Slashdot Mirror


Ask Slashdot: Dealing With VoIP Fraud/Phishing Scams?

An anonymous reader writes I run the IT department for a medium-sized online retailer, and we own a set of marketing toll-free numbers that route to our VoIP system for sales. Yesterday we began receiving dozens and now hundreds of calls from non-customers claiming that we're calling out from our system and offering them $1 million in prizes and asking for their checking account details (a classic phishing scheme). After verifying that our own system wasn't compromised, we realized that someone was spoofing the Caller ID of our company on a local phone number, and then they were forwarding call-backs to their number to one of our 1-800 numbers. We contacted the registered provider of the scammer's phone number, Level3, but they haven't been able to resolve the issue yet and have left the number active (apparently one of their sub-carriers owns it). At this point, the malicious party is auto-dialing half of the phone book in the DC metro area and it's causing harm to our business reputation. Disabling our inbound 800 number isn't really possible due to the legitimate marketing traffic. Do you have any suggestions?

159 comments

  1. Level3? by Anonymous Coward · · Score: 0

    Good luck with that

    1. Re:Level3? by Anonymous Coward · · Score: 5, Insightful

      Time to file complaints with Regulatory Bodies.

      It's the phone provider's responsibility to ensure that the caller ID presented by numbers in their "pool" send valid information. You've notified Level3, so that's about all you can do to actually solve the problem. But getting a complaint filed will make it more likely to "light a fire" under Level 3 to block the offending sub-provider until they get their act cleaned up.

      Luckily for you this is an in-country operation... when it's an offshore provider doing it you're pretty much out of luck.

      As for solutions, best you can really do is put up an automated recording apologizing and advising that you're not the scammers, and encourage them to file complaints with their own providers and LEA/regulatory agencies (PSC, FCC, etc.)

    2. Re:Level3? by frisket · · Score: 1

      What's a phone, Mommy?

    3. Re:Level3? by hsmith · · Score: 2

      Regulators don't give a fuck. No one does. I've been getting robodialers to my cell phone endlessly. They all come out of blocks of phone numbers provided by one datacenter (they own blocks around the country). They won't do anything. The regulatory bodies in states the numbers call from won't do anything. FCC won't do anything. FTC won't do anything. I've contacted my state AG. I've contacted my senators and congressmen.

      No one gives a flying shit about this kind of thing. It is infuriating.

    4. Re:Level3? by Anonymous Coward · · Score: 0

      What, bureaucrats not giving a shit about anything other than taking away freedoms and money from citizens? No, that can't be true. Obviously you're an evil Libertarian troll.

    5. Re:Level3? by penix1 · · Score: 5, Insightful

      I've got a better solution for both of you...

      Put an automated message that says the following...

      "If you are calling about a recent scam involving our number, please call Level 3 at..." and give the phone number to Level 3's complaint office. If they don't have a complaint office then simply give the main number. Better yet if you can, forward the call to them via a menu system. Let them deal with the fallout. Maybe they will take the hint.

      --
      This is a sig. This is only a sig. Had this been an actual sig you would have been informed where to tune for more sigs.
    6. Re:Level3? by Livius · · Score: 1

      Completely untrue.

      You've just misunderstood whose interests the regulators are there to protect.

    7. Re:Level3? by DudeFromMars · · Score: 2

      Clever in it's simplicity, yet fiendish in offloading the headache and punishing someone else. Hopefully, that someone is at least partly responsible.

    8. Re:Level3? by Anonymous Coward · · Score: 1

      How do you know where the number originated? Assigned numbers are meaningless. By buying a trunk line for your call center you can modify the CID for anything you like. This is often the case for providing a CID of your 800 DID line. Simply entering someone else's number is how this fraud originates. The fake number does not identify the caller. IF you take the call directly from a scammer, and the SIP call is completed, the SIP log can show the IP of both ends of the call if it is not routed through a proxy.

      I am not sure how Level 3 was identified as the SIP provider for the scammer account. Unless a called customer captured the IP of the caller with a SIP to SIP call, the IP is lost once it is filtered by calling into the local exchange.

      This is an ask Slashdot without a link to real data on the source of the scam calls. A Trunk line for outbound calls does not have a phone number association. Only the incoming DID line is associated with a phone number.

      Try it your self. Find a commercial SIP provider and ask about DID and Trunk lines. DID lines have a number to be called, often an 800 number. The Trunk lines are not incoming lines and do not have a number and can't take incoming calls. The caller ID is set by the CUSTOMER to display the company info and switchboard, PBX, or 800 number on the CID. This is settable by the CUSTOMER. which is how this fraud is created.

      The best defense is to place the entire scam summary on the front page of the corporate website to explain the situation, and have the auto attendant inform the customers of the scam and ask them to review the website. You are the victim of a Joe Job. A link to the Wikipedia article of Joe Job will help.

      http://en.wikipedia.org/wiki/Joe_job

    9. Re:Level3? by jafiwam · · Score: 1

      I've got a better solution for both of you...

      Put an automated message that says the following...

      "If you are calling about a recent scam involving our number, please call Level 3 at..." and give the phone number to Level 3's complaint office. If they don't have a complaint office then simply give the main number. Better yet if you can, forward the call to them via a menu system. Let them deal with the fallout. Maybe they will take the hint.

      I suggest the sales department phone number. Those seem to be able to accomplish things with screeching to management and IT.

    10. Re:Level3? by ArcadeMan · · Score: 1

      It's a place where people used to go to borrow printed versions of websites, honey.

    11. Re:Level3? by kilodelta · · Score: 1

      You have to approach it from the right angle. Tell them it interferes with emergency communications and they'll be all over it like white on rice.

    12. Re:Level3? by AK+Marc · · Score: 1

      Not true. I had a problem with my phone line in the '90s. I sent a letter to the FCC and the phone company. The phone company, who had insisted the problem was "impossible" to fix had it fixed withing 48 hours of me putting the letter in the mailbox. They did so so that when the FCC contacted me, I could tell them that the problem had been fixed.

      If they were as powerless and uninterested as you say, they wouldn't have reacted so fast.

    13. Re:Level3? by AK+Marc · · Score: 1

      How do you know where the number originated?

      You can spoof CLID, but not ANI. If you could spoof ANI, then nobody would ever pay for calls, other than the one grandma everyone set their billing identity to.

      This is settable by the CUSTOMER. which is how this fraud is created.

      Which was by design. You can spoof the CLID all you want, but not the ANI. The idea is that anyone spoofing CLID for fraud would be caught. Instead, we get police much more interested in drug charges and other victimless crimes, and nobody investigating fraud, with identifiable victims.

      But it's required so that when I get two trunks, one in-only and one out-only, I can set the 800 number as the CLID of the outbound trunk, so that if someone doesn't already know your DID, they'll call back the company main number. This is how most places that do sales and such like it. You call the "main" number, until you have a relationship with someone to call their DID. All the CLID-protection schemes that don't allow this behavior are rejected by carriers and corporates.

      Level 3 should be thrown in jail for fraud and conspiracy to commit fraud.. They allowed numbers to be advertised that were provably not in their blocks of numbers.

    14. Re:Level3? by Chris+Mattern · · Score: 1

      And what a lovely greeting that will be for their customers who *meant* to call them...

    15. Re:Level3? by Cramer · · Score: 1

      IF you take the call directly from a scammer, and the SIP call is completed...

      And just who in their right mind allows random SIP traffic from the internet to reach their PBX? ABSOLUTELY FUCKING NO ONE! Page one, step one of toll-fraud: allow access only from authorized sources. So, if a SIP call is "completed", it came from your phone service provider.

      If they're spoofing the caller-id, then you have NO WAY to know where it came from. Only a "trap and trace" can follow it back, hop by hop, to the origin -- one switch at a time, one provider at a time, all the way back to China (or where ever.) That's the basis for the hollywood phone trace, but in reality, it takes people combing through records to see what's going on. (unless it's crossing metered lines, in the US, it's almost a certainty no CDRs are being generated and/or recorded, and even then, only for the segment that's metered -- eg. your cellphone.)

  2. This is a legal matter. by FireballX301 · · Score: 4, Interesting

    Refer to L3's legal department, threaten to file suit against them if they won't give up the identity of the sub-carrier's customer. They will cough it up immediately, or you will get a nice payout for civil fraud.

    1. Re:This is a legal matter. by Anonymous Coward · · Score: 1

      Refer to L3's legal department threaten to file suit against them if they won't give up the identity of the sub-carrier's customer.

      And they will refer you to the Law, which prevents them from giving out that kind of information. You're going to need a court order to get that info.

      They will cough it up immediately, or you will get a nice payout for civil fraud.

      No. You might be able to file a suit against whoever did the scamming, or their direct provider if you can show negligence or a Rules violation. But you probably will just end up with a large Lawyer Bill.

    2. Re:This is a legal matter. by CaptainDork · · Score: 5, Informative

      I work for a law firm and this will not work.

      Threats are a dime-a-dozen and no one takes them seriously.

      What works is to get an actual lawyer to compose an email that actually originates from the law firm and/or send snail mail, on law firm letterhead, explaining why the scammer is suspect and asking for clarification.

      --
      It little behooves the best of us to comment on the rest of us.
    3. Re:This is a legal matter. by Anonymous Coward · · Score: 0

      While they shouldn't give the information, they have to act to stop the spoofing.

    4. Re:This is a legal matter. by Minupla · · Score: 4, Insightful

      Yep, a call to my corporate legal dept would be my first move in this situation. It's amazing how many situations got deescalated when we got the other party on the phone with my legal dept on the line.

      Min

      --
      On the whole, I find that I prefer Slashdot posts to twitter ones because I don't get limited to 140 chars before
    5. Re:This is a legal matter. by Richard_at_work · · Score: 3

      Hehe, so in this case a Slashdotter thinks you should be able to get details without a court order, but when the RIAA or MPAA wants details its a completely different situation...

    6. Re:This is a legal matter. by Anonymous Coward · · Score: 0

      I'm a lawyer named Bill so I got a kick out of this response.

    7. Re:This is a legal matter. by FireballX301 · · Score: 1

      Well yes, if they don't respond, actually file the lawsuit. Nothing is more useless than an empty threat.

    8. Re:This is a legal matter. by Anonymous Coward · · Score: 0

      But are you large?

    9. Re:This is a legal matter. by jareth-0205 · · Score: 2

      I think his point is that you can shortcut the inevitable ignoring of a badly worded threat if you get a well-worded threat in the first place. Given the damage that's currently being done waiting the 7 days or whatever and actually starting a lawsuit you probably don't actually want to carry out... better to get a lawer immediately.

    10. Re:This is a legal matter. by tompaulco · · Score: 1

      Actually, damage has already been done. File the lawsuit anyway. Sue for actual damages plus punitive damages equal to the net worth of their company plus the net worth of all corporate officers.

      --
      If you are not allowed to question your government then the government has answered your question.
    11. Re:This is a legal matter. by Tyr07 · · Score: 1

      Shock surprise! Slashdotters are against people getting tens of thousands in fines over their kid downloads a single MP3 that got shared!
      Damn, people want their invisible money, because man, all those people would have totally purchased THAT SONG if they couldn't have downloaded it.

      We also think that when it's a case of fraud, that people would engage properly instead of ignoring it. I work in a datacenter.

      If we receive a phishing email complaint, or website, and confirm it exists, we SHUT THEM DOWN.
      The owner of the server might not be responsible, but they have to communicate with us and correct it or it stays down.

      By the same margin, if Level3 can confirm that spoofed caller ID is coming from another company, contact that company. If they won't shut it down, shut them down.

    12. Re:This is a legal matter. by CaptainDork · · Score: 1

      You guys are too aggressive.

      A polite, inquisitive, probe by a lawyer, asking for simple clarification, goes a LONG way when the recipient knows damn well they don't want to be embarking on a journey that the recipient can't justify.

      --
      It little behooves the best of us to comment on the rest of us.
    13. Re:This is a legal matter. by Anonymous Coward · · Score: 0

      As an ordinary Joe who has sued many telemarketers pro se, listened t lots of bulls#*t lawyer arguments as to why black is really white, gotten lots of judgments (after convincing the appellate courts that the trial judge's opinion agreeing with the telemarketers were all wrong), and collected money from some of them, I can tell you and you can take it as gospel that scammers don't care whether you threaten to sue, get a lawyer to write threatening to sue, or actually do sue. They are criminals who are effectively invisible operating under a shell corporate name. You only hope is to convince the telephone carrier to intervene and stop the scammer's telephone service (at least until they get a new scam going under a different shell corporate name). Complaining to the FCC is a pitiful joke (or maybe a cruelty joke). Go through he motions of an FCC complaint, but don't expect the FCC to do diddlysquat. But, you'll need to have filed a written complaint with the FCC in order to have any clout with the carrier.
      The only real solution is to fight a major legal battle with the carrier attempting to convince the judge that the carrier is liable for the scammer's misdeeds on the grounds that the carrier "knew or should have known" that he was aid and abetting a criminal scheme. Might try filing a civil RICO claim against the carrier (which would increase your legal burden astronomically, since you'll also have to prove a "predicate offense" in addition to proving the offense you are suing for).
      You might try getting congress to act to impose carrier liability under the Telephone Consumer Protection Act of 1991. Good luck with that one.

    14. Re:This is a legal matter. by AK+Marc · · Score: 1

      He's already asked nicely. Paying a lawyer to ask nicely is extortion by the legal profession. If he has to pay a lawyer, he should pay them to sue.

    15. Re:This is a legal matter. by CaptainDork · · Score: 1

      No.

      He has an objective and it doesn't include smashing anyone's big toe with a hammer.

      It's a lot cheaper to have a lawyer compose an inquiry than it is to actually file a lawsuit.

      --
      It little behooves the best of us to comment on the rest of us.
    16. Re:This is a legal matter. by AK+Marc · · Score: 1

      In my experience, anyone who fails to respond to a letter, won't respond to a letter signed by a lawyer. Unless the first letter was written in crayon on toilet paper.

    17. Re:This is a legal matter. by Cramer · · Score: 1

      Actually, the MPAA/RIAA do have a court order in these cases... but just one for many IPs. When they have to file one case per address, it becomes a huge burden (and expensive) and they tend to walk away.

    18. Re:This is a legal matter. by CaptainDork · · Score: 1

      In my experience, anyone who fails to respond to a letter, won't respond to a letter signed by a lawyer.

      I work in a law firm. Do you?

      --
      It little behooves the best of us to comment on the rest of us.
    19. Re:This is a legal matter. by AK+Marc · · Score: 1

      I have, but don't currently. Why?

    20. Re:This is a legal matter. by CaptainDork · · Score: 1

      I was comparing our experiences.

      --
      It little behooves the best of us to comment on the rest of us.
    21. Re:This is a legal matter. by AK+Marc · · Score: 1

      "Work in a law firm" isn't very specific. And given that there wasn't a mention of in what capacity, I'm not sure your experience would be relevant. You didn't mention working as a lawyer or paralegal, which are the two positions that would be more relevant, though less so for a paralegal, who generally stick to the books, while the lawyers deal with the clients and outcomes. For all we know based on your comment, you are a janitor, or other office support with no legal training or experience. In which case, my pre-law classes back in college would put me in a good position, comparing experiences.

    22. Re:This is a legal matter. by david_thornley · · Score: 1

      In my very limited experience, companies pay a lot more attention to something a customer's lawyer says than something a customer says.

      --
      "When you have eliminated the unacceptable, whatever is left, however improbable, must be the truthiness" - Holmes
    23. Re:This is a legal matter. by AK+Marc · · Score: 1

      There's a heirarchy of bluff. Letter. Letter threatening to involve a lawyer (often asking for contact information to the legal department). Letter from lawyer.

      If they were serious, the first letter would have been from the lawyer. The second act is sue. Those that send an impotent letter of whine before the lawyer letter ensure ignoring, as they've demonstrated inability/unwillingness to follow through.

      The *only* exception to that is when the letter (from you, or your lawyer) is sent certified mail and indicates it is official legal notice of intent to sue. But that doesn't need a lawyer. The only time I sent one of those, the other party called up and apologized, fixed the issue, then sent an email full of profanity. She stole my car and put a lien on my house when I asked for it back. She had a lawyer draft the lien, but my notice of lawsuit (required for small claims court) got the lawyer to tell her she was crazy. I'm sure she lied to him to get his help in the first place.

    24. Re:This is a legal matter. by CaptainDork · · Score: 1

      We were comparing experiences because of your comment:

      In my experience, anyone who fails to respond to a letter, won't respond to a letter signed by a lawyer. Unless the first letter was written in crayon on toilet paper.

      I am countering with my experience, which includes 18.5 years total immersion and counting, with yours which apparently is long distance in both perimeter and time.

      I know what I'm talking about, and you are guessing.

      I'm OK with that, but let's just be clear about it.

      --
      It little behooves the best of us to comment on the rest of us.
    25. Re:This is a legal matter. by Anonymous Coward · · Score: 0

      Ah! So your experience with the law is through your crazy ex? I can see where that might teach you a few things. :-) Just having a bit of fun... The 'dork' you were arguing with definitely is one, and a big failure in the bluffing department. He's a new guy, probably a part time spammer here...

    26. Re:This is a legal matter. by Anonymous Coward · · Score: 0

      18.5 immersed in toilet repair... You really should go somewhere else with your bullshit. You don't fool anyone here with your stupid macho talk... ...let's just be clear about it.. Christ! GTFO! You're part of the big decline of Slashdot!

    27. Re:This is a legal matter. by AK+Marc · · Score: 1

      I note, even after my comments, you avoided saying what you did. You aren't a lawyer. You aren't a para-legal. You are "immersed" in a janitorial career.

      Given that you refuse to answer a clear and simple question, I can only assume it's the worst possible option.

    28. Re:This is a legal matter. by AK+Marc · · Score: 1

      She wasn't an ex. Your guesses are all wrong. You are a presumptuous idiot. But thanks for trying.

    29. Re:This is a legal matter. by CaptainDork · · Score: 1

      Wow. My font selection reveals much.

      --
      It little behooves the best of us to comment on the rest of us.
    30. Re:This is a legal matter. by AK+Marc · · Score: 1

      So you are a typesetter for a law firm? Or do you just clean the toilets?

    31. Re:This is a legal matter. by CaptainDork · · Score: 1

      At times, I'm a type of sitter for toilets that brings out the commenters like you.

      --
      It little behooves the best of us to comment on the rest of us.
    32. Re:This is a legal matter. by AK+Marc · · Score: 1

      Ah, so a lying sack of shit, trolling for those who would correct your wrong opinion presented as fact. Have fun cleaning the toilets for lawyers. Does theirs smell better?

    33. Re:This is a legal matter. by CaptainDork · · Score: 1

      You have not expressed any opinion or fact.

      You just insult janitors and crap.

      --
      It little behooves the best of us to comment on the rest of us.
    34. Re:This is a legal matter. by AK+Marc · · Score: 1

      No, I insulted you. I asked a simple question. That you refuse to answer indicates you are lying about your abilities. I have worked at a law office in a legal capacity. You have never worked at a law office in a legal capacity. That's all I can gather, other than you assert that 18.5 years of cleaning toilets in a law office makes one a legal expert.

    35. Re:This is a legal matter. by CaptainDork · · Score: 1

      We will never get this resolved as long as we are still in high school.

      --
      It little behooves the best of us to comment on the rest of us.
    36. Re:This is a legal matter. by AK+Marc · · Score: 1

      Ah, so you've been scrubbing toilets since you were 6 months old. And are a 19 year old 9th grader, having been held back many times.

      Nah, you are a hypocriical liar who refuses to answer simple questions about his asserted qualifications, while demanding the same of others.

    37. Re:This is a legal matter. by CaptainDork · · Score: 1

      And you are a misogynistic, gender-confused, rude troll.

      --
      It little behooves the best of us to comment on the rest of us.
    38. Re:This is a legal matter. by AK+Marc · · Score: 1

      Troll? For asking a demanding and pretentious prick for his legal background, after said prick demanded the same of others?

      Hilarious. I'm a troll for doing *exactly* what you did. Well, that and calling you a liar when your answer was a lie.

    39. Re:This is a legal matter. by CaptainDork · · Score: 1

      You said I was a janitor and then you ask for my legal background and you call me a liar, anyway, so exactly what is your point?

      --
      It little behooves the best of us to comment on the rest of us.
    40. Re:This is a legal matter. by AK+Marc · · Score: 1

      No, you demanded my legal background. I answered, and returned the question. You've lied and dodged the question ever since. My point is you are a lying sack of shit who attacks others qualifications, but refuses to give his own. Making you a hypocritical lying sack of shit. You originally said you wanted to compare our experiences. But you were lying then, you were just fishing for something to attack me over. Then you did. You are just mad that I replied in kind.

      I worked in a law firm in a legal capacity. You have *never* stated you have. Have you? In what capacity?

    41. Re:This is a legal matter. by CaptainDork · · Score: 1

      I worked in a law firm in a legal capacity.

      I applaud your decision to refrain from working in a law firm in an illegal capacity and it's fortunate that you also avoided document generation.

      --
      It little behooves the best of us to comment on the rest of us.
    42. Re:This is a legal matter. by AK+Marc · · Score: 1

      What job did you do for the 18.5 years of immersion?

    43. Re:This is a legal matter. by CaptainDork · · Score: 1

      I certainly did not waste my time asking questions of a known liar.

      --
      It little behooves the best of us to comment on the rest of us.
    44. Re:This is a legal matter. by AK+Marc · · Score: 1

      Ah, so you admit you are a know liar, trying to waste the time of others. You could have saved time and posted that as your resume, rather than the lie about 18.5 years as a lawyer.

  3. Sue Them or Give Up by Schezar · · Score: 3, Insightful

    There is no technological solution. (The phone system as a whole is just so old).

    There is no human solution. (The other company will not bother).

    You have three options.

    1. Wait until it stops and ignore it
    2. Change your phone number
    3. Sue Level 3 for damages (and file a police report)

    In my professional (but not legal: I am not a lawyer) opinion, there is no way to resolve this sort of problem other than suing the closest legitimate business that links you to the perpetrators. Whoever is furthest downstream to the bad guys is your only target, and suing them is probably the only option. Maybe just to get a C&D, maybe punitively just in hopes of getting them to clean up their act. A police report on its own will have zero effect: the police just don't care about IT crimes on this scale.

    Sue them, and as part of it file a police report. Don't even bother with any other options at this point: they are not likely to work.

    (Again, not a lawyer, just an IT professional).

    --
    GeekNights!
    Late Night Radio for Geeks!
    1. Re:Sue Them or Give Up by sunderland56 · · Score: 4, Funny

      There is no human solution.

      Of course there's a human solution. My cousin Tony, from over there in East Jersey, he'll fix your problem right up with one visit. Your business, hey, it just needs a little protection.

    2. Re:Sue Them or Give Up by Anonymous Coward · · Score: 0

      As a side note, I have to say the whole IANAL stuff is incredibly stupid. It's a mandated dirty fix to people's stupidity and as European I find it amazing that any sane people would confuse online comments as legal advice from legal experts.

      I think your advice is mostly legal advice and I think it's good advice BUT I also recognize it as not advice from a legal expert. This is how normal people's brains should work (although $advice_quality may change depending on subjective opinions).

    3. Re:Sue Them or Give Up by Animats · · Score: 1

      There is no technological solution. (The phone system as a whole is just so old).

      No, it's the new part of the system that's broken. The big hole on caller ID is where VoIP enters the switched telephone network without cryptographic source identification.

      When caller ID was generated by physical wires strung through the holes of a Dimond ring translator (this was ROM, 1950s style), there was no way to spoof it from outside the central office.

    4. Re:Sue Them or Give Up by swb · · Score: 1

      My last boss was one of those people who end up an IT director because they run out of operations management roles to take and IT Director is somehow a step above facilities management in the operations hierarchy.

      Anyway, he worked at our local newspaper and when a major strike was planned including most of the unionized employees (from reporters to truck drivers), he happened to be on the management strike committee.

      They hired a private security company and one of the "products" on offer from the company were professional goons who would start fights and instigate violence among the strikers. The security company said the men were "indepdendent consultants" who couldn't be tied back to the security firm or the newspaper and were even willing to get arrested if necessary.

      I would believe at this point that similar "services" could be had from private security contractors with rolexes full of ex-special forces types willing to do a more physical form of conflict resolution. I'm sure somebody who knows something at L3 could be leaned on to provide information on the naughty customer who in turn could be persuaded to change their behavior, versus, say having their hands shattered with a ball peen hammer, which tends to preclude any kind of onoging technology career.

    5. Re: Sue Them or Give Up by Anonymous Coward · · Score: 0

      "I find it amazing that any sane people would confuse online comments as legal advice from legal experts."

      Frankly, I often find it amazing that anyone would confuse online comments on Slashdot with technical advice from technical experts, not just legal advice from legal experts.

    6. Re:Sue Them or Give Up by Anonymous Coward · · Score: 1

      >> contractors with rolexes full of ex-special forces types

      Rolodex, surely?

      What's the plural of Rolodex anyway? (ROLling inDEX)
      Rolodices?

    7. Re:Sue Them or Give Up by gstoddart · · Score: 3, Interesting

      There is no technological solution. (The phone system as a whole is just so old).

      There is no human solution. (The other company will not bother).

      And, as far as I can tell, there isn't really much of a legal solution either.

      See, the large companies who need to do callouts who got themselves some exemptions in the laws? They need to be sure that the people who call on their behalf show with their caller ID.

      So the "legitimate" companies need to be able to spoof their caller ID, and they don't want it to be illegal to spoof your caller ID.

      They, unfortunately, use the same kind of overseas call centers as are used in these scams. In some cases, I suspect the exact same call centers.

      So, the root cause issue here is that the big players pushed for exemptions in the law, to be sure they could have whatever call center they need call out as if it was from a given number. In effect, they legalized spoofing caller ID.

      That the shady players take advantage of that, and usually call from overseas locations where you'll never get the law to do anything ... well, that's the problem. But, this was predictable.

      I have my cordless phone set to drop any call which is Unknown or Private, I pretty much won't answer calls from 800 numbers, and I won't answer calls from numbers I don't recognize ... because they've made call display so useless as to be something you can't trust.

      I believe if it was made illegal to spoof caller ID, this could be stopped. But, the big players don't want it illegal to spoof caller ID, and the paid a lot of money for lobbyists to give them an exemption.

      Unfortunately, this same exemption now exists for the people running scams.

      Surprise!!

      Ever exemption in the Do Not Call list pretty much made the legislation toothless and useless. And this, is quite logically, the expected outcome.

      Once again, the exceptionalism by businesses means the laws surrounding this are pretty much useless.

      --
      Lost at C:>. Found at C.
    8. Re:Sue Them or Give Up by Dareth · · Score: 1

      So you are saying you are a lawyer, and this is valid legal advice. Gotcha!

      --

      I only look human.
      My mother is a halfling and my dad is an ogre, so that makes me an Ogreling
    9. Re:Sue Them or Give Up by AK+Marc · · Score: 1

      There's still no way to spoof it outside the CO. The difference is that the CO no longer cares. The CO is fully capable of setting CLID (and does so on the residential lines). But they choose to accept money to bypass protections on business lines. The CO effectively sets the CLID to the "requested" CLID. It's still the CO's fault. In this case, Level 3 for setting the CLID for the numbers based on the requested CLID.

      You no longer have to physically be in the CO, but you have to have the CO's permission and cooperation to do so.

    10. Re:Sue Them or Give Up by Cramer · · Score: 1

      There is no technological solution.

      There is, and always has been. With a simple POTS line, there's no means for the caller to manipulate anything -- it's all set by the serving switch. With ISDN (PRI and to some extent BRI), the caller was allowed to set CLID fields to indicate which "extension" is calling, ANI would be set by the switch to indicate the billing number for the line, however, your phone doesn't show ANI (even if it's a ISDN phone.) ISDN was expensive, so only a business would have them, and businesses could be trusted to not abuse the feature. That has worked out so well. :-)

      Every phone switch I'm aware of supports limiting what's allowed for CLID. It's obvious most (all?) telcos cannot be bothered to use this feature.

    11. Re:Sue Them or Give Up by Cramer · · Score: 1

      The CO (switch) never cared. Despite having the ability to check/reject CLID values, no one ever has. Today, with SIP and soft switches, it's even easier, and they still don't do it. (I bet your voip.ms personal account could send out whatever it wants -- not a cutomer, so I don't know.)

    12. Re:Sue Them or Give Up by Anonymous Coward · · Score: 0

      So, uh, the gotcha being you trying to be sarcastic by acting like an idiot as described by OP?

  4. Lawyer up by Anonymous Coward · · Score: 0

    Get your lawyers involved. Explain to Layer3 that they either absorb the consequences of blocking the number, or absorb the consequences of the damage their inaction is having on your reputation.

    As an online marketer your biggest asset is your reputation.

  5. Record an Apology by Anonymous Coward · · Score: 0

    Tell the caller you are sorry about the situation. Good Luck!!

    1. Re:Record an Apology by Anonymous Coward · · Score: 0

      Right, because it always sounds so sincere when a robot tells you its sorry.

    2. Re: Record an Apology by Anonymous Coward · · Score: 0

      That is the best solution.

      1) record a statement that there is a current phishing attack that refers callers to a reputable 1-800 number

      2) state clearly that your business will never request banking account numbers from it's customer base

      3) apologize to any existing customers to about the extraordinary situation, and please press #200 to be connected to an operator.

    3. Re: Record an Apology by Anne+Thwacks · · Score: 1

      You missed the bit about "Nuke from high orbit, just to be sure!"

      --
      Sent from my ASR33 using ASCII
    4. Re: Record an Apology by sumdumass · · Score: 1

      It might be wise to release a press statement warning of the scam in your points 1 and 2 and state that they are "cooperating" with regulators and authorities to catch the scammers.

      I put cooperate in quotes because trechnically it is true as long as it is reported to them whether they act or not.

      But it seems that one of the ways this works is the legitimate number being used to trick people. Well, if the news runs a story about it, that element goes away.

    5. Re: Record an Apology by j-beda · · Score: 1

      It might be wise to release a press statement warning of the scam in your points 1 and 2 and state that they are "cooperating" with regulators and authorities to catch the scammers.

      I put cooperate in quotes because trechnically it is true as long as it is reported to them whether they act or not.

      But it seems that one of the ways this works is the legitimate number being used to trick people. Well, if the news runs a story about it, that element goes away.

      This could actually work in your favour, as the resulting news coverage could increase your legitimate business, and put pressure on the enablers upstream to do something about it.

  6. Contact the FBI by skaag · · Score: 5, Insightful

    I suggest you contact the FBI and work with them. Why? Obviously the criminals are asking for banking information, and I can't imagine this being used for anything other than nefarious purposes. The FBI can sting them and locate the relevant bank accounts and freeze the money (in other words, give the scammers a kick in the balls). If you both get lucky, the FBI will actually catch the criminals and jail them.

    --

    All those moments will be lost in time, like tears in rain... time... to... die...

    1. Re:Contact the FBI by Anonymous Coward · · Score: 0

      That's a dumb idea for any number of reasons, number one being that the FBI isn't going to give a fuck about a case like this

    2. Re:Contact the FBI by Anonymous Coward · · Score: 0

      Bull...the FBI is gonna be all over this.

    3. Re:Contact the FBI by ganjadude · · Score: 1

      they could be terrorists trying to fund an operation (unlikely I know) in this fear induced country you would think the FBI would be all over that

      --
      have you seen my sig? there are many others like it but none that are the same
    4. Re:Contact the FBI by Anonymous Coward · · Score: 0

      Right, which is why the submitter is asking Slashdot for help on this....

    5. Re:Contact the FBI by Anonymous Coward · · Score: 0

      Is that you Bennett?

    6. Re:Contact the FBI by Anonymous Coward · · Score: 0

      They would not care about attempted wire fraud? How about the USPS?

    7. Re:Contact the FBI by SeaFox · · Score: 1

      Don't be silly. The comment was too short.

  7. How can faking a call back number be remotelylegal by RichMan · · Score: 2, Interesting

    Looking at the US today, how can providing an incorrect call back number not lead immediatly to an FBI investigation?

    Sure the general police don't really care because they don't understand this, but this is "interfereing with the operation of computer network" (yes the phone system does count as a computer network) and the phone network is a vital civil infrastructure. We know from past things interfering with a computer network, even a small scale private one, can actually lead to very serious charges. The phone networks is much more important (than some universities database accesses).

  8. Caller ID spoofing by buckfeta2014 · · Score: 1

    In the same fashion that ISPs should be using Source Path Verification, TelCos shouldn't be allowing their its users to change (or cause) their Caller ID to something that's not their phone number. Petition the government to force ISPs and TelCos to clean up their act.

    --
    Buck Feta. You know what to do.
    1. Re:Caller ID spoofing by Todd+Knarr · · Score: 4, Informative

      The problem is that there's a lot of legitimate reasons to "forge" the caller ID information. Many companies use a group of lines for outbound calls, any outbound call simply grabs the next available outbound line and uses it for the call. You don't want people calling in to those numbers though, there's no way for anyone to pick up a call on them since they don't go to an actual phone, so you set the caller ID to the correct inbound number for people to call (eg. the company's main number, or the main sales number (that gets distributed to the next available sales agent) or whatever number matches the type of outbound call) so callbacks go to the right place. And no the obvious solution won't work since the correct inbound number may not be with the same provider as the outbound line so you can't check whether the caller ID number's owned by the same entity that owns the line in use.

    2. Re:Caller ID spoofing by Strider- · · Score: 2

      Sure, but you can verify that the ANI (originating number) belongs to a block that the customer is allowed to use. I have a PRI with two 100 blocks associated with it. I would expect that the telco would verify that the originating number I send to the switch is taken from those 200 valid numbers, if only in case someone calls 911 etc...

      --
      ...si hoc legere nimium eruditionis habes...
    3. Re:Caller ID spoofing by Anonymous Coward · · Score: 0

      About 8 years ago I spoofed an ANI as a co-worker's number; knowing his wife was an at-home mother. Telco didn't give 2 craps what number I shoved down the line.

      Sadly, above mentioned co-worker didn't even notice the number come across his phone so the joke was on me.

    4. Re:Caller ID spoofing by Ichijo · · Score: 1

      And no the obvious solution won't work since the correct inbound number may not be with the same provider as the outbound line

      To me, the obvious solution is to route the calls that originate from a different provider through the provider that has the outbound line, similar to the way VPNs work.

      --
      Any sufficiently unpopular but cohesive argument is indistinguishable from trolling.
    5. Re:Caller ID spoofing by Anonymous Coward · · Score: 0

      WUT. Is the telephone system really this backwards that it can't differentiate between what the computer industry would call a mac address and an IP address? It should be trivial to limit a given trunk line to a given subset of phone numbers. Allowing it to make up whatever number it wants is a recipe for disaster.

    6. Re:Caller ID spoofing by Anonymous Coward · · Score: 0

      Changing CID is normal day to day operation for many businesses. For example if you own 5 DID lines, 2 are 800 and 3 are local, and you run a sales promotion, your trunk lines calling for the promotion can be changed for the local market by the company for each internal phone in the phone bank placing calls.

      A Night Attendant operation center can change CID on the fly by the account that was called. For example an office night attendant handeling reservations for all the hotels in town can call you back as Hilton, Holiday Inn, Ramada Inn, Motel 6, etc and display the normal business number for those customers. Tech support in India does this on a regular basis when they call you back.

      Preventing normal rental night phone staff in a call center would be broken if this fix was put into place.

    7. Re:Caller ID spoofing by Anonymous Coward · · Score: 0

      You know, the rest of the (civilized) world doesn't have these problems. It always amazes me when I read news concerning how technically crappy the US phone system is. Are you totally incapable of copying something that works over there? All those function are perfectly available around here as well, but you have to contact the phone company for those, because why the fuck would they let you mess with the system?

    8. Re:Caller ID spoofing by Tyr07 · · Score: 1

      Actually, you're kind of wrong in my opinion.

      You don't have to use your real name if you don't want to, except where law requires it, such as the government.

      You can sign up for services using an assumed name if you wish. You cannot provide false government identification though, false drivers license, false social insurance number, those are illegal. You can live in a town with assumed names, use that to talk to people, setup email accounts using them, generally for any reason, like privacy.

      However - you cannot do it for fraudulent purposes. If you use a false name to commit a crime or fraud, it's a federal crime.
      E.G Spoofing your caller ID is okay. Spoofing your caller ID to fraudulently represent another company to steal information for more potential fraud, is illegal. Then just spoofing your caller ID on it's own, is illegal.

      It's a matter of intent or purpose. E.G Driving a car down a street isn't illegal if you have a license and own it. However, driving someone elses car that you have stolen down the street without a license will get you hit for multiple crimes / fines. Driving without a license, fine. Even though "driving" E.G "Faking caller ID" isn't illegal on it's own.

    9. Re:Caller ID spoofing by buckfeta2014 · · Score: 1

      Don't care. I'm tired of calling India when I'm trying to reach my ISP/TelCo/CableCo/etc/etc/etc.

      --
      Buck Feta. You know what to do.
    10. Re:Caller ID spoofing by Slashdot+Parent · · Score: 1

      Sure, but you can verify that the ANI (originating number) belongs to a block that the customer is allowed to use.

      Not sure how far you want to go with that or where it should be enforced. But it probably would have prevented a use case that I used a few months ago. When I transferred my phone number from Verizon to a VoIP provider, Verizon was taking its sweet time authorizing the port. While Verizon sat on it, my VoIP provider spoofed my Verizon number on CID so that I could at least have my outgoing calls appear to come from my correct number, and I forwarded my Verizon calls to my temporary VoIP number.

      If that made any sense. Anyway, there was no real way for my VoIP provider to prove that it was authorized to set that number as CID. But they did it, and it made my life easier during the switch.

      --
      They don't grade fathers, but if your daughter's a stripper, you fucked up. --Chris Rock
  9. Divert the calls to level 3 by Anonymous Coward · · Score: 0

    Just divert all the incoming calls to level 3 helP desk. Then that will get their attention and a quick resolution
    Should only have to do it for one or two days. If your business can't handle loosing two days of call backs you have other problems!

    1. Re:Divert the calls to level 3 by almondo · · Score: 2

      While the Rambo style vigilante response option sounds good on the surface (and don't get me wrong, my natural response would be along these lines if it were not for the legal implications) the problem is that when you do this, you are now violating the same regulations as they are and you are arguably by definition "retaliating" which stacks even more regulatory violations on your illegal response. They have a bus full of overpaid lawyers ready to swoop on you if you "attack" them. For this reason I strongly recommend against this type of response even though the BOFH in me would very much like to employ it.

    2. Re:Divert the calls to level 3 by Anonymous Coward · · Score: 0

      predictable reply, though thank you for pointing out where I was right! (focusing on the positive)

      FYI, last I checked, tampering with the information integrity of public computer systems was a federal crime. On top of this the OP asked the question because his business's integrity is being damaged by it so there are likely monetary damages involved so on top of a crime being committed, there is at least a tort against a business with monetary damages.

      You are right (Admittedly) that the "file criminal charges" and "filing cease and desist letters" is not the whole solution, but until the identity of the guilty party is known the question would be, what clear actions on the part of the OP were taken to resolve the situation? These questions will be asked once the authorities get involved (and mark my words, they will!) It helps the OP's case if they take all the corrective actions that they can take within the bounds of the law.

      As for your comment about me being cute and adorable in my "innocent beliefs" about using the law to effect a solution when a crime is committed and there are damages, as opposed to "eye for an eye" style revenge against a party that is very likely not even directly involved, but just not helpful in resolving the issue, Some people do not ever get wiser with age as you have demonstrated. I don't have to read your mind when the between the lines misconceptions about "the way things are" that older conservatives tend to have especially when they have reached a level of mediocre success, you are very transparent. You are right that people tell me that I am "cute" but not in the way I think you meant (I sincerely hope! /protecting corn hole)

  10. At the risk of seeing insensitve to your plight .. by Anonymous Coward · · Score: 0

    .. (I am not, really!)

    If the scammer is really hitting all of the DC metro area. Maybe if he p*sses off enough gubment types, they'll do more to put a stop to phone fraud (yeah, I know they do a lot now. How's that working out?)

  11. Legitimate Marketing Traffic by Anonymous Coward · · Score: 0

    I love how OP tosses out the term "legitimate marketing traffic."

    Really, OP? REALLY? If it's truly legit, just change your number and tell about the scammers and the change. Do that, and this problem will disappear overnight.

    1. Re:Legitimate Marketing Traffic by tysonedwards · · Score: 3, Informative

      Yes, because making new marketing materials, distributing updated business cards and getting everyone involved to stop using the old number and separate the old number from the company is *such* an easy task and can happen overnight!

      The phone number of a presumably reputable business that parties would likely recognize for their Caller ID number is a social engineering trick to get around one of the roadblocks and make people subconsciously overcome one of their answers to why this is a scam. Any act at this point is damaging the brand of the business, whether they capitulate and change their number, or whether the scamming entity continues to portray themselves as the company in question.

      Let's change this a little bit and put a name to these calls... What if instead of "unnamed company", it was "Google" that had someone using their corporate phone number to do these calls? What about "Amazon", or "Microsoft", or "Apple", or "Cisco", or the "FBI"? Would your opinion about "just change your phone number" be the same?

      --
      Thirty four characters live here.
    2. Re:Legitimate Marketing Traffic by Anonymous Coward · · Score: 0

      My response would be "Wait, Google/Amazon has a phone number? When the hell did that happen?"

  12. Write your Congressman/Senator by david.emery · · Score: 2

    I contacted Senator Warner's office about this, and frankly was blown off. That being said, I think we need a -law- that requires the Telcos to work out how to make Caller ID unforgeable. I've been challenged to 'show the RFCs and related standards that would support this,' but since the industry has shown no interest in solving the technical problems, I reluctantly believe that it'll take legal action (either law, regulation or legal liability) to force the issue.

    On a related note, I also asked about the impact of all those CallerID violations I've filed over the years, and got no response back from that. In both cases, I was forwarded a letter from the FCC that basically quoted from their website.

    1. Re:Write your Congressman/Senator by Zarjazz · · Score: 1

      I thought the majority of voice circuits in the US were restricted to the callerid they could display? Only certain VoIP services and carrier level interconnects would allow you to set anything you wanted?

    2. Re:Write your Congressman/Senator by Anonymous Coward · · Score: 0

      I think we need a -law-

      Caller ID spoofing is already illegal. Maybe if we pass a couple more laws and make is super duper triple illegal it will magically fix the problem.... More laws! Yea!

    3. Re:Write your Congressman/Senator by Jaime2 · · Score: 1

      I worked at a call center with an analog PBX and a whopping staff of fifty, with four T1's for connectivity. One day I was testing some telephony integration of the software I maintained and had the system call my cell phone. The caller ID came up with the four-digit extension of the caller. It turned out that we could set anything as the caller id number.

    4. Re:Write your Congressman/Senator by Anonymous Coward · · Score: 0

      Your Congressman is more apt to be of help (on any issue) than any Senator. The nature of the problem means, however, that there is little which can be done from that office.

      I would suggest contacting the FCC, FTC, and your state Attorney General. Of the three, the AG is probably going to be the one who makes an effort on your behalf.

  13. Re:How can faking a call back number be remotelyle by Anonymous Coward · · Score: 0

    The FBI doesn't have enough cybercrime agents to deal with stuff like this

  14. How did you "talk" to level 3? by Lumpy · · Score: 1

    It should have been a lawyer demanding the resolve it immediately or they are liable for fraud. They know it's illegitimate but until slapped with a lawsuit they don't give a rats ass.

    Level3 is one of the shadiest ones, they do nothing until a lawsuit is threatened.

    --
    Do not look at laser with remaining good eye.
  15. High dollar litigation with the FCC is effective by almondo · · Score: 5, Informative

    In the past I have had to deal with L3 on some similar nonsensical "our abusive users are not our problem" crap. As you have already observed, they have a well refined hearing problem. First, decide how much the per call impact is to your business in your opinion. Estimate the number of calls per day and multiply by the per call rate and then by the number of days to come up with a daily and sum "rate of damages". Then have a lawyer letter drafted and sent to their legal department and make sure the letter shows that you also sent a copy of the draft to the FCC Attn: Fraud & Abuse at 445 12th Street SW, Washington, DC 20554.

    In about the time it takes you to go to lunch, the problem will subside. At L3, FCC copied abuse resolution rolls down hill, pretty fast.

  16. Re:How can faking a call back number be remotelyle by guruevi · · Score: 1

    The same reason they don't go after people that fake the e-mail headers to be referring to legitimate domains, including the USPS and their own (fbi.gov) I get on a regular basis. There is no profit for them to investigate and it only affects small business and individuals.

    --
    Custom electronics and digital signage for your business: www.evcircuits.com
  17. Stupid PSTN by Anonymous Coward · · Score: 1

    You can't really do much of anything. The calling party number can be set to whatever the caller wants - the only technical controls to prevent this would be for ALL carriers to enforce some sort of whitelist, which they don't do.

    VoIP makes this problem much worse as it is trivial to buy/steal a new "SIP trunk" account. Since the traffic is IP the source of the traffic can easily be obscured behind a VPN provider or compromised system. Even if you get Level3 to suspend the account they will likely have a new one spun up in minutes. Even if you get Level3 to divulge the identity of the perpetrator, it is likely fake. Even if you managed to trace it back to the source, they are likely operating out of a country without any useful/enforceable laws. These folks are professional scam artists, they know how to get away with this.

    Since Level3 operates most of SIP media gateways in the US, it is not surprising that this is the source of the fraud. Many / most SIP trunk providers just contract with them to provide the actual service.

    I would suggest putting a greeting message on your toll free number explaining the situation, that should help to filter out much of the impact to your actual business. Perhaps just make it the first option off of the menu tree. Depending who calls this toll free number you may be able to only play this message for numbers that have never called before or for numbers in/not in a particular area code.

    Given that toll free numbers are cheap, buy another one and point it to the same destination. On everything new publish the new number, that way in a year when folks google the toll free number they don't get a bunch of scam reports.

    Also the damage to your business is likely minimal, short of driving up your phone bill and wasting folks time.

    As for suing Level3, the scammer will likely move onto something new well before that yields anything useful.

    The Truth in Caller ID Act of 2009 might also be interesting reading, but getting it enforced it likely impossible.

    Good luck, and sorry the PSTN sucks...

  18. Level3 by Anonymous Coward · · Score: 0

    I've been tracking down the phony calls I've been getting via 'white pages' source and a lot of them if not all of them are from Level3.

    Funny, huh?

  19. Turn it to your advantage by roman_mir · · Score: 2, Insightful

    You are looking at it all wrong, those people that are calling you are all potential customers of your business. Offer to them something they are looking for: satisfaction. They are calling you to complain. Sell them something, like a way to kick ass of somebody, who you can present as the guy that placed that call they are complaining about. I am sure many would give you their money for some type of a moral satisfaction. Learn to sell, life gives you a lemon, make lemonade.

    1. Re:Turn it to your advantage by stephanruby · · Score: 1

      You are looking at it all wrong, those people that are calling you are all potential customers of your business. Offer to them something they are looking for: satisfaction. They are calling you to complain. Sell them something, like a way to kick ass of somebody, who you can present as the guy that placed that call they are complaining about. I am sure many would give you their money for some type of a moral satisfaction. Learn to sell, life gives you a lemon, make lemonade.

      Scammers also sell anti-scam services. Personally, I would be even more suspicious of someone who wanted to help me and sell me something to get back at those scammers.

    2. Re:Turn it to your advantage by Anonymous Coward · · Score: 0

      Yes, sell them guns so they can shoot somebody as a pain relief. 100% libertarian solution.

  20. notifications are done by ihtoit · · Score: 2

    bring out the guns. Interim injunction with two options: Level3 disables the number and the forwarding or they're shut down, end of. Second barrel: Level3 discloses the identity of the subscriber. Third barrel: arrest warrant on the subscriber for wire fraud (in some jurisdictions this is an offence one step down from mail robbery).

    --
    Political debates have me rolling my eyes so much I think I got optical whiplash. I should sue. - Foamy The Squirrel
  21. VoIP is the whole problem by King_TJ · · Score: 2

    Traditional land lines have the caller ID information generated at the phone company's central office, based on who is paying the bill for the circuit.
    Unless you're planning on hacking into their computers - it's not really changeable.

    The problem lies with all the VoIP based phone systems out there. These days, there are probably more phone lines using VoIP than traditional copper lines.

    The VoIP systems don't even have a way to tell emergency 911 operators what your correct address is. You're expected to provide the right one to go with the number you receive (often with the ability to do that yourself with a self-service web based control panel). So yes, the caller ID information is also controlled by the VoIP server -- and anyone running their own can do as they please with it.

    1. Re:VoIP is the whole problem by Megane · · Score: 1

      You can hang a caller ID box on your line and watch the kind of crap that comes in. Usually they try to make a "real" phone number, only it's in an area code you've never heard of. But some of them give shit like "123-4567" or just "1" or "---------------" for the phone number. Also fun are the ones that set the name to "NEW YORK" or "FLORDIA". I can just imagine Cletus from the Simpsons saying "Well gawwwawleee we've got us a call from NOO YARK!"

      The insidious ones are like mentioned in TFS, where they use an actual number that's not theirs, often picked at random. I heard of one case where they used the phone number of some little old lady in Boston, who of course got all the backscatter from the phone spammers.

      And of course most people on the receiving end of the junk calls have no clue that the CNID could ever possibly lie to them.

      --
      #naabhaprzrag, #sverubfr-000, #agi-fcbafberq, negvpyr[pynff*=' negvpyr-ary-'] { qvfcynl: abar !vzcbegnag; }
    2. Re:VoIP is the whole problem by Anonymous Coward · · Score: 0

      Better yet (aside from the numbers that are all zeros), I started getting several calls a day from one of the non-public office numbers of my insurance agent. After I answered the first time, and found it was the "Rachel" scammer with the "last chance for Prez O's economic stimulus" loan consolidation, I called my agent's office to ask if any of their other clients were getting such calls. When told they had not heard of such, I told them, OK, just do not try calling me from this particular number in your range in the future, because I added it to my answering system's block list (have filled all the slots it can hold with similar such...).

      Then, I started getting my own home phone number with my own name showing on the caller Id for these calls, so I added my own number to the block list - crazy! Hoping to move soon to an area where I will have to get a new landline number (and yes, I want to keep one for 911 accuracy and power outages as I get older and more decrepit, and not depend on cellular or cable digital with their issues), and be more diligent about not listing it any more. We have had the current number since the early 90's when this was almost unheard of, and listing one's home number was more a courtesy than an exposure.

    3. Re:VoIP is the whole problem by nblender · · Score: 1

      Around here (Canada) there's a long-running scam perporting to be a local airline (WestJet)... I get a few of these calls a week on either my cellphone or the landline at work... They always spoof the caller ID with the first 6 digits of the phone number they're calling. ie: if they're calling 780-656-1234, the spoofed caller-id will be "780-656-xxxx" where "x" is random. If they're calling "250-684-1234", the spoofed caller-id will be "250-684-xxxx"... The automated recording is the same in all cases. So it _looks_ like a local call and it's tempting to answer it...

  22. Longstanding Flaw in CallerID by SkiTee94 · · Score: 1

    Unfortunately it's fairly trivial to make the caller ID say just about whatever you want--especially if you are running your own system. There's no form of reverse lookup verification to check if a call is really coming from where it says it's coming from. There are some legit uses for this (eg our office setup always shows the main switchboard as he called ID even if people are calling from a specific line) but it's all to easy to abuse if someone is intent on doing so.

  23. Not Copyright by Etherwalk · · Score: 5, Insightful

    >Hehe, so in this case a Slashdotter thinks you should be able to get details without a court order, but when the RIAA or MPAA wants details its a completely different situation...

    Yes. Most Slashdotters recognize that the penalties for noncommercial copyright violation are ridiculously disproportional to the crime and have limited economic impact, and might support something small (like a $50 ticket that doesn't leave anyone with a criminal record or entry in any system) but will generally side with pirates against content-creators when you are looking at $10,000 per title, criminal penalties, dealing with the legal system, or really anything more than a slap on the wrist.

    On the other hand, when someone is responsible for crimes that are much more universally recognized as deserving of criminalization, and as an actual pain in the ass, they are much more willing to support substantial actions against that person--and more, to preserve the reputation and business of the people being significantly harmed.

  24. No free market solution by Anonymous Coward · · Score: 0

    This is at its core the result of the corporate laser focus on short term profit. There is currently little or no cost to telcos and ISP's to take any action to reduce this type of fraud. Never mind the incessant cry of persons with certain political leanings, the market will not solve this. This is a case where regulatory accountability is needed. Currently the telco's content that there is nothing they can do about spoofing. I suspect that if they named considered co-conspirators in a few criminal fraud prosecutions and fined heavily, they would start to take affirmative action (all the while using their paid mouthpieces to complain about "overreach") Only when the cost of doing nothing exceeds the cost of preventing this fraud, will there be any action.

  25. Re:Sue Them or Give Up? No. Kill them. Messily. by Anonymous Coward · · Score: 1

    Exactly. Spammers (and scammers) will continue to do what they do until they start dying for doing it.

  26. Don't fight it, use it. by Anonymous Coward · · Score: 2, Interesting

    Contact the local police and/or the FBI, advise them that you have evidence of an identity theft ring, and provide them the information you have. They will open a case. Get the case number.

    Instruct your call center that, when people call and complain, that there is a known fraudster who is spoofing caller ID records, and provide them the case number and the phone number to whoever is assigned the case.

    The people who are calling you are understandably angry. Help them focus that anger on the right place by a.) acknowledging they have a reasonable complaint, b.) acknowledging you're aware of the issue, and c.) having them direct their complaint to someone who can actually help resolve it.

  27. subpoena by BradMajors · · Score: 1

    You can obtain the identity of this party with a subpoena. It is not difficult to obtain one.

  28. Do you really have the scammer's number? by laughingskeptic · · Score: 2

    You do realize that the phone number that you think you have for the scammer is also likely spoofed? These guys are probably sitting in India or Kenya.

    1. Re:Do you really have the scammer's number? by Anonymous Coward · · Score: 0

      why india ? whats india has to do with this ? grow up guys ... you are getting spoofed by some one and just because you dont know the scammer, you are blaming india for it ? not cool mr slashdotter not cool at all :(

    2. Re:Do you really have the scammer's number? by Anonymous Coward · · Score: 0

      Because most of this shit comes from India, Kenya, Russia, China, Indonesia or Brasil. Why do you get annoyed if people point out facts of life?

    3. Re:Do you really have the scammer's number? by Anonymous Coward · · Score: 0

      why india ? whats india has to do with this ? grow up guys ... you are getting spoofed by some one and just because you dont know the scammer, you are blaming india for it ? not cool mr slashdotter not cool at all :(

      EVERY scam call I've ever gotten has been from someone very obviously in India. "Grow up" and realize that there's a reason India is the first place people think of when it comes to phone scammers.

  29. Automated Message by Anonymous Coward · · Score: 0

    That's all you need to fix this. Send your legal team to deal with the spoofing issue on the backend, on the front end, you force an automated pre-connect message to play before they are put into the call queue to speak to someone.

    Legal can slap it together for you and run it through marketing tomorrow morning and you can have it going in an hour.

  30. "(I sincerely hope! /protecting corn hole)" by Anonymous Coward · · Score: 0

    So many things wrong with your world view. Don't know where to start.

  31. We don't have to care. We're the Phone Company by Anonymous Coward · · Score: 0

    We contacted the registered provider of the scammer's phone number, Level3, but they haven't been able to resolve the issue yet...

    Nor will they until you start legal proceedings against them. Once paperwork has been filed with a court you would be surprised how quickly this issue will be resolved

  32. Follow the money by thogard · · Score: 1

    When someone calls your 1-800 number, you pay someone. That someone gives a cut of it to other parties. One of those parties may have picked your number for a reason. This can work in a way that is similar to the "False Answer Signalling" fraud that was so common years ago .

  33. Update your website and move on by Kittenman · · Score: 2

    Put a comment on your website mentioning that someone out there is using your company's name and number for callbacks, and tell your customers to be aware of this issue.
    You can't be liable for their gullibility, any more than you can for the actual actions of the Nigerian scammers (or whoever they are).

    An Ancient Greek said "If people speak ill of thee, act so that no-one will believe them". I'd say that's still valid.

    --
    "The greatest lesson in life is to know that even fools are right sometimes" - Winston Churchill
  34. Sue immediately by Anonymous Coward · · Score: 2, Interesting

    Ignore nickel and dime lawyers who talk to you about "writing letters". That will accomplish nothing (except making a few bucks for useless, couch potato lawyers).

    You have already been damaged so you have a tort. You should be suing immediately. Note that you do not actually need a lawyer to sue, just the cooperation of the executive officer of your company. Get a paralegal (or anybody with a brain) to find a lawsuit template and file a John Doe lawsuit with the local county court (you can always file a federal lawsuit later, if needed). Also, even if your original lawsuit is incompetently written, it does not matter, because you can emend it later.

    The advantage of filing the lawsuit is that you can get subpoenas (and even bench warrants) from the court once your lawsuit exists. This is what you need to solve the problem. Your first subpoena is easy: demand the name of the John Doe who is screwing you from L3. Telcos have very efficient systems for dealing with such subpoenas. Some even have web forms you can use to request the info.

    You should also issue a subpoena designed to find out if L3 knew of, or in any way assisted, the criminal activities of the defendant. If you can prove they assisted in the tort, you can add them to the lawsuit. as defendants, which would be good, because they probably have a lot more money than the perps.

    Trust me, the way to get action in a situation like this is to get your butt to the county court pronto and start legal action. Most people have an irrational free of court houses, which is foolish and exactly why lawyers can prey on them. When you start acting like a lion instead of one of the lambs, trust me, you will get results FAST.

    1. Re:Sue immediately by Anonymous Coward · · Score: 0

      You should also issue a subpoena designed to find out if L3 knew of, or in any way assisted, the criminal activities of the defendant.

      Of course they know about the criminal activity. The victim informed them, and L3 choose to do nothing (thus assisting in further criminal behaviour).

  35. Talk to Fraud by Anonymous Coward · · Score: 1

    Level 3 is a large company and should have a dedcated fraud department that deals with this type of issue. Did you talk to them directly? If not I would contact them and place your complaint.

  36. Half empty / Half Full by Anonymous Coward · · Score: 0

    People are calling your business. Sounds like free advertising at least. Get it on the news, play the victim. Puts your name out there.

  37. Re:How can faking a call back number be remotelyle by Anonymous Coward · · Score: 0

    The FBI doesn't have enough cybercrime agents to deal with stuff like this

    And they have been "re-tasked" to chase "terrorists" rather than fight crime.

  38. C&D and an injunction by Anonymous Coward · · Score: 0

    This is where a cease and desist letter with a TRO on the ready is necessary. Call up your legal counsel and he should be able to draft it very easily. This is something that is very detrimental to business and using the right legal means to take care of these things deters others from attempting it later. Nothing scarier than an attorney and a judge.

    -David

  39. You're pretty much out of luck by kilodelta · · Score: 1

    Because with a BRI circuit - you can pump any CLID down the line that you want. Hell, that isn't even necessary. I know a few years ago a simple PERL script made the rounds and a MagicJack could be used for the nefarious spoofing.

  40. You imply that you have the scammer's phone number by Anonymous Coward · · Score: 0

    First, yes, you should go after both the scammer and Level 3 by hiring a lawyer.

    But more importantly, if in fact you have the scammer's real phone number then...
    Give THAT number on your answering machine as the correct number to all the people calling and claiming about it.
    Or even set up an "If you are calling about the scam artists, press 3 to be redirected to their actual phone number."

  41. How are these calls being redirected to you? by dowens81625 · · Score: 2

    Tim,

    You say these calls are being forwarded to your call center. Help me clarify how this behaving,

    A) Company XYZ (Scammer)
            Buys a trunk from Level 3 and sets the CID to your 1800?
            Calls everyone in DC, and they call the number on their CID

    B) Company XZY (Scammer)
            Buys a trunk and from Level 3 and sets the CID to one of their own numbers
            Calls everyone in DC, They receive a call and forwards the call over SIP to your IP Address and call center.

    C) Company XYZ (Scammer)
              Buys a trunk and from Level 3 and sets the CID to one of their own numbers
              Calls everyone in DC, They receive a call and forwards call back out over their trunk to the PSTN (Public Switch Telephone Network) to one of your 1800s

    D) Something else ?

    A) - Legal action is required as it is a violation of FCC regulations. And I would report the issue to them and let the FCC handle them.
    B) - Put in a firewall rule or VOIP rule based off the source IP Address sending you calls to either not accept them or to forward them to a honey pot or back off site to say Level 3s CEOs personal cell phone get creative.
    C) - a bit more difficult depending on if they forward the callers CID info or their own CID info for the trunk. in either case you can contact your LEC and ask them to block traffic intended for your 1800 number from that call trunk (this can be done regardless of CID) but you will need to get fairly high up the engineer Ladder to a good Central Office Engineer

           

  42. alls ya gottta do is... by Anonymous Coward · · Score: 0

    spoof the scammers number, calling the white house or somebody else very important that doesn't take shit........ ....you should be able to fill in the rest, yah know?

    someone should show up at the scammarz location to straighten them out very soon after that.

  43. Passwords by Anonymous Coward · · Score: 0

    Is the password on the VOIP phone(s) set to the default password, and directly accessible by IP? If so, anyone can get the credentials needed to spoof.

  44. Block vishing calls and more info by Anonymous Coward · · Score: 0

    I wish there was a simple technical solution. It is very easy with SIP and a free PBX such as Asterisk to spoof the calling number AND ANI. I can't figure out a benefit to spoofing your number for the voice phishing (vishing) calls, but I suspect the attacker does that because if they keep using the same number, a service like Nomorobo, which has excellent semi-static blacklists, will block many of the calls to the target consumers. You might want to contact Nomorobo to make sure your number gets on their blacklist and then maybe the attacker will stop using it quicker. Nomorobo is designed for home VoIP phones and I don't know if they work with the common VoIP/cable providers in the area being attacked.

    If I am right, the calls will stop in time. I know that is little consolation.

    I offer this because I don't think you will have much success with the service providers or even the FBI. Folks at the FCC care and there is work in the standards community - check out STIR - (Secure Telephony Identity Revisited), but none of this will help you any time soon.The FTC is getting aggressive with these issues, but they mainly try to help out consumers. You might try them, but again, that isn't a quick solution.

    There are technologies that detect spoofed calls to your 1-800 numbers, but that isn't your issue - the calls you are getting have legitimate numbers, just from confused consumer targets.

    I wrote a book - Hacking Exposed:VoIP and UC, which has a chapter on spoofing calling number/ANI and these sorts of attacks.I will send you a copy. It might provide some useful background - email mark.collier@securelogix.com

  45. Re:Sue Them or Give Up? No. Kill them. Messily. by RockDoctor · · Score: 1
    Well, I wouldn't go directly to murder.

    Removal of fingers, ears, external genitalia, in approximately that order. Lots of unsubtle anal rape with a cattle prod. Come on guys - you've got professionals doing this stuff for your government. It's not rocket science (though you can use pyrotechnics, if you want to be showy). Just good old torture. And you need to communicate to the spammers to make sure that they know their children, siblings or parents are paying for their actions.

    --
    Birds are not dinosaur descendants;birds are dinosaurs, for all useful meanings of "birds", "are" and "dinosaurs"
  46. I totally forgot about it by Anonymous Coward · · Score: 0

    I was about to say that this practice might even have some constitutional problems, but then I kind of remembered the UK doesn't even have a constitution because they're a monarchy. Fix that first since this is, after all, the 21st century we live in.