Showing posts with label law enforcement. Show all posts
Showing posts with label law enforcement. Show all posts

Monday, January 27, 2014

Roman Vega (CarderPlanet's Boa) Gets His Sentence!

For some time now I have been following with anticipation the case of Roman Vega, the hacker who went by the pseudonym BOA and ran the notorious BOAFactory website prior to helping spear-head the creation of Carder Planet, a specialty site created by and for credit card thieves that at its peak was servicing more than 6,000 members who brokered, bartered and sold their stolen cards.

In December 2013 it appeared that Vega, who had been in custody since 2003, was finally about to be sentenced. Vega was originally arrested while traveling in Cyprus and is said to have had in possession at the time of his arrest information on more than 500,000 credit card accounts. The New York court sentenced him December 18, 2013, but then it was time to find out what would happen in California.

On January 22, 2014, the Honorable Charles R. Breyer, Senior United States District Judge accepted Vega's plea bargain and in exchange for pleading guilty to 18 USC 1343 and 2, "Wire Fraud, Aiding and Abetting" (Counts 1-20), Counts 21-40 of his original charges were dismissed.

Boa was sentenced (by this Judgement Against Roman Vega document) to serve forty-six (46) months on counts one through twenty, all counts to be served concurrently, and also to be served concurrently with Docket #07-CR-707 (ARR) from the Eastern District of New York.

Vega will also have to pay restitution as follows:

  • Bank of America - $23,371.86
  • Bank of Cyprus - $92.63
  • Canadian Imperial Bank of Commerce - $681.56
  • Capital One - $15,039.56
  • Chase Bank - $16,223.74
  • Citibank - $29,284.42
  • Fla Card Services - $7,695.04
  • JP Morgan Chase - $1,849.27
  • Merrill Lynch Fraud Control - $6,118.54
  • National City Card Services - $614.84
  • PNC Bank - $3,144.92
  • Royal Bank of Canada - $488.49
  • USAA Federal Savings Bank - $89,294.75
  • Wachovia Bank - $13,303.35
  • Washington Mutual Bank - $12,525.60
With some fees, he is ordered to make a lump sum payment of $221,728.57 (including all the above) to the court.

The early court documents in the Boa case, including this Roman Vega Criminal Complaint from 2007 (25 page PDF) make fascinating reading, walking through how a dispute on the ShadowCrew Carding Site between Boa and others on the site that lead Boa to spawn his own website, www.boafactory.to. Boa worked closely with other famous carders, including Gollum and Script.

Roman Vega (Boa) was arrested February 26, 2003 in Nicosia, Cyprus. his laptop was imaged and shared with the US Secret Service and the US Postal Inspection Service, which revealed hundreds of email messages and thousands of pages of ICQ chats. The laptop also had 500,000 credit cards issued by 7,000 different financial institutions! Vega was flown from Cyprus to Minneapolis, Minnesota on June 3, 2004. He plead guilty in November 2006 to twenty counts of wire fraud in the Northern District of California. One of the especially interesting chats was between ICQ 107711 (Vega) and ICQ 100630 (Script) where Vega claims his "boys" have cracked a database containing 2 million credit card accounts in the United States. Script and RyDen said that was too large a volume for them to handle. Later Script sent an article about the hack to Vega about a breach against Data Processors International (DPI).

Although the court documents do not specify which article it was, it may have been this CNN article Hacker hits up to 8M credit cards. Vega confesses to Script that the article is wrong - they actually got 14 million cards, including 450,000 just from Capital One!

Boa was arrested after a large number of cards from the breach were found to be used at a particular POS terminal in Cyprus.

Now, if you'll forgive me, we'll go back to the New York case. Things did not go well for BOA in New York. He insisted on dismissing his counsel, who he did not trust, and defending himself, which did not go well. Vega had a limited command of English and his defense seemed to be a mix of magazine articles, things other prisoners told him and watching too much television. Here's one example transcript from a hearing where he is trying to say that he wants access to thirty boxes worth of notes and files, including everything the government found on his hard drive.

According to the sentencing memorandum from the US, Script was Dimitry Golubov, the Godfather of CarderPlanet. But Boa played a key role in making CarderPlanet the "go to place" for cards. It was Boa who instituted the "Card Review" process by which vendors had to ensure that their cards were original and had not been previously sold. The vendor ranking system, copied to so many other boards today, originated on CarderPlanet, and it was Boa's key contribution to the new system.

More than half of the sentencing memo from the US lists the many ways in which Vega misbehaved and violated his agreements to cooperate with the US in exchange for leniency. These include:

  • having a letter sent from Italy to the private unlisted address of a government analyst that insulted Vega by saying he no longer had contact or influence in the criminal world.
  • sending money to his girlfriend and then "not being able to recall" anything about that when asked repeatedly by the government.
  • consulting on Misha Glenny's book "Dark Market: Cyberthieves, CyberCops and You".
  • withdrawing his guilty plea
  • having a powerful cell phone antenna in his cell. Although no phone was ever found, Vega was somehow
  • able to maintain several blogs about his life in prison, despite theoretically having no access to computers or phones.
Some of CarderPlanet's top customers were Cumbajonny AKA Albert Gonzalez, now serving twenty years. Maksim Yastremskiey (Maksik) sentenced to 30 years for hacking by the Turkish police. Cesar Carranza, a money launderer to the carders, now serving six years in New York for laundering $2.5 million.

Here is the sentencing "point calculator" used in the case:

Base Offense Level 2B1.1(a)(2) 6
Loss between $200 and $400 Million 2B1.1 (b)(1)(O) 28
Stolen Property Business 2B1.1(b)(4) 2
Fraud from Outside US and Sophisticated Means 2B1.1(b)(9) 2
Use of Device Making Equipment 2B1.1(1) 2
Organizer and Leader of 5 or more Participants 3B1.1(a) 4
Adjusted Offense Level for Count One 44
Base Offense Level 2S1.1(a)(1)
See also 1B1.5(b)(1)
40
Specific Offense Characteristic
USC 1956
2S1.1(b)(2)(B) 2
Organizer and Leader of 5 or more Participants 3B1.1(a) 4
Adjusted Offense Level for Count Two 46

To show consistency with the sentence, the New York Sentencing Memo (10MB PDF) also lists previously sentenced carders and hackers and their respective sentences as a means of justifying the requested sentence:

1. Albert Gonzalez - 20 years (sentenced September 11, 2009)

2. Edwin Pena - 10 years and $1M restitution (sentenced September 24, 2010)

3. Lin Mun Poo - 10 years (sentenced November 4, 2011)

4. Tony Perez - 14 years (sentenced September 9, 2011)

5. Jonathan Oliveras - 12 years (sentenced December 9, 2011)

6. Adriann-Tiberiu Oprea - 15 years (sentenced for hacking into 800 US Merchants' systems resulting in $17.5 million in unauthorized charges on more than 100,000 cards.) Oprea was known as "the Subway Hacker" for stealing card data from hundreds of Subway restaurants.

(to read about other famous hackers and their sentences, see Major Achievements in the Courtroom.)

In New York 1:07-cr-00707-ARR, Vega was sentenced to 216 months for Count One and 90 months on Count two, to run concurrently for a total of 216 months or 18 years. Since that is longer than the California sentence, he'll pay the California restitution and serve the 18 years courtesy of the Bureau of Prisons in Lompoc.

Saturday, November 20, 2010

Lin Mun Poo: Hacker of the Federal Reserve and ...?

** UPDATE: Poo arraigned and in custody **

On October 21, 2010, Malaysian citizen Lin Mun Poo landed at the JFK airport in New York and and hit the streets to make a business deal. He was taken into custody a few hours later, after meeting with a "carder" who had offered to give him $1,000 cash for 30 active credit and debit card numbers. When the meet went down, in Queens, New York, it turns out the carder was an undercover Secret Service agent. His laptop computer was searched and found to contain thousands of stolen credit and/or debit card numbers, as well as log files indicating multiple servers belonging to various financial institutions had been infiltrated. (From Case 1:10-mj-01240-VVP, PACER)

He was arrested and arraigned on a probable cause affidavit from the US Secret Service stating that "in or about and between September 2010 and October 21, 2010, both dates being approximate and inclusive, within the Eastern District of New York and elsewhere, the defendant LIN MUN POO did knowingly and with intent to defraud produce, use and traffic in one or more unauthorized access devices, and by such conduct did obtain $1,000 or more during that period."

As the affidavit makes clear, that wasn't all that was going to be charged, but this violation of Title 18 USC § 1029(a)(2) - "Fraud and related activity in connection with access devices" - was enough to get POO picked up and held.

Poo was taken into custody, and Justice argued he would be a flight risk, so he should be held. *UPDATE 22NOV2010 @ 1300* - Poo was arraigned today, pleading not guilty. He was remanded into custody and will be held without bail until at least his next hearing on December 20th! A copy of his Detention Letter is available courtesy of the Eastern District of New York.

A Press Release from the Eastern District of New York Department of Justice has the headline Malaysian National Indicted for Hacking into Federal Reserve Bank and continues "Defendant's Criminal Activities Extended to the National Security Sector."

Poo was in possession of 400,000 stolen credit and debit card numbers at the time of his arrest. According to the Press Release, "the defendant made a career of compromising computer servers belonging to financial institutions, defense contractors, and major corporations, among others, and selling or trading the information contained therein for exploitation by others."

While the headline is all about the Federal Reserve Bank of Cleveland, Ohio, an SC Magazine article by Dan Kaplan downplays that aspect of the story. In a statement Dan received for his story, Malaysian Man Charged with Hacking into Bank Systems, Fed spokeswoman June Gates said "There's been some confusion based on the wording in the Department of Justice news release. The incident here involved a test computer that is used to test software and applications. No Federal Reserve data or information was accessed or compromised."

The confusion comes from a misunderstanding of the Detention Request filed by justice, which states:
the defendant admitted that he compromised a computer network of the Federal Reserve Bank (“FRB”) by exploiting a vulnerability he found within their secure system. The FRB in Cleveland, Ohio has confirmed that an
FRB computer network was hacked in approximately June 2010, resulting in thousands of dollars in damages, affecting ten or more FRB computers, and forming the basis for Counts Three and Four.


It is not necessary to steal data to cause thousands of dollars in damages.

What should be of bigger concern are the other victims of Poo's hacking. One of these was FedComp, described as a data processor for federal credit unions. As a result of the FedComp breach, the New York Press Release says Poo "was able to gain unauthorized access to the data of various federal credit unions, such as the Firemen's Association of the State of New York and the Mercer County New Jersey Teachers." Another was a system belonging to a DoD contractor "that provides systems management for military transport and other military operations, potentially compromising highly sensitive military logistics information," according to the Press Release.

The four-count indictment against Poo, filed Nov 18, 2010 in Brooklyn, charges the following:

COUNT ONE - Access Device Fraud
"knowingly and with intent to defraud possess fifteen or more unauthorized access devices, to wit: credit and debit card account numbers, in a manner affecting interstate and foreign commerce."

(See: Title 18 USC §§ 1029(a)(3), 1029(c)(1)(A)(i),
Fraud and related activity in connection with access devices )

COUNT TWO - Aggravated Identity Theft
"knowingly and intentionally possess, without lawful authority, means of identification of one or more persons, to wit: credit and debit card account numbers of individuals, knowing that the means of identification belonged to said persons."
(See: Title 18 USC §§ 1028A(a)(1), 1028A(b), 1028A(c)(4)
Aggrevated Identity Theft )

COUNT THREE - Unlawful Transmission of Computer Code and Commands - Federal Reserve Bank
"knowingly and intentionally cause and attempt to cause the transmission of one or more programs, infomration, codes and commands, to wit: malicious codes and commands, and as a result of such conduct, did intentionally cause damage without authorization to one or more protected computer, to wit: computer of the Federal Reserve Bank, which offense caused, and if completed would have caused, loss to one or more persons during a one-year period aggregating at least $5,000 in value, and damage affecting ten or more protected computers during a one-year period."
(See: Title 18 USC §§ 1030(a)(5)(A), 1030(b), 1030(c)(4)(B), 2 and 3551 et seq)

COUNT FOUR - Unauthorized Computer Access Involving Government Information
"knowingly and intentionally access and attempt to access one or more computers without authorization, to wit: computers of the Federal Reserve Bank, and thereby obtained and attempted to obtain information from a department and agency of the United States, to wit: the Federal Reserve Bank, which offense was committed for the purpose of commercial advantage and private financial gain.

(See: Title 18 USC §§ 1030(a)(2)(B), 1030(b), 1030(c)(2)(B)(i), 2 and 3551 et seq.)
Fraud and related activity in connection with computers

Thursday, August 26, 2010

Major Fraud Ring Busted in Largest Chinese Cybercrime Operation

Yesterday Taiwanese Criminal Investigation Bureau Commissioner Lin Teh-hua announced the largest cybercrime operation in the history of his organization. (The Criminal Investigation Bureau's report, in Chinese, is here). 548 Taiwanese police officers and 2,720 Chinese police officers took part in the operation which resulted in 450 fraudsters being arrested throughout Taiwan and in the Chinese provinces of Fujian, Huanan, Hubei, Anhui, Guangdong and Guangxi. After a joint operations agreement was signed between Chinese and Taiwanese authorities, more than 16 joint raids have been conducted leading to more than 1,000 arrests.

In this case, the activity particularly focused on telephone fraud and internet auction fraud. The arrests come close on the heels of the break up of a similar fraud ring in Ho Chi Minh City where 99 fraudsters from Taiwan and China were arrested. In the Vietnamese fraud, where 76 Taiwanese and 23 Chinese citizens were arrested, fraudsters would take over entire hotels, booking as many as 30 to 40 hotel rooms for their fraud. They would place randome phone calls, posing as telecom officials, police officers, or prosecutors, and urge people to wire money to specified accounts. Some individuals lost millions of dollars in that fraud. The Ho Chi Minh case made note that on July 1st there had been a related raid where 32 Taiwanese and 14 Chinese were arrested. Major General Huynh Huu Chien of the Ministry of Public Security called it the largest foreign hacker ring ever in Vietnam, saying that they also had been doing ATM fraud, hacking into foreign banks and using ATM card readers to steal from more than 200 foreign bank accounts and financial institutions.

The Vietnam case continued on August 13th, when police arrested eleven Taiwanese men and two women in Can Tho. In that case, the police seized laptops, phones, walkie-talkies, and most intriguingly more than 50 "fraud scripts" that guided the fraudsters through the "play" of imitating a police officer or state agency official in order to further their fraud.

The Taiwanese-Chinese arrests this week seem to be more of the same, as police explain that the groups formed temporary "Telephone Fraud Centers" where the scammers placed calls following elaborate scripts that helped them to perpetrate their frauds. In Taiwan, in addition to the seizure of laptops, cell phones, and fraud manuals, fake courier uniforms were found.

This raid began to be built after a large meeting in China's Fujian Province where police from across China came together in Ningde to address illegal telecom operations, money laundering, impersonation of public agencies for fraud, and online shopping scams, but the case actually originated with the arrest of "Rong Yu" who was arrested back in April when police discovered he had been operating a fraud from the Taizhong Emperor Hotel, pretending to be a Shen Fuwen law clerk. By tracing the criminal contacts of this phony law clerk, more than seven other similar groups were identified, including the identification of the group's headquarters in Hunan Province.

The group was also found to be related to a fake online auction group - the Wuhan Pride network (www.dey100.com). This group, which claimed to be an online trading company, was involved in both the sale of goods that were never actually delivered, but also ATM fraud conducted after stealing banking information from the buyers of those fake goods! Some of the victims report getting very strange deliveries, such as ordering goods online and receiving an empty CD box or a package of soap instead of what they ordered. When they called to complain, this allowed the fraudsters to gather additional personal information about them that allowed further fraud to occur.

I hope more details of this fraud will be revealed in the next few days, but for now, I want to offer congratulations to the investigators who are helping to clean up online crime throughout China and Taiwan!

Monday, July 12, 2010

PakBugs Hackers arrested

(Thanks to Twitter friends - @nartv, @cedricpernet, @HostExploit - for setting me onto this story mostly by pointing to this article by Lucian Constantin over at SoftPedia, who had the English Language Scoop, as he often does.)

For Pakistani Hackers, July 7, 2010 will be remembered as the beginning of a fearful period in their lives. On that day, Mr. Shahid Nadeem Baloch, the Director of Cyber Crime Investigations for the Federal Information Agency announced the arrest of five ring leaders of the popular hacker forum "PAKBugs" in this release from the Press Information Department. Among those praised by FIA's Director General, Mr. Zafar Ullah Khan, for their roles in the investigation are Mr. Muhammad Idress Mian, who directs the National Response Center for Cyber Crimes (NR3C), Mr. Muhammad Raza, Cyber Crime Circle sub-inspector for the Rawalpindi Police, and NR3C Technical Officers Mr. Aun Abbas, and Mr. Amjad Abbasi.

The hackers arrested or wanted include:

Jawad Ehsan, alias Humza, still at large in Riyadh, Saudi Arabia.
Jawad uses the hacker handle ZombiE_Ksa, and is the founder of PakBugs and probably the most famous of all the PakBugs hackers. He is charged with 169 website defacements.

Ahmad Hafeez, arrested in Lahore.
Ahmad uses the hacker handle vergil, and is a moderator on the boards Pakbugs and Pakhaxorz. He is charged with 480 website defacements.

Hassan Khan, arrested in Peshawar.
Hassan uses the hacker handle x00mx00m, and is a co-founder of Pakbugs. He is charged with 8,697 website defacements.

Farman Ullah Khan, arrested in Bannu.
Farman uses the hacker handle Farman, and was a VIP-member of Pakbugs. Charges against Farman are unknown.

Malik Hammad Khalid, arrested in Rawalpindi.
Malik uses the hacker handle inject0r, and was a "super moderator" at Pakbugs. He is charged with 134 website defacements.

Taimoor Zafar Bhatti, arrested in Rawalpindi.
Taimoor uses the hacker handle h4v0c-, and was a "super moderator" at Pakbugs. He is charged with 105 website defacements.

Also wanted by the FIA Cyber Crimes Department are:
BiG^Smoke
Cyber-Criminal
spo0feR
and [a]

According to the press release:
These individuals have expertise in following techniques:
1) Linux
2) SQL Injection
3) Trojan horses
4) Phishing
5) Rooting
6) Access to various servers
7) Botnets
8) PHP Scripts
9) Stealers
10) ASP scripts (self writing)
11) JSP scripts (self writing)
12) Key loggers
13) Credit Cards Jacking and usage of stolen Credit Cards


What the press release doesn't mention is that the NR3C's own website was hacked by these website defacers in January of this year.

zonehmirrors.org/defaced/2010/01/07/www.nr3c.gov.pk/ "Hacked by zombie_ksa"

In that defacement the Pakbugs hackers suggest that if Pakistani citizens want help with security issues they should turn to Pakbugs rather than the NR3C.

The NR3C defacement was signed:

We are L33t Pakistani H4x0rZ,
www.Pakbugs.com
We are PAKbugs, We keep it real:
Zombie_Ksa::Spo0feR::x00mx00m::Cyber-Criminal
Special Greetz: BiG^Smoke
Greetz: Agd_Scorp :aB0 M0h4mM3d : The Moorish

That is actually the last website defacement credited to ZombiE_Ksa in the Zone-H archives, although his activities in 2009 included hacking numerous ".gov.pk" websites, temporarily taking over nameservers on the ".ug" registrar to allow defacements of the Ugandan websites for Microsoft, Toshiba, CNN, Citibank, and Google, and hacking the websites of the Saudi "Bank Al Bilad".

Zombie_KSA (KSA = Kingdom of Saudi Arabia) uses the hotmail addresses "Zombie_KsA@hotmail.com" and "mr.lonely420@hotmail.com".

TrendMicro posted screenshots obtained from Zombie_KSA proving that he not only had defaced the website, but actually had control of the email systems of the NR3C.

Despite the ZombiE_KsA hack, the Pakistani government is to be highly praised for taking on Cybercrime in such a proactive way. Pakistanis are encouraged to report cybercrime by emailing helpdesk@nr3c.gov.pk. The 2007 "Prevention of Electronic Crimes Bill (english language PDF) offers penalties from six months imprisonment all the way up to Capital punishment for 17 types of cyber crimes, with the most significant being "Cyber terrorism".


Other articles show that Zombie_KsA and Cyber-Criminal hacked the Pakistani Air Force website.

Unfortunately for the PakBugs hackers, in addition to having the Pakistani government after them, they had a bigger problem. Greyhat vigilante hacker "catch.them@live.com" posted the entire user database of the PakBugs forums to the mailing list Full-Disclosure back on September 14, 2009. That report revealed the email addresses used by all 12,640 members of PakBugs, including many of the hackers on the FIA wanted list including:

ZombiE_KsA = mr.lonely420@hotmail.com
x00mx00m = x00mx00m@gmail.com
Farman = farmanullahkhan@gmail.com
vergil = hotpoint-001@hotmail.com
Injector = lovedontcostapenny_1@live.com
h4v0c- = amilliondollarsmile@hotmail.com

The FIA may want to check out the history of website "loverzpoint.net", which has been "Greeted" several times by ZombiE_KsA, and where two of their "still at large" hackers have email accounts:

Cyb3r-Criminal = cyber-criminal420@loverzpoint.net
BiG Smoke = bigsmoke@loverzpoint.net
spo0fer = outlaw41@live.com
[a] = ahmed.kamal29@gmail.com

loverzpoint.net was originally registered to "big_smoke_boom@yahoo.com" with a fraudulent US-based address. In October 2008 that changed to "loverzpoint@gmail.com" with a Riyadh address and the name "Syed Jawad Shah".

(According to the Hack, userids 1, 12, 99, 1628 and 3844 all had "Admin" privileges at PakBugs. That would be users = ZombiE_KsA, spo0fer, Maximus, Test User, and Big Smoke, the last of those being the original owner of LoverzPoint.net)


The website "Propakistani.pk" has run a message regarding these arrests which is said to be from the "Pakistan Cyber Army". The PCA was active in a clash between Pakistani and Indian hackers in November of 2008. The message reads:
“Message from Pakistan Cyber Army on arrest of Pakbugs Members

If anyone has doubt that we are not the one who defaced ONGC then get a life first. If people have forgotten, then we are the same guys who Defaced ONGC in response to the attack on OGRA. After which we did a peace deal with the groups involved on both sides of borders including “Pakbugs” and “ICW” but kids didn’t keep their promise and got arrested.

We told PakBugs many (many, many, many) times to not to deface/destroy Pakistani websites and infrastructure. We told them to take FIA and NR3C seriously – as these agencies are not bunch of NOOBS, we had warned Pakbugs that you people don’t know about the power and the resources that NR3C has got but they gave a damn to our words and ended up in their custody.

I feel sad about the kids but… it happened due to their carelessness and childish attitude, which eventually landed them in the jail.

If you people are upcoming hackers and don’t know about Prevention of Electronic Crimes Ordinance then go and read it on NR3C website. I fear that Pakbugs would have a jail of 7 years if they got trialed and if FIA bail them out with some punishment they should thank Allah and concentrate on their studies.

We always told Jawad (HUMZA) and other kids about the consequences that they may face if arrested. [Jawad correct me if I am wrong.

Request to FIA/NR3C

“It is our humble request to FIA (NR3C) authorities to consider the case realistically and don’t give the kids the capital punishment as they are kids and can improve if given a chance. If they got the capital punishment as mentioned in Prevention of Electronic Crimes Ordinance then their future will be ruined. Sir these are our kids and our force if given a direction“

Message for upcoming Hackers

Our message to upcoming hackers or people who are interested in this field is that there is nothing bad to have the knowledge of hacking or hacking techniques, what’s bad is the usage of such knowledge and skill against our own country, National and international organizations or departments – that may cause damage to our country and its repute in the world. Don’t push your efforts to get famous. The fame will come by the time.

Some of your kids out there think that organizations in the west give opportunity to the hackers, if that’s the case then you are living in a heaven of fools.

Don’t believe in such stories that hackers will have a good future. The person who has a criminal record cannot fly from the country or he can’t enter into a country legally – go and ask your elders about it.

Message for Indian Hackers

If Indian hackers think that the game is over then read our message once again “Don’t mess with Pakistan else you will lose both your Name and this Game”. If you think that “Pakbugs” got arrested and you have a chance to play then give it a second thought.

Regards,

Pakistan Zindabad,
We are still awake for our country.
Haroon aka D45H & Hamza aka r4yd3n
Pakistan Cyber Army



(someone named R4yd3n was a member at PAKBugs as well, using the email sana2005@fastmail.fm)

Thursday, July 01, 2010

ICE Operation "In Our Sites"

When you think of a Federal agency that should be enforcing criminal copyright violations, you might not think of the US Immigration and Customs Enforcement (ICE), but once again, they are serious members of the cybercrime-fighting pack with their recently announced "Operation In Our Sites".

ICE Assistant Secretary John Morton was backstage in Los Angeles for a meeting with movie studios, entertainment unions, and the Motion Picture Association of America (MPAA) where he announced the first arrests in this operation.



In their first action, nine web sites had their domains seized by agents operating from the Southern District of New York. In addition, ICE agents seized the criminals' assets from 15 bank, Paypal, investment, and advertising accounts and executed four residential search warrants.

The domain names targeted in the first round included:

TVShack.net
Movies-Links.tv
FilesPump.com
Now-Movies.com
PlanetMoviez.com
ThePirateCity.org
ZML.com

Visitors to these websites will see this sign instead of their regular content:



Some of these sites were quite creatively hosted. For example, TVShack.net was hosted on the IP address 84.22.98.3, owned by "CyberBunker Customer Delegations," which claims to be located in Antartica (although they have a sales office in Berlin Germany). One of its close neighbors, "the-movie-downloads.com" is still on live at 84.22.98.19, which claims to have 3 million members and a catalog of 80 million titles available for "instant free download."

FilesPump.com was hosted prior to its seizure on the subnet 213.174.143.0/24, which currently hosts more than 500 hardcore pornography websites at "Advanced Hosters", but still has free movie sites mixed in, such as "freemoviesplace.com" owned by Hungarian "Alen Miscak" according to the WHOIS information. That site claims to have been offering streams of Twilight Saga: Eclipse since June 30th and Toy Story 3 since June 18th, but its possible that they are just making money on their related "allposters.com" affiliate advertising.

Some of the sites are quite confusing for the novice to use . . . for instance ABCFilm.org is a Russian language site, offering streams of all the most recent movies - Eclipse, Grown-Ups, A-Team, Killers, Karate Kid, Jonah Hex - but to watch them you have understand their special "Codex" and use their "DownloadMaster" program. The movies are clearly labeled as to what kind of stolen IPR you will receive, for example Grown-Ups (Russian is Одноклассники) is labeled as a "CamRip" (meaning someone videotaped it in the theater) of 1938 kb/s 688x384 resolution. Although this one is a Russian site, its hosted at "HostForWeb"

PlanetMoviez was hosted in Chicago Illinois by Cogswell Enterprises on IP address 96.30.9.104, while ThePirateCity was hosted on 89.185.228.192 = "Fast Internet Web & Server Hosting" in the Czech Republic (exmasters.com = "best low-cost adult web-hosting")

ZML.com was hosted on a long-time favorite host of cybercriminals everywhere, Noc4Hosts in Tampa, Florida. Noc4Hosts IP 96.31.66.11 was ZML's previous home, on a subnet that also contains all your offshore banking domain names, from places like "caymanfinancialreview.com", and which also hosted DVD and Movie piracy websites such as Basecinema.com, BuyDVDFilm2.com, CinemaINet.com, DVDOnlineService.com, FilmoKingdom.com, MovieShop77.com, MoviesforaPenny.com, and many others. Strangely, quite a few of these sites are currently not online. I'm sure this means Noc4Hosts has decided to purge themselves of criminals. Haha!

The National Intellectual Property Rights Coordination Center (IPR Center), which is operated by ICE in Virginia, also seized the domain names and all web site content for the sites:

NinjaVideo.net
and
NinjaThis.net


The IPR Center has launched its own web presence to help identify and fight copyright and trademark violation on the Internet. Here's their new logo:


(click for full-sized image)

The IPR Center urges consumers to report additional websites where copyright violation is rampant by using the National IPR Coordination Center Complaint Referral Form or by contacting their IPR Hotline at 1-866-IPR-2060 (1.866.477.2060).

During Fiscal Year 2009, ICE launched 1,479 Intellectual Property Rights Investigations that resulted in 414 arrests, 164 indictments, 203 convictions, and the seizure of $62 Million in counterfeit merchandise, according to their IPR Fact Sheet.

If you think you'd be interested in a career with ICE as a Special Agent, read about The Hiring Process and use their "Contact Us>" page to call and discuss the recruitment process with one of their 26 offices around the country. In addition to Special Agent jobs, they also have positions as Auditor, Criminal Research Specialist, Investigative Assistant, Mission Support Specialist, and Technical Enforcement Officer.



Here are a couple screen shots from the ICE Press Release of sites that they took offline:




Wednesday, October 21, 2009

Phishing For Love: Banking Insiders

This week in the Eastern District of Pennsylvania, an indictment was unsealed against Miguel Bell, Christopher Russell, Michael Merin, Kareem Russell, and Tamika Brown for their actions in stealing more than $1 Million from Citizens Bank, PNC Bank, Wachovia Bank, M&T Bank, Provident Bank, and SunTrust Bank. Michael Levy, US Attorney in that district, brought the charges.

This entire article is a summation of the charges from the extremely detailed sixty-one page indictment.

The five were charged with the following violations:

18 U.S.C. § 371 - conspiracy to commit bank fraud and aggravated identity theft
18 U.S.C. § 1344 - bank fraud -8 counts
18 U.S.C. § 1028A - aggravated identity theft - 34 counts
18 U.S.C. § 2 - aiding and abetting

The charges resulted from activities between September 1, 2005 and November 30, 2008.

Miguel Bell



Miguel Bell is accused of being the ringleader in the scheme, which consisted of stealing identifying information and account numbers, and then having "check runners" pose as the bank customers and cash fraudulent checks from the accounts belonging to those whose identities they were using.

Bell developed his information feed by pursuing romantic relationships with bank employees and one insurance company employee, and after gaining their trust, compelling them to provide bank information, customer account numbers, and personal identifying information including names, addresses, dates of birth, social security numbers, and driver's license numbers. Bell's love interests also rented cars which he provided to the check runners in order to cash out the accounts.

Bell also required Michael Merin, Rashin Owens, and David Tunnell to recruit bank employees to provide the same information he was getting from his love interests.

Bell verified high account balances by calling the banks' automated banking telephone services.

Bell provided his check runners with fraudulent driver's licenses and to have them photographed, and also provided them with fake checks and "cheat sheets" to help them memorize their new identity. On many occasions he provided transportation and maintained cell phone contact with the check runners while they went into the banks.

Bell took the largest share of all the proceeds, and was in charge of distributing funds to others. Check runners were recruited, used for a day, and paid at the end of the day.

Christopher Russell


The indictment describes Christopher Russell as "the right hand man". Among his roles in the scheme he verified bank balances and recruited check runners, often in exchange for illegal drugs or money for illegal drugs. He accompanied check runners to be photographed for their fraudulent driver's licenses. He provided the identity cheat sheets and fraudulent checks to the check runners, and instructed them on their tasks to perform. He often provided transportation and maintained cell phone contact with the check runners. He would often receive the payout from the check runner, and then pass most of the funds to Miguel Bell for further distribution, and paid the check runners.

Kareem Russell


Kareem is described as a "middle man" in the scheme. He primarily recruited runners, and provided all the same activites as Christopher Russell, including recruiting check runners, providing them with drugs or money for drugs, escorted runners to be photographed for fraudulent drivers licenses, and provided transporation, passed funds to Miguel, and paid his check runners from the proceedings.

Michael Merin


Merin was also called a "middle man", but concentrated on recruiting bank employees in addition to some check runners. Among those recruited:

- Jon Steffon of Citizens Bank (charged elsewhere)
- Kern Haynes of Citizens Bank (charged elsewhere)
- Marcus Nabried of Citizens Bank (charged elsewhere)

Tamika Brown


Tamika Brown was partnered with Christopher Russell and accompanied him in transporting his runners for photography and for fraudulent transactions. She also was in charge of providing the runners with clothes to wear for their photographs and fraud, and for arranging the rental of cars to be used in transporting the check runners.

Recruiting


PNC Bank Employee Tiffany Brodie was in contact with Miguel Bell from at least September 1, 2005 until June 30, 2006, and provided at least four bank accounts and associated personal information to Bell from her customers at PNC Bank.

Tiffany's information allowed check runner James Kennedy to steal $13,050 by pretending to be one of these customers. She also rented cars for Miguel.

Citizens Bank Employee Trena Smith was in contact with Miguel Bell from at least November 1, 2005 until December 20, 2005. She provided information on thirty-seven Citizens Bank account holders, which resulted in $390,039 being stolen by check runners Ralph Guy, Jennie Hill, Priscilla Torres and others, who presented fake ids claiming to be these customers.

Citizens Bank Employee Jon Steffon was recruited by Michael Merin and provided at least fourteen sets of identity data for his customers to Michael, which were used between May 1, 2006 and July 30, 2006 to steal $100,687 from Citizens Bank via check runners. "On or about" June 10, 2006, Miguel Bell possessed hand-written person information on five Citizens Bank account holders, written by Jon STeffon and given to Merin by Steffon. He also held three false Pennsylvanie driver's licenses and two false Delaware driver's licenses in those names, as well as Citibank MasterCards and fraudulent checks in those names.

Citizens Bank Employees Jamila Hamler, Marcus Nabried, and Tamea Hill provided personal information of twenty-seven account holders to Merin between July 1, 2006 and July 30, 2006. Tamea Hill provided at least four additional identities to Elton Harris and Rashin Owens, who passed the information to Miguel Bell. These identities were passed to James Kennedy and other check runners to accomplish $213,145 in theft.

Citizens Bank Employee Kern Haynes provided sixteen accounts to Michael Merin, who then passed the information to Bell and Christopher Russell. These identities were used by check runner Eileen Comire and others to accomplish at least $98,375 in theft.

Citizens Bank Employee Regina Tolliver provided information on seven Citizens Bank account holders which was used between March 1 and November 30, 2007 by check runners Richard Maden and Eileen Comire to withdraw $181,577 using their false identities.

Citizens Bank Employee Deonda Barnett provided twelve identities used to steal $24,172 using check runner Eileen Comire and another $18,312 using check runner James Howard.

Citizens Bank Employee Clarissa Gavin provided six account holder identities, which were used by check runner Tommy Antone Murray, Eileen Comire, David TUnnell and others to cash out $70,811.

Car Dealership Recruitment



Rashin Owens and David Tunnell recruited Damoon Hosseinzadeh, an employee at the car dealership "New Concepts, Inc." to provide identity information regarding customers of the dealership. These were used to take $37,900 from Commerce Bank with David Tunnell acting as the check runner.

Insurance Company Recruitment


Colonial Penn Insurance Company employee Lisa Bryant Nelso was used to provide bank account information for persons banking at Citizens Bank, Wachovia Bank, M&T Bank, Provident Bank, and SunTrust Bank.

Ten Citizens Bank identities provided by Nelson were used by check runners to cash out $33,833.

Twenty-five Wachovia identities provided by Nelson were used by check runners to cash out $134,935.

Twelve M&T Bank account identities provided by Nelson were used by check runners to cash out $53,085.

One Provident Bank identity provided by Nelson was used to cash out $7,000.

One SunTrust identity provided by Nelson was used to cash out $2,250.

The Check Runners


There were SO MANY Check Runners, including:
Ralph Guy, Jennie Hill, Priscilla Torres, Gregory Grayson, David Tunnell, Richard Maden, Eileen Comire, and James Kennedy. The indictment actually details their involvement, claiming . . .

Ralph Guy did 37 checks on identities from Pennsylvania, Vermont, Ohio, and Michigan stealing or attempting to steal $174,046.

Jennie Hill did 24 checks on identities from Indiana, New Hampshire, Vermont, Ohio, and Michigan stealing or attempting to steadl $104,422.

Priscilla Torres did 2 checks for $9,243 on identities from Pennsylvanie and Delaware. She also was the driver for other check runners on some occasions.

Gregory Grayson did one check for $2,500 on a New Jersey identity.

James Kennedy did four checks vs. PNC Bank and twenty checks vs. Citizens Bank using at least eleven identities to steal $61,600.

Eileen Comire did at least thirty-seven checks imitating at least twenty-seven account holders to steal at least $240,599 from Wachovia Bank, and an additional $186,913 from Citizens Bank using eighty-eight fraudulent checks and twenty-one account holder identities. She also uses twenty-two checks belonging to twelve M&T account holders to steal an additional $58,135 from M & T Bank.

David Tunnell did seven transactions totalling $41,900 from Commerce Bank using two different identities, and six transactions totalling $45,100 from Citizens Bank using three identities.

Richard Maden used five Citizens Bank identities to present twenty-nine fraudulent checks totalling $97,374.

Notice of Forfeiture


These criminals stand to lose all property, real or personal, that constitutes or is derived from proceeds traceable to the commission of such offenses - up to a value of $1,300,000.

Thursday, October 08, 2009

The FBI's Biggest Domestic Phishing Bust Ever

Yesterday the FBI began performing arrests of more than 100 individuals involved in a phishing investigation announced in the Central District of California courts. The case, known as Operation Phish Phry was the top story on the FBI website yesterday. Robert Mueller announced the case during a speech to the Commonwealth Club of California, where he praised the cooperation with the Secret Service and their Los Angeles Electronic Crimes Task Force, as well as state and local law enforcement. He said this was the first joint cyber investigation with Egypt and that this cooperative effort illustrates "the power of our global partnerships." Mueller also used the speech to praise the 32,000 members of the FBI's InfraGard program, "experts on our critical infrastructure" who help the FBI prevent risks to that infrastructure from becoming a reality.

The official press release from the Los Angeles FBI office says the announcement of the case came from:
Keith B. Bolcar, Acting Assistant Director in Charge, FBI Los Angeles
George S. Cardona, Acting United States Attorney, Los Angeles
and
Kieran Ramsey, FBI Legal Attache in Cairo Egypt
along with Egyptian Law Enforcement Authorities.


The 85 page indictment, which was presented to a Grand Jury back in February was unsealed once the arrests began, and contains a wealth of information. WIRED Magazine's Threat Level blog was the first to have a copy of the indictment.

The basic charges are:
18 USC S 1349: Wire and Bank Fraud Conspiracy
18 USC $ 1344(1): Bank Fraud
18 USC $ 1028A: Aggravated Identity Theft
18 USC $ 371: Computer Fraud Conspiracy
18 USC $ 1030(a)(4): Computer Fraud
18 USC $ 1956(h): Money Laundering Conspiracy

I'm especially happy to see the Aggravated Identity Theft charge, as it provides an automatic and non-negotiable +2 years to each sentence, which guarantees none of these people will get a "slap on the wrist", unless the prosecution fails to show they used the identities of at least ten individuals.

Although the investigation is labelled "Operation Phish Phry" by the FBI, the US-based charges deal with the money-laundering aspects more than the actual phishing. The phishing portions of the scheme seem to have been run by a group of nearly fifty individuals primarily in Egypt, who would transfer bank account credentials to the US-based ring leaders, who would use their network to move the money through mule accounts, out to cash, and eventually to be wired back to Egypt (minus a commission for the US-based players). Mueller mentions that the funds came from "approximately 5,000 American citizens" who were presumably the victims of these phishing attacks.

This was a tiered operation involving three ring leaders, who used sixteen associates to enlist thirty-eight money mules to receive stolen funds and wire them primarily to Egypt. In order to establish that each of the defendants was definitely involved, the indictment lists 335 "Overt Acts", mostly taking the form of giving a date, place, defendant, and an amount of money transmitted from a stated account to another defendant or unindicted co-conspirator.




(click for larger image, created with i2 Analyst's Notebook by Gary Warner)

The three ring-leaders identified in the indictment were:

Kenneth Joseph Lucas of Los Angeles, California
Nichole Michelle Merzi of Oceanside, California
Jonathan Preston Clark

These three operated a ring of middlemen who recruited the actual money mules. The middlemen were:

Jarrod Michael Akers
Kyle Wendell Akers
Wayne Edwards Arbaugh
Demorris Brooks
Antonio Late Colson
Kenneth Crews
Manu T. Fifita
Jennifer Anabelle Lopez Gonzalez
Tinika Sabrina Gunn
Jason Marcellus Jenkins
Sylvia Johnson
Remar Ahmir Lawton
Kyle Brandon Martin
Frankline Anthony Ragsdale
Steven Aaron Saunders
Rynn Spencer
Raquel Raffi Varjabedian
Candace Marie Zie

Lastly, the actual money mules that were indicted:

Ashley A. Ager
Latina Shaneka Black
Michael Dominick Gunn Dacosta Jr.
Virgil Phillip Daniels
Tramond S. Davis
Shontovia D. Debose
Joshua Vincent Fauncher
Krystal Fontenot
Anthony Donnel Fuller
Michael Christopher Grier
Bryanna Harrington
Shawn K. Jordan
Billy Littlejohn Kelly
Reggie B. Logan, Jr.
Ikinasio Lousiale, Jr.
Raymond V. Mancillas
David P. Mullin
Vincent Nguyen
Ario Plogovii
Brandon R. Ross
Alan Elvis St. Pierre
Courtney Monet Sears
Me Arlene Settle
Paula W. Sims
Jamie Smith
Brandon Kyle Thomas
Christopher Uhamaka
James Michael Viorato
Jovon Darnell Weems
David D. Westbrooks
Bridget Deque Wilkins
Marcus Deshaun Williams

The ages of the defendants range from 19 to 44, with only two being older than 31. Kenneth Crews and Demorris Brooks recruited seven money mules from North Carolina, and one or more unindicted recruiters gathered seven additional mules from Nevada, including at least four from Las Vegas.

Overt Acts are broken into sections:

A. Defendants Lucas and Zie:
Zie opens a bank BOA account, communicates with Lucas by telephone five times, withdraws stolen funds that were tranferred to his bank account. He opens two more account, talks to Lucas 54 times by telephone, and withdraws more stolen funds. Opens more accounts, communicates with Lucas 24 times in a single day, withdraws more stolen funds. The first 14 acts are about these two.

F. Defendants Lucas, Crews, and Logan:
Crews text-messages account numbers opened by Logan to Lucas, who causes funds to move from a victim account to Logan's accounts. Logan withdraws the money.

G. Defendants Lucas and Mancillas:
(Unindicted coconspirator) text-messages Lucas with account numbers opened by Mancillas at BOA. Lucas transfers funds from a victim to the Mancillas account, and Mancillas withdraws the funds.

H. Defendants Lucas and Mullin:
(Unindicted coconspirator) text-messages Lucas the account numbers opened by Mullin at Bank of America. Lucas moves funds from a victim account to the Mullin account, and Mullin withdraws the funds.

They do that over and over and over. The first 200 "Overt Acts" listed all involve Lucas as the one who moves the money from the victim's account.

The credentials for the victim accounts were acquired by phishing, but at this time, we don't have enough details to really know WHICH phishing attacks we're dealing with. It should certainly be pointed out that the phishing attacks were NOT NECESSARILY against Bank of America and Wells Fargo. Funds from any bank can be sent to Mule accounts at any bank, as long as they are both part of the ACH network. Hopefully more details will come out as this case progresses.

The later activities in the indictment make it seem that at least one or more of the defendants had their phone tapped or was cooperating with investigators, such as:

On February 17, 2009, defendants Colson, Weems, and Lucas agreed via telephone that defendant Colson would deliver $1,200 to defendant Lucas

Beginning with Overt Act #201 in the indictment (page 54) the activities turn to Wire Transfers, such as:

On January 12, 2007 in Los Angeles County, defendant J. Akers transmitted $1,300 by Western Union to unindicted coconspirator E.A.

The next forty acts involve Jarrod Michael Akers wiring nearly $100,000 to various parties, mostly unnamed in this indictment. Rehmar Amir Lawton also does more than $30,000 in wire transfers in "Overt Acts". Jonathon Preston Clark, Nichole Michelle Merzi, Candace Marie Zie, Demorris Brooks, Jennifer Lopez Gonzalez and others are also involved in the Wires.

One of the key telephone conversations that was part of the indictment is "Overt Act No. 241":

On December 22, 2008, in Los Angeles County, defendants LUCAS and K. AKERS, in a telephone conversation, discussed the scheme to cause unauthorized transfers of funds into bank accounts for the purpose of allowing coconspirators to withdraw the transferred funds, and defendant LUCAS advised defendant K. AKERS to solicit individuals who need money to assist in the scheme.

Thursday, September 10, 2009

Tien Truong Nguyen pleads Guilty

In April of 2007, the Eastern District of California sent out a Press Release titled "SACRAMENTO MAN CHARGED WITH COMPUTER FRAUD AND AGGRAVATED IDENTITY THEFT" with the description, "Internet Phishing Scheme Used to Steal Thousands of Credit and Debit Card Numbers, Social Security Numbers."

At the University of Alabama at Birmingham, our UAB Computer Forensics program has a mix of Computer & Information Science and Criminal Justice students who are working together to research how phishing investigations are performed. When I saw this story back in the news today, I thought we might have another agent who could help us understand how the US Secret Service investigates phishing. While I'm very glad that Nguyen was picked up, and it looks like ECSAP-trained Senior Special Agent Brian Korbs did an excellent job on the Computer Forensics aspects of this case, unfortunately this wasn't a "phishing investigation."

Several of my students learned about the US Secret Service Electronic Crimes Special Agent Program (ECSAP) while visiting the National Computer Forensics Institute in Hoover, Alabama, about ten miles from our campus, earlier this month. Housed at the NCFI, the Electronic Crimes Task Force for the Birmingham field office of the Secret Service maintains a computer forensics lab where computer forensics examiners from the US Secret Service and the Alabama Bureau of Investigation work side-by-side with examiners from the Alabama District Attorneys Association and the Hoover Police Department to perform examinations and provide training and forensic services to all manner of law enforcement cases. The NCFI provides the equivalent of the Secret Service ECSAP training for state and local law enforcement officers across the country. ECSAP-based courses available in Hoover include "Basic Investigation of Computer and Electronic Crimes Program (BICEP)", "Network Intrusion Responder Program (NITRO)", "Basic Computer Evidence Recovery Training (BCERT)", and "Advanced Computer Evidence Recovery Training (ACERT)", which is ten full weeks of very hands-on training! The NCFI also offers two "Computer Forensics in Court" classes, CFC-J for Judges, and CFC-P for Prosecutors.

Back to the story . . . According to the Affidavit of SSA Brian Korbs, Nguyen was clearly involved in phishing. He was able to establish that from at least October 15, 2005 through January 26, 2007, Nguyen was involved in multiple identity theft, phishing, and credit card fraud activities.

The forensics examination covered:

A Dell Laptop Computer "Latitude" Serial Number 8P530B1
A Toshiba Laptop Computer "M-45" with black thumb drive Serial Number 26234221Q
A Hewlett Packard Laptop Computer "Pavilion D1000" with Serial Number CNF5382K5T
two black USB thumb drives and
A Dell Computer Model 470 Serial Number 37NQC61

These showed that Nguyen was regularly communicating with Eastern Europeans to acquire credit card and debit card numbers, social security numbers, and other personal identification information. Files on the computer were used to create phishing websites, including sites against eBay, Fairwinds Credit Union (Florida), Heritage Bank (Olympia, Washington), Honolulu City and County Employees Credit Union, and others. A program for encoding credit cards, lists of account information, a magnetic card writer, and a laminator were found. Thousands of email addresses, sorted by the state in which they were located, were found to be used for sending out phishing emails state-by-state. (For example, it would make sense to only send "Honolulu City and County Employees Credit Union" phishing emails to people who live in Hawaii.)

The fruit of the phishing was "thousands of pages of customer information" from companies "such as eBay, Western Union, and others." Korbs reported finding
"Hundreds of files of credit card numbers, many with PINs, as well as the true cardholders name, address, email address, password, bank account information, social security number, driver's license number, telephone number, etc." Korbs estimates that "tens of thousands" of identities were on the computer, which is certainly "more than 15" as described in the Federal statute (see below).

Yahoo! chat logs were also found on the computer, which, if printed, would be 16,000 pages of logs. Many of the chats related to buying and selling credit cards, and exchanging email addresses for phish targeting.

In Nguyen's case, the whole story seems to be that he worked with several Romanians to build phishing sites and steal personally identifiable information. Then he provided that information to local accomplices who cashed out in an interesting manner. Apparently GE Capital runs a system of kiosks in California Wal-Mart stores where you can enter your information and be approved for an instant line of credit, which is provided as Wal-Mart coupons that can be used to shop in the store. According to Special Agent Korbs, they did this for more than $200,000 worth of merchandise. In the full indictment, it lists many of the items purchased with these cards, including laptops, monitors, satellite radio systems, 8 ipods, infrared night light, a "Nightowl" night vision scope, CB radios, GPS units, watches, televisions, a radar detector, etc.

When Detective Jim Hudson, from the Placer County Sheriff, and Special Agent Korbs talked to Tien Nguyen after he was arrested on January 26, 2007, he waived his Miranda rights and told them pretty much everything. He admitted to using his computer to trade identities and credit card information, and he explained the GE Capital / Wal Mart scheme.

Enter the 9th Circuit


So, why after all this time is Nguyen just now pleading guilty? Apparently the defense's plan all along has been to say that all of the evidence that was obtained from Nguyen, INCLUDING HIS CONFESSION, was based on a warrantless search of the premises, which meant all of the evidence should be suppressed. After the recent 9th Circuit ruling, Nguyen's lawyer, Micheal K. Cernyar of Long Beach, California, thought he had fresh evidence, and on September 8, 2009 a hearing was held before the Honorable Morrison C. England, Jr, to hear this a plea to establish a new hearing for a new motion to suppress. Here are the basics outlined in the Motion to Suppress:

* Mr. Nguyen was arrested on or about January 26, 2007 on a Ramey Warrant at his residence located at 8225 & 8229 Gerber Road, Sacramento, California. "A warrantless search of the residence" uncovered all of the information, while Nguyen and his companion were detained in the living room of the home.

* On March 27, 2007, Special Agent Korbs applied for a federal search warrant seeking the items seized on January 26, 2007. After receiving this search warrant, Nguyen was indicted April 26, 2007.

* Nguyen moved "to suppress all evidence and any statements obtained" claiming his Fourth Amendment rights were violated, and his motion was denied October 15, 2008.

Here's the new part . . .

7. Last week, in United States v. Gonzalez -- F.3d --, (9th Cir. 2009) (D.C. No. 07-30098), the Ninth Circuit reversed a matter regarding suppression of evidence based upon a warrentless search when applying the recent ruling in Arizona v. Gant. The Ninth Circuit held that Mr. Gonzalez was entitled to benefit from the Supreme Court's ruling in Gant.

8. Counsel believes that the facts in Mr. Nguyen's warrentless search incident to arrest are at the very list similarly situated to those in the Gant and Gonzalez matter.


Rodney Joseph Gant v. Arizona was a case where a man was arrested, and after his arrest police went and searched his vehicle, which he was not in at the time of the arrest. In the car, they found cocaine, not related to the charges for which he had just been arrested, and expanded the charges to include drug possession. Because they did not have a warrant for the vehicular search, and because the perp was not in the vehicle, the Supreme Court ruled that they should not have searched the vehicle without a warrant. (This has been standard practice, called "The Bright Line rule" since 1981 . . .)

How does this relate to the 9th Circuit decision in US. v. Gonzales? It is well-established practice that police can perform a warrantless search "incident to arrest", meaning that after I've arrested you, it is "not unreasonable" to search for evidence related to the crime for which you have been arrested, both on your person, as well as in the immediate vicinity. The question of what is meant by the immediate vicinity is one that has had the legal scholars appealing searches on Fourth Amendment grounds over and over. In this case, it all starts with Chimel v. California. The Supreme Court held that when someone is arrested in their home, officers would be reasonable to search not only the room of the arrest, but other "sufficiently large spaces" where someone might be hiding that could be a risk to officer safety. So, the idea was, if I arrest you in your living room, but I feel that someone might be hiding in the closet, I can look in the closet, without a warrant, to see if your brother is hiding in their with a shotgun planning to jump out and shoot me. I couldn't search the drawer in the end-table, because it is unlikely a potential attacker is hiding in that drawer. Several arguments since then have argued whether you should only be able to do such a search if there was a suspicion that such a risk to officer safety was probable, and then, only in certain "reasonable areas", with three cases helping define those boundaries and expectations -- Maryland v. Buie, Belton v. New York, and Thornton v. United States. Arizona v. Gant reset those expectations by overruling some of those prior standards of when it was reasonable to do an "suspicionless search", which lead to the 9th Circuit Decision.

The judge rightly denied the motion to suppress, since this WAS a search "INCIDENT TO ARREST", and there was EVERY REASON to believe that the computers held relevant evidence of the crime for which Nguyen was being arrested, based on his own statements, and his own permission to search, meaning that NONE of those prior cases really had anything to do with this case.

With his last hope extinguished, Nguyen pleaded guilty, but even then went all the way to the wire. I really thought he was going to go to trial! His lawyer had submitted Questions for the Jury (Voire Dire) as recently as September 2, 2009! I had to chuckle as I read through them . . . he asks if they Bank Online, if they use their Debit Card online, if they have purchased online items in the past year . . . I thought the next question might be "Please state your debit card number slowly, and tell us your PIN." When it came down to the start of the Jury Trial, at 9:00 am on September 8th, the Courtroom minutes tell us that Nguyen asked for a five minute recess, and came back in and pleaded guilty to counts 1-4. He then asked for another recess, and came back and pleaded guilty to count 5.

The Penalty Slip with the indictment includes the charges. Especially sweet that the Aggravated Identity Theft adds an automatic +2 years. Nguyen was found to have a shotgun in his bedroom as well, a Remington 870 Express Magnum.

18 USC § 371 - Conspiracy to Commit Computer Fraud and Access Device Fraud:
- Not more than $250,000 or notmore than gross gain or loss;
- Not more than 5 years imprisonment, or both
- Not more than 3 years of supervised release

18 USC § 1029(a)(2) - Access Device Fraud
- Not more than $250,000 or not more than gross gain or gross loss;
- Not more than 5 years imprisonment, or both
- Not more than 3 years of supervised release

18 USC § 1029(a)(3) - Possession of More than 15 Unauthorized Access Devices
- Not more than $250,000 or not more than gross gain or gross loss;
- Not more than 10 years imprisonment, or both
- Not more than 3 years of supervised release

18 USC § 1028A(a)(1) - Aggravated Identity Theft
- Not more than $250,000 or not more than gross gain or gross loss;
- Not more than 2 years imprisonment, or both
- Not more than 3 years of supervised release

18 USC § 922(g)(1) - Felon in Possession of a Firearm or Ammunition
- Not more than $250,000 or not more than gross gain or gross loss;
- Not more than 10 years imprisonment, or both
- Not more than 3 years of supervised release

(Nguyen had already spent "more than a year" in jail back in 1999 for "Receipt of Stolen Property" and "Making and Passing Fictitious Checks", but these were state of California crimes rather than Federal crimes.)

The sentencing for Nguyen will be on November 19th, at 9:00 am.

The question for my student's research project is - "Was this a phishing investigation?" We haven't talked to Special Agent Korbs yet, but from a reading of the court documents, I believe the answer will be "No." This was a credit card fraud investigation, which uncovered a phishing case after the Computer Forensics evidence was evaluated.

The on-going and unsolved question for our research is, "Could this case have been worked the other way around?" If we had started with the Honolulu City and County Employees Credit Union phishing site, would we have still ended up at Tien Truong Nguyen's front door? If you are a law enforcement officer with first-hand experience in phishing investigations, we'd love to talk with you and get your opinion.

References: Stranger than Dictum: Why Arizona v. Gant Compels the Conclusion that Suspicionless Buie Searches Incident to Lawful Arrests are Unconstitutional by Colin Miller, Assistant Professor of the John Marshall Law School.

Sunday, June 14, 2009

Money Laundering $1 at a time - a win for the UK's PCeU

In London a little-known police unit called the Police Central E-Crime Unit (PCeU) has scored another big win. For several years people have been seeing tracks they didn't remember purchasing showing up on their credit card statements. In England they referred to this as "51 pence fraud", and explained that buying a track was a way that the criminals were using to test stolen Credit Cards to see whether the card was valid. The theory was that if the card was valid, the criminals would then move on to bigger and better purchase, or they would sell it as a "proven" card.

The PCeU found that there was actually something else going on. Working with the FBI, they arrested three women and seven men between the ages of 19 and 46 for buying their own music on iTunes and Amazon.com. The group of DJ's recorded at least 19 tracks and sold them via distribution company Tunecore, who marketed the tracks through the two online giants. They then used more than 1500 stolen credit cards to buy their own music repeatedly. As the creators of the music, their $750,000 (£469,000) in purchases earned them $300,000 in profits!

The investigation, which was launched in February of this year, culminated in simultaneous arrests, conducted on June 10th by more than 60 officers in London, Birmingham, Wolverhampton, and Kent, were used to round up the first nine members, and a tenth member was arrested later, according to the Times Online.

The PCeU certainly has a great sounding set of goals:

# Analysis and development of intelligence on e-crime to produce actionable operational products, in collaboration with other agencies.

# Intelligence-led disruption of e-crime.

# Development and maintenance of a collaborative network of police, government and industry partners on e-crime.

# Exchange of information and intelligence concerning e-crime with principal stakeholders, including government departments, industry partners, academia, and the charitable sector.

# Provision of education and preventative advice about e-crime to industry and the public.

# Promotion of standards for training, procedure and response to e-crime.

# Co-ordination of research on emerging e-crime threats and vulnerabilities (in collaboration with industry partners, government agencies and academia) and provision of advice on this to all stakeholders.

Some will think that sounds like the old National Hi-Tech Crime Unit, which was moved back in April of 2006 to the Serious Organised Crime Agency (SOCA). A controversy began brewing in early 2008 as various parties began calling for the creation of a new cybercrime unit, claiming that SOCA was devoting less than 2% of its staff and less than 1% of its budget to fighting e-crime.". The Tories began a public shaming attack trying to raise the £1.3m that was needed to get the unit started up. Not all covert law enforcement activities end up as line items in government reports, and SOCA was forced to come to its own defense in the press, revealing some of its operations, including the fact that a 58 person staff was focused "almost exclusively on cybercrime", while 140 liaison officers work worldwide on international matters, including cybercrime coordination with five other major western countries.

The money was approved, and now, with the PCeU officially online, SOCA's 2009-2010 plan reveals that technology enabled crime and fiscal fraud will continue to be a small part of its overall operations -- about 5% according to p. 12 of their Annual Plan, but as with so many other parts of crime, more and more computerization is occurring. Can we really say that the "Criminal finances and profits" portion of SOCA's 12% dedicated to "Criminals and their businesses" is not going to include a great deal of cybercrime?

ZD Net.UK calls Detective Superintendent Charlie McMurdie "one of the architects of the Police Central e-Crime Unit". McMurdie envisioned a "National Fraud Reporting Centre", which sounds very similar to the US's Internet Crime and Complaint Center - a place where the public could report the frauds they have experienced to a central law enforcement body. Questions have been raised in the British press if their government is serious about fighting cybercrime in articles such as: Can £7m dent £105bn cyber crime menace?, which admits they will not have the budget to be able to do centralized reporting of e-crime as was originally intended, especially with that £7m being spread over 3 years. McMurdie replies that with a limited budget, her unit will only be successful with great cooperation from industry, especially of their expertise. In that way PCeU may be more similar to some of the successful FBI public-private partnerships, such as the National Cyber Forensics Training Alliance, recently praised by President Obama's Cybersecurity review, where industry experts gather to share their expertise with Federal law enforcement, or the InfraGard program, where more than 28,000 citizens who work in security and infrastructure companies share their knowledge with their peers in government. McMurdie's push was described back in October in the Silicon.com article "Do you have what it takes to be an e-caped crusader?"

If someone from the PCeU's Partnership Development Team wants to chat, feel free to reach out.

Saturday, May 02, 2009

University Spammers, the Shah brothers, arrested

Congratulations to the Assistant US Attorney for Western Missouri, Matthew Wolesky, and the FBI investigators who have arrested and indicted the Shah brothers! The news was released in a Kansas City FBI Press Release on April 29th.

Amir Ahmad Shah, 28, and his brother, Osmaan Ahmad Shah along with their business, I2O, Inc, and their co-collaborators Liu Guang Ming of China, and Paul Zucker, 55, of New Jersey were named in the 51-count indictment.

Both Amir Shah and Osmaan Shah are listed on the Entrepreneur site, "The Rise To The Top", where they are listed as "Experts" on the site, which provides "Entrepreneurship Education for Young Entrepreneurs". (Any guesses on whether they will be there by Monday? haha! Just in case, I've taken screen shots for you here:



original URL: http://www.therisetothetop.com/guest-expert-profile.php?id=22



original URL: http://www.therisetothetop.com/guest-expert-profile.php?id=24

According to "CrunchBase", Osmaan Shah received his BS in Finance & Banking in 2006, and his MBA in 2009, both from the University of Missouri. His profile says:

Osmaan Shah is the co-founder and lead software developer of Noog. In his 7+ years of development experience, he exhibits a passion for dynamic front-end web design (javascript, AJAX/Comet). He specializes in the incubation of creative new products and online portals targeted towards students and young retail consumers. Mr. Shah is also the a Director and co-founder of VistaClick where he serves as the online marketing campaign manager.


Amir Shah's company is VistaClick.


(Original URL: http://www.vistaclick.com)

VistaClick's website describes an Affiliate Program where you could become one of their 17,000 "registered campus affiliates".

I wasn't able to pull the indictment from Pacer myself, as the "CM/ECF System for the Western District of Missouri is currently down for maintenance" (sigh), but someone else had already posted it online. (See indictment for case mowdce 4:2009cr00141, courtesy of Columbia Daily Tribune).

Here's what we can glean from the 59 page indictment:

First, the charges, which are all applied to the Shah brothers and to I2O, Inc. Liu Guang Ming and Paul Zucker are included in charges 1, 7-16, and 43-51.

Count One: 18 USC § 371 (Conspiracy), a Class D Felony, with possible sentence not more than 5 years with not more than $250,000 fine.

Counts Two through Six: 18 USC § 1030(a)(2) (Fraud in Connection with Computers), a Class C Felony, with possible sentence not more than 5 years with not more than $250,000 fine.

Count Seven: 18 USC § 1030(a)(5) (Fraud in Connection with Computers), a Class C Felony, with possible sentence not more than 10 years with not more than $250,000 fine.

Counts Eight through Sixteen: 18 USC § 1037(a)(1) (Fraud in Connection with Email), a Class E Felony, not more than 3 years, with not more than $250,000 fine.

Counts Seventeen through Forty-Two: 18 USC § 1037(a)(2) (Fraud in Connection with Email), not more than 3 years, with not more than $250,000 fine.

Counts Forty-Three through Fifty-One: 18 USC § 1037(a)(3) (Fraud in Connection with Email)

In the indictment, the defendants are said to have developed an email-harvesting program and used the program to harvest email addresses from the University of Missouri and over two thousand other United States universities and colleges. The defendants then used this database, which included more than 8 million email addresses, to send email messages advertising products that were specifically targeted to college students. The indictment covers thirty-one separate spam campaigns sent using this database.

The emails would claim to be sent from their local "campus representatives", and would often refer to the company as being "alumni-owned" in an attempt to make recipients believe their use of the advertised service would somehow benefit their alma mater or its graduates.

Many of the emails were sent from an "Offshore Bullet Proof Hosting" company located in China. Their emailing software falsified email header information and rotated the subject lines, reply-to addresses, message contents, and advertised URLs in an attempt to bypass spam filters. They also used false information when registering domain names.

After being investigated, and having search warrants served against their homes and business in an investigation into spam messages targeted at University of Missouri students, the spammers merely stopped sending email to any of the addresses harvested from the University of Missouri.

The defendants would register as many as sixty unique domain names for a single spam campaign, all pointing at identical content. They also started a social networking site called "noog.com" which also was advertised by spam. More than $4.1 million in product sales came from the defendants' spam campaigns. They attempted to conceal their earnings both through real estate purchases and sending large sums of money out of country.

In a useful part of the indictment that might be copied by others, definitions for the following terms are provided:
Addresses
Botnet
Domain
Domain name
Domain name service
Email harvesting
Email header
Instant messaging
Internet
Internet Protocol address (IP address)
Internet service provider (ISP)
Mail server
Name server
Proxy server
Realtime Blackhole List (RBL)
Server
Spam filter
Viruses
Website
Web Host

Here's how the roles of the defendants are described:

Amir Ahmad Shah - the co-owner and president of I2O, Inc. - the overall leader of the spam operations and the "idea guy".

Osmaan Ahmad Shah - the co-owner of I2O, Inc - the Chief Operating Officer and the "computer guy" in the partnership. He created the email extgractors, administered the websites, designed the websites, and dealt with other programming and implementation matters.

Liu Guang Ming - rented forty servers under his control in China to host websites, send spam, and search for proxies that could be used for sending spam.

Paul Fredric Zucker - a spammer who purchased proxies from the Shahs, and at other times sold proxies to the Shahs. He also leased space from Ming.

Several other unindicted and unnamed co-conspirators are mentioned, included a family member who ran "VistaClick Pakistan" for the Shahs.

Other companies in the conspiracy were DirectPO, VistaClick, Funding Junction, Veridio, OIBA, Textbook Registry, and Your City Development.

The Shahs began their operation "in or before 2001" by harvesting student email addresses. They began working with Ming in or before 2002, conducting conversations via AOL Instant Messenger. The ad they responded to read:


Servers are located in China and run by some of their largest ISPs. Our tech support team manages servers around the clock with constant contact from China to US. We have several sites sending millions of emails per day. Unlike other hosts, you will NOT need to switch domain names or experience periods of downtime. Our uptime guarantee is 90%. If you are serious about bulk mailing, you have come to the right place.


I was able to find a copy of a post by "AMIR SHAH" back on October 11, 2002, advertising "BULLET PROOF CHINA HOSTING" on this URL on sidetrak.com as an example.

In that ad, Amir offers to send messages for $30 per million emails sent. He used the AOL instant messager id "rulubos@aol.com".

Amir Shah also had a twitter account with that same identity, rulubos. He hasn't posted anything there since January 5th, 2009, when his last post was "looking at twitter and wondering if I should just incorporate this feature into Noog."

Amir follows Jianxiong Song. Hmmm...let's look at some more twitter links . . . Jianxiong is following WaqasShah, whose last twitter post is "WaqasShah is relieved" posted on APril 24th. WaqasShah follows noog_com, who was testing bloog mobile, according to their last twitter on April 17th. Noog has an interesting group of Venture Capitalists that he follows, but I won't list them here.

OK, back to the indictment.

In chat logs found on the computers, Zucker trains O. Shah in the art of spamming, and they communicate about how many proxies they would need to send 2 million emails, being disappointed with a rate of only 110,000 per hour. O. Shah later tells Zucker (July 14, 2003) that he can now send 1 million emails per hour with a 65% delivery rate (unblocked/unfiltered). Later, O. Shah tells his brother A. Shah that by plugging directly into the University of Missouri Columbia network "with a cable not using the wireless" he can send 2 million spam messages per hour from the school.

Search warrants were served against the Shah residence in Columbia, Missouri and their business address also in Columbia on February 23, 2005. They found more than 3 million student email addresses harvested from 2002, 5 million harvested from 2003, and 37.5 million AOL email addresses, 33.7 million MSN addresses, 10.8 Hotmail addresses, 5.2 million Yahoo addresses, and more than 4 million United Kingdom email addresses.

The indictment shows that the crew was identifying a ridiculous number of proxy servers which they could use to "bounce mail" from. For a price of $75 per week, Zucker was able to provide them "1500-2500 proxies twice a day". Originally, the transaction had gone the other way, with Shah providing a list of 45,000 proxies to Zucker earlier, receiving payment for his services via Paypal.

Zucker communicated with O. Shah about how to obtain and use the software program "Dark Mailer", and sent Shah a copy of the program on February 3, 2005. They also used the programs Supermailer and "Group Mail".

Bank records showed that the Shahs transferred more than $30,000 to Ming for hosting services.

Other chats showed the brothers discussing ways to make money. For example, they sent spam for a "teeth whitening" service, where they received a commission for successful sales. The brother said "if we need to mail a million or two to get 10,000 kids...then so be it...who cares."

Here's an example of their teeth-whitening emails, from April 1, 2004, which will illustrate how the SHAH brothers took advantage of students trust in their university relationships:

"Each year, several alumni-owned companies offer various specials to our students and faculty. This month, the university has been offered a special discount on custom fitted teeth whitening systems. Alumni-owned, Custom Bright, Inc., is offering its products to students and faculty at significant discounts all this month. We encourage you to visit their website and take advantage of this alumni offer."

This continued all the way through 2009, with messages like this one, sent March 1, 2009:

"As many of you may be aware, our campus has been offered a special discount on professional custom-fitted teeth whitening systems from a company run by our very own alumni. There will be several campus representatives (like myself) giving out more information over the next 2 weeks."

The brothers discussed having "a more forceful message" to encourage registration in a particular textbook system they were spamming:

"With higher tuition and course material costs, we are working to find new ways of saving students money. This semester, we have implemented a new textbook buyback program that will get students better payouts at the semester ending buyback and may also increase used textbook availability. You MUST complete your registration before the end of this week if you wish to be eligible for this semester's buyback."

Other campaigns that used similar spam sold Digital Cameras, iPods, NCAA Basketball merchandise, and Magazine subscriptions.

Some of the many domain names they used:

surveyproject.org
surveydirect.org
campuschange.org
whiteningtoday.com
whiteningnow.com
discoverwhitening.com
myschoolipods.com
studentipods.com
campusipods.com
semestersavings.com
semesterdiscounts.com
saveatcollege.com
collegedecember.com
estudentoffers.com
mycollegedeals.com
collegefuture.com
campusfuture.com
campusinput.com
whiteningservices.com
whiteningovernight.com
whiteninglabs.com
mycampusnanos.com
campusnanos.com
schoolipods.com

The full indictment gives date ranges for these and many other domain names.

Some of the purchases the Shah brothers made include:

a home in Columbia - $191,123.

a luxury lost in St. Louis - $251,861.

paying off a house in St. Louis - $33,698.

a downpayment on a Lexus sedan - $8,800.

The forfeiture of any assets, up to a total of $4,191,966.57 is also requested, which will come from several bank accounts, and the sale of properties at:

1301 Fieldcrest, Columbia, MO
1520 Washington Avenue, Unit #301, St. Louis, MO
a parking space (?)
5417 Idaho Avenue, St. Louis, MO

a 2002 Lexus (Missouri plate: CA9R6B)
a 2001 BMW (Missouri plate: 391ZEP)

Update



Apparently the Shah brothers indictment has shared with other spammers some good tips on this type of spam. Here's a message that one of my students at UAB received on April 30, 2009:

_____________________________________
From: Jenna T. [jenna@OverstockApple.com]
Sent: Thursday, April 30, 2009 2:20 AM
To: (name of my student)
Subject: Student/Faculty Discount

Dear Students/Faculty,

As you may have heard, several alumni-owned companies have teamed up to sponsor a campus-wide gift for our students and faculty. Working with Apple, they have acquired a small quantity of the new iPod Nano Chrome. This limited supply has now been made available to students and faculty at a significant discount. If you were at all interested in getting one of these iPods with this educational discount, please be sure to place your order online before this offer expires NEXT WEEK.

http://www.OverstockApple.com/h/3189094

Have a great summer!

Jenna T.
OverstockApple.com Student Representative



Have you seen a recent spam (after April 24th) from this group, pretending to be offering a discount for products from an "alumni-owned company"? If you can send it to me WITH HEADERS, I'd very much like to see it. Send it to: alumnispam@askgar.com