Thursday, June 11, 2015

A Nigerian in Spain arrested for phishing and online shopping with stolen credentials


From Spanish news source "ElComercio" we bring you this phishing story - about a Nigerian citizen arrested in Spain.  Click the Spanish headline for the original story.   A Google-translate-assisted version of the story is shared below for the convenience of our English-speaking readers with permission from Olaya!)

Detenido un nigeriano por realizar compras 'on line' con datos robados a cien víctimas

(A Nigerian Arrested locally for online shopping with a hundred victims' stolen data)
Olaya Suarez, Gijon @OlayaSuarez0

 A 44 year-old Nigerian citizen was arrested locally for defrauding hundreds of people by using their bank details to make purchases online and then resell these products on the black market. The National Police estimates that he gained more than 50,000 euros in this way.
 
The investigation began in September 2014 after receiving the first reports of victims whose banking data had been used illegally for various internet shopping portals. Police work was arduous and complex, but eventually determine that all the fraud in Spain was the work of a single author, but that he used different identities and operated using WIFI connections in private homes, cafes and public  spaces, thus trying to hinder their location.

After months of investigations, officers of the Economic Crime group of the Brigade of Judicial Police Station Gijon found that the suspect had fixed his residence in Gijon, "where he received shipments getting their illicit activity," sources said the police station.

A job as a lure

"The person under investigation belonged to a criminal organization operating transnational nature of the internet and dedicated to credit card fraud and debit cards. The network operated by credentials and numbers for bank cards using different methods, from cloning, 'phishing' or 'hacking' of online data, "says the police.
 
After obtaining this data, the fraud is facilitated through servers and private links to other members of the organization in exchange for financial compensation. The Nigerian resident in Gijon, allegedly, took this information and using it, effected purchases of technological devices such as televisions, tablets, laptops or mobile phones.
 
Each week they conducted three or four purchases of items using many identities and facilitating different directions for collection, "but always expecting the dealers on the street to avoid the reliable verification of your address." "Under the pretext of facilitating the work identified in the street before the workers of delivery companies and so getting the immediate delivery of the item, the cost would be charged to the person who had fraudulently obtained card information» , reports the National Police.
 
All of the material obtained in this way coming back into the virtual market since it was offering immediately in Internet-based ad pages to people unaware of its illicit origin and not belonging to this criminal network. Despite all the precautions taken by the investigation to hide his true location, the officers managed to identify and establish a means for his arrest. His precise location was noted when he was picking up one of his orders and he was taken to the police station.

49 Corporate Email Phishers arrested in Operation Triangle

The Europen Union's Judicial Cooperation Unit, EUROJUST, along with Europol's European Cybercrime Center (EC3) and the Joint Cybercrime Action Taskforce (J-CAT) have announced one of their most successful cyber actions to date.   The case, known internally as Operation Triangle, involves three lead agencies - Italy's Postal and Telecommunications Police through its office in Perugia, Spain's Investigative Court no. 24 in Barcelona, and Poland.  (EUROJUST Press Release: "Eurojust and Europol in massive joint action against cybercriminals")

(Click for article:J-CAT operations)
58 search warrants were executed in Spain, Poland, Italy, Belgium, Georgia, and the United Kingdom, resulting in 20 arrests in Italy, 18 arrests in Poland, 10 arrests in Spain, and 1 arrest in Belgium.  Most of those arrested were from Nigeria and Cameroon. 

By gaining control of the email accounts of well-placed individuals in corporations across Europe, the criminals were able to alter requests for payment to send the payments to themselves rather than the business bank accounts that were the intended destinations.  In a short period of time, more than 6 million euros were transferred to accounts controlled by the criminals.

In the United Kingdom, where the J-CAT task force is headquartered, recent government reports indicated that 81% of large businesses (>250 employees) and 60% of small businesses (less than 50 employees) experienced an information security breach in 2013.
(Report available here)

Next week, many European governments will be represented in the Octopus Conference 2015: Cooperation Against Cybercrime. Through the work of Octopus and others, European agencies are gradually coming into agreement on how to address multi-jurisdictional cybercrime.  At last year's Octopus conference, delegates were encouraged to work together through 18 Cybercrime Scenarios.  Fascinating puzzles that we NEED agreement on if we are truly going to stand a chance against the multi-national criminals who steal from our citizens.


UPDATE!  La Stampa article -- 

(Click for LaStampa article, which includes a short video of Italy's Polizia di Stato Cybercrime group)

 

For the convenience of my mostly English-speaking readers, I offer an English translation via Google Translate below.  This article is available to the Italian reader by clicking the story headline in Italian:

Phishing contro aziende: 62 arresti in Italia e all’estero, smantellata rete internazionale

Phishing Against Companies:  62 arrested in Italy and Abroad, International network dismantled: 
An operation that goes from Perugia to Turin and expands throughout Europe.  Here's how the scammers did it.

Via "LaStampa" journalist Carola Frediani and Google Translate -- 

It all started with a payment of 33 thousand euro. A routine, a transfer made ​​by a company of the Venetian food, which through its Spanish subsidiary had paid a supplier. Or rather, what he thought to be a provider, not suspecting that behind the request for a change of code Iban which paid the money was concealed an organization dedicated to computer fraud to the detriment of businesses and recycling. He had before hacked supplier and now he was impersonating online through email.
So that money, rather than to the real suppliers of the Veneto, end up on a postal account in Perugia made ​​out to a citizen of Cameroon. Which in turn has contacts with a criminal group based in Turin, specializes in money laundering and run by Nigerians, as revealed recently in an investigation of Europol and the Guardia di Finanza Piedmont.

 Operation Phishing 2.0

This episode started then the footage of another Italian international investigation, codenamed Phishing 2.0, which has once again at the center of the fraud against companies, and this morning has resulted in 62 arrest warrants in various countries, including 29 issued by prosecutors in Perugia.
An investigation then born and coordinated in Perugia, bounced on Turin had already been identified where a hub of illicit proceeds, and extended between Italy, Spain and Poland, with the support of Europol and Eurojust, the judicial cooperation unit of 'European Union.

The victims

Fifty (7 of which are Italian) companies all over the world were victims of digital fraud, 800 scam transfers were identified, 800 thousand euro taken away from businesses and recovered during the investigation, around 5 million euro estimate of the economic damage caused by the group in its business that dates back to 2012. The offenses: unauthorized access to computer systems, impersonation, aggravated fraud, and receiving stolen property.

How did it work

The mechanism of the scam started with a series of computer intrusions in the mailboxes of the companies targeted - characterized by having many foreign relations - through an advanced form of phishing, a technique that consists of sending email fake trying to trick the recipient, and then infect and / or [carpirgli] information. After obtaining the credentials of the emails of employees of a company, cybercriminals were monitoring the exchange of mail identifying commercial relationships, creditors and debtors; then they sent an email to the debtor to turn communicating a change of Iban [online payment destination address?]. Iban that actually corresponded to an account managed by a member of the organization.
 
To manage the assets of phishing was a network of Nigerians, Cameroonians and Senegalese, some of whom were residents in Italy. Once at the bank, also on many giro Italian, the money were taken quickly and redistributed abroad through various systems, including money transfer. "There was a division of roles," he told La Stampa Anna Lisa Lillini, assistant chief of the police post Umbrian added. "Who identified the victims took 50 percent of the amount; who was offering the bill received 30%; and the mediator that the hacker got in touch and took the 20%. " The amount stolen went from 800 up to 250 thousand euro. "In one case we have intercepted one wire of 300 thousand euro from America to  Turin," explains Lillini.

Between Umbria and Piedmont

Turin made ​​from recycling center, and here the investigation Perugia converges with what we previously reported from Turin, [LaStampa's article "Nigerian Drops: Women and Companies Cheated Online"] . In that system, the money stolen from the companies were sent to other parties, with dozens of credit transfers and of people involved, up to a stage where cash was taken piecemeal. A branched system, which were scattered in many streams ([ribattezzatto] precisely Nigerian Drops by investigators) and that has been traced through some specific analysis tools used by Europol. "In one case, one person has taken 150 thousand euro in eight hours making dozens of drops in different branches," says La Stampa Captain David Giangiorgi of the Financial Police of Turin. "The fraud was perpetrated by persons residing in Nigeria. The money was sent in the form of assets purchased with the proceeds of the scam and then shipped to the African country. "

A growing phenomenon

This kind of scams are increasingly common. "Just this week, carrying out a survey of defense on behalf of an Italian company that had lost many thousands of euro through a similar system, we were able to triangulate who had sent the phishing emails, and these seem to come just from Lagos (Nigeria) ", explains Paolo Dal Checco, the Turin studio of computer forensics, Digital Forensics Bureau (Di. Fo. B) that has long followed precisely such cases.
 
The interesting aspect is that the story in question fraudsters had been in touch with the company through Skype, as well as email. And through the program of VoIP (and with some tracking systems of the email), computer forensic experts have identified the IP address of the interlocutors. "By now using increasingly sophisticated techniques," says Dal Checco. "In some cases they go even to call pretending to be a creditor of the company contacted."


UPDATE #2 -- The News from Spain

The Spanish National Police have also released information about this case, in their press release of June 10, 2015.   As with the Italian article above, click the Spanish headline below for the original article.  For the convenience of English-speaking readers, we share a Google-translate-assisted version below:

Operación simultánea en España, Italia, Bélgica y Polonia contra una red de fraude cibernético

 (Images, courtesy of Spanish National Police press office - prensa.policia.es)
Spanish National Police perform on-site mobile forensics during one of their raids



Two suspects detained by Spanish National Police

Simultaneous operation in Spain, Italy, Belgium and Poland against cyber fraud network

National Police
Spain, Italy, Belgium, Poland, 06/10/2015
 
Joint operation of the National Police, NCA and the British Police in Italy and Belgium, coordinated by Europol and Eurojust
 
There are 49 detainees -10 of them in Spain and there have been 28 homes in which 9,000 euros have been seized along with laptops, hard disks, phones, tablets, credit cards and extensive documentation on the activities of the network.
 
Those arrested by means of intrusion techniques and social engineering, were able to control corporate email accounts and to interfere in international financial transactions between different companies and thus were able to modify the target bank accounts and thus appropriating money illegally
 
National Police agents have participated in a simultaneous operation conducted in Spain, Italy, Belgium and Poland against a network of cyber fraud. In this joint operation coordinated by Europol and Eurojust also they participated British NCA agents and police in Italy and Belgium. There are 49 detainees -10 of them in Spain and there have been 28 homes in which 9,000 euros have been seized laptops, hard disks, phones, tablets, credit cards and extensive documentation on the activities of the network. Those arrested by intrusion techniques and social engineering, were made to the control of corporate email accounts to interfere in international financial transactions between different companies. Thus they managed to change the target bank accounts and thus appropriate the money illegally.
 
The international coordination was established effectively through Europol headquarters in The Hague and link to cybercrime agent of the National Police. In this way it has enabled the operation has been developed jointly and simultaneously in all countries where they lived active members of the criminal structure dismantled. It also has received support personnel and Europol mobile office moved to places where it has intervened.
 
Modus operandi
The cyber attack used by this criminal group is called man-in-the-middle, which is to control email accounts, in the case of medium and large European companies. The members of the network were reviewing the messages sent and received from corporate accounts to detect requests for payment. Then modified the messages for payments were transferred to bank accounts controlled by the criminal group.
 
These payments were charged by the criminal organization immediately through different means. The investigation, originating mainly from Nigeria, Cameroon and Spain, then transferred the money out of the European Union through a sophisticated network of money laundering transactions.
 
The investigation culminated with the arrest of 49 people in Spain (10), Italy, Belgium and Poland. In addition there have been 28 homes, 8 in Spain, 2 in the UK and 18 in Italy, where agents have seized 9,000 euros in cash (5000 in Italy and 4000 in Spain), laptops, hard drives, mobile tablets, credit cards and extensive documentation on the activities of the network.
 
The operation was carried out by officers of the Unit for Technological Research and the Police Headquarters of Catalonia of the National Police, the Italian Polizia di Stato, the Polish National Police and the British National Crime Agency.  

UPDATE #3 -- The News From Poland

The Polish National Police have also issued a press release about the arrests made in Poland.  Click the Polish language headline below for the original article.  A Google-translate assisted version follows for the benefit of our English-speaking readers.  (stills from video http://cbsp.policja.pl/dokumenty/zalaczniki/3/3-165386.mp4 )

Police in Poland prepare for a raid.

The Phishing suspect is apprehended


Laptops, passports, cell phones, and cash seized in the raid

Międzynarodowa operacja Europolu i Eurojustu - w sumie zatrzymano 49 cyberprzestępców

(International Operation of Europol and Eurojust - a Total of 49 Criminals Arrested)

Officers Coordination Team Central Bureau of Investigation Police and Border Guard as well as police officers Municipal Police Headquarters in Krakow and the Department for Combating Cybercrime Regional Police Headquarters in Krakow, acting under the supervision of Appellate Prosecutor's Office in Krakow together with the police and law enforcement authorities from Italy and Spain, with collaboration with investigators from Belgium, Georgia and the UK and support of Europol and Eurojust, figured out an international organized criminal group, engaged in money laundering, originating, inter alia from phishing attacks carried out against citizens of European countries. On the Polish territory had been detained this matter for a total of 18 people.
 
On June 9th and 10th,  Europol and Eurojust conducted an international action against cyber criminals. A total of 49 suspects have been detained. The activities were also conducted in Poland.
Yesterday, in the province of Malopolska police activity was carried out in this case, one of the most important leading to the arrest of five people, including the man who organized criminal dealings on Polish territory. The Central Investigation Bureau Police seized more than 160 thousand from phishing.
 
In total, the Polish were detained in that case 18 people. According to estimates investigators, members of criminal group could "launder" a total of over 7.7 million (this amount coming only from the crimes committed in our country).
 
Detained charges of fraud, money laundering and participation in an organized criminal group.
On account of the suspect threatened penalties and fines secured property value of 1.8 million.
 
Results of "Operation Triangle" are the result of large-scale investigations carried out in Italy, Spain and Poland (Central Bureau of Investigation Police Department with the participation of cybercrime Police Headquarters in Krakow under the supervision of Appellate Prosecutor's Office in Krakow). The aim was to break organized crime groups engaged in phishing on the Internet. These types of crimes are carried out by specialized criminals who use the Internet to commit fraud. In addition criminals from exploiting cyberspace to "laundering" of money, proceeds of crime. In this way, embezzlement made substantial amounts of money from victims throughout Europe.
 
In parallel, the investigation showed the existence of international fraud on a massive scale, extortion million in short time. The suspects, mainly from Nigeria and Cameroon, upload illegal profits outside the European Union through a complex network of transactions related to money laundering.
In preparation for the run yesterday and today operations, Eurojust coordinated the gathering of information from various law enforcement agencies, as well as organized several coordination meetings with representatives of national authorities from Italy, Spain, Polish, Belgium and Great Britain. With all these joint efforts, coordination center was established who carried out the operation with the support Team. Analysis Affairs Eurojust, the European Centre for the fight against Cybercrime Europol (EC3) and the Joint Task d. Cybercrime (JCAT) - a new European institution created to assist investigations to combat cybercrime.
 
Joint action brought excellent results, while she realized that joining forces selected EU agencies and national authorities can successfully contribute to the fight against one of the most difficult to detect forms of contemporary crime.
 
Teresa-Angela Camelio, National Assistant Representative of Italy to Eurojust, commented: "Eurojust played a key role in promoting the agendas of EU efforts in combating this type of crime, which requires knowledge, cooperation and coordination between all involved national and international actors. The results of the two-day operation are a clear signal to criminals that they will be prosecuted in every jurisdiction. "
 
Phishing on the Internet: This type of cybercrime, carried out by organized criminal groups, depends on gaining access to passwords and names (nicknames) of users for illegal activities. Criminals replace respective owners information through "phishing" their data and thereby gain access to their accounts, which means access to the money the victims and their customers. Credentials obtained in this way by organized criminal groups hurts many Internet clients, while generating billions of euros of profits for organized crime groups.

Monday, March 30, 2015

Tech Support "pop-ups"

There is a new trap on the Internet that seems to be growing in popularity in the form of a Tech Support pop-up Window.  The first of these I saw was last Tuesday, March 24, 2015.

Norton Scam


While reviewing some pharmaceutical spam web pages, we were suddenly forwarded to the page:

alert.norton.com.pctechhelpforyou.com/index-15mac.html

Immediately after this page rendering, a pop-up window is repeatedly displayed insisting that we need to call the telephone number 1-888-884-7058, ringing a bell each time the window is displayed.  The pop-up is so insistent that it is very difficult to get past the pop-up to close the browser.

Despite the fact that this pop-up is warning me about my APPLE COMPUTER, the original trigger that we encountered was in a Windows 7 Virtual Machine.

Looking at the source code for the page we see that we are dealing with JavaScript that has several tricks, including "right-click disable" and an annoying command "window.onbeforeunload = PopIt".  Actions such as "document.onmouseup" and "document.captureEvents(event.MOUSEDOWN)" help to keep control of the window, making it nearly impossible to close the browser, which also sets itself to appear in the Center of the screen, obscuring other opportunities to deal with the warning.

iPad / Mac Pop-ups


This weekend, I found myself looking at a very similar variant, this time on an iPad, where it was even more difficult to get rid of the pop-up!

Because of the lack of mouse or keyboard on the iPad, this version of the browser pop-up was especially hard to deal with.  The pop-up prevented me from being able to exit Safari!  In the end, it was necessary to power off the iPad, power back on, and then use the "Settings" tab to clear my history and settings.  By default an iPad Safari browser returns you to the most recently visited page, which unfortunately was this pop-up!

As I explored this version, I found that the current domain was hosted on the IP address 198.143.166.36.   This same IP address was also hosting a great number of other suspicious domain names,which began to show up on March 9, 2015, according to the Passive DNS service from Internet Identity.  Checking several of these domains on the Apple forums indicates that victims are charged between $150 and $399 to clean-up an imaginary malware attack.

  • mac-issue-online.com -- https://discussions.apple.com/thread/6684596 (800 680 4131)
  • apple-alert-online.com -- https://discussions.apple.com/thread/6850245
  • safarisecurityissue.com -- https://discussions.apple.com/thread/6516787
  • mac-security-alerts.com -- https://discussions.apple.com/thread/6897787
  • online-window-security.com -- (Windows - see below)
  • window-system-error.com -- suspended (why only this one??)
  • mac-pc-alerts.com -
  • safarisystemalert.com
  • online-system-alerts.com
  • safarialerts.com
  • window-security-issues.com
  • instantcomputerfix.com -- https://discussions.apple.com/thread/6669786
  • techcarelive.com -- https://discussions.apple.com/thread/6527487
  • safarisystemissue.com
  • online-warning-support.com
  • quickbo0ks.com
  • iexpertstech.com
  • ixperts.net
  • joinremote.me
  • i-xperts.us
 The last several of the links on that page appear to belong to a company that does support for Intuit Quickbooks, however "JoinRemote.me" is a remote control tool.  When the telephone number is called, the tech support person walks the customer through entering a tech support code by visiting "JoinRemote.me":
When that is done, the customer service technician is provided remote control access to the computer to "clean it up."

A friend from MalwareBytes has documented similar scammy behavior where a tax-season Intuit helper website ends up charging for a malware removal.  See Jerome's blog here:  https://blog.malwarebytes.org/fraud-scam/2014/03/the-tax-season-tech-support-scam/


By reviewing the Apple Discussion boards, we also saw evidence that several other people were struggling with these pop-up messages:

 


 Continuing to explore through the Apple discussion forums, we found evidence that this was also discussed back on September 2, 2014 in this post by Carlton Chin:

The September file had a different domain name, and a different telephone number, but could it be shown to be the same scammers?  Was applesecurityalert.com on 1-866-782-9808 related to safarisystemissue.com on 1-800-632-9078?

Back to Passive DNS to try to find out.

According to the Internet Identity Passive DNS system, AppleSecurityAlert.com was hosted on the IP address 50.87.153.101 beginning on August 8, 2014.

That IP address ALSO hosted i-xperts.us, ixperts.net, joinremote.me, and quickbo0ks.com, all of which were also found on both the August/September IP (50.87.153.101) and the March 2015 IP (198.143.166.36).

Several of the attack sites that share these IP addresses are Microsoft imitators rather than Apple.  One example is "online-window-security.com" pictured below:

Imitating Microsoft Security Essentials

Bottom line - anyone seeing one of these pop-ups suggesting that a telephone number be called for support is DEFINITELY dealing with a scammer and should terminate the session immediately.
















Tuesday, February 24, 2015

Connected World Conference 2015

This week I've been attending the Connected World Conference 2015, hosted here in Birmingham,  Alabama.  Connected World's editor-in-chief, Peggy Smedley, hosts a weekly radio program that focuses on the Internet of Things (IoT) which their industry has called M2M for many years before the IoT tag came along.   Peggy's website has a great tutorial on the Machine To Machine networking technologies and the many ways in which they communicate, but I think nothing really brought the point home to me until I attended the Connected World Awards dinner last night.

If you are thinking about Cyber Security and the Internet of Things, here are quite a few interesting applications I learned about in the dinner last night.  The full range of Connected World Award winners are listed here, but these were a few that really caught my attention.

AT&T Drive Studio - The AT&T Drive Studio in Atlanta, Georgia - The AT&T Drive Studio™ is the first connected car innovation center in the U.S. to be opened by a wireless carrier. And AT&T is inviting the world's most innovative companies and developers to come create the future of connected cars.

ApartmentGuardian, powered by RacoWireless, won the Gold award in the PERS category.  Property managers can use the technology in many ways, from protecting their Lone Workers with a personal safety button (reminiscent of the "I've Fallen and I Can't Get Up!" button that you might buy for your grandmother) to a system for identifying guests to the property in a combined ID card and biometrics solution for visitors to the property, and innovative Security Panels.  The use of low-power radio technology as a backup to "wall power" for keeping your building security and alarm systems online and active during power failures.

Two companies won awards in the Lighting/Manufacturing category.  In both situations the recipients, Atlantic States and Clow Water Systems, were able to achieve amazing savings in both energy and true financial savings by putting in intelligent lighting systems.  Synapse Wireless allows the light fixtures in both organizations to be controlled remotely and through connecting all of the lights in a "Mesh" system - a cloud of lighting services that are in constant communications with one another.

SNAP LightSense from Synapse Wireless

Mesh Systems was the IoT-enabler for BUNN who received an award in the Remote Equipment Management category.   You have heard of the IoT refrigerator, but BUNN has created the IoT Coffee pot!

One of the most interesting M2M applications was SOLARKIOSK, which is using Gemalto's Cinterion modules to deliver remote connectivity and a web-interface for monitoring power production to a mobile unit about the size of a food truck that can be deployed in remote areas, including extremely rural Africa, to provide power and cellular connectivity to areas that lack reliable power.  The first such unit was featured in this story "First SolarKiosk opened in Ethiopia."  The creator, Lars Krückeberg, was featured in a TED talk about the technology as well.

The IoT enables some interesting Fleet Management capabilities as well.  CalAmp and the City of Dayton received an award for their system for monitoring and protecting their fleet of 210 snow removal vehicles.  The system, called GovOutlook, turns itself on when a key is inserted into a vehicle, and requires a City of Dayton employee id badge to be scanned to prevent lockdown and alarming.  The system also provides safety for the drivers, who are out on the roads, often in the middle of the night, plowing the 1800 lane miles of snow-covered roads in the city of Dayton.


The focus of our Connected World Conference this year has been on Cyber Security ... speakers including myself and John Grimes from UAB, JD Sherry from Trend Micro, Seth Danberry from Grid32, Jonathan Ratner from Sixgill, Brian Zaugg from Authentic8 and others joined to share our thoughts on Cyber Security to those who have come from the Internet of Things / Machine 2 Machine world.  I was glad I participated and learned much more about the IoT world!

Thanks, Peggy!

To learn more about the IoT, please do check out Connected World Magazine and check in with the Peggy Smedley Radio show.







Friday, February 06, 2015

DIA Cyber Warrior delivers first Worldwide Threat Assessment

Vincent R. Stewart, Lieutenant General, U.S. Marine Corps was promoted into the position of Director of the Defense Intelligence Agency. While our friend and colleague Lt. General Ronald Burgess (ret.), now at Auburn University here in Alabama, certainly understood and respected the importance of the cyber domain, General Stewart represents the first time we have a true cyber warrior at the helm of the DIA.  Immediately prior to his appointment as Director of the DIA, General Stewart served as the commander of the Marine Force Cyber Command (described at the end of this blog post.)  General Stewart was director of Marine Intelligence from 2009 to 2013, rising through the ranks in a long and distinguished career that began with humble beginnings in Jamaica and includes many decorations for valor and leadership.


Worldwide Threat Assessment - Cyber

On February 3, 2015, Lt. General Stewart delivered his first Worldwide Threat Assessment to the Senate Armed Services Committee. (Transcript here). So what did our new DIA Cyber Warrior leader have to say about Cyber threats?

The briefing began, appropriately, with a status of Iraq and Afghanistan, focusing on terrorist threats from ISIL, al-Qa'ida, and the Taliban. After that he touched on certain other "violent extremist organizations" and concluded with a region-by-region and global threat summary.

In his discussion of ISIL, al-Qa'ida, and the Taliban, no technology or internet discussion was featured. Expanding beyond Iraq, AQAP (Al-Qa'ida in the Arabian Peninsula) was said to be focused on commercial aviation targeted with innovative explosions. AQIM (Al-Qa'ida in Lands of the Islamic Mahgreb) is mostly focused on kidnapping and attacks against allies. The Al-Nusrah Front and the Khorasan group were said to be focused on providing personnel and training in Syria, but with an interest in targeting western interests. IRGC-QF (Islamic Revolutionary Guard Corps-Quds Force) and Lebanese Hizballah were described a "instruments of Iran's foreign policy and its ability to project power in Iraq, Syria, and beyond." Boko Haram was described as having the potential to expand beyond Nigeria to become a "significan regional crisis."

Cyber Operations

The first mention of cyber comes with regard to Russia, mentioning that Russian actions against Kyiv included "the use of propaganda and information operations, cyberspace operations, covert agents, ..."While the other regional assessments did not include cyber individually, cyber was brought up in the concluding portion of the remarks in the section labeled "Global Threats."

General Stewart's points on the lack of consensus about the status of cyber attacks was especially telling. The "big bullets" from the cyber portion of the talk seem to be:

  • aggressive attacks against DoD and allied defense networks
  • increased cyber-espionage against DoD and Defense Contractor networks
  • concerns about supply chain vulnerabilities
  • increased use of cyber operations in regional conflicts
  • a lack of international "norms of behavior" in cyberspace
  • freedom of action, especially by Iran and North Korea, to conduct peacetime cyber offensive attacks on western interests without fear of reprisal
  • the use of the Internet by non-state actors for Communication, Propaganda, Fundraising, and Recruitment
Below I quote the General's remarks on cyber in full:
The global cyber threat environment presents numerous persistent challenges to the security and integrity of DoD networks and information. Threat actors now demonstrate an increased ability and willingness to conduct aggressive cyberspace operations -- including both service disruptions and espionage -- against U.S. and allied defense information networks. Similarly, we note with increasing concern recent destructive cyber actions against U.S. private-sector networks demonstrating capabilities that could hold U.S. government and defense networks at risk. For 2015, we expect espionage against U.S government defense and defense contractor networks to continue largely unabated, while destructive network attack capabilities continue to develop and proliferate worldwide. We are also concerned about the threat to the integrity of the U.S. defense procurement networks posed by supply chain vulnerabilities from counterfeit and sub-quality components.
Threat actors increasingly are willing to incorporate cyber options into regional and global power projection capabilities. The absence of universally accepted and enforceable norms of behavior in cyberspace contributes to this situation. In response, states worldwide are forming "cyber command" organizations and developing national capabilities. Similarly, cyberspace operations are playing increasingly important roles in regional conflicts -- for example, in eastern Ukraine -- where online network disruptions, espionage, disinformation and propaganda activities are now integral to the conflict.
Iran and North Korea now consider disruptive and destructive cyberspace operations a valid instrument of statecraft, including during what the U.S. considers peacetime. These states likely view cyberspace operations as an effective means of imposing costs on their adversaries while limiting the likelihood of damaging reprisals.
Non-state actors often express the desire to conduct malicious cyber attacks, but likely lack the capability to conduct high-level cyber operations. However, non-state actors, such as Hizballah, AQAP, and ISIL will continue during the next year to effectively use the Internet for communication, propaganda, fundraising and recruitment.


MARFORCYBER background

In January, General Stewart passed control of the U.S. Marine Corps Forces Cyber Command (MARFORCYBER)to Major General Daniel J. O'Donohue.


(a somewhat dated biography of General O'Donohue is available from the Armed Services Committee)

The command, established in October 2009, was complemented by the Navy's U.S. Tenth Fleet Cyber Command. According to the Marine Corps' "Concepts and Programs" document, the mission of MARFORCYBER is to "plan, coordinate, integrate, synchronize, and direct full spectrum Marine Corps cyberspace operations. This includes Department of Defense (DoD) Global Information Grid (GIG) operations, defensive cyber operations, and when directed, planning and executing offensive cyberspace operations. These operations support the Marine Air Ground Task Force (MAGTF), joint, and combined cyberspace requirements that enable freedom of action across all warfighting domains and deny the same to adversarial forces."

MARFORCYBER has two sub-units, Marine Corps Network Operations and Security Center (MCNOSC), which defends the Marine's own network, and Company L, Marine Cryptologic Support Battalion (MCSB), which plans and executes offensive cyberspace operations.
(www.marines.mil/Portals/59/Publications/U.S. Marine Corps Concepts and Programs 2013_1.pdf, PDF page 42)











Tuesday, January 06, 2015

Universities Targeted with "Library Account" phish

Many universities across the country have been targeted with phishing emails that warn their students that their "Library Account" is going to expire. As with so many cybercrime issues, these crimes could be addressed much differently if the Powers That Be were aware that these were not individual cases, but an on-going campaign across victims across the country!

Towards that end, I've collected full text examples of many of these phish, with links to the University web pages where there students have been warned. Hopefully we can start warning people of national on-going campaigns like this BEFORE they are victimized!

While I was reviewing University Phish for this project, I was especially impressed with the phishing details shared at University of Michigan (Go Blue!) and University of Pennsvylvania. Both are great examples of giving students enough details to understand the scope of the risk at hand.

January 2014 Library Account phish


January 9, 2014 - George Washington University
Subject: Library Account
Dear User,

Your library account has expired, therefore you must reactivate it immediately or it will be closed automatically. If you intend to use this service in the future, you must take action at once! To reactivate your account, simply visit the following page and login with your university account. After logging in, your account is reactivated and it will redirect you to your Library Account.

February Library Account phish


February 21, 2014 - Flinders University
Have you received an email asking you to “validate” your Library Account? This email is attempting to steal Flinders user credentials and is not legitimate.

Don’t follow the links in the email, just delete it. The library will never ask you to login to verify your details or activate your account.

May Library Account phish


May 23, 2014 - Lehigh University

June Library Account phish


June 26, 2014 - University of Minnesota
From: Library
Date: Thu, Jun 26, 2014 at 8:47 AM
Subject: Library Account
To:
Dear User,
Your library account has expired, therefore you must reactivate it immediately or it will be closed automatically. If you intend to use this service in the future, you must take action at once!

To reactivate your account, simply visit the following page and login wilth your library account.

Login Page:
xxxxxxxxxxxxxxxxxx
Sincerely,
University of Minnesota Libraries
499 Wilson Library
309 19th Avenue South
Minneapolis, Minnesota 55455
(612) 624-3321 (voice)
(612) 626-9353 (fax)

September Library Account phish


September 10, 2014 - University of Pennsylvania
From: Jonathan Heller < jheller@pobox.supenn.edu > 
Subject: Library Account Access 
Date: Wed, Sep 10, 2014 2:11 PM 

Dear User, 
Your access to your library account is expiring soon and it won't be accessible for you. You must reactivate your account in order to continue to have access to this service. For this purpose, click the web address below or copy and paste it into your web browser. After logging in, your access is reactivated and you will be redirected to your library profile.

(LINK REMOVED)

If you are not able to login, please contact Library Services Manager at jheller@pobox.upenn.edu .


Sincerely, 
Jonathan Heller 
Library Services Manager 
Access & Delivery Services 
Penn Libraries 
University of Pennsylvania 
(215) 898-8956 
jheller@pobox.upenn.edu 

September 17, 2014 - University of North Carolina Health Sciences Library
Alert: Phishing Emails Impersonate UNC Library

Some members of the UNC community have received false emails that appear to be from the Library.

These emails state that “access to your library account is expiring soon and it won’t be accessible for you.” The email directs the recipient to a link that appears to be from the Library.

October Library Account Phish


October 8, 2014 - UC Denver's Auraria Library
October 9, 2014 - University of Colorado Health Sciences Library
The University has been recently subjected to a phishing attack. The subject line of these new phishing messages is “Library Account Access”. These emails are designed to appear as if they are coming from the library concerning a library account activation. The phishing emails also contain links to malicious web sites that ask for your University information (Name and student/employee ID).


October 10, 2014 - Miami University of Ohio
    From: XXX XXX [mailto:xxxxxxxx@miamioh.edu]
    Sent: Friday, October 10, 2014 12:45 PM
    To: xxxxxxxx@miamioh.edu
    Subject: Library Account Access

    Dear User,

Your access to your library account is expiring soon and it won’t be accessible for you. You must reactivate your account in order to continue to have access to this service. For this purpose, click the web address below or copy and paste it into your web browser. After logging in, your access is reactivated and you will be redirected to your library profile.

(LINK)

If you are not able to login, please contact Library Services Manager at xxxxxxxx@miamioh.edu.


    Sincerely,
    
    Alison Withers
    Library Services Manager
    Access and Delivery Services
    University Library
    Miami University
    513-529-2938
 

October 30, 2014 - Virginia Commonwealth University
To:
From: Access Services Manager 
Date: 10/30/2014 11:54AM
Subject: Library Account Access

Dear User,
Your access to your library account is expiring soon and it won’t be accessible for you. You must reactivate your account in order to continue to have access to this service. For this purpose, click the web address below or copy and paste it into your web browser. After logging in, your access is reactivated and you will be redirected to your library account.

(Link redacted, actual link goes to login.vcu.edu.cavc.tk)

If you are not able to login, please contact Library Services Manager at kbonis@vcu.edu.


Sincerely,

Kerry Bonis
Library Services Manager
Access & Delivery Services
Main Library
Virginia Commonwealth University
(804) 827-3968

November Library Account phish


November 13, 2014 - Illinois Institute of Technology
IIT faculty, staff and students may have received an email to “All Members of the University of Illinois” notifying you about a new library system that requires you to activate a new library account. Do not respond to this email. It is a phishing attempt to collect IIT campus-wide ID numbers (CWIDs).

Library users affiliated with Illinois Tech gain access to subscription databases when off-campus by entering their CWID. Releasing that information to a third-party may result in access to our databases being limited or cut off. You can always safely access the library website by using the IIT Portal links, or going directly to the library website. If you believe your CWID has been compromised, please contact the OTS support desk.


November 17, 2014 - Southern Methodist University
Sample Phishing Email

Subject: Library Account Access
Sender: Jane Sippell 

Dear User,
Your access to your library account is expiring soon and it won’t be accessible for you. You must reactivate your account in order to continue to have access to this service. For this purpose, click the web address below or copy and paste it into your web browser. After logging in, your access is reactivated and you will be redirected to your library profile.

Note – this link appears in the email:

https://libcat.smu.edu/cgi_bin/ldapauth.cgi_loginType=E25JFHNfCD7…

The actual destination does not point to the SMU library catalog but to a web address at http://libcat.smu.edu.cvre.tk

http://libcat.smu.edu.cvre.tk/cgi_bin/ldapauth.cgi_loginType=E25JFHNfCD7v…

If you are not able to login, please contact Access Services Manager at jsippell@smu.edu.


Sincerely,

Jane Sippell
Access Services Manager
Access & Delivery Services
Central University Libraries
Southern Methodist University
(214) 919-5931
jsippell@smu.edu
November 17, 2014 - University of Arizona
From: library (EMAIL ADDRESS REMOVED)
Subject: Library account
Date: November 17, 2014 at 8:46:39 AM MST
Reply-To: (EMAIL ADDRESS REMOVED)

Dear User,
Your library account has expired, therefore you must reactivate it immediately or it will be closed automatically. If you intend to use this service in the future, you must take action at once!

To reactivate your account, simply visit the following page and login with your library account.

Login Page:

(URL REMOVED)

Sincerely,

The University of Arizona Libraries
(ADDRESS, PHONE NUMBER AND URL REMOVED)


November 18, 2014 - Washington University in St. Louis
Dear User,

Your access to your library account is expiring soon and it won’t be accessible for you. You must reactivate your account in order to continue to have access to this service. For this purpose, click the web address below or copy and paste it into your web browser. After logging in, your access is reactivated and you will be redirected to your library profile.

(LINK)

If you are not able to login, please contact Access Services Manager at *********@wustl.edu.

Sincerely,


November 19, 2014 - Ball State University Library
University Libraries was alerted that some members of the Ball State community received an email message stating their library account was soon to expire. The email said to reactivate the account by clicking on a web address included in the message. This was a phishing scam and the campus Office of Information Security took steps block access to the phony site.

December Library Account Phish


December 1, 2014 - Harvard University
December 1, 2014 - McGill University (Canada)
    From: Library  
    Subject: Library Account
    Sent: Monday, December 01, 2014 8:49 AM
    To: 

    Dear User,
    Your library account has expired, therefore you must reactivate 
    it immediately or it will be closed automatically. If you intend 
    to use this service in the future, you must take action at once!

    To reactivate your account, simply visit the following page 
    and login with your library account.

    Login Page:

    Sincerely,

    McGill Library
    McLennan Library Building
    3459 rue McTavish
    Montreal, Quebec
    H3A 0C9
 
December 1, 2014 - Cornell University
Subject: Library Account
Date: December 1, 2014

Dear User,

Your library account has expired, therefore you must reactivate it immediately or it will be closed automatically. If you intend to use this service in the future, you must take action at once! To reactivate your account, simply visit the following page and login with your library account.

Login Page:
(BAD LINK)

Sincerely,

Cornell University Library, Ithaca, NY 14853 | (607) 255-4144


December 3, 2014 - University of Tennessee Knoxville
Dear User,

Your library account has expired, therefore you must reactivate it immediately or it will be closed automatically. If you intend to use this service in the future, you must take action at once!

To reactivate your account, simply visit the following page and login with your library account.

Login Page:

http://www.lib.utk.edu/reactivation?service

Sincerely,


    University of Tennessee
    University Libraries
    Email: library@utk.edu
    Tel: (865) 974-4351
 

December 15, 2014 - California State University Long Beach
December 18, 19, 20, 2014 - University of Michigan - (Hail to the Victors! Go Blue! WELCOME COACH HARBAUGH! Watched you play in 1985 while I was a Wolverine myself!!!) (oops) (blush)
Date: Thursday, December 18, 2014
Subject: Library Account Access

Dear User,

Your access to your library account is expiring soon and it won’t be accessible for you. You must reactivate your account in order to continue to have access to the library services. For this purpose, click the web address below or copy and paste it into your web browser. After logging in, your access is reactivated and you will be redirected to your library profile.

[LINK REMOVED]

If you are not able to login, please contact [LINK REMOVED] for immediate assistance.

Sincerely,


Access Services Manager
University of Michigan Library
(734) 936-2921
[LINK REMOVED]
Date: Friday, December 19, 2014
Subject: U-M library System Problem
Dear [Your Name],

You are receiving this message because your login and off-campus access may have been compromised.

Your access will be inactive in 3 days. Because of some security problems, we decided to make some changes (Upgrade) and this is due to the implementation of a new version of Central Authentication System(CAS) and Umich WebLogin.
This means while you are off-campus or on-campus you will have no access to library's internal web services.

You can activate it by going again simply login to University of Michigan Library Weblogin System with your U-M LoginID and reactive your access.
Offer that Logout your account and close your browser.

Please note: If you get an Authentication Error ,just try 2 times to login again. Because System will automatically block your IP and Account and you should contact Systems Help Desk to Unlock.

University of Michigan Library
818 Hatcher Graduate Library South
913 S. University Avenue
Ann Arbor, MI 48109-1190
(734) 764-0400
[LINK REMOVED]
Date: Friday, December 19, 2014
Subject: ADMIN

Dear Web-mail Account User,

Your e-mail Account have Exceed the 20 GB e-mail Storage Set-Up by your Service Provider/Admin. You have to contact your Service Provider on Help Desk Support Portal below in less than 48 hours to avoid Suspension of your Web-mail Account if you dont Verify your e-mail account. To keep your Account Safe, Kindly Click the Help Desk Support Blue Portal below:

umich.edu-helpdesk [LINK REMOVED]

SERVICE DESK - IT HELP DESK
©COPYRIGHT 2014 WEB-TEAM. ALL RIGHT RESERVED.

December 23, 2014 - Wake Forest University
Dear User,

Your access to your library account is expiring soon and it won’t be accessible for you. You must reactivate your account in order to continue to have access to the library services. For this purpose, click the web address below or copy and paste it into your web browser. After logging in, your access is reactivated and you will be redirected to your library profile.

(LINK)

If you are not able to login, please contact James Hart at hartja@wfu.edu for immediate assistance.

Sincerely,

James Hart
Access Services
ZSR Library
Wake Forest University
336-758-4967
hartja@wfu.edu

December 23, 2014 - UAB Library

Wednesday, November 12, 2014

Phishing Success Rates and Google Phish

Last week a group of Google employees led by Elie Bursztein joined UCSD researchers Andreas Pitsillidis and Stefan Savage in presenting the findings of a study on phishing to the ACM Internet Measurement Conference in Vancouver, British Columbia. Their paper, Handcrafted Fraud and Extortion: Manual Account Hijacking in the Wild (12 page PDF) was picked up broadly in the press, and as usual, wildly misinterpreted.

At least 110 articles referring to the study were found in a simple Google News search with headlines ranging from the somewhat accurate:

  • Manual Phishing Gmail Attacks Found To Be Very Effective - Top Tech News, Nov 9, 2014
  • Google Study Finds Email Scams Are More Effective Than You'd Expect - Huffington Post, Nov 7, 2014
  • Old-time phishing scams are working just fine, Google finds - Naked Security, Nov 11, 2014
to the extreme bending of the facts for headline value such as these:
  • Phishing attacks on email accounts are successful 45 percent of the time - Firstpost, Nov 10, 2014
  • Phishing scams work 45% of the times: Google study - Times of India, Nov 10, 2014
  • Have You Been Scammed? Phishing Emails Successful 45% of the Time - Crave Online, Nov 11, 2014
  • A scary number of you are still falling for phishing scams, says Google - Nov 10, 2014

What did Google and UCSD Actual Say about Phishing?

First, the 45% quote. For the 100 Google/Gmail phishing sites that the researchers studied, they found that depending on the structure of the page, as few as 3% of the visitors filled out the phishing form and submitted their data. Overall 13% of the visitors to the webforms shared their personal data with the phishers, while in the most extreme example, 45% of the visitors to the phishing web page completed the form and submitted their personal data.

There were several interesting findings in the study. A few that I found interesting included:

  • 35% of phishing sites target victims' email
  • 21% of phishing sites target banking credentials
  • A growing number of phishing sites are targeting App Stores and Social networking credentials
  • Account takeovers are primarily Fast and Foreign:
    • 20% of compromised Google accounts were logged into within 30 minutes
    • The top countries of origin for hijackers were China, Ivory Coast, Malaysia, Nigeria, and South Africa
  • The easiest way to have your account restored is to have registered an SMS telephone number for out of band contact.

Manual Hijacking

The focus of this study was the process of Manually Hijacking accounts belonging to Google users. Because of that focus, it is not clear how broadly the observed behaviors can or should be projected onto other types of phishing. At Malcovery Security we observe 600 to 800 newly created phishing sites per day. This study focused primarily on Gmail/Google phish from January 2014, and for part of the study focused specifically on 100 Gmail phishing websites.

Google provided some statistics on how widely the problem of manual hijacking has been seen in the past. Over calendar 2012-2013, Google's security teams found that approximately 9 manual hijacking cases per day per million active users occurred. With over 500 million subscribers, Google is dealing with thousands of such account hijacks per day.

With Google participating in the research, researchers were able to determine that when an account is taken over, the criminals login to the account and search the email history and address books to determine how best to monetize the account. It seems that every week someone will make the comment in my presence "Yes, I have malware on my computer, but the worst that might happen is they get my email password!" But think about what is possible with that? How would you reset your password at your Bank? Amazon.com? eBay? On most of those sites, clicking "I Forgot My Password" results in an email being sent with a "Reset My Password" link! If the criminal finds an email from your bank in your email history, they now know exactly which bank to visit to click the "I Forgot My Password!" The email account is the key to the entire balance of your account!

The researchers also found that the scam we first wrote about in 2009 in the post Traveler Scams: Email Phishers Newest Scam is still quite prevalent. In this scam, because the criminal has access to your recent sent emails and address book, they are able to contact your friends and family with news of a tragedy while traveling where they desperately need money wired overseas to help them through the crisis. I've met many individuals who have wired money to their friends before realizing it was a scam! They often have stories of how they KNEW the email was truly from their friend, because when they asked questions, their friend replied with details only the friend would know. Often these details made use of prior "private" conversations in the phishing victim's email sent items box!

Popular Email Phish from Malcovery's ThreatHQ System

In the past seven days, Malcovery Security confirmed 416 distinct phishing URLs related to Google and their properties. These URLs were hosted on 207 distinct domain names on 174 different IP addresses. By country, the United States is the most prominent host of phishing sites, not just for Google, but for nearly every brand that does business in the USA. Of those 174 IP addresses, 90 are in the United States.

Google phish locations: November 5-12, 2014

90United States of America
8Great Britain
7Turkey
6Australia
5Canada
5Chile
5Germany
4Indonesia
4India
4Italy
4Netherlands
4Romania
4Russia
4Singapore
4Spain
3France
3Thailand
2Brazil
2Hong Kong
2South Africa
1Japan
1Korea
1Mauritius
1Ukraine
This popular phish appeared on the domains bloo8.net, iyfcolombia.org, beingmedicalep.com, lifeofease.us, microcenterengineering.com, manosartesanasdelaregion.com, ouzophilippos.com, acount-verification.com and many ohters.

Although this phishing site is PRIMARILY imitating DropBox, it still steals Gmail and other email credentials:
The domain hosting this phish was "t-online.de".
This version brings in many cable-provider logos for email address choices, rather than relying on "Other Email" as some of the others do:
This version brings the logos of many Chinese language email providers into the mix:
One of the earlier forms of the phish:
These just a few examples of the "look and feel" of some of the 400+ Google-related phishing URLs we've seen in the past seven days at Malcovery security. Most of them were seen many times each!

US Federal Grant Scam: Greendot MoneyPak Edition

Last week we shared a blog post about phone scams claiming to have a Warrant For Your Arrest. After sharing some information about that scam, we've been receiving student-generated tips from several of our students about similar phone scams.

US Federal Grant Scam

Today's scam comes to us courtesy of UAB Criminal Justice student Kyle Jones. Kyle works on the Malware Research Team at the UAB Center for Information Assurance and Joint Forensics Research.

The scam begins with a phone call, in our case coming from callerid 305.356.9999, claiming that we have been selected to receive a Grant from the Federal Government because of our participation in a survey. Of all the people who have taken this IRS Survey, 1700 people have been selected to receive this grant. The caller then instructs us that we should go to a Western Union location near us and we should call them back once we are at the Western Union for instructions on how to receive our $9,500 grant.

The callback number was (516) 554-0006, which seems to be a New York number in Garden City.

So, we waited a bit and called the criminals back from the Western Union store in my office. (grin).

When we called the 516 number, the line was answered "US Federal Grants" and we were asked for the code that we had been given during the first call. I tried providing a slightly wrong code, and learned that they actually are tracking the codes, because she was unable to look up our information. We provided the correct code and learned that it was "very important that we don't go into the Western Union Store yet!" She then asked me if we were near a grocery store, such as a Seven-11? I told her I had a Publix store nearby but she said that wouldn't work. After some back and forth, we learned that a CVS Pharmacy would work for her needs. She instructed me that I needed me to go to the CVS and buy a GreenDot MoneyPak card for $200.

"You need to put $200 on the card to activate the Money Transfer Control Number, but you will get the $200 back, it will be reimbursed with your grant.

Now, simply let me tell you, you are not going to pay the money to me or to my department. This is your money and it is going to be reimbursed back to you. Before we can transfer the money you have to make a registration with the Federal Reserve Bank and once you make the registration then with the help of the Federal Reserve Bank registration number, I will generate the Money Transfer Control Number so that you can receive your money from the Western Union Store."

Here's the audio clip of that part . . .

(audio)How it works - the woman at US Federal Grants, who sometimes claimed this grant was from the IRS, tells us we need to pay a $200 registration fee.

She then "transferred us" to the Federal Reserve Bank as you can hear with this link.

(audio)Transferred to the Federal Reserve Bank - Kevin Jones, manager of the Federal Reserve Bank took my call and helped me.

Kevin was good enough to explain the whole process of how to purchase a GreenDot MoneyPak card for $200 so that I could "within 5 minutes" pick up my $10,000 - (the $9800 grant + $200 reimbursement for my registration) - from the Western Union Counter. Here's the audio of him explaining it to us:

(audio)The GreenDot MoneyPak Process - as explained by the Federal Reserve Bank's Kevin Jones

What To Do if you are a US Federal Grant Scam victim

  • The Best Place to report any type of online scam is the FBI's Internet Crime & Complaint Center. To go directly to their complaint page, use this link:

    https://complaint.ic3.gov.

    Although the form has many questions that you may not be able to answer, complete the form to the best of your ability with the information you DO know. Specifically make sure to note things such as:

    • What name did the person use?
    • Did they call you by name?
    • What agency, department, or company did they claim to be with?
    • How much money did they want you to pay?
    • What number(s) shows up in your callerid?
    • Did they give you any other numbers to call or websites to visit?
    Even if you do not have ALL of this information, any information you share can help link cases together. If someone calling Houston and someone calling Birmingham both told you to call the same phone number, that is a "link". If they used the same Officer Name, that is another "link". The more individual cases we can link together, the better chance we have of catching the criminals!

  • IF YOUR SCAM MENTIONS THE IRS, be sure to report the crime to the investigators at the Department of Treasury who have set up a special website for gathering information about this scam:

    http://www.treasury.gov/tigta/contact_report_scam.shtml

  • IF YOU HAVE LOST MONEY in your case, be sure to ALSO report this as a crime to your local Police Department!
Thank you for reading! Please share this link with your friends, family, and co-workers for their awareness! If you have a story you would like to share, please use the Comment form below!