Tuesday, January 8, 2008

[Fraud Series: Topic 1] Easy Identity Theft

I used to think it was very difficult to steal "good" identity information. But after a little research, I have learned it's really very easy!

CASE 1: Criminals simply drive into any community that re-cycles and pick up the bags left at curbside. This is nice, clean, paper (no smelly garbage mixed in it). The criminals instantly get the "victims" address (it's on the envelopes) , and all they need to do now is search through the papers for names, telephone numbers, bank account #'s, social security #'s...you name it, it's in there!

CASE 2: Criminals go to any domain name registrar (like www.godaddy.com) and purchase a seemingly legitimate URL, something like "www.californiarefinance.org". And if they're not a programmer, then they'll simply go visit an existing bank's web-sites and copy their pages. Using a tool like Adobe's DreamWeaver they can quickly build a "fake" web-site for their fake business. Now they're ready to apply at a search engine, pay top dollar for the best home mortgage refinance search terms, such as:"refinance", "mortgages" etc. to link to their new domain name. Finally, real victims come willingly to visit their web-site. The victim enters page after page of personally identifiable information, which is then immediately stored in a database. The victim might be told they will receive an email notification regarding the status of their application (but they either never get the email, or the email simply says, "I'm sorry, your application has been declined."). Either way, the criminal now has the victims very good identity info.

In both of the above cases, the criminal can use your information and apply directly online for credit cards, on your behalf.

Next week's [Fraud Series: Topic 2] Stolen Credit Cards.

Friday, December 28, 2007

Goodbye 2007...Hello 2008

Over the holiday break, I found myself repeatedly explaining to both friends and family the difference between identity based fraud management tools and device-reputation based fraud management tools (I know, I know...who'd have thought this could be a "hit" ice-breaking topic at a holiday party?). But when people ask me, "so, what do you do?", and I say, "I stop identity theft and stolen credit cards." They immediately want to know, how can they protect themselves, including my father-in-law?

My father-in-law uses a MAC and I use a Windows tablet PC. As I stood there this morning looking down at our respective machines, I suddenly realized that after 20 years of having a relationship with him either one of us could positively identify the other one out on any street corner. But then I suddenly felt a growing sense of vulnerability; only 2-mouse clicks away (out in the virtual internet world) either one of us could so easily become the other one and nobody would be the wiser! We each know enough about the other, or have easy access to the personal documents (like wallets, drivers licenses, passports etc.), that the only thing standing in the way of such a crime, and is protected us one from the other, is the combination of personal ethics and mutual "trust".

But as I recall looking around the living room of various holiday parties this year, I suddenly realize that there were many people there neither my wife nor I even knew. Meanwhile, our coats and her purse lie in wait, amidst a mountain of other coasts and purses pilled high onto our hosts bed. I know I trust my close friends and family, but what about all these other people, the ones we are calling friends of friends of friends? How protected am I, online ??

Thursday, November 15, 2007

ItsMyMarket.com (UK) WARNS about Scams

While I've been holding off posting my own list of common frauds, mainly because I haven't decided how to best organize them in a blog, here are some links to other fraud lists....enjoy!

http://www.itsmymarket.com/scams/common.php
(UPDATED) http://www.lookstoogoodtobetrue.com/fraud.aspx

Friday, November 9, 2007

iovation - Intel Capital - TheFraudKahuna

Yesterday, iovation (Portland, OR - U.S.A.) announced that they have partnered with Intel Capital, who has made an initial $10M investment in the company's fraud management solution.

iovation IS NOT simply a "device printing" company, rather, it uses "device recognition" as one of many design components within their Device Reputation Authority.

Beyond fraud management, iovation's manypending patents are designed to protect its IP (intellectual property) in and around what they call "Device Reputation". In today's vernacular, "device" = "PC", or PDA, or mobile phone, or Xbox, can be virtually anything which is used to access the internet. Eventually, when IPv6 becomes more universally deployed, a device will likely refer to anything with built in electronics, such as, automobiles, televisions, even refrigerators. The reputation of a device is not only us asking the question, "has this PC been used to commit online fraud?" But is also us asking the question, "has this PC been used for email spamming, chat abuse, and other sorts of unwanted online behaviors?"

NEWS LINKS
http://www.bizjournals.com/portland/stories/2007/11/05/daily21.html
http://home.businesswire.com/portal/site/home/index.jsp?epi_menuItemID=887566059a3aedb6efaaa9e27a808a0c&ndmViewId=news_view&ndmConfigId=1000017&newsId=20071108005370&newsLang=en
http://www.redherring.com/Home/23128
http://news.google.com/news/url?sa=t&ct=us/0-0&fp=4734e0a5f545a105&ei=ljw0R9PLDZveqwPcsNTrAQ&url=http%3A//www.redherring.com/Home/23128&cid=1123328964&sig2=rCRFk67zoOzDmtFFXKZgVQ

Wednesday, October 31, 2007

NCFTA...more help is on it's way!!!

I recently visited the guys at NCFTA. Check out their web-site at www.ncfta.net. This is a new organization focused on the exchange of intelligence data. I fully support their charter. In their own words...

The National Cyber-Forensics and Training Alliance provides a neutral collaborative venue where critical confidential information about cyber incidents can be shared discreetly, and where resources can be shared among industry, academia and law enforcement.

The Alliance facilitates advanced training, promotes security awareness to reduce cyber-vulnerability, and conducts forensic and predictive analysis and lab simulations.

Thursday, October 11, 2007

Do you know where your PC has been?

I was looking at a device the other day (PC) in our database. It had been flagged with repeat counts of identity theft in 1 particular vertical market. I then looked at the other markets this PC has visited. What I found interesting was this: although they have been repeatedly flagged for identity theft in the target market, but at the same time, they have been flagged with no fraudulent activity in any other markets; they appear to be "good" citizens in other community while a "bad egg" in the other.

Has anyone else seen this sort of profile by fraudsters?

Monday, July 23, 2007

Fraud does not discriminate

This past week I investigated two extreme cases finding that the same fraudsters (fraud ring) had quickly hit multiple web-sites crossing multiple vertical markets. For example, they hit hard and broad across multiple iDating sites, and then, jumped over into the online purchase space at some of the largest online merchants. This same group was also caught frequenting online poker sites.