Friday, February 10, 2006

Adobe Latest Name Being Used in Phishing Attacks

Phishers love names we trust. Adobe is their latest target. Here is an alert from the people at Websense:

"Websense® Security Labs™ has received reports of a new phishing attack, using the brand name of Adobe Systems Incorporated. Users receive a spoofed email that provides a link to the phishing website, which is designed to mimic the Adobe online store. Users are given the option to buy and download Adobe products at substantially discounted rates. The site has links to awards hosted locally, which supposedly prove its veracity. When checking out, the user is prompted for credit card information."

"This phishing site is hosted in China and was up at the time of this alert."

For the alert from Websense, which contains a screenshot of the spoofed Adobe site, go to: Adobe.

Bank of America Debit Card Breach Grows to 200,000 and BofA Isn't Alone

The Bank of America debit card breach seems to be growing. Estimates are now that 200,000 customers have been affected AND it goes further than just Bank of America. There is evidence that Washington Mutual and Wells Fargo customers have been compromised, also.

Although, the banks aren't commenting, David Lazarus of the San Francisco Chronicle writes:

"But well-placed sources within the banking and credit card industries now tell me that the company in question is a leading retailer in the office-supply business."

Allegedly, the retailer in question knew of the breach last month.

There is also speculation that California's disclosure laws might have been violated by the retailer:

"It's unclear at this point whether the retailer violated state law by not directly notifying customers of the breach, instead allowing customers to be ambiguously alerted by their banks."

"State Sen. Jackie Speier, D-Hillsborough, a leading privacy advocate in Sacramento, said the spirit, if not the letter, of the law appears to have been violated."

For the full story by David Lazarus:

Security breach fallout reaches 200,000 debit card holders

For anyone, who has been violated by this, here is a link from the Privacy Rights Clearinghouse, explaining the laws and what your rights are:

California Identity Theft Laws

A fellow blogger (travis) left a comment on my post, Boston Globe Hands Out 202,000 Credit Card Numbers about a federal bill modeled after California's proactive legislation:

"Since the S.1789 bill is in the Judiciary Committee, it doesn't look like it will get much attention from those guys for a while. Here's the bill summary. There have been no hearings yet."

These laws are designed to protect all of us. Hopefully, the federal bill will move a little quicker and California's laws will be enforced to the letter of the law.

I highly recommend letting your opinion be known by contacting your elected representatives.

Thursday, February 09, 2006

Phishing for a Lonely Heart

Romance Scams are not new on the internet. In the past, they have become a variation of Advance fee fraud (419) activity. The typical ploy was to establish e-mail/IM contact with a victim and get them to send money.

Now, it seems, the stakes are getting higher. Valentines Day could bring on a surge of phishing attacks designed to install malware (malicious software) on computer systems. The end-result of many of these attacks is personal and financial information being stolen and used to commit identity theft .

Here is a warning from Michael Carr of Purdue University, courtesy of TMCNet:

Electronic Valentine cards promising sweet nothings may instead infect loved ones' computers with a nasty surprise from a cyber scam artist, according to a Purdue University computer security expert.

"An e-mail or instant message from a 'secret admirer' on Valentine's Day may be specifically designed to pique your curiosity," says Michael Carr, Purdue's chief information security officer. "It's human nature and exactly what the bad guy is counting on."

According to the article, and Mr. Carr, here are items to be wary of:

- Not clicking on links or attachments unless they are part of an expected e-mail or instant message from a reliable, known source.

- Protecting your computer with current anti-virus software and manufacturer-recommended system patches.

- Checking the authenticity of a questionable message by contacting the sender via telephone or another messaging technique.

Sometimes dangerous e-mails can even arrive having been forwarded by or appearing to have been forwarded by people known by the recipient. Carr says even these messages also need to be evaluated and confirmed by a phone call to the sender.

"If you continue to have doubts about the e-mail or instant message, just delete the message," Carr says. "It is not worth the risk of being a victim."

"Information Technology at Purdue, also known as ITaP, provides free- of-charge computer security advice, including how to identify spam and phishing scams, on the Web at http://www.purdue.edu/SecurePurdue.

Here is the full story by TMCNet:

Expert: Electronic Valentine Cards Present Cyber Security Risk

Here is a previous post, I did on Romance Scams:

Criminal Activity on Dating Sites

A lot of these scammers lurk on dating sites and there is a Yahoo Group, Romance Scam 419 Yahoo Group (US) that is (in my opinion) the best resource out to learn how to avoid being a victim, or go to if you have become one. The members of this group support victims and actively go about scamming the scammers.

Here is what they do, in their own words:

"Welcome to the group Romancescams. Please feel free to tell us your story whether it is your own personal story or that of someone you know. This group provides a safe haven for all, free of criticism and judgment. Our goal is to educate by getting the word out to as many people as possible. Check out our photo, link, database, and file pages when you get the opportunity."

I highly recommend you find the opportunity to visit them and educate yourself. The group and it's members truly give a lot of themselves to help others, which is a noble cause. They also get quite a bit of revenge on the immoral people, who take advantage of other's feelings.

Wednesday, February 08, 2006

NCL Releases the Top Ten Internet Scams of 2005

The National Consumers League has released their 2005 Fraud Trends: Consumers Being Hounded by Internet and Telemarketing Scams.

The "Top Ten" internet scams were:

Auction items never delivered or misrepresented, the average loss was $1,155 and this category accounted for 42 percent of all the complaints.

General merchandise never delivered or misrepresented, the average loss was $2,258 and this category accounted for 30 percent of the complaints.

Nigerian money offers. False promises of riches if consumers pay to transfer money to their bank accounts, the average loss was $6,937 and this category accounted for 8 percent of the complaints.

Fake checks sent for goods or services and victim is told to wire back money, the average loss was $4,361 and this category accounted for 6 percent of the complaints.

Lotteries/lottery clubs. Requests for payment to claim lottery winnings or get help to win, often foreign lotteries the average loss was $2,919 and this accounted for 4 percent of the complaints.

Phishing, fraudulent e-mails asking for personal information, the average loss was $612 and this accounted for 2 percent of the complaints.

Advance-fee loans, loans promised with upfront fee, the average loss was $1,426 and this accounted for 1 percent of the complaints.


Internet Access Services, cost of internet access and other services misrepresented or never provided, the average loss was $1262 and this accounted for 1 percent of the complaints.

Information/adult services. Cost and terms of services not disclosed or misrepresented, the average loss was $504 and this accounted for 1 percent of the complaints.

Work-at-Home Plans. Kits sold on false promises of big profits from working at home, the average loss was $1,785 and this accounted for 1 percent of the complaints.

Although, these statistics are based on complaints made to the National Consumer League, they doubled over the past year (scary).

Wire transfers through non-banking institutions, such as Western Union and MoneyGram were the favorite venue for the fraudsters to have their money sent to them.


Here is an interesting statistic from the survey about eBay. I'm starting to think they deserve an award for ignoring the massive problems fraud has created for their customers:

* In the fall of 2003, online giant eBay removed the link from its Web site to fraud.org. As a result, the number of auction complaints reported to NCL’s fraud center dropped to 1/6 its previous level. Based on statistics prior to eBay’s action, NCL estimates that there would have been 30,720 auction complaints in 2005, representing 71 percent of complaints.

If you are interested in more information regarding eBay, put in keyword "eBay" in the search box at the top of the page.

The National Consumer's League and it's sister site National Fraud Information Center provide a lot of great information on how to avoid being a fraud victim. There are also other relevant (social awareness) resources on the National Consumer League's site. I highly recommend both of them.

You can go directly to the site for the National Consumer League by clicking on the title of this post.