The security media is reporting a new scam called "vishing," ( phishing by telephone). In vishing, a person is called, or directed to call a number and tricked into giving up their personal details. Note that the call might have someone give up information over the telephone, or direct them to a fraudulent website (like they do in phishing). The intent of these (vishing) scams is to steal personal information, which are used in "identity theft" schemes.
Of course using the telephone to rip-off people is nothing new. Telemarketing scams have been around for years.
The lures used to "dupe" innocent people are normally the same ones used in phishing, like telling you an account has been compromised. It's even possible they might already have some of your information (a lot of it has already been compromised) and be trying to get a credit card's CVC code, or obtain a password to an account.
According to a recent BBC article, the recent bouts with "vishing" started with spam e-mails directing someone to call a number, where they would be prompted to give up personal information. The scam has now mutated (they always do) and now people are being called by "autodialers," which dial number after number and leave a recorded message.
The rise in popularity of Voice over Internet Protocol (VoIP) is being cited by security experts as the reason why vishing is becoming a problem. VoIP has made calling long distance cheap, which means that vishing crosses borders; making it hard to trace and or prosecute.
The BBC article also states that it is relatively easy to spoof "caller-id" with VoIP. Security Focus recently did an article that supports this contention. In the article, a hacker easily showed the reporter how it was done.
For anyone unfamiliar with "spoofing caller id," fraudsters aren't the only ones who do it. In fact, many legitimate corporations use "caller id spoofing services" to trick people (my own words) into picking up the telephone.
For a post, I wrote about this, link here.
So far as how to protect yourself from this sort of scam, I would highly recommend that if you receive any telephone calls (or a e-communication to call a number) asking you to "verify" personal, or financial information that you take a "deep breath" before proceeding. Most of us have access to legitimate telephone numbers with places we do business with. The key to protecting yourself is to always verify who you are talking to and make sure they are entitled to the information in question.
And remember that since "vishing" is relatively new, financial institutions might now be the only organizations impersonated. The history of phishing tells us that sometimes government institutions are also impersonated. In the past couple of years, we have seen the IRS and even the FBI impersonated in phishing schemes. As a matter of fact in October, 2005 - I did a post on the Jury Duty Scam - where fraudsters (we might now term as "vishers") were calling up to verify personal information.
Maybe "vishing" isn't as new as we thought it was?
Tuesday, July 18, 2006
Monday, July 17, 2006
Armed Robbers Pose as Craigslist Customers
This story reaffirms something we should all know, which is be wary of anyone you know only from the Internet. In a story released on SFGate.com, a seller on Craigslist, selling "hooded jackets" was talked into meeting someone at a local mall. When they arrived for the meeting, they were relieved of their merchandise at gunpoint.
The good news is that the only loss was the "hooded jackets!"
For the full story on SFGate.com, link here.
In my opinion, Craig and Craigslist - who provide a "mostly" free service - have been extremely honest and proactive about protecting their "users" from crime.
Although, I could find nothing about this (new and frightening scam) - here is a link to their warnings about some of the scams attempted on their site. Hopefully this one will make their list soon.
The dangers of meeting someone that you have met only over the Internet have been well documented. Although primarily written in the context of "romance encounters," anyone meeting someone they meet on the Internet needs to be careful and verify (via a trusted source) who they are dealing with before proceeding.
For a resource from the University of Oklahoma (The Police Notebook), which covers this subject - link here.
The good news is that the only loss was the "hooded jackets!"
For the full story on SFGate.com, link here.
In my opinion, Craig and Craigslist - who provide a "mostly" free service - have been extremely honest and proactive about protecting their "users" from crime.
Although, I could find nothing about this (new and frightening scam) - here is a link to their warnings about some of the scams attempted on their site. Hopefully this one will make their list soon.
The dangers of meeting someone that you have met only over the Internet have been well documented. Although primarily written in the context of "romance encounters," anyone meeting someone they meet on the Internet needs to be careful and verify (via a trusted source) who they are dealing with before proceeding.
For a resource from the University of Oklahoma (The Police Notebook), which covers this subject - link here.
Bid Reaper, "TELLING IT LIKE IT IS" on eBay
Over the past year, I've written more than one post about problems on eBay. Recently, my friend and partner in "Digging A Little Deeper," Paul Young was able to get the "Bid Reaper" to give me honorable mention on his site.I'll have to admit, I had never been exposed to the "Bid Reaper" before. I found the site to be extremely informative, and a "informative" read for anyone trying to navigate the "sometimes" murky waters of Internet auctions.
Bid Reaper's motto is - Telling "IT" like it is - and it details what is going wrong on eBay - right now.
I plan to continue my visits to "Bid Reaper" and highly recommend that anyone interested in protecting themselves on eBay - do so - also!
And the pictures (see above) are very "interesting," to say the least. The very vision of the "Bid Reaper" should instill fear in auction fraudsters - as well as - eBay's marketing department.
To visit the "Bid Reaper," click here.
Labels:
auction fraud,
auction scams,
bid reaper,
ebay,
prying1
Sunday, July 16, 2006
U.S. to Issue RFID Passports Despite Warnings
Despite the concerns of a lot of security experts, the U.S. State Department will begin issuing passports using RFID technology in August.
In an article by CNNMoney.com, here is what these security experts are saying:
Kidnappers, identity thieves and terrorists could all conceivably commit "contactless" crimes against victims who wouldn't know they've been violated until after the fact.
"The basic problem with RFID is surreptitious access to ID," said Bruce Schneier security technologist, author and chief technology officer of Counterpane Internet Security, a technology security consultancy. "The odds are zero that RFID passport technology won't be hackable."
For a link to the full story: click here.
And if we think "hackers" haven't already started "cracking" this technology, Wired Magazine recently wrote an expose on "The RFID Hacking Underground," which details how it's already being done. In the story, a hacker steals the details off an "access" card and gains entry into a (supposedly) secure building.
Taking too much of the "human element" out of security is dangerous. The "bad and the ugly" have proven this, time after time.
Quite frankly - on a personal level - this technology scares me. Here are some previous posts, I've written on RFID:
RFID, How Effective for the Long Term and What is the Cost?
RFID, A Necessary Evil; or an Invasion of Privacy?
RFID, Abuse in the Private Sector?
State Department is Taking Another Look at RFID
In an article by CNNMoney.com, here is what these security experts are saying:
Kidnappers, identity thieves and terrorists could all conceivably commit "contactless" crimes against victims who wouldn't know they've been violated until after the fact.
"The basic problem with RFID is surreptitious access to ID," said Bruce Schneier security technologist, author and chief technology officer of Counterpane Internet Security, a technology security consultancy. "The odds are zero that RFID passport technology won't be hackable."
For a link to the full story: click here.
And if we think "hackers" haven't already started "cracking" this technology, Wired Magazine recently wrote an expose on "The RFID Hacking Underground," which details how it's already being done. In the story, a hacker steals the details off an "access" card and gains entry into a (supposedly) secure building.
Taking too much of the "human element" out of security is dangerous. The "bad and the ugly" have proven this, time after time.
Quite frankly - on a personal level - this technology scares me. Here are some previous posts, I've written on RFID:
RFID, How Effective for the Long Term and What is the Cost?
RFID, A Necessary Evil; or an Invasion of Privacy?
RFID, Abuse in the Private Sector?
State Department is Taking Another Look at RFID
Subscribe to:
Posts (Atom)
