Thursday, July 17, 2008
Russian Coreflood Gang targets online bank accounts - news.yahoo.com - 16 Jul 2008
Once inside, it infects every PC within reach with a custom-made data-stealing program called Coreflood. The goal: go rip off bank accounts online.
Over the past 16 months, the Coreflood Gang has infected swaths of PCs inside thousands of companies, hospitals, universities and government agencies, says SecureWorks researcher Joe Stewart, who has tracked and documented the spread of Coreflood over that period.
"It's spying on you, capturing your log-ons, user names, passwords, bank balances, contents of your e-mail," Stewart says. "It can capture anything."
Coreflood is part of a class of malicious software, called banking trojans, designed primarily to help crooks break into bank accounts online. The number of banking trojans detected on the Internet this month topped 24,800, up from 3,342 at the start of 2006, security firm F-Secure says.
An infection usually starts when you visit a Web page implanted with a snippet of malicious coding. By simply navigating to the tainted page, your browser gets redirected, unseen, to a hub server that downloads the data-stealing program onto your hard drive.
Dozens of gangs specialize in banking trojans. They have it much easier than phishing scammers, who must lure victims into typing sensitive data on spoofed Web pages, says F-Secure researcher Patrik Runald.
"This is very organized crime," Runald says. "These gangs are hiring people and making tons of money."
The Coreflood Gang is among the most sophisticated. Stewart recently analyzed 500 gigabytes of stolen data stored on a rented hub server. He pinpointed 378,758 Coreflood infections inside thousands of organizations, small and large.
A workplace PC can get a new infection each time someone logs on. The most infections: a county school district with 31,425, a hotel chain with 14,093 and a health care company with 6,744. About 230 networks turned up with 50 or more Coreflood infections, while 35 networks each had 500 or more.
Gang members cull the stolen data for log-ons and account statements, especially bank accounts online with high balances. Next, they log into the accounts and make online cash transfers into "drop" accounts they control.
After having two hub servers shut down by the tech security community in May, the Coreflood Gang rented two new hubs and picked up where they left off. Today, they continue operations unimpeded, says Stewart.
Companies infiltrated by the Coreflood Gang need to rethink how they do network security. Employees surfing the Internet on work PCs ought to take pause. "If you don't understand the threats that are out there, then you probably should not be banking online," Stewart says.
By Byron Acohido, USA TODAY
A Monster Phishing Scam - news.digitaltrends.com - 16 Jul 2008
Almost a year ago hackers stole the details of 1.3 million users from Monster.com. Even more recently a group used an identity harvesting tool to extract information from resumes posted on Monster and other job sites.
Now a security analyst a McAfee, Greg day, has issued a warning of a new phishing attack at Monster.com that targets both recruiters and those looking for jobs, according to Vnunet.
Day said:
"Scammers are trying more and more diverse and sophisticated techniques to obtain information that can be of financial reward.
"With concerns about potential job cutbacks, many people are looking to the internet to find potential employment opportunities and see what's available to provide some reassurance in the current climate.
"Unfortunately, scammers are getting wise to this as we have seen with a recent influx of phishing attacks looking to steal personal details by gaining access to online job hunting profiles or tempting victims with information of potential jobs."
The sam involves e-mails purportedly from Monster.com sent to users, urging them to click on a link to update their profiles. McAfee has traced the attack back to a Turkish botnet, but said that if they’re able to obtain plenty of resumes, the potential for ID theft is large.
Saturday, July 12, 2008
Stimulus Checks Are Bait Used By E-Mail 'Phishing' Scammers - tmcnet.com - 12 Jul 2008
Almost 700 such scam attempts were reported in May and June, bringing the tally for 2008 to about 1,600.
Victims of these fraud attempts -- which are called "phishing" scams -- received official-looking e-mails purporting to be from the IRS and requesting personal information to expedite the receipt of their checks.
With an address and Social Security number in hand, a scammer then can open fraudulent credit card accounts or take out false loans, damaging the victim's credit rating.
"Generally you can look at them and find grammar errors and punctuation errors, and they're not professional," said IRS spokeswoman Gloria Sutton.
"If you receive an unsolicited e-mail purporting to be from the IRS, don't open it. We do not send unsolicited e-mails. The IRS would have no reason to ask for your PIN number or bank account."
The IRS asks that anyone who receives a phishing e-mail forward it to so the agency can trace the scam's origins.
Between 2006, when the agency opened the account, and November, the Treasury Inspector General of Tax Administration had identified host sites in at least 27 countries in addition to the United States.
The economic stimulus fraud isn't the first time scammers have taken advantage of current events to steal cash or identities, said Sally Hurme, senior project manager with AARP financial security in Washington.
Natural disasters such as Hurricane Katrina have been used to drum up donations for nonexistent charities.
"The key about any scam is that the scamsters like to follow the news," Hurme said.
"Even before the president signed the bill, the IRS reported that there were phishing schemes popping up."
In other scams reported this year, victims have received e-mails appearing to be from the IRS and offering tax refunds in exchange for personal information.
Sometimes scammers also will send e-mails with phony links, which install malicious code on the victim's computers.
Sunday, July 6, 2008
Credit CardRacket Busted - Times of India - 03 Jul 2008
The crime branch stepped up action on receiving a complaint from a bank that a fake credit card is being used for purchase at a South Extension market. They later apprehended the suspects on Tuesday.
Interrogation of the accused revealed that they had been using fake credit cards to do shopping in Delhi. A S Cheema, DCP, (crime and railways), informed that, "the accused had procured the cards from a friend in Nigeria. A laptop and seven mobile phones were seized from them. The laptop contained data of about 200 international credit cards."
The police also seized three mobile phones which the accused had purchased using the fake credit cards. One of the mobiles had details of six credit cards in it. A police remand has been sought for further investigation.
Those arrested have been identified as Abayomi Anifowoshe (30), Evans Amathila Imadonmwinyi (32) and Bawwa (29). Police said Abayomi arrived in India in June 2008 in Mumbai for medical treatment of his wife who is yet to come to India.
He stayed in Mumbai with a friend for a week before coming to Delhi. He had been sharing a room with co-accused Bawwa at Arjun Nagar. Evans had been renting a place near Safadarjung airport. He came to India last year on a tourist visa. The third accused, Bawwa, came to India in March this year for a kidney surgery at Batra Hospital. "The three accused met through their contacts and received details of the credit cards through their contacts in Delhi," said a senior police officer.
Monday, June 23, 2008
Photobucket’s DNS records hijacked by Turkish hacking group - ZDnet.com
Third-party site monitoring services indicate that the site was down for 15 minutes yesterday, from from 17:39:39 to 17:55:10, whereas according to a comment left by a Photobucket Forum Support representative, the downtime due to the propagation of the corrected DNS entries was longer :
“On Tuesday afternoon, some users that typed in the Photobucket.com URL were temporarily redirected to an incorrect page due to an error in our DNS hosting services. The error was fixed within an hour of its discovery, but due to the nature of the problem, some users will not have access to Photobucket for a few hours as the fix rolls out. It is important to note that only a portion of Photobucket users encountered the problem and that no Photobucket content, password information or other personal information was affected by the redirect.”
The hacking group appears to have been using the hosting services of atspace.com, the web hosting service of Zetta hosting solutions, and users of Photobucket attempting to access the site with the old DNS entries are still being redirected to a default hosting ad page within atspace.com. The effect of the redirection can also be seen by taking a peek at the publicly obtainable stats for atspace.com, where the sudden peak in traffic resulting in 118,864 visitors for today came from the default ad page used in the redirection.
With the second DNS hijacking attack against a high-profile domain in the recent months, it seems that adaptive malicious parties unable to directly compromise a site will continue taking advantage of good old-fashioned DNS hijacking. At least to prove that it’s still possible even on a high-profile domain using the services of a Tier 1 domain registrar.
By Dancho Danchev
Saturday, June 14, 2008
'Phishing' Attackers Hit Teachers Credit Union - redorbit.com - 12 Jun 2008
Jun. 12--Dear Action Line: I received an e-mail message, apparently from Tulsa Teachers Credit Union, that my account had been "compromised" by hackers and shut down by the credit union. It asked me to call a North Carolina (704) number to provide my TTCU routing and account numbers so the credit union could reactivate my account. I've been calling the credit union for three days to ask about this but can't get past the busy signals. I'm sure this is a hoax, but do I need to check on this in person? -- S.J., Broken Arrow.
This monumental "phishing" attack, out of Davidson, N.C., on Tulsa Teachers Credit Union customers started a week ago and reached the crisis level Wednesday when all 40 of the system's telephone customer assistance personnel were busy answering panic calls. Also, the lobbies of all credit union facilities were packed with customers on foot asking the same question: "Is my money in trouble?" It's not.
The attack was unique in that it was three-pronged: it involved not only e-mail phishing attacks but also text-messaging attacks to people's unpublished cell phone numbers and "vishing" attacks -- live people voice-fishing over the phone asking people for their credit union account numbers.
At 9:47 a.m. Wednesday, the Tulsa Better Business Bureau issued a "scam alert" to all media outlets in which Rick Brinkley, bureau president and CEO, stated, "Within the last 30 minutes, the BBB serving Eastern Oklahoma is being inundated with consumer calls regarding a text message and/or e-mail stating that the consumer's account with Tulsa Teacher's Credit Union has been closed and the consumer is directed to call a 704 area code number (Davidson, N.C.). A recording then directs the consumer to enter a credit card number. The BBB has tracked the telephone number and is continuing to investigate."
Kristi Brooks Cohea, vice president of marketing for Tulsa Teachers Credit Union, said the attacks affected "less than 20" credit union members, and that only a few of them actually provided the requested account numbers. Those accounts were closed and new ones were opened for the customers.
However, the BBB's phones became jammed around 9 a.m. Wednesday, primarily because text message fraud is so new -- unlike e-mail scams -- that many users went on the alert.
"This was a massive attack," Brinkley said. "We know of five carriers it went out over -- including AT&T, T-Mobile, US Cellular and Sprint -- and I think there were thousands of these text messages that went out. Members and nonmembers alike began calling the credit union about this text message, and it backed up our phone system."
The attack was eased, Brinkley said, when the credit union's Internet protection company -- Tacoma, Wash.-based Internet Identity -- placed a warning message on the 704 phone number stating, "The scam phone number is now answered by a recording telling callers the phone line was originally set up by criminals."
This was not a universal-numerical attack.
"There's no way we can even try to guess how they came up with the database they used," Cohea said. "We know of several large companies in town that have many people in their organization that have received these text messages over unlisted corporate phones. Most of these text messages went out to cell phones and these are not listed anywhere."
By Phil Mulkins
Friday, June 13, 2008
Phishing-Related Schemes Grow in Sophistication - itbusinessedge.com - 13 Jun 2008
Though it shares most of the name, spear phishing and a third variant, whaling, are significantly different than traditional phishing. The older (can it be called “old school?”) phishing involves sending out thousands or even millions of generic e-mails in hopes of fooling a small percentage of people. Spear phishing and whaling take the opposite approach: The criminals research the victims and include enough information to make the e-mails appear legitimate.
The definitions are a bit unsettled, but spear phishing is discreet from whaling. Spear phishing blankets a group of people with something in common, such as employees of a particular company or people who work in a specific industry. Whaling aims for top executives, often by name and with specific information that suggests the messages’ authenticity. All these definitions are amorphous and flexible, however.
iDefense, according to this PC World story, has tracked 66 spear phishing attacks since February 2007 and believes that 95 percent were the product of two groups. The attacks stole data from an estimated 15,000 people during that time. An iDefense spokesman said the groups were perfecting their methods, with the most successful of the attacks launched in April.
The National Post from Canada provides a couple of examples of such exploits. One was launched against thousands of corporate executives who received e-mails that purported to be subpoenas from the U.S. District Court in San Diego. Each named the recipient and demanded that he or she appear in front of a grand jury in a civil case. At some key point in the presentation, the target had to click on a link – which downloaded a Trojan horse into his or her machine. The writer also said that the spear phishers recently have targeted about 90 university systems.
Indeed, academia seems to be magnet for cyber criminals. This Daily Bruin piece provides background on a series of spear phishing attacks against UCLA. The school’s director of IT security said that the initial attack occurred around the winter break and are increasing every month. An initial warning at Bruin OnLine, which contained an option to change passwords, itself looked like a phishing attempt and was abandoned.
There is a lot an organization can do to fight various forms of phishing. Information Security Short Takes offers several preventative steps: use e-mail digital signatures; educate assistants, advisors and executives; train personnel on what to look for; run social engineering penetration tests; and provide fall back security measures.
The key issue is less confusing than the overlapping names: There is no shortage of bad people online trying to get information that will enable them to do things that they shouldn’t be able to, and that undoubtedly will hurt people and the companies for which they work. The first step in combating phishing, spear phishing, whaling or any other aquatic-0sounding exploit is to train employees to exercise caution.
By Carl Weinschenk
Wednesday, June 11, 2008
Major Security Vendors' Sites Could Be Launchpads for Phishing Attacks - .darkreading.com - 10 Jun 2008
Not so, according to a report issued yesterday by a security watchdog site. The site, XSSed, states that it has verified some 30 cross-site scripting vulnerabilities spread across the Websites of three of the industry's best-known security vendors: McAfee, Symantec, and VeriSign. The vulnerabilities could make it possible for attackers to launch phishing campaigns from these sites or even distribute malware to the companies' customers, according to XSSed.
By Tim Wilson
Recent studies have shown that Web-based attacks are increasingly being launched from trusted, legitimate sites, rather than from hastily created sites and servers built by the attackers. By exploiting vulnerabilities in legitimate sites, the attacker gains credibility for phishing or malware links and bypass security tools that blacklist known phishing sites. (See 68% of Malware Now Found on Legitimate Sites and 'Hack-and-Pier' Phishing on the Rise.)
The new XSSed report shows that the big security vendors' sites are no exception to this trend, said Kevin Fernandez, one of the founders of XSSed. "It shows that any company can be infected with XSS," he says. In fact, some attackers have specifically targeted their vulnerability searches on sites such as McAfee, Symantec, and VeriSign, looking on them as a particular challenge, Fernandez says.
"It is unfortunate that many Websites tend to suffer from relatively simple vulnerabilities. It’s worse, though, that the same security vendors who preach security are the ones who often need just as much help as everyone else," says Robert Hansen (aka RSnake), CEO of SecTheory, a security consulting firm. "It just lends credence to the belief that knowledge of the problems doesn’t make you immune to them, which is why education doesn’t appear to be working."
This isn't the first time that XSS vulnerabilities have been exposed on sites such as McAfee's and Symantec's, notes Jeremiah Grossman, CTO of WhiteHat Security. Back in January, XSSed reported that some 60 sites that had received the "hacker safe" label from McAfee's ScanAlert service were vulnerable to XSS attacks. (See Many 'Hacker Safe' Websites Found Vulnerable.)
At the time, Joseph Pierini, director of enterprise services for the ScanAlert "Hacker Safe" program, maintained that XSS vulnerabilities couldn't be used to hack a server. "You may be able to do other things with it," he said. "You may be able to do things that affect the end-user or the client. But the customer data protected with the server, in the database, is not going to be compromised by a cross-site scripting attack, not directly."
"XSS vulnerabilities do present a serious risk; however to date their real-world use has been limited," said Oliver Friedrichs, director of Symantec Security Response, following the XSSed report in January. "XSS vulnerabilities can result in the theft of session cookies, Web site login credentials, and exploitation of trust. XSS vulnerabilities are site-specific, and therefore their lifecycle is limited; they become extinct once they are discovered and repaired by the Website owners."
But both Fernandez and Grossman noted that there have been a number of recent attacks that exploited XSS vulnerabilities in major Websites, including MySpace, Paypal, and major Italian banks.
"Should we be worried? About XSS, yes, but not because these particular security vendors have XSS on their Websites," Grossman says. "Symantec and McAfee really don't specialize in Web application security -- they focus more attention on anti-virus and anti-malware.
"The main worry should be around the more popular and e-commerce driven Websites, like banks, credit unions, social networks, and storefronts," Grossman says. "That is where businesses and users have the most to lose -- and where the real bad guys are focusing their attention."
Monday, June 9, 2008
Nigerian held for Internet fraud - IndianExpress - Chandigarh - 08 Jun 2008
Chandigarh, June 08 CYBERCRIME CATCH: Gang operates from UK or Nigeria, says Crime Branch
“Congratulations! You have won the UK National Lottery worth one million pounds.”
Anybody will be excited to receive such an alluring e-mail and won’t mind paying £7,000 to 8,000 for receiving the huge sum of money.
This was the ploy used by Bright, a Nigerian national, the alleged kingpin of an overseas gang that cheats people through the Internet. The gang is suspected to be operating from the UK or Nigeria and has members in Punjab and other parts of India.
The Crime Branch of the Chandigarh Police arrested the 25-year-old Nigerian from the city railway station on Saturday where he had come to hand over the “prize” to one Balbir Singh, a local resident.
Bright is doing software engineering from Delhi, officers said.
Booked on charges of cheating, under Section 420 of the Indian Penal Code (IPC) and Section 14 of the Foreigner Act, he has been remanded in police custody till June 10.
The Crime Branch swung into action after it received a complaint from one Balbir Singh, a resident of Mohali, who was duped of around Rs 2 lakh.
Balbir had received an e-mail that said he had been selected as the lucky recipient of the £1 million UK National Lottery. “Balbir received the mail on May 9. He walked into the trap and ended up paying Rs 1.81 lakh,” said DSP (Crime Branch) K I P Singh.
Balbir would receive e-mails asking him to deposit money on account of courier charges, identification certificate, VAT etc in two international accounts of ICICI and Axis banks. “When I last received a call, demanding a payment of Rs 56,000 on account of government tax clearance charges, I got suspicious and approached the Crime Branch,” he said.
Balbir was advised to ask the caller to come and meet him personally. “We asked Balbir to tell them he cannot further deposit any money in the bank as he was left only with black money. We advised him to ask the caller to come to India and hand over the parcel. They refused initially, but later told Balbir to come to Delhi, to which he refused and it was finally decided that an agent will come to Chanidgarh,” said the DSP.
Accordingly, Bright came to Chandigarh and was arrested. A mobile phone was recovered from his possession. “We have found out that he was in touch with nearly 20 to 25 people from whom he was to receive money,” said K I P Singh.
The e-mails sent by the gang bore a corporate look, with warnings and notes advising the recipients not to get fooled, the police said.
The Crime Branch is yet to find out whether this gang operates from the UK or Nigeria, though the officers confirmed that the gang comprises members operating in Nigeria and India, particularly New Delhi.
The Chandigarh Police will write to the Nigerian government and the Ministry of Home Affairs soon to find out the details about other people involved.
The Central Bank of Nigeria has recently posted a message on its official website warning people not to fall in such traps.
How they trap you
* You will receive an alluring e-mail informing you that you have been randomly chosen for a huge cash prize
* If you respond, the gang will contact you through e-mails and telephone calls, demanding your identity proof, bank account number and other certificates to earn your confidence
* They will start demanding money on pretexts of airport clearance, VAT, courier charges, etc
* Within hours of your depositing the money in the specified international bank account, it is withdrawn
* You will receive a big parcel containing a box full of useless papers
Thursday, June 5, 2008
Phishers Targeting Your Tax Dollars - redmondmag.com - 03 Jun 2008
E-mails, phone text messages and so-called "vishing" voice-mail messages ask recipients to confirm or update EPPICard account data, directing them to a phony Web site. Once the scammers have gathered the account information, they can drain money from the benefits account.
"They are apparently targeting government payments" such as food stamps and child support payments, said Marc Salomon, a researcher at Cloudmark, an anti-spam company in San Francisco that noticed the attacks earlier this month. "It is the taxpayer who is footing the bill," he said, because the compromised accounts are held by states, not financial institutions.
EPPICard is a magnetic-stripe debit card branded by MasterCard or Visa to access benefits accounts. The cards are used by Florida, Georgia, Illinois, Indiana, Mississippi, Nevada, New Jersey, New York, North Carolina, Ohio, Oklahoma, Pennsylvania, Texas, Utah and Virginia.
Each state uses the card to deliver the types of benefits payments it chooses. When a payment has been credited to the account, the holder uses the debit card for purchases and the payment is deducted from the account. Holders also can get cash back from a purchase and withdraw cash at banks and automated teller machines.
The e-mails apparently come from the address customeralert@eppicard.com and direct victims to a phony Web site. "They are hosted on servers around the world," Salomon added.
EPPICard has posted a warning on its Web site of phishing and vishing attacks. "We will never request your personal information, such as a Social Security number, card number or PIN through any of these methods," the company said.
Cloudmark has spotted about 20 of the phishing e-mails and said that number is probably just the tip of iceberg. There is no indication the e-mails are specifically targeting EPPICard users, said Adam O'Donnell, Cloudmark's director of emerging technology. But he said this type of attack against a niche target is likely to become more common as larger targets such as banks d services such as PayPal become over-phished.
by William Jackson
'Untraceable' phone fraudsters eye your credit card - theregister.co.uk - 03 Jun 2008
The calls begin with a recording that makes a tempting offer - usually for a lower credit-card interest rate or an extended car warranty - and then invite the caller to speak to a live agent. The agents then ask for information including the credit card number and expiration, name, address, and in some cases social security number and other data. Recipients who have fallen for the ploy report finding charges as high as $900 on their credit card.
Your reporter has received three such calls in as many weeks. After taking the bait for a lower interest rate, an agent named Donna said her company, amorphously called Financial Services, uses its clout to negotiate directly with the issuing bank to lower my rate. Eventually, she put a supervisor named Johnny Davis on the line to answer questions like where Financial Services was incorporated and whether it was a member of the Better Business Bureau.
His answer: "That has nothing to do with the purpose of the phone call. Are you interested in us negotiating your interest rates of your accounts?"
Obviously, Davis wasn't the least bit daunted by the questions and neither were any of his colleagues, judging from similar online accounts, in which recipients report getting an abrupt click when seeking such information. Other people report receiving the calls every day at 3 a.m.
The reason Johnny, Donna and the rest of the cabal can't be bothered with maintaining even the appearance of legitimacy is they know they are largely untraceable. The varying phone numbers that appear in recipients' caller id screens are spoofed. There is little that typical users can do to find the real origins of the call.
"I actually pursued it a little bit," said Dan Clements, head of credit card-monitoring service CardCops after he received a call. But because CardCops, a division of Affinion Security Center, is set up to focus on internet-based abuses, he took a pass on one based solely using phone lines. "I couldn't dig in on it," he said.
Identity theft investigators at Consumer's Union say they are unfamiliar with the scam. Officials from the California Attorney General's office the the Federal Trade Commission didn't return phone calls by time of publication.
That's left people to resort to alternate ways of handling the calls. One person, for instance, started Stopping Heather, a site named after the perky voiced operator whose recording graces the beginning of many calls. Participants are encouraged to log as much information about the calls they receive as possible, including spoofed numbers and the scripts of the scammers. Ad-hoc forums on sites such as 800Notes serve much the same purpose. Others report keeping a whistle or an air horn at the ready.
The surge of calls come as security researchers report an up-tick in so-called vishing attacks, which use VoIP, or voice over IP, to trick people into turning over banking credentials and other sensitive data. Last fall, more than 12,000 people in Texas were targeted in a scam that attempted to capture their account details for eTrade and two local banks, according to a recent report from iSIGHT Partners.
Vishers typically set up demo accounts with one of the many VoIP providers, carry out their attack and then move to another provider. The attacks observed in the report were different from the recent scam, however. They typically rely on emails that encourage recipients to call an automated number and manually enter their account information.
The use of live agents at a time when open-source public branch exchanges and similar gear makes number spoofing cheap and simple is a wrinkle that will take time for enforcers to crack down on.
By Dan Goodin in San Francisco
Tuesday, June 3, 2008
Beauty contest winner becomes latest victim of online phishing fraudsters, Sophos reports - sophos.com 02 Jun 2008
IT security and control firm Sophos is reminding computer users about the risks of identity theft and online fraud following news that Jade Saunders, the current beauty contest winner in the British seaside town of Scarborough, has fallen foul of an email phishing scam.
The twenty year old student, who was crowned Miss Scarborough in April this year and who is also a semi-finalist for Miss England 2008, had clicked on a link in an email purporting to be from her bank which took her to a genuine looking website. By entering her details on this convincing fake site, designed to con trusting web users into entering their account information, Jade was providing devious cybercriminals with all they needed to set up a standing order on her account for £10,000 (approximately US $20,000).
Sophos experts remind computer users that they should never respond to emails that request personal financial information and check that the websites they are visiting are secure.
"Although these phishing attacks are nothing new, sadly Miss Scarborough is unlikely to be alone in her misfortune," said Graham Cluley, senior technology consultant for Sophos. "According to the Anti-Phishing Working Group, phishers are able to convince up to five per cent of recipients to reply to the kind of email sent to Jade, but this needn't be the case if simple habits are learnt. Reputable companies don't ask their customers for passwords or account details in email, so even if you think a message from your bank may be legitimate, don't follow any links, instead visit your bank's website by typing its address into your web browser."
Read additional tips on how to prevent falling victim to online banking fraud
Listen to a Sophos podcast - "Phishing: Are the banks to blame?"
"Businesses need to be on their guard against phishing attacks too," continued Cluley. "It's important that companies have properly defended their staff against attacks which can aim to steal corporate information as well as personal data."
Sophos recommends that all computer users ensure their computer security is up to date and that they are fully protected against the latest spam, email and web threats.
Friday, May 30, 2008
Arco debit-card scams in San Jose, Los Altos linked to statewide ring - MercuryNews.com - 29 May 2008
A group of high-tech thieves who police believe stole bank card information from consumers at gas stations in South San Jose and Los Altos are likely the same group that has been targeting Arco stations statewide, the Mercury News has learned.
Los Altos detective Wes Beveridge, who has been involved with the case since thieves made off with about $100,000 from more than 80 customers at a Los Altos Arco station in March, said the group has also hit Arco stations in southern and central California.
"I've been in contact with five different agencies, including the FBI, to try to track the whereaabouts of these people," said Beveridge, who spoke with San Jose detectives about the case. "In each of these cases, the photos we have match the photos they have as well."
In each case, the victims used debit cards to buy gas at Arco stations, which only accepts debit cards. Thieves attached a card-reading device to the payment machine's keypad that allows them to steal bank card numbers and personal identification codes.
San Jose police first received reports of the thefts Monday night, when a San Jose couple realized three separate $500 withdrawals had been made during Memorial Day weekend. Police traced the thefts to the Arco gas station at 5755 Camden Avenue.
San Jose police say the number of victims is now approaching 80 and estimate the thieves have withdrawn $45,000 from Bay Area banks so far. San Jose police expect those numbers to grow-the skimming machines were in place for about one month - and investigators are still in the process of confirming dollar amounts.
"ATMs are a cash-only business," San Jose police detective Patrick Ward said. "They can get straight up cash, as opposed to buying" merchandise with a stolen credit card.
The practice of card "skimming" works like this: Thieves glue a card-reading device on the front of the Arco payment machine. The carefully positioned device can be difficult to detect.
"I defy anybody to tell me they would have noticed it," Beveridge said.
Every time a customer swipes a card, the skimming device transmits the information instantly to a computer nearby, or at other times, thieves come back and retrieve the tiny device.
Thieves then used cloned bank cards - any card with a magnetic strip, including already used gift cards will work - and go on a withdrawal spree.
In Los Altos, thieves made most of their withdrawals on a weekend, and spent a couple of weekdays in the area before moving on. In some cases, Beveridge said bank photos show thieves making five different transactions in a span of five minutes.
"They go where they know people aren't going to be around when they do remove funds," Beveridge said.
Beveridge has contacted the FBI in hopes of creating a task force aimed at catching the high-tech thieves.
"The more they do, the more likely they will screw up," Beveridge said. "The more crimes they commit, the more information we have and then the more likely we are to catch them and get a conviction."
In a separate case, more than 200 shoppers had their debit card information stolen after swiping their cards at a Lunardi's Supermarket in Los Gatos.
"You have very ingenious people who are doing these things because the rate of return is so high," Adam Levin, chairman of Identity Theft 911, an Arizona company that works with banks and institutions to resolve cases of identity theft, told the Mercury News earlier this month. "It happens all over the U.S., and it happens almost every day unfortunately."
By Mark GomezWednesday, May 28, 2008
Yahoo says companies 'phishing' - Desert News - 28 May 2008
Yahoo! Inc., the second-most-popular search engine, has accused unidentified companies of trying to trick Internet users into providing credit-card information and other personal data.
The company, based in Sunnyvale, Calif., filed a lawsuit in Manhattan federal court this month against at least 25 companies, accusing them of deceiving Internet users into believing they won a lottery or prize offered by Yahoo.
"This type of lottery scam is a hoax designed to trick unsuspecting e-mail users into revealing valuable personal data like passwords, credit card information, and social security numbers," Yahoo said in a statement Tuesday.
Yahoo delayed its annual meeting last week after billionaire Carl Icahn threatened to oust its directors for snubbing a $47.5 billion takeover offer from Microsoft Corp. The meeting, originally set for July 3, will now occur at the end of July.
More 'phishing' scams hit Hawaii e-mail - Pacific Business News - 27 May 2008
The warning comes after phishers last week tried to obtain information from Hawaii National Bank customers. And this week there are already phony e-mails circulating in Hawaii from Mainland banks, including Chase and Bank of America.
"One of our member banks got notice that again somebody was sending e-mails purporting to be this bank," said Gary Fujikawa, executive director for the banking association. "Fortunately, most people are smart enough not to respond."
He said statistics report anywhere from 1 percent to 3 percent [of Internet users] respond to fraudulent e-mails. "It's a numbers game," he said.
A recent report by the state's Anti-Phishing Working Group estimated that the Internet has more than 2,600 active phishing sites aimed at conning people into divulging sensitive financial information.
In a common type of phishing fraud, indidividuals receive e-mails disguised as authentic messages from their financial institution, right down to logos and slogans. The e-mails describe a situation requiring immediate attention and warns about account termination unless the e-mail recipients provide account information by clicking on a provided link. The information then goes to the con artist who sent the e-mail.
The bankers association advises consumers to:
* Never click on links in e-mails if there is a reason to believe it is fraudulent. The link may contain a virus.
* Not be intimidated by e-mails that warn of dire consequences for not following instructions
Alert your financial institution, place fraud alerts on your credit files and monitor your account statements closely if you are a victim of phishing.
In addition to Hawaii National Bank, the association comprises American Savings Bank, Bank of Hawaii, Bank of the Orient, Central Pacific Bank, First Hawaiian Bank, HomeStreet Bank, Ohana Pacific Bank, Pacific Rim Bank and Territorial Savings Bank.
Phishing scam targets ANZ users - smh.com.au - 27 May 2008
One scam email warns that the reader's internet banking account has been "suspended".
"Although we cannot disclose our investigative procedures that led to this conclusion, please know that we took this action in order to maintain the safety of your account," it reads.
The email provides a link to a false ANZ bank web page asking customers for their registration number, name, password, phone number and email address.
In a telling flaw, the hoax ANZ page also asks customers for their address and "zip code", an American term for postcode, but is sophisticated enough to automatically lead users to the real ANZ page.
An ANZ spokeswoman said the bank was aware of the scam and had received complaints.
"Under no circumstances should you click on the link, reply to the email or provide any of the requested details," she said.
"Always ensure that you only log on to ANZ internet banking by typing http://www.anz.com into the address bar, rather than following links to the ANZ website. Disregard any emails that advise otherwise."
A NSW Office of Fair Trading spokeswoman said the hoax email was an example of scammers "phishing" for information they could potentially use to access accounts and steal funds.
The spokeswoman said it was very difficult for authorities to track down such scammers.
"These emails can look legitimate, they are really hard to spot and these people are pretty good," the spokeswoman said.
"It is easy to panic when contacted by someone official, especially when money is involved."
She said consumers should only contact their bank through their official websites or on phone numbers obtained from the White Pages or a bank statement.
Daniel Emerson
Monday, May 26, 2008
Feds Warn of Fake Tax E-Mail - PCWbusiness center - 24 May 2008
"The e-mails are designed to look like a petition from the Tax Court and are fairly believable," said McAfee researcher Kevin McGhee in a notice posted to the company's Web site. "There's also a legitimate telephone number for the organization [and] the executive's name is listed as the respondent in a case versus the Commissioner of Internal Revenue."
McGhee included a screenshot of the e-mail received by a McAfee executive; the image showed the "From:" address as "ustaxcourt.org."
The legitimate U.S. Tax Court site -- "ustaxcourt.gov" -- also warned of the scam on its home page.
"The United States Tax Court has received many telephone calls regarding an e-mail which purports to originate from the Court being sent by a member of the Tax Court's practitioner bar," the warning said. This message is an example of 'Spear Phishing,' which is an e-mail spoofing attempt that targets a specific organization.
"The Tax Court is not disseminating any e-mail notice to anyone who currently has a case before this Court. If you receive an e-mail with a subject line that includes the text, 'Notice of Deficiency #' or 'US Tax Petition,' ignore/delete the e-mail and do not click any link within the e-mail message," the agency said.
Targeted identity theft attacks, which have been dubbed "spear phishing" by some, "whale phishing" by others, are not new; nor are attacks that pose as legal messages from courts or the Internal Revenue Service . But such attacks have picked up as of late. Last month, for example, several waves of messages masquerading as notices of federal lawsuits reached recipients.
When users click on the link embedded in the phishing message, they're directed to a fake Tax Court Web site, said another security researcher, where they're asked to upgrade their copy of Microsoft Corp.'s Internet Explorer browser. "By string manipulation, in this case, adding a dash to the actual domain name of the actual site, unknowing users are easily made to believe that the bogus site is legitimate, making them most likely to click on the link," said Jovi Umawing, a researcher with Trend Micro Inc. in a separate warning posted on Friday.
McGhee noted that clicking on the purported IE update link actually downloads and installs malware, including a behind-the-scenes keylogger that records usernames and passwords typed on the PC's keyboard, then transmits that information to the identity thief.
Gregg Keizer, Computerworld
Friday, May 23, 2008
Cyber-criminals turn to LinkedIn - www.vnunet.com - 22 May 2008
Scammers have turned to social networking site LinkedIn in a bid to bypass corporate spam filters, a security firm warned today.
A standard 419 scam was sent earlier this week via the LinkedIn website claiming to come from a 22 year-old woman living on the Ivory Coast who had inherited $6.5m from her father.
Part of the message reads: 'Before the death of my father on the 12th December 2007 ... he called me secretly to his bed side and told me that he kept a sum of $6.5m in a bank in Abidjan, Cote d'Ivoire.'He explained to me ... that I should seek for foreign partner in a country of my choice where I would transfer this money and use it for investment purpose.'
The message goes on to request bank account information, and implores the recipient and potential victim to reply to a Yahoo email address within seven days.
"419 scammers may be hoping that the typical professional on LinkedIn has more disposable income than the typical MySpace or Facebook user and is potentially a bigger catch," said Graham Cluley, senior technology consultant at Sophos.
"Web 2.0 sites like LinkedIn and Facebook give strangers the ability to contact you without the defensive umbrella of your corporate anti-spam filter.
"Computer users should be on their guard against any unsolicited email as it could be from a cyber-conman."
Written by Robert Jaques
Wednesday, May 21, 2008
New phishing scam targets Apple's iTunes users - www.macnn.com - 20 May 2008
There have, however, been previous reports of "bogus" electronic iTunes certificates, scams targeting .Mac users with an email saying that Apple purportedly was unable to process their most recent payment, and phishing scams targeting Apple users, but Apple has not setup a specific email for users to report the problem, but provides some (very basic) information on Identifying phishing emails.
Phishing scams often target banks, where personal information can be used to steal a victim's identity and even take money from their accounts; however, the new scam is a new twist on the usual phishing attack, said Andrew Lochart, an executive with e-mail security vendor Proofpoint Inc. "We've gotten used to seeing the usual companies and brands attacked," he said, "like PayPal, eBay and Citibank. But we've never seen Apple as the target.
"Lochart said the phishing campaign is likely being used because of its popularity and reach among users -- "that the bad guys see Apple's online presence as large enough to be a target." But he also noted that the demographics of iTunes users may also be part of the target.
"I wonder if the bad guys are thinking that [iTunes users] are younger than those for some of the other phished sites, like banks and eBay," he told the publication. "The way that teenagers and young adults use the Internet, they show a certain level of trust or openness when they post their name and age and school on MySpace."
Tuesday, May 20, 2008
Phishing ring busted - CNN.com/technology - 19 May 2008
The two related cases marked the latest example of what the Justice Department describes as a growing worldwide threat posed by organized crime.
"International organized crime poses a serious threat not only to the United States and Romania, but to all nations," Deputy Attorney General Mark R. Filip said in a statement from Bucharest, where he announced the charges. "Criminals who exploit the power and convenience of the Internet do not recognize national borders; therefore our efforts to prevent their attacks cannot end at our borders either."
The practice known as phishing typically involves sending fraudulent e-mails that include links directing recipients to fake Web sites where they are asked to input sensitive data.
Phishers may also include attachments that, when clicked, secretly install "spyware" that can capture personal information and send it to third parties over the Internet.
More than half of the people charged in Monday's cases are Romanian, although the alleged scam also operated from the United States, Canada, Portugal and Pakistan. The cases were linked by two Romanians who participated in both schemes, authorities said.
In Los Angeles, 33 people faced a 65 counts on a bevy of charges, including racketeering, bank fraud and identity theft. Prosecutors say phishers based in Romania snagged information about thousands of credit and debit card accounts and other personal data from people who answered spam e-mail.
The data were then sent to the U.S. and encoded on magnetic cards that could be used to withdraw money from bank accounts.
One encoder in the scam, identified only as Seuong Wook Lee, pleaded guilty last week in federal court in Los Angeles to racketeering conspiracy, bank fraud, access device fraud and unauthorized access of a protected computer.
Meanwhile, in Connecticut, seven Romanians allegedly spammed consumers with directions to visit a hacked-in Web site posing as at least a half-dozen legitimate bank sites, including Citibank, Wells Fargo and PayPal.
The seven Romanians -- including two also involved in the Los Angeles scheme -- were indicted in January in charges that were unsealed only last week. One of them, Ovidiu-Ionut Nicola-Roman, was arrested in Bulgaria last summer and extradited to the United States in November.