Custom Search
Showing posts with label phishing. Show all posts
Showing posts with label phishing. Show all posts

August 07, 2017

Nigerian Citizen Living in North Carolina Arrested for Phishing Scheme Targeting Connecticut and Minnesota School Districts


Nigerian citizen Daniel Adekunle Ojo was arrested last week at his residence in Durham, North Carolina.  He is being charged with fraud and identity theft charges filed by Connecticut U.S. Attorney Deirdre Daly.  

According to prosecutors, an employee of the school district in Glastonbury, Connecticut was duped by a phishing scam which Ojo was allegedly behind.  A phishing scam is one where an e-mail that appears to be legitimate asks for private information or asks the recipient to log into an account via a link in the e-mail that leads to a fake site.  Any information obtained via a phishing e-mail can then be used to commit financial crimes.

In the scam in this case, Ojo allegedly spoofed the e-mail address of one school employee to make it appear that that school employee had e-mailed the duped school employee requesting tax information for approximately 1600 school district employees.  Not realizing that the e-mail was not legitimate, the school employee provided the requested information, which was then allegedly used to file 122 bogus tax returns for nearly $600,000.00 in tax refunds.

At least six of the fake tax returns were successful, resulting in $37,000 in refunds being electronically deposited into various bank accounts.

It is also believed by authorities that Ojo is not a first time phisher.  Ojo's e-mail address is allegedly linked to a phishing scam in Bloomington, Minnesota earlier this year and that he may have been involved in a similar phishing scheme that targeted the school district in Groton, Connecticut.

A federal magistrate judge has ordered that Ojo be transferred to Connecticut for prosecution.

My advice on phishing:  Never, ever, ever click a link in an unsolicited e-mail even if it looks like it legitimately came from a company with which you do business.  Phishers used to be easy to spot due to their poor grammar and odd phrasing used in their e-mails.  But they have gotten better and thus less easy to spot.  So think hard before you click.

December 02, 2009

H1N1 identity theft e-mail phishing scam

As if the swine flu virus wasn't bad enough, now identity thieves are using it to their advantage.  Scammers are using e-mails offering a "Personal H1N1 Vaccination Profile".  The e-mail scam appears to come from the Center for Disease Control and actually uses a pretty good (but still fake) version of the U.S. Department of Health and Human Services logo. 

The e-mail tries to dupe the reader into clicking on a link to a separate site, ostensibly to set up a profile containing the reader's name, contact details, and personal medical history.  A screen shot of the picture is below:




The website has several links that all will download a file which probably contaisn some malicious code which would do Lord knows what to your computer.  The virus would probably include code to obtain your personal information from your computer.

Although the Web address in the e-mail link appears to be operated by CDC.gov (the agency's Web site), a hidden portion of the address indicates that the site is actually in Belgium.

July 03, 2009

More about id theft via social networks

Speaking of using common sense to protect your identity, here's a quote from an article with some advice about what not to put on your online profile:

"BE CAREFUL about what you include in your profile on social-networking sites as the information could lead to identity theft.

According to a study by British software-security firm Webroot, one third of social networkers have at least three pieces of information visible on their profiles that could expose them to identity theft, PC World reported.

The study found that 59 per cent of Britons are unsure of who can see their profile, while 78 per cent have profiles that are visible in a Google search.

These are in spite of 78 per cent of them saying they worry about the privacy of information put up on their social-networking sites, such as Facebook and MySpace.

According to PC World, the study found that 36 per cent of respondents said they did not hide any of their personal information from people viewing their profiles. Twenty-eight per cent said they accepted 'friend requests' from strangers.

And what about passwords? A third of them said they used the same passwords for all of their online accounts.

Mr Mike Kronenberg, chief technology officer of Webroot's consumer business, told PC World: 'The growth of social networks presents hackers with a huge target. The amount of time spent on communities like Facebook last year grew at three times the rate of overall Internet growth.'

Mr Kronenberg added that users of social-networking sites should protect themselves by being aware of such risks, as well as how not to expose themselves to such threats."

For the original article, see - http://digital.asiaone.com/Digital/Features/Story/A1Story20090630-151742.html

Identity theft and Facebook

Identity thieves are using Facebook to steal personal information. Below is part of an article appearing on Reuters UK:

"Cybercrime is rapidly spreading on Facebook as fraudsters prey on users who think the world's top social networking site is a safe haven on the Internet.

Lisa Severens, a clinical trials manager from Worcester, Massachusetts, learned the hard way. A virus took control of her laptop and started sending pornographic photos to colleagues.

'I was mortified about having to deal with it at work,' said Severens, whose employer had to replace her computer because the malicious software could not be removed.

Cybercrime, which costs U.S. companies and individuals billions of dollars a year, is spreading fast on Facebook because such scams target and exploit those naive to the dark side of social networking, security experts say.

While News Corp's (NWSA.O) MySpace was the most-popular hangout for cyber criminals two years ago, experts say hackers are now entrenched on Facebook, whose membership has soared from 120 million in December to more than 200 million today.

'Facebook is the social network du jour. Attackers go where the people go. Always,' said Mary Landesman, a senior researcher at Web security company ScanSafe.

Scammers break into accounts posing as friends of users, sending spam that directs them to websites that steal personal information and spread viruses. Hackers tend to take control of infected PCs for identity theft, spamming and other mischief."

As always, the best advice to avoid having your identity stolen is to use your common sense and not fall for scams. Not that common sense alone will prevent your identity from being stolen but it will help protect you from phishers such as those referenced by this article. For the rest of the article, see http://uk.reuters.com/article/idUKTRE55T6KU20090630.

June 27, 2009

Cybercrime on the rise

This is a quote from an article prepared by the law office of Howard Snader and appearing on http://www.24-7pressrelease.com/press-release/as-cybercrime-increases-so-do-law-enforcement-efforts-105662.php.

"Cybercrime is on the rise. The Internet Crime Complaint Center (IC3) reports that cybercrime increased in 2008. Moreover, IC3 reports that from February to March 2009 there was an additional 50 percent increase in reported Internet fraud complaints. With this increase, law enforcement agencies are stepping up enforcement efforts and offenders face steep penalties for conviction.

Federal officials from the Federal Bureau of Investigation (FBI) and Department of Justice (DOJ), which are responsible for investigating and prosecuting cybercrime, are increasing efforts to find and punish alleged perpetrators of Internet fraud and other computer crimes such as hacking and phishing. These agencies, along with the US Postal Inspection Service and US Secret Service are aggressively prosecuting data breaches in which hackers steal large amounts of personal information from financial institutions, government agencies, credit card companies and other businesses.

In fact, between 2004 and 2008, there was a 138 percent increase in identity theft convictions by United States Attorneys. In addition, fighting computer crime is a priority for the new administration. President Obama recently announced that he would appoint a cybersecurity czar who would be tasked with overseeing the fight against cybercrime.State and local law enforcement agencies are also ramping up efforts to prosecute cybercriminals.

The Arizona Attorney General has a computer crimes unit that is dedicated to fighting crimes involving technology. Further, many local police departments have developed and improved strategies for tracking computer crimes. For example, the Phoenix Police Department has a Document Crimes Detail that investigates identity theft, phishing and other Internet scams."

June 14, 2009

Another phishing scam

The Pennsylvania Attorney General is warning about another phishing scam. Phishing is where identity thieves or other criminals try to get you to give them your private information (i.e. Social Security number, date of birth, etc.) so they can then use it to steal the consumer's identity or sell it to someone willing to steal the identity. This new scam involves text messages or automated calls to cell phones.

"Attorney General Tom Corbett urged consumers to be watchful for scam text messages or automated calls on their cell phones and urged consumers to never divulge personal information in response to an unsolicited message. Corbett explained that the Attorney General’s Bureau of Consumer Protection has been receiving a steadily increasing number of complaints about unwanted cell phone text messages – often claiming to be from consumers’ banks or credit card companies.

'These bogus ‘security alerts’ typically warn consumers that their bank or credit card account has been compromised and requests that they send a reply message or call a toll-free number to correct the problem,' Corbett said. 'Consumers who call the scam number are often asked to ‘confirm’ their account number, password or PIN – leaving them vulnerable to fraudulent charges or identity theft.'

Corbett noted that identity thieves are always looking for ways to disguise their scheme and reach out to new potential victims – especially young people, who are much more likely to use text message services. Messages that appear to come from banks, credit card companies or other legitimate businesses are the latest tools that thieves are using to trick consumers into giving up vital personal information. Corbett added that consumers are also reporting a growing problem with unwanted 'spam' text messages. These messages are typically unsolicited ads for prescription drugs or pornography and can be costly for consumers, who may be charged fees ranging from $.10 to $.50 per message that they receive.

Corbett offered the following tips for consumers interested in preventing unwanted 'spam' or scam text messages:

- Be careful when asked for your telephone number. Giving your phone number in response to contests or online promotions can lead to unwanted calls and messages.

- Never respond to unsolicited text messages – it only lets the sender know they’ve reached a working number and may lead to more messages in the future.

- If your wireless provider bills you for unsolicited messages, contact them and ask them to remove the charge or give you a credit for those fees.

- If your cell phone company will not waive fees for unsolicited text messages, file a complaint with the Attorney General’s Bureau of Consumer Protection.

- If you do not wish to receive any text messages, consider asking your cell phone provider to block all text message services for your phone.

- Report messages that are deceptive, offensive or advertise illegal products or services."

The rest of the article can be found here - http://www.gantdaily.com/news/11/ARTICLE/54229/2009-06-14.html.

June 05, 2009

New phishing scam

What is "phishing", you might ask? According to wikipedia.org, it is "the criminally fraudulent process of attempting to acquire sensitive information such as usernames, passwords and credit card details by masquerading as a trustworthy entity in an electronic communication."

The way it works is that you receive what looks like an e-mail from a trusted source, i.e. a bank, the IRS, etc. that says there is some problem (or in the case of the IRS, an unclaimed tax refund) and asks you to log in with your user name and password, which the phisher then steals. Or you could be asked to call a number and give your name, Social Security number, etc. to what you think is a legitimate business. Unfortunately, its not and you have just given away your private information.

I read an article this morning about a new phishing scam that's preying on the growing number of people looking for jobs. The articles says "FlexJobs, the leading website for legitimate telecommuting and online job listings, today cautioned jobseekers to beware of a new phishing email scam targeting jobseekers. This most recent email phishing scam involves asking jobseekers to fill out a credit report in order to gain access to the final interview stage for a job. The phishing email includes a link to a 'free credit report' that the employer has arranged for the jobseeker's convenience. Scammers are taking advantage of the high unemployment rate to contact people by email with deceptive offers for interviews and jobs. "

FlexJobs also warns jobseekers (and anyone else) to look out for:
  • "Unsolicited emails.
  • Emails from supposed employers but using free email domains (e.g., @yahoo.com, @gmail.com, @aol.com, or @hotmail.com) instead of one related to the company domain name.
  • Emails from individuals or companies the jobseeker does not recognize, especially if the emails include links to click on for more information or to proceed with the job application process.
  • Requests for detailed personal information, especially social security numbers or financial account details, before a job interview has even taken place.
  • Required credit checks to prove interest in a job, or to get an interview."

To read the whole article, see http://www.prweb.com/releases/job/scam/prweb2501944.htm.