Slashdot Mirror


Scamming Spammer Hooks the Wrong Person

CrypticSpawn writes "Read on SecurityFocus, a 55 year old woman spammed an FBI computer crime agent. She got caught mailing off a credit card scam to AOL users." Her scam targeted AOL users with messages saying their credit cards were refused during the last billing cycle, and linked to a false billing center page which demanded private information.

31 of 408 comments (clear)

  1. How gullable can people be? by Quasar1999 · · Score: 4, Interesting

    Really... We have just charged your credit card for 19.95... if you want to cancel the transaction, enter your card number, full name, and expiry date below...

    With the same logic, phone someone up, and tell them that if they don't want to be 0wN3d, they should disable their firewall, and tell you their IP address...

    The darwin award exists for those who kill them selves in stupid ways... we need to invent an award for idiots that fall for obvious scams like this.

    --

    ---
    Programming is like sex... Make one mistake and support it the rest of your life.
    1. Re:How gullable can people be? by skinfitz · · Score: 4, Funny

      The darwin award exists for those who kill them selves in stupid ways... we need to invent an award for idiots that fall for obvious scams like this.

      There is - it's called "Manager".

    2. Re:How gullable can people be? by Anonymous Coward · · Score: 3, Insightful

      Part of the problem is that the people who DO know about the workings of these sorts of things don't educate others on the matter.

      Think about it, how many /.ers are frustrated with friends and family not understanding why they should patch regularly? Now, think of how many /.ers are completely ineffective at presenting a simple argument on an annonymous message board.

      The fact of the matter is, most of us geeks just aren't good communicators and teachers when it comes to people outside of the community. We assume that the person we're educating has a modicum of understanding from the get go. What we need are more geeks who can communicate and teach effectively to the entire populace and help get the word out about such things.

      Hell, if /. managed a series of funny and educational public service announcements, I'd be in seventh heaven.

  2. Spammers and law enforcement by ergo98 · · Score: 4, Insightful

    I suspect that a vast majority of spams hit a large number of law enforcement inboxes - it isn't like spammers are selectively making hand-crafted to lists. Of the spams I get (of which there has been a marked increase in the past month), a good percentage are illegal or gray-legal pennystock pump and dumps, PayPal imitators attempting to get your information, or our good Nigerian friends looking for some assistance in rescuing their money.

  3. FBI uses AOL by vspazv · · Score: 5, Funny

    I can't be the only one that finds it disturbing that the FBI uses AOL.

    1. Re:FBI uses AOL by yintercept · · Score: 5, Funny
      I can't be the only one that finds it disturbing that the FBI uses AOL.
      You mean you missed the Time/AOL/FBI merger?
    2. Re:FBI uses AOL by seriv · · Score: 3, Funny

      I am surprised the fbi is able to function in the computer world at all. Their internal search was really bad for so long, and the fact that an FBI agent uses AOL comes as no surprise.
      -Seriv

    3. Re:FBI uses AOL by MosesJones · · Score: 4, Funny

      They've given up on that name...

      Now they are going for

      "Investigation Time for America"

      --
      An Eye for an Eye will make the whole world blind - Gandhi
    4. Re:FBI uses AOL by Daniel+Dvorkin · · Score: 4, Funny

      "You've got a subpoena!"

      --
      The correlation between ignorance of statistics and using "correlation is not causation" as an argument is close to 1.
  4. bigger catch than just that by ethelred · · Score: 5, Insightful

    An electronic trail of stolen AOL accounts and free Web pages led agents to raid the homes of a professional spammer and a credit card thief, both of whom snitched on Carr, naming her as the ringleader of the operation

    She isn't the only one going down. But, sadly, there are still many more to go...

    --

    Remember: If you buy anything from spammers, you have a small penis.
  5. People aren't what you'd expect by Rosco+P.+Coltrane · · Score: 3, Insightful

    a 55 year old woman spammed an FBI computer crime agent. She got caught mailing off a credit card scam to AOL users.

    What this story teaches us:

    - Little middle-aged (well, quite ripe already) ladies are not to be trusted

    - AOL users are idiots, since they are prime targets of even little middle-aged lady spamsters

    - FBI agents too open AOL accounts, which is worrying in a sense

    --
    "A door is what a dog is perpetually on the wrong side of" - Ogden Nash
  6. No wonder! by l3prador · · Score: 4, Funny

    No wonder I get so many email offers for Viagra and low-cost prescription drugs!

  7. Earthlink users are getting similar spam by Cujo · · Score: 3, Informative

    I've had about 2 e-mails a day of this ilk with respect to my Earthlink account for at least 3 months. A similar scam is in work with respect to Paypal. You don't need to be a total dunce to fall for this, either. Just naive and not savvy with raw e-mail source.

    --

    Helium balloons want to be free.

  8. Hooks the wrong person? by Zuke8675309 · · Score: 5, Insightful

    The article makes it sound like she wouldn't have got caught if an FBI agent hadn't been a recepient of the email. I hope this isn't the case and that the FBI is taking a more pro-active attack on this kind of thing than what the article seems to say.

  9. Geez... by Cytlid · · Score: 5, Interesting

    ... sounds like she got off a lot easier than those caught sharing music via p2p programs. Either the FBI should hire the MPAA or anyone swapping music online should start credit card fraud, it sounds like the lesser offense.

    --
    FLR
  10. See for your selves by littleRedFriend · · Score: 5, Informative

    AOL Billing center sample page.

    --
    IANAL, but imagine a beowulf cluster of in Soviet Russia all your belong are base to us welcoming the new SCO overlords.
  11. apathy in law enforcement by SuperBanana · · Score: 4, Interesting

    Danger Will Robinson, Danger! Rant Ahead!

    Read on SecurityFocus, a 55 year old woman spammed an FBI computer crime agent.

    Great. So what about:

    • the thousands of people getting ripped off daily on eBay
    • the DDoS's against blackhole list services
    • the thousands of script kiddies running loose

    ...? It seems like every day I'm reading about how some guy got screwed over and the FBI/SP/Local cops just didn't give a shit enough to do anything about it, whether it was technology related or otherwise, because it wasn't sexy enough. Crime is crime is crime.

    Case and point, you can pretty much scam anyone outside of your state and get away with it because interstate fraud laws have a $5,000 'ground floor'. That single law is probably the most responsible for the prolific fraud we've ever seen, virtual or otherwise. I could loose $4900 tomorrow and the FBI won't do jack shit. Some FBI nerd gets a scam email any moron would know not to answer, and they call out the swat teams. Faaaaantastic.

    It's like the local cops who don't give a shit if your laptop, your radio, etc were stolen and hundreds of dollars in damage done to your car. But, mind you, they've got all day to sit out on 'speed patrol'...

  12. Logic 101... by MosesJones · · Score: 5, Insightful


    Actually what it teaches us is

    - Criminals don't wear stripes and sound like Cagney

    - For any scam the best approach is to target the largest user group... more people means more idiots

    - The FBI staff use personal email

    This is exactly what you should expect, the FBI aren't a mixed race of mutant beings, and large crimes can be commited by pretty much anyone.

    --
    An Eye for an Eye will make the whole world blind - Gandhi
  13. There are so many... by MisanthropicProggram · · Score: 5, Informative
    Let's see:

    I once received an email with a link that said that I needed to "update" my eBay account with a new: credit card #, my SSN, DOB. The funny thing is I never had an eBay account - ever.

    I was at a hotel in Houston one time and I wanted to use my calling card to call home. After following the directions listed on the phone a few times, i was redirected to some telco that I've never heard of, and someone came on the phone, asked for the number I was calling and my calling card number. He then asked for my PIN. I said no way. He then told me that he couldn't make the call. I hung up.
    Later, at the airport, my card worked perfectly. I wish I got the name of the telco that was blocking access to my long distance company so I could have filed some sort of complaint with the FTC.
    Is it common practice for hotels to block access to your long distance provider so that you have to use their company for help that they charge you for?

    I've gotten so paranoid, I've repeatedly hung up on legitimate calls. It's unfortunate, but this shit is hurting legitimate businesses and making it harder for us consumers to know if we're being taken or not.

    --

    There is no spoon or sig.

    1. Re:There are so many... by eMartin · · Score: 4, Interesting

      After following the directions listed on the phone a few times, i was redirected to some telco that I've never heard of, and someone came on the phone, asked for the number I was calling and my calling card number.

      Maybe a scammer just put his own sticker on the phone when he had the room before you. I doubt that housekeeping checks for that kind of thing.

  14. it gets better by monkeySauce · · Score: 5, Informative

    The 22 year old guy she was working with thought he was breaking the law with a 20-something hottie instead of this 55 year old overweight felon from Akron. He must feel pretty stupid about now.
    this story has more detail

  15. so it's only an issue if it's personal? by binarybum · · Score: 3, Insightful

    I don't get it. Is this all it takes to get spammers busted? Can I just forward the scams and spams I get to this guy and have all these people caught? Why did this only become an issue when it was a personal attack on someone in a position of power to do something about it. What about the rest of us, how can we fight back? And more importantly why isn't the FBI doing more to attack spammers other than when they're personally feeling the heat?

    --
    ôó
  16. Re:Let em guess she was American ? by ljavelin · · Score: 4, Insightful

    Sorry, but it is incredibly naive of you to assume that only "computer idiots" fall for these scams.

    They are very convincing... stealing all the branding of a legit informational email. I'll tell you, my mom and dad just cannot tell the difference between http://www.citibank.com/signup/account.jsp and http://www.citibank.com@192.168.0.1/acct.jsp.

    These scams can be compelling to people who don't understand that ALL email should be untrusted, and that all URLs within email should be untrusted, and that all forms that you fill out should be untrusted.

  17. Oops... by Pan+T.+Hose · · Score: 5, Interesting

    I think everyone (not only "spammer") had such an "Oops" in her career. I remember when we counterattacked CIA agents scanning our network... I saw a host slowly and randomly syn/fin/null scanning (something like nmap --randomize_hosts -Tparanoid but with -sS, -sF and -sN changing randomly -- a custom patched nmap or something like that) our hosts, so I answered with directing a broadcast-magnified traffic to its class C (something like "smurf" but with custom tools using UDP and TCP as well as ICMP packets) to disable the offending host, having absolutely no idea that I saturated the backbone of ISP used by a CIA covert operation. Imagine my surprise when I saw agents knocking on my door... Fortunately after I described some of my techniques and explained to them that I am a security professional, not a cracker, they let me go but if I wasn't working for the government at that time I probably wouldn't write this now. I wonder what stories other slashdotters can tell about their biggest "Oops!"

    --
    Sincerely,
    Pan Tarhei Hosé, PhD.
    "Homo sum et cogito ergo odi profanum vulgus et libido."
  18. Password Checker! by dolo666 · · Score: 4, Interesting

    You wanna know how gullable people are? As a joke last year, I coded a little password checking program, at my site. Users could check their password against a list of a million common English words, to see if their passwords were secure. There was a database with a million words in it, and each time someone put in their password, the site would tell them if it was in the list. It would also tell them that if they are stupid enough to give out the password to just anyone, then it's certainly not secure!

    People would show up and type in something that looked like a real password, and then type in another password as a message to me -- along the lines of Fuck You on a Silver Platter, Asshole.

    Hackinthebox.org posted the site and a pile of gullable flies* showed up to check their passwords. I'm guessing people from HiB would send the site to other unsuspecting people, as a joke. Thing is, eventually some pretty scared people were emailing me. I took it down after while. It was getting to be more annoying than fun.

    There is always someone out there who is greedy or scared enough to be scammed online -- it's just sad when it happens to someone you know.

    * flies: a fly is someone who gets stuck in the web, and a spider is someone who owns it.

  19. Re:Let em guess she was American ? by kfg · · Score: 5, Funny

    There are certain items of the arcana that are only available to the wise. Ok, some MCSEs know them too, but only a few.

    Do wish to have arcane knowledge and be the envy of your 133t friends? How on earth those spammers, well know for deep knowledge of the darkside, produce a cent sign when it isn't on the keyboard?

    You (sir/madam) have been carefully selected as one the few who have what it takes to secret forces and such power right at your fingertips!

    Don't be a clueless dork anymore. Just send $19.95. Your seat at the table of the Illuminati is waiting. . . for you (sir/madam)!!!

    KFG

  20. *bzzzzt* by devphil · · Score: 4, Informative


    I hear you on the FBI thing. But consider: somewhere a just-not-worth-the-taxpayer's-money line has to be drawn. The FBI is seriously understaffed. (Go figure. The technologically astute are too proud to work for a measly $35K FBI salary, investigating tech crimes. Nooooo, gotta be making glamourous six-digit salaries on high-visibility programming projects.) But anyhow, the reason I'm posting is...

    It's like the local cops who don't give a shit if your laptop, your radio, etc were stolen and hundreds of dollars in damage done to your car. But, mind you, they've got all day to sit out on 'speed patrol'...

    Unless you live in Andy Griffith Town, the officers who sit on speed trap duty are not the same ones who investigate theft. Different division, different rules, different salaries, therefore a different allocation of officers/resources/time/budget.

    A traffic cop "sitting all day" on watch costs less than an investigating agent spending even half a day looking for stolen laptops chock full o' pr0n. It's harder to hire investigative officers and detectives, it's more expensive to train them and pay them.

    --
    You cannot apply a technological solution to a sociological problem. (Edwards' Law)
  21. conversation with my credit card company by 3ryon · · Score: 4, Interesting

    me: I've received 3 scam e-mails today which are trying to get me to give up my credit card number. Do you have a special card number I can give them that will set off an alert when someone attempts to use it, so that you can apprehend these people?

    CC Company: No, but that sounds like a great idea.

    me: Yes. Now do something about it.

    What do you think the odds are that the idea ever got past the person I talked to on the phone?

  22. Re:Social Engineering by techt · · Score: 5, Informative

    No. The ones I've seen use this:
    http://www.myrealbankname.com:whatever@real IPaddre ssindotlessformat/

    The "www.myrealbankname.com:whatever" before the @ is not a URL, but a value sent to the real site which is denoted by the "realIPaddressindotlessformat".

    For example, cut and paste this into your browser:

    http://www.kuro5hin.org:section@1109654166/

    The above URL doesn't take you to Kuro5hin, it takes you to the Slashdot main page.

  23. Spamers lack imagination. by arose · · Score: 3, Insightful

    Why email millions of inteligent people, when all you need to do is to set up an "Free IQ" test, that delivers results via email...

    --
    Analogies don't equal equalities, they are merely somewhat analogous.
  24. Re:Social Engineering by marnanel · · Score: 3, Informative

    Opera warns you every time you try to access a site with a username in the URL - does Mozilla do this too?

    No, it doesn't yet. I agree-- it should. Mozilla bug 122445 tracks this issue. I suggest voting for it.

    (Copy and paste
    http://bugzilla.mozilla.org/show_bug.cgi?id=122445
    into your browser to go there; Bugzilla doesn't allow links straight from slashdot.)

    --
    GROGGS: alive and well and living in