Showing posts with label cybercrime. Show all posts
Showing posts with label cybercrime. Show all posts

Thursday, January 27, 2011

Search Warrants Executed - Cyber Investigation

Search Warrants Executed in the United States as Part of Ongoing Cyber Investigation

Washington, D.C.
January 27, 2011 FBI National Press Office
(202) 324-3691


FBI agents today executed more than 40 search warrants throughout the United States as part of an ongoing investigation into recent coordinated cyber attacks against major companies and organizations. Also today, the United Kingdom’s Metropolitan Police Service executed additional search warrants and arrested five people for their alleged role in the attacks.

These distributed denial of service attacks (DDoS) are facilitated by software tools designed to damage a computer network’s ability to function by flooding it with useless commands and information, thus denying service to legitimate users. A group calling itself “Anonymous” has claimed responsibility for the attacks, saying they conducted them in protest of the companies’ and organizations’ actions. The attacks were facilitated by the software tools the group makes available for free download on the Internet. The victims included major U.S. companies across several industries.

The FBI also is reminding the public that facilitating or conducting a DDoS attack is illegal, punishable by up to 10 years in prison, as well as exposing participants to significant civil liability.

The FBI is working closely with its international law enforcement partners and others to mitigate these threats. Authorities in the Netherlands, Germany, and France have also taken their own investigative and enforcement actions. The National Cyber-Forensics and Training Alliance (NCFTA) also is providing assistance. The NCFTA is a public-private partnership that works to identify, mitigate, and neutralize cyber crime. The NCFTA has advised that software from any untrustworthy source represents a potential threat and should be removed. Major Internet security (anti-virus) software providers have instituted updates so they will detect the so-called “Low Orbit Ion Canon” tools used in these attacks.

Monday, May 10, 2010

Happy Birthday IC3

The Internet Crime Complaint Center (IC3) is celebrating 10 years of crime fighting.

IC3 was established in May 2000 as a partnership between the National White Collar Crime Center (NW3C) and the Federal Bureau of Investigation. The organization gives victims of cybercrime a convenient and easy-to-use reporting mechanism that alerts authorities of suspected criminal or civil violations. IC3 provides law enforcement and regulatory agencies at all levels a central referral system for complaints involving Internet-related crimes.
“Since its creation in 2000, we have seen the number of complaints coming into IC3 increase year after year. Cybercrime is not going away and, in fact, is only going to continue as criminals become savvier,” said Don Brackman, Director of the NW3C. “We are so proud to be partners with the FBI in operating IC3 to address this growing global issue.”

Tuesday, April 27, 2010

Compensation for Scam Victims

Don't get too excited thinking that I am going to share with you the secret to recovering money that you lost to a scam. Nope . . . it is just the title for the scam email that I want to share with you this week.

From: dr.jfisher55@gmail.com;

COMPENSATION AWARD FOR SCAM VICTIMS

Hello,

I'm Dr. John Fisher... ed. T.H.Turner (London, 1855), Coll. No. *VIII, II, 263-272. 10) - Erasmus, Ep., I, 415, I'm 51yrs Old. I'm one of those that took part in the Compensation in awards many years ago and they refused to pay me, I had paid over $18,000 while in the London, trying to get my payment all to no avail.

So I decided to travel down to the Compensation and lottery company with all my compensation documents, And I was directed to meet Mr. Larry Gold, who is the member of COMPENSATION AWARD AUTHORITY and a Human Rights Activist (Lawyer), and I contacted him and he explained everything to me. He said whoever is contacting us through emails are fake.

He took me to the paying bank for the claim of my Compensation payment. Right now I'm the most happiest man on earth because I have received my compensation funds amounteing to $750,000 Moreover, Mr. Larry Gold, showed me the full information of those that are yet to receive their payments and I saw your email as one of the scam victims, that is why I decided to email you to stop dealing with those people, they are not with your fund, they are only making money out of you. I will advise you to contact Mr. Larry Gold

You have to contact him directly on this information below.

COMPENSATION AWARD AUTHORITY

Name : Mr. Larry Gold (Barrister)
Email: barristerlarrygold@lawyer.com
Telephone: +8613925551141

You really have to stop dealing with those people that are contacting you and telling you that your fund is with them, it is not in anyway with them, they are only taking advantage of you and they will dry you up until you have nothing.

The only money I paid after I met Mr. Larry Gold was just $350 USD for the paper works, take note of that.

Thank You and Be Blessed.

Dr. John Fisher... ed. T.H.Turner (London, 1855),
Coll. No. *VIII, II, 263-272. 10) - Erasmus,
Ep. Education: BS, Business Administration


dr.jfisher52@gmail.com

-----------------------------

So how do we know this is a scam? If there really was a way to recover the money lost in a scam the information would be all over the news and on every government website so that all scam victims could contact the correct people and recover their money.

Second, a Google search of the phone number shows that it is listed on MANY scam fighting sites, and that it is a phone number from China. Strange . . . the person in this email claims to be in London.

He even tries to tell you that you need to stop listening to the scammers because they will only lie to you and drain your funds . . . this is the only truthful thing in this email.

Saturday, April 17, 2010

Hiding behind the email

You just got an email and it looks like it is really from a local business or organization that you know. Is it possible that it could be from a scammer? The answer is yes. Scammers use a technique called spoofing to do this.

What is spoofing? Well, if you want to go and read the technical definition of it, you can go here, but for those of you who are like me and some of the technical talk starts to sound like "blah, blah, blah" here are the spoofing basics.

Spoofing is when the person who sent the email makes it appear like the email cam from a different email address. One of the clues would be if the From line in the email has a different address than the Reply To line of the email.

Why would anyone want to do this? Well, the scammers take on many different profiles, and since they are trying to gain your trust, and your money, they have to make it LOOK like they really are who they say that they are. If they can spoof an email address of a well know business, and in their email they say they are with that business, there are some people who are not as internet savvy that will believe that the scammer is really who they say they are or associated with the company they claim to be with simply because the email address appears to be from that company.

Email spoofing is a common tool used by internet scammers, since it allows them to hide behind the identity of another person or company.

Thursday, April 15, 2010

Look inside your emails

I have never claimed to be a internet or computer know it all, so I have learned to do some research and look to those who do know more on the "technical" side of how things work when I need to. When I decided I wanted to talk to my readers about the information inside of an email, spoofing, hacking and IP addresses I knew I was entering into a world that I am not comfortable with . . . seriously, all of the technical talk starts to sound like "blah, blah, blah" to me. So that is when I contact my friend and fellow scam fighter at CyberCrimeOps.com

Ironically, he wrote an article just this month about a LOT of the things that I wanted to touch on. Here is a sample . . .

Some of you reading this article may have seen news reports of people getting alarming email messages from their friends.
Tales such as "Help, I'm stranded in Nigeria and need money" have come to many people as a surprise in recent months, and the trend seems to getting more widespread. The messages are coming directly from the email accounts of someone you know, and at first glance it may seem real. The truth, once discovered, is that the email account has been taken over (hacked [link]) by a fraudster, and the solicitations for money being sent out are a simple fraud. One question that seems lost in all of these news reports is "how did this happen?" -- Let's investigate this a little further and shed some light into this dark corner.
From Hack To Phish
Hacking covers a wide range of techniques, such as Security exploit; Vulnerability scanner; Packet Sniffer; Spoofing attack; Rootkit; Social engineering; Trojan horse; Virus; Worm and Key loggers; but for the purpose of this article we will concentrate on only one of these, social engineering.
"Social engineering is the act of manipulating people into performing actions or divulging confidential information. While similar to a confidence trick or simple fraud, the term typically applies to trickery or deception for the purpose of information gathering, fraud or computer system access; in most cases the attacker never comes face-to-face with the victim." (Source Wikipedia: [link])
Phishing [link] of course, comes under the general umbrella of social engineering and is a technique of fraudulently obtaining private information. People may associate Phishing with financial institutions (banks, credit cards and credit unions), eBay, PayPal and others due to a great many reports in press. However, one form of this phishing hides in relative obscurity, and asks not for banking details, but for your email account login credentials. If you get one of these emails, it may actually look very real indeed.
To read the rest of this article, go to CyberCrimeOps.com

Tuesday, April 13, 2010

It starts with an email

Here is a typical email that could show up in your inbox and start you down the path of becoming a scam victim if you don't know what to look for.


Subject: You Have A Package
From: Brenda.Kellen@marshall.k12.mn.us
Reply To: info@fedexdelivery.com
You have a bank draft of $580,000.00 USD , which await the outstanding payment of $95.00 Contact our dispatch unit for dispatch immediately. Contact person: Mr. Celin Smith, Email: fdexcourierdeliveryltd01@gmx.com  Tell: +234 807 363 6733

How do I know that this is a scam from just this small amount of information? Let me show you.

First, they tell you that you have a large amount of money just sitting there waiting for you, and all you have to do is just send them some money and they can release these funds to you.  This is used in inheritance and lottery scams on a regular basis.  If you really did have a large amount of money owed to you, and the only thing holding that money from getting to you was some sort of payment, they could take that payment from the amount owed and just send you your money.

Second, there are WAY too many email addresses going on in this email.  There is the one in the From line, which is probably spoofed or this person could have had their email account hacked into.  We will talk about spoofing and hacking later on this week.  Then there is a different email address in the Reply To line, which includes the term FedEx, but is not a legitimate FedEx extension . . . a simple Google search verified this.  Then, within the email there is a third email address, again with terms referring to FedEx, but if you look they are on the front part of the email address, the part after the @ is from gmx.com which is a free email service.  With free email services the person setting up the account has full control over the letter that appear before the @ in the email address.  I could go and create one right now that said WaltDisney@(insert free email service here) but that does not mean that the people who I am emailing are getting emails from Walt Disney.

Third, look at the phone number provided . . . Tell: +234 807 363 6733 . . . that is WAY too many numbers to be a United States phone number.  Another Google search tells me that 234 phone numbers are from Nigeria, and Nigeria is the number one country of these types of scams.

So what have we learned today?  Google is our friend, look at the email address and see if it is a free email service, and check your phone numbers.

Saturday, February 27, 2010

Take Action Cyber Security Awareness Reception

From Antiphishing.org, Tech America and StaySafeOnline.org

The Take Action Cyber Security Awareness Reception will be held on Tuesday, March 2 from 6pm - 8pm at B Restaurant and Bar Yerba Buena Gardens San Francisco

Thursday, February 4, 2010

Google and the hackers

Reposted from http://www.msnbc.msn.com/id/35231454/ns/technology_and_science-washington_post/

The world's largest Internet search company and the world's most powerful electronic surveillance organization are teaming up in the name of cybersecurity.

Under an agreement that is still being finalized, the National Security Agency would help Google analyze a major corporate espionage attack that the firm said originated in China and targeted its computer networks, according to cybersecurity experts familiar with the matter. The objective is to better defend Google — and its users — from future attack.

Google and the NSA declined to comment on the partnership. But sources with knowledge of the arrangement, speaking on the condition of anonymity, said the alliance is being designed to allow the two organizations to share critical information without violating Google's policies or laws that protect the privacy of Americans' online communications. The sources said the deal does not mean the NSA will be viewing users' searches or e-mail accounts or that Google will be sharing proprietary data.

The partnership strikes at the core of one of the most sensitive issues for the government and private industry in the evolving world of cybersecurity: how to balance privacy and national security interests. On Tuesday, Director of National Intelligence Dennis C. Blair called the Google attacks, which the company acknowledged in January, a "wake-up call." Cyberspace cannot be protected, he said, without a "collaborative effort that incorporates both the U.S. private sector and our international partners."

But achieving collaboration is not easy, in part because private companies do not trust the government to keep their secrets and in part because of concerns that collaboration can lead to continuous government monitoring of private communications. Privacy advocates, concerned about a repeat of the NSA's warrantless interception of Americans' phone calls and e-mails after the Sept. 11, 2001, terrorist attacks, say information-sharing must be limited and closely overseen.

"The critical question is: At what level will the American public be comfortable with Google sharing information with NSA?" said Ellen McCarthy, president of the Intelligence and National Security Alliance, an organization of current and former intelligence and national security officials that seeks ways to foster greater sharing of information between government and industry.

On Jan. 12, Google took the rare step of announcing publicly that its systems had been hacked in a series of intrusions beginning in December.

The intrusions, industry experts said, targeted Google source code — the programming language underlying Google applications — and extended to more than 30 other large tech, defense, energy, financial and media companies. The Gmail accounts of human rights activists in Europe, China and the United States were also compromised.

So significant was the attack that Google threatened to shutter its business operation in China if the government did not agree to let the firm operate an uncensored search engine there. That issue is still unresolved.

Google approached the NSA shortly after the attacks, sources said, but the deal is taking weeks to hammer out, reflecting the sensitivity of the partnership. Any agreement would mark the first time that Google has entered a formal information-sharing relationship with the NSA, sources said. In 2008, the firm stated that it had not cooperated with the NSA in its Terrorist Surveillance Program.

'Deficiencies'

Sources familiar with the new initiative said the focus is not figuring out who was behind the recent cyberattacks — doing so is a nearly impossible task after the fact — but building a better defense of Google's networks, or what its technicians call "information assurance."

One senior defense official, while not confirming or denying any agreement the NSA might have with any firm, said: "If a company came to the table and asked for help, I would ask them . . . 'What do you know about what transpired in your system? What deficiencies do you think they took advantage of? Tell me a little bit about what it was they did.' " Sources said the NSA is reaching out to other government agencies that play key roles in the U.S. effort to defend cyberspace and might be able to help in the Google investigation.

Jan 13: Washington has demanded an explanation from Beijing over claims by Google that the internet accounts of human rights activists have come under concerted attack from hackers.

These agencies include the FBI and the Department of Homeland Security.

Over the past decade, other Silicon Valley companies have quietly turned to the NSA for guidance in protecting their networks.

"As a general matter," NSA spokeswoman Judi Emmel said, "as part of its information-assurance mission, NSA works with a broad range of commercial partners and research associates to ensure the availability of secure tailored solutions for Department of Defense and national security systems customers."

Despite such precedent, Matthew Aid, an expert on the NSA, said Google's global reach makes it unique.

"When you rise to the level of Google . . . you're looking at a company that has taken great pride in its independence," said Aid, author of "The Secret Sentry," a history of the NSA. "I'm a little uncomfortable with Google cooperating this closely with the nation's largest intelligence agency, even if it's strictly for defensive purposes."

The pact would be aimed at allowing the NSA help Google understand whether it is putting in place the right defenses by evaluating vulnerabilities in hardware and software and to calibrate how sophisticated the adversary is. The agency's expertise is based in part on its analysis of cyber-"signatures" that have been documented in previous attacks and can be used to block future intrusions.

The NSA would also be able to help the firm understand what methods are being used to penetrate its system, the sources said. Google, for its part, may share information on the types of malicious code seen in the attacks — without disclosing proprietary data about what was taken, which would concern shareholders, sources said.

Greg Nojeim, senior counsel for the Center for Democracy & Technology, a privacy advocacy group, said companies have statutory authority to share information with the government to protect their rights and property.

Wednesday, January 27, 2010

Cyber - Education/Awareness

From http://calendar.bollearningconnect.com/main.php?view=event&eventid=1260215055941
You offer internet banking because it is cost effective for the bank and convenient for the customer.

And when you complete a risk assessment, you review E-SIGN rules and logon credentials and disclosures you give your customers. But have you evaluated your customer awareness program? The FFIEC authentication guidance issued several years ago tells us "Financial institutions have made, and should continue to make, efforts to educate their customers. Because customer awareness is a key defense against fraud and identity theft, financial institutions should evaluate their consumer education efforts to determine if additional steps are necessary." It goes on to say that management should both implement a customer awareness program and evaluate its effectiveness periodically.

Banks are being sued by their customers when a loss is incurred via internet banking. While some banks look to Reg E for guidance, it isn't always there, and it won't apply when your customer isn't a consumer. Have you taught your customers how to act and react when there is a threat? In this webinar we will discuss:


What should be in your customer awareness program?

How to educate customers about phishing;

What you need to do when a phishing attack occurs;

Is mobile banking safer than using a PC?

Are customers required to practice safe surfing?

What is safe surfing?

Is multifactor authentication "required" for all customers?

What is a strong password, and how often should it be changed?

And much more.

About the speaker:

Andy Zavoina Mr. Andy Zavoina, CRCM, is a consultant with the Glia Group, best known for its involvement with BankersOnline.com.

Andy has been in finance and banking for 22 years. Over 20 years were with a holding company with two Central Texas community banks that had $534 million in assets, 89 branches spanning Texas and nearly 500 ATMs. After starting in loan workouts, Mr. Zavoina has been a consumer, commercial and real estate lender and managed those departments as well as being the banks first Webmaster. He was responsible for compliance- management, -auditing, and -training for both banks.

Andy is a past Chairman of the American Bankers Association's Compliance Executive Committee. He was the 2003 recipient of the American Bankers Association's Distinguished Service Award for his involvement and accomplishments in the field of regulatory
compliance management. He currently serves on the Editorial Advisory Board for the ABA's Compliance Magazine, Compliance Action magazine, is a member of the ABA's Compliance School Board and is a BankersOnline Guru. He also served on the
Texas Bankers Association's Compliance Committee.

He is a graduate of the ABA National Commercial Lending School, National Compliance and National Graduate Compliance School and is a Certified Regulatory Compliance Manager with the Institute of Certified Bankers. He has written numerous articles and
lectured on compliance, the use of the Internet and technology as a tool, as well as compliance in cyberspace to local, state and national associations. Internet policies and other compliance related programs are made available on his personal Web site.

Wednesday, January 20, 2010

MYSTERY/SECRET SHOPPER SCHEMES

From http://www.fbi.gov/cyberinvest/escams.htm

01/20/10—The IC3 has been alerted to an increase in employment schemes pertaining to mystery/secret shopper positions. Many retail and service corporations hire evaluators to perform secret or random checks on themselves or their competitors, and fraudsters are capitalizing on this employment opportunity.

Victims have reported to the IC3 they were contacted via e-mail and U.S. mail to apply to be a mystery shopper. Applicants are asked to send a resume and are purportedly subject to an extensive background check before being accepted as a mystery shopper. The employees are sent a check with instructions to shop at a specified retailer for a specific length of time and spend a specific amount on merchandise from the store. The employees receive instructions to take note of the store's environment, color, payment procedures, gift items, and shopping/carrier bags and report back to the employer. The second evaluation is the ease and accuracy of wiring money from the retail location. The money to be wired is also included in the check sent to the employee. The remaining balance is the employee's payment for the completion of the assignment. After merchandise is purchased and money is wired, the employees are advised by the bank the check cashed was counterfeit, and they are responsible for the money lost in addition to bank fees incurred.

In other versions of the scheme, applicants are requested to provide bank account information to have money directly deposited into their accounts. The fraudster then has acquired access to these victims' accounts and can withdraw money, which makes the applicant a victim of identity theft.

Tips

Here are some tips you can use to avoid becoming a victim of employment schemes associated with mystery/secret shopping:

Do not respond to unsolicited (spam) e-mail.
Do not click on links contained within an unsolicited e-mail.
Be cautious of e-mail claiming to contain pictures in attached files, as the files may contain viruses. Only open attachments from known senders. Virus scan all attachments, if possible.
Avoid filling out forms contained in e-mail messages that ask for personal information.
Always compare the link in the e-mail to the link you are actually directed to and determine if they match and will lead you to a legitimate site.
There are legitimate mystery/secret shopper programs available. Research the legitimacy on companies hiring mystery shoppers. Legitimate companies will not charge an application fee and will accept applications online.
No legitimate mystery/secret shopper program will send payment in advance and ask the employee to send a portion of it back.
Individuals who believe they have information pertaining to mystery/secret shopper schemes are encouraged to file a complaint at www.IC3.gov.

Wednesday, January 13, 2010

BBB Top 10 Scams for 2010

From http://www.myfoxtwincities.com/dpp/news/bbb-stats-pedict-scams-january-12-2010

ST. PAUL, Minn. - The recession has thousands of people out of work, but the scam artists are hard at work. In year ahead, the Better Business Bureau says they are likely to come at you from every angle.

No one knows that better than the Bureau’s Dan Hendrickson.

“The people that are out there trying to get information dishonestly are very persistent, said Hendrickson. “And they will keep on coming at you and that’s way you always have to be on guard.”

The Better Business Bureau has looked at the past to try and predict what will happen in the future, in this case the next year. For 2010, it has put together its own Top Ten List of scams:

1. Winter Olympics Scams. This year’s Olympic Games are fairly close by in Vancouver, British Columbia. A little known fact is that U.S. citizens can buy event tickets only through www.cosport.com . Buy your tickets anywhere else, and the BBB says you risk losing your money. It also advises consumers to be aware of travel packages that don’t provide accommodations.

2. Census Scams. At its core the government Census is about counting people. For the crook it’s about counting something else. The BBB fears that under the guise of collecting data, scammers will try to trick people into giving out banking and other personal information. The Census WILL NOT contact you by email, and if a Census worker comes to your door, you have the right to ask for their credentials proving they work for the Census.

3. Green Remodeling Offers. President Obama and Congress are giving away tax credits for qualified remodeling projects that reduce energy consumption. When working with a contractor, homeowners should have a clear understanding of what makes a product or appliance green and if it benefits them. Also, check the credentials of the contractor with the Better Business Bureau or the state licensing agencies.

4. Job Scams. In this recession, scammers will try to rope people into fraudulent re-shipping schemes or offer jobs in exchange for an upfront payment.

5. Pre-Acquired Account Marketing Offers. It’s a high-brow term for a low-brow attempt to take your money. It happens when you buy something on line and you suddenly get a pop-up offering discounts to the store from which you just made a purchase. By clicking on these offers to save, customers unknowingly sign up for memberships which result in a monthly bill.

6. IRS Related Scams. These are typically by email. The message indicates it’s from the IRS asking for financial information. The IRS reminds taxpayers that it never discusses tax account information by email.

7. Wireless Security Breaches. Which business person or college student hasn’t fired up their laptop and gone online at a coffee shop? Yes, they are great places to hang out, but everything you transmit is viewable on an unsecured network.

8. Fake Online Classified Ads or Auction Sales. Think Craigslist. It’s a great site, but also a place where crooks can post fake ads to scam you out of your money. The BBB advises that if you buy from a online classified ad or auction site that you consider only making payment through third party transaction companies such as PayPal.

9. Gift Card Scams. The BBB says there are actually online sites where people can buy gift cards at reduced prices. Later they discover that the cards carry little to no value.

10. Smishing Scams. This works like Phishing on your computer, except Smishing takes place on your cell phone. It happens when a text message is sent to your phone indicating your bank or credit card accounts have been frozen and you need to call a certain number to rectify the accounts. The scammer is looking to collect your banking information. This actually happened in December of 2008 to many customers of a major Twin Cities bank.

The best advice from the Better Business Bureau is to be aware.

“We hear so many times people saying, ‘Well it sounded like such a good deal, or such a good offer, I had to do it,’” said Hendrickson. “And, you know we understand that. But the reality is if it sounds too good to be true, it probably is.”

Monday, November 30, 2009

Stay safe from scams at the holidays

This information can be found at
http://www.ic3.gov/media/2009/091130.aspx

This holiday season the Federal Bureau of Investigation ( FBI) is reminding people that cyber criminals continue to aggressively create new ways to steal money and personal information. Scammers use many techniques to fool potential victims including fraudulent auction sales, reshipping merchandise purchased with a stolen credit card, and sale of fraudulent or stolen gift cards through auction sites at a discounted price.

Fraudulent Classified Ads or Auction Sales
Internet criminals post classified ads or auctions for products they do not have. If you receive an auction product from a merchant or retail store, rather than directly from the auction seller, the item may have been purchased with someone else's stolen credit card number. Contact the merchant to verify the account used to pay for the item actually belongs to you.

Shoppers should be cautious and not provide financial information directly to the seller, as fraudulent sellers will use this information to purchase items for their scheme from the provided financial account. Always use a legitimate payment service to protect purchases.

As for product delivery, unfamiliar Web sites or individuals selling reduced or free shipping to customers through auction sites many times are deemed to be fraudulent. In many instances, these Web sites or sellers provide shipping labels to their customers as a service. However, the delivery service providers are ultimately not being paid to deliver the package; therefore, packages shipped by the victims using these labels are intercepted by delivery service providers because they are identified as fraudulent.

Diligently check each seller's rating and feedback along with their number of sales and the dates on which feedback was posted. Be wary of a seller with 100% positive feedback, if they have a low total number of feedback postings and all feedback was posted around the same date and time.

Gift Card Scam
Be careful about purchasing gift cards from auction sites or through classified ads. If you need a gift card, it is safest to purchase it directly from the merchant or another authorized retail store. If the gift card merchant discovers the card you received from another source or auction was initially obtained fraudulently, the merchant will deactivate the gift card number and it will not be honored for purchases.

Phishing and Smishing Schemes
Be leery of e-mails or text messages you receive indicating a problem or question regarding your financial accounts. In this scam, you are directed to follow a link or call the number provided in the message to update your account or correct the problem. The link actually directs the individuals to a fraudulent Web site or message that appears legitimate where any personal information you provide, such as account number and PIN, will be stolen.

Another scam involves victims receiving an e-mail message directing the recipient to a spoofed Web site. A spoofed Web site is a fake site or copy of a real Web site and misleads the recipient into providing personal information, which is routed to the scammer's computers.

Tips
Here are some tips you can use to avoid becoming a victim of cyber fraud:

Do not respond to unsolicited (spam) e-mail.

Do not click on links contained within an unsolicited e-mail.

Be cautious of e-mail claiming to contain pictures in attached files, as the files may contain viruses. Only open attachments from known senders. Virus scan the attachments if possible.

Avoid filling out forms contained in e-mail messages that ask for personal information.

Always compare the link in the e-mail to the link you are actually directed to and determine if they actually match and will lead you to a legitimate site.

Log on directly to the official Web site for the business identified in the e-mail, instead of "linking" to it from an unsolicited e-mail. If the e-mail appears to be from your bank, credit card issuer, or other company you deal with frequently, your statements or official correspondence from the business will provide the proper contact information.

Contact the actual business that supposedly sent the e-mail to verify if the e-mail is genuine.

To receive the latest information about cyber scams, please go to the FBI Web site and sign up for e-mail alerts by clicking on one of the red envelopes. If you have received a scam e-mail, please notify the IC3 by filing a complaint at www.IC3.gov.

For more information on e-scams, please visit the FBI's New E-Scams and Warnings webpage at http://www.fbi.gov/cyberinvest/escams.htm.

Thursday, October 15, 2009

Phishing Scam Email

Here is a Phishing Scam email that got into my inbox. This is a classic example of how a scammer will try to get your account information, by saying that it is an urgent matter and providing a link for you.

----------------------------------------------

Dear Member,
Your Yahoo Marketing account has expired. You must renew it immediately or your account will be closed. If you intend to use this service in the future, you must take action at once!

To continue click here, login to your Yahoo Marketing account and follow the steps.Thank you for using Yahoo Marketing!
Yahoo Marketing Services DEP.

Please do not reply to this email.
This mailbox is not monitored and you will not receive a respons.

--------------------------------------

Not only are their spelling errors, but if you were to hover over the link they provided (which I removed) you would find that it does not go to yahoo, but to a site that they created which has yahoo in it

marketingservicesweb.yahoo.duebymatteo

Wednesday, October 14, 2009

Seven years

Seven years ago this month my husband and I became victims of a counterfeit cashier's check scam while selling his 1961 Buick Special online. So much has happened in those seven years.

We found that we were not alone, and that this was happening to others.
We started our website Scam Victims United to share our story with others.
We spoke out in the news about this issue.
We have worked with Consumer Protection Agencies to help spread the word about scams.
In the first two years of our site being operational, we helped to stop over 2 million dollars from going into the hands of scammers.

We have come a long way, but we still have so far to go. The Consumer Federation of America released the results of a survey in May 2009 which relates directly to information we at Scam Victims United work to educate people about. They found that fifty-nine percent of the respondents incorrectly believe that when you deposit a check or money order, your bank confirms that it is good before allowing you to withdraw the money. The number goes up to 70 percent among young adults age 18-24, and 71 percent of people with incomes under $25,000 and who did not complete high school. More than 40 percent of those surveyed do not know that they are liable if the checks or money orders they deposit or cash are counterfeit. Fifty-two percent age 18-24 and half of Hispanics incorrectly said the person who gave you the check must pay the bank back. This is precisely the type of information that we at Scam Victims United work to educate people about.

As you can see by the results of this survey, there is a great need for education in the area of banking terminology and the check clearing process. One of the major reasons that counterfeit cashier's checkscams work so well is that when a bank customer hears the terms "the check is clear" or that it will be "verified in 24 hours" it gives them a false sense of security that the check is legitimate and that they can use the money with no repercussions.

And that is our mission.

Shawn Mosch
Co-Founder of ScamVictimsUnited.com
There is strength in numbers!

Find us on Twitter, Facebook and more through
http://www.retaggr.com/page/ShawnMosch

Tuesday, October 13, 2009

Secret Shopper email

Since the Secret Shopper and Mystery Shopper scams seems to be increasing, I wanted to post an example of the email that the scammer would send to their would be victim.

Dear Representative,
You have been selected for an assignment as a Mystery Shopper. You willearn $300 been a mystery shopper. Your employment packet will includefunds for the shopping, a training assignment which will be sent to youon the same day you receive payment for the assignment. A Pay check would be sent toyou for the assignment in the form of a Check or money order. The paycheck would be for a certain amount which you would be required to cash atyour bank, deduct your salary and have the rest used for the evaluation atthe store that would be given to you to evaluate.Get back with the following details if interested

Email me the below details:
Full Name:
Full Address (Not P.o.box):
City:
State:
Zip Code:
Phone Number:
Nationality:A
lternative Email Address:

As a mystery shopper you work and shop together for pleasure and the payis $300 weekly on Part time basis, You only work 2-3hours twice in aweek. Do get back to the recruiting department of Mystery Shopper Inc.

You may contact me at msparecruits01@sify.com
Regards,
Chad Stinson
Personnel Manager

Monday, October 12, 2009

Cyber Threats

re-posted from http://www.fbi.gov/pressrel/speeches/mueller100709.htm
Thank you and good afternoon. I am happy to be back in San Francisco, and back at the Commonwealth Club.
Today, I want to talk about cyber threats. So it seems fitting that my remarks are being broadcast on the Club’s national radio program, airing on XM Radio and iTunes, and streaming live to Club members. This is going on all around us, but if Skip hadn’t mentioned it, we would be none the wiser. Our lives are impacted by the Internet all the time, whether we can see it or not.
The Internet has thrown wide the windows of the world, allowing us to learn and communicate and conduct business in ways that were unimaginable 20 years ago. This is the upside of globalization, as author Tom Friedman has noted in best-sellers such as “The World is Flat.” But the downside of our increasingly flat world is that the Internet is not just a conduit for commerce, but also a conduit for crime.
The Internet has created virtual doors into our lives, our finances, our businesses, and our national security. Criminals, spies, and terrorists are testing our doorknobs every day, looking for a way in.
Cyber crime is a nebulous concept. It is difficult to grasp intangible threats, and easy to dismiss them as unlikely to happen to you. So far, too little attention has been paid to cyber threats—and their consequences.
But what if I told you that as you sit here today, strangers were walking through your offices, homes, and dorm rooms? What if they were opening your drawers, reading your files, accessing your financial information, or stealing your company’s research and development?
Well, that is happening, right now, in homes and offices and schools around the world. Intruders are reaching into our networks every day, looking for valuable information. And unfortunately, they are finding it, because many of us are unaware of the threat these persons pose to our privacy, our economic stability, and even our national security.
Most of us assume we will not be targets of cyber crime. We are not as careful as we know we should be. Let me give you an example.
Not long ago, the head one of our nation’s domestic agencies received an e-mail purporting to be from his bank. It looked perfectly legitimate, and asked him to verify some information. He started to follow the instructions, but then realized this might not be such a good idea.
It turned out that he was just a few clicks away from falling into a classic Internet “phishing” scam—“phishing” with a “P-H.” This is someone who spends a good deal of his professional life warning others about the perils of cyber crime. Yet he barely caught himself in time.
He definitely should have known better. I can say this with certainty, because it was me.
After changing all our passwords, I tried to pass the incident off to my wife as a “teachable moment.” To which she replied: “It is not my teachable moment. However, it is our money. No more Internet banking for you!”
So with that as a backdrop, today I want to talk about the nature of cyber threats, the FBI’s role in combating them, and finally, how we can help each other to keep them at bay.
* * *
Let me start by giving you two examples of what the FBI investigates on a daily basis.
In July 2008, a California oil and gas company called Pacific Energy Resources contacted the FBI and the Long Beach Police to report a computer attack. Six computer servers had been rendered inoperable, disabling the critical leak-detection systems on three off-shore oil platforms. This was the last in a series of network attacks, which cost the company over $100,000 in losses.
The investigation led us to a former IT contractor. After he had been let go, he retaliated by remotely accessing the system. His actions could potentially have resulted in significant environmental damage. He pled guilty last month to a federal computer intrusion charge, and faces up to 10 years in prison.
And this past April, someone hacked into the database of the Virginia Department of Health Professionals. The intruder blocked over 8 million patient records—records that hospitals, doctors, and pharmacies depend on in order to accurately prescribe and dispense medication. Those records are no longer blocked, and our investigation continues.
As you can see, cyber cases can have costly—and potentially deadly—consequences.
Again, most of us assume our systems have nothing that would interest a hacker or spy. But we never know exactly what information might have value to a criminal. Information is power, period.
Whenever an intruder opens a door to our networks, there is a clear risk to individual privacy and intellectual property—not to mention economic and national security.
My eyes were first opened to these risks back in the early 1990s, when I read a book called “The Cuckoo’s Egg.” It chronicles the electronic adventure of Cliff Stoll, then a systems manager at a Berkeley laboratory. In the mid-1980s, he noticed an accounting disparity of 75 cents. This was before the Internet as we know it existed. Cyber threats were just beginning to appear on our radars.
He tracked it to an unauthorized user who had repeatedly broken into the system and then used the lab’s computers to tap into military networks. He eventually traced the attacks to a German hacker who was part of an espionage ring.
The book was prescient. Twenty years later, the whole world is online. And because the web offers near-total anonymity, it is that much more difficult to discern the identity, motives, and location of an intruder.
At the start of a cyber investigation, we do not know whether we are dealing with a spy, a company insider, or an organized criminal group. Something that looks like an ordinary phishing scam may be an attempt by a terrorist group to raise funding for an operation. An intrusion into a corporate network could be the work of a high-school hacker across the street, or a hostile foreign power across the ocean.
Cyber threats present a unique challenge to law enforcement because we have a tendency to compartmentalize our investigations. Criminal cases are usually separate from espionage cases, which in turn are separate from counterterrorism cases. But when it comes to cyber threats, there is almost always some overlap.
The FBI is both a law enforcement and national security agency, which means we can and must address every angle of a cyber case. This is critical, because what may start as a criminal investigation may lead to a national security threat.
Take, for example, a next-generation bank robbery that occurred last fall. A group of cyber criminals orchestrated a highly sophisticated attack on a major financial institution. Hackers found their way into the network of this institution, and altered data to allow them to increase the funds available for a number of accounts. They also stole account data and created duplicate ATM cards. Then, one day in early fall, they struck.
Within 24 hours, the thieves targeted more than 2,100 ATMs in 280 cities around the world. They inserted their phony ATM cards, and then walked away with more than $9 million. Arrests have been made internationally, and our investigation continues.
To put it in perspective, imagine for a moment that these groups had simultaneously entered dozens of banks, armed with assault weapons, and emptied the vaults. It would have been one of the most notorious bank heists in history. But instead, the attack was planned and executed under the radar, using computers and fiber-optic cables as weapons. They did it without a shot being fired, and then disappeared back into the ether.
Such techniques make global deterrence a challenge, to put it mildly. The perpetrators can be anyplace in the world. And so can the victims. And, for that matter, the evidence.
At a minimum, piecing together a case requires close collaboration with our counterparts in other countries. But actually prosecuting one requires harmonizing different criminal justice systems, all of which work according to the laws of their own lands.
The global scale and scope of such attacks puts law enforcement at a disadvantage. The investigative challenges may seem insurmountable.
But we do have a significant advantage: partnerships. Partnerships with law enforcement and intelligence communities across the world. Partnerships with universities, corporations, and small businesses. Partnerships with citizens such as yourselves.
* * *
After the September 11th terrorist attacks, the FBI’s mindset and mission changed fundamentally. We could no longer focus our efforts on investigating terrorist attacks after the fact; we had to prevent them from happening in the first place. The only way to do that is to gather and analyze intelligence, and share it with those who need it.
The same mindset is true for our cyber responsibilities. The FBI can bridge both criminal and national security cases. So we are uniquely positioned to facilitate joint investigations that cross both local and international jurisdictions.
Within the government, the FBI has established the National Cyber Investigative Joint Task Force. This task force brings together law enforcement, intelligence, and defense agencies to focus on high-priority cyber threats.
But cyber threats take us well beyond partnerships with government alone. The FBI runs a program called InfraGard, which is one of our most important links to the private sector. We exchange information with partners from a host of industries, from computer software companies to chemical corporations. They are the experts on our critical infrastructure, the majority of which rely on computer networks. We have 32,000 members and counting, and those relationships have helped us to prevent risk from becoming reality.
And our partnerships stretch beyond our borders. For example, a substantial amount of cyber crime originates in Eastern Europe. And so we have embedded FBI agents in several police agencies there, to assist full-time on cyber investigations. Our relationship with the Romanian National Police is an example of the results of such cooperation: In the past year alone, we have dismantled organized criminal groups and arrested over 100 individuals, both here and in Romania.
And just this morning, we announced a major takedown in an international cyber investigation. A group of criminals in the United States and Egypt was engaged in a wide-ranging “phishing” scam. They targeted American financial institutions, and also approximately 5,000 American citizens. The FBI, the Secret Service, and state and local law enforcement cooperated closely with our Egyptian counterparts. As a result, earlier today we arrested over 50 subjects in the United States and Egypt.
This is the first joint cyber effort between the United States and Egypt. It is the largest international “phishing” case ever conducted. And it shows the power of our global partnerships in the face of global cyber criminal networks.
Those are just a small sampling of our many partnerships. Yet we are still outnumbered by cyber criminals. And that is where you come in.
Just as the police cannot come by every home or business, every night, to make sure the doors are locked, we must all take ownership of cyber security.
Cyber crime might not seem real until it hits you. But every personal, academic, corporate, and government network plays a role in national security. And given the extent of the damage cyber attacks can cause, it is important for all of us to protect ourselves, and each other.
If you are a basic user, then make sure to enable basic protections for your network—firewalls, anti-virus software, strong passwords, and security patches. And if you are part of a large corporate or academic network, start thinking of cyber security as a mission-critical component, and not an afterthought.
Investing in cyber security is akin to buying hazard insurance for a house. You invest relatively little to guard against losing everything.
Finally, talk to us. The more information we have, the more effective we can be at preventing you from becoming a victim of cyber crime. Whenever companies or institutions inform us of a potential breach, we have the chance to gather, analyze, and share critical intelligence. You never know when a single scrap of information may lead to the takedown of a global ring of cyber criminals, or even a terrorist cell. Remember the example of Cliff Stoll: a 75-cent billing disparity was no mere accounting error. It was the key to uncovering an international espionage ring.
* * *
For better or worse—and I generally think for better—cyberspace is here to stay. We live in a wireless world, and we have grown accustomed to its convenience.
We are all used navigating with GPS, checking our e-mail at the airport, trading stocks online, and—for most of us, anyway—paying bills online. “Tweeting” or updating your Facebook status from anywhere is no longer a luxury but an expectation.
There is no going back. Technology will continue its march forward, and criminals will take full advantage of it. We in the FBI liken our challenge to a “cyber arms race,” where both sides are competing to stay ahead of the other.
We have to bring the fight to them. We have to work together, as a united front—government, private industry, and the public.
We know the game plan of our adversaries. They will keep twisting doorknobs and picking locks until they find a way in. But we must not let them in. We must change the locks. We must bar the doors. And we must sound the alarms when we notice anything out of the ordinary.
We are all citizens of the Internet, and we must also be its stewards. We all have a responsibility to protect the infrastructure that protects the world. It will not be easy. But together, we are up to the task.
I will leave you with just one more warning. Many of you may be familiar with the Nigerian e-mail scam, which offers the recipient the “opportunity” to make millions—if they could just help the author with a few illegal money transfers.
If you ever receive a similar e-mail purporting to be from me—as has happened in the past—delete it! Especially if it asks you for money. Take it from me—having to memorize all those new passwords is no picnic.

Brought to you by
Shawn Mosch
Co-Founder of ScamVictimsUnited.com
There is strength in numbers!

Find us on Twitter, Facebook and more through
http://www.retaggr.com/page/ShawnMosch

Tuesday, October 6, 2009

Scammers and Social Networking Sites

This information is re-posted from the FBI Press Release Page

Fraudsters continue to hijack accounts on social networking sites and spread malicious software by using various techniques. One technique involves the use of spam to promote phishing sites, claiming there has been a violation of the terms of agreement or some other type of issue which needs to be resolved. Other spam entices users to download an application or view a video. Some spam appears to be sent from users' "friends", giving the perception of being legitimate. Once the user responds to the phishing site, downloads the application, or clicks on the video link, their computer, telephone or other digital device becomes infected.

Another technique used by fraudsters involves applications advertised on social networking sites, which appear legitimate; however, some of these applications install malicious code or rogue anti-virus software. Other malicious software gives the fraudsters access to your profile and personal information. These programs will automatically send messages to your "friends" list, instructing them to download the new application too.

Infected users are often unknowingly spreading additional malware by having infected websites posted on their webpage without their knowledge. Friends are then more apt to click on these sites since they appear to be endorsed by their contacts.

Tips on avoiding these tactics:

Adjust website privacy settings. Some networking sites have provided useful options to assist in adjusting these settings to help protect your identity.

Be selective of your friends. Once selected, your "friends" can access any information marked as "viewable by all friends."

You can select those who have "limited" access to your profile. This is for those whom you do not wish to give full friend status to or with whom you feel uncomfortable sharing personal information.

Disable options and then open them one by one such as texting and photo sharing capabilities. Users should consider how they want to use the social networking site.
If it is only to keep in touch with people then perhaps it would be better to turn off the extra options which will not be used.

Be careful what you click on. Just because someone posts a link or video to their "wall" does not mean it is safe.

Those interested in becoming a user of a social networking site and/or current users are recommended to familiarize themselves with the site's policies and procedures before encountering such a problem.

Each social networking site may have different procedures on how to handle a hijacked or infected account; therefore, you may want to reference their help or FAQ page for instructions.

Individuals who experienced such incidents are encouraged to file a complaint at www.IC3.gov reporting the incident.

---------------------
Shawn Mosch
Co-Founder of ScamVictimsUnited.com

Find us on Twitter, Facebook and more through
http://www.retaggr.com/page/ShawnMosch

Saturday, October 3, 2009

Google it!

I think that Google is a wonderful scam fighting tool. On a daily basis we will have people come to our site and post on our message board that they did NOT become a scam victim because they ran a Google search on something from the scammer's email . . . their name, email address, company, phone number . . . and that search brought them right to a post on our message board. Once they see this information on our message board they know for sure that it is a scam.

If you ask me, it is better to be over cautious . . . Google everything! You never know what information you might find out. It is better to be safe than sorry.

Shawn Mosch
Co-Founder of ScamVictimsUnited.com
There is strength in numbers!

Find us on Twitter, Facebook and more through
http://www.retaggr.com/page/ShawnMosch

Thursday, October 1, 2009

October is Cyber Security Awareness Month

You can find out more about Cyber Security Awareness Month at http://staysafeonline.org/NCSAM



And there is a listing of events going on across the country.

Social Networking Friend Scam

This is from a Press Release from the FBI today

No, Your Social Networking “Friend” Isn’t Really in Trouble Overseas

According to the Internet Crime Complaint Center (IC3), there has been an increase in the number of hijacked social networking accounts reported to www.ic3.gov.

One of the more popular scams involves online criminals planting malicious software and code onto to victim computers. It starts by someone opening a spam e-mail, sometimes from another hijacked friend’s account.

When opened, the spam allows the cyber intruders to steal passwords for any account on the computer, including social networking sites. The thieves then change the user’s passwords and eventually send out distress messages claiming they are in some sort of legal or medical peril and requesting money from their social networking contacts.

So far, nearly 3,200 cases of account hijackings have been reported to the IC3 since 2006.

Cyber thieves are also using spam to promote phishing sites, claiming a violation of the terms of service agreement or creating some other issue which needs to be resolved. Other spam entices users to download an application or view a video. Some of these messages appear to be sent from friends, giving the perception of legitimacy. Once the user responds to a phishing site, downloads an application, or clicks on a video link, the electronic device they’re using becomes infected.

Some applications advertised on social networking sites appear legitimate but install malicious code or rogue anti-virus software. These empty applications can give cyber criminals access to your profile and personal information. These programs will automatically send messages to your contacts, instructing them to download the new application too.

Infected users are often unknowingly spreading malware by having links to infected websites posted on their webpage without the user’s knowledge. Since the e-mail or video link appear to be endorsed by a friend, social networking contacts are more likely to click on these links.

Although social networking sites are generally a safe place to interact with friends and acquaintances, keep in mind these suggestions to protect yourself while navigating the Internet:

Adjust website privacy settings. Some networking sites have provided useful options to assist in adjusting settings to help protect your identity.
Be selective when adding friends. Once added, contacts can access any information marked as viewable by all friends.
Limit access to your profile to only those contacts you trust with your personal information.
Disable options, such as photo sharing, that you might not regularly use. You can always enable these options later.
Be careful what you click on. Just because someone posts a link or video to their wall does not mean it is safe.
Familiarize yourself with the security and privacy settings and learn how to report a compromised account.
Each social networking site may have different procedures on how to handle a hijacked or infected account; therefore, you may want to reference their help or FAQ page for instructions.
If your account has been hijacked or infected, report it to by visiting www.ic3.gov or www.lookstoogoodtobetrue.com.

The Internet Crime Complaint Center is a partnership between the FBI and National White Collar Crime Center (NW3C).