Saturday, February 18, 2006
eBay's Fraud Hall of Shame
Fraudulent forms of payment, Advance fee fraud (419) scams, phishing and account takeovers are common. Counterfeit merchandise and misleading ads abound on the site and by the time there is any response by eBay, the damage is often done.
So far as misleading ads, here is a post, I did during the Christmas Season: XBox Latest Lure in Auction Scams. People were tricked into buying the box, versus the contents by ads, which were written in a deceptive manner.
Yahoo's Group, eBayFraud is trying to do something about it. In their own words, here is what they are working towards accomplishing:
"This Group is designed to share information regarding fraud on eBay, including law enforcement, legal proceedings, reimbursement and fraud prevention. Members are welcome to post links, files, databases and messages that are relevant to this topic. You can also use the chat function for more direct communication."
I was recently contacted by them and asked to help publicize their efforts.
Here from the site is a compilation of articles about the fraud problem on eBay. Essentially, this is eBay's Fraud Hall of Shame:
Department of Homeland Security and NCSA 2006 Emerging Internet Threat List
2/17/06
This tidbit, is from www.staysafeonline.org:
http://www.staysafeonline.info/basics/2006threatlist.html
Authorities unable to track most money lost to alleged eBay scam
On 2/9/06, Chris W. Colby of www.naplesnews.com wrote this:
Authorities are unable to track lost money to alleged eBay scam
Seeing Fakes, Angry Traders Confront Ebay
1/29/06 Katie Hafner of www.nytimes.com, wrote:
http://www.nytimes.com/2006/01/29/technology/29ebay.html
Warrants for Arrest Issued in eBay Scam Case
On 1/26/06, a press release from www.colliersheriff.org, stated:
http://www.colliersheriff.org/news/today/todaydetails.asp?nkey=914
2005 Fraud Trends: Consumers Being Hounded by Internet and Telemarketing Scams
1/19/06, NCL News, wrote:
http://nclnet.org/news/2006/2005_fraud_trends_01192006.htm
2005 Fraud Trends: Official Report
http://www.fraud.org/2005_fraud_trend_report.pdf
Consumers Question eBay's Security
On 12/20/05, Martin H. Bosworth of www.consumeraffairs.com, wrote:
http://www.consumeraffairs.com/news04/2005/ebay_fraud.html
eBay Admits Growing Fraud Problems
On 12/16/05, Geoff Duncan of Designtechnica News, wrote:
http://news.designtechnica.com/article9083.html
SAN ANTONIO MAN CONVICTED OF EBAY SCAM
On 3/3/05, John Yembrick of the United States Attorney General for the Southern District of Texas wrote:
http://www.usdoj.gov/usao/txs/releases/March2005/050303-Schoffner.htm
Online auction scams soar, Complaints nearly double
On 2/2/05, Carolyn Said, Chronicle Staff Writer (www.SFGate.com) wrote:
http://www.sfgate.com/cgi-bin/article.cgi?f=/c/a/2005/02/02/COMPLAINTS.TMP
AND these are but stories from the past year, or so.
Here is another telling statistic, which reveals eBay's refusal to face up to reality. When reporting the top ten scams of the year, the National Consumers League noted:
"In the fall of 2003, online giant eBay removed the link from it's site, http://www.fraud.org. As a result, the number of auction complaints reported dropped to 1/6 its previous level. Based on statistics prior to eBay's action, NCL estimates that there would have been 30,720 auction complaints in 2005, representing 71 percent of complaints."
Should eBay continue to IGNORE this problem AND fail to get in front of it, the number of victims will continue to grow.
Is Asia Becoming a Greater Target for Fraud
In fact, Bangalore is becoming a center for "Information Services." Here is an earlier post, I did about that and fraud implications:
What are the Security Implications of Outsourcing
Here is evidence that one international corporate entity (Visa International) that recognizes this and is taking action.
The Edge Daily is reporting:
Visa Asia Pacific has uncovered and shut down 20 spoof websites to prevent cardholders from succumbing to online data theft. Here is the story regarding Visa's Asian adventure:
Visa shuts down 20 spoof, phishing websites
Here is another story regarding the same issue, but more of a warning:
Visa Remind Cardholders To Ignore E-mail Scams
Both of the articles suggest a resource for reporting phishing that is new, to me at least:
phishing@visa.com
There are many, who fear the implications of internet crime in Asia. I fear it not only in Asia, but everywhere in the world. The key is protecting each other through awareness AND realizing "It's a Small World After All."
Friday, February 17, 2006
Who Really Profited in the Hurricane Disasters
"The Senate as well as the White House should conclude from this story that FEMA "reform" cannot amount to mere organizational change or undue attention to the overworked question of whether the agency belongs inside DHS. The agency needs some much simpler changes, too: It could start, for example, by learning who made these terrible decisions and relieving them of their duties immediately."
Apparently, along with the rampant fraud that was going on, FEMA spent 900 million on modular homes, which by their own regulations aren't permissible for use in the area they bought them for. These homes will now be sold for pennies on the dollar and many of them have warped from sinking into the mud.
Here is the editorial from the Washington Post:
Waste, Fraud and Abuse
I did a post on the fraud in Katrina, where I stated: No Wonder We are Facing a Budget Crisis.
In this post, I estimated fraud could have been 691 million. This was based on figures cited in an article, I read.
Perhaps someone should be taking a closer look at this....specifically to see who profited from it?
Thursday, February 16, 2006
Internet Crime Predictions for 2006
2005 saw internet crime becoming more and more prevalent. Here is a press release from the National Cyber Security Alliance and the Department of Homeland Security predicting what is in store for us in 2006:
According to the 2006 Department of Homeland Security and NCSA Emerging Internet Threat List (http://www.staysafeonline.info/basics/2006threatlist.html) viruses continue to pose a threat to consumers, as malicious codes become more sophisticated and targeted towards popular activities, such as Instant Messenger and text messaging. Wireless devices, such as PDAs and cell phones are also becoming increasingly more vulnerable to hackers and viruses. Phishing continues to be an ongoing threat to consumers as they become more prevalent and sophisticated in obtaining consumers’ personal and financial information. Five online preparedness best practices are also highlighted to offer consumers the necessary tips on how to take action against cyber thieves and avoid becoming victim to Internet crime this year.
Emerging Threats for 2006:
Hackers use Instant Messaging to spread viruses and worms.
Phishing fraud becomes more prevalent and sophisticated.
Viruses attack cell phones and PDAs.
Hackers target online brokerage accounts.
Online Preparedness Practices:
Practice the core three protections – install, configure, regularly update.
Do not open unexpected emails.
Do not download attachments in unsolicited emails.
Take precautions to protect your mobile devices.
Here is a link to their Stay Safe Online site, which has a lot of relevant information on how to protect yourself from these threats.
The Anti-Phishing Working Group (APWG) just released their December Phishing Activity Trends Report, which shows an increase in activity. They reported 4,630 sites distributing crimeware in November to 7,197 in December.
Here is the definition of crimeware from Wikipedia:
"Crimeware (as distinct from spyware, adware, and malware) is designed to (through social engineering or technical stealth) perpetrate identity theft to access a computer user's online accounts at financial services companies and online retailers for the purpose of taking funds from those accounts or completing unauthorized transactions that enrich the thief controlling the crimeware."
"Crimeware can surreptitiously install keystroke loggers to collect sensitive data—login and password information for online bank accounts, for example—and report them back to the thief. A crimeware program can also redirect a user's browser to a counterfeit website controlled by the thief even when the user types the website's proper domain name in the address bar. Furthermore, crimeware can wait for the user to log into their account at a financial institution, then drain the account behind the scenes."
Knowledge and awareness are the best defenses against internet crime. Unfortunately (all too often), internet crime goes unreported. A good place to report internet criminal activity is the Internet Crime Complaint Center (FBI).
Reporting it provides valuable intelligence (real time) to the cyber crime warriors, who are out there protecting US!
