Sunday, December 11, 2005

$100 Million Dollar Fraud Stopped Dead in it's Tracks

Lately, the news in the fraud arena hasn't been very positive. This next story is "Chicken Soup for the Soul." Here is a breaking story by Judy Nichols of the Arizona Republic involving PBI (Prime Bank Instrument Fraud) and a tip that led to stopping $100 million in fraud.

According to the article, this scam "involves attracting investors to a fund that would tap into a supposedly secret market for the world's prime banks, a market in which billions are said to trade daily for huge, guaranteed profits. In one subset of PBI fraud, designed to also put financial institutions at risk, the scammers quickly move the money from one financial institution to another, from bank to brokerage house, in this country and overseas, all the while telling weird stories about its origin and leaving fishy documents in their wake."

Cameron Holmes, head of the financial remedies section at the Arizona Attorney General's Office received a tip involving $100 million being moved around the world, allegedly backed by a gold mine worth $152 billion.

The total amount of gold mined in Arizona since statehood represents less than $8 billion.

Holmes moved quickly and issued subpoenas to several financial institutions and after interviewing employees was able to track the money and freeze it.

The victims in this can be both the investors, who fall for this scam, as well as the financial institutions, who can be held liable for it when they are charged with not exercising "reasonable care" or due diligence on all the transactions associated with it.

This is certainly an interesting case and Cameron Holmes and the Arizona Attorney General's office should be commended for acting so quickly and effectively. All too often (in more sophisticated scams) by the time they are reacted to, the money is long gone and the victims are left holding the proverbial bag.

For the full story in the Arizona Republic, go to: Fast work in Arizona halts fraud, freezes $100. million.

Here are some tips, I found in a DOJ document on PBI Fraud, January 6, 2000 Mr. Joshua R. Hochberg United States Department of Justice Chief, Fraud Section P.O. Box 28188 :

Don't expect to get rich quick.

Don't assume that your on-line computer service polices its investment bulletin
boards.

Don't buy thinly-traded, little known stocks strictly on the basis of on-line hype.

Don't act on the advice of a person who hides his or her identity.

Don't get suckered by claims about "inside information" including pending news releases, contract announcements and products.

Don't assume that just because someone says that they have checked something
out that they have actually done so.

Call your state or provincial securities agency when you suspect a scam.

As with most fraud of a financial nature, much of this is easily spread through the internet. Like all the various scams this one starts with the premise of "something that is too good to be true." The best remedy in these scams is awareness is to "let the buyer beware."



Saturday, December 10, 2005

Should We Consider Nazis Potential Terrorists?

The Sober Worm, which was attached to phony e-mails from the FBI and CIA is making a comeback. According to the Washington Post-"The junk traffic generated by Sober has bogged down e-mail systems at some of the nation's largest Internet service providers. For several days last week, subscribers of Microsoft Corp.'s Hotmail and MSN e-mail services experienced long delays in receiving new messages as the company struggled to filter out Sober-generated traffic."

The article also reports that the Sober Worm is the most extensive attack to date and has generated twice the number of quarantined e-mails as the Mydoom Worm (it's closest competitor) did. For the full story by the Washington Post, please read, Sober.X worm makes return.

Meanwhile, "iDefense, cyber security intelligence provider and VeriSign company (Nasdaq: VRSN), reports that the next planned attack of 2005's most prolific e-mail worm family, Sober, is scheduled to start on Jan. 5, 2006 based on commands hard-coded within the worm. The attack date coincides with the 87th anniversary of the founding of the Nazi party. Additionally, the attack could have a significantly detrimental effect on Internet traffic, as e-mail servers are flooded with politically motivated spam e-mails from potentially tens of millions of e-mail addresses.

In addition to the Nazi party anniversary, the Jan. 5 trigger on the Sober variant appears to also be timed to coincide with a major German political convention meeting the next day, Jan. 6. In the past, VeriSign iDefense Security Intelligence Services has seen mass distribution of propaganda timed with political events to increase the worm's notoriety, and help to further circulate it.

In another interesting story this week, the FBI (Louis Reigel, Assistant Director, Cybercrime) is reassuring the public that they believe the originator(s) of the Sober Worm will be caught and that he isn't aware of any major risk by cyberattack from terrorists. Here is the press release on the FBI website, FBI Exec on Cyber Crime.

Meanwhile, Valerie McNiven (who advises the U.S. Treasury in cybercrime) made the statement that the profits from cybercrime have exceeded those of the drug trade. Here is CNet's version of the story, Cybercrime yields more cash than drugs. I hear that other experts are disputing this, but then again, hows does one come to an exact figure? Pretty sure, the people involved in these criminal enterprises don't publish their financial portfolios and make every attempt to conceal where the money is coming from.

Terrorists, organized criminals and now possibly Neo-Nazis seem to be in the mix and according to the FBI, all is well. To my knowledge, the CIA hasn't commented, but they normally don't, at least to the general public. My question is should we Neo-Nazis consider Terrorists?

If Neo Nazis might be terrorists, Sober is the most prolific attack to date and the person(s) behind it are openly mocking both the CIA and FBI (among others) by impersonating them, I fear everything isn't is as well as is being stated.

Terrorism, according to Wikipedia, is the unconventional use of violence for political gain. It is a strategy of using coordinated attacks that fall outside the laws of war commonly understood to represent the bounds of conventional warfare (see also unconventional warfare).

"Terrorist attacks" are usually characterized as "indiscriminate," "targeting of civilians," or executed "with disregard" for human life. The term "terrorism" is often used to assert that the political violence of an enemy is immoral, wanton, and unjustified.

According to definition of terrorism typically used by states, academics, counter-terrorism experts, and non-governmental organizations, "terrorists" are actors who don't belong to any recognized armed forces, or who don't adhere to their rules, and who are therefore regarded as "rogue actors".

Could Neo Nazis be the culprits behind the Sober Worm? To meet the definition of terrorisim (above) there needs to be violence. Sending out malware doesn't meet this standard. On the other hand, Neo Nazis have been associated with violence and often preach it against anyone, who doesn't subscribe to their warped ideals. All one would have to remember is the horror their forefathers (Nazis) unleashed upon the world during the Holocaust.

All things considered, Neo Nazis could be terrorists and probably are capable of committing terrorist acts. According to CourtTV, Timothy McVeigh: The Oklahoma Bomber was a fan of: "The Turner Diaries written by former American Nazi Party honcho William L. Pierce, under the pen name Andrew Macdonald. Its hero responds to gun control by making a truck bomb and blowing up the Washington FBI Building."

According to an article in Wikipedia: "Some investigators contend that Timothy McVeigh and his accomplice Terry Nichols had ties to Islamic terrorism through Ramzi Yousef, a militant who planned the 1993 WTC Bombing, and through a series of meetings with Islamic terror group Abu Sayyaf members in the Philippines. Others suggest he had ties to a radical Christian Identity group call Elohim City near Muldrow, Oklahoma."

I'm certain not everyone will agree with me, but cyber attacks seem to be steadily increasing in scope and technological sophistication. There is mounting evidence that organized criminals, terrorists and now Neo Nazis are using computer technology to further their political and financial agendas. In my humble opinion, we can no longer afford to ignore a problem that threatens the entire world.

Whether we call them fanatics, terrorists, or common criminals, these people threaten the well being of society at large and in the end, our freedom. The time to decide we won't tolerate this is now!

Thursday, December 08, 2005

Seventy Percent of the Population Unable to Recognize a Phishing Scam

Twenty five percent of us will receive a phishing attack aimed at stealing our identity and or financial information every month, according to the AOL/National Cyber Security Alliance (NCSA) Online Safety Study. Also discovered in this survey is that about seventy percent of us, who receive these phishing e-mails won't be able to identify them as a scam.

According to my friends at Wikipedia, "phishing is a form of social engineering, characterised by attempts to fraudulently acquire sensitive information, such as passwords and credit card details, by masquerading as a trustworthy person or business in an apparently official electronic communication, such as an email or an instant message. The term phishing arises from the use of increasingly sophisticated lures to "fish" for users' financial information and passwords."

The activity is also becoming more sophisticated and these e-mails often inject malware (malicious software) on systems, which can automatically capture personal information via Keyloggers. Keyloggers automatically record "keystrokes" (including passwords, account information etc.) and sends them back to the cyber criminal responsible for putting the software on someone's system.

For those of us, who are unfamiliar with phishing scams, which are getting more sophisticated all the time, a great place to learn how to protect yourself is Stay Safe Online, or the National Cyber Security Alliance.

Phishing designed to steal personal information is a rapidly growing enterprise and with internet access and computers becoming more readily available (cheaper), there are a growing number of victims. Nine million people in the United States fall victim to having their identities stolen (every year) according to the government!

There is also a lot of information on this blog designed to provide resources (often free) on how to avoid becoming a victim of internet scams. Phishing is a subject, I have covered extensively and the blog can be "searched" by "keyword" at the top.

Another great resource to learn about the dangers of identity theft and what to do if one becomes a victim is the Federal Trade Commission: ID Theft website, courtesy of the FTC.

With the holiday season upon us, it is traditional to share goodwill. If seventy percent of us are unaware of the potential dangers of phishing, take a moment and help educate someone you care about. Think about it, if everyone in the world did this, we would protect the innocent and deal a severe blow against the immoral cyberscum, who ruin people's lives for their own gain.

Wednesday, December 07, 2005

Russian Gang Members Busted at Circuit City

In my last post, High Tech Theft Not the Only Loss Category Rising, I discussed a retail theft survey, which deducted that an increase in shoplifting losses was attributable to organized gang activity. I noted that the loss categories mentioned in the press release from the survey failed to include fraud (check and credit) and e-commerce fraud. These are also areas that seemed to be consistently targeted by organized activity and have the ability to impact the profitability of the retail industry.

Here is an interesting story from WOOD TV in Grand Rapids Michigan, which shows how organized activity is impacting retailers in other ways besides shoplifting.

WOOD TV reported, "It appears the suspects were hitting stores across the state, particularly Circuit City and Best Buy. The Muskegon County prosecutor tells 24 Hour News 8 two men were arrested with more than $10,000 worth of electronics in their possession after providing stolen identification at a local home electronics store."

When arrested, the alleged low level Russian gang members were in possession of $10,000.00 worth of merchandise and there are ties to numerous other thefts from Best Buy and Circuit City.

In this scam, high-end electronic merchandise would be ordered over the internet using fraudulent credit cards. Individuals would then appear at the stores to pick up the merchandise using fake identification.

I'm assuming that when arrested they merely had the merchandise from one haul. According to the local authorities the merchandise was going to be shipped overseas to Holland. WOOD TV also reported, there were other indicators that this is a very organized operation.

"Authorities confiscated a global positioning device to help navigate fast getaways and map out the next hit.

Authorities believe the two men are part of a sophisticated Russian organized crime ring after discovering high-tech items and cell phones in their van. The high-tech devices are capable of altering magnetic strips on credit cards.

The phone was ringing throughout our proceedings from a variety of individuals speaking Russian, also with code names including Godfather.

The investigation is now spreading to other sites after authorities traced stolen credit cards "including Illinois, Indiana, Arizona, Colorado," Tague says. "So we're certainly seeing contacts throughout the country in terms of ID theft and contacts with this organization."

For the full story from WOOD TV go to: Nationwide identity theft ring busted in Muskegon. County.

It would be pretty hard to shoplift a van full of big screen televisions.

My recommendation to those implementing security strategy for the retail industry is that while they need to continue to monitor employee theft, shoplifting, vendor theft and administrative errors; ignoring the increases in fraud fueled by technology and the internet could be deadly to the profitability of the industry as a whole.

For my previous post regarding the retail survey, click on the title of this one.