Wednesday, July 20, 2022

Nigerian Money Transfer Company Linked to Romance Scam Money Laundering

On July 7, 2022, the US Attorney for the Northern District of Texas announced that Ping Express had been found guilty. Prior to this, their CEO Anslem Oshionebo*, their COO Opeyemi Odeyale (now imprisoned at the Danbury Federal Correctional Institute, 60177-177), their IT Manager Aleoghena Okhumale (now imprisoned at the Fort Worth FMC), and Olufemi Sadiq (now imprisoned at the Pollock FCI) were arrested on March 10, 2020.

What was Ping Express? Ping was a small business, never having more than ten employees, which operated from 8585 N. Stemmons Freeway, Dallas, Texas. Their CEO was Anslem Oshionebo and their COO was Opeyemi Odeyale. Ping had a smart phone app and a website and advertised that its users could easily send money to Nigeria for a small fee. It operated by having money on deposit in Nigeria. When a US-based client requested a transfer, a hold was placed on the customer's bank account (similar to a hold placed when one rents a car or stays in a hotel.) Then Ping would transfer funds from its Africa-based wallet to the recipient's Africa-based bank account. When the transfer was completed, Ping would then request payment from the sender's bank account.

While this post is about the US-based aspects of Ping Express and their crimes, the company's Instagram page continues to advertise that individuals in many places can use their services, including the UK, Canada, and Europe.

During a three-year period examined in this case, Ping transferred more than 300,000 payments totaling $167 Million USD. During this time it did not file a single Suspicious Activity Report, although they did make some batches of reports under section 5318(g) in 2015, 2016, and 2019.

To maintain a business license in Texas, they were required to file a detailed business plan, including their statements regarding how they would comply with BSA/AML laws (Bank Secrecy Act and Anti-Money Laundering Act, including CFT, Countering Financing Terrorism). Among the rules that Ping established and conveyed to the state of Texas, they agreed to the following:

  • All first-time customer transactions are limited to $499.
  • Total monthly transactions cannot exceed $4500.
  • Further transactions are limited to $1800 each, with a $3000 daily maximum.

They also claimed that they had "automated velocity checks" and the ability to "track and block IP addresses" to help prevent violations.

The court records include a "Factual Resume" "in support of Ping Express US LLC's plea of guilty to the offense in Counts 1 and 2 of the Superseding Information."

Count One - "failure to maintain an effective anti-money laundering program" was proven by demonstrating the defendant acted willfully in failing to develop, implement, and maintain an effective anti-money laundering program.

Count Two - "operating an Unlicensed Money Transmitting Business"


In the Factual Resume, the Count One requirements which they failed to implement are stated as:

An "effective anti-money laundering program" which is required by law, requires that Ping Express establish one or more of the following minimal requirements set forth by regulations of the Secretary of the Treasury. The Guilty Plea confirms that they failed to do so:

a. Effective written policies, procedures and internal controls for one or more of the following:
i. Verifying customer identification
ii. Filing reports, such as suspicious activity reports
iii. Creating and retaining records

b. Designating a person to assure day-to-day compliance with the anti-money laundering program, including assuring that:
i. Ping properly filed reports, created and retained records, in accordance with applicable requirements, such as suspicious activity reports
ii. the [AML] program was updated as necessary to reflect new requirements

c. Provide education and/or training of appropriate personnel concerning their responsibilities.

Examples of AML Failures

Many specific examples are then listed, demonstrating the failures of Count One enforcement, in the Factual Resumes for Ping itself, and also for its CEO and COO who have also both pled guilty:
  • Fatai Okunola, a first-time customer, sent $1800 in January 2018
  • Raman Saliu, a first-time customer, sent $1800 in October 2017
  • Jeffersonking Anyanwu, a first-time customer, sent $1400 in March 2018

Between April 1, 2016 and June 30, 2018, 1500 different customers violated the maximum monthly transfer rules.

Okunola sent more than $6700 his first month, and broke the $4500 rule every month from January 2018 to November 2018. He sent $80,000 just in August 2018!

Anyanwu paid $17,000 through Ping, and broke the maximum monthly rule six times between March and November 2018, paying more than $10,000 in a month four times.

Another customer broke the rule six times from October 2016 through June 2018.

Okhumale, who worked for Ping as their IT and Technical Support Manager, broke the monthly rule three times, paying $25,000 just in October 2018.

The daily rule was also largely ignored. Okunola violated the $3000 daily limit 45 times, and sent more than $5000 in a day 20 times! Okhumale, the Ping employee, sent on three consecutive days in October 2018 $4600, $5200, and $3600! Collins Orogun sent more than $3000 per day 60 times between November 2018 and December 2019, totaling more than $300,000!

Although Ping claimed that they used the IP address of the customer to ensure that they lived in a state where Ping was licensed to do business, and required customers to submit a utility bill from a company where they were licensed to do business as proof of residency in that state, they frequently ignored this rule. Ping was only licensed to do business in Georgia, Maryland, Texas, Washington State, and Washington D.C.

  • Joseph Kadiri, a Ping customer, sent $216,000 claiming to be in Texas or Maryland, when in fact he resided in New York and Michigan where Ping is not licensed. He violated the daily limit 20 times and the monthly limit twice.
  • Isaac Omohake, a Florida resident, sent $469,000 through Ping, which is not licensed in Florida. He violated the daily limit repeatedly, and in November 2018 sent $78,000 in one month.
  • Taiwo Akinsanmiju, an Indiana resident, started sending funds at age 17 (a violation) and sent $220,000 to 85 different named individuals!
  • Ayodeji Jegede, an Ohio resident, sent $468,000 through Ping, violating the first transaction rule, the monthly rule (twelve times from June 2018 to June 2019) and in May 2019 sent $69,000 in a single month!

Investigators found that Ping's top 100 customers sent $19,400,000 from March 2016 through September 2019, and that 2/3rds of these customers were from "unlicensed" jurisdictions. Ping was fully aware that these customers lived in unlicensed states. When the Ping offices were search on March 9, 2020, 130 customer shipping labels were found for statements being sent to unlicensed states. Just those customer's transactions were $4,000,000!

The laws in this area are United States Federal Code Title 18 Section 1956, the Anti-Money Laundering Law, and Title 18 Section 1960, the Prohibition of Unlicensed Money Transmitting Business Law. The first states that you may not process funds that you know or should know are derived from certain specified criminal activities. (There are 200 such illegal activities specified in the law.) It specifically states that you cannot allow yourself to be "Willfully blind" to the source of funds. Detailed guidance, often called "Know Your Customer" or KYC, is provided for how to recognize and report suspicious activities.

As examples of transactions from unlicensed states, Ping processed for residents of:
  • Nevada: $476,000
  • New Jersey: $234,000
  • Utah: $1,500,000
  • West Virginia: $507,000
  • Connecticut: $626,000

When a customer entered their street address at registration, Ping willfully chose to not include the City, State, or ZIP code in their records if the customer was not in a licensed location, storing only their street address.

Ping's Execs and Investors

Ping's Chief Operating Officer, Opeyemi Odeyale, was well aware of US banking law. Prior to Ping, Odeyale earned an MBA from Edinburgh School of Business and held jobs at Pricewaterhouse Coopers, JPMorgan Chase, Oceanic Capital, BNP Paribas, and Barclay's Bank.

During the time he was running Ping Express in the United States, he also served as a director in the British firm "PayZen Limited" from 25JUN2013 through 03DEC2020 (recall he was arrested in March 2020.) His fellow officers at PayZen included Adekanmi Olaolu Adedire and Anslem Oshionebo (Financial Consultant), his CEO at Ping. Notably, Payzen was originally incorporated as Fiem Ltd but changed its name on 10FEB2020. Texas records also indicate that Ping Express originally operated as Fiem Group, LLC, and bank accounts in the name of Fiem Group are on the Forfeitures list below! On 01FEB2017 Opeyemi Odeyale filed papers with Companies House indicated that his nationality had changed to "British." When the British company was first incorporated (as Clicks FX Limited), he had given his date of birth as 14FEB1979 and his nationality as Nigerian.

Ping's Chief Executive Officer, Anslem Oshionebo, began his career with an MBA from Seton Hall University's Stillman School of Business. His LinkedIn page says he worked at PriceWaterhouse Coopers for 14 years, working his way from Senior Associate to Manager, and then Senior Manager, at least partially in Los Angeles. He then worked at Riveron Consulting as a Principal in the Dallas/Fort Worth area before co-founding Ping Express in 2014. His Crunchbase profile says that his areas of practice at PWS included "Compliance regulations and financial forensics!" Anslem's domain "anslemoshionebo.net" has articles he has written on philanthropy and diversity, while his anslemoshionebo.medium.com page has articles about what books Entrepreneurs should read and a five part series called "Challeges of an Immigrant" (which were mostly written AFTER he was arrested!)

In April of 2017, Synergy Capital Managers, a Mauritius-based private equity firm, made an investment in Northstar Finance Services Limited, "a financial services platform providing solutions across the financial service value chain in select countries across West Africa." Northstar was said to be managed by Obafami Alonge and Bolanle Oduyale, In Synergy's announcement, Northstar's CEO said that with this investment the company now had a "majority stake" in Safetrust Nigeria, Northstar Home Finance, Avance Insurance, Ping Express Inc., and Fast Credit Limited. PWC, where Oshionebo worked for so long, was said to be the advisor to Synergy Capital "on Financials and Tax due diligence."

This comes to play in that if Ping had "foreign investors" they are required to disclose those.  When the Texas Director of Banking gave the license, they claimed to be based entirely in Texas.

Top Customer: Collins Orogun, Romance Scammer and Money Launderer

Collins Orogun, a Texas resident, paid Ping more than $800,000 which included $220,000 in wire transfers during a six-month period in 2019. Ping only reported $292,500 of these transmissions. (Collins was released from prison on 12MAR2020 for prior charges but has another sentencing hearing in October 2022 for the current charges.) In his guilty plea, Orogun admitted that he received funds from people "all across the United States" in forms including cash, money orders and checks. He then deposited those funds into his accounts, including at JPMorgan Chase, both in his true name and as "Collins Enterprise", at Navy Federal Credit Union, at Wells Fargo Bank, both in his true name and as Orogun Enterprises, and at BBVA.

His JPMC accounts received $120,000 in funds, which he sent out through Ping in 13 transactions. In another example, he received $26,500 "in currency and money orders" between November 29, 219 and December 31, 2019. He sent these funds out via Ping in six $5,000 transactions. In his Navy FCU account, he received $530,500 in "currency and money orders" and sent a wire transfer of $218,500 out. He also sent $192,600 via Ping in 68 transactions. His first Wells account received $87,171 in deposits, sending $65,610.56 of those out via Ping. His second Wells account received $157,578 in deposits, of which he sent $82,367 out via Ping. His BBVA account received $144,808 in deposits, of which $140,000 was sent out via Ping.

Some of his Romance Scam victims included:

$40,000 into BBVA that came from "D.M." a senior citizen in California who sent the money to facilitate the sale of an estate in Nigeria. He believed that he was helping to repair an estate which would be then sold for $570,000,000, and that he would receive a large repayment when the estate was sold.

"P.L" from Indiana believed her $6,309 was sent to "Thomas Ken" an Irish sea captain with whom she had a romantic online relationship. The funds were supposed to be used to repair his ship. She took out a title loan against her vehicle and wired the money to Orogun Enterprises. The captain immediately asked for more funds afterwards.

"D.N." a 59 year old in Indiana sent $2300 to the BBVA acount, believing that "Carson Steve Jacks" an oil roughneck working in the Gulf of Mexico needed the funds because he had contracted malaria and couldn't work. He later asked for an additional $15,000. The couple "fell in love" via Google Hangouts.

These three had all agreed to testify at trial, prior to Collins changing his plea to Guilty on June 28, 2022.

Additional Factors Violating Texas Department of Banking License

The Texas Department of Banking found many more reasons for considering revoking Ping's business license, including:
  • Ping stated that they had no "authorized delegates or agents" yet Nimerex claims to be Ping's agent and has Ping letterhead documentation appointing them as Ping's agent.
  • Ping claimed to have no foreign affiliates, but had received $160,000 from a Mauritius-based account in the name "Ping Express (Mauritius) Ltd." "for the benefit of Fiem Group LLC" and a $280,000 wire from a British account in the name Ping Express CM.
  • Ping claimed to be sending "small remittances" back to Nigeria, but had sent $1,600,000 in large round number wire transfers to business bank accounts in Nigeria (at First City Monument Bank and Wema) for "marketing" and "consulting" payments.
  • Ping received $49,000 in wire transfers from the company "Date2Marry LLC" and an individual connected with that LLC.

These details came out during a search of Olufenwi's phone as he returned to California from England. The phone also documented a five year "currency exchange partnership" between Ping and "Wilfobs Bureau De Exchange Limited" in Nigeria involving multiple foreign bank accounts for Ping. Ping had disclosed in previous reporting to the Texas Department of Banking that they had no bank accounts outside U.S. borders and thus were not required to file a Foreign Bank Account Report.

Chats on Odeyale's phone made it clear he was trying to avoid AML and Suspicious Activity detection as he received foreign funds. An example:

Forfeitures ordered by the Court

Forfeiture Notice:
  1. Approximately $10,601.52 in funds seized from the JPMorgan Chase Bank account with number ending in 2885 in the name of Collins Ogaga Orogun.
  2. Approximately $3,679.78 in funds seized from the JPMorgan Chase Bank account with number ending in 8900 in the name of Collins Ogaga Orogun dba Collins Enterprise.
  3. Approximately $42,873.96 in funds seized from the JPMorgan Chase Bank account with number ending in 1223 in the name of Ping Express LLC.
  4. Approximately $1,385.13 in funds seized from the JPMorgan Chase Bank account with number ending in 2686 in the name of Ping Express LLC.
  5. Approximately $13,269.69 in funds seized from the JPMorgan Chase Bank account with number ending in 5397 in the name of Crusaders Health and Wellness LLC.
  6. Approximately $3,010.72 in funds seized from the Navy Federal account with number ending in 2248 in the name of Collins O Orogun.
  7. Approximately $8,307.53 in funds seized from the Wells Fargo Bank account with number ending in 4593 in the name of Anslem Oshionebo.
  8. Approximately $369.82 in funds seized from the Wells Fargo Bank account with number ending in 4437 in the name of Blackbit LLC.
  9. Approximately $8,364.86 in funds seized from the Kasasa Tunes 0031 account at Neighborhood Credit Union for member number XXXX5691.
  10. Approximately $55,235.41 in funds seized from the Soho Business Checking account at Resource One Credit Union for member XXX1450 in the name of Fiem Group LLC.
  11. Approximately $37.40 in funds seized from the Bank of America account with number ending in 3918 in the name of Deyks LLC.
  12. Approximately $9.91 in funds seized from the Bank of America account with number ending in 3921 in the name of Deyks LLC.
  13. Approximately $14.15 in funds seized from the Bank of America account with number ending in 3947 in the name of Deyks LLC.
  14. Approximately $11.52 in funds seized from the Bank of America account with number ending in 3692 in the name of Deyks LLC.
  15. Approximately $29,198.23 in funds seized from the Capital One account with number ending in 2957 in the name of Aleoghena Okhumale.
  16. All funds seized from the account with number ending in 1891 at Silvergate Bank in the name of Wyre Payments Inc. deposited after February 19, 2020 from “5/3 BANKCARD SYS DEPOSIT; 5/3 BANKCARD; or WORLDPAY”. 
* - (Although Anslem was to surrender to be imprisoned on July 12, 2022, the Federal Bureau of Prisons Inmate Locator indicates he is not currently in custody.)

Friday, June 03, 2022

That Job Your Co-Worker Emailed You About? Yeah ... No.

My niece, Anna, is a school teacher in the Birmingham Public School system.

Another teacher in the system got phished and the phisher sent an email to a bunch of other teachers, offering them a summer job as an administrative assistant, earning $500 weekly for working only 8 hours.  Tempting?  

The email had a link to a Google Form with the job application.

The form goes on to ask her Full Name, Email: [Not School Email!], Alternative Email, and Phone Number, as well as Current Occupation, Age, Sex, and Available Time.

Why does it say "Not School Email!" -- because this exact scam is being conducted by phishing people in schools all across the country! 

Her new boss, Dr. Reinn, hit her up on text, from the phone number (904) 297-8521, got her resume, reviewed it, and offered her the job on the spot!

She got hired and was EMAILED a set of duties and responsibilities.

Her duties were basically:

  • DONATE to three foster homes a month
  • book TRAVEL ARRANGEMENTS for her boss and his associates 
  • manage RETURNS and errands such as shopping, POST OFFICE 
  • send birthday cards and GIFTS to clients, family, and friends

Her first assignment would be to make a donation to a local orphanage.  

So he emails her an IMAGE of a check that she was supposed to mobile deposit to herself and then send $4800 of the $4950 via ZELLE to a second scammer email: lookatthepudding@gmail.com


I'm not sure why she would think this check is not TOTALLY LEGITIMATE, right?  And why wouldn't donations to an orphanage be sent to someone's Zelle account named "Look At The Pudding?"

Clearly Anna's name and the amount have been laid on top of the check on another piece of paper and then photographed.  Who writes a check like that?  Oh!  Someone who has STOLEN a check and needs to re-use it but is too lazy or stupid to wash it properly.

She wisely did NOT deposit the check, which revealed that she knows this is a scam.  


Unfortunately, during the job application process she was required to provide referrals.  Now the scammer is calling and messaging her references asking for her whereabouts and claiming that she stole $4,950 from his company and he was trying to find her to have her arrested.  He also called her current employer at least three times.



Friday, March 25, 2022

Russia's Invasion of Ukraine and CISA/FBI's New Era of Transparency

BLUF: Bottom Line Up Front


I want to start this post with the most important thing right up top:

The CISA.gov/Shields-Up page starts with this statement.  PLEASE take it seriously, and escalate to your top management:

"Russia’s invasion of Ukraine could impact organizations both within and beyond the region, to include malicious cyber activity against the U.S. homeland, including as a response to the unprecedented economic costs imposed on Russia by the U.S. and our allies and partners. Evolving intelligence indicates that the Russian Government is exploring options for potential cyberattacks. Every organization—large and small—must be prepared to respond to disruptive cyber incidents. As the nation’s cyber defense agency, CISA stands ready to help organizations prepare for, respond to, and mitigate the impact of cyberattacks. When cyber incidents are reported quickly, we can use this information to render assistance and as warning to prevent other organizations and entities from falling victim to a similar attack."

Organizations should report anomalous cyber activity and/or cyber incidents 24/7 to report@cisa.gov or (888) 282-0870.


Second "Bottom Line Up Front" BLUF point:  CISA has released TTP's of Russian threat actors known to attack US Critical Infrastructure.  If you work there, skip this blog and go read their report first!
"Alert (AA22-083A):  Tactics, Techniques, and Procedures of Indicted State-Sponsored Russian Cyber Actors Targeting the Energy Sector."

CISA/FBI and the New Era of Transparency

 Anyone who has seen one of my presentations recently knows that I am a huge cheerleader for CISA.gov, the Cybersecurity & Infrastructure Security Agency at DHS, which replaced the National Protection and Programs Directorate (NPPD) that previously led private sector engagement and interaction for DHS.

Previously, I've asked people to make sure someone in their organizations was watching four critical information sharing pages at CISA.  


  • https://www.cisa.gov/uscert/ncas/current-activity
  • https://www.cisa.gov/uscert/ncas/alerts
  • https://www.cisa.gov/uscert/ncas/bulletins
  • https://www.cisa.gov/uscert/ncas/analysis-reports
I had already said publicly many times that they are doing a PHENOMENAL job of sharing information - unprecedented in my 22 years of working with the government on Critical Infrastructure Protection, from Ron Dick and the NIPC (National Infrastructure Protection Center), serving on the national boards of InfraGard and the Energy ISAC, and interacting with FS-ISAC (Financial Services), H-ISAC (Healthcare), and REN-ISAC (Research and Education).  But now CISA (and the FBI) has taken Information Sharing to a whole new level.

The White House on Russian Cyber Threats

It started with the White House.  On March 21st, President Biden stated that there was "evolving intelligence that the Russian Government is exploring options for potential cyberattacks." Based on this new intelligence, the administration gave the order that thing that were not previously shared needed to be shared at an even higher level of detail and specificity, including things that were previously deemed too sensitive to share in an unclassified environment. 

That same day, Press Secretary Jen Psaki brought in Anne Neuberger, the Deputy National Security Advisor over Cyber and Emerging Technologies.  She stated that in the past week, CISA and the FBI had held meetings with 100+ Critical Infrastructure Companies to determine a best course forward in helping to protect critical infrastructure, including encouraging them to participate in the CISA Shields-Up! program. 

  • Mandate the use of multi-factor authentication on your systems to make it harder for attackers to get onto your system;
  • Deploy modern security tools on your computers and devices to continuously look for and mitigate threats;
  • Check with your cybersecurity professionals to make sure that your systems are patched and protected against all known vulnerabilities, and change passwords across your networks so that previously stolen credentials are useless to malicious actors;
  • Back up your data and ensure you have offline backups beyond the reach of malicious actors;
  • Run exercises and drill your emergency plans so that you are prepared to respond quickly to minimize the impact of any attack;
  • Encrypt your data so it cannot be used if it is stolen;
  • Educate your employees to common tactics that attackers will use over email or through websites, and encourage them to report if their computers or phones have shown unusual behavior, such as unusual crashes or operating very slowly; and
  • Engage proactively with your local FBI field office or CISA Regional Office to establish relationships in advance of any cyber incidents. Please encourage your IT and Security leadership to visit the websites of CISA and the FBI where they will find technical information and other useful resources.
After this set of announcements, CISA.gov's director, Jen Easterly, convened a meeting that was attended by more than 13,000 Critical Infrastructure stakeholders from all across the United States, including every sector and every size. A recording of the CISA CALL WITH CRITICAL INFRASTRUCTURE PARTNERS ON POTENTIAL RUSSIAN CYBER ATTACKS AGAINST THE UNITED STATES has been shared on their YouTube page!

During the call, which included FBI Deputy Assistant Director for Cyber, Tonya Ugoretz, and CISA Deputy Executive Assistant Director for Cyber, Matt Hartman,  Director Easterly committed to push to have even more sensitive data released to the public if it would possibly help protect American Critical Infrastructure.  And today, we see a great example of that!

Documentation of Two Historical Hacking Campaigns Against Critical Infrastructure

The FBI and the Department of Justice released the legal side, in the form of an extremely detailed press release about Russian hacking campaigns targeting Critical Infrastructure at hundreds of companies in 135 countries.
https://www.justice.gov/opa/pr/four-russian-government-employees-charged-two-historical-hacking-campaigns-targeting-critical


The Press Release was accompanied by two indictments: 

The first, "USA v. Evgeny Viktorovich Gladkikh," (17-page indictment) details the origins, creation, and distribution of the "TRITON" malware.  This attack framework was described in great depth in December 2017 by Mandiant in their report "Attackers Deploy New ICS Attack Framework 'Triton' and Cause Operational Disruption to Critical Infrastructure." While Mandiant described the malware as "an attack framework built to interact with Triconex Safety Instrumented System controllers," they could only say they believed it was "activity consistent with a nation state preparing for an attack." 

Through the new transparency we are seeing, the full details of the indictment are now unsealed and we learn the attacks were conceived and executed from the Russian Ministry of Defense, Federal Service for Technical and Expert Control, in a lab known as the Applied Development Center, which was in turn part of TsNIIKhM, the State Research Center of the Russian Federation Central Scientific Research Institute of Chemistry and Mechanics.  

The second indictment, "USA v. Pavel Aleksandrovich Akulov, Mikhail Mikhailovich Gavrilov, and Marat Valeryevich Tyukov," (36 page indictment) is targeted at members of the Federal Security Service (FSB)'s "Military Unit 71330" also known as "Center 16." Members of this lab are better known by their flamboyant APT Designations:  Dragonfly, Berzerk Bear, Energetic Bear, and Crouching Yeti.  In particular, this indictment addresses their attacks in 2017 which attempted to target and compromise critical infrastructure and energy companies worldwide, including in the USA generally, and in Kansas in particular (the home office of the indictment.) 

Again, the new transparency shows us that these attacks, also known as Dragonfly, Havex, and Dragonfly 2.0, were supply chain attacks, where various ICS/SCADA system manufacturers had their software manipulated to include malicious backdoors which would be downloaded by unsuspecting customers. Through this campaign, at least 17,000 unique devices in the US and elsewhere were compromised, including ICS/SCADA controllers used by power and energy companies. In 2.0, malware was delivered via Spear-phishing attacks and Watering hole attacks targeting employees of such companies. At least 3,300 systems were compromised using this methodology as well. 

Some of the groups attacked in this way included the Nuclear Regulatory Commission, WolfCreek Nuclear Operation Corporation in Burlington, Kansas, Westar Energy, in Topeka, Kansas, and the Kansas Electric Power Cooperative. 

Again, Havex was known to the security community.  Trend Micro wrote about it in their report "HAVEX Targets Industrial Control Systems" back in July 2014, and in more detail in their white paper "Who's Really Attacking Your ICS Equipment?"  Dragonfly 2.0 was similarly discussed, for example by Symantec, in their report "Dragonfly: Western energy sector targeted by sophisticated attack group" in October 2017.  WIRED magazine also wrote about the group Berzerk Bear in October 2020 in their article "The Russian Hackers Playing Chekov's Gun with US Infrastructure." 

But now, in a coordinated Information Sharing To Protect Our Nation blitz, CISA, working with the FBI and the Department of Energy, have released "Alert (AA22-083A):  Tactics, Techniques, and Procedures of Indicted State-Sponsored Russian Cyber Actors Targeting the Energy Sector."

Tuesday, March 22, 2022

BEC Still #1, but Investment Fraud passes Romance Scams


https://www.ic3.gov/Media/PDF/AnnualReport/2021_IC3Report.pdf


The FBI's Internet Crime Complaint Center (ic3.gov) has released their 2021 Internet Crime Report.

The number of complaints increased by 7% to 847,376 from 2020 to 2021, however the reported losses increased by 64% year over year to $6.9 Billion!


For several years, the #1 Cybercrime type has been Business Email Compromise followed by the #2 of Romance Scam. But this year, we had a change!  The criminals have discovered how many people don't understand investing in cryptocurrency and have turned Investment Scams into a new money factory. 

#1 is still Business Email Compromise, but with only a 3% increase in victims, there was a 28% increase in reported financial losses.  That's an average loss of $120,000 per victim, compared to last year's $96,700 per victim. 

#2 dislodges Romance Scams by Investment Scams for the first time ever with a dramatic increase!  Investment Scams went from 8,788 complaints to 20,561 complaints, while losses increased 333% from $33.6 Million dollars to $1.45 Billion dollars!  THat's an average loss of $70,810 per victim, up from $38,287 per victim last year!

#3 Romance Scams was quite similar to 2020 in the number of complaints, however the amount of losses still increased by 59%.  In 2020, the average victim lost $25,272, but in 2021, the average victim lost $39,344.  And these victims tend to be senior citizens! 

Crime Type 2021 Losses2020 LossesChange in Loss2021 Victims2020 VictimsChange in Victims
BEC/EAC $2,395,953,296$1,866,642,10728%19954193693%
Investment $1,455,943,193$336,469,000333%205618788134%
Confidence Fraud/Romance $956,039,739$600,249,82159%24299237512%
Personal Data Breach $517,021,289$194,473,055165%518294533014%
Real Estate/Rental $350,328,166$213,196,08264%1157813638-15%
Tech Support $347,657,432$146,477,709137%239031542155%
Non-Payment/Non-Delivery $337,493,071$265,011,24927%82478108869-24%
Identity Theft $278,267,918$219,484,69927%516294333019%
Credit Card Fraud $172,998,385$129,820,79233%1675017614-5%
Corporate Data Breach $151,568,225$128,916,64818%12872794-54%
Government Impersonation $142,643,253$109,938,03030%1133512827-12%
Advanced Fee $98,694,137$83,215,40519%1103413020-15%
Civil Matter $85,049,939$24,915,958241%111896815%
Spoofing $82,169,806$216,513,728-62%1852228218-34%
Other $75,837,524$101,523,082-25%123461037219%
Lottery/Sweepstakes/Inheritance $71,289,089$61,111,31917%59918501-30%
Extortion $60,577,741$70,935,939-15%3936076741-49%
Ransomware $49,207,908$29,157,40569%3729247451%
Employment $47,231,023$62,314,015-24%1525316879-10%
Phishing/Vishing/Smishing/Pharming $44,213,707$54,241,075-18%32397224134234%
Overpayment $33,407,671$51,039,922-35%610810988-44%
IPR/Copyright and Counterfeit $16,365,011$5,910,617177%427042131%
Health Care Related $7,042,942$2,904,2515-76%5781383-58%
Malware/Scareware/Virus $5,596,889$6,904,054-19%8101423-43%
Terrorism/Threats of Violence $4,390,720$654,7449-33%1234620669-40%
Gambling $1,940,237$3,961,508-51%3953911%
Re-Shipping $631,466$3,095,265-80%516883-42%
Denial of Service/TDoS $217,981$512,127-57%11042018-45%
Crimes Against Children $198,950$660,044-70%21673202-32%

Investment Scam Examples

What does an Investment Scam look like?  The most common ones these days are promising a guaranteed rate of investment. Thousands of such Investment Scam sites have been created and most of them are being pushed on social media.  People who claim to be successful on the sites are often only trying to earn a commission by referring others to the site.

It only took a couple hours to find more than 500 live Investment Scam sites last month.  Many of these sites are still live today.


Many of the sites are unlikely to attract real investors because of how ridiculous their rates are.  No one believes that they can earn 50% per hour ... however this site promises that if you can trick your associates into investing, you'll get 5% of whatever they deposit.  This is quite common. 

Crypto-Trades[.]uk 

A more believable site promises a much lower rate, such as 3% per day for investments up to $4,999 dollars.  If the site owners believe they have a big fish, they may actually PAY the 3% for a small investment, using that as proof that the system works in order to lure a larger investment.  This site, and many like it, then offer 6% daily profits for investments of at least $5,000, or 9% daily profits for investments of at least $30,000. 


The site pictured above claims to be "Crypto-Trades[.]uk" and offers proof of their legitimacy by providing a link to their "Certificate of Registration."

Crypto-Trades dot UK
claiming to be the British Corporation, "Crypto Ltd" which is a real company, just not them. 


They are regularly abused in that way.  CryptSparkFX[.]com, Crypto-binary[.]com, CryptoTrust[.]ltd, CryptoAlphas[.]uk, CryptoHive[.]uk, Webull-Investments[.]com, ExploreFX[.]uk, Crypto-Gain[.]ltd, Slushpool-investment[.]com, Intrex-invest[.]com, and FedelityFunds-Crypto[.]com are some of the other Investment Scam sites that use their address, hoping to gain credibility from it. 

Intrex-Invest[.]com

FedelityFunds-Crypto[.]com

Slushpool-investment[.]com

CryptoHive[.]uk

A True Victim Story

A successful businessman in my area came to me to ask for help.  He had originally joined a group such as those above called CryptoHood[.]io which later became CryptoHood[.]co.  He invested a small five figure number on their site, and got scammed, losing it all.  When he was complaining about being scammed, someone in a Facebook investment group let him know they too had been scammed by those people.  But good news!  He had found a legitimate company that really paid out!  EasonFXPro[.]com! Because he had been burned already, he put in a smaller investment this time.  $2,500.  An amount that this CEO "could afford to lose."

The scammers let him know that because he was a VIP investor, they were going to let him use their "special" app, so that he could watch his trades in real time.  The theory was that their advanced Artificial Intelligence was doing Bitcoin trading to make amazing profits.  The app they used was in the Google Play store ... but the VIP version was only available via their special URL.  They convinced him to download the app from "blockchain.en.uptodown[.]com/android/download/2264221." That was his "personalized" version.  He was truly amazed by the bot, and could enter "his" bitcoin address into any blockchain explorer to see his earnings.  (We checked the address, and it was doing HUGE volumes of small transactions ... it just wasn't his wallet.   He was led to believe that the transactions were "the AI doing trades" for him.  Within a couple months, his bitcoin address had funds worth nearly $250,000!  So he decided to cash out.

In order to cash out, he just had to pay them a "Sigma Fee" of 10%.  He refused ($25,000!?!?!?!) 
They then offered to let him withdraw just $50,000, for a Sigma Fee of only $5,000.
He was harassed on the phone for a while by "Elizabeth Frances" and "Evelyn" and "Mark Gerrard" and "Steven Williams" but chose to file an IC3.gov report about his experiences and walk away from Crypto Investments for a while.

The Appeal of Easy Money

With 1100 "likes" it must be real, right?

And they provide screenshots as proof that they are really getting paid!  So, it's guaranteed, right?



Monday, March 21, 2022

Chinese Call Center "Runner" Pleads Guilty in Georgia

This week the Department of Justice received a guilty plea from Jianjie Liu, a Chinese citizen living in Texas. 

https://www.justice.gov/usao-ndga/pr/chinese-national-pleads-guilty-money-laundering-scheme

In Call Center Frauds, there are many roles to be played.  One of these roles is often referred to as "Runner." When people in other countries are the ones running the phones and Facebook accounts used in fraud, they often need someone in the United States to pick up packages and open bank accounts.  From that perspective, Liu was a Runner.

The case began when Liu was arrested at a Walmart in Duluth, Georgia after attempting to purchase "a suspicious number of gift cards."  During that arrest, her 2016 black Nissan Altima was searched, and was found to have 718 gift cards, mostly WalMart, Vanilla Mastercard, and American Express gift cards. he also had a deposit slip showing that she controlled a JP Morgan Chase Bank account ending in #5887. The bank account was tied to her business license in Gwinnett County, Georgia fro "A&J Commercial Services" which used an address at 16634 Roseglade Drive, Cypress, TX 77429. 

The 16,000 images on her phone were reviewed, and found to contain many images of gift cards along with their accompanying purchase receipts. 

From May 30, 2019 until September 30, 2019, Liu deposited at least $70,400 into her Chase account from elderly fraud victims.  Those funds were all seized by the U.S. Secret Service, however there were many other victims and victim types described in the court records:


In a "Government Grant Scam" an elderly "J.B." received a message from a Facebook friend, who told him about a $150,000 government grant he could receive.  He sent $2,500 cash to an address in Heath, Ohio; 4,000 to an address in Atlanta, Georgia; $4,500 to an address in Newark, New Jersey, and was later instructed to purchase gift cards at a Walmart in Washington and message them to "Agent Walter" (which were then forwarded to Liu, who used those cards to purchase OTHER gift cards!)

In an "Inheritance Scam" a woman using a Facebook account in the name "Fola V. Williams Fly" asked a 64-year old man from Cheyenne, Wyoming to help her receive a multi-million dollar inheritance by paying various fees.  He sent two cashier's checks for $10,000 each payable to Jianjie Liu at the address 3182 Steve Reynolds Blvd, #105, Duluth, GA 30096. 

In a "Computer Support Scam" someone claiming to be "Allen Johnson" from Microsoft took control of a victim's computer, claiming he needed remote access to her bank account to process a $300 refund.  Instead he pretended to deposit $3,000, claiming it was in error.  He then asked the victim to refund $2,600 of the erroneous funds, by sending three money orders to Liu in Duluth, Georgia. 

An identical process was used by someone claiming to refund $555, but "accidentally" depositing $20,555 instead.  The victim, an 89-year old priest in St. Paul, Minnesota, sent the "accidental" $20,000 via cashier's check to Joy Liu, A&J Commercial Services, 3182 Steve Reynolds Blvd, Duluth, GA.

In a "Grandparent Scam" "Sergeant Jonathan Parker" called one of the elderly victims claiming their teenaged grandson had been arrested for assaulting a police officer and was required to post $9,000 bail.  He sent a box with $9,000 cash in it to an address in Las Vegas, Nevada.  Days later, Sergeant Parker demanded an additional $15,000 to settle the matter out of court.  He again sent a box of cash to Las Vegas.  Then he was asked to send $5,000 to pay the medical bills of "Officer Joyce Phillips" and this time sent a personal check to "Joyce Phillips" of A&J Commercial Services, 3182 Steve Reynolds Boulevard, Duluth, GA 30096. 

In a "Compromised SSN Scam" another elderly victim was told he was being investigated by the IRS, and that during the investigation, to protect his funds, he needed to convert all of his cash to Gift Cards, which would be held in escrow pending the results of the investigation.  These gift cards were used by Liu to purchase the gift cards in the Walmart in Duluth, Georgia. 

Liu posted $10,000 bail, and shockingly, failed to appear in court again.  

She was re-arrested in Pearland, Texas on 06JAN2021 for theft, where it was discovered that she had an outstanding warrant.

Saturday, December 04, 2021

Online Shopping Reminder: If It Looks Too Good To Be True ...

As we look towards the Christmas holiday, 'tis the season for freaking out and making poor decisions with regards to online shopping. Tonight a friend reached out to get my help in convincing his family that an incredible laptop sale they saw on laptop was not real.
That's the ad they saw on Facebook.  "Due to special reasons" the company has decided to "sell the last batch of laptops." If you click the Shop Now button, it takes you to the website "maxwellplaceonhudson[.]com"



Now, I'm not saying that everyone who re-uses an image is a scammer, but John J. Rogers and MaxwellPlaceHudson are using a photo from a 2019 Mainichi News article in Japan about the fact that computers were piling up in warehouses in China.  Doesn't that look familiar?  

https://mainichi.jp/english/articles/20191223/p2g/00m/0bu/050000c

John J. Rogers is being an extremely helpful and interactive salesperson as people are asking him how long it takes to ship the laptops.  He's giving recommendations on which model to order, and estimates on shipping time.




But How Do We Know It's Real?  ... Testimonials!

Just look at all the happy customers! "Sdhuy Fhabn" says "This is a quality built and spec'd laptop! Very satisfied!"
Strange that all of the comments on Sdhuy's page are in Filipino.  Even stranger? Someone named Tonie Pomintel thanked the computer seller "Memasabe" for a laptop using exactly the same words!

Mandy also loves his new laptop.  "Mine has arrived, this is an unexpected laptop, it even has a touch screen, I like it very much!" he gushes.

Mandy lives in Quezon City, Philippines, which does make it seem odd that he would be mail-ordering a laptop from New Jersey.  Even stranger?  "Ams Minang" shared exactly the same image to thank "Memasabe" for her new laptop!



MD tells us "So far so good, works great, looks great!" 
But then, for MD, people who look like John J. Rogers are kind of "his type."
I'm sure that Mandy and Sdhuy are fine people.  But let me tell you friends, MD, he's a Scammer!
MD Sajjad is a fake account that is giving a fake testimonial.

Take a look at his Facebook "Likes" -- 

He likes John J. Rogers, Noah Robert, Oliver Noah, Sean M Hemming, Debra Carter, Gerry R Frederickson, George S Krebs, and RiodiJanero ... who surprisingly all have the same two profile pictures!

Romance Scam and Online Fraud expert "FireFly" at www.scamsurvivors.com let us know that one of these men is the model "Michael Justin."  The profile picture is swiped from a 16MAY2019 post by Instagram user @themichaeljustin: 
https://www.instagram.com/p/Bxizn4iFWXy/ (@themichaeljustin)

The other primary profile picture is from a photo sales site and is entitled "businessman with laptop thinking at night office." 
https://photodune.net/item/businessman-with-laptop-thinking-at-night-office/20174205



Let's look at what else they have in common!


Noah Robert is a "Computer Company" ... oh gee! On November 25th "due to special reasons" he starting selling computers from his website "ajakubowski[.]com"

You may be surprised to know that ajakubowski's website is IDENTICAL to  MaxwellPlaceHudson's website!

His telephone number is in Afghanistan. (+93 is international dialing code for Afghanistan.)

Email ioiw7nkrvs@claimab.com

https://www.facebook.com/Noah-Robert-103879551585935/

Oliver Noah is a Computer Company. You'll never guess! Due to Special Reasons, he's selling the last batch of his laptops! 

His website, "utoal[.]com" strangely looks EXACTLY like John's website!

Sort of odd that he has an Afghanistan telephone number (+93)

Email n7x1z325fk@thrubay.com

https://www.facebook.com/Oliver-Noah-100751858389405/

Sean M Hemming is a Computer Company . Guess what! Due to Special Reasons, he's selling the last batch of his laptops! 

He has an Afghanistan telephone number and his website is MarbleTownGreen[.]com. (But it's closed down now.)

https://www.facebook.com/Sean-M-Hemming-769171696455694/

Facebook tells us the Page Manager location is Bangladesh


Debra G. Carter is a Computer Company. Guess what! Due to Special Reasons, he's selling the last batch of his laptops. He has a +93 Afghani telephone number and his website is "teamlse[.]com"

https://www.facebook.com/Debra-G-Carter-746064202423878/

Facebook tells us the Page Managers are in Indonesia, Liberia, Saint Vincent, and the Grenadines.


You might already be able to guess on this next one.

Gerry R Fredericksen is a Computer Company. 

Due to Special Reasons, he's selling the last batch of his laptops. 

He has a +93 Afghani telephone number and 

His website is "legeb[.]com" is currently disabled.

https://www.facebook.com/Gerry-R-Fredericksen-104079251980543/


George S Krebs is a Computer Company. 

Due to Special Reasons, he's selling the last batch of his laptops. 

His email is "esi01uo8d15@claimab.com" 

His website is "highlyacceleratedstresstest[.]com" is offline.

https://www.facebook.com/wo.kya.hoti/


RiodiJanero is a Computer Company. 

Due to Special Reasons, he's selling the last batch of his laptops.

His email is xdwdseiwb6@linshiyouxiang.net

His website is PineappleHillDesigns[.]com is offline.

He has a +93 Afghani telephone number.




So, getting back to the original question:  

Actually, I'm thinking that you may not really be able to buy a $2,600 laptop for $79 and have it delivered anywhere in the world in time for Christmas.  But then, my friends all tell me that I'm paranoid.

And there's so many more ... 

 
another Fake testimonial account: https://www.facebook.com/ams.minang.5/likes 

https://www.facebook.com/antonia.pomintel.5/likes_all

  • Helen Z Picket
    • https://www.facebook.com/Helen-Z-Pickett-111752013985708/
    • http://andaluciapropertyservices.com/
    • (216) 755-9391
  • Jackie K Freund
    • https://www.facebook.com/Jackie-K-Freund-448774108917513/
    • http://affordablegreensystems.com/
  • Andrew H Doyle
    • https://www.facebook.com/Andrew-H-Doyle-105266824762892/
    • http://affordablegreensystems.com/
    • +93212-307-8110
  • Memasabe
    • https://www.facebook.com/Memasabe-103806308164677/
    • http://snvpL.com/
    • +93803-520-1898
  • Fernando
    • https://www.facebook.com/Fernando-1894457434202054/
    • http://caughtfromabove.com/
    • 6trmfvuo2sh@thrubay.com
    • +93704-927-4239
  • Anne P Dudley
    • https://www.facebook.com/Anne-P-Dudley-141541912968147/
    • http://fricade.com/
    • y38msxh8zps@claimab.com
  • Dean B Vigil
    • https://www.facebook.com/Dean-B-Vigil-116775383783140/
    • http://fmpcms.com/ (live) 
    • +93816-539-3967
    • shhk60jhpng@claimab.com
  • A Addawd
    • https://www.facebook.com/A-addawd-100571795787651/
    • http://schoolbackpackstore.com/ (live) 
  • Criative
    • https://www.facebook.com/criativcalcad/
    • http://fourteenkaratomaha.com/
    • 5c992xqncjc@thrubay.com
  • My House 
    • https://www.facebook.com/My-House-100743925704289/
    • https://konamitech.com/ nbsp;(live) 
    • +213717-630-6321
    • gv2q360p9q@claimab.com
  • Helen T Lewis
    • https://www.facebook.com/Hector-T-Lewis-106551108311154
    • http://stevestoyboxny.com/
    • +93304-763-9483
    • ftxwy0rlela@linshiyouxiang.net
  • Leonia D Hill
    • https://www.facebook.com/Leonia-D-Hill-107212691802456/
    • https://chealyjean.com/
    • +93361-299-6243
    • ioiw7rnkrvs@claimab.com
  • Kermit
    • https://www.facebook.com/Kermit-119766538090600/
    • http://certificadoscolombia.com/
And the network is even bigger, because they also have female fake store owners selling Mobile Phones: