Saturday, April 14, 2007

Oprah's name spoofed in sweepstakes scam

At about the same time, Oprah did a show on Internet scams, the Illinois Attorney General (Lisa Madigan) issued (another) alert about scammers using Oprah's name to instill (trust) in the garbage they send.

Although, Oprah has run some sweepstakes recently, this one is a scam!

From Attorney General Madigan's press release:

According to Harpo Productions, Inc., which produces The Oprah Winfrey Show, several legitimate sweepstakes were held in the summer of 2006 through Oprah.com but all winners were previously notified. Harpo Productions, Inc. has not sent any letters in 2007 announcing additional winners for this sweepstakes. The sweepstakes letters being mailed to consumers have a check enclosed that is made payable to the letter recipient. The checks look real but are actually counterfeit. Consumers should disregard these letters and should not attempt to cash the checks.

The letters and checks are props in an especially devastating form of consumer fraud—conning check recipients into believing the checks are real, convincing recipients to deposit the checks into their banks, and even persuading the recipients to wire their own money to the con artists.

Full release, here.

Oprah covered this (and a lot of other scams) on her show yesterday, which can be seen on her site, here.

She also mentions this and another scam involving tickets to see her show on her site, here.

Tom Fragala (MyTruston) and I collaborated on a post about counterfeit checks being used in a variety of I-Scams a few months ago:

Counterfeit Cashier's Checks Fuel Internet Crime

Oprah's name is being used because of her immense popularity, which is a common theme in a lot of this activity. Popular brands, disasters and even government agencies are used in same manner, also!

Friday, April 13, 2007

Symantec's Family Resource Web Site

Symantec has launched a new web page designed to educate children (and their parents) about how to avoid the (sometimes) murky waters of the Internet.

The goal of the page is to (in their own words):

Our goal is to help parents provide guidance to their children who are using the Internet . We want you to keep your children and your computer safe online, and help you make sure your children are good cybercitizens. With your direction and supervision, the Internet can be a positive, safe place for your child to research, learn, communicate, and socialize.

The page can be viewed, here.

Symantec has also hired someone to administer this effort (Marian), who writes columns to support the page.

You can even submit a question to her, here.

The page has links to other sites on this important subject, also:

iKeep Safe

Web Wise Kids

National Cyber Security Alliance

Taking the time to educate our children, as well as ourselves, on how to safely use the Internet is an important effort!

Thursday, April 12, 2007

Sage Predictions on the State of Cyber Crime from McAfee

According to McAfee, cyber crime is growing and as soon as the good guys (white hats) close one loophole, the bad guys (black hats) exploit another.

Unfortunately, technology grows faster than laws and security fixes. Criminals, who are becoming increasingly organized, realize and exploit this fact, frequently.

The report confirms predictions that exploiting VoIP and mobile devices will become more common.

Vishing will probably become more dangerous than phishing - it adds a more personal (voice) touch to tricking people into giving up their personal details. VoIP (cheap long distance) is one of the reasons for this. Since caller-id spoofing is easily available and legal, it makes sense that a lot of people are going to fall victim to vishing attacks.

Also covered is the growth in music and software privacy. Billions of dollars are being lost in both these areas - systems are now being sold with pirated software already installed on them.

To me, this shows how organized, the activity is becoming!

The report also covers RFID technology (quickly becoming commonplace) and how easily it can be exploited. Despite warnings from a lot of concerned experts, we seem to be implementing this technology at a foolish pace (my emphasis).

McAfee deserves recognition for having the courage (there is a lot of money behind RFID technology) to point out the dangers behind this highly profitable, but dangerous (my emphasis), technology.

Enough ranting for the moment, I highly recommend reading the full report, which can be viewed, here.

Wednesday, April 11, 2007

Warning if you don't open (and respond) to snail mail from American Express, they will sell your personal information!

I get snail (mostly junk) mail from credit issuers, daily. Being concerned about identity theft and my personal privacy, I try to shred all of them. But am I doing the right thing? As you will see, some of them probably hope I never do.

Here is what happened to someone, who is a lot more diligent than I am (he actually opens the mail). Christoper Null (ATT/Yahoo Tech blogger) got his most recent privacy notice from American Express, which informed him if he didn't want all of his personal and financial information sold, he needed to opt-out with them.

They gave him two methods to do so, snail mail and a 1-800 number. Chris selected the 1-800 number and here is what happened:

I call (800-297-8378 if you want to try it for yourself). I get a recording welcoming me American Express and notifying me that the call could be recorded... thenabruptly says: "The computer system needed to answer your questions is not available." And it hangs up.

Now I understand computers go down, but that was five days ago, and I'm still getting the recording. Will it ever come back online or is it all a scam? The paranoid side of me believes that there is no computer connected to this 800 number, and that it's designed to trick me into forgetting about the entire matter and being too lazy to fill out the paperwork so I'll remain opted in.

According to several comments on his post, the 1-800 was down for quite awhile.

He later (being the saavy tech guy he is) tried to go to their webstite to opt-out and was only able to opt out from electronic, not snail communication.

Very REVEALING post from Chris, here.

It is pretty scary that credit card companies require us to opt-out, and if we don't, they sell our information to, anyone and everyone. After all, selling information, is highly profitable.

The Personal Finance Blog did a post about how much personal information is worth (retail-value), here.

The post is about a year old, and the prices might vary, depending on who is selling it.

I guess the finance industry has found a way to get around recent privacy concerns, and they do it under the guise of a privacy notice!

It's no wonder there is so much identity theft!