Showing posts with label Online fraud. Show all posts
Showing posts with label Online fraud. Show all posts

Thursday, July 17, 2008

Russian Coreflood Gang targets online bank accounts - news.yahoo.com - 16 Jul 2008

Call them the Coreflood Gang. A ring of cyber bank robbers from southern Russia has quietly perfected a way to get a beachhead inside company networks.

Once inside, it infects every PC within reach with a custom-made data-stealing program called Coreflood. The goal: go rip off bank accounts online.

Over the past 16 months, the Coreflood Gang has infected swaths of PCs inside thousands of companies, hospitals, universities and government agencies, says SecureWorks researcher Joe Stewart, who has tracked and documented the spread of Coreflood over that period.

"It's spying on you, capturing your log-ons, user names, passwords, bank balances, contents of your e-mail," Stewart says. "It can capture anything."

Coreflood is part of a class of malicious software, called banking trojans, designed primarily to help crooks break into bank accounts online. The number of banking trojans detected on the Internet this month topped 24,800, up from 3,342 at the start of 2006, security firm F-Secure says.


An infection usually starts when you visit a Web page implanted with a snippet of malicious coding. By simply navigating to the tainted page, your browser gets redirected, unseen, to a hub server that downloads the data-stealing program onto your hard drive.


Dozens of gangs specialize in banking trojans. They have it much easier than phishing scammers, who must lure victims into typing sensitive data on spoofed Web pages, says F-Secure researcher Patrik Runald.


"This is very organized crime," Runald says. "These gangs are hiring people and making tons of money."


The Coreflood Gang is among the most sophisticated. Stewart recently analyzed 500 gigabytes of stolen data stored on a rented hub server. He pinpointed 378,758 Coreflood infections inside thousands of organizations, small and large.


A workplace PC can get a new infection each time someone logs on. The most infections: a county school district with 31,425, a hotel chain with 14,093 and a health care company with 6,744. About 230 networks turned up with 50 or more Coreflood infections, while 35 networks each had 500 or more.


Gang members cull the stolen data for log-ons and account statements, especially bank accounts online with high balances. Next, they log into the accounts and make online cash transfers into "drop" accounts they control.


After having two hub servers shut down by the tech security community in May, the Coreflood Gang rented two new hubs and picked up where they left off. Today, they continue operations unimpeded, says Stewart.


Companies infiltrated by the Coreflood Gang need to rethink how they do network security. Employees surfing the Internet on work PCs ought to take pause. "If you don't understand the threats that are out there, then you probably should not be banking online," Stewart says.

By Byron Acohido, USA TODAY

Saturday, July 12, 2008

Airlines act against e-ticket fraud - The Telegraph – 10 Jul 2008

Fliers must carry photocopy of credit card used for purchase

The next time you buy an air ticket online for someone you know, don’t forget to give that person an attested photocopy of your credit card because airlines are becoming stricter in implementing a fraud-prevention rule that has been in existence for some time.

Amitabha Banerjee (name changed on request) was unaware of this when he checked in for an afternoon flight to Mumbai last week. The executive at the check-in counter of the private airline sought a photocopy of the credit card that was used to buy the e-ticket, leaving him puzzled.

Banerjee said he had bought the ticket from a travel agent and didn’t know whether a credit card had been used in the transaction. “On being told that airlines are being extra cautious in regard to tickets bought with credit cards, I called up my travel agent from the airport to ask for a faxed photocopy of his card,” he recalled.
He was lucky to get it in half an hour, just in time to board the flight.

The high incidence of identity theft — all you need for an online purchase is the credit card number, the expiry date and the three-digit CVV number printed at the back — is the reason why airlines are insisting on fliers carrying photocopies of credit cards if their tickets have been booked by someone else.

“There have been several such frauds over the last six months,” a Jet Airways official said.

He said almost all airlines had this clause in their e-ticket rules, though very few were implementing it until recently. “Henceforth, if any passenger fails to show the photocopy of the credit card attested by its owner, the ticket will be cancelled and a fresh ticket issued. The owner of the card will get the refund,” the Jet official said.

The system is, however, far from foolproof. A card that is stolen can be used to buy tickets, photocopied and presented as proof of the purchase being bona fide. “If a person commits this kind of fraud, there is nothing one can do,” said an official at airport police station.

There have even been instances of hackers cracking online payment gateways with fake credit card numbers and purchasing tickets. In such cases, airlines incur losses.
Last month, the e-commerce department of Jet Airways asked its airport division to look out for a passenger booked on a Calcutta-Mumbai flight because of doubts about his online purchase. "We were asked to check the photocopy of the credit card and if the passenger failed to produce it, the ticket should be cancelled. The passenger did not turn up. It seems he had a hunch he would be caught," an official said.
Most frauds are committed by small-time tour operators. "Tickets are issued usually 24 hours before departure, giving us little time to detect the fraud," a Deccan official said.

"We advise passengers to buy tickets from authorised travel agents. They should not fall for unusually low fares offered by tour operators whose credentials are not known," said Anil Punjabi, chairman (east) of the Travel Agents’ Federation of India.

According to sources in the aviation industry, 5-7 per cent of airline tickets are bought online. Around 20 per cent are purchased with credit cards from travel agents.

By Sanjay Mandal

Wednesday, July 9, 2008

Helping prevent online fraud - - southbendtribune.com – 06 Jul 2008

As if identity theft wasn't scary enough, last month's string of fraudulent withdrawals from hundreds of accounts at local financial institutions gave area residents more reason to worry.

Luckily, in some cases consumers can prevent scams with the right defensive measures.

Some strategies should be obvious. For example, don't use "password" as a password, shred old bills, and don't keep pin numbers written down in a wallet or purse.

But as crooks get smarter, common sense may not be enough to stave off scams.

While 1st Source Bank officials said an online data breach was most likely to blame for scams related to their ATMs, Ray Miller, owner of Michiana Mobile Computer Repair, speculates that skimmers may have been part of the problem.

Skimmers are devices that can read a card's magnetic strip when placed over an ATM card slot.

"Skimmers will have a little pinhole camera mounted in them so they can see the key presses and store the pin numbers there," Miller said.

Miller, who deals with security issues daily in his business, also warns against card catchers. These devices are thin strips of metal or plastic a thief places inside the card slot, allowing cards to be inserted but not ejected. Victims believe their cards have been "eaten" by the ATM, and when they leave to report the problem to their local branch, the thief can remove both the strip and the card.

1st Source Bank's online breach is not the norm in causes of identity theft, according to a study by the Better Business Bureau in 2005.

The study found that the theft of online information accounted for only 11.6 percent of identity fraud cases. In addition, the study found that half of all identity thefts were committed by someone the victim already knew.

To prevent against offline fraud, the identity theft protection company LifeLock recommends dropping off outgoing mail in official post office boxes rather than leaving it in a home mailbox.

"A lot of criminals will steal people's mail for credit card numbers or account numbers and steal that information," Miller said. "People stealing trash is not as frequent but it still happens, so people should use shredders."

Though paper is the biggest target of identity theft, public computers and wireless Internet connections present dangers that users often don't think about, Miller said.

"What most people aren't aware of is that when they use Wi-Fi hot spots, anyone who's on the same hot spot can use any shared folders or files they have on their computer," Miller said.

He also warns against packet monitoring software, which hackers can use to intercept and log traffic passing through the network.

"For any traffic they're sending back and forth in a Wi-Fi hot spot, anyone who's on the same network can view what they're sending," Miller said.

Keylogging software may also be a danger on public computers, Miller said. Someone could install such software on a public computer, store the keystrokes users type with a USB device, and collect the user names and passwords logged weeks later.

Some recent legislation aims to protect consumers against fraud. Because of the Fair and Accurate Credit and Transactions Act of 2003, consumers can receive a free annual credit report from one of the three major bureaus, Equifax, TransUnion, or Experian. Consumers who suspect fraud on their accounts can receive credit reports for free as well.

While prevention may be the best weapon against identity theft, people can minimize damages by checking on their accounts daily via the Internet, Miller said.

"ATM debit cards are really easy to keep track of," he said. "For myself, every day I'm downloading and updating transactions and comparing them to things my wife and I have done."

By SUPRIYA SINHABABU

One in four Asian banks hit by online scam attempts – The Economic Times - 7 Jul 2008

SINGAPORE: More than 25 percent of banks in the Asia-Pacific region have been hit by attempts to steal online information over the last 12 months, but beefing up security is still not viewed as a prime concern, a study said on Monday.

The survey by security software specialist ReadiMinds was conducted by Web and telephone polls across 11 economies including Malaysia, Hong Kong, Bangladesh, Vietnam, Cambodia and Singapore.

In such internet scams, crooks typically pose as the websites of financial institutions and attempt to "phish" for information including user names and online banking passwords, the study said.

In most Asian countries, "regulations are still catching up with the strengthening of their online security regime," a ReadiMinds spokesman told The Business Times. "Asian countries with weaker regulatory frameworks have therefore attracted the extra attention of online fraudsters."

Singapore banks are the exception, fortifying their defences to counter the on slaught of new threats. Online security is still not regarded as a prime concern by the majority of the regional banks. Seventy-five percent of the respondents said they were not aware of the impact of cyber security on their operations.

More than 60 percent of the banks polled did not set aside a budget for online security, lumping it instead into the overall technology budget. Only 20 percent have adopted measures to strengthen internet-based transactions, the report said.

Underscoring the lax security stance, the survey found 80 percent of the banks queried have no formal plans for raising consumer awareness against threats such as identity theft and financial fraud. Individual country breakdowns were not revealed to protect the confidentiality of the banks involved.

Sunday, July 6, 2008

Credit card fraud worth over Rs 25 lakh busted, 3 arrested - Expressindia.com - 01 Jul 2008

Mumbai, June 30 The Mumbai Police Crime Branch claims to have busted a credit card fraud worth over Rs 25 lakh after it arrested three accused who allegedly used credit card details of over 100 customers to purchase online airline tickets and mobile phone refills, and even to procure a bank loan.
The arrested accused have been identified as Sandeep Mullick (25), a resident of Mazgaon, and Shakeel Shaikh (23) and Mohammed Miya Umedin (27), both Sewri Cross Road residents. They were arrested by Unit 1 of the Crime Branch on June 20, and have been remanded to police custody till July 1. As per the police, the amount involved in the fraud is estimated to be between Rs 25 to 30 lakh.

According to the Crime Branch, Mullick was working as a courier boy for an agency called Supreet Data Tech Ltd., which was outsourced by Barclays Bank for credit card application procedures. "Customers would be contacted over the phone for credit cards or loans offered by Barclays Bank. Supreet Data Tech Ltd. is responsible for collecting the necessary documents provided by the applicants, who would also provide details of credit cards they already had in their name. Mullick would photocopy these documents, and hand them to the other two accused for a sum of Rs 200 per case. Shaikh and Umedin would then go to a cyber cafe and misuse these credit card details for online transactions. Barclays Bank and Supreet Data Tech Ltd. were not in the know about Mullick's illegal activities," said Joint Commissioner of Police (Crime) Rakesh Maria.

"Shaikh and Umedin used the credit card details to purchase 180 airline tickets online. These were domestic flights from Mumbai to Delhi, Jaipur, Lucknow and Rajkot. They also made about 300 transactions for mobile phone recharge ranging from Rs 201 to Rs 3,999. Finally, they also procured a loan of Rs 1.69 lakh from Citibank. The total fraud is estimated to be between Rs 25 to 30 lakh," said Maria.

The Crime Branch is now on the lookout for two more suspects in the case. "Mullick sold the details to four accused, two of whom have been arrested. He collected documents from 567 applicants, of which 125 had previous credit cards. Of the 180 airline tickets they bought, they used 84 for their personal use and sold the remaining. The total mobile phone refills amount to Rs 17,000. This racket has been on since December last year," said Senior Police Inspector Ramesh Mahale of Crime Branch Unit 1.

Sunday, June 22, 2008

Fraudulent ATM transactions overseas could be tied to Indiana bank breach - computerworld.com - 19 Jun 2008

A server intrusion at 1st Source Bank in South Bend took place in May

A flurry of fraudulent ATM transactions in recent days in countries such as Russia, Ukraine, Turkey and the Czech Republic may be tied to a server intrusion at 1st Source Bank in South Bend, Ind.

So far, the fraud appears to have affected at least 200 consumers who belong to more than half a dozen banks and credit unions in the state, according to local media reports. Among those reportedly affected are customers of 1st Source, Teachers Credit Union (TCU) and Farm Bureau Credit Union.

Representatives from TCU and Farm Bureau did not immediately respond to a request for comment. Neither did the St. Joseph's County Police Department in Indiana, where a large number of affected consumers reported being victimized by fraudulent automated teller machine transactions.

James Seitz, a vice president at 1st Source, today said it is "reasonable" to assume that the fraudulent transactions are linked to an intrusion into one of the bank's servers on May 12.

The breached server contained debit card transaction data belonging to customers of 1st Source and other financial institutions who used 1st Source ATMs. Seitz confirmed that the information in that server was stolen by hackers, but he refused to say how many records were stolen or how many individuals may have been affected.

After the breach was discovered, the bank immediately "shut down" all of its own cards that were compromised, Seitz said. He refused to disclose how many cards 1st Source blocked and reissued.

The bank also compiled a list of all the other cards that were on the affected system and informed the major credit card companies about the breach, he said.
According to Seitz, much of the fraudulent transactions being reported appear to have taken place over the weekend. Since then, the transactions have "slowed down significantly," he said. Most of the withdrawals were for amounts of $200 or $300 or whatever the daily limits for each card might be.

The incident highlights the international nature of cybercrime and the global market for stolen credit card and bank data. A report released yesterday by security vendor Finjan Inc. noted that the underground market is flooded with stolen credit and debit card data, leading to its easy availability and commodity pricing. According to Finjan, stolen credit and debit card data, which retailed for $100 per card a few months ago, these days costs just about $20 per card and can often be purchased after little more than a Google search.

Wednesday, June 11, 2008

Number of Internet Fraud Victims on the Rise - scoop.co.nz - 10 Jun 2008

Failing to do basic background checks is resulting in more internet users falling victim to online fraud this year, costing them up to as much in value as a small car.

Internet fraud is up 20 per cent from last year, says the Internet Crime Complaint Centre, with 37.5 per cent of all complaints due to online auction fraud.

Barnaby Jack, a staff security researcher at Juniper Networks in the United States says that fraud involving online auctions continues to be the most prevalent.

“A lack of education about the latest tricks employed by scammers, a lack of education about technology and the internet in general increase a person’s vulnerability” he says.

The most common type of internet fraud involves online auction sites such as TradeMe or ebay. Mostly its simple fraud whereby the buyer sends money for a product, and the product never materialises. It likely never existed and was a fake listing purely for the purpose of a scam.
Others involve potential buyers offering to pay for goods via cheque, asking the seller to refund the difference in cash. Once the bogus buyer has received the cash, the cheque bounces, and the seller never hears from them again.

Kris Bainbridge, systems administrator for Guidance Media says that simple background checking on online auction sites, such as checking the users feedback, can be a good indicator of their trustworthiness.

“Many people are simply too trusting, or may not be familiar with the various scam methods” he says.

Garrett Denton, a 28-year-old customer service rep, explained how his mother fell victim to an online scam when trying to book an apartment for her trip to New York last year.

After spotting the apartment on the internet they contacted the owner, who asked them to send a deposit to “secure their booking.” This worked out at approximately NZ$2700.
A bank cheque was made and sent over to the seller, whom they never heard from again. The number initially provided to them was a prepaid phone and has since been disconnected.

Further background research revealed the same apartment had been listed on several different websites, under contact names like John Doe and Joe Smith.

“I don’t think there’s a way of stopping him” Denton says.

“The sites he’s used are TradeMe type sites, so users can just sign up for a new account and list whatever they like.”

Bainbridge says that online auction sites are starting to get more proactive in their approach to avoid such scams.

“TradeMe is actually pretty good. They make it hard for you to fully use the site until you are ‘address verified’, a process which requires you to prove your address is real” he said.
Both Jack and Bainbridge agree that the age old adage “If it looks too good to be true…” applies in all cases when shopping online.

“On sites like ebay or TradeMe, a lot comes down to common sense” Jack said.
“Check feedback,” says Bainbridge “See what sort of contact details the other party provides, real phone numbers, emails, addresses. Talk to them via phone if you need to.”

Phishing is another common, and dangerous, scam. The victim will receive an email which appears to be from a legitimate retailer, bank, organization, or government agency.

The sender asks the victim to “confirm” their personal information for some made-up reason: your account is about to be closed, an order for something has been placed in the victim’s name, or your information has been lost because of a computer problem. Scammers are then able to obtain the victim’s login details and can access personal information or clear their bank accounts.
Most recently AUT has become target of one such scam. Staff members received an email allegedly from AUT IT services, requesting staff confirm their login details.
The AUT IT Service Desk states, “IT Services would never send a blanket email asking for staff or students to supply their login details. If this were the case it would be a personal face-to-face communication between the IT Service Desk and yourself.”

Bainbridge says “Like any kind of fraud, scammers prey on human weakness. The internet is simply another vehicle for them. That’s the tough bit.”

By Angela Beswick

Report: Thieves Target Online Travel Sites - csoonline.com - 09 Jun 2008

Online travel sites and airplane parts manufacturers are among the biggest victims of cybersquatting, false association, pay-per-click abuse and domain kiting, according to a new report from security vendor MarkMonitor.

The vendor points to the increased risk in those business sectors in its newly released Brandjacking Index for the spring. The findings reflect a trend observed by other security experts who have found, among other things, that the bad guys are using search-engine optimization (SEO) tricks to get their bogus sites higher in the search rankings.
Trends noted in the report included:

The rise of online auctions for fraudulent travel vouchers. The average discount for the more than 150 listings analyzed was 80 percent under face value. With the recent airline industry bankruptcies, increased cases of online fraud related to refunds, credits and vouchers are likely.
The growing success of search engine optimization tactics. Through higher search rankings, scammers divert Internet users searching for legitimate travel brands to illicit sites with questionable content, including pornography.

Blended abuses targeting travel brands. Attackers have combined multiple techniques such as spam, pay-per-click fraud and malware to put shoppers' computers as risk for viruses and spyware.

Meanwhile, the vendor found that cybersquatting is the most pervasive form of brandjacking, growing by 40 percent in the first quarter of 2008, while pay-per-click fraud actually declined by 42 percent. Phishers also appear to be targeting fewer new organizations, focusing 90 percent of the phishing activity on a small number of brands.

Dancho Danchev, an independent security researcher and consultant based in the Netherlands, said the MarkMonitor research reflects much of what he has been monitoring in recent months.
"What I've been witnessing is an automated approach that comes up with relevant brand impersonating domains such as anti-virus-2008.com, registering these and uploading the fake security software," Danchev said, adding that scams are getting more sophisticated due to the localization crooks are starting to apply even in the domain names themselves - registering the domains in a native language to attract local traffic, for example.

Where the money is During a recent visit to the offices of CSOonline to promote the latest Brandjacking Index, MarkMonitor Chief Marketing Officer Fred Felman said he's not surprised by the explosion of online travel scams designed to lure shoppers from legitimate e-commerce sites. But he was taken aback by the number of bogus sites selling questionable aircraft parts on business-to-business exchanges and consumer auction sites.

"The criminal is always thinking about where the money is, so it makes sense they would go after travel sites," he said. "We all travel and are frustrated by the high cost of airline tickets and hotel rooms, so we're constantly looking for bargains."

He's also not surprised the bad guys are making so much money since, as Danchev noted, they are getting more adept at using cybersquatting and SEO tactics, a trend reflected in a recent special report from CSO magazine (Black Hat SEOs: Is This the Future of Search?).

Danger in the skies? Though he wasn't surprised to see travel sites targeted so aggressively, Felman said he was shocked by research showing vendors in China, the U.S. and other countries selling questionable aircraft components in bulk online.

"Given all the regulations out there, it's surprising that we found so many bogus parts sites," he said. "There's a growing risk that these parts could end up in standard distribution channels."
Other security experts are far less surprised to see bogus airplane parts proliferating across cyberspace. For them, the China connection in particular is a no-brainer.

"I'm not surprised by anything coming from China," said Petko D. Petkov, a self-described hacker and founder of UK-based think tank GNUCITIZEN. "The cyber laws in China are a bit vague and [hackers] are usually left to do whatever they want without consequences."

Independent security consultant and former Radianz CSO Lloyd Hession noted that there has always been a market for bogus plane parts and that people have been traveling for years in planes fitted with some of the questionable components. It's just that the bad guys have finally taken their business online, he said.

Security options limited While companies can reduce the threat to their reputations through a layered security program and constant surveillance to see if their brands are being abused, Petkov said defensive options are limited.

"In the case of brandjacking, I don't think there's an easy solution due to the fact that the people who abuse the particular brand may not reside within a country that has sensible regulations" to deal with the practice, he said.

In cases where phising attacks happen via a third-party domain the targeted company has no control of, there is very little to do, he said. One can contact the ISP in charge of the domain or the hosting space with the hope that they will terminate it, or report the malicious URLs to numerous anti-phishing registers.

Unfortunately, he said, "none of these workarounds will be 100 percent effective."
For its report, MarkMonitor analyzed feeds from leading international ISPs, e-mail providers and other alliance partners.

By Bill Brenner

Tuesday, June 10, 2008

Online crooks up the ante - australianit.com - 10 Jun 2008

INTERNET service providers and the industry need to do more to secure consumers' PCs, as experts concede strong passwords, regular patching and antivirus software are now of limited value.

With the AusCERT Home Users Computer Survey finding nearly one in four PCs have been infected by malicious software, security heavyweights concede ordinary users can no longer deal with the threats.

AusCERT general manager Graham Ingram said 92 per cent of respondents to the survey believed internet service providers should inform customers when they become aware a user's machine had been infected.

Sixty-one per cent favoured the ISP restricting their internet access to a "walled garden" of safe websites, until the computer was fixed.

People are desperate for help, Mr Ingram said. "I was surprised at the level of support for getting ISPs involved in trying to help customers fix their machines, and it would appear there are a lot of machines to be fixed."

The flood of malware (malicious programs spread by software viruses, worms and Trojans) seems unstoppable.

Internet security research group Shadowserver monitors the lag between the release of malware, the time antivirus vendors develop a patch and when users upload it. On average, almost 40 per cent of malware in circulation on a given day cannot be detected by existing products.

Shadowserver estimated it obtains about 10,000 new malware samples on the web each day.
Many of these are downloaders, designed to compromise computers then fetch other malware to perform specific functions, such as capturing bank account details.

This had contributed to massive growth in fraud.

Last year,card-not-present fraud (involving online, phone or mail transactions) on locally issued credit cards reached $53.5 million, up from $32 million the previous year, according to the Australian Payments Clearing Association. As well, millions of dollars flowed out to advance-fee fraud every month, despite warnings about email scams, Queensland Detective Superintendent Brian Hay said.

Advance-fee fraud had its roots in the old Nigerian letters/faxes/emails scam, but perpetrators today are just as likely to be in Tokyo, London or Amsterdam.

In a further refinement, people are being individually targeted -- online dating sites, Facebook and professional networking sites such as LinkedIn provide vast volumes of personal information that allows criminals to tailor their approach.

Mr Hay said the "romance hook" was a very potent and particularly nasty trick.
"Romance victims have been set up to cash fake cheques, transfer illegally obtained property and even transport heroin into Australia, usually under the guise of doing a favour for a friend," he said. "Many victims only not lose their savings and belongings, but they are shocked and traumatised."

Mr Hay said criminals got greater returns on targeted attacks and were prepared to play a patient game.

"If you send out 10,000 spam emails, you will get a small response and it takes time to work that up," he said.

"But when you've got a person's complete profile on the internet, and their likes and dislikes, it's easy to create a story that dovetails straight into that.

"Having said that, some relationships have been online for six months before the sting is launched, so they're extremely patient as well."

Scott Charney, head of Microsoft's Trustworthy Computing program, was among speakers at last month's AusCERT conference who warned that it was time to rethink IT security. "We have a huge problem with identity theft, and it's growing," he said.

"I'm not just talking about credit card fraud, but where people get pieces of information and then convince a bank they are really you, and take out a line of credit.

"Things like that are really hard to unravel, and the internet in part makes it possible, because so much personally identifiable information is available online."

Mr Charney proposed a new trust model, based on credentials issued to authenticate individuals in specified online situations.

"The model we use today is completely broken," he said. "We use shared secrets, which aren't secret at all.

"It's not always about proof of identity, it's often proof of something about you. I can choose which proof to present. If it's a financial transaction, I use my bank proof. When I'm getting on an airline, I use my government proof," he said.

Karen Dearne

Friday, June 6, 2008

A victim of Online Fraud - BBC.co.uk - 05 Jun 2008

George Nicolas was the victim of an online fraud scam run partly by Nigerians in London and lost 15,000 euros.

interview can be viewed at http://news.bbc.co.uk/1/hi/uk/7436556.stm

Thursday, June 5, 2008

Police net more than 20 online fraudsters - couriermail.com.au - 06 Jun 2008

MORE than 20 online auction fraudsters have been caught by Queensland police, including one man who sold non-existent holidays to about 3000 victims.
Police Minister Judy Spence revealed a joint operation between Queensland police and auction site eBay unearthed 23 Queensland-based "recidivist offenders", accused of repeatedly failing to deliver advertised auction items to buyers.

Some have been arrested, with one Queensland man charged with 48 offences and another with 33 offences.

Under the initiative aimed at improving the investigation of online fraud, Queensland police - with the help of eBay - last year launched a central website for complaints relating to fraud at online auction sites.

The website enabled police to resolve minor disputes quickly and more easily target repeat offenders."

In the past if a consumer had a complaint when an item they purchased on a site like eBay didn't arrive, or was not what was listed, they often made their complaint straight to their local police," Ms Spence told State Parliament.

"In many cases, police found that if the consumer had contacted their online auction site or the seller directly instead, their complaint could easily have been handled without police involvement.

"While in the past there was no simple process for police to link complaints and offences across jurisdictions, our officers are now able to quickly identify the recidivist offenders who are taking advantage of multiple buyers.

"Since the system went live in May last year, 416 matters have been reported on the site and investigated.

While most related to Queensland-based offenders, a Victorian man is also under investigation after he allegedly conned more than 3000 victims into purchasing non-existent holidays.Ms Spence said it was estimated the website had saved police from spending 30,000 hours filling out reports.

Rosemary Odgers

Tuesday, June 3, 2008

Beauty contest winner becomes latest victim of online phishing fraudsters, Sophos reports - sophos.com 02 Jun 2008

Miss Scarborough has £10,000 stolen from her bank account by phishers

IT security and control firm Sophos is reminding computer users about the risks of identity theft and online fraud following news that Jade Saunders, the current beauty contest winner in the British seaside town of Scarborough, has fallen foul of an email phishing scam.

The twenty year old student, who was crowned Miss Scarborough in April this year and who is also a semi-finalist for Miss England 2008, had clicked on a link in an email purporting to be from her bank which took her to a genuine looking website. By entering her details on this convincing fake site, designed to con trusting web users into entering their account information, Jade was providing devious cybercriminals with all they needed to set up a standing order on her account for £10,000 (approximately US $20,000).

Sophos experts remind computer users that they should never respond to emails that request personal financial information and check that the websites they are visiting are secure.
"Although these phishing attacks are nothing new, sadly Miss Scarborough is unlikely to be alone in her misfortune," said Graham Cluley, senior technology consultant for Sophos. "According to the Anti-Phishing Working Group, phishers are able to convince up to five per cent of recipients to reply to the kind of email sent to Jade, but this needn't be the case if simple habits are learnt. Reputable companies don't ask their customers for passwords or account details in email, so even if you think a message from your bank may be legitimate, don't follow any links, instead visit your bank's website by typing its address into your web browser."
Read additional tips on how to prevent falling victim to online banking fraud
Listen to a Sophos podcast - "Phishing: Are the banks to blame?"

"Businesses need to be on their guard against phishing attacks too," continued Cluley. "It's important that companies have properly defended their staff against attacks which can aim to steal corporate information as well as personal data."

Sophos recommends that all computer users ensure their computer security is up to date and that they are fully protected against the latest spam, email and web threats.

Sunday, June 1, 2008

Online fraud: Duped of Rs 20 lakh, she tries same on others - ExpressIndia - 31 May 2008

Pune, May 30 The city police on Friday arrested 52-year-old Flora Akkavan of Dhanlaxmi society in Dhanori who duped two persons of Rs 5 lakh. She claimed the crime was committed to make good about Rs 20 lakh she lost to a group of online fraudsters based outside India who promised to make her richer by $ 10 million (about Rs four crore) in double quick time.

The police have seized 30 bundles of ‘black-and-green paper’ having size similar to that of a 100-dollar note and a diplomat’s bag that Flora had got from the fraudsters. Each bundle carries a label — United States of America $ 50,000.

Police Inspector Bhanupratap Barge of crime branch who busted the racket said that the fraud had its roots in Nigeria and Thailand.

Barge said that Flora claimed she had received a fraudulent email sometime prior to April 2007 saying that former Philippines President Asteda wanted to secretly transfer $ 120 million to a bank account in USA and assured to pay her $ 10 million.

Flora said she got another email asking her to pay $ 8,000 (about Rs 4.5 lakh) for opening an account in Crew Bank in USA. She was then told that $ 120 million had been transferred to her Crew Bank account. A few days later, she got an email that $ 110 million had been transferred to Asteda’s account while the remaining $ 10 million was being given to her as promised.

Flora was again asked to pay $ 8000 for transferring the money from USA to India via Thailand. Flora gave this money to a foreigner at Hotel Ambassador in Mumbai. Then in November 2007, she was called to Delhi to collect her kickback money of $ 10 million.

She got the parcel containing a diplomat’s box with bundles of green and black paper. The foreign national who gave the parcel said that these were US dollars coated with green and black colour and demonstrated how the currency could regain its original shape by washing away the coating on the notes with a chemical.

The fraudster said they would send the chemical to her soon and left. Police said that Flora spent about Rs 20 lakh in the process but never got the chemical. Still hopeful of getting her money, she approached Pradeep Baldev Rajput (22), a real estate agent in Wadgaon Sheri.

Flora told him that she has sold three software packages in USA for Rs 17 crore and that the money has already landed in India via ‘a secret channel’ route. She also took Rajput to a cyber café to show the demonstration of notes are converted to dollars by washing with a chemical on a website - doilrich007.

Flora said a Swiss Bank manager would be coming to India with the chemical and lured Rajput to invest Rs 50,000 for purchasing the chemical, saying he would be paid back Rs 2.5 lakh in one month. Later, she managed to extract Rs 1 lakh from Rajput and about Rs 3.5 lakh from his friend Anil Vasant Upshant with the same promise.

As months passed, Rajput realised that Flora was cheating him and his friend and lodged a complaint with the crime branch. A team led by inspector Barge arrested Flora and the case has been transferred to Vishrantwadi police station for investigations.

The police have recovered an Iranian passport from Flora as she was married to an Iranian national. While the foreigners who cheated Flora remain unidentified, police suspect that she has cheated more persons like Rajput.

Thursday, May 29, 2008

Be wary of money scams - The Daily Triplicate - 28 May 2008

The FBI recently took down a "phishing" scam based in Romania that spanned three continents and five countries—38 people ended up being arrested.

Unfortunately, that is one of hundreds of scams that ropes around the globe. Recently, a family placed a classified ad in The Daily Triplicate for dogs for sale.

An out-of-towner using an AT&T "relay system" for the hearing or speech impaired called the family. The caller supposedly wanted to send money to pay for at least one of the dogs and for shipping. The local family received a check and deposited it, then sent off some of that money as part of the transaction, only to find that the original check had bounced.

The Triplicate has no knowledge of this happening to other local residents.

Be skeptical about these orders when the person wants to use multiple sets of credit cards or wants to send more money than necessary for any number of reasons. AT&T also suggests merchants request a U.S. telephone number and U.S. contact information for all orders.

The Internet and e-mail has opened up countless scams and most of them have the same purpose: to take someone else's money.

There's even a jury duty scam. "Court employees" call up saying you've been selected for jury duty and want to verify social security and credit card numbers. The courts never require this for jury duty, even if they threaten you with fines.

The Nigerian letter scam usually involves some ousted government officials or princes who need to send you all of their money while they secretly escape the country. To help this person you will need to send your bank account information.

The advance fee scam usually involves you winning some large amount of money for no reason, but you have to send a small fee in order to receive it. Do not respond to this letter; instead, forward the information to the FBI. No one wants to give you money, they only want to take your money.

If you don't know the person or company sending you the letter or e-mail, trash it. Look over business agreements carefully, be wary of businesses that operate out of post office boxes or people who never seem to be in when you call.

Pyramid schemes can seem like a legitimate business deal. You invest money into a franchise and then make money by getting two more people to sign up and so on. Be wary of any investment that requires you to bring in more investors to profit from your investment. These schemes always collapse.

Secret or mystery shopper job ads frequently are fraudulent. This happened to a local resident who responded to an ad in The Triplicate last year. It's usually a fake company sending a check that you deposit before wiring a lesser amount out of the country. The bank usually comes looking for you when it becomes apparent the original check was a fake.

Many times addresses and phone numbers are hidden clues in any e-mails or paperwork potential scammers send. Area codes or zip codes will be off by a number—a quick fact-check on the Internet will lead you to a dead end.

Things that seem strange or out of the ordinary—someone who promises lots of money, people who are pressuring you to sign something or have you send money oversees—are all red flags for scams. The bottom line is to be skeptical. Protect your money.


Reach Kelley Atherton at katherton@triplicate.com

Wednesday, May 28, 2008

Online auction or mail fraud scheme in the Valley? - abc15.com - 27 May 2008

Jeanine Raab spent a lot of time online last year searching eBay.com for an old magazine. She was looking for anything to do with the 1950s. Raab wanted Life magazines from that time and found four for $67 on the site from a seller called 'Apropos Auctions.' It read check or money order only.

After Raab put the check in the mail, weeks passed and she saw nothing. The seller said the merchandise was in the mail, but the magazines never arrived.Benjamin Anderson is the man who owns Apropos Auctions.

The ABC15 Investigators uncovered a federal search warrant through the U.S. Postal Inspector’s office. It lists about 225 complaints against Anderson and his company. They're investigating him for mail fraud and money laundering.Dan Schultz of Tempe tried to buy a vintage Life magazine from Apropos Auctions.

When his merchandise didn’t arrive, he phoned the company. Schultz said the voicemail identified himself as Colby Farnan at Apropos Auctions. And when he searched for Colby Farnan online what he discovered disgusted him. “Colby Farnan memorial is on a web site called Fallen Heroes Memorial,” he said. The site was made to honor Pfc. Colby Farnan who was killed by an explosive device in Iraq. “It just stuck in my craw that he was doing this to these young men who had served in Iraq and who died,” said Schultz.
We found similar complaints online in other cases when Anderson used names of fallen soldiers as sellers.Neighbors said Anderson moved out of his California home but it will be hard to know if he's still in business, online and using yet another name.

To protect yourself, use an online payment service. In most cases, the seller doesn't get the money until you get the item.
Reported by: Joe Ducey

Tuesday, May 27, 2008

Online job seeker says she was duped into scam -


Woman facing jail time after responding to classified ad

Bobbie Jean thought she had finally found work when she answered an online classified ad last fall for an overseas firm. Instead, within weeks of her hiring, she was arrested at her local bank, charged with a felony, and is currently facing an August trial date in a Harris County, Texas court. Bobbie Jean now says she was tricked into helping an international fraud ring to move stolen money out of the country.

Fraudulent ads on online job sites are not new. But expert Pam Dixon, who has studied the phenomenon, says this is the first case she's heard of where the alleged victim was actually arrested as an accomplice to a crime. Dixon operates WorldPrivacyForum.org.

The 51-year-old Bobbie Jean, who requested through her attorney that her last name not be published, is a former accountant who had been unemployed for several months when she responded to an ad on CareerBuilder.com. When she was hired, she was told to collect payments from clients in the United States and wire the money to London. But the ad, like the firm, was a con.

The other part of the scam took place on eBay, where the same con artists put up a motorcycle for sale, according to Bobbie Jean's attorney, Jeffrey Goldstein. The motorcycle was sold to a Florida resident for $9,000, and he shipped the money to Bobbie Jean in Texas. But there was no motorcycle -- the con artists were just using Bobbie Jean as a domestic address, so as not to raise the suspicion of the eBay buyer.

According to Goldstein, when Bobbie Jean showed up at her local bank to wire the money to London, she was arrested and later charged with a single felony. According to the complaint filed against her, she is charged with taking more than $1,500 and less than $20,000 from the Florida eBay buyer.

Goldstein says Bobbie Jean is an innocent victim, but local authorities so far don't see it that way.
Prosecutor Joe Vinas did not return phone calls placed to his office by MSNBC.com.
"A person got duped who couldn't find employment," Goldstein says. “"(Prosecutors) did not buy that she was [a victim of] some kind of criminal conspiracy ... but she has no criminal background."

Ads keep popping upOnline job sites like Monster.com, CareerBuilder.com, and Yahoo.com's HotJobs expend a lot of energy trying to beat back illegitimate ads; some post warnings on virtually every page of their site and on every e-mail they send.

Still, con artists have seized on the willing, and often, vulnerable populations that frequent job sites to mine for fresh victims. For years, hundreds of thousands of dollars worth of merchandise have been moved out of the country by U.S. residents who fall for fake "postal forwarding" jobs, says U.S. Postal Inspector Barry Mew. Working as some kind of finance manager, accepting checks and other payments and transferring funds overseas, is just the latest incarnation of the scam, Dixon says.

All the sites say they take steps to verify job posters, and quickly remove fraudulent ads. CareerBuilder, for example, says it has a dedicated team of quality control specialists who monitor job postings.

But that's not enough, Dixon says, because the fraudulent ads keep re-appearing on various job sites. The ad Bobbie Jean answered, for example, first appeared in August, and is still popping up on job sites all over the Internet. And there have been at least a dozen other victims.

Dixon says a man in Dallas, Texas, lost his job at a bank after responding to the same job posting. Four other victims had money stolen out of their personal bank accounts when the con artists simply stole their identities after convincing them to divulge their account numbers.


The advertisements vary slightly; in one version, the company name is listed as Macrocommerce Intersales. In another, UMAB. In still another, UNK Electronics


Dixon says the patterns of job postings show a highly organized effort to perpetuate the scam. In a study released last week, she traced the job listing as it appeared in over 100 Internet locations. The first appearance was apparently last July, at PickAJob.


Later, it appeared on Careerspan.com in Dallas, New York, and Sacramento. It then systematically appeared all over the country -- from Miami to Seattle. Despite the slight variations, Dixon was critical of the various job sites' inability to keep the ads off their services.
"Job sites have to provide a way job seekers can make a real accurate determination about how safe the site is how can job seeker make a decision about how good the process is," she says.


"This job ad has really been collecting victims left and right."

CareerBuilder spokeswoman Jennifer Sullivan says the firm is willing to help Bobbie Jean's attorney clear her name, and has complied with requests to compile information about the incident.

"This is an issue we take very seriously, and we're giving our full attention to the issues involved," she says.But in the meantime, Bobbie Jean is still unemployed, and facing even more challenging prospects than ever.

"She has a pending felony theft case, who's going to hire (her)?" Goldstein, her attorney, says. "She lost her house now because she couldn't make payments. She is living with family. ... You have to wonder what are the duties of the job sites in terms of policing their own ads."


By Bob Sullivan
Technology correspondent

Saturday, May 24, 2008

People's Bank customers at risk from data breach - theday.com - 22 May 2008

Several hundred thousand People's United Bank customers in Connecticut have been hit by a data breach that potentially exposed their personal information, state Attorney General Richard Blumenthal said Wednesday.

Blumenthal said The Bank of New York Mellon lost an unencrypted backup tape provided by Bridgeport-based People's Bank, resulting in the data breach involving about 4.5 million accounts. The tape included bank account information, Social Security numbers and other data about depositors and investors tied to the bank, he said.

This security breach seems highly dangerous, indeed possibly devastating in light of the identity theft threat,” Blumenthal said in a statement. People's Bank has 10 locations in southeastern Connecticut, including five at local Stop & Shops. The bank has more than 150 locations throughout the state.

A People's Bank spokesman denied any knowledge of the data breach Wednesday afternoon before the official announcement at a Hartford press conference. He and a spokesman for Bank of New York Mellon could not be reached after the announcement.

Blumenthal was particularly concerned with the amount of time that elapsed between the discovery of the data breach and the reporting of it. Bank of New York lost the information in February but didn't start informing consumers until six weeks ago, he said.
Blumenthal first heard about the breach earlier this week, he said

Blumenthal said the Bank of New York Mellon on Feb. 27 gave an unencrypted backup tape as well as nine other tapes to a storage firm, Archive Systems Inc. of Fairfield, N.J., which was assigned to store the information. But when a storage company vehicle arrived at the storage facility, one of the tapes could not be found.

According to a letter from Blumenthal to the Bank of New York, a lock on the truck was broken, and the truck had been left unattended several times.
”The loss of this tape - so far unrecovered and unremedied - is inexplicable and unacceptable,” Blumenthal said. “It must be addressed by protective measures to forestall identity theft immediately.”

The banks are cooperating with Blumenthal's office to determine exactly how many Connecticut residents are affected by the breach.

Blumenthal, in a letter dated Wednesday, asked the Bank of New York to respond to a series of questions about the data breach. He requested detailed information about what was lost and how the bank has notified consumers about the loss. He also asked the bank to detail other instances in which it had lost back-up tapes.

This is not the first time that loss of personal information has affected People's Bank customers.
He termed as inadequate the Bank of New York's offer to pay customers for one year of credit monitoring. He said two years of monitoring and $25,000 in identity theft insurance as well as free credit freezes would be more appropriate.

In January 2006, the company revealed that a computer tape with information about 90,000 customers had been lost in transit by United Parcel Service. The tape was bound for TransUnion, a credit-reporting bureau in Woodlyn, Pa.

The state itself was hit by a data breach last year when a laptop containing information about more than 100,000 taxpayers was stolen. Other breaches last year with strong local ties included more than 54,000 records released during a series of lapses at Pfizer Inc. as well as another incident affecting 2,000 patients at The Westerly Hospital.

But none of these breaches comes close to a record for the release of personal information. That dubious distinction belongs to TJX Co., parent firm of T.J. Maxx and other retailers, which had more than 94 million credit- and debit-card numbers stolen by a hacker last year.

Other major breaches have involved Visa, MasterCard and American Express, which released data on 40 million customers in June 2005; Citigroup, 30 million just a few days earlier; America Online, 30 million in June 2004; the U.S. Department of Veterans Affairs, 26.5 million in May 2006; and HM Revenue & Customs, 20 million in November 2007.

After a previous breach last year, Blumenthal sued a company for negligence, unauthorized use of state property and breach of contract in connection with data involving 58 taxpayers, hundreds of state bank accounts and other information. The company, Accenture, said its procedures were not followed because of human error.

Last year, fewer data breaches were reported in the United States than in the year before, but the lapses were more severe. While 346 incidents were reported two years ago resulting in about 50 million record breaches, last year's totals were 310 incidents and a whopping 162 million exposures, according to the Privacy Rights Clearinghouse.

Five of the top 10 data breaches of all time occurred last year.

Before the People's Bank incident, the two biggest data breaches of the year involved the University of Miami in Florida, with the records of 2.1 million people released; and Hannaford Bros. Supermarket chain in Portland, Maine, 4.2 million.

l.howard@theday.com

Hannford Data Breach: TD BankNorth Cards Compromised - bankinfosecurity.com 23 May 2008

NH Customers Notified; New Cards Issued

New Hampshire customers of TD BankNorth were notified earlier this week that their Visa debit or credit cards have been compromised, and the likeliest culprit is the recent Hannaford Brothers Supermarkets security breach.

"We became aware during the last few days that there was some fraudulent activity on some of our customer's credit card accounts," says Jennifer Carlson, TD BankNorth's spokesperson. "It was limited to New Hampshire. As far as the New Hampshire customers, they have been contacted and their accounts have been closed and new cards reissued." Carlson says the bank's privacy policy prevents the bank from giving out how many customers were involved.

Cards of the affected customers are being replaced as soon as fraud is detected. Instead of having a mass cancellation and reissuing its Visa debit and credit cards, the bank is relying on fraud-detection computer programs, which it says can monitor for fraud, and even decline transactions as they are being made.

Another bank, Citizens Bank, also located in the Northeast, took the immediate step after the breach to announce it was reissuing all credit cards of customers that had shopped at Hannaford, regardless whether they might have been involved in the breach.

In March, Hannaford announced that a security breach had compromised more than 4 million customer card numbers. (See related stories: Hannaford Data Breach: An Inside Job?; Hannaford Data Breach May be 'Tip of the Iceberg')

Carlson notes that the Hannaford breach isn't the only event that triggers fraud. "Fraudulent transactions happen every day, not just as a result of breaches," she says. "We encourage all of our customers to be vigilant in protecting their personal and financial information at all times."

Customers are also advised to review their bank statements online or when they arrive in the mail for any suspect transactions. "And always call the number on the back of the credit card when there is a problem with the card," she says.

Credit card fraud just got bigger and worse! - Rupee Times - 23 May 2008

Keeping a credit card just got a bit more expensive! Stealing and using a credit card are passé. In today’s world, hackers are working overtime to find out new innovative ways to make new money, and going by the look of things, they are gaining a sizeable lead in this domain! From skimming and cloning your credit card, to making fake sites; from using stolen cards on them to using new online trading models, the cyber thieves are on prowl to hack into your bank account.
Now, it’s no longer safe to trust a restaurant employee or petrol pump attendant with your credit or debit card. Many cases of multiple cards being ‘skimmed’ and ‘cloned’ are being reported to the police and bank authorities, and many of them are originating when a customer is least expecting it! So next time, think twice about giving your credit card in a restaurant or in a petrol pump! Card thieves are using magnetic stripe readers and encoders which are easily available in the market for $250-$600.

While a card reader can read the data on the magnetic band of your credit or debit card, an encoder can encode it on to any plastic card with a magnetic band, even a normal hotel room key.

Rajat Khare, who is the founder director of network security management company, Appin, said, "All credit cards can be cloned by simply inscribing cards with a similar magnetic band just like a hotel number is fed into a magnetic room key. These kinds of card frauds are becoming common."

Banks are trying to fight this menace, by advising customers to subscribe to mobile alerts. ICICI Bank card products head Sachin Khandelwal said, “We have a 45% market share with about 8.5 million credit cards in the market. The percentage of card frauds is low at about 4 basis points of all transactions. Nevertheless, we shoot an SMS alert for every transaction above Rs 2,000 to all our customers. Skimming of credit cards is generally done when a customer places a mail or phone order transaction.”

However, certain banks, like HDFC, do not stop at mobile alerts. In additions to the alerts, the bank also provides an extra security layer for all credit and debit card customers. Through this facility, the cardholder can create his own additional password, which provides an additional security layer for all On-line transactions, said HDFC Bank credit card marketing head Parag Rao.

If you have just received a new credit card from the bank, but discover that it already has a charge attached on it, don’t be surprised. These days credit fraud happens even before a new card has been received from the bank. Credit card number generators are freely available online (on sites like http://www.brothersoft.com) which claim to generate card numbers of various companies starting from ‘5’ (Master Card) or ‘4’ (Visa) or other digits. It also generates 13, 16, 18 or 19 digit card numbers. These generators use the same algorithms like `Luhn formula’ used by government agencies and banks to generate numbers.

“In one case, a hacker managed to crack the algorithm of a bank’s credit card generator and sold hundreds of numbers online. So even before the fresh card came into customer’s hands, they already had a charge on them. In another case, a credit card hacker set up a site and started using stolen card numbers to provide downloadable images and managed to siphon off about $2 million,” adds Mr Khare.

However, the biggest wrath of the credit card fraud can be felt in the E-commerce portals, which have also become like trading havens for hackers. This is how it works: A hacker enters the stolen card number and CVV (card verification value) number, as mentioned on the reverse of the card, into an e-commerce site and buys a product. The payment is made but the buyer doesn’t take the delivery immediately. He gives the delivery date – of generally a week to 10 days. During this time, the hacker posts his costly buys (from the stolen card) on the portal for sale obviously for an even lower price. As the hacker gets a customer for his product, offered at a jaw dropping price, he gives the customer’s address as the delivery address, on the same or other portal.

He receives cash from the final customer in an electronic cash account or an escrow account from where he converts it into hard cash. Escrow is a legal arrangement in which an asset (such as cash, real property or other tangible assets) is deposited into safekeeping (e.g. a bank account) under the trust of a neutral third party (escrow agent) pending satisfaction of contractual contingency or condition. Once the condition has been met, the escrow agent will deliver the asset to the party prescribed by the contract.

Thus during the entire transaction the hacker can manage to cruise through without leaving a trace. Says IT risk and consulting firm Mahindra Special Services Group Captain, Raghu Raman, “Most hackers try and steal small amounts–just 2-3% of a monthly transaction to avoid getting caught. In large transactions, the banks usually call and ask the customer immediately to cross check whether a transaction was done by him. Hackers are also using card numbers to get a subscription or download a costly software which they in turn sell it online.” Thus, this makes it difficult to catch them also.

However, all is not lost for the credit card customers. There are certain precautions which one can adopt so as to be on the safe side. Net security experts have warned that web transactions with credit cards are no longer 100% safe. They suggest the use of credit cards only on sites which are ‘Https’ (Hypertext Transfer Protocol over Secure Socket Layer) and direct the transaction webpage to a payment gateway. Deleting cookies and browsing history from your computer after a transaction might also help prevent the cyber thief stealing your card number.

By Ankit Sharma

Wednesday, May 21, 2008

Counterfeit credit cards main source of cyber crime - Daily Times - 21 May 2008

LAHORE: Counterfeit credit cards, allegedly smuggled from China, are the main source of cyber crime across the country, as it is the easiest way to swindle banks and financial institutions, said a Federal Investigation Agency (FIA) official on Tuesday.Card skimming, the electronic theft of information from the magnetic strips of credit cards, is the fastest-growing scam in Pakistan and now represents 60 percent of all credit-card frauds, he said on the condition of anonymity.

“Criminals have also started producing counterfeit credit cards that are barely detectible or differentiable from the original cards,” he said. Highly sophisticated portable machines are freely available in Pakistan, which are capable of producing ‘genuine’ cards with ‘original’ holograms and imprinted signature strips, he said.

He said that most of the gang leaders were highly qualified and live in posh areas. “They are specially interested in foreign banks, especially those of Italy, South Africa, Singapore, Thailand, Malaysia and England, because of a higher credit limit as compared to local banks,” he said.

According to the FIA officials, the cyber crime unit (CCU) registered 15 cases and arrested 24 people in 2007, out of which 12 cases were related to credit cards fraud.

“The cyber crime unit registered 14 cases this year, out of which six cases were of credit card fraud, two were related to online banking and three involved software hacking,” he said. CCU Deputy Director Azhar Mehmood said that criminals often used Chinese-made white plastic cards with electro-magnetic chips.

He said that the unit helped banks recover millions of rupees since its establishment in 2005. He claimed that the unit has helped various banks recover Rs 20 million the past year-and-a-half.

“The criminals have a special liking for petrol pumps, as they purchase oil with counterfeit credit cards to sell on the open market,” he said, adding that some petrol pump cashiers were also involved in the business. “Traders have now started informing on the criminals after being warned against becoming accomplices in the crime,” he said. He said that the general public was not aware of such crimes and usually became an easy prey. “A campaign has been launched to educate them about cyber crimes,” he added.

By Shafiq Sharif