Showing posts with label scams. Show all posts
Showing posts with label scams. Show all posts

Friday, February 01, 2019

Caller ID can Cost You $$$$

Fraud using the telephone is nothing new and has been around for as long as there have been telephones. After all, a telephone is merely a communication device that can be used to dupe someone into doing something they might regret later.

Saying that telephone technology, which has grown rapidly in recent years, has given fraudsters a wide array of new tools. More and more frequently, these tools are used to depart common people and even large businesses from their hard-earned money.

Take Caller ID for instance, which is marketed as a means of protecting our privacy. When I say marketed, it's normally sold to us for a fee so we can see who is calling us. The irony of the situation is that for a fee (over even for free in an app store) -- just about anyone can make the ID appear to whatever number they desire. If you have a person stored in your contacts and their number is used, the contact information stored in your phone will appear on the screen. 

The ability to spoof (fake/impersonate) Caller ID has been around for a few years. Collection agencies, private investigators, telemarketers, and even law enforcement agencies use it to get people to answer their telephone.  Unfortunately, scammers and seedy telemarketers are now using this technology to trick people into buying questionable goods and services or even steal from them. 

The FTC has a great site to educate the public on this activity and you can file a complaint with them.

Common lures/signs of a scam to snag a victim include:


  • Your banking credentials have been compromised and they ask for financial verification to verify your identity (they often spoof the financial institution's number).
  • You owe the IRS money and will go to jail if you do not pay today.
  • You owe for a loan and will go to jail if you do not pay today.
  • That they have been monitoring your credit and you now qualify for zero interest on your credit cards. 
  • You've been specially selected (for this offer).
  • You'll get a free bonus if you buy our product.
  • You've won one of five valuable prizes.
  • You've won big money in a foreign lottery.
  • This investment is low risk and provides a higher return than you can get anywhere else.
  • You have to make up your mind right away.
  • An offer of a free vacation. 
  • An offer of a "too good to be true" business or investment opportunity. 
  • You trust me, right?
  • You don't need to check our company with anyone.
  • We'll just put the shipping and handling charges on your credit card (If they get your payment card they often use it to commit additional fraud).

Please note that some of these scams are telemarketing come-ons. Many are also charity scams, where no money is ever given to a real charity. It is prudent to research the validity of any charity, which can be done by visiting the Charity Navigator website. 

More and more frequently, Caller ID is being used by organized (and maybe some not so organized) criminals to commit fraud. A couple of years ago, 62 people were arrested for operating from a call center in India and impersonating IRS or ICE agents. They allegedly made $75,000,000 in one year from this operation. I received several of the alleged IRS calls and they all had a Washington DC area code appearing on my telephone. With tax season here, we can probably expect to see these calls resurface again. 

Most of the calls, I have personally received or heard about involved a person with a foreign accent. I suspect a lot more of this activity comes from call centers located overseas. Unfortunately, we have all been "trained" to accept calls from people with foreign accents by corporate entities outsourcing jobs in order to save payroll dollars. 

The Truth in Caller ID Act was signed into law in 2010, which makes it illegal to spoof a number in order to commit fraud. Despite the law, the amount of this type of fraud seems to be on the rise. Due to the fact that most of these calls originate from overseas by purchasing a local telephone number -- and then forwarding the calls -- the danger of any real consequences is extremely minimal. The other option provided is to sign up for the FTC's "Do Not Call List," but this seems to be ignored by the people making the calls. 

Being able to spoof a call has become too easy. A simple Google search will reveal all kinds of "resources" available to anybody. 

In my humble opinion, the need for additional legislation to combat this growing problem is pretty apparent. Most of us are exposed to this activity "too frequently" via easily available technology, which not only includes "spoofing," but also includes professional sounding "phone trees" backed up by "robocall dialers." Perhaps the solution is to make it illegal to sell this type of technology to "anyone." The telecom types should also be forced to aggressively to come up with robust solutions to protect their customers from a service they are charging them for.

Saturday, January 02, 2010

Will 2010 be a Banner Year for Identity Thieves?

For the past six months or so, this blog was put on hold. I could come up with a lot of excuses why it was put on hold -- such as increased workload and job responsibilities -- but I probably just needed a break from writing.

Now that I am taking a look at getting back into blogging, it doesn't appear much has changed in the fraud arena or that the news is getting better. Of course, I probably already knew that. After all, I didn't get much of a break from all the fraud that is going on out there, I merely wasn't writing about it.

For instance, Jay Foley at the Identity Theft Resource Center did a recent interview with Tom Field at Bank Info Security and is predicting some scary trends for 2010. Two of the predictions are that medical identity theft and too good to be true scams will be on the rise.

I can attest to the too good to be true schemes being on the increase. They happen all over North America on a daily basis. Strangely enough, the scams seem to recycle themselves and use the same bogus financial instruments, over and over, again.

"Well, first and foremost we are going to see a lot more scams. Because of the tough economic times, we are seeing a lot of scammers come out of the woodwork and try to suck you into this quick job, that quick job, here make a little extra money, and invariably what happens is you find yourself on the hook for greater debt and greater problems because you went to work with these scammers," according to Jay Foley.

Besides this, Jay is predicting an increase in medical identity theft, which struck me as "interesting" given all the media attention on health care legislation. Apparently, he is seeing a lot of people, who are without insurance, use some else's name and social security number to piggyback on someone else's benefits. In the article (also a podcast), Jay aptly points out that the medical industry has been plastering social security numbers on just about every document they create for years.

It should be noted -- especially as move towards digital medical records -- that in the wrong hands these records can be used for more than medical identity theft. The same information can be used to commit a host of financial crimes, including scamming the government and the insurance companies. In case you missed it, the WSJ did a story on the subject, where an insider (employee) downloaded 1100 records, which were later used by his cousin to commit $2.8 million in fraud.

There is no doubt that medical records have been identified as an easy place to steal information by the criminal element. The "trillion" dollar question right now is if making these records digital is going to make the problem worse? Only time will tell.

Estimates on medicare fraud vary greatly, but some go as high as $80 billion a year. Please note this is an estimate on medical fraud in the public sector and doesn't account for the fraud directed at the private sector. The NHCAA (National Healthcare Anti-Fraud Association) is a good place to see all the different aspects of this growing problem. The end result is a monetary loss that we all end up paying for, whether as a taxpayer or a consumer.

It's pretty hard to get an accurate estimate of how much fraud occurs, we can only guess what it might be based on the known incidents. The reality is the more successful frauds are never discovered. After all, most of the people committing fraud go to great lengths to keep their activities anonymous. It is bad for business, otherwise.

So far as industries that will be targeted, Jay predicts the payment services industry and medical industry will be the most attractive to information thieves. Is this because the payment services industry is where there is instant access to money and the medical industry has an abundance of easily accesible information to steal?

Also predicted is that the scammers, hackers and identity thieves behind these schemes are going to be much younger. Citing the urban legend status given to Albert Gonzalez (28), who has now been identified as being a member of the Shadow Crew and behind the TJX, Heartland and Dave and Buster's breaches as a fueling factor. According to Jay, his group is seeing a trend where teenagers are putting up fake e-commerce sites etc. etc. to steal payment information and steal money.

Jay also points out that most information theft is being done by insiders, or people who are given access to it. I've always said that you can have the best security systems out there -- but if you give the wrong person access -- even the best systems can be redered useless. With information being worth money, people can be recruited or even planted in organizations to steal it. While the Albert Gonzalez types make good news stories, if an organized crime group (or lone crook) wants to get in a system, it's a lot easier if they have an inside connection.

Perhaps we need to take a step back and realize that the human being is the most important part of any security equation. Human beings are on both side of the equation, whether they are the victim or the victimizer. As long as we continue to maintain information in easily accesible places (to make money) and send it (electronically) all over the place, we are going to have a problem.

You can read more about Jay Foley and the Identity Theft Resource Center (highly recommended), here.

Sunday, June 28, 2009

Lucid Intelligence – A Free Way to Discover IF Your Identity Has Been Stolen!

Millions of personal and financial records have been compromised in recent years and the criminals involved in trading this information operate worldwide.

"A criminal might be based in Romania, using servers hosted in Russia, stealing data from people in Germany, to buy goods from an American retailer for delivery in the UK, using an Australian credit card," according to a new site called Lucid Intelligence, which seeks to level the playing field for the individual victims of these crimes.

Lucid Intelligence has set up a site that has a user-friendly tool that allows a person to see if their personal and or financial information is in the hands of criminals. It then provides resources – that are free for the most part – a person can use to protect themselves. The Lucid Intelligence Database contains the information of over 40 million people who have already been compromised.

Although, the site freely admits they can't do anything about getting your information back, the truth is that an aware person can take measures to make the information useless (and maybe more dangerous) for criminals to use.

Some of the ways the site suggests protecting yourself is setting up a Google Alert (detailed instructions included), getting a free credit report, finding some free identity theft protection and protecting your computer. Free options of doing this are identified on the site.

All of the records in the Lucid database have already been compromised by criminals and made available on the Internet. These stolen details were found in chat rooms, bulletin boards or FTP sites, which are used as underground forums to sell stolen information. Recently, two major reports indicated there is so much stolen information available, the law of supply and demand is causing prices to go down. This would suggest there is a glut of stolen information out there.

The information is stolen in a variety of ways. It can be stolen by hackers, who compromise a retail or banking system, dishonest employees at a wide variety of places or malicious software delivered by the botnets that "virtually phish" the digital world with billions of spam e-mails. Information can also be stolen when you pay a bill using a card or when an irresponsible employee throws it in trash. Please note, there are other ways information is stolen and I am only listing the more well-known methods.

A lot of the information in the database has been obtained by the highly skilled operators behind Lucid, who seek out and engage cyber criminals and beat them at their own game. These operators, who come from all walks of life, are volunteers and most (if not all of them) have put a few scammers behind bars.

There is little doubt that the amount of information in this database is going to grow and, whenever possible, Lucid records exactly where they discovered the information.

The information you input to do the searches is not maintained by Lucid until you request the detailed summary. There are reasons for this, which I will explain below. The site also doesn't use any cookies that are designed to track activity on a computer. From what I can see, everything associated with the site is designed to protect individual privacy and takes the necessary precautions to stop someone with malicious intent from exploiting the Lucid database itself.

If the search reveals your information has been compromised, they provide you with a limited summary. For an administrative fee – and only after your identity has been completely verified – they will provide you with all a detailed summary. The administrative fee of £10 (approximately $16.56) to get the detailed summary covers the costs of pulling the information. Included in the detailed summary is an individual risk analysis based on the information discovered.

In most cases, the limited summary, combined with the protection information, will be sufficient for most people.

In the past four years, Lucid has turned over the details of every credit card they've discovered to the “Dedicated Cheque and Credit Card Unit” in London and APACS. In turn, this information is turned over to the credit card issuer. Lucid has already provided the details of several hundred thousand compromised credit cards and it is estimated they have saved more than £200,000,000 (approximately $331,250,263) from being stolen. When considering this statistic, we need to remember that the actual card details came from all over the world.

It should be noted that payment (credit/debit) cards aren't the only type of information available for sale on the Internet. Lucid attempts to report all the information they discover if there is a place to report it to.

There are good reasons that Lucid doesn't turn these credit card details over to the card issuers directly. Replacing credit cards is costly and sometimes card issuers choose to merely monitor known compromised information and then issue a new card if there is suspected fraudulent activity. By reporting it to the authorities and APACS, Lucid ensures a record is maintained should someone run into complications with an issuer after they have been victimized. Despite all the zero liability ads out there, the sad truth is that not all victims come out of these schemes without losing money (sometimes a lot).

Another thing the Lucid database might reveal is synthetic identity theft before it comes back to haunt a person. Credit reports don't necessarily catch all forms of identity theft. Sometimes different parts of people's identities are used to forge a synthetic one. In these instances, because a lot of the information doesn't match, the credit bureaus don't pick it up.

Other examples where a credit bureau might not reveal identity theft are medical benefit fraud, employment fraud, government benefit fraud, some forms of check fraud and when it is used to commit crimes of other than a financial nature.

Another thing to consider is that since not all compromised information is used or used right away, the risk is there, but it will not show up on a credit report.

The people behind Lucid are also active in dealing with advance fee fraud (419) and the different varieties of this are covered on the site, also.

Last but not least, if you need further information they have a way to contact a member of the group.

The site is largely the work of Colin Holder, a retired Detective Sergeant from the United Kingdom, who is considered one of the leading experts in the world on advance fee fraud and identity theft. This isn't the first Web site Colin has set up, either. In 2001, he set up the Metropolitan Police Fraud Alert site and came up with the idea that later became the "KYC" and "Money Laundering" compliance database. His full biography, which is both impressive and extensive, can be found on the site.

Saturday, May 30, 2009

Charity Scams Busted Nationwide

Most Americans embrace the philosophy of helping others in their time of need. In every disaster -- whether it is in this country or anywhere in the world -- Americans are there to help those who need a helping hand. Unfortunately, there are those who take advantage of this, which has led to an ever-growing problem with charity fraud.

One of the more popular charity causes is to support the public service organizations, which are on the front lines of protecting the rest of us. Sadly enough, charity fraudsters are impersonating organizations that raise money to support fire fighters, policemen, and members of the armed forces.

Often, the line between an outright scam and the deceptive marketing of charitable causes is a little blurry. There are a lot of services-for-profit that market charitable causes for a cut of the proceeds. Unfortunately, some of them get too greedy when taking their cut.

To combat this growing problem, the Federal Trade Commission, along with dozens of state law enforcement officials, announced Operation False Charity on May 20th. Operation False Charity is a crackdown on fraudulent telemarketers, who claim to be gathering money on behalf of police, firefighters and veteran’s charities.

In keeping with the FTC tradition of educating the public, they are also releasing a lot of educational materials about charity fraud. They even provide a lot of these materials in Spanish.
Warning signs of scams, and what you should do about them:

• High pressure pitches. Reject them: It’s okay to hang up.

• A “thank you” for a pledge you don't remember making. Be skeptical. Scam artists will lie to get your money.

• Requests for cash. Avoid giving cash donations.

• Charities that offer to send a courier or overnight delivery service to collect your money.

• Charities that guarantee sweepstakes winnings in exchange for a contribution.

• Charities that spring up overnight, especially those that involve current events like natural disasters, or those that claim to be for police officers, veterans, or firefighters. They probably don't have the infrastructure to get your donations to the affected area or people.

To assist the public in learning how to avoid being taken when giving money to a charitable cause, the FTC has a lot of tips to identify a potential scam. Here again, these tips are provided in Spanish, too.

Individuals are not the only ones targeted by charity fraudsters. Frequently businesses are targeted, also. One way businesses are targeted is by being solicited to buy advertising in publications that look like they're sponsored by nonprofit groups. Just because the publication may use words like "firefighter," "police," or "veteran" doesn't necessarily mean they are affiliated with these groups. The prudent thing is to check out any unknown charity with a site like NASCO (National Association of State Charity Officials), which provides resources to identify legitimate charities throughout the country.

The results are starting to come in from the efforts put forth in Operation False Charity. On Friday, Jerry Brown, the California AG, announced they have filed eight law suits on 53 people, 17 telemarketers, and 12 charities accused of squandering millions of dollars of charity money intended to support policemen, fire fighters, and veterans. According to the announcement, the so-called agencies involved had bloated overheads and even purchased a 30-foot sail boat with the money they collected.

Thus far, 76 law enforcement actions against 32 fundraising companies, 22 non-profits or purported non-profits on whose behalf funds were solicited, and 31 individuals throughout the United States have been initiated as a result of Operation False Charity. Also included in this total are two FTC actions against alleged fake non-profits and the telemarketers making the calls.

If you want to learn more about how to make your donations count, you can visit the special site the FTC has put up on this subject. Furthermore if you spot what you suspect is charity fraud, contact your State Attorney General or local consumer protection agency.

Other recognized places to ensure a charity is legitimate are the American Institute of Philanthropy, Better Business Bureau Wise Giving Alliance and CharityNavigator.

You also may file a complaint with the Federal Trade Commission by visiting the page on their site, or calling toll-free, 1-877-FTC-HELP (1-877-382-4357); TTY: 1-866-653-4261.

Friday, May 15, 2009

Craigslist Shuts Down Erotic Services Section

Craigslist has given in to the immense media attention regarding its "erotic services" ads and announced they are shutting the section down. In its place they are now adding an "adult" section, which appears to hawk the same type of personal adult services.

A lot of this occurred after it was discovered that a killer used Craigslist to stalk his victims, who were offering adult services. Since then the nasty subject of teenage prostitution on Craigslist has been covered in the mainstream press and the site has been referred to as an "online bordello."

Of course, Craiglist isn't the only place that advertises "adult services." They can be found in newspapers, alternative weekly rags, and a whole slew electronic venues besides Craigslist.

Craigslist announced the change on their blog and made some points in their defense. At the same time, they announced they will be charging for the ads in the new section and the proceeds will go to charity. All of the new ads will be reviewed by Craigslist employees before they are posted.

The post refers to statistics that the chances of a predator abusing their forum are less likely than a predator using print ads to commit a foul deed. Also pointed out was that Craigslist has safety features built into the site that most "classified advertising" venues don't have. These include blocking, screening, telephone verification, and a community flagging system. The company also claims they cooperate (at a high level) with law enforcement and that predators can be tracked electronically back to the computer they are using. Last but not least, they point to safety tips prominently posted on all forums. These safety tips run the gamut of illegal schemes commonly found on the Internet.

Investigations are normally confidential matters, but if someone was tracking a sexual predator some of these forums could provide real-time investigative capabilities to resolve the case. They could literally track everything to a particular location given the right circumstances and cooperation by the forum and the ISP. Quite often, the frustrations voiced by those tasked with investigating internet crime are that the site and or the ISP do not cooperate as much as they should. If these sites aren't going away, then maybe the solution is to make is easier to tag the offenders?

Craigslist claims they do cooperate with investigative inquiries, but thus far no one is publishing any of these stories. It does state that law enforcement personnel provided feedback on how to design their new "adult section." Again, I'm not sure, but I imagine they couldn't claim this unless there was some truth to it; there is probably an army of lawyers monitoring this situation.

I doubt a flurry of media attention directed at Craiglist is going to solve the "people abuse" problem caused by anonymous venues. The problem will merely move from one anonymous venue to another one. The key will be the ability of the people doing the abuse to remain anonymous, or at least think they are. When sites and ISPs cooperate, it really isn't hard to track a lot of these individuals.

Since none of these sites are going away anytime soon, perhaps the best solution is to make it easier for the authorities to obtain cooperation from them when abuse is suspected or occurred, which is exactly what Craigslist is claiming to do. But Craigslist is hardly the only place where people are victimized by those with sinister intent on the Internet or via advertising in the print media. We need to begin to take a realistic look at the entire issue.

Friday, February 27, 2009

FTC Site Teaches Public How to Avoid Bad Deals

March 1st through the 7th is Consumer Awareness Week. This year, the Federal Trade Commission (along with an army of partners) are providing a user-friendly set of free e-tools designed to help the average "Joe or Jolene" safely navigate the murky waters they face in the current economic environment.

Besides teaching us how to make the most of our financial resources, the tools also teach how to avoid the underground army of not very honest people who are spreading more economic doom and gloom with too-good-to-be-true schemes designed to take advantage of the grim economic situation.

The Web site for the 11th annual National Consumer Protection Week is now up and running. Launched by the Federal Trade Commission and its NCPW (National Consumer Protection Week) Steering Committee partners, the site gives people free tools to make smart business decisions in today’s economy. The information on the site is designed to help the average person get the most value for their money, whether they are trying to improve their credit history, tell the difference between a real deal and a rip-off, or protect their mortgage from foreclosure or foreclosure rescue scams. It explains their rights under various laws and tells how to file a complaint or seek assistance from the appropriate government agency.

According to the Federal Trade Commission, scam artists, fraudsters, hackers and flim flam artists follow the headlines and use the current economic downturn to part people from their hard-earned (and ever-dwindling) financial resources. The NCPW Web site has tools (educational resources) to teach people how to recognize a ripoff, sniff out a scam and ensure they are getting value for their dollar in today's marketplace.

The site has tips on a wide range of topics from partner organizations. These tips include from how to get a free credit report to how to spot a telemarketing scam and how to deal with debt to how to deter and detect identity theft and from how to avoid home and auto repair scams. Also included is detailed information on how to file a complaint with the appropriate agency if you do run into an issue.

Of course, on a personal level, I always recommend reporting them if you spot a problem and are able to avoid becoming a statistic, also. This can prevent a less educated person from becoming a victim and is a good deed.

National Consumer Protection Week


The FTC partners involved in providing this information include the AARP, the Comptroller of the Currency, the Consumer Federation of America, the Council of Better Business Bureaus, the Federal Citizen’s Information Center, the Federal Communications Commission, the Federal Deposit Insurance Corporation, the Federal Trade Commission, the National Association of Attorneys General, the National Association of Consumer Agency Administrators, the National Consumers League, the U.S. Department of the Treasury, the U.S. Postal Inspection Service, and the U.S. Postal Service.

The FTC also just released the top complaints they received in 2008. For the ninth year in a row, identity theft came in at number one. 1,223,370 complaints were received in 2008. 313,982 (26%) were related to identity theft.

Not surprisingly, with all the data breaches seen recently, credit card fraud was the most common form reported. This was followed by government documents/benefits fraud at 15%, employment fraud at 15%, phone or utilities fraud at 13%, bank fraud at 11% and loan fraud at 4%.

Other complaint categories included Third Party and Creditor Debt Collection, Shop-at-Home and Catalog Sales, Internet Services, Foreign Money Offers and Counterfeit Check Scams, Credit Bureaus, Information Furnishers and Report Users, Prizes, Sweepstakes and Lotteries, Television and Electronic Media, Banks and Lenders, Telecom Equipment and Mobile Services, Computer Equipment and Software, Business Opportunities, Employment Agencies and Work-at-Home, Internet Auction, Advance-Fee Loans and Credit Protection/Repair, Health Care, Auto Related Complaints, Travel, Vacations and Timeshare Plans, Credit Cards, Magazines and Buyers Clubs and Telephone Services.

Please note these are statistics where people were victimized. The information on the NCPW site is designed to keep people from becoming one (a statistic).

Friday, January 09, 2009

Spam Levels on the Rise, Again

With the shutdown of McColo by Internet Service Providers in November, global spam volumes dropped over 50 percent. Sadly, this appears to have been a short-term fix. According to a new Symantec report, the spammers have moved to new locations and the volumes are back up to 80 percent of pre-McColo levels.

While spam originates from a lot of places, the United States is still in the number one spot, with 27 percent of the spam observed originating from there. China and Brazil tied for second place with 7 percent of spam originating from these countries.

The report indicates that URLs in Canadian Pharmacy spam messages were noted as being top-level Chinese domains (.cn TLD). Could this mean that Chinese knock-off (counterfeit) prescriptions are trying to make it appear as if they are coming from Canada? Given the recent concerns of tainted and poisonous merchandise being exported from China, this might be a concern. Of course, I would think that buying prescription meds over the Internet should be a concern to most people, anyway.

In another variation of recently observed spam, a user is invited to join a social networking site. The link goes to a real group, which was created on the social networking site by the spammer. The group then links to a free blogging site, which redirects the victim to the ultimate destination URL. At the destination URL, personal information is requested, which is probably used to sell to marketing companies or used in other spam campaigns. Please note, although not mentioned in the report, that some of these campaigns might have malicious intent or be scams.

Also noted during the holiday season was a lot of e-Card spam. This spam sometimes comes with malware (malicious software) designed to steal personal and financial information or turn your machine in to a spam spewing zombie computer using your credentials.

A partcularly deceptive spam delivery method noted recently is spammers inserting their messages into legitimate newsletters. This method seems to get past spam filters pretty effectively. If the recipient clicks on the message, they are taken to a spammer site. Here again, it might be a site selling junk, but also could be a site with more malicious intent.

Another spam trend in vogue these days is to use the recession as a social engineering lure designed to get people to click on a spam link. Messages are being sent out in the millions touting easy bail-out money to be had and an assortment of the normal get-rich- quick schemes. If it's too good to be true and doesn't make sense, it's normally a scam, and I suspect that most of this type of spam is one.

Last but not least, the spammers are still using President-elect Barack Obama's name to market coin offers, a "Barackumentary DVD" and a free Visa card for helping the Obama clan pick their dog.

Shutting down McColo by reaching out to the ISPs — which was done largely through the work of Brian Krebs at Security Fix (Washington Post) -- showed that a significant impact can be made on spam when ISPs are held accountable. Given that Brian is one person and a journalist, this was an admirable piece of work. The fact that spam is approaching pre-McColo levels tells us that there are more ISPs that need to be held accountable. Maybe in the end, government and international agencies need to follow Brian's example and and make an impact on spam levels that will last a little longer.

Spam is a dangerous pain for everyone who uses e-mail. Most scams, questionable goods and services and cyber-attacks using malicious software start with a spam e-mail. Shutting down the spam operators can only make everyone's experience on the Internet a little more safe and sane.

Thursday, January 01, 2009

Fraudulent Checks Too Profitable for Criminals

Fraudulent checks, bank drafts, money orders, travelers cheques and gift cheques seem to be showing up all over the place. While a portion of these are passed by professional criminals — who sometimes recruit people off the street to pass them — a lot of people are being tricked into cashing them because they believed a (too good to be true) money-making opportunity.

Unfortunately — with the current state of the economy — people seem to be falling for the too good to be true scam opportunities more and more frequently.

Even though the quality of these fraudulent instruments varies, many of these counterfeit items are now produced with magnetic ink that scans. High quality check stock complete with the latest security features can be purchased in office supply stores or on the Internet. This means they scan through most of the readers in point of sale systems at businesses. When used with a real account number, which is why counterfeiting works, these items can be difficult to detect as fraudulent.

The increase in counterfeiting isn't limited to checks. Complete sets of counterfeit documentation are being presented at banks to open new accounts. A small amount of money is put into the account so funds verify on an individual check and then an area is plastered with a lot of checks. Sometimes this is done over the weekend and the funds put in to verify the checks are removed the following Monday. The identities used to pass these checks are often stolen. Since the identities and checking accounts are changed frequently to avoid detection, it's difficult to tie all the activity back to one group or person.

Frequently, people who are down-and-out are recruited to pass these items after receiving a promise for a few quick bucks. If they are caught they are normally considered "expendable" by the people behind the schemes. Sometimes, they even do this using their own identities.

It should also be noted that the groups opening fraudulent accounts and counterfeiting checks also set up phony numbers and even business addresses that get listed in 411 and on information sites fairly easily. Most people would be amazed at how easily they accomplish this because little to no verification is done by the companies listing these numbers. This is also done in a lot of the Internet-related scams and it is not uncommon for them to list a number to a financial institution that isn't real. When they set up these numbers, while the scam is active, they have people answering the lines. Often, if you listen carefully, it's pretty obvious that it is not a legitimate business and sometimes calls are forwarded to cell phones.

Another growing phenomenon is that fewer and fewer banks verify funds when businesses try to find out if a check being presented is good. In this instance, privacy laws and fear of litigation probably have enabled the problem to get worse. A lot of businesses use computerized check verification services, but when stolen identities are used, the checks pass through these systems fairly easily. Even worse, after the check is determined bad and the data goes in the system, innocent people are pegged as passing bad checks.

These checks often returned by the bank for “non-sufficient funds" because they aren't aware the account was set-up with fake information. Eventually the account is closed by the bank, but by this time the damage is done. Since banks frequently don't investigate thoroughly enough to determine the account was set up with fake (often stolen) information, it is never identified as fraud. The exception might be when the bank takes a loss, but more frequently they pass the losses to the entity cashing the check.

It's almost impossible to get anyone prosecuted criminally for non-sufficient funds/account closed cases, which means there is little fear of getting caught in this type of scam. Privacy laws also make it difficult for anyone outside the bank to investigate individual cases. In most cases, law enforcement needs a subpoena, which take time and effort to obtain. Given the resources available at most white collar crime units and the amount of fraud, it often seems like the system is ripe for manipulation by criminals.

Technology and the anonymous nature of the Internet have made check fraud grow substantially. All the necessary software/hardware needed is available right for sale at merchants that sell software and office supplies and on the Internet, itself.

There are also Web sites that appear to be dedicated to providing all the materials to commit fraud despite disclaimers that the items are for educational purposes only. One example, of one of these sites is called HackersHomePage. If you take the time to look at this site — you will see that the the items for sale on this site might enable someone to commit a lot more than simple check fraud.

Another growing phenomenon over the past several years has been the sheer number of counterfeit instruments being passed for a “too good to be true” money making scheme. These schemes, which normally don’t make sense, normally involve secret shopper job opportunities, offers to become a financial representative, auction deals and of course, winning a sweepstakes or lottery.

These scams lure people via spam e-mails, which are sent by the millions, daily. Once someone makes contact with the unknowing victim, they are shipped bogus financial instruments to cash. Along with the bogus financial instrument to be cashed there is a letter instructing the victim to wire the bulk of the money (normally over a border) back to the location of the scammer. Another twist in these money making schemes is to buy small and expensive items, normally electronics or jewelry, and ship them (again) normally overseas. A lot of eBay and Craigslist sellers get taken by these schemes.

From the botnets spewing the spam e-mails out in the millions to the counterfeit checks being sent by the parcelful all over the world, there is little doubt that some pretty organized criminals are behind this activity.

In 2007, an International Task Force monitored the mail in Africa, Europe and North America and intercepted billions of dollars worth (face-value) of counterfeit checks.

The coordination across International borders in these scams is pretty amazing. In any individual scam, the e-mail can come from one country, the checks from another and the request to wire the money to a third.


(Picture of checks intercepted in the mail)

There is also a trend where opportunists receive these items, cash them and keep all the money for themselves. If caught, they pretend to be a victim. If no attempt is made to wire the money to an exotic locale, they are probably in the scheme for their own personal gain. It isn't hard to look in just about any inbox or spam folder, reply to the right e-mail and have all kinds of bogus financial instruments shipped whatever address a person wants.

The first step to recognizing these scams is to understand how they work. Most if not all of the reasons these checks are being presented aren't going to make sense to a reasonable person. The cliche is that they are too good to be true and they normally are.

The best places for potential individual victims to learn how not to be taken are FakeChecks.org and OnlineOnGuard.gov.

A good resource for businesses and other public entities to learn about check fraud is the National Check Fraud Center.

In closing, the sour economy is probably fueling an increase in all kinds of fraud. The bottom line is that individuals and businesses are being ruined by it. When it comes to businesses, any dollar lost to fraud normally equates to a dollar off the bottom line. So far as the individuals being victimized, cashing these items can lead to being financially ruined and even arrested.

The best defense against becoming a victim is to know how these scams work. After all, very few people become victims when they know they are being ripped-off!

Sunday, December 14, 2008

Most Internet Scams Start with Spam

I'm sure we've all noticed spam levels are slightly down, or that our spam filters seem to be working a little better. Nevertheless, spam continues to get through filters and for the next few weeks, a lot of it will have a holiday theme. Due to the sour economic situation, it's also likely going to take advantage of financial fears or the promise of a rescue from an already bad situation.

Since most unfortunate situations involving fraud, phishing, and financial misdeeds on the Internet start with a spam e-mail, it pays to use a little common sense and caution before falling for a too good to be true, or sometimes scary e-mail from an unknown source.

Last week, Symantec issued its December 2008 State of Spam Report. It predicts that although spam volumes are down after a lot of providers blocked access to sites hosted by McColo.com, we will likely see them rise again. Spam levels dropped a reported 65 percent after this happened. "McColo.com was allegedly hosting a significant number of botnet command-and-control systems'" according to the report. The bad news is that the report indicates the bad guys are moving elsewhere and that a number of them are hosting their efforts from IP addresses in (where else) China.

Getting back to the holiday season, the report notes that spammers are mimicking marketing come-ons from legitimate retailers offering holiday shopping deals. This makes it hard to distinguish exactly who is behind the e-mail. Sometimes the line between legitimate and illegitimate becomes a little blurry, which is something spammers have always taken advantage of.

The report also reveals a lot of links leading to malware infected sites in spam e-mails are using political themes to draw in their victims. Items related to Barack Obama are especially popular with spammers and scammers. In another twist to using Obama's good name, one spam campaign offered a Barack Obama coin, "a piece of history for only $9.95 plus shipping." This was an attempt to steal debit and credit card information.

Hot news stories were also used as lures to download malicious software. In particular, the recent Mumbai terrorist attacks pointed to links designed to infect machines. Ironically, a lot of this malware is designed to turn a computer into what is referred to as a "zombie," which when used in a botnet is used to send out even more spam.

While we haven't seen the holiday season pass, spammers of the scammer type are already using the IRS name to steal personal and financial information. The pre-tax season phishing scheme mentioned in the Symantec Report involved a come-on designed to snare people by telling them they had a tax refund or economic stimulus payment due to them. The link in these e-mails went to fake IRS site(s) — complete with offical logos — designed to steal personal and financial information.

The IRS isn't alone when it comes to having their good name spoofed. Just this week the FBI reported that their name was being used (yet again) in a campaign involving a typical Nigerian 419 scam. If an intended victim got leery after initially responding — they were threatened with "official consequences" should they fail to turn over the required personal and financial information.

Fear or scaring a victim into submitting to a scam is nothing new. In fact, some of it is now being referred to as Scareware. Scareware most frequently surfaces as a fake message claiming your computer is infected. In then offers to fix the problem for a nominal amount of money. My guess is that malware might actually be downloaded on a system by clicking on one of these come-ons.

Since it's hard to pay in cash over the Internet, anyone who pays on this form of extortion might have their method of payment stolen, also. Symantec recently released another report showing how many personal and financial details are for sale (super-cheap) on the Internet.

Alex Eckelberry of Sunbelt Software and the popular Sunbelt Blog just posted a visual presentation of scareware examples on his Flickr account.

There is little doubt that spam and its intended purposes have made the electronic world somewhat of a "virtual minefield" at times. It pays to make your computer bullet-proof by using good state of the art software from a legitimate vendor, but even if you are protected in this manner, you also need to protect yourself from social engineering schemes designed to lure a person into doing something they are going to regret later.

The Anti Phishing Working Group offers sage advice (from a variety of reputable sources) to the average person on how to avoid becoming a victim. Interestingly enough, they also recently released a report that is rather ominous stating the the number of crimeware spreading URLs are at an all-time high. Crimeware is another name for malware when it has a pure criminal intent.

To close this post, I'll point to a amusing video Symantec did on the 12 Days of Christmas Spam. It's probably best to end on a lighter note on what has become a serious problem.

Saturday, November 08, 2008

Telephone Call Offering to Lower Interest Rate is a Scam!

Cheap long distance, the ability to spoof caller ID and the credit crisis are being used to facilitate a scam called vishing. Although telephone (telemarketing) scams are nothing new, the term vishing probably came about because advances in telephone technology are being used to depart unsuspecting people of their hard-earned money.

The term vishing was coined from the word phishing. Internet scammers phish the waters of the Internet using spam e-mail as bait. Once a person falls for their "too good to be true" lure -- personal and financial information is stolen using social engineering (trickery) or malicious software designed to data-mine the information right off the infected machine. The personal and financial information is then used to commit financial crimes, which is often referred to as identity theft.

In the past week, I've received several calls where a computerized voice informs me that the offer to lower my interest rate is almost over. It then says to press "1" if I want to lower my interest rate.

I went ahead and pressed the number "1" to see what this "too good to be true" offer was all about. After a few seconds, a female voice came on and asked me if I was interested in lowering my interest rate. I told her I was and she asked me for the 800 number of my financial institution so she could verify my eligibility. Since this is public information, I went ahead and gave one to an institution, I no longer do business with. While I was digging up the number on the Internet, she made a lot of inquires about how many lines of credit I was behind on. After providing her with the 800 number, she asked me to give her all the credit card numbers that I wanted to lower the interest rate on.

At this point, I had very little doubt I was dealing with a scam designed to steal credit card numbers. At no point did she identify a financial institution -- and besides that -- no financial institution would make a cold call and ask for credit card numbers. Additionally, when was the last time a financial institution offered to lower an interest rate to an existing customer unless they were being bailed out by the government (taxpayer)?

I asked if she felt good about ripping people off and if I could speak to her supervisor. Of course, I was never referred to a supervisor and after cursing at me, she hung up. Trust me, from the vulgar language that was expressed, this call was not being recorded for training purposes!

In the past couple of years, we've seen reports of vishing. In the case, I'm writing about a dialer system is obviously being used. Dialers are used by collection agencies, telemarketing companies, political campaigns and even charities to direct calls to live employees. Basically, dialers screen the calls via computer to make the process more efficient.

Having never priced one, I decided to see what Google had to offer. I found them to be rather inexpensive starting at a mere few hundred dollars. There were also options to use already set-up systems on a cost-per-call basis.

Caller-ID spoofing services can be purchased legally and are used by a lot of legitimate companies to entice us to pick up calls. Because of this, it is probably wise not to put your faith in caller-ID.

Some blame VoIP (Voice over Internet Protocol) technology for vishing. VoIP has made calling long distance cheap.

So far as where the victim lists are obtained, they can be easily purchased. My phone number has been unlisted for over 20 years, but information brokers data-mine information from every source imaginable, including magazine subscriptions. Since these lists are worth money, companies who gather information routinely sell the marketing information they gather on all of us. It also isn't unknown for dishonest employees to sell information directly to criminals. Often this is done right on the Internet in chat rooms, which keeps the transaction fairly anonymous.

Recently, the FBI announced that they stung an Internet forum used to sell stolen information known as Dark Market. At it's peak, the group had 2500 registered members and it is estimated that they prevented losses of $70 million (worldwide) by cracking this case.

Even the IRS and Social Security have been impersonated in the past two years in vishing schemes.

InsideCRM magazine recently published an article detailing 50 ways to protect your privacy. This magazine represents the call center industry and has a stake in fighting vishing activity, which gives legitimate e-commerce a black eye. If you (like a lot of us) enjoy the hassle-free environment shopping at home, the article is a great educational resource.

The U.S. government has also set up a highly visual and interactive site to educate people about crimes being enabled by technology. Please note this site is available in Espanol, also.

While both of these sites are designed to cover computer security issues in addition to telecom type scams, we need to remember that a lot of these scams probably started before telephones or computers made them easier to do, as well as, more efficient.

Scams rely on human emotion and greed. Knowing this is the best way to prevent yourself from becoming a victim. The "too good to be true" principle coupled with "does the transaction make sense" is the best way to figure out whether an offer is legitimate or NOT!

Friday, June 06, 2008

Monthly Spam report reveals how uncertain economic times are fueling new scams!


(Courtesy of Symantec)

With prices rising out-of-control and foreclosure signs being used to market real estate, one might think that scam artists and other less than ethical people would lay off for awhile. Think again, they are out in force and coming up with devious methods to make bad situations, worse.

I follow Symantec's spam report on a monthly basis. If you want to get an idea of what fraud campaigns are being run by cyber criminals, or what new twists to old scams are surfacing - it's a great place to get an overview.

Interestingly enough, the report starts with a comparison of e-mail spam to the lunch meat it is named after:

The harsh economic times can be witnessed from every angle, with the rise not only in email spam, but also the sales of the actual lunchmeat product, Spam. According to NBC’s Brian Williams, the spike in Spam sales is a huge economic indicator of the times, and families trying to do more with less. The exact same could be said for email spam. With spam messages accounting for over 80% of email in May 2008, the economic slowdown and its effects are definitely being targeted by spammers – preying on the hardships of people not only in the United States, but Worldwide.

In the past month, the economic stimilus program and the disasters in China and Myanmar have clogged inboxes with come-ons designed to trick people out of their money, or even worse (if a little malware is dropped) all the personal and financial information off their computer.

The report also highlights a campaign in China, offering fake invoices to avoid paying taxes.

Also noted was a scam to sell tickets to the Championship League Final, which was the biggest football (soccer) event in recent times:

The biggest football game in the European football calendar took place on May 21, 2008 in Moscow. Tickets were in big demand all over Europe for this event, and spammers certainly took notice.

Under the guise of a travel agency, the spammer offered the recipient “a unique opportunity” to acquire tickets for the game. The prospective customer was asked to click on a link to purchase the tickets and provide personal details. The recipient was then instructed to go to a legitimate online payment site to complete the transaction.

When the recipient paid for the tickets using the legitimate online payment site, the spammer requested that they email their name, surname and the unique online payment voucher number to the spammer in order to receive the tickets. The legitimate online payment website for the Champions League Final clearly states that the unique voucher number should never be emailed and only used on secure websites that accept their payments.
Please note that ticket scams are nothing new and the more popular the event is, the more likely spammers (scammers) are going to try to dupe people out of their money in the hopes of securing a ticket.

The June report highlights how spam has become a problem that has become International in nature!

Full June report from Symantec can be accessed, here.

Previous posts I've done on the monthly Spam Report can be seen, here.

Saturday, May 24, 2008

China earthquake and Burma (Myanmar) cyclone inspire another round of charity fraud!


(Photo courtesy of IslamicReliefUSA at Flickr)

Last weekend, I lamented that the Western media wasn't reporting the expected fraud activity in the wake of the China earthquake and the Burma (Myanmar) cyclone.

Most of the scam activity, associated with the earthquake, was being reported out of China.

Having been extremely busy in my day job, I didn't get the chance to follow-up and see if this trend would continue. It did not and as expected, inboxes are being targeted with come-ons designed to take away from those, who would really benefit from our charitable impulses.

As expected, we are now seeing fraudsters, using their favorite technique (spam) to trick people out of their hard-earned money and (possibly) their personal and financial details.

The reason, I mention personal and financial details being stolen (identity theft) is because malware is being dropped on systems when unsuspecting people click on a link regarding a plea for financial assistance. Sadly, this more technical means of stealing information is becoming more and more commonplace. Not very intelligent criminals (my opinion) can easily buy all the software necessary to do it -- which sometimes comes with technical support -- right over the Internet.

Of course, identity theft, might not be the only intent in dropping the malware. Frequently, the intent is to take over your system and turn it into a member of a botnet so it can be used as a spam spewing zombie. Most of the time, the owner isn't aware their computer (zombie) is being used to flood cyberspace with spam e-mails.

Internet security firms are reporting suspicious e-mails asking for help and marketable domain names are fetching premium prices.

Sophos went on record that they had detected malicious software attached to some of these spam mails. McAfee also reported malware attached to electronic documents referencing the earthquake. The FBI issued an alert on this subject, also.

As a discaimer, at first sight, it can be hard to determine if a request for a donation is legitimate or not. Charity is a often practiced social-engineering ploy used by fraudsters and associated internet ghouls to steal money.

Besides using the Internet, charity fraudsters also use the telephone, snail mail, or even go door to door. Text messaging is another tool being used to commit charity fraud, also. This surfaced in the activity reported in China last week.

The best thing to do -- before handing over your hard earned money for an honorable cause -- is to make sure the entity receiving it is legitimate. Taking the time to check things out will help ensure the money goes where it is supposed to.

It might also be wise to give directly to an organization. Besides fraudsters, a lot of telemarketing types sell their services to charities and take a cut of the action. Simply stated, this means that less money will reach the people you are trying to help.

Listed below are some places, where you can cut out the middle-man, or avoid handing over your money to a scam artist. Please note, these organizations, might or might not be involved in the current earthquake and cyclone efforts. Current events often dictate the disaster come-on currently being used by fraudsters.

The United Way, http://national.unitedway.org/, 800 272-4630.

American Red Cross, http://www.redcross.org/, 800-HELP-NOW

Salvation Army, http://www.salvationarmyusa.org/, 800-SAL-ARMY

Network for Good, http://www.networkforgood.org/.

Habitat for Humanity, http://www.habitat.org/, 800-HABITAT.

Samaritan’s Purse, http://www.samaritanspurse.org/, 800 665-2843.

Save the Children, http://www.savethechildren.org/, 800 728-3843.

Humane Society of America, http://www.hsus.org/, 888 259-5431.

Feed the Children, http://www.feedthechildren.org/, 800-525-7575.

America’s Second Harvest, http://www.secondharvest.org/, 800 771-2303.

Additionally, if you are interested in charities that do a lot of work in Asia, here is another list:

Doctors without Borders
Mobilizing to provide medical assistance, blankets, water, sleeping mats and tents.

International Federation of Red Cross and Red Crescent Societies
Dispatching teams to assess damages and the needs of victims.

International Rescue Committee
Assessing immediate needs on the ground and preparing emergency response.

Mercy Corps
On the ground providing emergency relief, including water and tents.

Oxfam
On the ground assessing the response effort and responding to victims.

UNICEF
Sending emergency staff to distribute aid and make further assessments of the damage.

In more general terms, there are some excellent sites to check out, whether a charity is legitimate or not:

Better Business Bureau Wise Giving Alliance, http://www.bbb.org/charity/.

Charity Navigator, http://www.charitywatch.org/.

American Institute for Philanthropy, http://www.guidestar.org/.

Last, but not least - I would like to provide some resources to report suspected fraud activity.

If it is cyber related, report it to the Internet Crime Complaint Center.

For more general complaints, fraud can be reported to the Federal Trade Commisssion, here.

Friday, May 16, 2008

Mortgage scams target the "already unfortunate!"

I guess I'm one of the luckier people out there. When housing prices skyrocketed, I chose to remain happy with my humble digs and watch the frenzy. Now that the bottom has fallen out of the housing boom, at least I'm still semi-whole.

The reason I can only say that I'm semi-whole is that last month I mailed a check to the IRS. In reality, it's probably going to be "proceeds from tax coffers" paying for the mess that was created.

There was fraud in the housing boom. Exactly how much, nobody really knows or is saying. With a lot of desperate people out there -- one thing is for certain -- there are going to be dishonest people approaching them with fraud schemes promising to get them out of their current dilemma.

The FBI just released an interesting report showing fraud trends that contributed to the current financial crisis the housing boom has caused. It's key findings were that mortgage fraud is on the rise, subprime loans contributed to mortgage fraud, the downward trend in housing will continue and that the current financial crisis is creating a new wave of fraud targeting the people, who have already lost their shirts, as as result of this crisis.

From the press release on this subject:

The latest mortgage scams run the gamut: from “builder-bailout” schemes where developers unload excess inventory through financial trickery…to foreclosure rescue frauds that trick homeowners into signing over the deed to their house; from seller-assistance scams that use false appraisals to sell homes…to identity theft that leads to home equity credit lines being opened and drained. See the report for more details.

The report lists the two main categories of mortgage fraud:

Mortgage loan fraud is divided into two categories: fraud for property and fraud for profit.

Fraud for property/housing entails misrepresentations by the applicant for the purpose of purchasing a property for a primary residence. This scheme usually involves a single loan. Although applicants may embellish income and conceal debt, their intent is to repay the loan.

Fraud for profit, however, often involves multiple loans and elaborate schemes perpetrated to gain illicit proceeds from property sales. It is this second category that is of most concern to law enforcement and the mortgage industry. Gross misrepresentations concerning appraisals and loan documents are common in fraud for profit schemes and participants are frequently paid for their participation.
The full report, which goes into a lot of detail on current trends can be seen, here.

Besides the latest report, the FBI has a page on their website dedicated to educating the average person how they might be taken to the cleaners as a result of mortgage fraud.

The page has information on a lot of the recently discovered schemes. Included is a well-written story about a pretty scary phenomenon called, "house stealing."

House stealing is where mortgage fraud meets identity theft.

… The con artists start by picking out a house to steal—say, YOURS. … Next, they assume your identity—getting a hold of your name and personal information (easy enough to do off the Internet) and using that to create fake IDs, social security cards, etc. … Then, they go to an office supply store and purchase forms that transfer property. … After forging your signature and using the fake IDs, they file these deeds with the proper authorities, and lo and behold, your house is now THEIRS.*

Although not considered common, there was a recent case in Southern California involving a variation of this scheme and it involved over 100 homeowners. More recently, the Boston Globe reported that 11 individuals were indicted in a $10.6 million loan fraud scam. Straw buyers and identity theft are part of the formula in this case, also.

And it doesn't only happen in the United States, I've read of this occurring in Canada, also.

The FBI has allocated 200 agents and 33 task forces to investigate mortgage fraud, according to an article in Reuters that quoted FBI Director Robert Mueller. The article mentioned that 19 major corporations are under investigation and Mueller referred to the FBI's involvement in investigating the Saving and Loan crisis, Enron and World.com, while delivering his speech.

If you happen to get approached with an offer that seems a little too good to be true (or are suspicious of a past scheme) you can report the matter to the FBI. The people behind these schemes have caused a lot of pain and suffering for a lot of people and besides that, if you pay taxes, you are probably paying for this problem.


(Courtesy of the FBI site - click for larger image)

Sunday, May 11, 2008

Symantec May Spam Report reveals IRS e-mail leads to vampire game?

Symantec just released it's monthly spam report. I always find these reports a valuable tool to see exactly what trends the cybercriminal and less than ethical e-commerce communities have been up to in the past month.

Although most of us view spam as a major nuisance, the fact remains that spam is the preferred vehicle of marketing garbage and ripping off human beings on the Internet.

This month continues a nasty trend where spammers and phishermen (identity and information thieves) continue to manipulate Google's search engine:

For some time, spammers have used reputable brands to try and deliver spam and phishing messages to end-users. In the last year, Google has become a favorite target for some spammers. In November 2007, Symantec reported the emergence of a technique where spammers manipulated Google’s advanced search query and the “I’m feeling lucky” option to direct users to a spam site. In February 2008, Symantec reported that spammers had manipulated parameters in Google URLs used for AdSense and redirected unsuspecting end-users to a spam website. In April 2008 phishing emails purporting to come from the Google AdWords service have emerged. Google AdWords is a service that allows advertisers to intelligibly connect with individuals who search using Google. In the Google AdWords phishing samples that have emerged, the end-user is encouraged to click on a link to update their billing information and/or renew their account. The link in these phishing emails leads to a fraudulent website where personal information is requested and harvested.
Spear phishing, where specific people are targeted arrived in inboxes in the form of fake government subpoenas addressed to corporate executives. Also seen were come-ons to become a movie star, spam being sent in the form of instant messages and the 419 (Advance Fee) boys inserting calendar reminders in their spam to remind people send them their money.

While closely related to the long known use of job sites to gather information to commit identity theft, a new twist has been noted where professional networking sites are used for this purpose, also.

From the May report:

One of the side effects stemming from the growth of personal and professional networking sites is the increase in unsolicited emails that operate under the guise of connecting business professionals with their peers. The recipient is asked to join the “inner circle” and is encouraged to supply the network with their professional history by clicking on a URL which brings the user to a registration page. The page requests personal information that could be used for identity theft and could fuel future spam attacks.

In these monthly reports, Symantec normally has one twist with a particularly ghoulish or amusing angle. This month is no exception and they are reporting an IRS spam campaign that leads to a site where you can raise a vampire from the dead:

This time, instead of the refund link taking you to a site to steal your credentials, the link takes you to a popular web-based game in which you incarnate a vampire. The vampire gains more power every time end-users click on his link. It’s a rough, dark world out there… be warned.
I found this especially ironic because scammers and spammers are often referred to as ghouls or vampires when being described in literary terms. So far as the connection to all of this with the IRS, I'll leave that to the reader's imagination.

The IRS having their name spammed is nothing new. As predicted, there is an IRS spam (phishing) campaign going on right now using the tax stimulus program as a come-on to steal personal and financial information, which will probably be used to commit financial crimes. I'm predicting this might be a topic of interest on the June Spam Report.

The full report on the State of Spam for the month of May may be seen courtesy of Symantec, here.

Monday, April 14, 2008

A final (???) salute to Attrition.org's Data Loss Database - Open Source

I came across some pretty sad news on Tom Fragala's blog that Attrition.org was throwing in the towel on their well respected DLDOS (Data Loss Database - Open Source).

In their own words, this is the reason why they are shutting down:

Much like Attrition.org's past defacement mirror, the time has come for us to say "no mas". In the past few weeks, it has come to our attention that too many people are more concerned with making a profit off of our work without any offer of acknowledgement or compensation. For those who aren't familiar with Attrition, we're a non-profit hobby site that takes on "projects" as we see fit, when we want to, and when we have time. For those who *are* familiar with Attrition, you probably know that we don't take kindly to being dealt with unfairly. Commercial entities, including "identity-theft prevention" upstarts and book authors, will gladly contact us, ask for information and advice, and then not even offer us the equivalent of a reach-around when selling their materials. We don't pimp our resources to others; they come to us. Unfortunately, more often than not, they won't even send us a "thank you". We've mentioned it in the past, but we're not going to mention it in the future. This is the last mention.
I've often mentioned the fine work the good folks at Attrition did on being a honest (not motivated by money) voice in what most of us agree is a serious problem. Because of this, I've always tried to point people directly to their work.

Perhaps, as I lamented in an earlier post, the pay for protection racket is getting a little out of hand? A good example of the frustration Attrition might feel is evidenced by some of the comment spam at the bottom of that post.

Please note for the record that I consider this blog a small one-person effort, which couldn't hope to keep up with the extensive amount of work the Attrition.org team put into maintaining this now "historical database."

Maybe this will be the last time, I can thank them publicly. Saying that, I will do so one last time for all they "did" for who really matters in the growing problem of too much information being stored in not very safe places. If you want to know who I am referring to, all you need to do is look in the mirror.

After all, most us have probably had our information compromised (sometimes more than once) in one of the data breaches catalouged in the Data Loss Database - Open Source.

I guess the old saying is true, "money is the root of all evil."

You can read the post from Attrition on this matter on their site, here.

Update 4/17/08: It appears that the DDLOS database might not be completely inactive. Emergent Chaos and Entering the Networked World are reporting that the database is generating new material.

If you go to Attrition's news page, Lyger has done a post "A new beginning." In it he announces a partnership with a new identity theft protection service:

Going forward, we would like to announce that we have a new partnership with Identity-Love-Sock, a trusted provider of identity theft prevention services. Not only can Identity-Love-Sock protect YOU from IDENTITY THEFT, it also provides several guarantees for your PROTECTION should YOU be affected by IDENTITY THEFT. With the services provided by Identity-Love-Sock , YOU will NEVER have to WORRY about your IDENTITY being STOLEN, MISUSED, or otherwise COMPROMISED. For more details on how YOU can be COVERED and PROTECTED, please visit Identity-Love-Sock . You'll be glad you did.

Hmmmm...I've been looking for an ehtical way to monetize this blog, I wonder if they are accepting affiliates?

Saturday, March 08, 2008

Symantec releases March Spam and Scam Trends

Even though scams don't all originate on the Internet, a great majority of them do. If you ever want to figure out what scams are making their rounds, taking a look at spam analysis is a pretty good way of doing it.

Spam is the vehicle that most cyber misfits seem to prefer when trying to pull a fast one on the unwary. Fortunately, most of them are far from geniuses and all it takes is a little awareness to foil their attempts at trickery.

Of course, providing a little body armor for your system is highly recommended, also. Especially, if you are a Windows user.

Please note that when providing body armor for your system to make sure you are buying it from a reliable vendor. I see spam come-ons for so-called computer security software that might turn your system into a spam spewing zombie, steal all the information from it, or a combination of both.

Last week, Symantec released their March report. This report is a good resource to use to see what is going on in the wild world of spam, scams and malicious software.

Kelly Conley writes:

Social engineering was the driving force behind spammers during the month of February. While overall spam volume hovered steadily at 78.5% of email and tactics remained relatively the same, the use of events, big brands, and public figures drove spam campaigns during the month. The March State of Spam report highlights several of these.

Kelly brings up another point -- which is that despite the fact that scams frequently use technology as a tool -- they also rely on a healthy a dose of social engineering (trickery) to accomplish their intentional misdeed.

Predictably, the presidential candidates are a big lure:

Last month, spammers began to spread bogus links purporting to show a Hillary Clinton speech, but in actuality the links were cloaking a malicious Trojan. Most recently we’ve seen spammers leveraging the last remaining front-runners of the 2008 presidential elections; Obama, McCain, and Huckabee. Just what are spammers linking the candidates with? Everything from Viagra, porn, get-rich-quick schemes, and portable dewrinkle machines.

If you think about it, this shouldn't surprise very many of us. After all, the candidates are filling up our mailboxes with a lot of political spin and requests for financial support, also.

It's probably a good idea to be careful when clicking on a link in any unsolicited messages. Especially, when over 75 percent of all e-mail sent is spam.

Of course, politicians aren't the only human lures spammers use. Celebrities are pretty good "spam fodder," also.

The presidential candidates aren’t the only targets. Also seen were high profile names such as Michael Jackson, Heather Mills, and Indiana Jones to name a few. Spammers are using these names to spread malicious links to videos and the names being circulated are all currently high profile. Who hasn’t heard of the McCartney/Mills divorce or Britney Spears’ woes? The spammer is banking that you want to know more about these celebrities and are therefore leveraging their names to tempt you into opening the malicious link. These are fairly easy to spot because in most cases the names are misspelled. I wonder what Paul McCartney would think of his name more closely resembling a martini (Maccartni)?
It never ceases to amaze me that spammers can't spell. A common demoninator in most scam letters is that a lot of words are misspelled. Especially, the variety that orginate out of Internet cafes in third world countries.

Other notable trends in the lures being used are International Women's Day and (too good to be true) offers of free tickets from Southwest Airlines.

The monthly reports normally includes an amusing, or not so amusing (reader's choice) "hall of shame" category. This month the mortgage crisis is being used, with a sick twist:

As economic conditions have slowed in recent months, Symantec has observed a torrent of spam messages encouraging users to “refinance before its too late,” ”take out a mortgage for the lowest APR ever,” or “this is the time to be the proud owner of your house.” While the deluge of finance spam continues, spammers have also decided to diversify their sales portfolio to include the buying and selling of burial plots. Talk about an idea to get out from being buried, no pun intended. As the message indicates, the U.S. national average price for a burial plot in 1978 was $200 and this has risen to $4500 in 2008. “Get started today” – adverts say – “because tomorrow could be too late”.
In case you missed the link to the full report (above), it can be seen (with some interesting screenshots), here.