The Washington Post, did an interesting article about organized retail crime in 2005, here.
It noted that federal law enforcement is getting involved in the prosecution of these cases, because of their impact, and (probably) the fact that they cross state lines, frequently.
RILA (The Retail Industry Leaders Association) proposed changes to Congress to deal with the problem, here.
Of note, they quote the FBI as saying that organized retail crime is funding terrorist organizations.
Another problem (the FBI calls out) is when outdated medicine and items, such as baby formula are repackaged and sold as new.
This could pose significant health risks to those, who purchase these stolen items.
Besides the fact that we all pay for this with our hard earned money (higher prices), our safety is being compromised by these criminals, also.
Wednesday, December 06, 2006
Store Detective Discovers Traveling Credit Card Ring
The store detective noted suspicious behavior - customers purchasing large amount of gift cards and did a little checking. When he did, he discovered that the cards being used were counterfeits.
When the merry trio was arrested at a bank down the street, police discovered maps to area retailers, a lot of counterfeit credit cards and - of course - gift cards.
After being identified, the authorites determined that the fraudsters had traveled to Washington from California.
The fraudsters claim that they were using the gift cards to buy things for themselves. Let see, they travel from California to Washington and use numerous counterfeit credit cards to obtain merchandise for themselves?
And the authorities aren't buying their story either -- they are being charged with "leading organized crime."
My guess is that they were going to find a way to convert the gift cards to cash. I recently wrote about the problems associated with gift card fraud and how they are being fenced on auctions all over the Internet:
Why Buying Gift Cards on Auction Sites isn't a Good Idea
Normally - I write from a broader perspective - but this story illustrates how we might be rubbing elbows with some fairly sophisticated "criminal types," while out doing our Christmas shopping.
Jeremy Palowski of the Olympian wrote the story, which attracted my attention to this, here.
Saturday, May 06, 2006
Retailers Find their Stolen Merchandise for Sale on eBay
A common misconception is that the majority of losses stem from individuals stealing items for their own use. In fact, the majority of stolen goods are converted into cash.
With the increased focus on the traditional means of converting stolen merchandise into cash, such as refunding, common and professional "boosters" are flocking to eBay to accomplish their primary goal.
This was a matter of concern raised at the Retail Fraud Conference held in London recently. Penelope Ody of the Retail Bulletin reports:
Retailers at this week's Retail Fraud conference in London (May 4) had a new preoccupation adding to the usual concerns over dishonest cashiers, sweethearting and back door delivery thefts-eBay. According to Boots head of loss prevention and security, Robert Jennings, this is now in the top five areas of concern as retailers increasingly see their merchandise offered in bulk on the web auction site.
Link, here.
Note that the Jennings is saying for "offered in bulk," which would lead one to speculate that this isn't being done by the "opportunists" and is more likely the work of organized gangs.
Interestingly enough, there has been a lot of buzz recently on organized gangs involved in shoplift activity. Margaret Pressler of the Washington Post recently wrote:
Retailers and theft experts say criminals have discovered that large profits can be made relatively easily, and without much risk, by stealing merchandise from crowded, understaffed stores. They say the most stolen items tend to be high-priced, widely used products that are routinely sold in chain stores: over-the-counter medicines, razors, film, CDs and DVDs, baby formula, diapers, batteries, hair-growth and smoking-cessation products, hardware, tools, designer clothes and electronics.
Link, here.
AND another recent viewpoint from SecurityInfoWatch.com might lead one to believe that organized retail crime has ties to illegal immigration and terrorisim.
Liz Mart'nez wrote:
According to CIS Robert W. Nolen, a lead trainer in a course developed with Bureau of Justice Assistance grant money called "Understanding, Combating, and Surviving Terrorism," many criminals from terrorist countries specialize in the re-sale of stolen consumer goods. The profits from these enterprises are used to fund terrorist activities.
In many cases, men and women from El Salvador, Honduras and Mexico travel together, doing the actual stealing. Each person in the crew has a particular area of expertise, whether it be distracting store employees, doing the actual boosting, or driving the get-away vehicle. These professional thieves often earn $3,000 a week.
Link, here.
Although not stated in the article, if illegal immigrants are doing the stealing and criminals from terrorist countries are selling the goods, it makes me wonder how close their relationships could be?
Another issue, retailers have had with eBay is the sale of gift cards on the site. Whether purchased with bogus financial instruments, or issued as refunds (which could be a direct result of shoplifting), gift cards are another means of converting stolen proceeds into cash.
In another interesting article, again from the Washington Post, Ariana Cha wrote:
The shoplifters discovered some stores would allow them to return the goods without receipts for store credit or gift cards. They then sold those vouchers on the giant online marketplace. It was easy, instant and anonymous. The money flowed in -- they got 76 cents per dollar of stolen merchandise, a huge takeaway considering that shoplifters traditionally net 10 percent or less of the retail value of the items. The group made more than $200,000 in 10 months.
This is yet another example of many, where crimes of all sorts are occurring in the Internet auction world (particularly eBay). We can't hold auction sites accountable for being in collusion with criminals, but we can hold them accountable for not providing a safe shopping environment.
After all, how long would one of these retailers survive if they allowed the amount of crime to occur within their four walls with people walking around? My guess is that they would be out of business pretty quickly.
The same standard needs to be applied to the Internet and if this "business model" is to survive, the auctioneers needs to wake up and smell the coffee. Thus far, eBay has been able to blame everyone, but themselves; however as corporations become victims, the stakes are likely to grow.
Corporations have money and can afford a lot of lawyers.
Tiffanys might have already started this trend with it's pending litigation regarding the sale of counterfeit merchandise on eBay.
