Monday, March 25, 2013

Email fraud: Avoid getting scammed when you’re online

Many people believe that fraudulent schemes are isolated incidents that could never happen to them. But if you’ve read Will Ferguson’s 2012 Giller prize-winning book 419 about Nigeria’s Internet scams you’ll know better.
 
Cons intended to separate you from your money are big business. The Better Business Bureau and partner organizations investigate thousands of scams every year, from the latest gimmicks to schemes as old as the hills. So does the Canadian Anti-Fraud Centre, a joint operation of the Royal Canadian Mounted Police, the Ontario Provincial Police and the Competition Bureau.
The agency collects information and criminal intelligence on “mass marketing fraud” aimed at multiple victims.
 
In the first six months of 2012 the CAFC received almost 21,000 complaints of mass marketing fraud with losses of over $30 million. Another 11,500 claims related to identity fraud/identity theft and cost victims $7.5 million. “These calls represent only about 5 per cent of the people who have been duped,” says Det. Con. John Schultz who is part of the CAFC team.
 
The BBb has compiled it lists of the biggest scams of the year, showing that something that seems good may not live up to its promises.
 
1. Top advertising scam: If you place an ad on a free site like Craigslist to sell your car, you may receive a call from unlicensed telemarketers offering to help sell your car. If you accept their offer, you will pay a fee of about $500 for posting to online classifieds you can post yourself at no charge.
 
2. Top love scam: You meet someone through a social networking or dating site who turns out to be from a faraway place. They fall in love with you in a very short time. The person gains your trust and asks for money to travel or help with a family emergency. Victims usually send money through wire transfer.
 
3. Top financial scam: Here the person earns the trust of an influential member of a group, family or workplace to use this connection to get their hands on their money. The investment is a fraud, you lose your money and your relationships could be irreparably harmed.
 
4. Top online scam: Online financial fraudsters send e-mail spam or they approach you on a social media website or a web forum. The target is consumers who go online for financial advice. Some spam will lead to an internet ad, designed to gather your personal information. A fraudster will later approach you directly about the phony investment.
 
5. Top sales scam: “Curbers,” buy old or damaged cars and sell them from parking lots or curbsides, advertising in newspapers and online ads. The buyer is out-of-pocket after realizing the vehicle has a long history of damages, a lien against it or the odometer has been rolled back. In some cases the vehicle may be stolen.
 
6. Top youth scam: You receive a text message that invites you to participate in a contest for a great prize. The target is smart-phone users with web-browsing capabilities. You are asked to enter the PIN and later an email address with a link to another site to apply for a credit card. In the end you never receive a credit card and have given out personal information.
 
7. Top computer scam: Consumers receive a call with a warning that your computer has been infected with a virus. Then an offer is made to clean your computer for a fee. The target is homeowners who have a computer with an internet connection. The result is that the scammer gets remote access to your computer and will also ask for credit card information for payment.
 
8. Top business scam: The business receives an invoice that appears to be past due, when in reality your company has had no dealings with the business listed on the invoice. The target is business owners and busy employees handling accounts payable. The result is that businesses pay a fake invoice or receive more threatening letters about the credit consequences of non-payment.
9. Top home improvement scam: Rogue door to door contractors will come to your home to seal or repave your driveway or fix your roof with product left over from another job. In some cases they offer a furnace repair that wasn’t requested or a free “inspection.” Targeted home owners are then out-of-pocket for unnecessary work or a poor job that has to be redone
 
10. Scam of the year: An email that mentions the Better Business Bureau and says something like “Complaint against your business.” You are asked to either click on a link or open an attachment. If you click on the attachment, you may download a malware virus.
 
How can you recognize a scam?
The CAFC says if it sounds too good to be true, it probably is. For example, you’ve won a big prize in a contest that you don’t recall entering. You are offered a once-in-a-lifetime investment that offers a huge return. You are told that you can buy into a lottery ticket pool that cannot lose.
 
They also suggest that you watch for these warning signs if you suspect that a relative or friend is being targeted by unscrupulous telemarketers.
 
A marked increase in the amount of mail with too-good-to-be-true offers.
Frequent calls offering get-rich-quick schemes or valuable awards, or numerous calls for donations to unfamiliar charities.
 
A sudden inability to pay normal bills.
Requests for loans or cash.
Banking records that show cheques or withdrawals made to unfamiliar companies.
Secretive behaviour regarding phone calls.

Friday, November 9, 2012

Ransomware Scams Netting Criminals Up To $33,000 a Day


Ransomware pays. A lot. These extortion scams, in which infected computers are essentially locked down by malware and electronic payment is demanded for a supposed cure, can net the criminal behind the scam as much as $33,000 per day.
Symantec studied 16 variants of independently developed ransomware over the last two years and found the potential for stunning profits and a surprising willingness on the victim’s behalf to pay up. While these schemes had been limited initially to Russia and the rest of Eastern Europe, more of it has been discovered in the United States and Canada.

“Given the number of different gangs operating ransomware scams, a conservative estimate is that over $5 million dollars a year is being extorted from victims,” wrote Symantec researchers Gavin O’Gorman and Geoff McDonald in a report “Ransomware: A Growing Menace.” “The real number is, however, likely much higher. From just a few small groups experimenting with this fraud, several organized gangs are now taking this scheme to a professional level and the number of compromised computers has increased.”

The most common ransomware involves malware that disables a computer and puts up a banner claiming to be from local law enforcement. The malware determines the geo-location where it has been downloaded and customizes the law enforcement message accordingly. For example, infected computers in the U.S. will display a message purporting to be from the FBI. The scam claims the user has viewed or downloaded copyrighted or illicit material and must pay a fine in order to have their computer restored, or face arrest.

Victims were required to pay their “fines” via a prepaid electronic payment system that required them to purchase a special PIN from vendors such as Moneypak, Paysafecard or Ukash; that valid PIN is the fraudster’s ultimate target.
Users are infected most commonly via drive-by downloads where popular websites are infected with a malicious advertisement or iFrame connecting to the criminal gang. Most of these scams target pornographic websites, Symantec said, and the ransomware locks the victim’s computer and puts up a message about viewing prohibited images. Payment of $200 is required within 72 hours, the scam demands. The criminal is counting on the victim to pay up to avoid the embarrassment of being caught viewing pornography, Symantec said.

“This payment PIN will then be sent by the ransomware to a C&C server where the attackers can retrieve it,” the Symantec report said. “At this point, the attackers should honor their promise and send a command to the ransomware telling it to uninstall itself. Unfortunately, this rarely happens. In actuality, many of the ransomware variants do not even contain the code to uninstall themselves.”
The victim must have his computer cleaned of the infection. The criminal, meanwhile, launders the stolen PIN, either trading it in an online forum, or using it to gamble online or buy exploit packs, Symantec said.

The profit potential is noteworthy. Symantec watched one particular variant of the Ransomlock Trojan from September through October and saw 68,000 unique IP addresses connecting to the command and control server; 5,700 in one particularly busy day. Of the 5,700, 168 PINs were entered resulting in $33,600 in revenue, a 2.9 percent turnover—that’s almost $400,000 in one month.

“This recent increase in variants may be related to established online criminals branching out into ransomware from other scams,” Symantec said.
In August, the FBI warned of a similar scam involving the Reveton malware, which was related to the Citadel banking Trojan. Reveton included a fake FBI warning that the victim’s IP had been linked to child pornography. The FBI said some people paid up and still required help removing the malware, which in some cases also included a keylogger.

Wednesday, October 31, 2012

What Columbo Can Teach Us about Internal Investigations


When conducting investigation interviews, take a hint from Lieutenant Columbo, who always got to the bottom of things, even when the odds were stacked against him. His humble, conversational style of questioning put his subjects at ease and enticed more than a few people to spill the beans.

One of Columbo’s signature tactics was his slow and measured way of engaging the subject and building rapport with questions that would “help him to understand” the case. His frequent “oh, and just one more thing” questions as he was leaving a room often pinpointed the very fact on which the case hinged.

Expert investigator and member of the ASIS Investigations Council, Timothy Reddick, CPP, PCI, CFE, likes Columbo’s approach to questioning suspects. He gives the “help me understand” tactic as a fine example of how to draw information from a witness or suspect. Reddick, who was director of fraud and special investigations for the city of Philadelphia before he retired, has many years of interviewing experience from which to draw his conclusions about successful approaches to evidence-gathering.

Never Accuse

The Columbo approach, says Reddick, is friendly and non-confrontational, almost apologetic. “Sorry I have to ask this,” Columbo used to say, eliciting a sympathetic reaction and often an honest answer from the subject.

You need to establish rapport, explains Reddick. “Act like you believe them,” he advises. “That’s how you develop rapport.” Instead of questioning something you don’t believe, ask for clarification. Again, it’s the “help me understand” approach that Columbo used so successfully, never taking on an accusatory tone.
The non-confrontational interview will get you to the truth more often than other methods. Being friendly, establishing rapport and stressing that you are just trying to help to clarify things, is an effective tactic, says Reddick.

Othello’s Error

Another very good reason to give the impression you believe your subject, even if you don’t, is to reduce your chances of committing what is known as “Othello’s Error”, a phrase coined by Paul Ekman in his 1985 book, Telling Lies. According to Ekman, this error occurs when a suspicious observer discounts cues of truthfulness, given the observer’s need to confirm his or her suspicions of deception. The “lie catcher” fails to consider that a truthful person who is under stress may appear to be lying.

“If someone perceives that you don’t believe them or you accuse them of lying, then sometimes their behavior adapters will be the same as someone who is being deceptive. So behavior adapters then become unreliable,” says Reddick. By giving the subject the impression that you believe him or her and using a non-confrontational approach, you can reduce his or her stress level and be better positioned to read any signs of deception.

Unfortunately, sometimes people have the perception you don’t believe them even when you are being non-confrontational. In these cases you have to remember that those adaptors may be unreliable, says Reddick.

Don’t Assume

“If you think you know whether or not they are lying, you are going to be deceived at times,” says Reddick, citing the many myths people rely on to detect deception, including the myth that a subject who avoids eye contact is being deceptive.

“I spent 15 years overseas and there are a lot of cultures that avoid eye contact whatsoever, because looking you straight in the eye is aggressive. And even here, there are lots of people who are very good at deceiving who know the eye contact ‘tell’ and intentionally use it to deceive,” he says.

So if you really want a subject to tell you what you need to know, take a lesson from Columbo. Go into the conversation with an open mind and get the subject to help you “understand”, to “clarify things” for you, and to enlighten you about “just one more thing”.

Saturday, October 27, 2012

Computer users warned of ‘Ransomware’ scam

Authorities are warning the public about a cyber scam that locks users out of their computers and attempts to scare them into paying a “ransom” to regain control.

Ransomware is a type of malicious software, or malware, that freezes the computer and activates a pop-up message demanding that the user pay a fee or fine to unlock their computer.

Some of the pop-ups use police logos and claim to be from the RCMP, CSIS or other law enforcement agencies, with messages warning users their computers have been associated with child pornography or illegal music downloading, according to the Canadian Anti-Fraud Centre.

“These types of messages are scams designed to create shock and anxiety so that victims respond by sending money quickly,” the centre said in their website.

Acting Sgt. Kathy Macdonald with the Calgary Police Service’s crime prevention unit said the police would never communicate with the public in that manner.“They would never ask for fines to be paid in that way. That’s not how police organizations work,” she said. People may fall victim to the Ransomware scam by clicking on links or opening phishing e-mails, she added.

The scam has been around since 2006, hitting Europe hard, then making its way to Australia, the U.S., and finally Canada, said Daniel Williams with the Canadian Anti-Fraud Centre.

Since March, the centre has received 10 reports out of Calgary, including one who paid the $100 “ransom” via Ukash, an online payment service provider, he said. In the most recent case Oct. 19, the scammers used the name “Cybercrime Investigation Department of Calgary,” he added.

In Lethbridge, about half a dozen calls were made to police in the past few months, said Const. Kevin Althouse with the Lethbridge Regional Police Service’s economic crimes section.
Williams said victims might be reluctant to report the scam for fear they’ve been looking at or doing the wrong things online and don’t want to be caught.

Police are warning victims not to send money, to contact a computer technician to repair the virus or malware, and to report the incident to the Canadian Anti-Fraud Centre at www.antifraudcentre.ca or 1-888-495-8501.

Computer users are urged to protect their machines by installing software updates, backing up their data and using a firewall, antivirus or spyware program.


Read more: http://www.calgaryherald.com/Computer+users+warned+Ransomware+scam/7448425/story.html#ixzz2AVy0UMYF

Thursday, October 18, 2012

A Message From a Former Student

I wanted to inform you that I have become a victim of a scam that has been going around, the last couple of days, and thought I would inform you of it, as many of your students are probably paying off or will be paying off student loans.

Please be aware of any company that calls from Tricura Canada, they will call and inform the former/current student that they are calling on behalf of the Student Loan Centre, and that it is important that you call them back, and that there hours are from 7:30am to 11pm in your region (They never specify the region). That centre would have to be open 24hrs.

This is the number that they leave 1-866-788-0288, and after doing research on the internet, there are blogs/forums stating not to call this number and that it's all a scam.

I haven't had any student loans in over 10yrs, and this made me very suspicious of their credibility and authenticity. They got my number through my brother in-law, which they got from the phone book. I wasn't even married when I went to college at that time, so I was still under my maiden name. It was a fluke that they just so happened to pick my brother in-laws name, as he would be listed first as his first name starts with an A, and who knows how many others they tried.

If your students have a student loan the only people that should be contacting them is their financial institutions, or the government department, National Student Loans Services Centre (Canlearn).
If they get a call from Tricura Canada, or any other company that is suspicious, please have them contact Toll free:1 888 815-4514 (within North America) and speak to someone from the National Students Loans Services Centre. I have also provided you with their link. https://nslsc.canlearn.ca/eng/contactus.aspx

Please remind to never give out any personal information over the phone, even if it's their bank, unless they call them back themselves. If the person that called them hesitates in give the students the number so that they may call them back, they should be suspicious. If the number is not familiar to the financial institutions that they could get of the site, they should be suspicious. The safest action for your students to do is to call the direct line to the company and ask to speak to the manager and confirm if it was an legitimate call from their company.

 

Wednesday, October 17, 2012

What Was The Internet Originally Called?

In April of 1963 computer scientist J. Licklider published a memorandum on the topic of remotely networked computers entitled “MEMORANDUM FOR: Members and Affiliates of the Intergalactic Computer Network”.

The memo is the first evidence of computer scientists moving towards establishing a geographically distributed network of computers resembling the modern Internet and, for a time, the “intergalactic computer network” nomenclature stuck.

The title fell out of popularity with the introduction of the Advanced Research Projects Agency’s ARPANET in 1969. The term “Internet” to refer to a large network of remote computers would not be put into use until an appearance in a 1974 paper by Vint Cerf and Bob Kahn and wouldn’t be popularized until the early 1990s.

Sunday, October 14, 2012

MP REPORT: Ottawa targets fraud

Canada is a generous country to those wanting to immigrate and call Canada their home. Unfortunately, our generosity has been abused by some who have made false claims regarding residency and false statements on their application form.
Minister Jason Kenney has announced that our government is investigating residence fraud with nearly 11,000 individuals potentially implicated in applying for citizenship or maintaining permanent resident status illegitimately.

The minister also announced that the government has begun the process of revoking the citizenship of up to 3,100 citizens who obtained it fraudulently.

In most cases, suspects will use deceitful immigration representatives to fraudulently create evidence of living in Canada while actually living overseas.

This deception is created so that individuals can fraudulently maintain their permanent residence status and later apply for citizenship.

This fraud hurts all Canadians.Those who illegitimately obtain permanent residence or citizenship status have access to taxpayer subsidized education, health care, and other social benefits without ever contributing as a taxpayer themselves.

It also hurts the majority of immigrants who come to Canada, who follow the rules with honesty and integrity.

Minister Kenney has said “Canadian citizenship is not for sale.”

Since the immigration fraud crackdown was launched, 600 former permanent residents have either been removed or denied admittance to Canada.

Another 500 permanent residents have had their citizenship applications denied.

The minister encourages anyone who has information regarding citizenship fraud to call our tip line at 1-888-242-2100, or via email at mailto:Citizenship-fraud-tips@cic.gc.ca

Your government promised to clean-up the abuses of our immigration policies. A promise made. A promise kept.