Showing posts with label identity theft. Show all posts
Showing posts with label identity theft. Show all posts

Sunday, March 27, 2011

Anatomy of a Scam - Secret Shoppers

Here's a recent example of a secret shopper scam. Like many scams, this one attempts to lure people who think that accidentally receiving a secret shopper invitation is a way to free money. In the end, it is merely an attempt at identity theft - though it may also involve a fee scam as well!

If the recipient bothers to check who it is from, it purports to come from Dow Chemical, with an email address that is recruit@hsbrv.net, with a cc to david212@blumail.org. The hsbrv.net domain points back to a Betty Prevo, with an email address listing mark212@blumail.org. That sounds suspiciously like our david212 address as well. The whois results are below:

Administrative Contact:
Prevo, Betty mark212@blumail.org
1368 X W. Estes Ave
Chicago, Illinois 60626
United States
For those who are interested, that address points to an apartment building in Chicago. Interestingly, Betty Prevo apparently exists and does live in that area in Chicago, but she'd probably be interested to find out that she's running various domains.

Blumail? Well, it's a free email service that, "provides global e-mail accounts, educational content, employment needs, entrepreneurship, networking, story / experience sharing, mentoring and volunteering opportunities to youth and others who are coming online in developing countries." In this case? It's a great place for a scammer to get free email hosting. It's also a well known 419 scam domain. Blumail is a legitimate service, unlike the hsbrv.net domain we first looked at.

Now, the actual scam letter:

Hello there,

My Name is David Anderson and I am your group regional Instructor from within the USA.Henceforth you will be working with me on the completion of your Mystery Shopper's Position application. Like you already know, your weekly per assignment is $300:00 Flat for working with us and will come in payments of $300 each per assignment you complete for the company.
Note that the name actually somewhat matches the email address - that's often a missed detail for our scammers.
PAYMENT TERMS:
Your payment would be sent ($300) per assignment , Also the company is in charge of providing you with all expense money for the shopping and other expenses incurred during the course of your assignment.All the tools you will needing would be provided to you with details every week you have an assignment.

JOB Description :
1} When an assignment is given to you,You would be provided with details to execute the assignment and in a timely fashion.
2} You would be asked to visit a company or store in your area and they are mostly our competitors as a secret shopper and shop with them to know more about their sales and stock , cost sales and more details as provided by the company then report back to us with details of whatever transpired a the store. But anything you buy at the shop belongs to you,all we want is an effective/quick job and reports.
Free money, and what sounds like a somewhat reasonable reason why the company would want you to do this. The grammar is even better than most letters of this type.
ASSIGNMENT PACKET :
Before any assignment we would provide you with the resources needed {cash}Mostly our company would send you a check which you can cash and use for the assignment. Included to the check would be your assignment packet .Then we would be providing you details on here. But you follow every single information given to you as a secret shopper .
It starts to fall apart here with lines like "Then we would be providing you details on here".

And now for the meat of the scam:
KINDLY RECONFIRM YOUR INFORMATION BELOW TO PROCEED ON FIRST ASSIGNMENT:
Full Legal Name :
Full Physical Address :
City :
State :
Zip code :
Age:
Nationality :
Home and Cell # :
Present Occupation:
Email:

Thank you for reading.
Yours sincerely.
Contact Person: David Anderson
Time: 24 Hours daily by e-mail
And that's the anatomy of a secret shopper scam. A simple way to hook the gullible into providing details for identity theft.

Thursday, September 16, 2010

A Different Angle on Identity Theft: When Identity Thieves Use Your Identity

The story of Dr. Gemma Meadows, as reported by MSNBC is an intriguing one. Like many victims of identity theft, she was contacted by her bank and informed of fraudulent activity. What happened next though, is a bit off the normal path for identity theft victims.

Various packages with a wide range of values started to show up, and have continued to show up. Now, Dr. Meadows spends time tracking and returning packages, as well as fielding calls from various vendors from whom the items are ordered.

Why? According to the article, and what she has been able to determine, the identity thieves are using her information to test validation scripts on e-commerce websites. Her valid address, phone, and other details are being used to make transactions appear valid.

Interestingly, the scripts seem to work in some cases, flagging the transactions as possible fraudlent. The article mentions that some sites note that the item is to be shipped thousands of kilometers away from the order location, and that others call to verify that she is the one placing the order. Many others, however, don't do as well, and the stream of packages continues.

The article is well worth a read. We're used to seeing lives disrupted by identity theft and the credit and financial issues that can go with it. Receiving packages when criminals use your identity to support their crimes in a different way is an entirely different event, and appears to be one that law enforcement and our database driven society isn't geared to handle.

Monday, July 13, 2009

CVV2 Irony Redux

Creative Commons attribution licensed image courtesy of Flickr user Andres Rueda

After my recent post about How Not To Sell CVV2's, it was only a matter of time until a CVV2 spammer posted a reply. Yesterday, one came in. Rather than post it, I'll list some of the interesting details.

Here's the price list:
1 US ( visa,master) = 2$/1cvv ( buy > 50 Price $1.5/1cvv)
1 US (Amex,dis) = 3$/1cvv ( buy > 50 price $2/1cvv)
1 US with DOB = 12$/1cvv
1UK = 6$/ ( Buy > 50 price 5$/1cvv)
1UK CVV with DOB = 15$/CVV ( Buy > 50 CVV Price 12$ = 1CVV)
1 Ca CVV = 8$/CVV
1 CA CVV(Amex,dis) = 7$/cvv
1 EU CVV = 15$/CVV
1 EU CVV(Amex,dis) = 15$/cvv
1 US CVV full info = 80$/CVV
1 UK CVV full info = 100$/CVV
In general, prices for non-US countries were higher, as were prices for a credit card with full details on the owner, or one with a date of birth associated with it.

The seller provided ICQ, MSN, and Yahoo contacts, a website, and payment methods via both LibertyReserve and WMZ. They also specified that they did not sell dumps with pins, bank logins, or ATM skimmers. Interestingly, the poster also offered rapidshare premium accounts, including a bonus free account if you bought more than 30 CVV2 numbers. Differentiation in the marketplace is definitely occurring.

Friday, September 26, 2008

NACUBO: The FTC's Red Flag Rule Identity Theft Prevention Rule May Affect Colleges

The National Association of College and University Business Officers notes that the FTC's Red Flag rule likely applies to colleges. For security analysts, this means that your identity theft prevention procedures and policies may get a federally mandated update.

Two parts of the rule may apply to colleges - first, that users of consumer reports must develop reasonable policies and procedures when they receive notification from a credit agency that there is an address discrepancy. Second, that financial institutions and creditors holding covered accounts must develop a written identity theft prevention program for their accounts.

NACUBO points out that many of the activities and accounts offered by higher education might cause such organizations to fit the rule. These include Perkins loans, institutional loans, and other similar activities.

NACBU also provides a nice breakdown of the FTC rules. This is a good one to point out to your university administration if they're not aware of it yet.

Tuesday, September 16, 2008

Identity Theft and VISA giftcards

A recent news article shows another way to use a stolen credit card: write the magstripe to a gift card that won't be questioned when it is processed. In this case, the cards were used to purchase cigarettes, which are difficult to trace. The criminals' only mistake was returning to the place that they purchased the cigarettes to make a second transaction.

With magstripe encoders a commodity item, this is an easy way to avoid questions about a name not matching on a card. Small transactions in stores without cameras would make for a very difficult to trace crime.

Tuesday, April 1, 2008

FERPA updates: Recommendations for Safeguarding Education Records

On March 24th, the Department of Education released 34 CFR Part 99, "Family Educational Rights and Privacy; Proposed Rule". This is a proposed update to FERPA (the Family Educational Rights and Privacy Act of 1974).

The document lists a number of recent incidents, ranging from grade exposures to SSN and personally identifiable information disclosures, and suggests that a number of steps are available to organizations after exposure. Most organizations should have similar steps in their incident response plan - if you don't, this provides at least a basic overview of the steps you'll want to take.

Remember, FERPA does not have a specific requirement regarding notification of students in the event of unauthorized release or theft of their education records - but organizations are required to maintain a record of each disclosure. This is very different many existing SSN and other PII disclosure laws.

As noted in the document, the Office of the Inspector General does provide a student focused identity theft resource site: http://ed.gov/about/offices/list/oig/misused/idtheft.html as well which includes a list of steps to take for victims: http://ed.gov/about/offices/list/oig/misused/victim.html. The FTC's identity theft guide is still an excellent resource as well: http://www.ftc.gov/bcp/edu/microsites/idtheft/

Thursday, March 27, 2008

Identity theft: Income tax returns and stolen identities


The University of California's Irvine campus recently made the following announcement:

UC Irvine has received more than 50 reports that Social Security numbers have been stolen and used to file fraudulent tax returns to gain refunds. Victims are identified as current and former UCI graduate students and medical students. In most cases, the students have discovered the issue when they electronically submit their federal income tax returns and the IRS informs them that someone has already filed using their name and Social Security number.
This should be particularly disturbing to people, as it isn't simple credit card fraud - actual tax returns were filed using these Social Security numbers. Not only could this cause real hassles in dealing with the IRS if it becomes a widespread issue, but it means that attackers have discovered how little validation there is in the IRS tax return system and exploited it to their advantage.

This is the first time I've seen a report of relatively large scale tax return fraud with the intent to make money from returns on more than an individual basis, but, if it is successful and doesn't result in a successful investigation, it likely won't be the last.

It will be interesting to see if similar issues occur as other campuses dealing with SSN exposures. The IRS is handling it reasonably well - they're allowing second, valid returns to be filed, and are asking the affected individuals to file police reports. It is worth noting that they are requesting a paper tax return be sent to a specific office: online tax return submission may make this exploit much easier.

UCI now gets to try to find out if they were the source of a data leak - from the FAQ on their announcement page:
Q. Does this appear to be an isolated case?
A.
There are more than 50 cases at UCI, but this currently appears to be focused on graduate and medical students.
With that sort of pattern, we may well see a breach announcement in the near future as required by the California Breach Disclosure Act - UCI notes that they are currently investigating.

Flickr Creative Common licensed image credit to Matt Honan.

Sunday, March 2, 2008

Fighting data exposure in small claims court

StorefrontBacktalk's Eric Schuman writes about Theodore Karantsalis's pursuit of Wells Fargo and Sprint Nextel for exposing his personally identifiable information. Interestingly, in this case Karansalis went after both companies in small claims court, claiming that class action rarely saw any real return to the consumer, and that it was often not in a reasonable timeframe.

Schuman asks an interesting question - what happens to large corporations if consumers begin to sidestep the normal process of litigation and take their claims to small claims court. Often, large companies will settle rather than fight, as their costs are higher than the small payouts requested. Karatansalis requested three times the cost of a PGP license ($597) in his claim, and received it. If this became a standard practice, corporations would have to defend themselves more actively, or establish precedent against such claims - something that would be difficult to do if consumers can show real costs associated with the loss of their data.

The original StorefrontBacktalk article can be found here.

Tuesday, February 5, 2008

Credit reporting - getting your credit score for free


As I discussed recently, you don't have to have your credit score to monitor your credit for identity theft.

Lots of people still want to see their credit score, and it does give you a reasonable gut feel for how your credit is doing. Fortunately, MyMoneyBlog has five ways you can get your credit score for free.

Remember that each reporting agency and method is likely to be somewhat different, so don't expect scores from multiple agencies to be identical. If you're trying to get a, er, ballpark idea of your credit rating, and you want to watch for big drops, these might be a useful option for you.

Monday, January 28, 2008

Top Five Ways to Protect Yourself From Identity Theft

Identity theft is big business these days. Between 10 and 15 million Americans were victims of fraud that stemmed from identity theft between mid-2005 and mid-2006. The average loss more than doubled as well, from $1408 to $3257. With numbers like that, more and more people are wondering how to keep their credit and their identity safe.

Fortunately, there are a number of simple things you can do to help protect both.

1. Review: Get a free Credit Report

Your credit report shows what credit you have - a who, what, and where of your financial standing. Simply reviewing your credit report three times a year using the free credit reports available through www.annualcreditreport.com and checking for things that you don't recognize can help save you. Be careful, and use the official site.

When you receive your report, you will not receive your credit score. You don't need it to help protect your identity, so don't worry. Look for accounts that aren't familiar, addresses you don't recognize, and anything that you are not familiar with.

Since each of the credit agencies will give you at least one free credit report a year (and in some states, or other certain circumstances, more), you can check your credit report every four months. Think of this as preventative maintenance like changing the oil in your car, and
set a reminder for yourself.

The credit agencies are:

2. Guard: Protect Your SSN

Your Social Security Number or SSN is used for many identification purposes. Everything from taxes to credit applications to health insurance relies on Social Security numbers, and that makes them one of the most frequently targeted pieces of personal information. You can help protect yours by only giving it when required - many forms request it, but do not require it.

A few tips:
  • Never write your social security number on a check
  • Don't provide your SSN over the phone unless you have dialed the company yourself, and you trust the company.
  • Don't carry your Social Security card unless you need it - most people can keep their Social Security card at home in a safe place, rather than in their wallet where it can be stolen along with credit cards and a driver's license or other personal data.
3. Dispose: Properly dispose of records, receipts, and credit applications.

Shred statements, receipts, credit card applications and checks, and any other records that you throw away. A diamond or crosscut shredder is always preferable to a strip cut shredder, but any shredding is better than throwing them away intact.

4. Monitor: Check your financial statements, and keep accounts up to date.

Monitor bills and other financial statements such as bank statements regularly. Check for charges you didn't make, or locations that are unfamiliar. In addition, make sure that all of your accounts are up to date, and that addresses and other contact information are current. This ensures that you receive your bills, replacement credit cards, and that the companies can contact you in the event of a problem.

5. Cleanup: Cancel old accounts, and remove yourself from mailing lists.

You can remove your name from the Direct Mail Association's Mail Preference Service at https://www.dmachoice.org/MPS/, which will help cut down on junk mail and credit offers. You can also opt to not receive pre-screened credit offers at http://www.optoutprescreen.com/.

Canceling old accounts helps to ensure that credit cards aren't sent to old addresses, and keeps your unused cards from being abused without your knowledge. Not carrying extra cards can also help to make you safer if you do lose your wallet - you'll be less exposed, and you'll still have a card that you can use while you wait for replacements.

Simple maintenance can really help to protect your personal information and your credit. Make these steps a part of your everyday habits, and you can feel confidence that you're taking the right steps to protect your identity!

Creative Commons licensed photo credit Flickr user shawnzlea

Monday, August 27, 2007

Dial an Identity Thief: a story from the front lines

A co-worker was kind enough to share his story of attempted identity theft today:

I received a interesting phone call on my office phone this morning.

The caller claimed to be with the 'recovery department' of a company in New York. The caller spoke English very poorly and the connection was noisy, so I never did figure out the name of the company he supposedly represented.

The caller claimed to be calling about $650 that was supposedly withdrawn from my account (not sure what kind of account, or where) several years ago, apparently without my permission. He wanted to confirm some information, so he could return the money to me. He was difficult to understand, but I am fairly certain that he said he needed my credit card number.

We went around and around for several minutes, as I tried to figure out who he supposedly represented and how much information he already had. I finally told him that if he knew how to reach me by phone, he should also know how to reach me by mail, and he should simply send me a check.

Callerid on my phone reported that the call originated from 1234567890. That number is completely bogus. The caller was probably using an internet phone; it is relatively easy to fake callerid with an internet phone.
My thanks to the co-worker for giving permission to post his story. The moral of the story here is to always ask questions, to not give up information without verification, and to always know the identity of your callers. How would you respond to a call like this? What would you do if the callerID had matched a local bank instead of a number you didn't recognize?

I normally advise people to call the company back - ask for a number that you can verify in their website and call that number. If they can't provide that information, ask them to send you more information using your contact information on file. And, as always, the FTC identity theft website is a great resources. While you're at it, you may also want to check out the Privacy Rights Clearinghouse.

Monday, May 14, 2007

RSnake and the phisherman

RSnake has a very interesting interview with a phisher on his blog.

There are a number of obviously interesting points - the high level of password re-use, the price that accounts can get, and that the anti-phishing technologies are starting to become annoying to the professional thief. I'm sure I'll be seeing the blog post quoted in more than one Powerpoint presentation this year.

What stood out to me, however, is why lithium got started - he saw an opportunity in the spam email his parents were receiving and thought that he could do it better. That's how many entrepreneurs get started, and is, in many ways how technical folks tend to think. This creates an arms race for technical superiority.

Where does RSnake's article leave us? I think it reminds us to remember that a lot of today's hacking world is built on a profit motive. While a certain crowd is definitely still in it for the fame, the more serious threats are from people who make their living stealing cycles, identities, and money.

Or, to put it another way...they get paid to do this. Is your organization treating external threats like they are professionals?