Sunday, April 30, 2006
California Predicts the Top Ten Scams for 2006
Based on this, it would make sense to pay attention to what California predicts when it comes to fraud.
Here is what California predicts for 2006, courtesy of the Department of Corporations:
Senior Investment Fraud. The elderly are targeted for fraud for several reasons, such as older Californians are most likely to have a nest egg, own their own home or have excellent credit-all of which the con artist will try to tap into. As seniors plan for retirement, they may fall victim to such investment schemes as oil and gas, real estate, and annuities. They should be careful when solicited by mailers, telephone, and through free lunch or dinner seminars. In the past year, DOC assisted with a Southern California district attorney's office to bring criminal charges against three perpetrators for selling promissory notes offering a 12 percent annual return and then absconding with seniors' money. The defendants were charged with 850 felony counts of senior fraud.
Mortgage Fraud. Predatory mortgage lending involves a wide array of abusive practices and usually takes place in the subprime market, targeting borrowers with weak or blemished credit records. The most common lending abuses include excessive fees, abusive prepayment penalties, loan flipping, and other shady practices. In addition, foreclosure schemes are on the rise in which the prepetrators mislead the homeowners into believing that they can save their homes in exchange for a transfer of deed and up-front fees. The perpetrator profits from these schemes by remortgaging the property or pocketing fees paid by the homeowner. DOC, as part of a California task force comprised of local district attorneys and the California Attorney General filed a judgment in 2006 against a major subprime lender to resolve predatory lending allegations against the company, which will provide consumers $295 million in restitution and require sweeping reforms of the firm's business practices.
Affinity Fraud. These scams exploit the trust and friendship that exist in groups of people who have something in common, such as religious or ethnic communities, the elderly, military servicemembers, or professional groups. The fraudsters who promote affinity scams frequently are-or pretend to be-members of the group and enlist respected community or religious leaders from within the group to unwittingly spread the word about the scheme. In 2005, DOC brought enforcement actions against perpetrators of investment scams affecting members of the African American and the Korean American communities in Southern California, and a foreign currency scheme targeted at the Chinese American community in the Bay Area.
Identity Theft/Phishing. Identity theft is a trend that is often aided by technology and is the criminal activity of stealing someone's personal information for financial gain. More often than not, it involves "phishing," where Internet users believe that they are receiving e-mail from a specific, trusted source, or that they are securely connected to a trusted Web site, when that is not the case. As more investment and banking accounts, as well as 401(k) plans, are accessible online, thieves may attempt to obtain your access codes and passwords so they can transfer all of the assets out of accounts.
Online Escrow Fraud. In 2005, DOC enforcement actions to crack down on online escrow fraud increased by 16 percent from 2004. Escrow services fraud involves a perpetrator proposing the use of a third-party escrow service to facilitate the exchange of money and merchandise. The buyer sends payment to a phony escrow site that closely resembles a legitimate escrow service. Or, the seller sends merchandise to the bogus buyer, and waits for the payment through the escrow site, which is never received because it is a sham.
Commodities/Foreign Currency. Consumers should take special care to protect themselves from the many types of commodities fraud. They might be selling precious metals, such as silver or gold, or foreign currency, such as Euros, Yen or Deutschmarks. Be wary of any firm that offers to sell commodities or commodity futures or options, particularly if a firm promises high profits and low risks, or claims that they have made profits for all of their customers. The commodities and futures markets are very risky, and investors can lose their entire investment very quickly. In 2005, DOC took enforcement action against a firm and sales representatives in San Diego County who were not registered with the Commodity Futures Trading Commission to sell foreign currency contracts. Investors were not aware that the promoter had been barred from the National Futures Association, the self-regulatory organization for the futures industry, and a principal had been ordered by the NASD to pay damages in two separate incidents. Oil and Gas Scams. With oil prices at record levels and continued Middle East instability, DOC is concerned about the increase in oil and gas scams that it is experiencing. Perpetrators lure investors into unsuitable or fraudulent oil and gas ventures promising quick profits on a low risk investment. A San Diego scam using five different company names touted a 90 to 95 percent probability of striking oil in oil wells and returning investors' principal investment within a few years, which some customers never received. At least seven California residents invested more than $770,000 in the scam. The perpetrators failed to disclose prior convictions of mail fraud and wire fraud and that at least seven other states had taken administrative action against the sales agents for securities fraud.
Ponzi/Pyramid Schemes. Named for swindler Charles Ponzi, the premise is simple: use money from later investors to pay early investors. Instead of investing customers' funds, the operator pays dividends to initial investors using the principal amounts invested by subsequent investors. The scheme generally falls apart when the operator flees with all of the proceeds, or when a sufficient number of new investors cannot be found to allow the continued payment of dividends. Another very old form of fraud, a pyramid scheme, promises consumers or investors large profits based primarily on recruiting others to join their program, not based on profits from any real investment or real sale of goods to the public. A product may be used to hide the pyramid structure if the company's incentive program force recruits to buy more products than they could ever sell, or the sales occur only between the people inside the pyramid structure or to new recruits joining the structure, not to consumers out in the general public.
Military Fraud. There has been heightened concern at the federal and state government levels about the financial vulnerabilities of servicemembers and their families, particularly in light of recent deployments to Iraq and Afghanistan. Money woes can be especially difficult for National Guard and Reserve soldiers, who often have to make a rapid switch from civilian to military life when they get called up. DOC created the California Troops Against Predatory Scams (TAPS) program to provide financial education and consumer protection tips, supported by an effective and timely consumer enforcement program.
Disaster and Charity Scams. Scammers will attempt to capitalize on the aftermath of Hurricane Katrina and other disasters. Be careful of investment fraud scams which claim to be trading programs that guarantee high returns, with a portion going to aid relief efforts. Others promote businesses that stand to profit from relief and rebuilding efforts. Be cautious of the influx of Web sites soliciting for charitable donations to avoid phishing and identity theft.
It never ceases to amaze me at the lack of moral fiber fraudsters have. If California is correct, they will target the elderly, charities, people's homes, their identities, their retirement savings and even the military in time of war.
Besides supporting legislation to put these people away (for a long time), the most effective tool against fraud is awareness. It is a kind thing to share awareness to protect those, who might fall into harm's way by an activity that is becoming epidemic in nature.
I would like to thank the State of California for sharing this with us all.
Press Release link, here.
Friday, April 28, 2006
Do Financial Crimes and Internet Fraud Fund Terrorism
"Five relatives of a U.S. citizen suspected of being a senior Al Qaida operative were arrested in California and Utah on charges of defrauding banks of hundreds of thousands of dollars."
"The FBI said Omar's relatives netted $327,000 from fraudulent bank loans and bad mortgages in Utah, and Bretzing said some of the money wound up in Jordan with Omar's relatives.
Omar, a 44-year-old Kuwaiti native with U.S. and Jordanian citizenship, has been indicted in Jordan with Iraq insurgent leader Abu Musab al-Zarqawi in an aborted chemical attack on the Jordanian intelligence agency."
Full story by the AP courtesy of MSNBC, here.
Of course, the FBI says the matter is still under investigation and won't speculate. Please note, I can't blame them for not doing so in an ongoing case.
BUT here is evidence that the FBI takes the ties between fraud and terrorism seriously. Here are excerpts from a speech delivered by Grant Ashley, Executive Assistant Director of the FBI to the International Association of Financial Crimes Investigators in 2004:
It has often been said that money is the root of all evil. I don't know if that's the case, but I do know that it is the root of terrorism. Terrorists rely on money to fund their training and operations. They disguise their fundraising activities as legitimate charity organizations. They resort to white-collar crime to raise money. Money laundering is no longer exclusive to sophisticated criminals, but is now routine for terrorists.
Money can also be the fruit of terrorism and crime. Today's terrorists and criminals use sophisticated business practices to achieve their goals, not unlike those of legitimate multinational corporations. Criminals today are not just stealing funds, they are stealing credit card information, social security numbers - entire identities - and selling them for profit. Those who traffic in humans, drugs, or weapons are motivated and rewarded by money.
Link to Assistant Director Ashley's speech, here.
Although it rarely makes it in the news, it appears that the FBI sees a connection between financial crimes (fraud) and terrorism.
If there are some of you out there that are leery of government sources, the Washington Post did a story on Imam Samudra, the terrorist behind the Bali Night Club bombings in Indonesia. Samudra published a book with a chapter entitled "Hacking, Why Not?"
There, Samudra urges fellow Muslim radicals to take the holy war into cyberspace by attacking U.S. computers, with the particular aim of committing credit card fraud, called "carding." The chapter then provides an outline on how to get started.
Samudra, 34, is among the most technologically savvy members of Jemaah Islamiah, an underground Islamic radical movement in Southeast Asia that is linked to al Qaida. He sought to fund the Bali attacks in part through online credit card fraud, according to Indonesian police. They said Samudra's laptop computer revealed an attempt at carding, but it was unclear whether he had succeeded.
Samudra was quoted in the article:
"It would not be America if the country were secure. It would not be America if its computer network were impenetrable," he writes at the beginning of the hacking chapter. He continues by urging fellow militants to exploit this opening: "Any man-made product contains weakness because man himself is a weak creature. So it is with the Americans, who boast they are a strong nation."
Here is a link to the story by the Washington Post.
Interestingly enough, we have seen some major hacking activity in the recent past, where large numbers of credit and debit card numbers have been compromised. There have also been a large number of data breaches, most of which seem never to have been solved.
In testimony before Congress, Dennis M. Lormel, Chief, Financial Crimes Section, FBI said:
Because most of these are never solved, we as average people can only speculate as to what the source of this activity is.
After all, (Terrorist 007) Irhabi 007, the so-called Al Qaida hacker, who was spreading terrorist propaganda on the Internet used stolen credit cards to set up his ISP connections.
In testimony before Congress, Dennis M. Lormel, Chief, Financial Crimes Section, FBI stated:
Another pattern of terrorist financing involves funding of terrorist cell activities through various criminal activity. Al Qaida has been known to encourage and instruct terrorist cells in terrorist training camps in Afghanistan in ways they can fund their terrorist activities through various criminal activity. For example, Ahmed Ressam, the Algerian extremist convicted in the terrorist plot to place bombs at Los Angeles International Airport among other locations, was instructed in these camps to engage in criminal activity such as bank robberies and fraud schemes to fund his terrorist activities. As another example, investigation has identified a terrorist cell based in Spain with ties to Al Qaida that used stolen credit cards in fictitious sales scams and for numerous other purchases for the cell. They kept purchases below amount where identification would be presented. They also used stolen telephone and credit cards for communications back to Pakistan, Afghanistan, Lebanon, etc. Extensive use of false passports and travel documents were used to open bank accounts where money for the mujahadin movement was sent to and from countries such as Pakistan, Afghanistan, etc. In addition, the cell relied upon street crimes such as home burglary, car theft, and car burglary to fund their cell activities.
We live in a new and more dangerous world since the 9-11 attacks. This new world requires that we take another look at issues, such as financial crimes and illegal immigration. These issues, which were not priorities in the past, have become increasingly important in the quest to ensure our safety and security.
Unfortunately, there are too many out there, who want things to remain the same and are now exercising their political voices to prevent the necessary changes.
Perhaps, they should go out and watch "United 93" to refresh their memories of why we can no longer allow tolerate loose financial controls and allow criminals and terrorists easy access to our borders.
Using VoIP to Phish for Victims

The world of Internet fraud is a constantly mutating animal. Phishing in particular is a rapidly growing problem and the latest mutation is the use of VoIP (Voice over IP) technology.
Using VoIP technology, the phishermen are luring the innocent into giving up sensitive personal and financial information by impersonating call centers.
Robert McMillan of IDG News Service reports:
Typically phishers email their victims, trying to lure them into revealing sensitive information on bogus websites. But instead of telling victims to click on a Web link, this attack asks users to verity account information on a phony customer support number.
"Part of the danger here is just the fact that it is novel," senior research scientist with Cloudmark, Adam O'Donnell, said. "Most people are pretty comfortable calling to a phone number that they think is their bank's."
Link to story from IDG News, here.
If you happen to see one of these Phishy e-mails, you can report it to the PIRT Phishing Incident Reporting and Termination Squad. This is a new service (volunteer driven) that actively goes after and takes down phishing sites.
Here is a previous post, I did on PIRT.
Tuesday, April 25, 2006
Do It Yourself Hacker Kits
The Trojan is even smart and can detect what browser is being used via the user agent and customize the exploit based on the browser settings.
Here is the ad, which was translated into English by Websense:
Dear Friends! We would like to offer you multi-component exploit Web-Attacker IE604, that realizes vulnerabilities in the internet browsers Internet Explorer and Mozilla Firefox. With the help of this exploit you will be able to install any programs on the local disks of visitors of your web pages. In the foundation of work of the exploit Web-Attacker IE0604, there are 7 already-known vulnerabilities in the internet browsers: Objective of the Exploit: Hidden drop of the executable from the deleted source to the local hard drive of the site visitor.
-Bypasses all security measures-Is not blocked by Firewalls [Agnitum Outpost, Zone Alarm, Sygate Personal Firewall]
-Tri-level protection -Flexible installation -Updates -Detailed Statistics
For the full alert, with screenshots, click here.
John Leyden of the Register is also covering this story.
trimMail's E-Mail Battles has an interesting story about why some of these kits are so dangerous. Here is an excerpt:
Smart computer users know that once a computer is infected by a rootkit, it's changed forever. And as Windows rootkits go, Hacker Defender is among the most dangerous. The author of Hacker Defender, holy_father, explains why he does what he does, and what you can do to detect his rootkit.
Antivirus companies sell a fake sense of security, but they do not bring real security to your computer. Antivirus just fights programs that are visible to common users. They don't care about the cause.
Do it yourself kits are becoming increasingly common and are making the Internet increasingly dangerous for the common user.
Here is a recent post, I wrote about "how to scam kits" and one that is designed for use in committing fraud on eBay.
Link, here.
