Wednesday, July 16, 2008
New technology to monitor cyber crime - Times of India - 15 Jul 2008
Titled 'Cyber Cafe Monitoring System (CCMS)', the technology comprises of a biometric system for recording fingerprints of persons who use a workstation. This potent system has some other features like facility to take live snapshots, public IP address and MAC address (used to keep record of computer systems used in a crime).
According to the firm's director Anuj Kacker, who displayed the technology in front of cyber cafe owners, it will have a US-made thumb scanner device for recording fingerprints of a user. The software will also record photographs along with the name and others details of the user.
However, in a survey of some cyber cafes in the city it came to light that small owners were apprehensive of the technology. Talking to TOI, Rajendra, a cyber cafe owner in Aliganj, said, "if we use this technology we will be under constant watch of the cops as the main server of the system will be connected to that of the cops."
A Hazratganj cyber cafe owner was bold enough to admit that since most of the people who visit his cafe surf pornographic websites, adopting the technology will hit his business and "intrude into the privacy of the user".
Allaying fears, Anuj told TOI that the technology will not record the content of the website or an email. "It will only record the public IP address. The police will only intervene if it comes to light that a crime has been committed on a particular IP," he added.
Anuj added that since cyber cafe owners were not aware about the technology and its use, the firm was planning to conduct regular such presentations. According to Anuj, the software is designed in such a manner that the data base will be recorded for a period of two months. In case a cyber crime is committed using a particular computer system, and it comes to the knowledge of cops, a tracker will be put on the user's name and if on any later date the culprit again uses any other computer system attached to the CCMS main server with the police, his identity will be revealed.
Talking to TOI, senior superintendent of police (SSP) Akhil Kumar said, "it is solely at the discretion of the cyber cafe owners to use this technology or use close-circuit television cameras for maintaining a record. The technology is in no way being endorsed by the district police but it is a good system that will help in controlling cyber crime in a big way." The SSP also assured that if a cyber cafe owner adopts CCMS, police will only intervene in case of complaint lodged for a crime.
The news system will alert police officials of a particular area where a cafe is situated within seconds of any violation and display a status column which will define whether a particular computer system is being used or not by the culprit.
The technology will cost Rs 6,800 along with an additional charge of Rs 200 for the services. According to the technology providers, the cost is less when compared to installing close circuit television cameras (CCTVs) which cost around Rs 14,000 per unit.
So far six cyber cafes out of a total of 3,000 in the city have installed the system and according to Anuj, another 35 proposals are in the pipeline
Saturday, July 12, 2008
Airlines act against e-ticket fraud - The Telegraph – 10 Jul 2008
The next time you buy an air ticket online for someone you know, don’t forget to give that person an attested photocopy of your credit card because airlines are becoming stricter in implementing a fraud-prevention rule that has been in existence for some time.
Amitabha Banerjee (name changed on request) was unaware of this when he checked in for an afternoon flight to Mumbai last week. The executive at the check-in counter of the private airline sought a photocopy of the credit card that was used to buy the e-ticket, leaving him puzzled.
Banerjee said he had bought the ticket from a travel agent and didn’t know whether a credit card had been used in the transaction. “On being told that airlines are being extra cautious in regard to tickets bought with credit cards, I called up my travel agent from the airport to ask for a faxed photocopy of his card,” he recalled.
He was lucky to get it in half an hour, just in time to board the flight.
The high incidence of identity theft — all you need for an online purchase is the credit card number, the expiry date and the three-digit CVV number printed at the back — is the reason why airlines are insisting on fliers carrying photocopies of credit cards if their tickets have been booked by someone else.
“There have been several such frauds over the last six months,” a Jet Airways official said.
He said almost all airlines had this clause in their e-ticket rules, though very few were implementing it until recently. “Henceforth, if any passenger fails to show the photocopy of the credit card attested by its owner, the ticket will be cancelled and a fresh ticket issued. The owner of the card will get the refund,” the Jet official said.
The system is, however, far from foolproof. A card that is stolen can be used to buy tickets, photocopied and presented as proof of the purchase being bona fide. “If a person commits this kind of fraud, there is nothing one can do,” said an official at airport police station.
There have even been instances of hackers cracking online payment gateways with fake credit card numbers and purchasing tickets. In such cases, airlines incur losses.
Last month, the e-commerce department of Jet Airways asked its airport division to look out for a passenger booked on a Calcutta-Mumbai flight because of doubts about his online purchase. "We were asked to check the photocopy of the credit card and if the passenger failed to produce it, the ticket should be cancelled. The passenger did not turn up. It seems he had a hunch he would be caught," an official said.
Most frauds are committed by small-time tour operators. "Tickets are issued usually 24 hours before departure, giving us little time to detect the fraud," a Deccan official said.
"We advise passengers to buy tickets from authorised travel agents. They should not fall for unusually low fares offered by tour operators whose credentials are not known," said Anil Punjabi, chairman (east) of the Travel Agents’ Federation of India.
According to sources in the aviation industry, 5-7 per cent of airline tickets are bought online. Around 20 per cent are purchased with credit cards from travel agents.
By Sanjay Mandal
Man jailed for hacking Red Cross website to steal donations - www.chinaview.cn 11 Jul 2008
Yang Litao, a staff member of a network technology company in south China's Shenzhen City, was accused of hacking into the Kunshan Municipal Red Cross Foundation website in May and changingthe donation bank account number to his own in order to syphon off money, a Kunshan Municipal People's court ruling said. He had opened a bank account using a false name for the purpose.
The police shut down the website, one of several he had hacked into, on May 18 after discovering it had been hacked. Yang did not make any money, thanks to the quick response from the police.
Yang was caught three days later in a rented house in Shenzhen.
Unique technology to control cyber crime - Times of India - 11 Jul 2008
The technology introduced is titled 'Cyber Cafe Monitoring System (CCMS)' that will comprise techniques like biometric system, for taking image of fingerprints of persons using a computer system, along with having other features such as taking photographs, public IP address and MAC address (it is used for keeping a record of which computer system was used to commit the crime).
According to the firm's director Anuj Kacker, who presented the new technology to the cyber cafe owners, the technology would be having a scanner device for recording the fingerprints of the user.
The software installed would record photographs along with the names and other details of the user.
According to the police, the technology is designed in such a manner that the database will be recorded for a period of two months and if a criminal has used a particular computer system and after a few days again uses any computer system attached to the main server of the technology, his identity will be revealed and an SMS will reach the police officials of the concerned police station in a couple of seconds.
The software will also display a status column which will define whether a particular computer system is being used or not.
The technology will cost Rs 6,800 and an additional charge of Rs 200 for providing the services. According to the technology providers, the cost is less when compared to installing close circuit television cameras (CCTV), a set of which costs around Rs 14,000.
So far, six cyber cafes out of the total 3,000 in the city have installed the system and the firm and the police are optimistic about its use in future as well.
DBS Bank works with Unisys and Actimize to fight crime – bankingtech.com
Research from Celent has indicated that Singapore and Australia are the countries most aware of AML requirements in Asia Pacific and predicts that growth in AML technology spend in the region will outstrip the US and Europe in 2008.
Unisys will deploy Actimize's fraud prevention and anti-money laundering solutions across DBS Bank's Asia Pacific operations. The enterprise-wide risk management platform and surveillance system is designed to enhance DBS Bank's capability to detect potential fraud, misconduct, money laundering and terrorism financing activities. The solution uses analytics to identify, manage and reduce potential risks by
DBS Bank works with Unisys and Actimize to fight crime – bankingtech.com
Research from Celent has indicated that Singapore and Australia are the countries most aware of AML requirements in Asia Pacific and predicts that growth in AML technology spend in the region will outstrip the US and Europe in 2008.
Unisys will deploy Actimize's fraud prevention and anti-money laundering solutions across DBS Bank's Asia Pacific operations. The enterprise-wide risk management platform and surveillance system is designed to enhance DBS Bank's capability to detect potential fraud, misconduct, money laundering and terrorism financing activities. The solution uses analytics to identify, manage and reduce potential risks by
Wednesday, July 9, 2008
Helping prevent online fraud - - southbendtribune.com – 06 Jul 2008
Luckily, in some cases consumers can prevent scams with the right defensive measures.
Some strategies should be obvious. For example, don't use "password" as a password, shred old bills, and don't keep pin numbers written down in a wallet or purse.
But as crooks get smarter, common sense may not be enough to stave off scams.
While 1st Source Bank officials said an online data breach was most likely to blame for scams related to their ATMs, Ray Miller, owner of Michiana Mobile Computer Repair, speculates that skimmers may have been part of the problem.
Skimmers are devices that can read a card's magnetic strip when placed over an ATM card slot.
"Skimmers will have a little pinhole camera mounted in them so they can see the key presses and store the pin numbers there," Miller said.
Miller, who deals with security issues daily in his business, also warns against card catchers. These devices are thin strips of metal or plastic a thief places inside the card slot, allowing cards to be inserted but not ejected. Victims believe their cards have been "eaten" by the ATM, and when they leave to report the problem to their local branch, the thief can remove both the strip and the card.
1st Source Bank's online breach is not the norm in causes of identity theft, according to a study by the Better Business Bureau in 2005.
The study found that the theft of online information accounted for only 11.6 percent of identity fraud cases. In addition, the study found that half of all identity thefts were committed by someone the victim already knew.
To prevent against offline fraud, the identity theft protection company LifeLock recommends dropping off outgoing mail in official post office boxes rather than leaving it in a home mailbox.
"A lot of criminals will steal people's mail for credit card numbers or account numbers and steal that information," Miller said. "People stealing trash is not as frequent but it still happens, so people should use shredders."
Though paper is the biggest target of identity theft, public computers and wireless Internet connections present dangers that users often don't think about, Miller said.
"What most people aren't aware of is that when they use Wi-Fi hot spots, anyone who's on the same hot spot can use any shared folders or files they have on their computer," Miller said.
He also warns against packet monitoring software, which hackers can use to intercept and log traffic passing through the network.
"For any traffic they're sending back and forth in a Wi-Fi hot spot, anyone who's on the same network can view what they're sending," Miller said.
Keylogging software may also be a danger on public computers, Miller said. Someone could install such software on a public computer, store the keystrokes users type with a USB device, and collect the user names and passwords logged weeks later.
Some recent legislation aims to protect consumers against fraud. Because of the Fair and Accurate Credit and Transactions Act of 2003, consumers can receive a free annual credit report from one of the three major bureaus, Equifax, TransUnion, or Experian. Consumers who suspect fraud on their accounts can receive credit reports for free as well.
While prevention may be the best weapon against identity theft, people can minimize damages by checking on their accounts daily via the Internet, Miller said.
"ATM debit cards are really easy to keep track of," he said. "For myself, every day I'm downloading and updating transactions and comparing them to things my wife and I have done."
By SUPRIYA SINHABABU
Sunday, July 6, 2008
MPA to train cops to counter cyber crime - NDTV.com- 02 Jul 2008
The Nasik-based MPA, which trains police officers and police sub inspectors, has set up two computer labs to train cops simultaneously in tackling cyber crimes.
MPA's deputy director Ritesh Kumar said that the police officers and staff from all over the state would be provided proper training as white-colored-crimes are on rise.
''Solving on line frauds such as phishing, purchasing on one's credit card illegally, hacking transactions through credit cards and threatening messages using e-mail were a challenge before police'', Ritesh Kumar added.
''Considering these facts, MPA has come up with modern computer labs and also included syllabus of computer-integrated police application in its training programme,'' Kumar said.
''The labs have 56 computers connected through a wireless system. So far 630 police officers and employees have been trained while officers from other departments would also be trained after the completion of third laboratory,'' he added.
Fraud Worries Spur New Security Efforts - investors.com - 01 July 2008

High-profile banking scandals, rising worries over fraud and a sluggish economy are spurring closer monitoring of financial transactions — and a flurry of new security products.
More than 80% of Americans in a recent Unisys poll are concerned about identity theft, more than a third extremely so.
In another survey commissioned by risk management software vendor Actimize — a unit of Nice Systems (NICE) — 85% of investment firms said they plan to change their internal risk-management controls in the wake of trading scandals at big banks.
Security firms aim to counter the threat with a slew products and services to fight fraud.
Economic pressures make fraud an especially timely worry, says Amir Orad, executive vice president at the New York company.
"People (including regulators) think that the issues in the marketplace right now are going to create opportunities for traders and other employees to do things they would not do otherwise," he said. "People are making much less money. They have a certain lifestyle they want to maintain. Sometimes they step outside their boundaries."
In a risk outlook for this year, the U.K.'s Financial Services Authority warned that increasing financial pressures on firms, employees and consumers could entice some to commit financial crime, including market abuse and fraud.
Citing greater regulatory pressure after the multibillion-dollar trading fraud uncovered at French bank Societe Generale, Actimize in May launched a system to watch for signs of employee misconduct .
The software resides on computers in a company's back office, monitoring various data sources in real time to look for unusual activity.
Orad says the product checks multiple systems, such as trading or reconciliation systems, in conjunction. So it has a better chance of detecting employees who try to cover their tracks by manipulating transactions across the different systems.
Orad says eight of the 10 largest U.S. investment banking firms use Actimize for trade surveillance, and dozens of institutions have expressed interest in the new product. Actimize's software usually costs institutions a sum in the high six figures to low seven figures.
Meanwhile, an anti-fraud program geared toward a wider corporate audience came out in May from security giant Symantec. (SYMC) Ten to 20 businesses are using Symantec Online Fraud Protection so far, with the strongest uptake among banks and other financial firms.
It's meant to guard against fraud at firms that perform large volumes of financial transactions. Symantec put together a suite of consulting and technical monitoring services for the program and can assign an expert-in-residence to help clients.
Financial firms' worries about phishing drove development of the plan, says Ted Donat, director of product management at Symantec's consulting unit.
Phishing involves tricking people into revealing their account info, often with an e-mail that directs them to log into a convincing-looking fake of their bank's Web site. A similar type of fraud, called pharming, exploits security weaknesses to redirect traffic from legitimate banking sites to fakes.
"When we come to a customer's site, we look at all the different elements of online fraud and come up with a business impact analysis — what is your dollar risk associated with phishing and pharming?" Donat said.
Symantec tailors a program to ensure customers' online authentication services are sufficient and call centers are ready to handle an influx of calls resulting from phishing attacks. The firm also may recommend 24-by-7 online monitoring.
The service includes checking for typo squatting — "setting up 'TedsBank.com' with a z instead of an s," he said — and looking out via hacker newsgroups online for early word of attacks. It blends in some other features too, including data-loss protections for missing laptops and the like, and "shutdown services" meant to speed the job of thwarting fraudulent sites.
"We have cease-and-desist letters in 15 different languages ready to go. We're able very quickly to get these things out to ISPs," Donat said, citing how Symantec's services helped a European bank cope with online fraud threats. "We were able to get these things (such as rogue sites) resolved 10 times faster."
In November, the Federal Trade Commission's "red flag" rules will kick in, requiring financial institutions to have an identity theft prevention program to mitigate identity theft for some kinds of accounts.
The business of data-loss protection specialist Verdasys, which counts more than 100 firms as customers, has been growing about 300% a year, according to Chief Executive Seth Birnbaum. He says clients are concentrated in insurance, finance, manufacturing and tech.
"Almost every company in the world has some demand for data-loss prevention," he said. "They have some information they want to protect better."
BY DONNA HOWELL
Taking ATM Fraud Prevention to the Next Level - banktech.com - Jul 2, 2008
Although ATMs create convenience for customers and generate income or cost savings for banks, they also allow access to criminals, who have multiple methods of fraud in their arsenal—from sophisticated gadgets that allow them to steal personal information from a card when swiped, to setting up and operating their own ATMs. Unfortunately crime is a concurrent element of modern society and it benefits from the same technological advances that are created to open new opportunities.
Even though the percentage of incidents of fraud relative to the total number of daily transactions at ATMs is less than one percent by some estimates, the menace of fraud should not be underestimated. It is necessary to be aware of existing threats, as well as the available technological innovations that safeguard against them.
For instance, withdrawals with cloned cards (or so called "white card" fraud, when stolen data is loaded onto the back of a blank plastic card that looks like a credit card) can be prevented by checking special security codes embedded in the magnetic stripes on the back of every ATM card. Similarly, shoulder surfing (looking over another person's shoulder in an attempt to obtain a password for an ATM or other data), and card skimming (using a hidden card-reading device and a camera to steal a customer's card information) can often be avoided by educating consumers and increasing their awareness and vigilance. Similarly, technology is available to provide powerful means of protection against other types of fraud. In particular, software can be used to combat empty-envelope fraud, which according to industry reports, is the number one type of fraud affecting ATMs.
Image-enabled ATMs using OCR technology can completely eliminate empty-envelope fraud, as well as help stop check kiting and closed-account fraud, as processing times become significantly shorter. Once checks are deposited, they are imaged and OCR technology automatically performs courtesy and legal amount recognition (CAR/LAR) on a deposited item, without having to rely solely on the input from the customer. Images and relative transaction data are sent to the central check processing site, where item processing and a complete audit are executed for clearing purposes. Thus, an image-enabled ATM becomes a remote deposit capture system, allowing for Day 0 or Day 1 processing as part of the financial institution's check processing workflow. As soon as the check is deposited, the image can be processed as a remote deposit item, resulting in faster processing and posting.
However, the idea of image-enabled ATMs is not enough to ensure the success of the project (enterprise). It is crucially important to choose a reliable software solution that can guarantee a read rate and accuracy acceptable for the application. Such products are available, and have been used (and proven in efficiency and reliability) by financial institutions in back office check processing for years. Nowadays, read rates and accuracy have achieved a level that is acceptable for applications that involve direct interface with customers, where a high false alarm rate could cause discontent and reduction in usage.
In addition to amount recognition, technology can execute CAR/LAR mismatch detection by verifying that the legal amount and courtesy amount are the same. This feature helps to detect check alterations and prevent fraud. Other fraud detection solutions are also available and, if integrated in ATMs, can help combat fraud. For example, signature verification can be performed at the time of deposit on "on-us checks," as well as be used to verify signatures on checks between members of an image exchange network if the images of signatures are shared.
These are just a few examples of software capabilities that can provide a reliable safeguard against crime. Better communication with vendors and collaboration in working out the requirements for emerging technologies or products will help to equip the industry with powerful, innovative, and secure solutions that will satisfy customers, generate revenue, minimize fraud and become a competitive differentiator for banks.
By Mike Fenton, Parascript, LLC
Sunday, June 29, 2008
Trouble on the cards for holidaymakers in fraud crackdown - business.scotsman.com – 29 Jun 2008
Evidence is mounting of a record number of transactions being turned down by card machines across continental Europe in a bid to stamp down on fraudulent use abroad.
Problems in obtaining credit while abroad come as UK holidaymakers look set to wi
ADVERTISEMENT
thdraw a record £7bn from overseas cash machines this year and spend up to £5bn more with their cards during on a foreign break.
Credit card companies deny they are taking part in a coordinated campaign where suspect card use is being rejected. They say such decisions are always at the discretion of individual issuers.
A spokesman at the Apacs, the banks' payment system trade body, says: "We know of no collective strategy to clamp down on card usage abroad. All we can surmise is that issuers are looking at people's transactions and making decisions based on what they see happening in each individual case."
However, in one recent example, dozens of Lambretta scooter riders travelling to a rally in Sweden last week found that their cards were being rejected by petrol stations, restaurants and shops there and in Denmark. In many cases, several cards were turned down in succession, leaving their owners to borrow cash off friends in order to continue their journey.
One rider who attended the event said: "It was incredible. I was in a group of about 10 riders and the further we went on the more people were having their cards rejected at service stations. By the end, almost everyone in our little group had several pieces of useless plastic in their wallets. When we got to the main campsite we discovered lots of others with the same experience."
Despite the introduction of Chip and Pin cards, which were meant to make life much more difficult for criminals, total losses from card fraud while abroad grew by more than 85% in 2007 to £207m. At £532m, total fraud is higher than it has ever been.
The most important growth in fraud has come from overseas. The main reason for this is that not all EU countries (or the US) operate a Chip and Pin system. This means it is possible for criminals to skim your card and counterfeit it by making the old-style magnetic stripe on it.
The card can then be used abroad, especially in Italy, Australia and the US, which have no plans to implement Chip and Pin.
A spokesman at Barclaycard denies that his company is targeting holidaymakers. "That's the very last thing we want to do," he says. "What is happening, however, is that our security systems are becoming increasingly sophisticated an identifying patterns of suspicious transactions.
"Clearly, if in one week you have been using your credit card to do the shopping in a certain supermarket and the next you are in Sweden, paying for petrol several times over in one day, that will be totally different spending pattern and our systems will pick up on that."
The spokesman adds that Barclaycard is to start asking its cardholders to inform the company of when they are planning to go away, where and how long for. In addition, cardholders are being asked to supply a contact number where they can be reached in order for its staff to clarify any potentially dubious transactions before they are accepted or rejected.
Having your card rejected is not the only danger for holidaymakers. Even if a card is accepted, research suggests many could be paying through the nose for the privilege.
The financial website MoneyExpert.com says the cost of withdrawing cash abroad can vary dramatically between providers. With an average cash withdrawal abroad of £103, debit card holders will pay on average an additional £4.12 in charges, and credit card holders £4.33.
Sean Gardner of MoneyExpert.com says: "Withdrawing cash from an ATM or over the counter whilst abroad can be the most convenient way of getting hold of your money. It's also safe and simple. However, most people will have to pay for the privilege and some will pay considerably more than others."
The consumer group Which? says people making purchases on their debit or credit card abroad could face fees of more than £20 if they spend £500 on holiday. Most cards add a foreign exchange loading fee of 2.75%, and debit cards usually add a handling fee for each purchase.
Which? says the best options are Nationwide's debit card, while credit cards from Abbey, Nationwide, the Post Office, Saga or Thomas Cook don't add fees for overseas spending.
How to play your cards right when you go abroad
Before you go overseas:
• Only take cards with you that you intend to use.
• Take your card company's 24-hour phone number with you. Tell the issuer you are going abroad.
• Make sure your card company has your latest contact details.
Sunday, June 8, 2008
Equipping officers to probe cyber crimes - The Hindu - 07 Jun 2008
The spectrum of offences that could come under the purview of cyber crimes included obnoxious calls and SMS from cell phones, threats and obscene materials through e-mail, hacking of websites, frauds committed through misuse of ATM cards and credit cards by stealing the Credit Verification Value (CVV) numbers and Personal Identification Numbers (PIN) of credit cards for online purchases and trading.
Today the police with the expertise they had gained in resolving a number of cases were able to investigate and detect even the complicated, clueless crime cases by tracking the mobile numbers of the offenders. But, everything has come by way of experience in investigating cases.
Coimbatore City Police will soon have a cyber crime wing and the necessary orders had already come from the government. The process of setting up the unit with trained officers and manpower is on and the specialised investigation unit would soon start functioning, Kanhu Charan Mahali, City Police Commissioner said. To ensure that the personal had the basic functional knowledge about mobile phones, online transactions, Internet, computers and so on, periodical refresher courses were being conducted for the police personnel and the officers with the help of the Cyber Society of India.
At present, police officers in the rank of Sub-Inspectors and Inspectors belonging to the latest batches, especially those with a graduation, were being used for investigating such cases, since they had adequate knowledge about mobile phones and Internet by virtue of their education background as well as experience in using these latest tools.
But the officers belonging to the earlier batches required a formal training for investigating such cases. A proper training is paramount because more than detecting and resolving a case, the officers should know the modus operandi used for committing the offence. Investigation should not only resolve the case but come up with substantial evidence sustainable before the court of law to prove the offence and the involvement of the accused.
In addition, owing to the lack of a cyber crime unit and formal training in investigating such cases, officers tend to prosecute the offenders with the provisions in the existing Indian Penal Code and the provisions of the Information Technology Act 2000 were very rarely invoked.
The law demands that investigating officers should be in the rank of not less than Assistant Commissioners of Police/Deputy Superintendents of Police.
The force is yet to be equipped in terms of imparting training to such senior level officers, a senior police official pointed out.
When pointed out, Mr. Mahali said that officers were being sensitised on the need for making use of the relevant legal provision i.e., the IT Act whenever and wherever required and in the event of an offence qualifying for a prosecution under the IT Act, the investigating officers in such cases would be provided with the required assistance in terms of legal and technological expertise.
Stuff's guide to internet scams - Stuff.com - 07 Jun 2008
But people can be dangerous too. Just like the real world, the internet has its share of baddies out to steal your cash (not to mention your pride) by using technology combined with age-old confidence tricks. You don't have to be constantly on guard, but a little caution and know-how will make you a lot safer.
Here are some of the scams to watch out for, and some tips for staying safe.
SOME OF THE SCAMS YOU'LL ENCOUNTER
419 scamsNamed after the section of the Nigerian criminal code they violate, 419 scams are emails that claim to be from various dodgy organisations, like European lotteries that you never entered or African banks that claim you're the last living relative of a Moroccan billionaire. They'll ask you to get in touch to claim a reward, usually something ludicrous like $100 million, almost always typed out afterward ("ONE HUNDRED MILLION US DOLLARS").
The catch, besides the money doesn't actually exist, is that they'll ask for some money to cover the costs of getting the money to you. A variant of this scam asks for money to cover duties for goods held by Customs.
Phishing These emails pretend to come from banks or auction sites like TradeMe or eBay. Sometimes they'll ask you to confirm your password, sometimes they'll say there's been "unauthorised activity" on your account. Either way the email will contain a link to log-in. Do not click on this link, even if it appears to be genuine, because it will lead you to a fake site that often look real but is just out to steal your info. Type your bank's address in your Web browser and log in normally instead.
Spear Phishing Like the name implies, spear phishing is a more targeted attempt to steal personal details. Typically you'll receive an email or phone call where they refer to you by name. The message may claim to be from your company's IT department or bank or even the police. They've targeted you not because you've got a reputation for being a dupe, but because your bank account is probably healthy or they want to break into your company's systems. Instead of giving out any information, get their name and then check it and what they're doing with the appropriate authorities.
Mules Have you ever received a job offer that seemed like you'd be making money just for having a New Zealand bank account? Don't be fooled. Foreign scammers need a Kiwi bank account to transfer money into because there are blocks or limits on transferring money overseas over the internet. Being a mule is illegal, and ignorance won't be much of an excuse when the police come knocking.
Love traps Dating websites aren't just for lonely hearts. There are also scammers out there pretending to be girls (and guys, but mostly girls) searching for love. Typically they will let the romance begin to bloom, then have a personal crisis and need a loan or reveal they actually live in another country and could you please send money for a plane ticket because they're really eager to see you in person.
Some clever scammers have even written a computer programme that automatically flirts with men to wheedle out their personal details.
To be safe steer clear of overseas sites (you don't need a Russian or Vietnamese bride that badly) and be extra careful talking to people on Kiwi dating websites who live outside the country. If something seems fishy, use your brains instead of other body parts to make a decision. Maybe they really are "crazy about Kiwi guys", but the smart money is they're after your wallet rather than your heart.
Scam websites Scam websites come in a few flavours. There are fake bank and auction websites that sit on web addresses which are close to the real thing (like www.mybnak.co.nz). These opportunist sites exist solely to trick people who aren't careful typists into giving up their account details. They often use the real bank's logo and images.
Sometimes the websites are even sneakier. They will automatically load the details you put in, say for your bank account, into the real bank's website, so you can't tell anything's wrong. Then when you log out, the scammers keep the connection open and transfer your money out.
Fake sites go one step further and try to hijack your PC. Called drive-by-downloads, they exploit flaws in your web browser to make you automatically download spyware or viruses.
Finally, there are scam websites pretending to be legitimate charities or businesses. After every disaster fake charities will spring up looking for donations, so stick to the official websites of the ones you know. The same is true for online shops. Don't buy unless you're sure it's legit, or you could lose your cash and your credit card details.
HOW TO SPOT A SCAM
Bad grammar and spelling - English often isn't the first language of the scammers, and if you read carefully you can spot tell-tale mistakes that a real bank wouldn't make.
The email asks you for your account details - Emails from banks or TradeMe should never ask you for any of your personal details. Email is not a secure way to communicate because it's hard to verify who exactly is on the other end and the message can be intercepted.
If it sounds too good to be true, it is - Sometimes good things happen. People really do win the lottery. But not if they haven't bought a ticket. If you could really make money doing nothing, everyone would be rich.
WHY DO PEOPLE FALL FOR SCAMS?
Sometimes they're stupid, but more often they're desperate or not paying attention. Emails from fraudsters pretending to be your bank and fake websites often disguise themselves well, using official logos and even real employee's names.
People do fall for 419 scams too, amazingly enough, usually because they desperately need the money and think the email is a godsend. If someone wants to believe something is true, they'll usually find a way to convince themselves.
Spear phishing is "social engineering". If someone called you up at work pretending to be from your company's IT department, you probably wouldn't think someone was trying to scam you.
Ads for mules can go the extra mile to appear to be genuine, using employment websites and official looking websites of their own.
DOH! WHAT TO DO WHEN YOU SCREW UP
I clicked on a link in a phishing emailYou're probably ok if you didn't enter in any details. Shut down your browser (and internet connection if you can) and run a full scan for viruses and spyware.
I typed in my bank account/credit card/auction account details Call your bank immediately. The sooner you do the less likely you'll be held liable for the money the fraudsters spend on your behalf.
They've stolen my money The bad news is the criminals responsible are usually overseas, and the chances of catching them are pretty much nil. ASB and Kiwibank will reimburse losses on a case by case basis. If your computer is up to date and running security software and you tell your bank quickly what's happened, the banks will look on it pretty favourably.
Westpac will reimburse all stolen money and BNZ will fully reimburse customers who use their NetGuard system. ANZ and National offer the same guarantee as long as you're don't actively participate in the fraud, like for a mule scam.
ANZ, National, ASB, Kiwibank and BNZ offer "two-factor identification" - numbers on tokens or cards which you use as well as your password to log in. This extra security measure makes it much harder for fraudsters to get into your account, so if you can, sign up for it.
I used a computer in an internet café to check my email or bank balance Never use public computers like in libraries or internet cafes to log into anything important. If you have, change your password as soon as you can from a secure computer.
I replied to a fraud email Whether you're asking for more info or telling the scam artists they're scum, it's a bad move. You're just confirming your email address is valid and active. Expect lots more spam in future.
I think I downloaded a virus or spyware Update your security software and run a complete scan on your system. If you're really paranoid, reformat your hard drive and reinstall your operating system
Friday, June 6, 2008
Dedicated cyber crime police station to go online - Economic Times - 05 Jun 2008
Tuesday, June 3, 2008
Cibil to keep tab on fraudulent deals - TOI - 02 Jun 2008
The Indian Banks’ Association has asked Cibil to set up a pilot project called Credit Information Company (CIC) for such a centre in association with Trans Union. The IBA decided this at its annual general body meeting last Monday.
Trans Union already runs a similar bureau on retail in the US and holds a10% stake in Cibil.
Ten banks are likely to join the pilot project for forming a centre on fraud data. Some of the banks that will be part of the project include State Bank of India, ICICI Bank, Bank of Baroda and Union Bank of India. Confirming the development to FE, K Unnikrishnan, deputy CEO of the association, said, "We are now in the process of communicating to the 10 banks that will be joining the pilot project."
The remaining banks would join only on the successful completion of the pilot, he added. “We wanted to have a mechanism on the issue and when Cibil approached us, we asked them to help us develop it,'' he explained.
Cibil managing director Arun Thukral said, "Although we are already successfully running the country’s sole credit information bureau for seven years, we don’t have any central database on frauds. The initiative will help us a lot in that direction.''
Apart from Cibil, there are a few more Companies aspiring to run the proposed CIC. They include UK’s Experian and the premier rating agency, Crisil. Experian has formed an Indian entity, Experian India, in which it will have a 49% stake.
Vikram Narayan, Experian’s managing director and country manager for India, said, "We have applied for a licence from the RBI. We plan to set up a credit bureau with Equifax in the country similar to Cibil. Crisil, too, is keen and has also applied for a licence. “We are awaiting the RBI’s response,'' confirmed, Roopa Kudva, MD & CEO, Crisil Ratings .
Announcing the annual monetary policy a month ago, RBI governor YV Reddy said, "The central bank will review all the 13 applications received by it for the CIC and will issue a licence to the eligible Companies.'' A high-level advisory committee headed by RH Patil will be clearing all these new proposals for CIC by June-end. The Credit Information Act, 2005, allows the country to have more than one agency in the credit bureau space....
Hannaford upgrades card-security system - First Source - 02 Jun 2008
As Hannaford prepares to defend itself in a class-action lawsuit, the company says it continues to make changes to better protect consumers.
Those changes include a stronger system to detect any intrusions into Hannaford's computer network. Hannaford has consulted with experts from General Dynamics Advanced Information Systems, IBM, Cisco and Microsoft to ensure the highest levels of information security, spokeswoman Carol Eleazor said Friday.
''This is all above and beyond the industry standard for retailers,'' Eleazor said.
Hannaford, a grocery store chain headquartered in Scarborough, learned Feb. 27 that data thieves had attacked its security system beginning Dec. 7, 2007. When the company announced the breach to the public March 17, officials said they were aware that 1,800 cards had experienced fraudulent charges.
The Secret Service is investigating the massive data theft.
Most of the security upgrades were announced by Hannaford officials in April, and company staffers are working with contractors to implement the changes, Eleazor said.
Hannaford expects to spend millions of dollars on the changes, but has not disclosed an estimate.
Hannaford is working to install the triple-DES PIN encryption system to guard against theft of customer credit card and debit card numbers.
New PIN pads are being installed at all the Hannaford stores and Sweetbay grocery stores in Florida operated by Hannaford.
''That process will be completed at all Hannaford and Sweetbay stores in the next several weeks,'' Eleazor said.
Since the breach was contained, the company has launched a ''real-time/real people'' security-monitoring program, which provides alerts about any intrusive traffic trying to access the Hannaford network
tmaxwell@pressherald.com
Monday, June 2, 2008
Hey, banks, earn your stripes and fight ATM fraud scams - kansascity.com 31 May 2008
How well is your financial institution protecting you from growing ATM frauds?
Don’t know? You should ask. Turns out financial institutions now have the technology to thwart even the most innovative ATM scam artists.
Yet, surprisingly, many institutions have only lately started using the technology, said Overland Park security expert Mark J. Tomasic.
Some still don’t, said Tomasic, security director for StoreFinancial, an electronic payment processor that handles gift card programs for more then 360 shopping centers throughout North America and the United Kingdom.
Recent news accounts describe how con artists have used e-mails, phone calls and text messages to con hundreds of consumers into giving them their banking account numbers and PINs — which is like handing over your house keys.
The scammers made phony ATM cards, complete with magnetic stripes embedded with a victim’s personal banking data. Using a PIN, the thieves could access their accounts from anywhere in the world.
The con artists convinced naive consumers their accounts were suspended and could only be reopened by providing personal information. It wasn’t smart of consumers to give out their information in the first place.
But the scams won’t work against financial institutions that are prepared.
Turns out also embedded in the magnetic stripe on the back of every legitimate credit, debit and ATM card is a hidden logarithm called a CVV, which stands for Card Verification Value.
The CVV is transmitted with every transaction. That means any institution can require its ATM network processor to verify every ATM card transaction.
And if the CVV doesn’t match, the transaction won’t go through and the fraud is stopped in its tracks.
In fact, Tomasic said, someone could give out all his personal information, PIN included, and a fraudster could attempt to use a fake card, “and it would be declined for ‘invalid CVV.’ ”
So why don’t all banks, credit unions and other financial institutions use this ATM technology that’s already available?
Actually, financial institutions have been using the technology for years with credit cards, debit cards and transactions at stores and other retail establishments.
Indeed, a big advantage of using plastic is that you are protected from fraudulent transactions. In most cases, you won’t lose more than $50 if your card is used without your permission.
But ATMs are a more recent invention, and seemed less susceptible to fraud. So many institutions let them slide. But that changed in the last two years as ATM fraud spiked, Tomasic said.
Tomasic knows this personally from working at banks, where he tracked frauds. He recalls one bank that lost $4 million in one month to fraudsters. But, he said, when the bank started requiring its ATM network to verify the transactions, the frauds stopped. And the customers were reimbursed.
Carl Bradbury, senior vice president at Commerce Bank, said his bank began using the technology several years ago and it has “cut that sort of PIN-based fraud off at the knees — it’s a powerful tool against the bad guy.”
Bradbury points out that banks will never ask customers to disclose their PINs in the first place. If asked to do that, you can be sure you’re dealing with scam artists.
So how can you find out if you’re protected?
Tomasic said the best way is to simply ask your bank. “All cards are bank products, and from my perspective the onus is on your bank to protect you,” he said
That applies, he said, even if you are conned or give out your PIN inadvertently. If your bank won’t tell you, he said, you have the option to take your business to one that does.
Debunking myths
You may have heard the one about how personal information gets embedded on a cardkey when you check into a hotel with a credit card — allowing a dishonest employee to steal your identity.
“No, I guarantee it’s not true,” Tomasic said.
“There isn’t any personal information put on a cardkey,” he said.
He said another urban myth that won’t go away claims “that if you are being robbed at an ATM or forced to withdraw money, you can enter your PIN number backwards and the police will be alerted.
“That’s also not true,” he said
By PAUL WENSKE
Sunday, June 1, 2008
A look into the dark underbelly of data breaches - www.networkworld.com
That is but one of the disconcerting details of a Department of Justice-penned report that looks at the rapidly morphing, dark side of stolen personal information set to appear in next month’s issue of the Santa Clara Computer and High Technology Journal.
The article goes on to say the large volumes of stolen data are priced to sell and charges are determined by the degree of difficulty in obtaining the data, according to the paper’s author, DOJ attorney Kimberly Kiefer Peretti. In the first half of 2007, for example, credit card information ranged from $0.50 to $5.00 per card, bank account information ranged from $30.00 to $400.00, and full identity information ranged from $10 to $150.79. Such information is available on illegal Web sites known as carding forums.
Indeed “carding” is at the heart of the issue, which the paper describes as the process by which large volumes of data are stolen, resold, and ultimately used by criminals to commit fraud. In its narrow sense, the term “carding” refers to the unauthorized use of credit and debit card account information to fraudulently purchase goods and services, the article states.
The term has evolved in recent years, however, to include an assortment of activities surrounding the theft and fraudulent use of credit and debit card account numbers including computer hacking, phishing, cashing-out stolen account numbers, re-shipping schemes and Internet auction fraud, Peretti states.
The prosecution of such card forums has been ongoing. A few of the more well known include:
· Shadowcrew: A global organization of thousands of members that was dedicated to promoting and facilitating the electronic theft of personal identifying information, credit card and debit card fraud, and the production and sale of false identification documents. The organization operated and maintained the Internet website www.shadowcrew.com from 2002 until October 2004, when it was taken down by the U.S. Secret Service as the result of an undercover investigation known as “Operation Firewall.”
· Carderplanet: The Carderplanet organization operated and maintained the website www.carderplanet.com for its criminal activities and was founded in May 2001.47 By August 2004, the site had attracted more than 7,000 members. The site provided its members with a marketplace for millions of stolen accounts. Although most of the postings on the forum were in Russian, and most of Carderplanet members were from Eastern Europe and Russia, the forum had a significant English-speaking component. Senior members of the organization shut the website down in the summer of 2004 following some arrests of high-ranking members and law enforcement scrutiny.
· Cardersmarket: The Cardersmarket organization allegedly operated and maintained the website www.cardersmarket.com for its criminal activities and was founded in June 2005. Similar to other carding forums, Cardersmarket was allegedly dedicated to the unlawful acquisition, use and/or sale of unauthorized credit card account information, and other personal identification and financial information. As of September 5, 2007, Cardersmarket allegedly had thousands of members worldwide. In August 2006, the forum’s administrator, known by the nickname “Iceman,” allegedly took over four rival carding forums and thereby increased the Cardersmarket membership to 6,000. The DOJ helped indict Iceman, AKA Max Ray Butler in Sep. 2007 on charges of wire fraud and identity theft related to an online scheme to steal credit card and other identity information.
The paper goes onto to suggest key ways to continue fighting the carder war. For one it advocates broadening the notification laws. Over 36 states have laws that require consumer notification in the event of a security breach. Many of these state laws allow victim entities to delay notification if a law enforcement entity informs the entity that notification may impede a criminal investigation, the paper notes.
Another key is bolstering the tools prosecutors can use to bang on such criminals. For example, the Privacy and Cybercrime Enforcement Act of 2007 that amends the federal criminal code relating to computer fraud and unauthorized access to computers to: (1) include computer fraud within the definition of racketeering activity; (2) provide criminal penalties for intentional failures to provide required notices of a security breach involving sensitive personally identifiable information; (3) expand penalties for conspiracies to commit computer fraud and extortion attempts involving threats to access computers without authorization; (4) provide for forfeiture of property used to commit computer fraud; and (5) require restitution for victims of identity theft and computer fraud. The bill is still in committee.
Finally the paper recommends strengthening sentences for such crimes. “Hackers and identity thieves receive light sentences in many cases either because of their young age or because the sentencing judge may not view these non-violent crimes as serious. Indeed, a recent identity theft bill passed by the Senate directs the Sentencing Commission to review its guidelines to reflect the intent of Congress that penalties for identity theft-related offenses should be increased.”
Friday, May 30, 2008
Fraud crimes will be a thing of past if banks exploit KEY and PIN system - ZDnet.co.uk - 29 May 2008
These details show that banks have option to reduce all fraud crimes to virtually ZERO simply by exploiting KEY and PIN system.
Fraud crimes will continue to grow until banks exploit KEY and PIN system described on website www.xwave.co.uk which will make both signature and PIN systems reliable and foolproof. This system will eliminate the need for us to protect our personal and PIN details since fraudsters will not get tempted to misuse them.
KEY and PIN system could be treated like international ID card since it will personalise signature and PIN to the right individual in any country in the world.
Fraud crimes will be a thing of past if banks and the government exploit KEY and PIN system.
Africa: Continent Must Unite in Fighting Economic Crimes - BuaNews (Tshwane) - 28 May 2008
A network of African countries, where information and knowledge is shared between law enforcement agencies, would help to solve financial crimes and open up economic opportunities for the continent, says Acting National Director of Prosecutions Mokotedi Mpshe.
He said African countries should see the criminal justice system as not only prosecuting criminals involved in crimes such as trafficking, but also ending illegal activities which hamper the economy.
"This will attract foreign investors while creating more jobs," said Mr Mpshe while addressing delegates at the Africa Conference on Economic Crime on Wednesday.
Mr Mpshe said economic crimes would be re-examined and the conference would come up with a clear mandate on how to tackle such crimes, something which will be of great benefit to South Africa.
"Although we have good units within the National Prosecuting Authority (NPA), there is a need to always re-look at our strategies and point out the necessary issues which need to be re-enforced while evaluating the progress."
He urged countries, especially those in the South African Development Community (SADC) to fight narcotic trafficking and money laundering."I believe the deliberations will enable us to make good strides as these act are not just criminally perceived, but also pose business risk," said Mr Mpshe.
He said he had no doubts about the excellent work carried out by different units within his institution so far, adding that the NPA had a strategic role to play in driving back crime to acceptable levels.
"We have already developed a 2020 strategy, set standards in fighting economic crimes and the organisation has so in the right track," said Mr Mpshe.
The NPA's Specialised Commercial Crimes Unit (SCCU) which specifically deals with complex commercial crime cases, has so far dealt with 3 500 cases and has been doing excellent job, he said.
The Asset Forfeiture Unit (AFU) has between 2006 and 2007 continued its upward trend, tackling 252 cases and seized R1.25 billion.
The Directorate of Special Operations, responsible for individual prosecution of organised crime, has been concentrating more resources on combating economic crimes and targeting top-end perpetrators.
"Again the strategy we used worked well for the organisation with major levels of success."
Commenting on the application to stop legislation being passed that will see the NPA, or Scorpions, from being disbanded which was turned down in the Pretoria High Court on Wednesday morning, Mr Mpshe said government's intention was to come up with an elite unit with necessary capacity while strengthening ways of fighting organised crime.
I advocate for the merging of Scorpions and the police to be given a chance, he said, adding that we should wait and judge the results.
Judge Willie van der Merwe ruled that the court did not have the jurisdiction to grant such an order as it has not enough jurisdiction to interfere with the decision to incorporate the Scorpions with the police.
The General Law Amendment Bill and the National Prosecuting Amendment Bill are due to be tabled in Parliament.
The two bills are set to pave the way for the formation of a new unit incorporating parts of the Scorpions and the police's Organised Crime Unit.
President Thabo Mbeki appointed the Khampepe Commission of Inquiry in 2006, headed by Judge Sisi Khampepe, to review the mandate of the Directorate of Special Operations (known as the Scorpions) as well as its location.
The report was never intended to be released publicly and President Mbeki only took the decision to release it in February.
He said the decision was taken to release the report at the same time as the tabling of the two Bills to Parliament so that it could form part of what people based their decisions on.
The report reveals that the location of the DSO is not unconstitutional, but it however noted some concerns over the size and operating methods of the unit.
Mr Mpshe noted that there were some issues which seem to have caused tension within the members of the public regarding Scorpions and police.
"The public has the right and ought to know what is happening within the NPA, we are currently putting together a statement which will soon be sent to the public on the unit's programme of action," said Mr Mpshe.