Hackers Track Down Banking Fraud
An anonymous reader writes "Noticing some commonalities in the spam flooding their email
in-boxes, a small group of hackers set out to track down who was
responsible. Along the way they uncovered a trail that led them to an
organized gang of criminals halfway around the world, and right back
to some of the largest financial institutions in the US, and their
customers, that became the gang's prey. See the SecurityFocus story for more details."
Its about time the "hacker" community gets some positive news, just one more step to remove the "cyber-terrorist" label the news/media has created
This reminds me of Cliff Stoll- an astrophysicist who moonlighted as a sysadmin at UC Berkley, and noticed a discrepancy of a cent or less in the CPU time accounting system.
I won't spoil the story, but see if your local library has a copy of the Cuckoo's Egg(by Stoll). His more recent book, Silicon Snake Oil, discusses the falsities behind throwing technology(computers) at people- particularly in schools, for example...and was also quite good when it came out(and schools were dumping boatloads of $ into computer labs which sat mostly empty).
He's humble, intelligent, well educated, writes fun to read stuff...one of the computer scientists(and physicists) I respect the most- far above all the three-letter personalities.
Please help metamoderate.
In this scam a pop up with no navigation and no URL box was presented to the user on top of a genuine web page. This confused the user into thinking the pop up came from citibank. Advertisers like such pop ups because it locks the user into a path specified by the advertiser and obscures the source of the ad. Some web designers like the format because they think it's looks less cluttered.
Most modern web browser can be set will block pop up, force navigation, or always display the URL. Many advertisers whine that this is unfair. So what. What is even more amazing is that generally responsible companies, such as eBay, will create pop up screens with no URL and no navigation, thereby setting a precedence to allow such fraud.
The same is true from images from a third party server. It is useful for advertisers to set web bugs and large scale rotating campaigns. It is even useful for websites to distribute load. It also introduces security issues.
Which is just to say that may on /. would say that the luser should be more careful, and stupid people deserve to be swindled. But i have seen financial organizations use pop ups and third party ads to push product to their customers on the customers financial information page. This is a page that should only contains sensitive information, not irrelevant content The banks are willing to compromise security to push products. And then the banks complain that customers are to blame.
"She's a scientist and a lesbian. She's not going to let it slide." Orphan Black
I was recently (about 2 months ago) defrauded in the amount of $6000 in an Advance Fee Fraud. I realize most people will laugh at me for this, but some of these scammers can be particularly convincing. The scam in this case involved the purchase of my car (which was being sold online), and a cashier's check of an amount in excess of the agreed purchase price. This 'excess' was to be wired to the 'shipper', as the car was going overseas.
Anyhow, I decided to do something about it. I hacked into the email account used to defraud me, and followed a chain of emails and accounts that eventually led me to a handful of personal accounts. Each time I gained access to a new email account, I'd peek at all the emails inside and warn off any people who were being targeted from that particular account. After a month and a half of monitoring personal email, I gathered real names, relations, addresses and even resumes on those people involved. The particular 'ring' of scammers that got me is a family and friends affair, with the eldest brother of the family attending university in London, UK. His brothers and cousins (who live in Nigeria) work the fake email accounts and collect 'clients'. Once they have a deal made and personal information collected, they forward this to the ring leader in London, who contacts his sources to produce fake checks. He also takes over the email account, giving out a UK mobile phone number (changes often) to 'clients' who ask for one.
The money is sent in the name of one-time accomplices. These are people that the ring leader recruits to pick up money at Western Union counters. Once the money is picked up, he gives them a portion then splits the rest between himself, the cheque source and the relative who originally manned the email account.
Long story short: I have all this information, and don't know exactly what to do with it. I've tried to contact the London Metropolitan police anonymously (via email), several times, and have not heard back. I'm not sure if I should go to my own federal authority because what I've done to gather the information is illegal.
This particular scam has people involved in the US, Canada, the UK and Nigeria. I'm located in Canada. Any advice?
To stop this phishing technique, browsers ought to
pop up a warning dialog for URLs with a username
field (especially if it contains one or more dots).
Something like:
| Alert -- Actual URL is:
|
| Domain Path: badpeople.hackedsite.ru/hahaha
| Username: www.citibank.com
| Password: verify=
This would at least highlight the real site the
link is pointing to.
>;k
This isn't exactly someone who ran out and did something positive securitywise out of the goodness of his heart. It isn't even data from someone who works in security and ran out and did something on the side.
This entire linked-to-article is, frankly, an advertisement. It's an advertisement to try to get people to buy security consulting services from this company. Impressively, this company managed to get the story on Slashdot. It's a sample report (you can figure this out early because of the number of tables and screenshots). (Silly execs love tables and pictures -- be sure to include lots if you're ever in a vending situation, even if they provide little useful content.) Other red flags include the fact that it's aimed at financial services (folks who have lots of money), and focuses on flaws in what Citibank is doing (with the implicit suggestion that this company could help them). Especially notable is the fact that if focuses on flaws in Citibank's behavior even if said behavior is not particularly relevant to the scam, such as the format of Citibank's emails. Are customers going to notice or care whether Citibank emails contain unique identifiers -- *not* hashbusters? No, though a security consultant who focuses on spam would.
Then they have the nice little blurb at the bottom about the company.
Frankly, they missed one important aspect. You can't sell anything to a company unless you can provide a measure of how much the company can save. They should run out and get a ballpark estimate on how much Citibank could potentially, worst-case, lose from this. They subtract proposed consulting fees and end up with a nice fat number.
The reason I find this advertisement vaguely disturbing is because folks like this are just another leech feeding off of fat, stupid corporations. Lots of consultants already do so. However, what these folks do *sounds* good but has little point. It's not financially feasible for a company to pay a small private army of techies to try to track down random Russians so that legal nastygrams can be sent to them (keep in mind that the firm didn't actually *identify* who the spammers were). There are too many potential baddies out there. A financial services corporation would be *far* better served by developing secure communication policies and technology that are *easy* to use for the consumer, and then spending money educating their customers about these. Then they become difficult to attack. To go after individual bad guys is like plugging holes in a dyke -- very profitable for the guy being paid to plug holes, but ultimately ineffective.
May we never see th