Thursday, September 4, 2008

[Fraud Series: Topic 4] Fraudsters are no longer showing site loyalty

I’ve been analyzing the online behavior patterns of criminals for about 4 years now. When I first started, the criminals were clearly “specialists” targeting a particular vertical market with their organized crime operations, e.g., online gaming, Internet dating, eCommerce, or financial institutions. They would craft their schemes to specifically exploit a victim Web site until they got caught. Then, they would simply shift their focus over to the next Web site with similar vulnerabilities in that same vertical market.

However, more recently I’ve been noticing fraud rings crossing over vertical markets and perpetrating their crimes/scams simultaneously upon multiple Web sites. I’ve seen, for example, criminals who have been committing Internet dating scams now moving into other vertical markets like eCommerce. In one case, a fraudster was buying “items” at an online jewelry site using a stolen credit card. Simultaneously, he/she was creating accounts on an Internet dating site, paying for their subscription using a stolen credit card.

Conclusively, fraudsters are “diversifying” their operations and committing various forms of fraud across a spectrum of vertical markets in order to increase their return on investment. However, I do still see the “old school” fraudsters sticking it out within the same vertical and focusing their efforts to try and overcome deployed fraud prevention tools within that vertical market.

My advice is simply this: don’t limit yourself to fraud strategies specific to one vertical market. The most effective fraud strategies today are the ones that leverage fraud intelligence collected from across the Internet, not just a subset community.

Thursday, May 22, 2008

[Fraud Series: Topic 3] Credit Card Phone Scam

This isn’t an online fraud, per se, but since both ANI/MIN/CLID spoofing and credit card frauds are current topics of discussion, I thought you’d find this interesting (if only for your own personal protection). The following is an example of both a credit card scams to collect from me all of my key credit card information so the criminal could use my card to purchase stuff online, via ANI/MIN/CLID spoofing (making the caller-ID be some other number) .

I just received a phone call on my cell phone (from a Voice Response Unit-VRU) with a caller-ID number of 321-504-7429. The recorded message said…

“This is your final notice to lower the interest rates on your credit card…blah blah blah…please select 1 to lower your rates now…blah blah blah”. I hung up, as should you!

Notes/Warning Signs:

  1. There was no indication for which bank it was calling me (I actually have 3 credit cards from 3 different banks).
  2. There was no authentication for who the credit card actually belongs to e.g. they might have said my name so I know it’s me their looking for.
  3. They called my work cell phone, which was likely taken off my business card picked up from one of our show booth tables. I NEVER use my business cell phone for credit card accounts.
  4. After I hung up I dialed the number back, and as expected it said, “The number you are trying to reach has been disconnected and is no longer in service.”

Thursday, February 7, 2008

[Fraud Series: Topic 2] Stolen Credit Cards

There isn’t much I can add to the discussion on the topic of criminals using stolen credit cards to make purchases online. I could talk about various methods used to catch them. However, this week what I thought would be interesting is to comment on the relationship developing between “Easy Identity Theft” and the fraudulent usage of credit cards.

Like many Americans, I used to think that the only way a criminal could use someone’s credit was to steal the plastic card, or at minimum steal the numbers and CVV off of it, to make fraudulent purchases. But now, as I discussed last week, I know that this is not the only use case. In fact, more and more people are starting to fall prey to criminals acquiring their personal information and then applying for credit cards on their behalf. In this scenario, the victim may or may not receive the invoice for the credit card. If they do, they are left with protesting and deactivating this account, if not it could go completely undetected and have lasting consequences.

This is one of the most common uses of identity theft and potentially has the most adverse impact, because unlike a fraudulent charge to your credit card, which most often is credited back to your account, a fraudulent credit application may go undetected and can negatively impact your credit rating for years.

Next blog [Fraud Series: Topic 3] Advanced Fee Frauds

Tuesday, January 8, 2008

[Fraud Series: Topic 1] Easy Identity Theft

I used to think it was very difficult to steal "good" identity information. But after a little research, I have learned it's really very easy!

CASE 1: Criminals simply drive into any community that re-cycles and pick up the bags left at curbside. This is nice, clean, paper (no smelly garbage mixed in it). The criminals instantly get the "victims" address (it's on the envelopes) , and all they need to do now is search through the papers for names, telephone numbers, bank account #'s, social security #'s...you name it, it's in there!

CASE 2: Criminals go to any domain name registrar (like www.godaddy.com) and purchase a seemingly legitimate URL, something like "www.californiarefinance.org". And if they're not a programmer, then they'll simply go visit an existing bank's web-sites and copy their pages. Using a tool like Adobe's DreamWeaver they can quickly build a "fake" web-site for their fake business. Now they're ready to apply at a search engine, pay top dollar for the best home mortgage refinance search terms, such as:"refinance", "mortgages" etc. to link to their new domain name. Finally, real victims come willingly to visit their web-site. The victim enters page after page of personally identifiable information, which is then immediately stored in a database. The victim might be told they will receive an email notification regarding the status of their application (but they either never get the email, or the email simply says, "I'm sorry, your application has been declined."). Either way, the criminal now has the victims very good identity info.

In both of the above cases, the criminal can use your information and apply directly online for credit cards, on your behalf.

Next week's [Fraud Series: Topic 2] Stolen Credit Cards.

Friday, December 28, 2007

Goodbye 2007...Hello 2008

Over the holiday break, I found myself repeatedly explaining to both friends and family the difference between identity based fraud management tools and device-reputation based fraud management tools (I know, I know...who'd have thought this could be a "hit" ice-breaking topic at a holiday party?). But when people ask me, "so, what do you do?", and I say, "I stop identity theft and stolen credit cards." They immediately want to know, how can they protect themselves, including my father-in-law?

My father-in-law uses a MAC and I use a Windows tablet PC. As I stood there this morning looking down at our respective machines, I suddenly realized that after 20 years of having a relationship with him either one of us could positively identify the other one out on any street corner. But then I suddenly felt a growing sense of vulnerability; only 2-mouse clicks away (out in the virtual internet world) either one of us could so easily become the other one and nobody would be the wiser! We each know enough about the other, or have easy access to the personal documents (like wallets, drivers licenses, passports etc.), that the only thing standing in the way of such a crime, and is protected us one from the other, is the combination of personal ethics and mutual "trust".

But as I recall looking around the living room of various holiday parties this year, I suddenly realize that there were many people there neither my wife nor I even knew. Meanwhile, our coats and her purse lie in wait, amidst a mountain of other coasts and purses pilled high onto our hosts bed. I know I trust my close friends and family, but what about all these other people, the ones we are calling friends of friends of friends? How protected am I, online ??

Thursday, November 15, 2007

ItsMyMarket.com (UK) WARNS about Scams

While I've been holding off posting my own list of common frauds, mainly because I haven't decided how to best organize them in a blog, here are some links to other fraud lists....enjoy!

http://www.itsmymarket.com/scams/common.php
(UPDATED) http://www.lookstoogoodtobetrue.com/fraud.aspx

Friday, November 9, 2007

iovation - Intel Capital - TheFraudKahuna

Yesterday, iovation (Portland, OR - U.S.A.) announced that they have partnered with Intel Capital, who has made an initial $10M investment in the company's fraud management solution.

iovation IS NOT simply a "device printing" company, rather, it uses "device recognition" as one of many design components within their Device Reputation Authority.

Beyond fraud management, iovation's manypending patents are designed to protect its IP (intellectual property) in and around what they call "Device Reputation". In today's vernacular, "device" = "PC", or PDA, or mobile phone, or Xbox, can be virtually anything which is used to access the internet. Eventually, when IPv6 becomes more universally deployed, a device will likely refer to anything with built in electronics, such as, automobiles, televisions, even refrigerators. The reputation of a device is not only us asking the question, "has this PC been used to commit online fraud?" But is also us asking the question, "has this PC been used for email spamming, chat abuse, and other sorts of unwanted online behaviors?"

NEWS LINKS
http://www.bizjournals.com/portland/stories/2007/11/05/daily21.html
http://home.businesswire.com/portal/site/home/index.jsp?epi_menuItemID=887566059a3aedb6efaaa9e27a808a0c&ndmViewId=news_view&ndmConfigId=1000017&newsId=20071108005370&newsLang=en
http://www.redherring.com/Home/23128
http://news.google.com/news/url?sa=t&ct=us/0-0&fp=4734e0a5f545a105&ei=ljw0R9PLDZveqwPcsNTrAQ&url=http%3A//www.redherring.com/Home/23128&cid=1123328964&sig2=rCRFk67zoOzDmtFFXKZgVQ