Wednesday, July 07, 2010
Phony Collectors Want Your Credit/Debit Card Information
Please note, there might be a reason for alarm even if you don't think you owe a debt and a collector calls. With more and more people becoming identity theft victims, a call from a collector could be the first notification a person gets that someone else is using their information. Of course, in this instance, since the calls were bogus, it was not the case. In fact, if you give these scammers any information they can use, you will likely become an identity theft victim yourself.
The person who provided me with this information also provided me with the number she was called from. I called the number and, after a slight delay, I got a person with a Indian accent, who identified himself as "William Scott" from ACS, Inc. Leading him on, I told him my wife was always getting us into trouble by borrowing money — and that we had received a message to call them. He asked me for my wife's name and I made one up. He then told me to wait a minute, while he looked up the file. After about a minute, he said he had located the file and that she owed $500.00, and said this was a "serious legal issue we needed to get cleared up right away." He even offered to settle for $300.00, if I paid that day with a debit/credit card.
During my conversation with William, I could hear the chatter of other calls being made. Listening carefully, I noted that all the people, "chattering" in the background seemed to have Southern Asian (probably Indian) accents. This leads me to believe that the call was being forwarded, possibly overseas. This is not hard to do and there are a lot of legitimate call centers where callers are forwarded from a local number, all over the world.
I gave him an e-mail address so he could send me a payment authorization form and he told me to fill it out, sign it and e-mail it back to him. About an hour later. I got the form coming from an e-mail address, acscorpusa@gmail.com. It asked for personal identifiers, the card number, billing address, zip code, expiration date and CVC number. There is very little doubt in my mind if I had sent the form back to him the account I gave them would have been promptly cleaned out.
I ran the number (813-434-4611) on a site called PhoneValidator.com, which tells you what company a number belongs to and if it is a cell phone or a landline. This number belongs to a PaeTec Communications in Tampa, Florida. PhoneValidator.com offers two additional tools after you run the number. One is primarily a paid search (how they make money), but they offer Google results, also. When I ran the Google results, it identified the same scam, I had run into. One site, 800notes.com, had quite a few comments about it.
The payment authorization letter listed a fax number of 646-786-4401. I ran that number and it went to a landline in New York. Again, I ran the Google results, which revealed more people getting faux collection calls. Besides the fax number on the authorization letter — designed to clean out a payment card — was another number (813-435-1963) to call them back. Although, it was another Tampa number, it went to different telecom outfit. By running the Google results, lo and behold, more complaints about phony collection calls were found, some of which stated that some pretty crude and disgusting comments were made by some of these fake collectors.
Based on the comments I found, it appeared that this activity had been going for a long time, and the Indian accents seems to be a common theme. I did report this to the authorities — but besides getting an initial call back — I haven't heard anything from them since then.
It is not uncommon for scammers to set up legitimate sounding numbers, either. As long as the bill gets paid, very little due diligence is conducted by telecom types to ensure a number actually belongs to what it says it does. Sometimes the numbers are paid for with stolen financial instruments, and it is not uncommon to call one back a week later and find it has been disconnected.
I did more research on this activity and discovered that the BBB had an interesting write-up about similar (if not the same) fraudulent collection activity. The report lists 67 complaints they had received. Another write-up in August of 2009 from the BBB suggested that the scammers had so much personal information about the victims — a data breach was suspected. In this case, it was reported that the people behind this had social security numbers, addresses and knew how to contact their victim's relatives. It also stated that people were being threatened with criminal prosecution, if they did not pay.
If you are called by a collector and you do not know anything about the debt they are talking about, you should always ask them to send you documentation proving that you owe the debt. The Federal Trade Commission (FTC) has information on their site on what your rights are and the specific laws that legitimate collection agencies have to follow. You can also file an online complaint (highly recommended if you suspect abuse) and even watch a video on how to do it properly. They also provide a number (1-877-FTC-HELP (1-877-382-4357); TTY: 1-866-653-4261) if you want to speak with a live human being.
The phenomenon of fraud by telephone is becoming more and more common. Officially dubbed "vishing," which is phishing by telephone, the people behind it spoof financial institutions to gather personal and financial details to commit identity theft and financial crimes. Cheap long distance — enabled by VoIP (Voice over Internet Protocol) — and caller ID spoofing (which is legal) have made vishing pretty easy to accomplish.
If you get a phone call that doesn't make sense, take a deep breath and then make sure the person calling you is legitimate before proceeding!
Monday, June 08, 2009
Trust Caller ID, Become a Crime Victim!
Saying that, telephone technology, which has grown rapidly in recent years, has given fraudsters a wide array of new tools to use to depart common people and even large businesses from their hard-earned money.
Take caller ID for instance, which is marketed as a means of protecting our privacy. When I say marketed, it's normally sold for a fee so we can see who is calling us. The irony of the situation is that for a fee, just about anyone can make the caller ID appear to whatever number they desire.
The ability to spoof (fake/impersonate) caller ID has been around for a few years. Collection agencies, private investigators and even law enforcement agencies use it to get people to answer their telephone. In these instances, they are normally paying the telecom company for the service. I guess this means the people selling caller ID and the ability to spoof it are making money on both sides of the fence.
While some might argue the semi-legitimate (?) uses are deceptive in themselves, I'm far more concerned when criminals or malicious beings use it to further one of their schemes.
For instance, caller ID spoofing has been used to dispatch a SWAT team to an unsuspecting person's house, and a Pennsylvania man made obscene phone calls to women and made the caller ID appear as if they were coming from within the house. It has also subjected a lot of people to abusive return phone calls when their number was spoofed and angry consumers wanted to complain.
Of even greater concern is when caller ID spoofing is used by "stalkers." In January, Alexis A. Moore did a very well researched post on her blog about this subject. Moore is a "crime victim advocate and expert in cyber stalking, identity theft, traditional stalking, domestic violence and privacy protection," according to her profile on Blogspot.
Before I move forward, please note that it seems to have worked on a 911 dispatch system. In this case, law enforcement – who is known to spoof their numbers – is being victimized by the same technology they use to cloak calls themselves. Please note that if anyone should be able to legally spoof calls, it’s probably law enforcement. Nonetheless, it is ironic.
More and more frequently, caller ID is being used by organized (and maybe some not so organized) criminals to commit fraud.
Last month, spoofing caller ID was reported to be used as a tool by an international credit card fraud ring that was broken up by the NYPD and the Queens District Attorney's office. The ring was using an easily purchased portable spoofing tool, known as a Spoof Card. Spoof Cards can be bought by anyone who has the money to buy them, right over the Internet! Besides spoofing a number, the cards can be used to disguise a person's voice and gender.
The ring, which was described as stretching from New York to Nigeria, obtained cards and activated them using a number they spoofed as legitimately belonging to the intended recipient of the card. Please note, most banks require you to activate a card from a known number when you receive it in the mail. I wonder how many of these same banks are using caller ID spoofing technology in their collections departments.
While the methods used by this group included counterfeiting, mail theft, taking over accounts and fraud applications to get the cards, using a Spoof Card was obviously a pretty successful tool used in furthering the fraud scheme. The victims were from all over North America and the cards were used worldwide. According to the authorities, the financial impact of this activity was estimated at $12 million in the past year alone.
While devices like Spoof Card are an issue, the problem doesn't stop there. Semi-legitimate (?) marketing firms, such as Voice Touch, Inc. and Network Foundations LLC – ones that the FTC shut down last month – were using robocalls with spoofed caller IDs. Of course, there were a lot of complaints that these warranties they were selling (provided by Transcontinental Warranty, Inc.) were virtually useless if you tried to use them, too.
Spoofing caller ID has led to a rash of vishing (phishing by telephone scams), also. Last year in November, I wrote about a call I was getting offering to lower my interest rate. The calls in question were robo-generated and the intent was to get you give up your credit card numbers to a scammer. As of this month, I received another one of these calls. Besides this particular scam, there have been numerous reports of financial institutions having their telephone numbers spoofed in vishing schemes.
Of course, Spoof Card isn't the only spoofing service out there. Some services offer software programs that can be used to spoof calls over a Web interface. One even calls itself PhoneGangster.com.
The services that allow it to be done over a Web interface enable the activity to be performed on a much larger scale. A simple Google search for "caller ID spoofing" brings up all kinds of Adsense ads selling a wide range of caller ID spoofing services. Of course, I shouldn't single out Google or Adsense; my guess is that any search on most commercial browsers will net the same type of advertising.
With VoIP technology in full vogue and services like Skype, the fraudulent use of caller id spoofing services now can feasibly be done across borders. This will make it much more difficult for law enforcement agencies to investigate and prosecute these cases.
In 2007, two bills were sent to the Senate to address caller ID spoofing. Neither was voted on and as a result no effective law has been put into place to address this issue. This year, Senator Bill Nelson (FL) and three co-sponsors introduced another bill (S.30) dubbed "The Truth in Caller ID Act."
In my humble opinion, the need for this legislation is pretty apparent. Laws are designed to protect people and it there are too many good reasons people need to be protected from caller ID spoofing!
The right place to file a complaint about something like this is the Federal Trade Commission. To file a complaint in English or Spanish, visit the FTC’s online Complaint Assistant or call 1-877-FTC-HELP (1-877-382-4357). There is also a link on the page to file a complaint on an overseas entity.
You can also write your representatives (elected officials) and encourage them to make 2009 the year that they finally pass some legislation on this issue.
Tuesday, February 03, 2009
Increase in Scams Attributed to Economy
I just finished reading an interesting article in the Wall Street Journal by M. P. McQueen, which suggests that the bear market is creating a bull market for fraudsters. According to the numerous experts cited in the article, the reason for this is economic gloom and doom with a healthy dose of anxiety.
This shouldn't be surprising because gloom, doom, and anxiety make effective social engineering tools that can be used to part people and businesses from their money.
The article references phishing expeditions that lead to fake Web sites — which often spoof a financial institution or government entity — and entice people into giving up enough of their personal details to drain their financial resources. It also mentions that some of these sites leave behind malicious software on a person's machine, which steal all these details automatically.
Also mentioned is the use of VoIP (Voice over Internet Protocol), caller-ID spoofing and cell phone technology to mount texting and vishing attacks. Vishing is merely another method of tricking people to give up personal and financial information via the telephone. In these attacks, the caller ID is spoofed to make it appear as if it is coming from a legitimate institution.
Apparently telephone technology is being used to commit other types of crimes, too. Many of our 911 centers cannot identify spoofed calls coming from computers using VoIP technology. This has led to S.W.A.T. teams being tricked into deploying in full battle gear to residential neighborhoods when no emergency existed. Of course, businesses use the same technology to trick people who have caller ID into picking up their telephones. You can even buy a card to do this at will from any telephone right over the Web.
It sometimes amazes me how much irresponsible technology there is out there, which is being sold legally. There are even Web sites, with disclaimers, that specialize in making this technology available to the general public. Of course, there are also complete DIY (do-it-yourself) phishing kits being sold over the Internet. Some of these even come with tech support. The phishing kits are illegal, but can be found for sale in chat rooms if you know where to look for them. Sadly, the truth is that these chat rooms aren't very hard to find. The fine line between legitimate enterprise and scams is often a little blurry.
The WSJ article quotes a lot of experts, including Gartner, the FBI and the National White Collar Crime Center, who all seem to agree that scams are on the rise. An interesting phenomenon called out were small fraud charges being found on accounts. I guess taking small amounts, which might be mistaken for bank fees, is a good way to stay under the radar. A lot of people don't realize how many small fees are being charged to their account and it can be quite confusing at times. I guess the crooks are trying to make themselves look like bankers (speculation) and it's probably a good time for all of us to review our statements, carefully.
Speaking of fees, which are used as revenue streams by a lot of businesses, the WSJ put out another article this entitled, "In the Fight Against Bill Creep, Every Extra Fee Is the Enemy." Besides being on the look out for cyber scammers, this article points out other reasons it is smart to review our financial statements with a keen eye these days.
Another notable trend in the past 12 months is executives being targeted. In this trend, specific people within organizations are being targeted and tricked into downloading malicious software on machines. In one of these scams last April, the targets were led to believe they were being subpoenaed to testify in federal court.
Last, but not least, the article points out that job scams are on the rise. It's a well established fact that job sites from Monster to Craigslist have scammers operating on them to recruit people to launder money, cash bogus financial instruments or give up all their personal and financial information. Adding fuel to this fire, it was disclosed recently that Monster.com had been hacked.
Capping off this interesting article — which is a pretty good recap of recent scam activity — is Pam Dixon of the World Privacy Forum pointing out that scammers have learned how to use "spell check." In the past, one of the best ways to identify a scam was it's lack of proper spelling and grammar. While the scammers might have have learned to use spell check, it might also point out that there are more and more people out of work (with better grammar skills), who are becoming scammers.
The WSJ quoted a lot of experts that agree with them that scam activity is on the rise. Another interesting read supporting this (not mentioned in their article) is the recent report that was commissioned by McAfee. This report points to all the unsecured data out there that is fueling the rise in cyber crime. They estimate, at this point, that the financial implications have reached $1 trillion. They also have some interesting information about social engineering and how it is being currently used to commit scams in the current economic environment in another set of articles on their main site.
In my opinion, it makes sense that scams of all kinds are on the rise. There is a lot of confusion going on and people are getting desperate. It might be desperation that is causing more people to get involved in scams on both sides of the fence. For the majority of us, who just want to ride these times out and survive the mayhem, the best thing to probably do is be extra diligent in our financial matters and use a little good old fashioned common sense.
Having dealt with a few scammers in my life, I've found that most of them aren't the most intelligent people around. The best thing to do is to think carefully before jumping in anything of a financial nature these days.
Saturday, November 08, 2008
Telephone Call Offering to Lower Interest Rate is a Scam!
The term vishing was coined from the word phishing. Internet scammers phish the waters of the Internet using spam e-mail as bait. Once a person falls for their "too good to be true" lure -- personal and financial information is stolen using social engineering (trickery) or malicious software designed to data-mine the information right off the infected machine. The personal and financial information is then used to commit financial crimes, which is often referred to as identity theft.
In the past week, I've received several calls where a computerized voice informs me that the offer to lower my interest rate is almost over. It then says to press "1" if I want to lower my interest rate.
I went ahead and pressed the number "1" to see what this "too good to be true" offer was all about. After a few seconds, a female voice came on and asked me if I was interested in lowering my interest rate. I told her I was and she asked me for the 800 number of my financial institution so she could verify my eligibility. Since this is public information, I went ahead and gave one to an institution, I no longer do business with. While I was digging up the number on the Internet, she made a lot of inquires about how many lines of credit I was behind on. After providing her with the 800 number, she asked me to give her all the credit card numbers that I wanted to lower the interest rate on.
At this point, I had very little doubt I was dealing with a scam designed to steal credit card numbers. At no point did she identify a financial institution -- and besides that -- no financial institution would make a cold call and ask for credit card numbers. Additionally, when was the last time a financial institution offered to lower an interest rate to an existing customer unless they were being bailed out by the government (taxpayer)?
I asked if she felt good about ripping people off and if I could speak to her supervisor. Of course, I was never referred to a supervisor and after cursing at me, she hung up. Trust me, from the vulgar language that was expressed, this call was not being recorded for training purposes!
In the past couple of years, we've seen reports of vishing. In the case, I'm writing about a dialer system is obviously being used. Dialers are used by collection agencies, telemarketing companies, political campaigns and even charities to direct calls to live employees. Basically, dialers screen the calls via computer to make the process more efficient.
Having never priced one, I decided to see what Google had to offer. I found them to be rather inexpensive starting at a mere few hundred dollars. There were also options to use already set-up systems on a cost-per-call basis.
Caller-ID spoofing services can be purchased legally and are used by a lot of legitimate companies to entice us to pick up calls. Because of this, it is probably wise not to put your faith in caller-ID.
Some blame VoIP (Voice over Internet Protocol) technology for vishing. VoIP has made calling long distance cheap.
So far as where the victim lists are obtained, they can be easily purchased. My phone number has been unlisted for over 20 years, but information brokers data-mine information from every source imaginable, including magazine subscriptions. Since these lists are worth money, companies who gather information routinely sell the marketing information they gather on all of us. It also isn't unknown for dishonest employees to sell information directly to criminals. Often this is done right on the Internet in chat rooms, which keeps the transaction fairly anonymous.
Recently, the FBI announced that they stung an Internet forum used to sell stolen information known as Dark Market. At it's peak, the group had 2500 registered members and it is estimated that they prevented losses of $70 million (worldwide) by cracking this case.
Even the IRS and Social Security have been impersonated in the past two years in vishing schemes.
InsideCRM magazine recently published an article detailing 50 ways to protect your privacy. This magazine represents the call center industry and has a stake in fighting vishing activity, which gives legitimate e-commerce a black eye. If you (like a lot of us) enjoy the hassle-free environment shopping at home, the article is a great educational resource.
The U.S. government has also set up a highly visual and interactive site to educate people about crimes being enabled by technology. Please note this site is available in Espanol, also.
While both of these sites are designed to cover computer security issues in addition to telecom type scams, we need to remember that a lot of these scams probably started before telephones or computers made them easier to do, as well as, more efficient.
Scams rely on human emotion and greed. Knowing this is the best way to prevent yourself from becoming a victim. The "too good to be true" principle coupled with "does the transaction make sense" is the best way to figure out whether an offer is legitimate or NOT!
Monday, September 15, 2008
Virtual Kidnapping - A New Version of a Confidence Trick!
Not all the kidnappings in Mexico and the United States are real. The US Immigration and Customs division gets reports of virtual kidnappings, where the intent is to extort money, but the alleged victim is safe and sound.
The kidnappers appear to be able to find out who is traveling to Mexico and/or is coming into the US illegally. They then call a family member or loved one, claiming they have the tourist or illegal immigrant hostage and demand money for their safe return.
I happened to pick up this story on Fox News, which reported that Immigration and Customs in Phoenix gets a report about once a week of smugglers holding a hostage. Although 75 percent of them are real, about 25 percent are bogus, according to the story.
The reason the virtual scam works is probably that real cases of people being kidnapped are becoming commonplace south of the border. In April, CBS News reported that a hotline set up in Mexico City to deal with extortion cases had received 44,000 calls since December. The hotline statistics recorded were 22,851 extortion attempts avoided, 3,415 telephone numbers identified as being tied to extortionists, and 1,627 people who paid off the virtual kidnappers.
In another version of virtual kidnapping, an illegal immigrant already in the country is contacted and told that a family member is being held hostage in Mexico. It's not unknown for smugglers to hold onto a family member and extort money from illegal immigrants whom they have brought across the border. With all the real kidnapping going on, it makes sense that fake ones seem legitimate.
In April, the New York Times did another story on virtual kidnapping. In their article, they speculated that at least some of it was being done from Mexican prisons. Apparently, the guards look the other way as long as they get a cut of the action. The article also mentioned that besides virtual kidnapping, other telephone scams are rampant in Mexico, like the sweepstakes variety, a type of the infamous advance fee (419) scam.
Network World asked why this type of kidnapping is referred to as virtual. Paul McNamara wrote a interesting piece pointing out that the term "virtual" doesn't really fit in these cases. "The crime itself is horrific — beyond comprehension in its cruelty — so there's some hesitancy to complain about semantics. But this is a technology column and the underlying issue — society's tendency to blame modern-day bad deeds on technology instead of the bad-deed doers — is an important one," according to McNamara.
He makes a very good point: scams designed to part people from their hard-earned money didn't start with the computer age. Confidence tricks have been around for a long time and virtual kidnapping is merely that, a confidence trick. A good example is what is known as the Spanish Prisoner letter, where someone was tricked into thinking they were securing the release of a wealthy individual (who couldn't reveal their own identity) from prison in return for future compensation. This particular scam dates back to well over 100 years ago.
The Internet is full of too-good-to-be-true scams, which use greed to lure victims. Besides greed, fear is another lure scammers use. We see this on the Internet in threatening letters allegedly from government agencies, or even in what is known as the hit-man scam. In the hit-man scam, a person is intimidated into paying someone off to remove a contract that has supposedly been taken out on their life.
Scams using the telephone are becoming more and more common as well, dubbed "vishing." Here the telephone is used to perform confidence tricks of all sorts, and/or to steal personal and financial information later used in identity theft schemes.
This doesn't take away from the fact that a lot of people are victimized because of the not very secure situation we have on our border. It often seems that the criminals are more in control than the authorities, and besides confidence tricks, we see an overabundance of crimes that threaten public safety and, some say, our national security.
Until we take the control of the border away from criminals, we are going to continue seeing a lot of people victimized.
Tuesday, June 24, 2008
Inside CRM publishes 50 ways to protect your privacy!
The article intended to provide useful tips to protect the average person from fraud, phishing, and all the assorted financial misdeeds facing the average person in today's world. The tips provide information on how these scams originate and emphasize how a person can take back control of their personal and financial information.
The article covers how to protect yourself both on and offline and how you can track your personal information on the Internet. Although I've seen many of these tips before, putting them all in a one-page format makes this article a useful tool. Along with the fifty tips are useful links, which direct the reader to the source material about the particular tip.
The CRM industry has a stake in fighting the battle against scams that are being made easier by technology. Consumer trust is a key factor in any type of business involving customers.
One growing concern that can give the industry a bad rap (even though the legitimate CRM center had nothing to do with it) is a phenomenon called vishing where personal information is stolen by calling people up on the telephone. This type of activity is a growing phenomenon. In most cases, the crooks impersonate a legitimate organization when doing this.
My personal tip on how not to get caught in a vishing expedition is to remember that no reputable organization will ever call (unsolicited by you) and ask for personal or financial information. If this occurs, a red flag should go up in your head and I recommend verifying the number via a known third party source and calling them back. Do not rely on caller ID; spoofing services (which fake caller ID) numbers are available to anyone with the capital to purchase them on the Internet.
The article lists some useful tips when dealing with VoIP (Voice over Internet Protocol) technology, which many believe is the cause in the recent surge of vishing activity. The reason for this is that it has made calling long distance cheap and vishing scams now come from all over the world, making them hard to investigate or trace.
Additionally, CRM centers often deal in personal and financial information. One of the biggest consumer trust issues that faces the industry is when information is breached from within a CRM center. Recent reports of information being stolen at CRM centers have made internal security at CRM centers a priority.
Please note that CRM centers are not the only places personal and financial information are compromised. This is becoming a sad reality and any business that deals in "information" needs to be aware of the potential risks of having this valuable commodity stolen from under their noses.
Most technology scams involve healthy does of social engineering (human trickery) to make them work. Education is the best defense against social engineering and InsideCRM has provided all of us with a valuable tool to do this with!
Saturday, June 14, 2008
Phishermen stealing food from the mouths of Children
The FBI and IC3 are reporting that EPPICards, which are set up as debit cards to disburse child support payments are the latest target of the phishermen.
In this instance, they are literally stealing food from the mouths of children.
From the FBI press release:
The FBI and its partner, the Internet Crime Complaint Center (IC3), have received reports of phishing attacks targeting users of EPPICards. The EPPICard is similar to a debit card. EPPICards are issued by a state agency for the purpose of receiving child-support payments. The cards are currently used in 15 states.My humble guess is that if a parent is being forced to support their children by loading funds on a EPPIcard, the kids in question could really use the money.
Individuals have reported receiving e-mail or text messages indicating a problem with their account. They are directed to follow the link provided in the message to update their account or correct the problem. The link actually directs the individuals to a fraudulent web site where their personal information, such as account number and PIN, is compromised.
If you happen to spot one of these phishing or vishing attempts, please take the time to report it to IC3.
If you want to learn more about phishing and other related Internet scams, the Federal Trade Commission (FTC) recently posted a series of videos on YouTube that can be viewed, here.
Full press release, here.
Saturday, February 02, 2008
The IRS must be a great lure to go phishing and vishing with!
The odd thing is the come-on, a tax rebate, hasn't even been approved yet.
The most accurate information I could find on this latest trend was from the IRS, who is being impersonated once again. They've gained considerable experience with this type of scam recently with their name being used (frequently) as a fake "badge of authority" (lure) to trick people into becoming an identity theft statistic.
From the IRS site (published on January 30th):
The Internal Revenue Service today warned taxpayers to beware of several current e-mail and telephone scams that use the IRS name as a lure. The IRS expects such scams to continue through the end of tax return filing season and beyond.The bottom line is that the IRS is not going to send you an e-mail, or call you on the telephone asking for personal information.
The IRS cautioned taxpayers to be on the lookout for scams involving proposed advance payment checks. Although the government has not yet enacted an economic stimulus package in which the IRS would provide advance payments, known informally as rebates to many Americans, a scam which uses the proposed rebates as bait has already cropped up.
The goal of the scams is to trick people into revealing personal and financial information, such as Social Security, bank account or credit card numbers, which the scammers can use to commit identity theft.
Trust me, they already have it if you are due to receive money from them!
Variations of the recent scams include a tax rebate phone call, refund spam e-mail, audit e-mail (besides money fear is a common lure), changes to tax law e-mail, and a telephone scam claiming the IRS has sent a paper check and needs to verify your banking information.
So far as the e-mails, they sometimes contain links that load malicious software (designed to steal more information). Although not mentioned in the IRS release, a new phenomenon called "drive by pharming" was recently seen in the wild (on the Internet).
Here is what I wrote about "drive by pharming" in a previous post:
"Pharming (pronounced farming) is a Hacker's attack aiming to redirect a website's traffic to another, bogus website. Pharming can be conducted either by changing the hosts file on a victim’s computer or by exploitation of a vulnerability in DNS server software," according to Wikipedia.Spam e-mail is becoming more dangerous all the time. Most of these lead to fake websites, or blogs that can download malware on a system by merely visiting them.
So far as the surge in using the telephone to scam information, often referred to as vishing -- VoIP technology (super cheap long distance) has made this easy to do. From what I hear, a lot of it is being done across International borders, which makes prosecution difficult, also.
The IRS release warns that the caller might sound foreign. This is a good tip, but with call centers being outsourced all over the world, it's becoming pretty common to speak to someone on the telephone with an accent.
The safest bet is to give out no personal information to anyone, no matter how official they might seem when they it solicit via telephone, or over the Internet.
The press release does offer resources to report any suspected scams. Please note, that paragraph one is an extremely good tip!
Anyone wishing to access the IRS Web site should initiate contact by typing the IRS.gov address into their Internet address window, rather than clicking on a link in an e-mail or opening an attachment.IRS release, here.
Those who have received a questionable e-mail claiming to come from the IRS may forward it to a mailbox the IRS has established to receive such e-mails, phishing@irs.gov, using instructions contained in an article titled “How to Protect Yourself from Suspicious E-Mails or Phishing Schemes.” Following the instructions will help the IRS track the suspicious e-mail to its origins and shut down the scam. Find the article by visiting IRS.gov and entering the words “suspicious e-mails” into the search box in the upper right corner of the front page.
I know a lot of us simply hit delete when we see this stuff, but if it didn't work, the phishermen wouldn't keep doing it. We should all consider reporting it a "act of kindness" towards those, who might fall for this.
The people at the IRS fighting this could certainly use the HELP! It might eventually lead to the people behind this being held accountable.
Those who have received a questionable telephone call that claims to come from the IRS may also use the phishing@irs.gov mailbox to notify the IRS of the scam.
Previous posts about the IRS being used as a lure from this blog, here.
Tuesday, December 11, 2007
Human beings are the reason for most security breaches!
The New York Times reported:
A cyber attack reported last week by one of the federal government’s nuclear weapons laboratories may have originated in China, according to a confidential memorandum distributed Wednesday to public and private security officials by the Department of Homeland Security.
Although the article suggests China may behind this attempt, the article suggests they have plausible deniability:
Security researchers said the memorandum, which was obtained by The New York Times from an executive at a private company, included a list of Web and Internet addresses that were linked to locations in China. However, they noted that such links did not prove that the Chinese government or Chinese citizens were involved in the attacks. In the past, intruders have compromised computers in China and then used them to disguise their true location.
I guess it might have been a host of undesirables trying to steal this information. A lot of Internet misfits redirect through China to do their misdeeds on the Internet.
What's scary is that eleven employees at a Nuclear Research Facility clicked on a phisy e-mail and compromised sensitive material.
I recently wrote a post, where an official government audit revealed that 60 percent of IRS employees tested fell for a vishing scheme and gave up sensitive information.
Vishing is stealing information by telephone.
It was recently announced that private investigators are being indicted for vishing infomation in an illegal manner, sometimes referred to as pretexting.
All of these events would suggest that businesses and government organizations have a big opportunity when it comes to raising employee awareness on social engineering schemes that are used to compromise sensitive information.
IT also illustrates that human beings are the common cause for most breaches of security!
New York Times article, here.
Here are the two previous posts on the IRS vishing test and the indictment of private investigators for using social engineering techniques:
IRS audit reveals that the human factor is one the greatest threats to information (computer) security
Private Eyes charged with aggravated identity theft
Saturday, December 08, 2007
Private Eyes charged with aggravated identity theft
Here is another case involving private investigators using illegal techniques to data mine information for their clients:
Ten people were indicted by a federal grand jury in Seattle in connection with a scheme to illegally obtain confidential information on more than 12,000 citizens across the country. To obtain confidential tax, medical and employment information, workers at BNT Investigations in Belfair, Washington, would pose as another individual to get government agencies including the IRS, the Social Security Administration, and various state employment security offices to provide confidential information. The year-long investigation dubbed, “Operation Dialing for Dollars,” also revealed that some workers posed as representatives of doctors’ offices to get medical or pharmacy records.The private investigators used "pretexting," which is a social engineering technique designed to trick people into giving up personal and financial information. Criminals use the same technique to steal people's identities.
In fact, phishing, where an e-mail is sent impersonating a trusted or authority figure with the intent of stealing personal information is a form of "pretexting."
In this case, we might term what these private eyes did as "vishing," which is phishing using the telephone.
It appears that the U.S. Attorney's office agrees that this is little difference in the techniques used by these private eyes and is charging them all with aggravated identity theft.
The ten defendants are charged with Conspiracy and Wire Fraud. Seven of the defendants are charged with Fraudulent Elicitation of Social Security Administration Information. Six of the defendants are charged with Solicitation of Federal Tax Information. All ten defendants are charged with Aggravated Identity Theft. The three Washington defendants are scheduled to appear in U.S. District Court in Tacoma at 2:30 today.
These are the defendants indicted by the grand jury:
EMILIO TORRELLA, 36, Belfair, Washington
BRANDY N. TORRELLA, 27, Belfair, Washington
STEVEN W. BERWICK, 22, Belfair, Washington
VICTORIA J. TADE, 52, San Diego, California
MEGAN OSOSKE, 40, Beaverton, Oregon
DARCI P. TEMPLETON, 55, Houston, Texas
ESAUN G. PINTO, Sr., 33, Brooklyn, New York
PATRICK A. BOMBINO, 58, Brooklyn, New York
ROBERT GRIEVE, 67, Houston, Texas
ZIAD N. SAKHLEH, 26, Houston, Texas
The Torellas, who own BNT investigations, allegedly are the "phishy-investigators" who were selling this illegally obtained information to their peers nationwide.
The private investigators had been hired by attorneys, insurance companies and collection agencies to investigate the backgrounds of opposing parties, witnesses and benefit claimants, and to uncover assets or income. The TORRELLAs promoted their services to the private investigators.
BNT investigations targeted financial institutions and government agencies to get the information they were selling.
This makes me wonder how much the people paying for these services knew and to what extent they might be held liable?
Although, it doesn't appear that more sophisticated spying (identity theft?) techniques were used in this case, in the Hewlett Packard case investigators dropped software (malicious?) on computer systems to monitor the people they were "investigating."
Press release from the Western Washington U.S. Attorney's Office, here.
Saturday, August 04, 2007
IRS audit reveals that the human factor is one the greatest threats to information (computer) security

(Courtesy of Flickr)
A new report issued by the Treasury Department's inspector general reveals that too many IRS employees compromised their user ID and password to an unknown person, who was actually a government auditor posing as a help desk employee.
Sixty percent of the IRS employees fell for the social engineering trick, sometimes referred to as vishing. This isn't the first time a test like this has been conducted. In 2004, 35 percent of the employees tested compromised information and in 2001, the failure rate was 70 percent.
In the recent past, the agency has also been criticized for it's aging computer systems and their name has been spoofed (impersonated) in phishing attacks.
I guess the IRS makes a good story, but they certainly aren't the only government agency, or private entity being compromised by activity like this.
Whether it's vishing or phishing -- where social engineering (fraud, deception etc.) techniques are used to trick people into giving up access to information that should be protected -- human beings are probably the biggest threat to information (computer) security.
True, the results of this report are shocking, but maybe we should listen to what it is telling us? If social engineering didn't work, my guess is that a lot of the current explosion in phishing and vishing activity would go away.
Even when malware, often referred to as crimeware, which steals information using technology is used, a human being has to be lured into clicking on a link, or visiting certain websites for the software to be implanted.
Maybe one of the problems is that people, who fall for these ploys are reluctant to admit they were tricked so easily? I've seen a lot of people fall for social engineering ploys, and not all of them are poorly educated, or what most of us would consider, stupid.
In fact, many us would probably be amazed at exactly who falls for social engineering ploys. Most people would rather remain anonymous because it's embarrassing to admit they were conned into whatever scheme they fell for.
Of course, the people I'm referring to have asked me to respect their privacy, and I'm an advocate of protecting that, along with being kind to victims, also.
Whether it is a government agency, big business, or non profit being targeted, the only thing that is consistent is we see more and more of this activity all the time. Trust me, if it didn't work, the criminals behind it wouldn't be wasting their time doing it.
If the activity is increasing, and social engineering it tied into most of it, the best thing we can do to defeat it, are more tests like these, combined with an effort to make people more aware of the problem.
While the results of this report aren't good, at least they are making the information public and not hiding it. My guess is that IRS employees aren't the only ones, who would fall for something like this.
Education and awareness are key in stopping this problem, which keeps growing by leaps and bounds!
Inspector General (Treasury Department) report, here.
Friday, July 13, 2007
If Social Security calls requesting personal information, it might be smart to verify who you are talking to!

(Nice Photo courtesy of Long N at Flickr)
If you get an unsolicited call from an "alleged" Social Security employee, it might be wise to verify (independently), who is calling you. Of course -- you should do this by using a number obtained from a legitimate source, and not one pointed to by the person calling -- who might be trying to steal by using your good name.
The Office of the Inspector General, Social Security Administration recently reported:
Over the past several months, the Office of the Inspector General has received a number of reports relating circumstances where individuals have been contacted by someone pretending to be an SSA employee. The caller identifies himself/herself as an SSA employee and may even provide a toll-free number as a point of contact. The caller generally asks for personal identifying information such as:The impersonator may state that "the SSA computers are down" or may refer to enrollment in the Medicare prescription drug program. The intent of the impersonator is to steal your identity and/or funds from your bank accounts.
- Social Security Number
- Date of Birth
- Mother's maiden name
- Bank account information
- Other financial account information
It is possible that an SSA employee may contact you to follow-up on a previous application for benefits, application for a subsidy for the Medicare Part D program, or to follow-up on business you have initiated with SSA. If you are unsure as to the authenticity of someone who claims to be an SSA employee, please call SSA's
toll-free number: 1-800-772-1213 to verify the reason for the contact and the person's identity.
More information on this particular scam can be viewed on the link provided to the original press release below.
I always recommend reporting fraud attempts. At a minimum, it helps get the word out and you never know when it will lead to someone getting caught.
Information about the OIG's fraud hotline can be obtained from the Reporting Fraud section of the OIG's website.Link to SSA press release, here.
Scams using the telephone are nothing new, but with VoIP (Voice over Internet Protocol) technology, the frequency with which they are being seen is increasing. The reason for this is that VoIP has made calling long distance cheap.
Telephone scams using VoIP are often referred to as "vishing." If you are interested in more information on this type of scam, I've written some other posts, which can be seen, here.
Impersonating official agencies is nothing new, either. In the recent past, the IRS, FBI, DOJ, FTC and even Interpol have all been spoofed (impersonated) as part of a fraud scheme involving vishing, or it's sister scam, phishing.
Saturday, June 02, 2007
Criminals scam military families using the Red Cross name

Here is a particularly ghoulish scheme reported on the Red Cross site:
The American Red Cross has learned about a new identity theft scam targeting military families:
The caller (young-sounding, American accent) calls a military spouse and identifies herself as a representative from the Red Cross. The caller states that the spouse's husband (not identified by name) was hurt while on duty in Iraq and was medevacuated to a hospital in Germany. The caller stated they couldn't start treatment until paperwork was accomplished, and that in order to start the paperwork they needed the spouse to verify her husband's social security number and date of birth. In this case, the spouse was quick to catch on and she did not provide any information to the caller.
Just to set the record straight - the Red Cross doesn't notify family members when this happens!
Not sure, where the identity theft ghouls are getting their lists to target military spouses? The Red Cross stated in their press release that the family member isn't identified by name, but this might have changed by now. Recently, I read a story from the New York Times, where a well known data-broker (InfoUSA) was selling marketing lists of senior citizens, known to gamble on the Internet, to lottery scammers.
I’m guessing that data brokers sell telephone lists to market goods and services to the military, also.
Not only are these blood suckers stealing information to enrich themselves, they are also putting military family members through a lot of personal grief, unnecessarily! Imagine what a call like this does to the family member, who receives it!
Red Cross press release, here.
Red Cross main page, here.
These are people that do a lot of good for other people, when they need it!
Thursday, April 12, 2007
Sage Predictions on the State of Cyber Crime from McAfee
Unfortunately, technology grows faster than laws and security fixes. Criminals, who are becoming increasingly organized, realize and exploit this fact, frequently.
The report confirms predictions that exploiting VoIP and mobile devices will become more common.
Vishing will probably become more dangerous than phishing - it adds a more personal (voice) touch to tricking people into giving up their personal details. VoIP (cheap long distance) is one of the reasons for this. Since caller-id spoofing is easily available and legal, it makes sense that a lot of people are going to fall victim to vishing attacks.
Also covered is the growth in music and software privacy. Billions of dollars are being lost in both these areas - systems are now being sold with pirated software already installed on them.
To me, this shows how organized, the activity is becoming!
The report also covers RFID technology (quickly becoming commonplace) and how easily it can be exploited. Despite warnings from a lot of concerned experts, we seem to be implementing this technology at a foolish pace (my emphasis).
McAfee deserves recognition for having the courage (there is a lot of money behind RFID technology) to point out the dangers behind this highly profitable, but dangerous (my emphasis), technology.
Enough ranting for the moment, I highly recommend reading the full report, which can be viewed, here.
Friday, March 02, 2007
Bank's Telephone ID Spoofed in Vishing Scam
A new term (vishing) is being used to describe this kind of fraudulent activity. Scams over the telephone are nothing new, but many experts believe that VoIP technology is making the problem worse.
Michelle Brooks, of the News Tribune is reporting:
More than 1,000 people in the Jefferson City area received a prerecorded phone message Wednesday that sought customer information and claimed to be from “Central Trust Bank”- a name Central Bank does not go by - and, in fact, showed Central Bank's customer service line on caller ID systems.
News Tribune story, here.
Besides stealing from people, a Washington Post story shows how this technology can be used by stalkers and criminals, who are potentially violent (stalkers).
This technology is a favorite of collection and telemarketing types to get people to answer their telephones. Some of the people marketing this technology, claim their intent is to protect privacy.
Of course, some of us believe, that this technology is violating a lot of people's privacy.
One of the most scary examples of this is spoofcard.com. They sell a calling card that not only spoofs the number being called from, but gives their customers the ability to change their voice. The calls are also recorded (accessible by calling a 800 number).
Besides this company, there are many others, that are hawking Caller-ID spoofing. Collection agencies and telemarketing types use the technology to trick people into answering their telephones.
The FTC (Federal Trade Commission) seems to be taking a look at this problem, a list of their press releases on this matter can be viewed, here.
The FCC (Federal Communications Commission) also has a lot of information about the problem on their site, here.
If you are mad about someone doing this to you, the FCC has a complaint form, here.
Isn't it a shame that we constantly see so-called legitimate businesses profiting from technology that victimizes the general population?
Congress needs to work with the FCC and the FTC to pass a law against this abuse!
Saturday, February 24, 2007
FBI issues vishing alert
Many believe it is being enabled by VoIP technology, which has made calling long distance cheap.
The FBI is reporting:
It’s one of the latest breakthroughs in telecommunications—Voice Over Internet Protocol, or VoIP, which enables telephone calls over the web.
And guess who’s hopping on the VoIP bandwagon along with millions of legitimate customers? Criminals, that’s who. They’re using the technology to hijack identities and steal money. It already has a name: “vishing.”
FBI vishing warning, here.
The term vishing comes from phishing, which is still a growing problem. The Anti-Phishing Working Group tracks phishing statistics, which go up (it seems) every time they issue a report.
I've yet to see any statistical analysis on vishing, but it seems to be a growing problem, also.
Legitimate companies don't contact people (unsolicited) and start asking for all their personal and financial details.
Vishing can be reported to the FBI, here.
Wednesday, October 18, 2006
Fraudsters Impersonate Bank Security Departments to obtain CVCs
Probably, not a good idea!
The Sussex Sun is reporting:
A new credit card scam has emerged and police are cautioning people to be leery of phone callers saying they represent a credit card company.
The twist to this latest scam is that the caller does not ask for a credit card number, but for the three-digit security number on the back of the card.
According to police, the caller identifies himself or herself as an employee of VISA or MasterCard working in the security and fraud department.
Sussex Sun Story, here.
The "telephone fraudster" then brings up an "alleged" fraud purchase and when the intended victim claims to have never made it - they are conned into giving up the three-digit number (CVC) on the back of their card.
A lot of e-commerce companies are now requiring this CVC (Card Verification Code) to make online, or telephone purchases.
CVC is an extra layer of protection, common in the credit and debit card industry.
Unfortunately, there is a lot of credit card information being bought and sold in "carder" rooms. From the "carder" perspective, cards with the CVC included are worth a lot more than cards without them.
Link to my most recent post about this, here.
The Sussex article recommends you call your credit card company and report the attempt. I agree with them this since - if you get a call like this - the crooks already have your number!
It's also probably a good idea to take a look at your credit report and make sure they aren't already compromising your information. If they are - I have a lot of links on this site on where to go and seek help.
This activity is also sometime known as "Vishing," Wikipedia already has a good article on this, here.
Thursday, August 10, 2006
Keeping kids safe on the Internet
From the article:
For the full article and additional tips, link here.The Federal Trade Commission reports that in 2005 Americans ages 18 to 24 made more than 69,000 identity theft complaints — more than any other age group. Here are 10 ways students can prevent identity theft and the headaches that come with it.
1. Watch what you blog. Millions of young people keep online diaries that are usually available to anyone surfing the Web. Safe blogging means not posting any personally identifiable information other than your first name, says Linda Foley, co-executive director of the Identity Theft Resource Center in San Diego. "There's nothing wrong with blogging," Foley says. "Blogging can be fun — as long as you do it safely."
2. Don't get caught in a phishing net. Phishers try to steal your personal information by misdirecting you to a counterfeit Web page that looks identical to one you might use to pay a credit card bill or check your cellphone minutes. On this page, they ask you to type in personal information, such as your Social Security number and harvest this information. Doug Jacobson, an associate professor of computer and electrical engineering at Iowa State University, says an easy way to spot phishing is by hovering the cursor over a hyperlink while looking at the bottom of the browser. If the URL displayed seems very long, it's probably a fraud. "Think of the computer as your phone," Jacobson said. "If someone called you out of the blue on the phone and asked for your Social Security number, you wouldn't do it."
Of note, vishing attacks (using the telephone to steal information) are on the rise. I'm not sure I completely agree with Mr. Jacobson on this one.
Young people (too often) are the targets of more serious crimes involving their personal safety.
Here is ANOTHER resource that teaches the young (and us older folks) how to be safe in the cyberworld:
SafeKids.Com
Tuesday, July 18, 2006
Vishing - The New Way to Lose Your Identity
Of course using the telephone to rip-off people is nothing new. Telemarketing scams have been around for years.
The lures used to "dupe" innocent people are normally the same ones used in phishing, like telling you an account has been compromised. It's even possible they might already have some of your information (a lot of it has already been compromised) and be trying to get a credit card's CVC code, or obtain a password to an account.
According to a recent BBC article, the recent bouts with "vishing" started with spam e-mails directing someone to call a number, where they would be prompted to give up personal information. The scam has now mutated (they always do) and now people are being called by "autodialers," which dial number after number and leave a recorded message.
The rise in popularity of Voice over Internet Protocol (VoIP) is being cited by security experts as the reason why vishing is becoming a problem. VoIP has made calling long distance cheap, which means that vishing crosses borders; making it hard to trace and or prosecute.
The BBC article also states that it is relatively easy to spoof "caller-id" with VoIP. Security Focus recently did an article that supports this contention. In the article, a hacker easily showed the reporter how it was done.
For anyone unfamiliar with "spoofing caller id," fraudsters aren't the only ones who do it. In fact, many legitimate corporations use "caller id spoofing services" to trick people (my own words) into picking up the telephone.
For a post, I wrote about this, link here.
So far as how to protect yourself from this sort of scam, I would highly recommend that if you receive any telephone calls (or a e-communication to call a number) asking you to "verify" personal, or financial information that you take a "deep breath" before proceeding. Most of us have access to legitimate telephone numbers with places we do business with. The key to protecting yourself is to always verify who you are talking to and make sure they are entitled to the information in question.
And remember that since "vishing" is relatively new, financial institutions might now be the only organizations impersonated. The history of phishing tells us that sometimes government institutions are also impersonated. In the past couple of years, we have seen the IRS and even the FBI impersonated in phishing schemes. As a matter of fact in October, 2005 - I did a post on the Jury Duty Scam - where fraudsters (we might now term as "vishers") were calling up to verify personal information.
Maybe "vishing" isn't as new as we thought it was?
Friday, April 28, 2006
Using VoIP to Phish for Victims

The world of Internet fraud is a constantly mutating animal. Phishing in particular is a rapidly growing problem and the latest mutation is the use of VoIP (Voice over IP) technology.
Using VoIP technology, the phishermen are luring the innocent into giving up sensitive personal and financial information by impersonating call centers.
Robert McMillan of IDG News Service reports:
Typically phishers email their victims, trying to lure them into revealing sensitive information on bogus websites. But instead of telling victims to click on a Web link, this attack asks users to verity account information on a phony customer support number.
"Part of the danger here is just the fact that it is novel," senior research scientist with Cloudmark, Adam O'Donnell, said. "Most people are pretty comfortable calling to a phone number that they think is their bank's."
Link to story from IDG News, here.
If you happen to see one of these Phishy e-mails, you can report it to the PIRT Phishing Incident Reporting and Termination Squad. This is a new service (volunteer driven) that actively goes after and takes down phishing sites.
Here is a previous post, I did on PIRT.
