Saturday, September 22, 2007

Is the Internet a Prosecution-Free Zone?

Jörg Ziercke, the chief of the Bundeskriminalamt (BKA) in Germany, was quoted in a
press release on the BFK website, following a simultaneous phishing raid in Bad Homburg, Düsseldorf, Köln, Frankfurt and Elmshorn. His words lay down an interesting challenge:

"This case shows once more: Criminal organizations are increasingly using the Internet in order to make enormous profits with an allegedly low risk of discovery." He said that prosecutors are constantly facing new challenges regarding Cyber Crime, but that "the Internet cannot develop into a prosecution-free zone."

That's exactly what's at risk. We have to decide whether the Internet is going to be patrolled and prosecuted just like the streets and alleys of our cities, or whether we are going to allow crime to occur unabated there.

In the BKA case, two women, aged 22 and 23, and six men, aged from 20 to 36 years old, have been imprisoned pending their court appearance. Two others are also charged but were not taken into custody.

Sounds good, and congratulations to the BKA! But what about all the other phishers? So far in September, we've made positive confirmation on more than THREE THOUSAND phishing sites in UAB's Computer Forensics Research lab. We can't continue to allow it to take 18 months before a phishing investigation leads to charges.

The more evidence we gather, and the more relationships we find between phishing campaigns, the greater the chance that we can get some law enforcement action.

Remember, if you hear of someone who has been a victim of Identity Theft, Phishing, or any other Cyber Crime, please make sure they fill out a complaint at the Internet Crime and Complaint Center, http://www.ic3.gov/.

Also, if there has not been a financial loss, phishing sites still need to be reported! When you receive a phishing email, please help by sending it to:

pirt@castlecops.com

or by using the webform at:

http://www.castlecops.com/pirt

Let's make sure the Internet doesn't become a "Prosecution-Free Zone".

Tuesday, September 04, 2007

TJX: From Florida to the Ukraine?

Last week the media lit up with speculations that 24 year old Ukrainian hacker, Maksym Yastremskiy, who had been arrested in Turkey on August 2nd, may be behind the TJX Credit Card hack. The Boston Globe's Ross Kerber may have had the best coverage with his story "Suspect
named in TJX credit card probe"
on August 21. The story quoted Greg Crabb of the US Postal Inspection Service's global investigations division. Crabb said Maksym was "likely the largest seller of stolen TJX numbers". TJX, the financial company in the TJ Maxx conglomerate, believes that as many as 45.7 million credit cards were stolen during a breach during 2005 and 2006, which captured credit card transactions all the way back to 2003.

How's your Turkish? This August 2nd article , "Antalya'da yakalanan Ukraynalı hacker 80 bin kişiyi dolandırmış", interviews Turkish police officer, Feyzullah Arslan, who arrested Maksym after a sting in a luxury night club in Kerem, Turkey.



Using a "follow-the-money" investigative technique, the investigation began with 10 guilty pleas in Florida back in March from a crew of careless cyber criminals who had racked up millions of dollars of purchases from Wal-Mart and other Florida retailers using stolen credit cards that tracked back to TJX. The Florida investigation actually started when Gainesville police were contacted regarding two local Wal-Mart stores who had made individual gift-card sales in the amounts of $18,000 and $24,000. HINT: IF SOMEONE WANTS $24,000 IN WAL-MART GIFT CARD, THERE MAY BE A CRIME LYING ABOUT.

Those cards were used at a Sam's Club in Miami, along with many other cards, to buy large quantities of electronics and jewelry. At that time, the cards were all tracked back to TJX, and an estimate of the loss from the database hack was released in the news -- Gainesville police Sergeant Ray Barber revealed "They estimate the loss from that hack job to be around $8 million", although this particular crew had only rung up $1 million in charges so far. (See, for example: "Florida police make arrests in TJX, Winners credit card theft".

The first six, arrested March 19, were:

Irving Jose Escobar, 18
Reinier Camaraza Alvarez, 27
Julio Oscar Alberti, 33
Dianelly Hernandez, 19
Nair Zuleima Alvarez, 40
Zenia Mercedes Llorente

All ten, including the additional:

Erick Fernandez Rodriguez
Hector Alfaro Rodriguez
Alexis Arcia
Armando Ochoa

have Mugshots posted on eweek.com.




In a USA Today story a map of Irving Escobar's shopping spree, where he bought as many as 60 $400 gift cards in a single location, and then spent the money from November 1st to January 18th, is mapped out.



The big break in this first case came when an alert Wal-Mart employee followed the gift card purchases out of the store and recorded their license plate number. (For more, see the March 24, 2007 Boston Globe story by Ross Kerber, quoted here: Scam May Be Tied to Stolen TJX Data

A second Florida-based TJX gang plead guilty in late June. This group was charged with possessing 172,000 sets of credit card data, which had been used to make at least $75 Million in bogus credit card charges. Arrested in this scam were:

Miguel Alegria, 46, of Hialeah, FL
Raynier Pupo, 22, of Miami, FL
Ariel Montero, 32, of Aventura, FL
Javier Padron-Bravo, 35, of Aventura, FL
Julio Lopez, 30, of Hialeah, FL
and Anett VIllar, 26, of Hialeah, FL



Alegria, Pupo, Montero, and Padron-Bravo plead guilty to conspiracy in exchange for a plea agreement that included cooperation.

The Nashville Secret Service ran the investigation as "Operation Blinky" named for the first suspect's online name, which they co-opted as an undercover identity. For more see: TJX, Polo Data Surfaces In Another Credit Card Bust.

Friday, August 31, 2007

The World v. AllofMP3.com & Russian Copyright Law

Music collectors on the Internet got a mixed message this week as a Russian court found that Denis Kvasov, the head of AllofMP3.com was innocent of all charges.

While Napster, iTunes, WalMart and other online music retailers sell songs for 75 cents to 99 cents each, AllofMP3.com had nearly as large a selection and sold tracks for a mere 10 cents apiece or entire albums for $1 apiece.

The US-based music industry cried foul, and the US Department of Commerce agreed, making the closure of AllofMP3.com a requirement in Russia's 2006 attempt to join the World Trade Organization. Eight online music sites in Russia were shut down, and criminal charges brought against their owners in July, prior to the WTO Summit.

The company's website made clear that users should make sure the use of AllofMP3.com did not violate copyright laws in their home country.

No news on the RIAA Lawsuit against AllofMP3.com, where they are asking for $150,000 in damages for each of the 11 million songs in their catalog, or a $1.65 Trillion lawsuit.

In Russia, the copyright law requires that selling copyrighted material is legal, if a 15% royalty payment is paid to ROM, the Russian Organization for Multimedia and Digital Systems. Oleg Nezus, speaking for ROM, says that all of the major record labels have royalty payments waiting for them in Russia, but EMI and Universal have refused to accept their payments - not wanting to send the message that 10 cent downloads are adequate for their constituents.

Zemchenkov, of the Russian Anti-Piracy Organization was praising Russia's newly beefed up anti-piracy laws, which carry penalties of up to six years in prison for DVD pirates, as recently as April -- see: Hollywood Reporter: Putin Beefs Up Penalties for Piracy. Now, he is saying this lack of action against AllofMP3.com "sets a very bad precedent".

Zemchenkov, whose organization has the support of the Motion Picture Association (MPA), has been active in the Coalition for Intellectual Property Rights, and has attended all of the meetings of the "Russian Federation IP Working Group". CIPR also produces a monthly newsletter about IPR issues in Russia. In their most recent issue they conclude their summary of the case with this statement:


the court was not convinced that EMI, Warner and Universal Music have rights to the music sold by Allofmp3


citing as their source this August 16th article in vedomosti.ru:

Вину Allofmp3 не доказали (Not Guilty Allofmp3 Vindicated)

Суд оправдал бывшего гендиректора “Медиасервисез”, владевшей музыкальным интернет-магазином Allofmp3. Прокуратура обвиняла его в нарушении прав звукозаписывающих компаний, но суд не нашел доказательств того, что EMI, Warner и Universal Music действительно владеют правами на музыку, которую продавал Allofmp3.

Which means (gar's rough computer-assisted translation):

Court absolved former general director MediaServices who owned the internet music shop Allofmp3. The office of the public prosecutor accused it of violating the rights of the production companies, but the court did not find evidence that EMI, Warner, and Universal Music really own rights for the music which was sold on Allofmp3.


The prosecutor in the case, had claimed that from September 4, 2003 until December 1, 2005, Kvasov had infringed on the rights of Universal, Warner, and EMI by distributing music for which they owned the rights.

The ruling went on to find there was no reason they could not return to business, which AllofMp3.com announced on their website this morning with the headline "The Service Will Be Resumed".

The press release, dated August 31st, says:

"The service will be resumed in the foreseeable future. We are doing our best at the moment to ensure that all our users can use their accounts, top up balance and order music."

This is a major blow to copyright holders around the world, as it sends a message that as long as you pay your license fee to the Russians, you can sell anything you want for any price you want. The Russians did have 1600+ arrests for copyright infringment in 2006, but it is believed these were cases against people who hadn't paid their local "fees".

A survey of Intellectual Property brand owners conducted in 2006 by CIPR had found that 6% believed the situation with regards to IPR in Russia had improved significantly while 46% believed it had improved slightly. (See Survey Results). I wonder what they will think after this ruling?

Tuesday, August 28, 2007

How Far Would You Travel for $7 Million in Gold?

How far would you travel for $7 million in gold bars? For Igor Klopov of Moscow, Russia, the answer was "all the way to Manhattan".

In an August 16, 2007 Press Release from the Manhattan District Attorney's office the full scheme was laid out as charges were pressed against Klopov and his four American co-conspirators.

Klopov found his inspiration as he read the Forbes 400 Richest People, determining that these would be the perfect victims. Using a combination of computer hacking, open source investigation, and actually hiring private detectives, he built profiles on his targets, but he felt safer using Americans to do his dirty work.

Using Monster.com and CareerBuilder.com, Klopov recruited Americans who would act as his agents to do the "real world" work. Klopov provided them with First Class air fare, 5-star hotels, limousine service, fake identities, and all of the false documents necessary to accomplish his frauds.

The co-defendants who were charged last week include:

Westley Watson, 37, Detroit MI
Lee Monopoli, 41, Fort Lauderdale, FL
James Dalton, 33, Konroe TX
Richard Hoskins, 29, London KY

JP Morgan Chase alerted law enforcement when they realized that James Dalton was attempting to withdraw $7 Million from the account of Charles Wyly. The Manhattan Identity Theft Task Force went into action, setting up an undercover sting.

In this operation, an undercover Secret Service agent managed to get himself "recruited" by Klopov. As proof that the transaction was completed, he arranged to have himself photographed with $7 Million in gold bars, which Klopov decided to come and handle himself.

He "snuck in" to the country on a private plane to meet the undercover officer, who arrested him at the airport in New York back in May.

Monday, August 20, 2007

Aggrevated Identity Theft Law in Action

There are so many interesting angles to the story this week about a case in Tucson, Arizona. The conviction actually went down in March 2007, with Jacob Vincent Green-Bressler, now 21 years old, being one of the 16 individuals who had been indicted in 2005 for trafficking in stolen identities. (See: Global Web Fraud Case has 17 Local Indictments in the Arizona Star, November 8, 2005.

Green-Bressler and company were not identity thieves themselves. They were not putting together phishing sites. They instead served in the role of "cashiers". A "cashier" in the Identity Theft business is someone who is willing to perform the risky role of converting the stolen identity information into an ATM Card and using that counterfeit card to drain a bank account.

During their time of activity, Jacob's gang obtained identities for 4,500 individuals from criminal conspirators in at least 20 countries, including Vietnam, Pakistan, Jordan, Egypt, the Philippines, Macedonia, Romania, Estonia, Lebanon, Mexico, France and the United Kingdom. They then used those identities to create counterfeit ATM cards which they used to steal and send overseas nearly $300,000 from various banking accounts. As their commission on these services, Jacob and friends kept $148,000 -- a 50% commission!

So what does this have to do with the Aggravated Identity Theft Law?

Jacob's original sentence would have been sixty months for his crime, but because of Title 18 section 1028A - the Aggravated Identity Theft Act, a mandatory +2 years is added to the jail time. With criminals getting so many light sentences for cyber crimes, its nice to see someone getting the Extra Two.

That's one of the reasons the Attorney General supported this act back in 2002. See this Congressional Testimony from Dan Collins, the Chief Privacy Officer of the US Department of Justice at the time. S.2541, the "Identity Theft Penalty Enforcement Act" was a good idea, and one that should be used more often in the courts.

The full list of defendants in this case:

Robbin Shea Brown, 24
Jacob Vincent Green-Bressler, 19
Joshua Trever Lee Breshears, 20
David Lee Merrill, 25
Corrine Dazette Perez, 24
Richard Daniel Staton, 24
Rollin Edward Vaughn II, 23
Randi Michelle Rodela, 20
Joseph David Wallum, 20
Joseph Robert Jando, 21
Martin Corey Halula, 19
James Dennis Olsen, 19
Steven Don Olsen, 23
Christopher James Griffin, 23
Daniel Roy Leon Mendez, 20
Robin Duane Brown, 52
Ana Marie Honeycutt, 32

(See: http://www.usdoj.gov/usao/az/press_releases/2005/2005-199(Brown%20etal).pdf )

I look forward to seeing how many of the others also get a taste of the Aggravated Identity Theft penalties!

Monday, August 06, 2007

AffPower Indictments Scare Affiliates!

Today I heard the news that the "AffPower" drug network is being shut down, starting with 18 arrests in Texas, Florida, Colorado, New York, and Oregon.

Congratulations, Corbin A. Weiss, Special Assistant US Attorney with the Computer Crime and Intellectual Property Section of the DOJ! What a great indictment!

Here's a link to the full Indictment (caution: 124 pages!)

http://www.courthousenews.com/Affpower.pdf

I have to say, I LOVE to hear about scared bad guys, and THIS one has people scared who have previously considered themselves bulletproof. Why? Because the AFFILIATES are also being arrested.

The 18 are:

3 doctors
2 pharmacists
1 pharmacy operator
1 credit card processor
and
8 website affiliates

Mark Anthony Heredia, Manager and administrator in the Affpower enterprise in San Jose, Costa Rica;

William Polk Harrington and Todd Wurtzel, AKA "Sonny Gallo", recruited doctors and pharmacies to participate in the Affpower enterprise and managed the doctors they recruited;

Claude Covino, operated Saveon RX Pharmacy in Florida, part of the Affpower enterprise, and recruited other pharmacies to participate;

Dolores Lovin and Mary Aronson, owned, operated, and were licensed pharmacists working in St. Vrain Pharmacy in Colorado;

Subramanya K. Prasad, MD, Chandresh B. Shah, MD, and Gerald C. Morris, MD, were licensed medical doctors who issued prescriptions for controlled and non-controlled prescription drugs through and on behalf of the Affpower enterprise;

Philip James Bidwell, 50, of Frisco, TX, is accused of operating multiple affiliated websites and recruiting other affiliates to the enterprise and managing them. He has been released on $1 million bail.

Henriko Chung is charged with the same activities as Bidwell.

David Eldon Fisher, Richard Edward Koch, Jeffrey A. Light, (Name Withdrawn By Request),
Peter P. Bragansa, and Bessie K. Ricoarango were affpower affiliates who operated multiple affiliate websites

Nathan Jacobson was the owner and manager of RX Payments, Ltd, a credit card processing agency in Tel Aviv, Israel.

How hard are they hitting the Website Affiliates?

Jeffrey A. Light, 44, of Heath, TX, has been released on $1 million bail.

(Name withdrawn by request), 46, of Dallas, has been released on $500,000 bail.

Chandresh Shah faces additional charges in Georgia, Subramanya Prasad faces additional charges in Kentucky and Ohio, and Gerald Morris faces additional charges in Massachusetts, the states where each was licensed to practice medicine.

Dolores Lovin and Mary Aronson face additional charges in Colorado, and Claude Covino faces additional charges in Florida, the states where they were licensed in pharmaceutical practice.

ALL of the defendants face racketeering charges and much more in this 313 count indictment.

--------------

But does this really scare the bad guys? ABSOLUTELY! Let's drop in and visit a few websites where they bad guys talk about their pill-spamming and see what they are saying:

We'll start at RxAffiliateForum.com.

http://rxaffiliateforum.com/showthread.php?t=5280

ChesterCoperPot, an RXAffiliateForum member since 2003 whose made more than 400 posts to this forum, starts things off by quoting in bold text "AND EIGHT AFFILIATE WEBSITE OPERATORS".

Pillz, a "senior member" with over 200 posts, adds:
"BTW, the gov't is going for RICO on this."

RxRob, another "senior member" with over 1400 posts, says:
"OMFG, they charged Bess (WICKED on this forum). She was just an Affiliate!"

Rumple, trying to stem the panic, posts:

------------

"Settle down boys and girls......

Trying to win a case against an affiliate would be very hard to do, the reason you never hear about affiliates being charged is because it would be damn hard to prove without a doubt in a court that an affiliate new that Affpower was breaking the laws that they were breaking...

You didnt touch any of the money being moved into Dave's accounts and you didnt handle any of the drugs being shipped .........so stop worring

It would be a waste of time and effort for the government to even try to get a case against an affiliate that it could win, you would have to have direct business dealings with Dave for them to have something on you..."

--------

And that is EXACTLY what needs to happen if we are going to stop pill-spam. If the government is serious about wanting to stop this, they need to convince the jury and the sentencing judge that it doesn't matter if they "touched the money" or if they didn't "handle the drugs". What matters is that their behavior makes this entire scheme possible, and puts American lives in danger for their own greed.

Some of the websites involved include:

buyallprescriptions.com
us-meds.com
secureprescriptionsonline.com
ubuyrx.com
millennium-pharmacy.com
medlinedrugs.com
officialpillsrx.com
horizonmeds.com
valuetrustrx.com
drugprescribe.com
rxdrugstore.us
life-meds.com
secure-pills-online.com
dietprescriptions.org
expressdrugstore.biz
easyprescribe.com
weldonpharmacy.com
pillscouts.com
pills-discount.info
medsshop.com
medsource-pharmacy.com
orderonlinepharmacy.com
netmedsdirect.cojm
medsdirect-md.com
ndapharmacy.com
giantrx.com
rxmedcorp.com
thepillstore.com
drugdepot.com
cheappillsonline.com
american-meds-direct.com
cheap-us-pharmacy.com
realpills.com
silverdrugs.com
rx-listings.com
mgdrugstore.com
mrhappypill.com


==========================
Let's peek in on a couple more forums and see how they affiliates are taking the news so far:

-------

http://www.epharmacywatch.com/freeboard/ubbthreads.php/ubb/showflat/Number/536852

On ePharmacyWatch everybody wants to know WHICH WEBSITES are involved! They are also scurrying to see if the sites they are selling for do business in Cyprus.

Sadly, several of the posts make it clear that some of these poor suckers think they are "following the rules" and doing pill-spam for prescription drugs in a "legal" way! DOH!

(One Hundred Seventy Two users had logged in to this forum in the previous 30 minutes when I was reading it!)

------


http://www.drugbuyers.com/freeboard/ubbthreads.php/ubb/showflat/Number/536852

(182 registered users in the past 30 minutes!!!)

This thread is also mostly about posters wondering if what they are doing is really illegal or not! Amazing!

------

Shroomery.com laughs at them all and points out that Magic Mushrooms don't use prescriptions. (a photo of a cow says "This is my pharmacist!")

------

Online Justice: Slow and Incomplete

Last week the online media went nuts over the sentencing of Christopher William Smith, known to anti-spam researchers as "Rizler". I'd like to stand at the front of the line in congratulating Assistant US Attorney Nicole Engisch and US District Judge Michael Davis for sticking it to Rizler with a THIRTY YEAR SENTENCE!

Rizler has been spamming an enormous volume for a long time. The 211-page complaint against Rizler by AOL documented over 1.1 BILLION emails that Rizler had sent -- just to AOL subscribers!

Rizler was arrested in a raid on May 10th, 2005, in which his 85-employee company, Xpress Pharmacy Direct, was shut down and in which $4.2 Million in assets, including $1.8 Million in luxury automobiles was seized. Skipping bail to the Dominican Republic, it was only a matter of weeks before Rizler had restarted his spamming operations. His websites, such as rxorderfill.com, xpress-rx.com, digihealthcorp.com, mypillrefills.com, and netmeds.com, claimed to operate legally by having a real doctor read answers to your online profile questions, and prescribe your medications from his office in New Jersey. Rizler paid Dr. Philip Mach $7 per prescription for these services. . .more than 20,000 times in one four month period!

Spamhaus's Steve Linford told Silicon.com's Will Sturgeon back at that time, "Rizler was way up in our Top Ten". (Silicon.com The Spam Report, 06JUL05)

Good story, right?

Well . . . how is that Rizler is charged with operating a "continuing criminal enterprise" and "conspiracy", but there don't seem to be any co-conspirators?

Bernadette Hollis, who was in charge of acquiring the Hydrocodone for the online pharmacies, and who Smith confided in with his desire to kill one of the prosecutions chief witnesses, walks away with one year of probation and forty hours of community service.

Alton Scott Poe, was described as being an innocent office manager, who was brought in to instill good business practices. Apparently the judge bought this story, or perhaps nobody ever heard of the Online University that Poe ran? The Lawsuit against Alton Scott Poe and his brother lays out their online scheme for selling diplomas for between $300 and $500, complete with an imaginary transcript showing what grades you received in what classes! Innocent Office Manager? He'll do 6 months for assisting in the sale of millions of dollars of illegal drugs. I wonder what scheme he'll launch in six months and one day?

Wednesday, July 25, 2007

GAO: CYBERCRIME Challenges

On July 20, 2007 I began my first day of work at The University of Alabama at Birmingham as the Director of Research in Computer Forensics. The position came about as a result of one fundamental issue that we have been working on together between the chair of Computer & Information Sciences and the chair of Justice Sciences: How can we better equip CyberCrime Investigators to do their job? The first part of our answer was to encourage more Academic partnership, where students would seek a "Certificate in Computer Forensics" by studying courses from both departments. We called this initiative "Training Digital Detectives for the 21st Century". The second portion was to begin hosting more training on CyberCrime Issues, such as The Birmingham Conference on Phishing on March 13-15, 2007, and the Identity Theft Summit held June 10-11, 2007. The third part was to create my position, and to begin focusing our joint research efforts on topics that would provide better techniques, tools, and training for CyberCrime Investigators.



With that background, you can imagine how reinforcing it was to see Federal Computer Week's article on July 23, 2007 -- FBI, Secret Service must improve CyberCrime Training. The article begins:

The FBI, the Homeland Security Department and other federal agencies are underequipped and lack enough properly trained employees to combat cybercrime, according to a recent report by the Government Accountability Office.

GAO found that staffing was one of four major challenges to addressing cybercrime.


The publication being referred to was GAO-07-705: CYBERCRIME: Public and Private Entities Face Challenges in Addressing Cyber Threats. This document, from David Pownder's group at the Government Accountability Office, says "The annual loss due to computer crime was estimated to be $67.2 Billion for US organizations" with the majority of that, $49.3 billion, being related to Identity Theft, and $1 billion associated specifically with phishing. That same opening letter pointed out that in addition, we know "Chinese military strategists write openly about exploiting the vulnerabilities" used by our military computing infrastructure, and that "terrorist organizations have used cybercrime to raise money to fund their activities". In 2006, it is estimated that there were 9.9 Million US consumers who suffered from Identity Theft.

Its our economy that is at risk. In the reports background it lists that "150 million US citizens" use the Internet, and that in 2006, "total nontravel-related spending on the Internet was estimated to be $102 Billion". And spam, according to a Ferris Research report cited by GAO, has a "global cost of $100 billion worldwide, including $35 billion in the United States".

As president of the Birmingham InfraGard, and a recipient of the 2006 "Partnership Award" from the IC3 and NCFTA, I was pleased to see the report listing "Key Partnerships Established to Address CyberCrime":


  • Internet Crime Complaint Center (ic3.gov)
  • InfraGard
  • The National Cyber Security Alliance
  • National Cyber Forensics and Training Alliance (ncfta.net)
  • Electronic Crimes Task Forces


The key challenges listed in the report are:


  • Reporting CyberCrime
  • Ensuring adequate law enforcement analytical and technical capabilities
  • Working in a borderless environment with laws of multiple jurisdictions
  • Implementing information security practices and raising awareness


Reporting CyberCrime


When surveys say 9.9 Million Americans lost $49 Billion to Identity Theft last year, its astounding that the Internet Crime & Complaint Center only had $180 Million in loss reports filed from 260,000 consumers. Some of the reasons GAO gave for this under-reporting were:


  • Financial Market Impacts - (will my stock tank if I tell you I was hacked?)
  • Reputation or confidence effects - (will my customers flee if I tell the truth about my brand's phishing losses?)
  • Litigation concerns - (will my customers sue me?)
  • Signal to attackers - (will other hackers pounce on me?)
  • Inability to share information - (is my data sequestered by the legal process?)
  • Job security - (will my IT staff be fired?)
  • Lack of law enforcement action - (will the cops do anything? do they know what to do?)


LE Analytical and Technical Capabilities



From the report:


Federal and state law enforcement organizations face challenges in having the appropriate number of skilled investigators, forensic examiners, and prosecutors.

...

officials, once an investigator or examiner specializes in cybercrime, it can take up to 12 months for those individuals to become proficient enough to fully manage their own investigations.


Some of the key challenges mentioned include the great possibility that a trained cybercrime investigator will be lured to the private sector by the much higher salaries their skills may demand in that arena. Within the FBI, the policy of rotating new agents to one of the 15 largest offices within 3 years often means that an agent recruited for their cyber abilities is assigned to a non-cyber position in their new office! (This happened to one of our favorite cyber agents in Birmingham, who is now in a non-cyber post in Miami!) These same rotations also mean that agents brought in to fill these new cyber-vacancies may have little or no cyber training. Even senior agents (supervisory agents) are limited to serving a 5 year term in their role if they wish to seek career advancement.

Keeping Up to Date with Technology and Techniques



The report also expresses the concern that cybercrime is evolving at a rate which requires new equipment and tools "and agencies' need for them does not always fall into the typical federal replacement cycle". Some of the training gaps are being met creatively within agencies by having centralized talent pools, such as the DOD Cyber Crime Center (DC3.mil), FBI Cyber Action Teams, and the Secret Service training programs for federal, state, and local officials (such as the new Center just opened in Hoover, Alabama!) These are all great, but often the resources are still too limited for the scope. These are supplemented by "public/private partnerships, like the FBI’s Infragard and National Cyber Forensics Training Alliance and the Secret Service’s Electronic Crimes Task Forces, [which] provide ways to share expertise between law enforcement, the private sector, and academia."

Borderless Crime



Key challenge in this area are:


  • techniques that "make it difficult to trace the cybercriminals to their physical location".
  • "the multiplicity of laws and procedures that govern in the various nations and states" - such as the fact that not all states or nations have antispam or antispyware laws.
  • "Developing countries, for example, may lack cybercrime laws and enforcement procedures."

  • The "need to rely upon officials of other jurisdictions to further investigate the crime."
  • "Conflicting priorities also complicate cybercrime investigations and prosecutions."
  • "Cybercrime can occur without physical proximity to the victim, and thus a cybercriminal can operate without victimizing a citizen in the jurisdiction or federal judicial district in which the crime originated." - It is difficult to commit local resources to investigate crimes that have no local victims!


Raising Awareness


"Criminals prey on people's ignorance". Ignorance of vulnerabilities. Of how to detect phishing. Of how to report CyberCrime.



In response to this report, the FBI mentioned that Director Mueller has established five "career paths" for agents, one of which will be a Cyber track. This will allow cyber agents to remain where there skills can be made most effective.

The Secret Service also responded, stating that their Electronic Crimes Special Agent Program (ECSAP) will have 770 trained and active agents by the end of FY 2007. Their response also mentioned their 24 Electronic Crimes Task Forces, which "combine the resources of state and local police, as well as academia and private industry", and their importance in maintaining a continuity of investigative ability even as new ECSAP agents face their 4th year rotations.

The Birmingham Electronic Crimes Task Force meets Quarterly according to their website. More information about the next meeting from 731-1144 or "bhmecwg@einformation.usss.gov".

Monday, July 23, 2007

CyberSecurity Enhancement Act of 2007

Its time to rally the troops on the political front once again. Those of you who know me know that I believe we have primarily not a lack of laws but a lack of manpower and interest in enforcing those laws. Is it against the law to send spam with false headers in the United States? Yes. It is actively investigated and prosecuted? No. Is it against the law to steal someone's identity in the United States? Yes. Is it actively investigated and prosecuted? No. Unless you can show enormous losses.

So, on the one hand, I would like to see adequate resources applied to enforcing the laws that we currently have on the books. On the other hand, when I see a great Bill is introduced in the House or the Senate, I'd like to see it supported.

The CyberSecurity Enhancement Act of 2007 is worth supporting. It goes beyond our current CyberCrime Laws and attempts to bring in the aspects of Organized Crime and Conspiracy that are behind the individual acts we see everyday.

Someone registered a new domain in Hong Kong and used a bot-infected computer to host a phishing website. Hardly interesting from a prosecutorial perspective. But if there were laws on the books that let investigators more easily go after the Criminal Conspiracy that encouraged this action to be committed hundreds of times this year by a related group of co-conspirators, that would make these smaller acts more likely to be prosecuted. Assistant US Attorney Erez Liebermann, the chief of the New Jersey CHIPS unit (Computer Hacking and Intellectual Property Section), was recently interviewed by Information Week where he mentioned this Bill. In the July 20th article, he says that by adding CyberCrime to the RICO statutes, as this Act would do, criminal penalties for these activities would be enhanced.

Are you familiar with the "CyberSecurity Enhancement Act of 2007"? Most of us aren't.

You can read the Full Text of the Bill here.

HR 2290 was introduced May 14th by Adam Schiff, a Democrat from California. (GovTrack categorizes him a "Radical Democrat". I like Radical Democrats love for technology and for their desire to help the poor. I can work with anyone. Schiff co-sponsored National Human Trafficking Awareness Day, and a bill to make trade in illegal nuclear weapons a Crime Against Humanity. Of course he also introduced a Bill to express No Confidence in our Attorney General, so bi-partisan, this guy ain't.)

This bill is currently sitting with the House Committee on the Judiciary, along with 43 other proposed amendments to Title 18 (where most of our CyberCrime Laws are outlined).

One of those other versions is a Republican sponsored Bill with almost the same name, introduced by Republican Lamar Smith, HR 836, introduced back in February.

A key phrase which was present in both the Republican and the Democratic version of the Bill would modify the penalties so that they applied both to the successful criminal, and the criminal who "conspires to" or "attempts" to commit certain CyberCrimes.

Another huge part of the act addresses the concern I mention at the top of this post. Section 10 of this act would give an additional $10 Million EACH to the Secret Service, the FBI, and the Attorney General for the Criminal Division of the DOJ, specifically for fighting CyberCrime. If for no other reason than this, I would strongly encourage your support of this bill!

I'm pleased to see that one of my two Congressman, Artur Davis, is listed among the co-sponsors of HR 2290. (I claim the one in the zip code where I work, and the one in the zip code where I live both represent me. I had the pleasure of escorting my son's orchestra on a Capitol Tour as guests of Mr. Davis' office last month!) I'm also pleased to see that Ohio Republican Steven Chabot and California Republican Daniel Lungren, 2 of the 9 Republican co-sponsors of Smith's earlier bill, and both members of the sub-committee on Crime, Terrorism, and Homeland Security, have joined as part of the 6 Republicans who make a total of 19 co-sponsors of HR 2290.

The fact that the members of this committee, both Democrats and Republicans, are signed on as co-sponsors to this Bill encourages me that it might make it out of committee!

I would encourage folks to read the Bill, and if you agree that it should be law, please encourage your Representative to lend his voice of support to the Bill.

The Bill is currently sitting in a sub-committee of the House Judiciary Committee, called the "Crime, Terrorism, and Homeland Security Committee". Especially if you are in Michigan, where the Honorable John Conyers, the Chairman of the Judiciary, is from, or in Virginia, where the Honorable Robert C. Scott, the Chairman of the sub-committee, is from, it would be very useful to hear your voice in this matter.

Please take a minute to review the Bill, members of the Subcommittee, and your own Congressmen's contact information, and determine what the right course of action is for yourself.

Thanks for your help!

_-_
gar

Wednesday, July 18, 2007

Buone Notizie! (Good News for Italian Bank Customers)



In a press release issued July 13 (or 13 luglio 2007, if you're in Roma), the Commanding General of the Financial Guard of Milan announced that they had arrested 26 phishers. 18 Italian citizens, and 8 foreigners.

Here's my Babylon 6 assisted translation of the press release:

----------

The Provincial headquarters of the Guardia di Finanza in Milan has, in fact, executed 26 orders of custody to members of two criminal associations responsible for a series of fraud perpetrated on hundreds of users of home banking services, by technical means better known under the name of "phishing".

The operation has identified 18 Italian citizens and 8 Eastern European foreigners, who are regular residents in our country, which are exploiting the home banking personal access credentials to customers of Poste Italiane bank, sent fraudulently in response to randomly dispatched e-mails apparently sent by their financial institution.

Hackers from the group, during questioning, have confessed to having sent the e-mail messages, which appeared to originate from Poste Italiane, by using stolen login credentials for electronic mailboxes of ISPs operating in Italy but with servers abroad. They subsequently logged in to the accounts during the next 30 days and defrauded them out, by transferring the sums on cards specially created by other members of the Organization.

The means of offense were identified thanks to a tight cooperative investigation between the "fraud management" team of Poste Italiane and the officers of the Guardia di Finanza, which have monitored in real time the activations of the cards, initially in the territory of Milan and then on the whole national territory.

The orders of custody have been carried out in the provinces of Milan, Brescia, Novara, Como, Florence, Parma, Forlì and Pescara.

In the course of the searches they seized computers, removable media archives, magnetic cards used to set up credit cards and debit cards, hundreds of credit cards and prepaid cards of various banking institutions, CARDS one, false documents and mobile phones last generation.

------------------

This type of investigation is possible every day in the United States. What is necessary to make it a reality? The belief by the management in charge of the manpower of various investigative and prosecutorial agencies that "small crimes" are worth investigating -- because they lead to Big Criminals!

Well Done, Italy! May you serve as a model for us all!

_-_
gar


(original press release, in Italian, is available here:

Italian Press Release

Tuesday, July 17, 2007

UAB Student Newspaper Interview

Kaleidoscope, the UAB Student Newspaper, interviewed me on Identity Theft for their July 10, 2007 issue.

Adrian Thurstin did a very nice job with the interview, and wrote a great story focusing on issues of particular interest to students.

_-_
gar

New Job!

Just wanted to let my loyal readers (yes, both of you!) know that I have taken a new position.

I am now the Director of Research in Computer Forensics at the University of Alabama at Birmingham. This newly created position is a partnership between the Computer & Information Sciences Department chaired by Dr. Anthony Skjellumand the Department of Justice Sciences chaired by Dr. John Sloan.

Our partnership was the cover article in a recent edition of UAB's magazine. The article, called Bugs in the System, discussed how CIS and JS were working together to create Alabama's first graduate certificate in Computer Forensics. The problem that we are facing is that CyberCrime professionals are either Justice Science majors, with a background in law enforcement but very little computer training, or Computer Science professionals, with a background in technology, but very little knowledge of law enforcement and legal practice. The new certification will be producing graduates who have a combination of knowledge in these areas BEFORE they enter the workforce.

My position, as Director of Research, will be seeking to develop new techniques, tools, and technologies for those who practice CyberCrime investigation, in the legal system, in traditional security companies, and in corporate and government security.

Wednesday, January 24, 2007

(Blog alert: Taking Vista By "Storm")

Just a note to say I have updated the Birmingham-InfraGard blog with a couple entries that might be of interest to readers here.

Tuesday, January 23, 2007

Italian Court declares itself Friend of Pirates (or does it?)

I couldn't believe this one.

The Associated Press reported yesterday that Italian high court says file-swapping is not illegal.

In this case, two college students from Turin Politechnic Institute were accused of piracy in 1994, after using the school's network to build a peer-to-peer file sharing network for their classmates.

On January 7, 2007, the Cassation (Italy's equivalent of the Supreme Court) declared that downloading music, videos, and programs from the Internet, even when they are clearly covered by copyright, was not illegal as long as the goal was not distribution for monetary gain.

George Assuma, the President of Italy's watchdog group on copyright law, SIAE (the Italian Society of Authors and Editors), points out that in fairness these students could only be judged by the laws as they stood at the time of their crime. (See his reaction at: Il Presidente Assumma su sentenza Cassazione: Reato downloading non autorizzato di opere.) Since that time, Assuma points out, there are at least four laws which have been added to the court's arsenal which may address these issues more appropriately, not the least of which is the European Union Directive on Copyright, which came into force in October of 2003. But do they help?

A look at the
EU Directive on Copyright shows that Article 5.2(b) says:

in respect of reproductions on any medium made by a natural person for private use and for ends that are neither directly nor indirectly commercial, on condition that the rightholders receive fair compensation which takes account of the application or non-application of technological measures referred to in Article 6 to the work or subject-matter concerned;


So it would seem that this may be a case where the initial panic will subside when people actually understand the true context of the case. The European Directive on Copyright, which would certainly apply in Italy, clearly says that EVEN FOR PRIVATE USE the "rightholder" must "receive fair compensation".



Let's hope the Italians get this cleared up in a way that the Associated Press can understand.

_-_
gar

Wednesday, January 17, 2007

First CAN-SPAM Jury Conviction?

Although its not the first conviction under the CAN-SPAM Act of 2003, the AOL phisher conviction this week is still newsworthy. At test? Can a Jury actually understand a spam case.

One of the arguments we've seen repeatedly as we try to get prosecutors to push forward with spamming cases is that they are "too technical" or "too boring" for jury appeal. The convictions so far have been largely based on the fact that, when faced with overwhelming evidence, spammers cop a plea.

So what was this case about?

Jeffrey Brett Goodin, a 45 year old resident of Azusa, California, hacked into a large number of EarthLink accounts (poor passwords and dictionary attacks, I believe), and used those accounts to send emails to AOL users. The AOL customers would receive a spam telling them that their AOL billing information needed to be updated, or that they would lose their service.

Following the link in the email would lead to an AOL phishing site - a fake website that looked very official - which would ask personal questions including their billing information.

Although the headline says "AOL Phisher Faces up to 101 Years in Prison", this blogger bets that on the June 11th sentencing we'll be lucky to see 7 years.

One note on "swift action" . . . Goodin was arrested on January 26, 2006 - so just 10 days short of one year later for a trial.

Goodin, who went by the creative hacker alias "The Hacker", had been a fugitive from the law for four months prior to his ultimate capture. On July 24, 2006, Goodin's photograph was posted on the FBI's "wanted" website as a fugitive. The original arrest press release, which credited the Los Angeles Electronic Crimes Task Force, and the Ontario Police Department with supporting the arrest, said Goodin faced up to 30 years in prison.

The additional charges occurred as a result of crimes committed during his four months of "fugitive" status after failing to appear for his bond hearing, according to this later Press Release from the LA FBI office. The additional charges includes Failure to Appear, and Witness Harassment.

Congratulations all around and all that, but ONE jury conviction in three years? With spam comprising 90% of all the email on the planet? Let's get that fixed!

_-_
gar

Saturday, January 06, 2007

Evidence Handling

Just a link to another article where I blog on Birmingham InfraGard:

Best Practices in Electronic Evidence

_-_
gar

Friday, December 22, 2006

FAL$E HOPE$ @ CHRI$TMA$

FAL$E HOPE$ was a Federal Trade Commission operation announced on December 12, 2006, which cracked down on Bogus Business Opportunities. Coordinated with the Department of Justice, the US Postal Inspection Service, and law enforcement agencies in 11 states, the report contains more than 100 law enforcement actions! (In the interest of full disclosure, these publicity operations solicit previously investigated cases from parties who wish to be included in the press release. Although the Operation was announced publicly in December of 2006, many of the activities had concluded as early as February of 2005.)

DOJ Actions were primarily in Nevada and the South District of Florida, but had some great cases themselves! In just one such case, AmeriP.O.S., individuals were told they were buying the right to mark kiosks for prepaid debit cards, phone cards, and internet access. Eleven defendants were charged and received hard time from between 24 and 135 months! Restitution was also ordered in the amount of $16,659,826.94! Altogether this group will spend 729 months in prison.

The original DOJ Press Release shows this to have been part of "Project Biz Opp Flop". In Biz Opp Flop DOJ documented 4,000 consumers nationwide who lost more than $60 million in these fraudulent business opportunities. AmeriP.O.S. promised that for their $12,000 investment, purchasers would received several Point of Sale terminals and support in establishing their own territory for the business. 1,500 people fell for the scam. Other companies, "Cash Link", "Tel 2 Net", "Pantheon Holdings" and "Global Resources" were offering the same offer. Global Resources advertised on television, the Internet, and by high pressure telephone calls, promising earnings of $6,480 per month (with a $14,000 minimum investment = two month break even!) 150 investors sent Global Resources $2.5 million! Pantheon got $19 Million from 1,500 consumers! Perfumes Unlimited, another case included in Biz Opp Flop, claimed consumers could earn $150,000 per year selling perfume in racks placed in stores. 150 consumers gave them $1.5 Million to invest. Accomplices were recruited to lie about their own experiences with the business as references to the success of the product.


The US Postal Inspection Service provided their Work at Home/Distributorshipos Case Briefs to the FTC which included many work at home schemes such as "Wealth By Mail, Inc", "GTEC", "Armand & Company", and many others, including one in my home town of Birmingham, Alabama.

In that case, "Employment Solutions" advertised a work at home envelope stuffing business, for which he would send a "start-up" kit for $32. Many folks received the start up kits, but they didn't receive the profits he described!

Perhaps the most successful case among the USPIS actions was "National Brochures / AAA Information Center". In this case, Malcolm Lincoln received 10 years in prison, and his wife three years, and were each ordered to pay $28,282 in restitution to 200 victims. Victims spent between $35.95 and $745.95 to receive their work-at-home business kits, and were promised they would earn between $4 and $21.82 per envelope stuffed. No one ever received a payment. In total over 1,000 people were victimized and the defendants earned more than $400,000!

Some of the claims were ridiculous! "EDI Health Claims Network" said that the customers medical billing business would earn as much as $1,200 per month with just one client! After consumers paid their $5,985, they were told their first client could be found by looking in their local yellow pages!

Many of the business opportunities in the FTC report promise returns of more than $1500 per week, and some as high as $150,000 in their first year!

One company, USA BEVERAGES, INC, (see the separate press release: FTC Halts Bogus Business Opportunity Scam) used Voice Over IP and prepaid cell phones to make it seem that they were calling from the local area, when in reality, they were making their pitches for coffee display racks from Costa Rica. Their website claimed it was a 12 year old company in New Mexico. With this 12 year history, the promise that franchisees would make "no less than $1,055.60 per week" if they operated 13 display racks must have seemed legitimate! Investors gave up between $18,000 and $85,000 each to learn that it was not true.

Thursday, December 21, 2006

Pump & Dump: SEC gives us a peek!

We all know that the most annoying spammers on the planet today are the ones who are sending out the image based Stock spam that seems to be most gifted at by-passing every form of spam filter. I frequently get the question: "How do these guys make money?"

This week, the Securities and Exchange Commission website has two interesting cases that give us some details. They illustrate two different methods of pump & dump. Account Theft, and False Profile spamming.

Let's look first at the password thief.

SEC Emergency Action Against Foreign Traders - SEC v. Grand Logistic

The subject of this action, Grand Logistic, is a company owned by Evgeny Gashichev who resides in St. Petersburg, Russia. His company operates in Estonia and is licensed as a corporation in Belize. The company exists to speculate in the penny stock market. The way it works is that Evgeny placed $30,000 in an online brokerage account, and began buying penny stocks. Curiously, these stocks, which had seen almost no activity, began to be bought and sold like mad after Evgeny would purchase them.

The charges from the SEC indicate that Evgeny would buy penny stocks from HIS account, and then would log in using stolen credentials to many other accounts, including E*Trade, ScottTrade, and TD Ameritrade accounts and make large purchases from other people's brokerage accounts - without their knowledge or permission - in volumes ranging from 6,000 to 71,000 shares! Then, when the price had risen sufficiently, Evgeny would liquidate the holdings in that account from his own profile.

So how did he do? Evgeny's initial investment grew from $30,000 to $383,000 in just seven weeks!

For more details see: The SEC's Complaint.



Now let's turn our attention to the Stock Spammer case "Red Hot Stocks". This is a case where we get to see the "end of the story", however, as usual, the question remains outstanding whether or not justice has been served. Still, the SEC is to be applauded for their action.

In the current SEC Final Judgement against Red Hot Stocks defendant Dieter Raabe, Raabe was ordered to pay $489,900 in disgorgement, plus prejudgment interest of $215,110 and post judgment interest of $16,300, and a civil penalty of $110,000, for a total of $831,310.

Wow! $831,310 sounds like a great deal of money! But wait, didn't we establish that in 2002 he had already earned $4 million from his fraudulent trading schemes!?!?


This case goes all the way back to an SEC Complaint in 2002 against Red Hot Stocks, where the SEC filing indicates that the defendant had earned more than $4 million through manipulation of the stock market.

In this situation, subscribers of the "Red Hot Stocks" website received a newsletter which contained a false or misleading statement about the dealings of a penny stock company. One of the biggest problems though, from SEC rulings, is that the profiles were made without disclosing that the author and promoter was personally planning to liquidate a large holding once his objectives had been met. There are rules dictating when an "insider" may sell their stock holdings after public statements are made. Raabe was previously accused with James E. Franklin. Franklin operated the companies "Vector Keel Ltd." and "Initial Public Offering Consultants, Inc." who would buy (or receive for services rendered) the stock. Then "Red Hot Stocks" would create online profiles for the companies, and spam the hell out of the profiles waiting for payday.

The actual Red Hot Stocks website is still available thanks to the Archive.org WayBack Machine. Here's a link:

Red Hot Stocks (WayBack Machine link to 1998)

Some of the stocks profiled there include:

AXPL, NTSA, NEOT, LCAV, EZCL, CMYN, GRB.V

So, this case brings to a close Pump & Dump activity which occurred through this "free stock tips" newsletter offered more than 8 years ago!






Many examples of similar scams can be found in the archives of Harvard University's CyberLaw archive on Stock Spam. Here is a great resource listing stock symbols touted by spam, produced by Laura Frieder and Jonathan Zittrain:

Stock Touts (From Harvard CyberLaw)

Their excellent paper, just released 16DEC06, is available here:

Spam Works: Evidence from Stock Touts and Corresponding Market Activity

Thursday, October 12, 2006

Counterfeit Checks? Who cares!

Today I had a pretty typical law enforcement interaction.

Before I get into that, I want to say that I have great admiration and respect for many of the law enforcement folks I meet every day. The down side of this interaction is not a reflection on any individual in law enforcement, but rather of the troubles at the next level - the US Attorney's Office, where they decide whether a federal case will be worked or not.

SCENARIO
============
In this circumstance, a family member had advertised some services on the Internet. Predictably, a number of non-English speaking persons jumped on the service and wanted to buy it. The first wants to know if he can send a Cashier's Check for $4,000 rather than the actual price of $2,100, and would she be willing to deposit it in her account and wire the additional funds to his Travel Agent. The second actually sent a check for $3600 (I have the check), and then Tragedy Struck, and the poor gentleman is hospitalized in Canada and his only hope is if my family member could send $500 of that $3600 to a Canadian address TODAY!

(The other guy wanted the money sent to a Travel Agency in London, who was paying for his son's trip to the United States).

CRIME
=================
So, we have a counterfeit check. The check itself is printed on check stock you can buy in an office supply store, and drawn from an American based Credit Union. Only they've mis-spelled common English words, even on the face of the check, and have given an invalid toll free number for the credit union.

I contact the credit union's "risk management" office, describe my scenario, and ask if its common. She says she gets "two or three calls a day" very similar to mine, each ending with a counterfeit check drawn from their credit union. Sometimes they have deposited the check and sent money to the con man. Sometimes they haven't.


REJECTION
=================
I ask her who her chosen law enforcement partner in this situation is. She says that she has called the Secret Service, who seemed interested at first, but lost interest when they realized the checks were being mailed from Canada. I call her local FBI CyberCrime Supervisor and describe the scenario to him. He says that unfortunately "bank fraud is not the priority that it once was" in the Bureau. He'd love to work the case, but "if there is not at least $500,000 in loss, the local Assistant US Attorney won't prosecute."

So, what should you do if you or a family member or friend receives a counterfeit check?

The best plan, according to all parties, is to fill out the report that you can find at the Internet Crime and Complaint Center website -- http://www.ic3.gov/ -- By entering as much data as possible into that database, your case can be combined with other cases to try to generate those minimums that will make a US Attorney want to prosecute. Note: The $500,000 is a higher threshold than I have heard in most jurisdictions. Some have stated they will take action for as little as $75,000 in proven losses.

I believe this will get better, but part of what will make it better is people like you and me making sure that we gather as much evidence as we can, and put it in front of the people who have to make these decisions. Maybe we waste our time today, but its the necessary leg work to getting this situation turned around.

Good luck!

_-_
gar

Counterfeit Checks? Who cares!

Today I had a pretty typical law enforcement interaction.

Before I get into that, I want to say that I have great admiration and respect for many of the law enforcement folks I meet every day. The down side of this interaction is not a reflection on any individual in law enforcement, but rather of the troubles at the next level - the US Attorney's Office, where they decide whether a federal case will be worked or not.

SCENARIO
============
In this circumstance, a family member had advertised some services on the Internet. Predictably, a number of non-English speaking persons jumped on the service and wanted to buy it. The first wants to know if he can send a Cashier's Check for $4,000 rather than the actual price of $2,100, and would she be willing to deposit it in her account and wire the additional funds to his Travel Agent. The second actually sent a check for $3600 (I have the check), and then Tragedy Struck, and the poor gentleman is hospitalized in Canada and his only hope is if my family member could send $500 of that $3600 to a Canadian address TODAY!

(The other guy wanted the money sent to a Travel Agency in London, who was paying for his son's trip to the United States).

CRIME
=================
So, we have a counterfeit check. The check itself is printed on check stock you can buy in an office supply store, and drawn from an American based Credit Union. Only they've mis-spelled common English words, even on the face of the check, and have given an invalid toll free number for the credit union.

I contact the credit union's "risk management" office, describe my scenario, and ask if its common. She says she gets "two or three calls a day" very similar to mine, each ending with a counterfeit check drawn from their credit union. Sometimes they have deposited the check and sent money to the con man. Sometimes they haven't.


REJECTION
=================
I ask her who her chosen law enforcement partner in this situation is. She says that she has called the Secret Service, who seemed interested at first, but lost interest when they realized the checks were being mailed from Canada. I call her local FBI CyberCrime Supervisor and describe the scenario to him. He says that unfortunately "bank fraud is not the priority that it once was" in the Bureau. He'd love to work the case, but "if there is not at least $500,000 in loss, the local Assistant US Attorney won't prosecute."

So, what should you do if you or a family member or friend receives a counterfeit check?

The best plan, according to all parties, is to fill out the report that you can find at the Internet Crime and Complaint Center website -- http://www.ic3.gov/ -- By entering as much data as possible into that database, your case can be combined with other cases to try to generate those minimums that will make a US Attorney want to prosecute. Note: The $500,000 is a higher threshold than I have heard in most jurisdictions. Some have stated they will take action for as little as $75,000 in proven losses.

I believe this will get better, but part of what will make it better is people like you and I making sure that we gather as much evidence as we can, and put it in front of the people who have to make these decisions. Maybe we waste our time today, but its the necessary leg work to getting this situation turned around.

Good luck!

_-_
gar