Slashdot Mirror


Glut In Stolen Identities Forces Price Cut

CowboyRobot writes "The price of a stolen identity has dropped as much as 37 percent in the cybercrime underground: to $25 for a U.S. identity, and $40 for an overseas identity. For $300 or less, you can acquire credentials for a bank account with a balance of $70,000 to $150,000, and $400 is all it takes to get a rival or targeted business knocked offline with a distributed denial-of-service (DDoS)-for-hire attack. Meanwhile, ID theft and bank account credentials are getting cheaper because there is just so much inventory (a.k.a. stolen personal information) out there. Bots are cheap, too: 1,000 bots go for $20, and 15,000, for $250."

15 of 152 comments (clear)

  1. Change your passwords ASAP! by DigiShaman · · Score: 5, Informative

    Seriously! If you even suspect that the machine you're working from has ben compromised by malware, CHANGE YOUR PASSWORD to the accounts you've used via a known clean computer. Then proceed to nuke the drive from orbit and reload the OS and apps. Botnets are known sources of dropping key loggers and harvesting user data to a central database.

    --
    Life is not for the lazy.
    1. Re:Change your passwords ASAP! by sycodon · · Score: 4, Funny

      We need a bounty on cyber criminals. How about $25 per ear?

      --
      When Fascism comes to America, it will call itself Anti-Fascism, and tell you to give up your guns.
    2. Re:Change your passwords ASAP! by ifiwereasculptor · · Score: 4, Informative

      I don't know how it is in the US, but here banks seem to deeply dislike OSs not retardedly easy to compromise. I have accounts in two banks. One of them started working in Linux only about four years ago, the other only did so last year. They both regularly splurt errors because of openJDK incompatibility - they want Sun's Java. And one of them hilariously has its https certification broken for almost a year now. Airlines are even funnier. At least one of them still only works on IE.

  2. Re:those numbers seem unsustainable by ATMAvatar · · Score: 4, Interesting

    Exactly. You aren't going to successfully withdraw all $150k in one go. Withdraw $100 once or twice a week, and there's a decent chance the owner may not notice for some time.

    --
    "They that can give up essential liberty to obtain a little temporary safety deserve neither liberty nor safety."
  3. Get rid of spam? by SB9876 · · Score: 5, Funny

    So, if I'm to follow the reasoning of this article, if we all use weak passwords , the market gets flooded and they all go out of buisness?
    SWEET
    password:password, here I come!

  4. Re:those numbers seem unsustainable by artor3 · · Score: 5, Insightful

    I think it goes without saying that when someone sells a $150k bank account for $400, it's because they know they can't withdraw more than $400 without getting caught.

  5. I want to cut out the middle man by the_Bionic_lemming · · Score: 5, Funny

    I'd like to cut out the middle man and sell my Identity.

    40 bucks buys a few cases of beer - just sayin...

    --
    _ _ _ Go for the eyes Boo! GO FOR THE EYES!
  6. Re:Capital Crime by sjames · · Score: 5, Insightful

    'Identity theft' should be recognized for what it really is, bank fraud.

    First the crooks defraud the banks by performing transactions in someone else's name. This is aided by the banks insistence on not implementing secure authentication.

    Then the banks defraud you by insisting that you are responsible for the transactions in spite of not having a single shred of evidence that you made them.

    The credit agencies compound it by repeating the bank's financial gossip with a wanton disregard for the truth.

    The 'justice system' then aids and abets by not telling the banks to pound sand and by not convicting the credit agencies for libel./p.

  7. Take Mine For Free by Anonymous Coward · · Score: 5, Funny

    Here, take my identity, please!

    You get to assume a recent bankruptcy, a child support obligation, a spotty employment record, a sub-500 credit score, three maxed-out credit cards, a beater car, and a psychotic ex-wife.

    Clean arrest record and a good tech education, though. Maybe you could apply to a NSA contractor.

    1. Re:Take Mine For Free by Jason+Levine · · Score: 5, Interesting

      Clean arrest record and a good tech education, though

      Sadly, there's more than just financial identity theft. There's criminal identity theft also. Here's how it works:

      1) Criminal arrested for some crime.
      2) Criminal gives your name/SSN/DOB/etc to the police.
      3) Arrest goes onto your criminal record and not the real criminal's record.

      Now you go for a job interview and your potential employer runs a background check. Suddenly, they find out that you've committed felonies across three states and were arrested nine times. You don't get that job offer - or any other one. Plus, if the local police stop you for any reason, they'll find out you're a "felon" and will treat you as such. No matter how many times you try to clear this up, if even one database still links you to the crimes, it will flow back over and start again.

      At one point, I was following the blog of someone who had this happen to him. He couldn't find a job, was being harassed by police, and nobody would help him. All this.despite the fact that the photo of "him" at the arrest was clearly not really him. People just trusted what was "in the system" even if the system seemed wrong. Last I heard, after years of struggling, he had finally gotten some people to listen and begin the process of clearing his record.

      It's insane that one criminal with a stolen identity could ruin someone's life like this but it does happen.

      --
      My sci-fi novel, Ghost Thief, is now available from Amazon.com.
  8. Re:Hurry up and sign up for ObamaCare by Anonymous Coward · · Score: 4, Funny

    Don't you know private industry is the epitome of security and efficiency? That's why the private sector is never plagued by budget overruns or mismanagement.

    Why do you hate America, you filthy communist?

  9. Re:Capital Crime by Joining+Yet+Again · · Score: 5, Insightful

    Calling for something to be a capital crime should be a capital crime.

    O shi-

  10. Need To Flood Market With Fake Identities by retroworks · · Score: 5, Interesting

    It should be easy enough for someone here to harvest phonebook or other records from 70 years ago, refresh and randomize birth dates, and begin to flood the identity theft market with fake personalities and random government identity records. That would greatly increase the amount of work for identity thieves, who actually benefit from passwords (which provide evidence it's bonafide identity they are stealing). For years I've promoted "camouflage" rather than invisibility. I now think the reason it has not taken off (disappearance of AntiPhorm?) is that it's equally a threat to Google, Bing, and advertising-based search engines. We can be less careful of our "identity needles" if we construct bigger "digital haystacks".

    See article on digital haystacks and cookie camouflage http://retroworks.blogspot.com/2010/09/simpler-ideas-cookie-camouflage-digital.html

    Oh, by the way, I'm not really Retroworks. I find I get higher mods if I steal a /. identity rather than to submit AC

    --
    Gently reply
  11. Re:those numbers seem unsustainable by AmiMoJo · · Score: 5, Informative

    Usually the plan is not to withdraw money from the account directly. Too easy to get caught, owner of the account usually notices pretty quickly. Instead the account is used to open other accounts or take out loans which are then defaulted on.

    This is pretty common in the UK. We have these shitty pay-day loan companies that charge 5000% interest and do only the most basic checks before handing over the cash. People give them someone else's name and bank account, so the first thing the victim knows about it is when Wonga starts taking internet payments by Direct Debit.

    --
    const int one = 65536; (Silvermoon, Texture.cs)
    SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC
  12. Re:those numbers seem unsustainable by Jason+Levine · · Score: 4, Informative

    Exactly this. When my identity was stolen, the thieves didn't use it to find and break into my bank account. Instead, they opened a credit card in my name (with my address, SSN, and DOB, but NOT with the correct Mother's Maiden name - red flag #1). The only reason they didn't get away with it was that they 1) paid for rush shipment of the credit card and 2) then immediately changed the address (red flag #2). So the card got shipped out quickly to my address and THEN the address was changed. The card arrived at my doorstep instead of theirs. Of course, that didn't stop them as they tried to get a $5,000 cash advance before even activating the card (red flag #3).

    And the credit card company's response to me? "Are you sure your wife didn't open the card in your name without telling you? No? Well, we can't give you any information on the account because if you go and kill them then we're liable." They stonewalled me and when I got the police involved, they directed them to a number that was never answered. To them, they just closed the account and the problem was solved. Actually helping to catch the people who did this would involve effort that they weren't willing to put in. That's why Capital One credit card's are not and will never be "what's in my wallet."

    --
    My sci-fi novel, Ghost Thief, is now available from Amazon.com.