Showing posts with label cybercrime. Show all posts
Showing posts with label cybercrime. Show all posts

Monday, April 2, 2012

Online Crimes of Fake Soldier Go Unpunished



By the time Cari Johnson caught wind of a Lebanon (OHIO) man’s online scam, victims in California, Connecticut and Texas already had sent him laptop computers, keys to their homes, personal photos and care packages they believed were headed to American soldiers serving overseas.

But the case of James E. Middleton, 47, of Ohio, demonstrates problems with cybercrime investigations, which cross multiple federal and state jurisdictions and present other dilemmas for investigators used to fighting land-based crimes. As a result, authorities have declined to pursue criminal charges against Middleton even though he admitted to scamming people.

“Where did this occur? It’s not like somebody broke into your house and you can take fingerprints,” said Sgt. Jeff Mitchell of the Lebanon Police Department, which declined to charge Middleton.

Confronted in January by his victims and a police investigation, Middleton said he took responsibility for his misdeeds and blamed his actions on loneliness and agoraphobia, and the companionship and calming effects he gained in relationships built over more than a year with victims nationwide.

He tricked donors into believing he was three different soldiers, including a female. He has since returned some of the items or reimbursed his victims. “Maybe it’ll help somebody else to realize how something that starts out so small can go so totally out of whack,” Middleton said in an interview with the Dayton Daily News.

The FBI’s Cybercrime Division is the top U.S. law enforcement agency charged with fighting online scams. Cases like Middleton’s rank far below a long list of FBI priorities topped by protecting the country from terrorists attacks, foreign intelligence operations and espionage, cyber-based attacks and high-technology crimes.

“Is ( Middleton’s case) going to be something the FBI can devote its resources to? Probably not,” Washington-based FBI spokeswoman Jenny Shearer said. The inadequacy of the existing cybercrime law enforcement is the focus of continued global discussion.

In January, the United Nations Office on Drugs and Crime convened a meeting of international experts in Austria “with a view to examining options to strengthen existing and to propose new national and international legal or other responses to cybercrime.” In America, the FBI works with National White Collar Crime Center, a non-profit organization that tracks cybercrime rates and teaches law enforcement officials the latest techniques. The center and FBI, in partnership with the U.S. Bureau of Justice Assistance, formed the Internet Complaint Call Center about 10 years ago.

“What is unique about Internet crime is that a perpetrator can live in one state and perpetrate a crime in many other states. They cross jurisdictional boundaries,” said spokesman John Everett with the National White Collar Crime Center. Criminal justice in cyberspace Lebanon police said they were unable to prosecute Middleton, in part because the victims lived in three other states. A federal postal inspector said Middleton’s alleged crimes did not involve the U.S. mail system.

“It really irks me that nothing can be done,” said Johnson, who runs A Dollar to Care, a charity for soldiers and their families, from her home in Riverside. Her son, Dominic Johnson, is a military policeman with the Ohio National Guard. Middleton lives with his teenage daughter, and they share a personal computer. During an interview at his apartment, he said he had learned his lesson. “If I ever felt the want to do that, I would just get rid of my computer,” he said.

Multiple false soldier identities In a case involving a California victim, Middleton acted as a fictitious female soldier, Amy Anderson. For a Texas woman, he was soldier, Michael Wolfe. For a Connecticut woman, he was soldier Jason “Thumper” Hayes. In all three cases, Middleton had the victims send him care packages, believing he would get them to their special soldier through his fake connections at Wright-Patterson Air Force Base. Middleton met his victims in chat rooms on JustinTV.com, a website where people can post videos and pictures, request and listen to music, and engage in real-time chats.

Middleton said he began entering the chat rooms as fictitious soldiers to get noticed. “In my heart I knew I was wrong but I thought if I entered the room as a soldier it would be better and more people would want to talk to me,” he said in a statement to police.

Jennifer Schmitz of San Antonio, Texas, said she fell in love with soldier “Wolfe” after online communications and receiving love letters actually written by Middleton during a two-year period. “This was someone I put my life on hold for,” she said in a telephone interview. Acting as Wolfe, Middleton said he encouraged Schmitz to send him care packages and wrote her love letters. When Schmitz confronted Middleton by phone, “he said actually, ‘I’m in love with you,’” she said.

Middleton usually favored pretending to be “Thumper” when he communicated with Sheila O’Leary in Connecticut. However, she said Middleton pretended to be 21 different soldiers, as well as himself, during more than a year of contact. “I talked with all of them,” O’Leary said. “This was not his first time doing this.”

Middleton’s third victim, a California man whom he duped to believing he was a female soldier, declined to comment. Johnson said she became aware of Middleton through friendships she built online with the victims. She said her charity has a network of more than 5,000 soldiers and military supporters. Standing up for soldiers “Ninety-five percent of my postings, everything I type, usually is centered around the military or veterans,” she said. Johnson discovered Middleton was using photos of people in uniform to bolster his fake identities. “That’s what really made my blood boil,” she said. Johnson said Middleton should have been charged with crimes, including the Stolen Valor Act, a federal law that bars individuals from falsifying their military service. The law is in limbo due to constitutional challenges in three states.

Johnson said she is concerned that Middleton and others who get away with their scams will continue their alleged cybercriminal activities. ‘If they’re successful and they don’t get caught, what’s going to stop them?” Johnson said. “You can go online and pretend you are whatever or whoever you want to be.” Lebanon police said their investigation was hobbled by the advanced state of the case when Johnson notified them. “Mr. Middleton and these people pretty much had it worked out between themselves before we caught up,” Mitchell said.

Middleton said he began the scam following the deaths of his mother and other relatives. He said he was driven by loneliness that fed the agoraphobia he has suffered from for 16 years. “I started out, oddly enough, as a female,” he said. “It just absolutely snowballed.”

Middleton said his only military experience was when he twice failed to complete basic training at Fort Dix Army base in New Jersey. He also learned military terminology aiding him in pretending to be a soldier from family members. “I’ve had family members in almost every branch except the Coast Guard,” he added.

Since these incidents, Middleton said he goes online only to check the weather and look at maps. He said he no longer visits social networking sites. “I don’t enjoy the computer anymore,” he said, adding that new medication is helping deal with his mental issues. Still Middleton said he felt he deserved to be punished. “That part I still have no answer to,” he said. “How do you morally repay someone?”

Thursday, September 22, 2011

E-Stalkers On the Prowl

by Rizanuzzaman Laskar

While conventional stalking has received much attention lately, harassment through mobile phones and the internet has grown to be a silent epidemic in the last few years.

The Daily Star has recently interviewed 30 women at random about the issue, and found every one of them has been harassed electronically by ex-boyfriends or strangers.

"It is sexual harassment of the new millennium," said Sultana Kamal, rights activist and former adviser to the caretaker government. “And almost all the victims are women."

Kamal said the anonymity of the electronic communication devices makes it more likely for a person to indulge in stalking. “Some people are turning to these tools to do and say things they otherwise would not do.

The women interviewed were middle and upper class professionals, students and a housewife.

One was a schoolgirl who spent sleepless nights because of crank calls; another was an industrialist's daughter who stumbled across obscene pictures and her personal details on a Facebook profile someone else had opened in her name.

Naima Hossain, a college student, was taunted and teased over the phone for a week by a person she had never met. The stalker, who asked her out several times, threatened to throw acid on her face for refusal.

"That they [stalkers] do not have a face makes it even more traumatic for the victims," said Shamim F Karim, a psychology professor at Dhaka University.

Getting stalked by someone the victim knows can be no less unnerving.

Shamrin Afia Adiba, a BBA student, knew her stalker. For three years, she got taunting phone calls almost every hour.

About the nightmare she had gone through, she said it felt like her life was being slowly poisoned.

The stalker, a jilted male friend working at a telecom operator, used her cellphone number to track her location in real time. He let her know he was watching her, and threatened several times to kidnap her.

Switching to a different operator did not help, as he managed to trace Shamrin's new number through a friend working there.

While no statistics are available to confirm the number of electronic stalking victims, social experts point out that almost every woman using a mobile phone or the internet has suffered abuse at one time or another.

From January to July this year, 44 women reported harassment to the cyber crime prevention cell of the police's detective branch. In response, the police have blocked 46 SIM cards.

The law enforcers however admit that blocking SIM is not enough, as most people own multiple numbers, and a new subscription is only some cash away.

They said the existing laws appear toothless when it comes to fighting e-stalking, as some of them are more than a hundred years old.

Mustafizur Rahman, officer-in-charge of the New Market Police Station, said, "The laws require us to know the stalker's identity to take action against him. This is a major problem since in many cases the perpetrator remains unidentified."

Supreme Court lawyer Nina Goswami, director (mediation) at Ain O Salish Kendra, the rights group which has received two cyber-stalking cases this year, stresses the need for a law against cyber crimes.

"It is difficult to take action against the stalkers as there is no specific law,'' said the lawyer, herself a victim of mobile phone harassment.

A proposed act to curb cellphone-related crimes and harassment promises some respite. The draft law defines stalking, both physical and digital, as sexual harassment, and prescribes punishment.

Experts, however, fear the new law may prove ineffective, as most of the stalking incidents tend to go unreported.

Arifa Hossain says she perhaps knows why victims are reluctant to complain to the police. She went to the local police station to report abusive phone calls but thought better of it.

"You won't expect much from the cops once you see how they fumble with the mouse and eye the computer as if it's an alien thing."

A police representative admitted there is a lack of tech-savvy officers needed to hunt down high-tech criminals. He said this is a reason why the detective branch's cyber crime cell, set up in 2008, exists in name only.

Exceptional cases, however, receive special attention from the police. When a youth posted offensive materials on Facebook to taunt politicians in May, he was arrested within days and the whole social networking website was banned for a week.

"Banning an entire website is out of the question. But there should be some sort of a law or policy to safeguard our young women," said Dr Muhammad Zafar Iqbal, a professor at Shahjalal University of Science and Technology.

Experts believe fear of social stigma is another reason why victims are loath to file complaints with the police.

"Forget police, women do not tell anyone about being harassed for fear of being stigmatised," said Shamim F Karim, psychology teacher at DU. "Women, especially those in the city, have become somewhat accustomed to harassment in everyday life."

She suggested that anyone experiencing harassment over the phone or the internet should inform her family members immediately. "The family members can go to the police if necessary."

She noted that some young women, who are actually unaware that they are being subjected to a form of sexual harassment, try to laugh off the matter.

Some do not.

Trisa Gloria Rodriguez, for one, has been receiving irritating phone calls for some time. The stalker calls from different numbers and makes loud smooching noises.

She tried to reason with him, but it did not work. Yelling did not bring result either.

"Disgusting. I feel like kicking him,” says an irate Trisa

Friday, July 1, 2011

South Carolina Man Sentenced for Internet Harassment

James Robert Murphy, 38, of Columbia, South Carolina, was sentenced to 5 years of probation, 500 hours of community service, and more than $12,000 in restitution today for two counts of Use of a Telecommunications Device (the internet) with Intent to Annoy, Abuse, Threaten or Harass.



Murphy was indicted in April 2004, for sending harassing emails to Seattle resident Joelle Ligon and to other employees of the City of Seattle. He pleaded guilty to two counts in June 2004. In sentencing Murphy, U.S. District Court Judge Thomas Zilly told Murphy he "...did not demonstrate the type of remorse he should under the circumstances."



In his plea agreement, Murphy admitted he had a sporadic romantic relationship with Ligon from 1984-1990. In May of 2002, Murphy began sending dozens of uninvited and harassing emails and facsimile (fax) messages to Ligon and her co-workers. Murphy hid his identity with special email programs and created the "Anti Joelle Fan Club" (AJFC) and repeatedly sent threatening emails from this alleged group.



Murphy disseminated false information about Ligon's background to her co-workers. The harassment escalated over time, with Murphy sending pornographic material and making it appear that Ligon was sending the pornographic material to her co-workers at the City of Seattle.



Even after Ligon was able to identify the person harassing her and get a court order barring contact, Murphy violated the order by sending an email denying he was the harasser.




No Remorse From Murphy

In court, Murphy told the Judge what he did was "stupid, hurtful and just plain wrong. I was going though a bad patch in my life. I want to take my lumps and get on with life."



In sentencing Murphy Judge Zilly noted that he was surprised that Murphy "made no effort to indicate your remorse to the victim, to indicate you were sorry." The Judge noted that he had received a letter from Joelle Ligon unlike any he had ever received from a crime victim.



In it Ligon asked the Judge to impose "an effective and compassionate sentence." Judge Zilly decided to impose 500 hours of community service instead of the 160 hours requested by the government. He ordered Murphy to pay $12,297.23 to the City of Seattle to compensate the City for 160 hours of work time lost by employees dealing with the harassment.



Task Force Targets Cyber Crime

This case was investigated by the Northwest Cyber Crime Task Force, composed of the FBI, United States Secret Service, Internal Revenue Service, Seattle Police Department, and Washington State Patrol. The NWCCTF investigates Cyber-related violations including criminal computer intrusions, intellectual property theft, child pornography and internet fraud.



The Task Force brings federal, state and local law enforcement agencies together to share intelligence and conduct joint investigations. Assistant United States Attorney Kathryn A. Warma is prosecuting the case.

South Carolina Man Sentenced for Internet Harassment

James Robert Murphy, 38, of Columbia, South Carolina, was sentenced to 5 years of probation, 500 hours of community service, and more than $12,000 in restitution today for two counts of Use of a Telecommunications Device (the internet) with Intent to Annoy, Abuse, Threaten or Harass.



Murphy was indicted in April 2004, for sending harassing emails to Seattle resident Joelle Ligon and to other employees of the City of Seattle. He pleaded guilty to two counts in June 2004. In sentencing Murphy, U.S. District Court Judge Thomas Zilly told Murphy he "...did not demonstrate the type of remorse he should under the circumstances."



In his plea agreement, Murphy admitted he had a sporadic romantic relationship with Ligon from 1984-1990. In May of 2002, Murphy began sending dozens of uninvited and harassing emails and facsimile (fax) messages to Ligon and her co-workers. Murphy hid his identity with special email programs and created the "Anti Joelle Fan Club" (AJFC) and repeatedly sent threatening emails from this alleged group.



Murphy disseminated false information about Ligon's background to her co-workers. The harassment escalated over time, with Murphy sending pornographic material and making it appear that Ligon was sending the pornographic material to her co-workers at the City of Seattle.



Even after Ligon was able to identify the person harassing her and get a court order barring contact, Murphy violated the order by sending an email denying he was the harasser.




No Remorse From Murphy

In court, Murphy told the Judge what he did was "stupid, hurtful and just plain wrong. I was going though a bad patch in my life. I want to take my lumps and get on with life."



In sentencing Murphy Judge Zilly noted that he was surprised that Murphy "made no effort to indicate your remorse to the victim, to indicate you were sorry." The Judge noted that he had received a letter from Joelle Ligon unlike any he had ever received from a crime victim.



In it Ligon asked the Judge to impose "an effective and compassionate sentence." Judge Zilly decided to impose 500 hours of community service instead of the 160 hours requested by the government. He ordered Murphy to pay $12,297.23 to the City of Seattle to compensate the City for 160 hours of work time lost by employees dealing with the harassment.



Task Force Targets Cyber Crime

This case was investigated by the Northwest Cyber Crime Task Force, composed of the FBI, United States Secret Service, Internal Revenue Service, Seattle Police Department, and Washington State Patrol. The NWCCTF investigates Cyber-related violations including criminal computer intrusions, intellectual property theft, child pornography and internet fraud.



The Task Force brings federal, state and local law enforcement agencies together to share intelligence and conduct joint investigations. Assistant United States Attorney Kathryn A. Warma is prosecuting the case.

Thursday, February 17, 2011

Internet Fraud Dupes Men More Often Than Women

by Robert McMillan

When it comes to being taken in by Internet fraudsters, men have a knack for losing cash, according to a new report from the Internet Crime Complaint Center.

Data compiled from more than 206,000 complaints received last year by the U.S. Internet Crime Complaint Center (IC3.gov) shows that men lost US$1.67 to every $1 lost by women in online fraud.

Identifying Fraud Trends
The IC3 is the clearinghouse for online crime complaints in the U.S., and its database is used by regulators and law enforcement to get a picture of criminal trends and, in some cases, help hunt down the criminals. It is a joint effort run by the U.S. Federal Bureau of Investigation and the National White Collar Crime Center.

The organization says that buying patterns and human nature play into the findings.
"Historically men were more apt to purchase large ticket item like electronics... that could explain a lot of it," said John Kane, the IC3 research manager who wrote the report.
But with women now spending more online, the difference is also due to the fact that certain types of schemes seem to suck men in. "Men tend to fall victim... to business investment schemes and some other schemes that have a higher dollar loss," Kane said.

Investment fraud complaints, where the average loss is more than $3,500, were overwhelmingly submitted by men, Kane said. Compare that to something like auction fraud, where both men and women are frequently victimized. The average loss there is just over $480.

Men also tend to be the victims of check fraud (average loss: $3,000) and Nigerian letter fraud scams ($2,000), Kane said.
Crime Climbs

Overall, Internet crime is netting the bad guys more money than ever.

Total losses from 2007 complaints came to $239 million, up $40 million from 2006.

The 2007 data, released Thursday, shows that the total number of complaints received by the group was actually down for the second year in a row. In 2007 the IC3 Web site logged just under 207,000 complaints. In 2005 that number was over 231,000.

Kane credited the drop in complaints to increased consumer awareness, but according to Gary Warner, director of research in computer forensics with the University of Alabama at Birmingham, there may be another explanation.

Warner spends a lot of time studying the criminals and said that in recent months, researchers have noticed that credit card numbers have often been stolen and then not used. "One theory is that nobody wants to go to jail for stealing $40," he said. "So when they get access to these accounts, they're using only the ones that they can get the most value from."

Often, criminals will do a balance check and then sell only the cards with the highest balances. "I think there's a little bit of filtering on the criminal side that's at play here," he said.

There was another interesting finding in the 2007 data. The IC3 found that many countries that were commonly linked with cybercrime were the sources of the incidents it tracked, but it did not list China as a top source of perpetrators. China has been named as the source of many online attacks over the past year, but it didn't make IC3's list of top 10 countries by perpetrators.

Leading the list were the U.S., the United Kingdom and Nigeria.

SOURCE

Internet Fraud Dupes Men More Often Than Women

by Robert McMillan

When it comes to being taken in by Internet fraudsters, men have a knack for losing cash, according to a new report from the Internet Crime Complaint Center.

Data compiled from more than 206,000 complaints received last year by the U.S. Internet Crime Complaint Center (IC3.gov) shows that men lost US$1.67 to every $1 lost by women in online fraud.

Identifying Fraud Trends
The IC3 is the clearinghouse for online crime complaints in the U.S., and its database is used by regulators and law enforcement to get a picture of criminal trends and, in some cases, help hunt down the criminals. It is a joint effort run by the U.S. Federal Bureau of Investigation and the National White Collar Crime Center.

The organization says that buying patterns and human nature play into the findings.
"Historically men were more apt to purchase large ticket item like electronics... that could explain a lot of it," said John Kane, the IC3 research manager who wrote the report.
But with women now spending more online, the difference is also due to the fact that certain types of schemes seem to suck men in. "Men tend to fall victim... to business investment schemes and some other schemes that have a higher dollar loss," Kane said.

Investment fraud complaints, where the average loss is more than $3,500, were overwhelmingly submitted by men, Kane said. Compare that to something like auction fraud, where both men and women are frequently victimized. The average loss there is just over $480.

Men also tend to be the victims of check fraud (average loss: $3,000) and Nigerian letter fraud scams ($2,000), Kane said.
Crime Climbs

Overall, Internet crime is netting the bad guys more money than ever.

Total losses from 2007 complaints came to $239 million, up $40 million from 2006.

The 2007 data, released Thursday, shows that the total number of complaints received by the group was actually down for the second year in a row. In 2007 the IC3 Web site logged just under 207,000 complaints. In 2005 that number was over 231,000.

Kane credited the drop in complaints to increased consumer awareness, but according to Gary Warner, director of research in computer forensics with the University of Alabama at Birmingham, there may be another explanation.

Warner spends a lot of time studying the criminals and said that in recent months, researchers have noticed that credit card numbers have often been stolen and then not used. "One theory is that nobody wants to go to jail for stealing $40," he said. "So when they get access to these accounts, they're using only the ones that they can get the most value from."

Often, criminals will do a balance check and then sell only the cards with the highest balances. "I think there's a little bit of filtering on the criminal side that's at play here," he said.

There was another interesting finding in the 2007 data. The IC3 found that many countries that were commonly linked with cybercrime were the sources of the incidents it tracked, but it did not list China as a top source of perpetrators. China has been named as the source of many online attacks over the past year, but it didn't make IC3's list of top 10 countries by perpetrators.

Leading the list were the U.S., the United Kingdom and Nigeria.

SOURCE

Sunday, January 24, 2010

Dark Market


To the casual observer, there was little to distinguish the Java Bean internet cafe in Wembley from the hundreds of others dotted around the capital. But to surveillance officers staking it out month after month, this unremarkable venue was the key to busting a remarkable and sophisticated network of cyber criminals.

From the bank of computers inside, a former pizza bar worker ran an international cyber "supermarket" selling stolen credit card and account details costing the banking industry tens of millions.

Renukanth Subramaniam, 33, was revealed today as the founder and a major "orchestrator" of the secret ­DarkMarket website, where elite fraudsters bought and sold personal data, after it was infiltrated by the FBI and the US Secret Service.

Membership was strictly by invitation. But once vetted, its 2,000 vendors and buyers traded everything from card details, obtained through hacking, phishing and ATM skimming devices, to viruses with which buyers could extort money by threatening company websites.

The top English language cybercrime site in the world, it offered online tutorials in account takeovers, credit card deception and money laundering. Equipment – including false ATM and pin machines and everything needed to set up a credit card factory – was available.

It even featured breaking-news-style updates on the latest compromised material available, while criminals could buy banner adverts to promote their wares.

So vast was its reach, with members in the UK, Canada, US, Russia, Turkey, Germany and France, the UK's Serious Organised Crime Agency (Soca), which helped bust it, said it was "impossible" to put a figure on how much it cost banks worldwide.

Subramaniam, who used the online soubriquet JiLsi, was remanded in custody at his own request at Blackfriars crown court today after pleading guilty to conspiracy to defraud and five counts of furnishing false information. Judge John Hillen warned it was "inevitable" he faced a "substantial custodial sentence".

A Sri Lankan-born British citizen, Subramaniam was a former member of ShadowCrew, DarkMarket's forerunner, which was uncovered by the US Secret Service in 2004. "JiLsi was one of the highest in cybercrime in this country with what he managed to achieve setting up a forum globally. No JiLsi, no DarkMarket," said one Soca investigator.

Its 2,000 members never met in real life. Quality, not quantity, was the key. DarkMarket was fastidious in banning "rippers" who would cheat other criminals. Honour among thieves was paramount.

It operated an "escrow" service, with payments and goods exchanged through a third party – "like a PayPal for criminals", the judge observed, and an arbitration service resolved disputes. To keep off the radar, the rules were strict: no firearms, drugs or counterfeit currency.

Built on a pyramid structure, administrators decided who joined, moderators ran specific site sections, and reviewers vetted wannabes – each demanding 5% or £250 per transaction as a fixer's fee.

To get on, criminals had to present details of 100 compromised cards free of charge - 50 to one reviewer, 50 to another. Reviewers would test the cards and write an online review of customer satisfaction – just like eBay customers. "If the cards did what they were supposed to … they would be recommended. If not they weren't allowed in," said the investigator.

Payment was via accounts on WebMoney, or E-Gold. "It was the QuickTime method of sending money anywhere."

Subramaniam was one of the top administrators. He kept his operating system on memory sticks. But when one was stolen, costing him £100,000 in losses and compromising the site's security, he was downgraded to reviewer. Surveillance officers caught him logging on to the website as JiLsi unaware the fellow criminal MasterSplyntr he was talking to was, in fact, an FBI agent called Keith Mularski.

Considerable money was exchanged, though actual transactions took place away from the site for security reasons. One buyer spent £250,000 on stolen personal information in just six weeks.

Described as "a very quiet man", Subramaniam worked at Pizza Hut and as a dispatch courier. "He owned three houses but was largely itinerant," said Sharon Lemon, Soca deputy director. "The key to investigations of this sort is finding the evidence to connect the online persona with a living, breathing person."

Harendra de Silva QC, defending Subramaniam, said the "evidence was unchallenged" but said the "question of interpretation does arise in certain areas" and there would be submissions on "nuance" of the fraud in so far as it applied to his client. He is charged alongside John McHugh, 66, known as Devilman, also a site reviewer who has pleaded guilty to conspiracy to defraud and at whose Doncaster home officers found a credit card-making factory. The two will be sentenced later.

But the battle against cybercrime continues. "This was one of the top 10 sites in the world, but there are more than 100 we know of globally, and another 100 we don't yet know of," said the investigators.
In the DarkMarket

DarkMarket price list

Trusted vendors on DarkMarket offered a smorgasbord of personal data, viruses, and card-cloning kits at knockdown prices. Going rates were:

Dumps Data from magnetic stripes on batches of 10 cards. Standard cards: $50. Gold/platinum: $80. Corporate: $180.

Card verification values Information needed for online transactions. $3-$10 depending on quality.

Full information/change of billing Information needed for opening or taking over account details. $150 for account with $10,000 balance. $300 for one with $20,000 balance.

Skimmer Device to read card data. Up to $7,000.

Bank logins 2% of available balance.

Hire of botnet Software robots used in spam attacks. $50 a day.

Credit card images Both sides of card. $30 each.

Embossed card blanks $50 each.

Holograms $5 per 100.

Dark Market


To the casual observer, there was little to distinguish the Java Bean internet cafe in Wembley from the hundreds of others dotted around the capital. But to surveillance officers staking it out month after month, this unremarkable venue was the key to busting a remarkable and sophisticated network of cyber criminals.

From the bank of computers inside, a former pizza bar worker ran an international cyber "supermarket" selling stolen credit card and account details costing the banking industry tens of millions.

Renukanth Subramaniam, 33, was revealed today as the founder and a major "orchestrator" of the secret ­DarkMarket website, where elite fraudsters bought and sold personal data, after it was infiltrated by the FBI and the US Secret Service.

Membership was strictly by invitation. But once vetted, its 2,000 vendors and buyers traded everything from card details, obtained through hacking, phishing and ATM skimming devices, to viruses with which buyers could extort money by threatening company websites.

The top English language cybercrime site in the world, it offered online tutorials in account takeovers, credit card deception and money laundering. Equipment – including false ATM and pin machines and everything needed to set up a credit card factory – was available.

It even featured breaking-news-style updates on the latest compromised material available, while criminals could buy banner adverts to promote their wares.

So vast was its reach, with members in the UK, Canada, US, Russia, Turkey, Germany and France, the UK's Serious Organised Crime Agency (Soca), which helped bust it, said it was "impossible" to put a figure on how much it cost banks worldwide.

Subramaniam, who used the online soubriquet JiLsi, was remanded in custody at his own request at Blackfriars crown court today after pleading guilty to conspiracy to defraud and five counts of furnishing false information. Judge John Hillen warned it was "inevitable" he faced a "substantial custodial sentence".

A Sri Lankan-born British citizen, Subramaniam was a former member of ShadowCrew, DarkMarket's forerunner, which was uncovered by the US Secret Service in 2004. "JiLsi was one of the highest in cybercrime in this country with what he managed to achieve setting up a forum globally. No JiLsi, no DarkMarket," said one Soca investigator.

Its 2,000 members never met in real life. Quality, not quantity, was the key. DarkMarket was fastidious in banning "rippers" who would cheat other criminals. Honour among thieves was paramount.

It operated an "escrow" service, with payments and goods exchanged through a third party – "like a PayPal for criminals", the judge observed, and an arbitration service resolved disputes. To keep off the radar, the rules were strict: no firearms, drugs or counterfeit currency.

Built on a pyramid structure, administrators decided who joined, moderators ran specific site sections, and reviewers vetted wannabes – each demanding 5% or £250 per transaction as a fixer's fee.

To get on, criminals had to present details of 100 compromised cards free of charge - 50 to one reviewer, 50 to another. Reviewers would test the cards and write an online review of customer satisfaction – just like eBay customers. "If the cards did what they were supposed to … they would be recommended. If not they weren't allowed in," said the investigator.

Payment was via accounts on WebMoney, or E-Gold. "It was the QuickTime method of sending money anywhere."

Subramaniam was one of the top administrators. He kept his operating system on memory sticks. But when one was stolen, costing him £100,000 in losses and compromising the site's security, he was downgraded to reviewer. Surveillance officers caught him logging on to the website as JiLsi unaware the fellow criminal MasterSplyntr he was talking to was, in fact, an FBI agent called Keith Mularski.

Considerable money was exchanged, though actual transactions took place away from the site for security reasons. One buyer spent £250,000 on stolen personal information in just six weeks.

Described as "a very quiet man", Subramaniam worked at Pizza Hut and as a dispatch courier. "He owned three houses but was largely itinerant," said Sharon Lemon, Soca deputy director. "The key to investigations of this sort is finding the evidence to connect the online persona with a living, breathing person."

Harendra de Silva QC, defending Subramaniam, said the "evidence was unchallenged" but said the "question of interpretation does arise in certain areas" and there would be submissions on "nuance" of the fraud in so far as it applied to his client. He is charged alongside John McHugh, 66, known as Devilman, also a site reviewer who has pleaded guilty to conspiracy to defraud and at whose Doncaster home officers found a credit card-making factory. The two will be sentenced later.

But the battle against cybercrime continues. "This was one of the top 10 sites in the world, but there are more than 100 we know of globally, and another 100 we don't yet know of," said the investigators.
In the DarkMarket

DarkMarket price list

Trusted vendors on DarkMarket offered a smorgasbord of personal data, viruses, and card-cloning kits at knockdown prices. Going rates were:

Dumps Data from magnetic stripes on batches of 10 cards. Standard cards: $50. Gold/platinum: $80. Corporate: $180.

Card verification values Information needed for online transactions. $3-$10 depending on quality.

Full information/change of billing Information needed for opening or taking over account details. $150 for account with $10,000 balance. $300 for one with $20,000 balance.

Skimmer Device to read card data. Up to $7,000.

Bank logins 2% of available balance.

Hire of botnet Software robots used in spam attacks. $50 a day.

Credit card images Both sides of card. $30 each.

Embossed card blanks $50 each.

Holograms $5 per 100.

Friday, October 30, 2009

Cost of CyberCrime in the U.K. = £390million (U.S. $646Million)


Businesses have been warned that internet crime is costing Wales around £390m a year.

The revelation comes as about 400 business leaders and experts gather for a summit to tackle the growing problem.

The event, organised by e-Crime Wales, brings together the assembly government, experts and police forces.

It says cyber crime can hit unlikely victims, like Nefyn and District Golf Club in Gwynedd, which was targeted by hackers from the former Soviet Union.

Criminals from ex-Soviet bloc countries such as Latvia and Estonia set their sights on the club on the Lleyn peninsula last year.

"What they were trying to to is hack into the computer system and steal data," explained Simon Dennis, the club secretary.

"We were somewhat shocked that organised crime, which in essence is what is behind these types of attacks, would target somewhere like Nefyn and District Golf Club.

"Initially, we thought it was somewhat of a hoax, whereby groups of youngsters etc, would be trying to break in to the system.

"But once we were able to back-check and validate the addresses, we found it was [coming] from the former Soviet Union - and that's when we really took the threat quite seriously."

The golf club managed to fight off the cyber attacks, without its data being compromised.

Danger signs
But dealing with the e-criminals came at a price. The club had to hire a computer specialist to beef up its technical security, landing it with a bill of more than £10,000.

It was a classic example of what can happen in the speedy world of electronic communications, according to e-crime Wales.
“ People are aware that there are problems out there, but I don't think they ever truly believe it is going to happen to them ”
Acting Det Sgt Andrea Barnard, e-Crime Wales

"I think the issue with the internet is who is responsible for what, in terms of safety, in terms of security, in terms of ownership," argued Simon Lavin, e-Crime Wales' strategic planning manager, who put the estimated cost of cyber crime at about £390m.

"If you use the analogy of road safety, I think we've all got used to it over the last 100 or so years that the car has been around.

"In terms of the internet, that's not clear at all.

"If you went in to town on a Friday night, you wouldn't walk down a dark alley, you recognise a dark alley as being dangerous.

"In the field of e-crime people don't recognise the danger signs."

In the push to get its message over, this year's e-Crime Wales summit is attracting speakers from the FBI, Interpol, and computer giant Microsoft.

It is also an opportunity for Wales' first e-crime police team manager to offer her advice.

'Stay safe'
Acting Det Sgt Andrea Barnard of North Wales Police recently took up the post, becoming a point of contact for businesses, the police and the assembly government.

"I think people are aware that there are problems out there, but I don't think they ever truly believe it is going to happen to them," she explained.

"Therefore they don't act, they don't take measures to protect themselves from e-crime.

"I would just like businesses in north Wales to be aware that e-crime can happen to anybody.

"But having said that - for them not to be totally frightened by that. Come and seek advice.

"Come and have a chat to us and we can explain the fundamentals of e-crime and how to stay safe."

original post here

Cost of CyberCrime in the U.K. = £390million (U.S. $646Million)


Businesses have been warned that internet crime is costing Wales around £390m a year.

The revelation comes as about 400 business leaders and experts gather for a summit to tackle the growing problem.

The event, organised by e-Crime Wales, brings together the assembly government, experts and police forces.

It says cyber crime can hit unlikely victims, like Nefyn and District Golf Club in Gwynedd, which was targeted by hackers from the former Soviet Union.

Criminals from ex-Soviet bloc countries such as Latvia and Estonia set their sights on the club on the Lleyn peninsula last year.

"What they were trying to to is hack into the computer system and steal data," explained Simon Dennis, the club secretary.

"We were somewhat shocked that organised crime, which in essence is what is behind these types of attacks, would target somewhere like Nefyn and District Golf Club.

"Initially, we thought it was somewhat of a hoax, whereby groups of youngsters etc, would be trying to break in to the system.

"But once we were able to back-check and validate the addresses, we found it was [coming] from the former Soviet Union - and that's when we really took the threat quite seriously."

The golf club managed to fight off the cyber attacks, without its data being compromised.

Danger signs
But dealing with the e-criminals came at a price. The club had to hire a computer specialist to beef up its technical security, landing it with a bill of more than £10,000.

It was a classic example of what can happen in the speedy world of electronic communications, according to e-crime Wales.
“ People are aware that there are problems out there, but I don't think they ever truly believe it is going to happen to them ”
Acting Det Sgt Andrea Barnard, e-Crime Wales

"I think the issue with the internet is who is responsible for what, in terms of safety, in terms of security, in terms of ownership," argued Simon Lavin, e-Crime Wales' strategic planning manager, who put the estimated cost of cyber crime at about £390m.

"If you use the analogy of road safety, I think we've all got used to it over the last 100 or so years that the car has been around.

"In terms of the internet, that's not clear at all.

"If you went in to town on a Friday night, you wouldn't walk down a dark alley, you recognise a dark alley as being dangerous.

"In the field of e-crime people don't recognise the danger signs."

In the push to get its message over, this year's e-Crime Wales summit is attracting speakers from the FBI, Interpol, and computer giant Microsoft.

It is also an opportunity for Wales' first e-crime police team manager to offer her advice.

'Stay safe'
Acting Det Sgt Andrea Barnard of North Wales Police recently took up the post, becoming a point of contact for businesses, the police and the assembly government.

"I think people are aware that there are problems out there, but I don't think they ever truly believe it is going to happen to them," she explained.

"Therefore they don't act, they don't take measures to protect themselves from e-crime.

"I would just like businesses in north Wales to be aware that e-crime can happen to anybody.

"But having said that - for them not to be totally frightened by that. Come and seek advice.

"Come and have a chat to us and we can explain the fundamentals of e-crime and how to stay safe."

original post here

Wednesday, October 7, 2009

October is National Cyber Security Awareness Month


October marks the sixth annual National Cybersecurity Awareness Month sponsored by the Department of Homeland Security. The theme for National Cybersecurity Awareness Month 2009 is “Our Shared Responsibility” to reinforce the message that all computer users, not just industry and government, have a responsibility to practice good “cyber hygiene” and to protect themselves and their families at home, at work and at school.

Americans can follow a few simple steps to keep themselves safe online. By doing so, you will not only keep your personal assets and information secure but you will also help to improve the overall security of cyberspace.

It is Our Shared Responsibility to stay safe online.

SOURCE

October is National Cyber Security Awareness Month


October marks the sixth annual National Cybersecurity Awareness Month sponsored by the Department of Homeland Security. The theme for National Cybersecurity Awareness Month 2009 is “Our Shared Responsibility” to reinforce the message that all computer users, not just industry and government, have a responsibility to practice good “cyber hygiene” and to protect themselves and their families at home, at work and at school.

Americans can follow a few simple steps to keep themselves safe online. By doing so, you will not only keep your personal assets and information secure but you will also help to improve the overall security of cyberspace.

It is Our Shared Responsibility to stay safe online.

SOURCE

Wednesday, May 6, 2009

Facebook Helps Cybercrime Fighters in Case

Facebook Stranger Pictures, Images and Photos

School resource officers from across Alabama and the nation fielded complaints about an Internet extortionist badgering girls for nude pic­tures. Victims even created a Facebook page warning fe­males not to talk to the per­son with the username Meta­scape.

Metascape turned out to be Jonathan Vance, an Alabama man who made lewd cyber re­quests of 206 girls and young women and attempted to hack into and gain control of their e-mail, Facebook and MySpace accounts, federal authorities say. He was suc­cessful in at least 53 cases.

Johnathan Vance will serve 18 years in prison and then the rest of his life on probation as a sex offender.

Those complaints, includ­ing several from Birmingham-area high school students, sparked an investigation across state and federal juris­dictions. The groundbreaking case will be used as a tem­plate for cyber harassment cases and used to train law enforcement officials and prosecutors, federal authori­ties said.

This type of cybercrime is relatively new, and federal au­thorities said they know of no other case that comes close to the size of this one.

"We learned a lot from this case," said Assistant U.S. At­torney Daniel Fortune, who prosecuted the case. "We're going to use this case to edu­cate law enforcement, teach­ers, students and parents."

Vance, 24, of Auburn, was sentenced to 18 years in fed­eral prison last week after pleading guilty to several charges, including attempted production of child pornogra­phy and interstate extortion. Upon release Vance will have to report to a federal proba­tion officer for the rest of his life and register as a sex of­fender.

Only 53 victims agreed to cooperate in the investigation, authorities said. There likely are more victims authorities said they don't know about.
"The embarrassment factor was big in this case," said Dale Miskell, supervisory spe­cial agent for the FBI's cyber­crimes squad in Birmingham. "How can a girl go to her pa­rents and tell them what hap­pened? Even the adult victim didn't come forward until we contacted her."

Others either denied they were victims -- after being confronted with photographic evidence -- or simply refused to talk to investigators, For­tune said. Miskell said the FBI was able to identify the two minors and one adult who sent Vance nude pictures. There were four others agents were not able to identify. In some of the photos sent to Vance, authorities could not discern if the person was a minor and under what cir­cumstance Vance got the pho­tos.

'A difficult, unique case'
Authorities said from Janu­ary 2006 to June 2008, Vance targeted girls and women in Alabama, Pennsylvania and Missouri, ranging in age from 14 to 26. Miskell said the FBI got involved in the fall 2007 after a Hoover High School re­source officer reported a com­plaint he received from a stu­dent.

Starting with only a screen name, Miskell said, FBI agents were able to track down Vance. Vance eluded authori­ties for a while by changing screen names -- using as many as 10 -- after word got out about Metascape.

It took the cooperation of law enforcement and victims across several jurisdictions before the FBI pinned Vance as their man. "Tracking him down was complicated . . . This was really a difficult, unique case," Fortune said.

Vance lived with his grand­parents in Auburn. He was born to a teenage mother and was adopted by his grandpa­rents as a child, according to court records. He grew up be­lieving that his mother was his sister. He was active in his church -- Vance attended church with some of his vic­tims -- and sang in the choir.

Vance's defense lawyer, Tommy Spina, said in court records and at the sentencing hearing that Vance's austere upbringing might have led to his behavior.

Agents seized his computer in December 2007, but months later, Vance bought a laptop and his conduct esca­lated. He was arrested in July.

Court records show Vance gained control of his victims' Yahoo, Hotmail, Facebook and MySpace accounts using several means. In interviews with the FBI, Vance said he would contact his victims through instant messaging and pretend to be a friend or a relative. He persuaded some victims to give him their login and password information, saying he was locked out of his own Facebook, MySpace or e-mail account.

In more complicated in­stances, Vance hacked into his victims' e-mail accounts using information from public Face­book pages, which included information such as birth dates, the names of the vic­tims' schools and their home­towns. Password protection on the e-mail accounts would use standard questions such as ZIP code, date of birth or school mascot. Once Vance had control of an e-mail ac­count, he would go to Face­book, pretend he forgot the password and have Facebook send a link to the victims' compromised e-mail account.

Victim relieved
Vance threatened to expose embarrassing details he learned if he didn't get nude photos.

In court last week, Fortune read a letter from a 14-year-old girl who ex­pressed relief that Vance was behind bars. She said she knew that taking the nude photos was wrong, "but I just wanted my Facebook back."

Fortune said authorities passed on what they learned from Vance to programmers for the social networking sites and e-mail services. "I can't say it was as a direct result of this case, but their security questions are more sophisti­cated," Fortune said. "Face­book and Yahoo said they're going to reference this case for training purposes."

The case illustrates the need for parents to know what their children are doing, Mis­kell said.

"A lot of these kids have Fa­cebook without their parents knowing it," he said. "Parents really need to talk to their kids about this."

SOURCE

Facebook Helps Cybercrime Fighters in Case

Facebook Stranger Pictures, Images and Photos

School resource officers from across Alabama and the nation fielded complaints about an Internet extortionist badgering girls for nude pic­tures. Victims even created a Facebook page warning fe­males not to talk to the per­son with the username Meta­scape.

Metascape turned out to be Jonathan Vance, an Alabama man who made lewd cyber re­quests of 206 girls and young women and attempted to hack into and gain control of their e-mail, Facebook and MySpace accounts, federal authorities say. He was suc­cessful in at least 53 cases.

Johnathan Vance will serve 18 years in prison and then the rest of his life on probation as a sex offender.

Those complaints, includ­ing several from Birmingham-area high school students, sparked an investigation across state and federal juris­dictions. The groundbreaking case will be used as a tem­plate for cyber harassment cases and used to train law enforcement officials and prosecutors, federal authori­ties said.

This type of cybercrime is relatively new, and federal au­thorities said they know of no other case that comes close to the size of this one.

"We learned a lot from this case," said Assistant U.S. At­torney Daniel Fortune, who prosecuted the case. "We're going to use this case to edu­cate law enforcement, teach­ers, students and parents."

Vance, 24, of Auburn, was sentenced to 18 years in fed­eral prison last week after pleading guilty to several charges, including attempted production of child pornogra­phy and interstate extortion. Upon release Vance will have to report to a federal proba­tion officer for the rest of his life and register as a sex of­fender.

Only 53 victims agreed to cooperate in the investigation, authorities said. There likely are more victims authorities said they don't know about.
"The embarrassment factor was big in this case," said Dale Miskell, supervisory spe­cial agent for the FBI's cyber­crimes squad in Birmingham. "How can a girl go to her pa­rents and tell them what hap­pened? Even the adult victim didn't come forward until we contacted her."

Others either denied they were victims -- after being confronted with photographic evidence -- or simply refused to talk to investigators, For­tune said. Miskell said the FBI was able to identify the two minors and one adult who sent Vance nude pictures. There were four others agents were not able to identify. In some of the photos sent to Vance, authorities could not discern if the person was a minor and under what cir­cumstance Vance got the pho­tos.

'A difficult, unique case'
Authorities said from Janu­ary 2006 to June 2008, Vance targeted girls and women in Alabama, Pennsylvania and Missouri, ranging in age from 14 to 26. Miskell said the FBI got involved in the fall 2007 after a Hoover High School re­source officer reported a com­plaint he received from a stu­dent.

Starting with only a screen name, Miskell said, FBI agents were able to track down Vance. Vance eluded authori­ties for a while by changing screen names -- using as many as 10 -- after word got out about Metascape.

It took the cooperation of law enforcement and victims across several jurisdictions before the FBI pinned Vance as their man. "Tracking him down was complicated . . . This was really a difficult, unique case," Fortune said.

Vance lived with his grand­parents in Auburn. He was born to a teenage mother and was adopted by his grandpa­rents as a child, according to court records. He grew up be­lieving that his mother was his sister. He was active in his church -- Vance attended church with some of his vic­tims -- and sang in the choir.

Vance's defense lawyer, Tommy Spina, said in court records and at the sentencing hearing that Vance's austere upbringing might have led to his behavior.

Agents seized his computer in December 2007, but months later, Vance bought a laptop and his conduct esca­lated. He was arrested in July.

Court records show Vance gained control of his victims' Yahoo, Hotmail, Facebook and MySpace accounts using several means. In interviews with the FBI, Vance said he would contact his victims through instant messaging and pretend to be a friend or a relative. He persuaded some victims to give him their login and password information, saying he was locked out of his own Facebook, MySpace or e-mail account.

In more complicated in­stances, Vance hacked into his victims' e-mail accounts using information from public Face­book pages, which included information such as birth dates, the names of the vic­tims' schools and their home­towns. Password protection on the e-mail accounts would use standard questions such as ZIP code, date of birth or school mascot. Once Vance had control of an e-mail ac­count, he would go to Face­book, pretend he forgot the password and have Facebook send a link to the victims' compromised e-mail account.

Victim relieved
Vance threatened to expose embarrassing details he learned if he didn't get nude photos.

In court last week, Fortune read a letter from a 14-year-old girl who ex­pressed relief that Vance was behind bars. She said she knew that taking the nude photos was wrong, "but I just wanted my Facebook back."

Fortune said authorities passed on what they learned from Vance to programmers for the social networking sites and e-mail services. "I can't say it was as a direct result of this case, but their security questions are more sophisti­cated," Fortune said. "Face­book and Yahoo said they're going to reference this case for training purposes."

The case illustrates the need for parents to know what their children are doing, Mis­kell said.

"A lot of these kids have Fa­cebook without their parents knowing it," he said. "Parents really need to talk to their kids about this."

SOURCE

Popular Posts

Blog Archive