Tuesday, January 17, 2006

Phishing for a Mac

John Leyden of the Register reported:

"Email fraudsters are targeting Apple fans in a change of tactic from standard phishing attacks. Commonly bogus emails that form the basis of phishing attacks pose as security messages from online banks in an attempt to dupe a tiny proportion of recipients, who happen to be customers of the bank, into visiting a bogus site on handing over account information.

eBay account details are also often targeted in a similar way but the latest scam emails, sent out last weekend, target Apple IDs. Armed with an Apple ID and password, fraudsters have access to user's iTunes Music Store account and their AppleStore account, information that might allow them to buy computers, software, peripherals under a false identity."

For the full story, read: Phishing fraudsters target Apple.

It appears Apple is the latest victim of being popular, which is what these scams seem to target.

In case you want to learn more about how to avoid a phishing scam, the Anti Phishing Working Group has an excellent page on their site: How to Avoid Phishing Scams.

The APWG (Anti Phishing Working Group) home page can be viewed by clicking on the title of this post.

Monday, January 16, 2006

Hurricane Audits

In the wake of Katrina, Rita and Wilma hurricanes, we saw a lot of instances of fraud being committed against the government and charitable organizations.

Apparently, the government (President's Council) is looking into some of the potential fraud and to quote Scott Amey, General Counsel of the Project for Government Oversight (POGO), “Some of the audit findings confirm our worst fears -- agencies were ill-prepared to meet the country’s contracting needs. These audits ensure that contractors did not exploit mistakes that may have been made in the chaotic rush following the hurricanes.”

Here is the report from Pogo: Investigations into Katrina Waste and Fraud Detailed.

In the rash of disasters (especially these and the Tsunami) fraud seem to occur from individuals making false claims to organized phishing scams and fake charity sites being set up.

I wrote a lot of posts regarding fraud at the time of Katrina. In case anyone is interested:

Being Prudent in Donating Money (Katrina)

Katrina Fraud Status

Fraud Relating to Katrina in Full Swing

Status of Fraud in Katrina

Advance Fee Scams with Katrina

Katrina Fraud Far and Wide

Katrina Commission

Identity Theft/Check Fraud in Katrina

FBI Reports Fraudulent Activity on Internet Related to Hurricane ...

With all the evidence of people lacking any morals taking advantage of the hardships these disasters created, it is a prudent move to investigate and (hopefully) prosecute these actions.

It's a rotten thing to take advantage of people's hardships and undermine efforts to help them. They deserve whatever punishment is handed down to them.

Here is POGO's website: Beth Daley - Government Oversight.

From Russia With Cash?

Advance fee fraud (419) scams never seem to go away. They mutate into another form and move forward. The news media and internet trace these scams to shady internet cafes in Lagos (Nigeria), but there is a lot of evidence that Nigeria isn't the only place they comes from.

The latest version is a solicitation to make a "cool" $45 million for helping a jailed Russian Billionaire invest some money. Of course, the end result for anyone who gets involved in this is having your account cleaned out.

Here is the latest twist as reported by Alex Nicholson from the Associated Press:

"Russia has more in common with Nigeria these days than just oil. Following up on the politically charged jailing of oil tycoon Mikhail Khodorkovsky, a wave of scam e-mails in the style of Nigeria's notorious spammers have been popping up in inboxes from Moscow to Kentucky."

Here is the full story: Russian Tycoon Is Spammers' New Target.

We can't even blame Nigeria for inventing the scam. The evolution of Advance Fee started with letters from (allegedly) rich merchants during the middle ages AND "a rash of Russian Letters that appeared in the 1920s, with money supposedly needed to rescue people held by the Bolsheviks."

Here is another mutation of the scam that stereotypically, we blame on Russians:

The internet is full of stories of Russian Romance Scams, where men and women are duped into sending money to someone they meet in a chatroom, or dating site. If you were to talk to the people at Romance Scam 419 Yahoo Group (US), my guess is that they would tell you that the scams not only originate from Nigeria and Russia, but several other places, also.

With the evolution of the internet, scams inducing people to send money in advance of a promise (which never materializes) are becoming epidemic. The original letter scam has led to romance, lottery, auction, check cashing and job scams. Undoubtedly, it will continue to mutate into different varieties as new events occur and different things become popular.

They are also no longer exclusively from Nigeria and Russia, but can come from anywhere. Recently, Canada and the Netherlands seems to be fertile breeding grounds AND in the future, who knows?

The internet with it's borderless environment has caused an explosion in this activity. Furthermore, with computers and internet access becoming cheaper all the time, more are more potential victims are getting on-line daily.

The reason why this scam continues to work is that it plays on human emotion and recognizing that is key to teaching people how to avoid being victims.

"If it seems to good to be true, it isn't."

For a good resource on definitions on all the various mutations of Advance Fee, Wikipedia does a pretty good job in their Internet fraud section.

Here is another well put together page on Advance fee activity from Caslon Analytics (Australia): the 419 Scam: basis, statistics, regulation.

Sunday, January 15, 2006

What are the Security Implications of Outsourcing

Let's face it, many corporations are now outsourcing work to India and in doing so are making available personal and financial information that can be stolen.

BBC News (Zubair Ahmed) reported that employees from a outsourcing firm (Mphasis) were recently implicated in a $400,000 fraud in which four Americans were the victims. Mr. Ahmed brought up other concerns in the article, such as the lack of screening of personnel working at some of these firms (10-25 percent submit fake information) to obtain employment. This "fake information" includes, phony credentials and diplomas; which can be bought in India.

He also cited a source that 80 percent of the companies don't use integrated security management tools in India, which allowed the most recent fraud to occur. For the entire story, please read: BBC NEWS Business Outsourcing exposes firms to fraud.

According to the article, there are fears that if too many of these episodes come to light, it could hurt the industry as a whole.

BUT what if all the fraud isn't being reported? After all, in most (individual) cases of identity theft, the point of compromise is never found. With the borderless aspects of internet crime, information is transmitted with a click of the mouse.

There are also cultural considerations to consider. Having lived in Pakistan and traveled in India, I learned very quickly that one needs to pay money (baksheesh) to get a lot of things done.

"Baksheesh" (roughly translated as bribe money) is a cultural aspect of South Asian society. Although written in a humorous vein, here is an article written by Melvin Durai (who is himself of Indian descent): Humor: Corruption in India.

Mr. Durai writes in his satirical essay:

"Yes, corruption is a serious problem, but despite what some believe, India is not the most corrupt country in the world. That distinction belongs to Bangladesh, which finished dead last among 91 countries surveyed for the 2002 Corruption Perceptions Index of Transparency International. India ranked 71st, while Pakistan was 79th, allowing Indian politicians to brag that they're more honest than their neighbors. "If you want to see real corruption, just cross the border. Even husbands have to bribe wives just to have children."

For a more serious look at (not only India), but corruption everywhere, here is the Global Corruption Report 2005 by Transparency International.

A little "baksheesh" in South Asia can go a long way and can open a lot of doors. I've heard this can even be true with law enforcement, who like many underpaid South Asians view it as a means of survival.

In another vein, since there is a perceived lack of security procedures at these firms, could they become greater targets for criminal activity? There is growing evidence that a lot of this sort of crime is being done by organized "international gangs." It would seem logical that if it is easier and safer to steal the information in India, we are going to see them take their activity there.

BUT should we blame corruption (AND the potential for information theft) in India on the Indians, or the corporations themselves? My guess would be the corporations, who in their quest for profit are exposing our personal information without ensuring it is properly protected. After all, India is a poor country, where we have been told (for years) that some don't even get enough to eat. The corporations, who enjoy the vastly reduced payroll costs, are making record profits by outsourcing work to India.

From a different perspective, these jobs have helped created a new and more prosperous middle-class within India. I cannot and will not argue against bringing up the standard of a people that historically have gone without some of the things we enjoy and in fact (my opinion) sometimes take for granted. There is no shortage of corrupt people in the West, either.

Internal plants, fake documents and fraud aren't only a problem in India. There is plenty of this activity to go around and with technology, it seems to be getting worse throughout the world.

The goal needs to be to protecting people from becoming victims, EVERYWHERE! If we are going to be business partners with these firms, it is imperative, we assist them in bringing their security infastructures up to par with ours. Otherwise, we expose them as easy targets.

With the Sarbanes-Oxley act in full swing (United States), outsourcing to far-away places might become more attractive. Compliance costs money and to some, it might be counterproductive to their primary focus, which is profit. After all, Sarbanes-Oxley and similar legislation ensures the very due diligence, I refer to. Perhaps, the answer is to enact further legislation forcing corporations to adhere to the same standards that have to be in place here, as well as, India.

In a perfect world, corporations would do this on their own, but sometimes laws are necessary for the good of all.

In fact, it seems to me that the international corporation of the future will need to consider security as more of a "customer service" and "profit protection" entity rather than a necessary evil. In the long run, should they fail to do so, they will lose the trust of their customer (who in the end) is the one who dictates their future.

Last, but not least, I would like to acknowledge my friend, Paul Young (author of prying1), who sent me a note with an article on this that inspired me to write this post.