Current Status

This blog is not frequently updated because most case-by-case scam reports are now listed in subordinate blogs. At this point in time, most of my efforts are targeted at documenting employment scams in the Suckers Wanted blog.
Showing posts with label Info. Show all posts
Showing posts with label Info. Show all posts

2006-11-28

Info: 419s and Lottery Scams Galore

Last month I considered the drop in the number of 419s and Lottery Scams arriving. Apparently it was a seasonal dip, rather than a trend: this month those crazy Nigerians and their brothers-in-scams have been making up for lost time. The month of November, 2006, is the worst month on record here at iDeceive for 419s and Lottery Scams by a long margin -- doubling the quantity over the worst previous month. I'm having a hard time keeping up with the inflow at the moment.

2006-11-23

Info: Job Scammers go .mobi

Dubious congratulations are in order for the new ".mobi" top-level domain name: they're now officially being used by job scammers. The Athens Financial Group job scam now includes the "afgl.mobi" domain as part of the scam. This top-level domain is intended for websites which are optimised for mobile devices, but our pet scammers are just using it as yet another name in their efforts to be a moving target: the website behind the name is the same old same old.

2006-10-26

Info: Israeli Brokerage Services shift tactics AGAIN

You just can't keep a determined spammer down, can you? In their on-going efforts to steal your money, the Israeli Brokerage scammers have not only started using yet another domain name, but they've given up their cherished tactic of putting all their text in graphic images. Well, I don't expect that they've given up on graphics, strictly speaking, but they've diversified into plain text. Anyhow, here's the text (including the new Hong Kong based web address), since it's a simple copy and paste job.

Hello! I am Tal Alkobi, manager of a Human Recourses department and I work in Israeli Brokerage services Ltd This letter is aimed at attracting Your attention to a vacant post of financial manager for cooperation with private individuals. But first I would like to tell You about the company. Israeli Brokerage services Ltd was established in 1994 to render assistance to our clients in selling, buying, privatization, arranging deals and brokering at stock exchange. We can put into practice any operation that our client wishes. To reach it, we possess a large choice of investment instruments. Owing to the high professional standard of our specialist, we attract a lot of clients so our company is the leading company of this kind in Europe. And we continue to grow! And now we want to offer You the next: - to join our work collective - to become one of high qualified specialists - to get a prestigious part time job - to raise more IT IS NOT NECESSARY FOR YOU TO HAVE ANY HIGHER OR PROFESSIONAL EDUCATION to get this job. The only requests are: - You must have several free hours a day - have a bank account or a possibility to open a new one - have a computer YOUR MAIN TASK CONSIST IN ensuring us the possibility to provide the best service for our clients in short terms. YOUR DUTIES will be the next: - to receive payments for the ordered securities from our clients to Your bank account - to withdraw the funds and to transfer it further to our brokers in other countries You should use Western Union or money Gram services for these transfers. Your PAY amounts 9% commission out of every deposit that You receive on Your bank account. If you are interested, please visit our site: http://ibsl.hk We are waiting for You! I beg Your pardon if You received this letter by mistake. In that case I ask You to be so gentle to delete it. Yours faithfully Tal Alkobi

2006-10-22

Info: Israeli Brokerage Services scammers change tactics

One of the ways to block spam fairly reliably is to block on the basis of the links contained in the spam. In reaction to this, apparently, the Israeli Brokerage Services scammers have mostly stopped linking the images in their spam to their websites. Instead, they have been opting for shorter domain names and instructing the recipient to type the address by hand, as shown in the sample spam image here. Because the text appears in a GIF image, the recipient can't even copy and paste the address.

As an aside, if their primary motivation here is to dodge spam filters, it's not working very well. There are a lot other characteristics of their spams which identify them as such.

2006-10-16

Info: Are Nigerians changing their tack?

I've noticed a downward shift in the number of 419 scams arriving. My 419 archives show fifty-something 419 scams per month in the months of June, July, and August, but then a 50% drop in September, and projections for the remainder of October are looking similarly low. At the same time, I noticed that a recent job scam had a very Nigerian feel to it (despite pretending to come from China). On investigation, I note that the modus operandi is very typical of the Nigerians (using a webmail system), and the sending system reports that the originating IP address was 80.88.141.71, which is allocated to Nigeria (delegated from "Emperion", Denmark, to Nnamdi Nwokoro of Benin City, Edo state, Nigeria, according to WHOIS data).

Perhaps the Nigerians have discovered that it's more profitable for them to engage in job scams rather than advance fee fraud? Unlike the Russians and other Eastern Europeans (who tend to run job scams in conjunction with phishing), I get the impression that the Nigerians prefer forgery, and target the USA. According to an article at Snopes, there is a lot of fraud involving forged cheques and money orders: individuals are persuaded to accept these and wire back 90% of the face value via Western Union (or some similar arrangement). Due to banking regulations in the US, the proceeds of the cheque become available before the cheque is fully verified. The recipient gets a rude shock later when the bank denies the cheque and reverses the deposit.

2006-07-04

Info: About Job Scams

Job scams have been around for a while, but they've now reached a level of maturity where I feel I can describe them as a whole, rather than comment on each scam individually. I'll provide that general description here, so if you get a job offer that seems suspicious, you can compare it against my checklist.

The absolute common element of all job scams is the job offer. The job offer may arrive by spam, or it may be posted on a "legitimate" employment website (to the extent that such a website can be called "legitimate" when it fails to check the legitimacy of job ads posted there). Someone wants to offer you a job: typically the job requires no special experience, simple work, and good pay. Job scams are bait on a hook, so expect the job offer to look attractive.

There are, by and large, three possible job scam scenarios: pyramid schemes, advance fee fraud, and mules. I'll now describe the details of each of these scenarios.

Pyramid Schemes

The pyramid scheme job scam has been around on the Internet for quite a while, and they're no longer as common as they once were. These are also known as MMF (for "Make Money Fast") schemes. They're very easy to identify: the email or website pushing the scheme invariably raves on and on about how this may seem impossible but it really works, I didn't believe it but I tried it anyway and now I'm raking in tens of thousands of dollars per month, testimonial, testimonial, rave, rave, hype, hype, and so on.

If you read the thing long enough (there is invariably a LOT of hype to wade through before you hit the actual details), you find that the process involves buying a kit of some sort from this seller (a "marketing kit" is a popular term, or "how to sell on the Internet", or similar). This kit is fundamentally worthless junk, but you make money by on-selling it to others. It's basically a chain letter with a worthless product thrown in the mix to make it look more like a sale.

Key identifying features of a pyramid or MMF scam:

  • Lots of hype about how it really works. Lots of CAPITAL LETTERS and exclamation marks!!!!! IT REALLY WORKS!!!!!
  • Lots of testimonials from people who went from debt-ridden poverty to affluence by using this scheme. Is any of it true? Who can tell?
  • Absolutely insane text sizes, colours, decorations, highlights, fonts, and layout. Every word on the page must SCREAM at you. They're trying to convince you to buy a MONEY TREE here!
  • There is an up-front cost involved. Note well what this up-front cost is, because that's the nature of the business. Anyone who joins will make it their business to obtain this up-front payment from others.

FYI, a contemporary MMF spam can be found at my "Suckers Wanted" blog.

Advance Fee Fraud

Advance fee fraud usually comes in the form of a Nigerian 419 scam or lottery scam, but sometimes employment scams are used. In the advance fee fraud employment scam, you are offered a wonderful well-paid job with little or no experience required. If you apply, you are then short-listed for the job, and they ask you to send personal identification (such as a photocopy of your passport) and fees to pay for certain expenses involved in processing your application. If you willingly pay those fees, then there will be some excuse or another why you have to pay more fees, or pay the same fee again using a different method. Always more and more fees to pay, and no job, ever! The job is just a big lie: it's bait on the hook of advance fee payment.

Key identifying features of an advance fee fraud job scam:

  • Your would-be employers are overseas. This kind of fraud is best carried out across national boundaries, so that police action becomes difficult to arrange.
  • You qualify for the job, but in order to proceed, you need to send us MONEY.
  • Your would-be employers probably want personal details as well. This not only makes them look official, but helps them engage in identity fraud, perhaps obtaining a loan in your name.

For a striking example of this kind of fraud, see the case of Starline Cruise, and also reports relating to fake corporate flight attendant job offers.

Mule Recruitment

And now, to the major issue: mule recruitment. This is possibly the most insidious form of job scam, because it really does look like paid work. There are two major variations on the scam: money mules, usually employed by phishing gangs, and goods mules (also known as reshippers), usually employed by Nigerian scammers. In both of these cases the catch is that the money or goods are stolen, unbeknownst to the mule. Thus the mule is unwittingly dealing in illegal activity.

In the case of a money mule job, the job offer will typically involve "payment processing", "escrow", or a "financial manager" role. The employee is to accept direct deposits into his bank account, and make out payments via a wire service such as Western Union. The inbound payments may also involve some other means, such as payment by cheque, if the recipient lives in a country (such as the USA) in which it's relatively easy to fool someone into accepting a fake cheque. (The cheque appears to "clear", but the bank later reports that the cheque is a fake, and takes the money back out of your account.) outbound payments, on the other hand, are almost invariably made by Western Union or Money Gram wire transfer services. These are hard to trace, and can't be reversed (unlike direct deposits or cheque payments).

Key identifying features of a money mule job scam:

  • The job offer comes from an overseas company that wants your assistance to do business in your country.
  • The job involves "payment processing" or "escrow": accepting money in one form, then sending it (minus a cut) to your employers via Western Union or Money Gram. This is the key risk, since the incoming payments may be fraudulent or stolen, and are liable to be reversed. Money sent via Western Union, on the other hand, is Gone For Good.

The last variation, that of the goods mule, is less common but just as dangerous. (Thanks go to Snopes for documenting it.) In this case, the employee is a "shipping manager" or similar, and the job involves being a middle-man for purchased goods. The employer arranges for goods to be delivered to the employee, and the employee is responsible for sending these goods back to the employer by bulk freight, usually to Africa, and usually on the pretext that this process saves money over having all the goods shipped individually. It sounds plausible, but the problem is that the goods are usually being obtained fraudulently, such as by credit card fraud. Handling fraudulently obtained goods in large quantities isn't a great career move.

Key identifying features of a goods mule job scam:

  • The job involves receiving goods, and forwarding them somewhere outside your local legal jurisdiction, usually Africa. This is a bad idea, because you're assisting in the transfer of stolen or fraudulently obtained goods.
  • Unlike the other job scams which involve no payment at all, or deduct payment from money handled, this kind of job will be paid in a somewhat traditional manner.

General Tips

General tips for avoiding job scams:

  • Assume that any job offer which arrives by unsolicited email is a direct attempt to defraud you (and thousands of others, no doubt).
  • Beware of jobs that promise great rewards for no special skills: they're bait on a hook.
  • Beware of temptation: promises of money raining down on you, or fast easy bucks, or luxurious work conditions. These are also bait on a hook.
  • Beware of overseas employers. If they're not within reach of your local police force, there's not going to be much you can do if and when they rip you off.
  • Beware of jobs which involve being a middle-man, especially a middle-man between people inside and outside your national boundaries. You'll probably be acting as a buffer zone between the criminals who hired you, and the police who are tracking down their illegal activity.
  • Beware of jobs which involve sending money overseas via Western Union. The modern scam artist prefers to receive money this way, because it's hard to trace and recover. If you're the sucker who made the payment via Western Union, it's likely to be your money that the crook obtains. Payments made to you, on the other hand, will have a distressing habit of being reversed at a later date.

2006-07-02

Info: A New Kind of Money Mule Scam

Here's a new twist on a well-established scam: take note and add it to your list of "behaviour that should make me suspicious". This information is gleaned from a post over at ScamFraudAlert. It's a variation on the "payment processor" job, where you wind up being stung in exactly the same way without ever becoming an "employee". The scam goes something like the following.

  1. Excellent offer on some kind of goods arrives via spam.
  2. Victim is lured to the scammers website by the offer, and decides to buy something, since the prices are unbeatable. Victim divulges credit card details to the fraudsters at this time: this is bad move #1, but there is no immediate fraud on the card.
  3. Fraudster contacts victim saying that the credit card payment system is down, and they aren't sure whether the payment went through or not, but offers a refund just to be sure. This refund is actually stolen money, transferred out of a compromised third party Internet banking account. Victim does not know this and accepts the refund, thinking that this is first-rate service.
  4. Fraudster then suggests to victim that some other means of payment might be better, such as Western Union. You all saw that coming, didn't you? The fraudster offers to deduct the cost of the money transfer from the transaction, so the victim feels like he's not paying any extra.
  5. After a while there is no sign of the goods arriving, but the bank does notice that the funds transferred during step #3 were stolen. They reverse the transaction, so the victim is now officially out of pocket. The fraudsters keep whatever money was sent to them via Western Union, and they have the victim's credit card details as a bonus.

Lesson number one in this should be "never under any circumstances purchase from someone who adertised to you using spam".

2006-06-16

Info: Stock spammers go to remarkable lengths for stealth

I'm not currently tracking pump and dump stock spamming, mostly because there's just so much of it. I note in passing, however, a new stage in a trend that's been going on for some time.

It used to be that stock spammers would just send their spam in perfectly plain and readable ways. They then started to corrupt some of the more readily identifiable parts of the spam, such as the "forward looking statements" boilerplate disclaimer that many of them include, so as to lessen the number of spam filters that would catch them on this. More recently again, they have started embedding spaces and punctuation into the stock name itself, so as to prevent searches on that stock name turning up all the spam that winds up being archived on the web. Some of them have chosen to embed their entire message in an image -- a technique which is also popular among the pill spammers, but note that the stock spam is usually just plain text rendered as an image. This also prevents any part of the text from being used as filter-fodder, and prevents the archived spam from being searchable on the web.

The final stage in this progression that I wish to note is one recent stock spam (pumping "Advanced Powerline Technologies, Inc." [APWL]) which not only encodes the entire text as an image, but breaks up that image into a grid of smaller sub-images. I'm not entirely sure what additional benefit this is supposed to have (from the perspective of the scumbag who is sending it), but it could be an attempt to foil my recent habit of archiving such images on the Stock Spam blog. Previously, it was just a simple case of "save the image and upload it to the blog", but since it's no longer a single image, this technique wouldn't work -- additional effort would be required.

As I've said, I'm not tracking stock spam at the moment anyhow, so this doesn't actually impact me. It's interesting to watch the arms race between scammers and scam-busters progress, though.

2006-06-02

Info: Swiss Invest and Mercury Industries Job Scams still active

I'm still receiving the same old dubious recruitment offers from both Swiss Invest (six spams) and Mercury Industries (thirteen spams). They still occupy the domain names "swiss-invest.cn" (".cn" is the country code for China, by the way) and "mercuryindustries.com". Steer well clear of these scams, since they invariably involve money laundering or other forms of fraud. The recruiters are looking for victims, not employees.

Update on 2006-06-05. I haven't seen so many Mercury Industries spams anymore, but Swiss Invest is still hammering away at it quite broadly, and has taken the lead in terms of quantity. The scam appears to be targeting Australians primarily, and the state government of Western Australia has released a consumer protection alert about it.

2006-05-31

Info: Why you should never click links in spam, no matter what.

I recently received a spam like so.

Dear [name]

On 2004-07-12 03:17:00.000 you purchased SystemSoap. As a SystemSoap user,
the improved SpySpotter 3.11 is available to you.
Did you know that when a PC is infected with spyware that every keystroke,
every website and every conversation could be recorded or monitored?
Try our newest version with improved features & updated spyware lists…
Scan your computer and find out now!
http://collegeclubpoker.com/upd200606.html

I decided to investigate that link -- very carefully, of course. If you just opened it up in a browser, you'd probably see a page of pharmaceuticals for sale and think "oh, that was just a lame lure to get me to buy some medecine." You'd be wrong, though: the medecine is just a ruse. The real sting is an invisible "IFRAME" on the page which links somewhere else entirely and attempts to exploit known vulnerabilities in various versions of Windows to install software on your computer!

Unless you're well up to date with all the latest security patches, just visiting a site like this can be enough to turn your computer into a spam-spewing zombie without you knowing it. In practice, you're substantially safer if you use anything but Windows while attached to the Internet -- not that this fact helps the majority who are stuck with it for one reason or another (my sympathies to you). Just bear in mind that any web site you visit could attempt a hostile invasion of your computer, and don't go visiting sites advertised by disreputable means (like spam) no matter what the cover story is.

2006-05-22

Info: Barcelo Travel Inc. Job Scam

I've reported two previous instances (1, 2) of job scam spam claiming to be from a "Barcelo Travel Inc." Further evidence has come to light which supports the theory that this is a money laundering job scam: a copy of details sent to a correspondent who made enquiries into the job.

Dear sir\madam,
Thanks for your e-mail.
Let me introduce myself! I`m Dominico Barcelo, direcetor Barcelo Travel Inc.
Barcelo Travel Inc. is a Company with a prestigious heritage with a combination of Anglo-Saxon efficiency and old European style.
Founded in 2003 and based in Milan, Italy, Barcelo Travel Inc. is a Receptive Tour Operator and Destination Management Company specializing in Incentive, Custom, Professional and Leisure Travel Programs. We create tailor-made itineraries to suit your requirements and budget. Now we have more than 50+ branches in the world.
We maintain excellent contacts with our suppliers and educate them about our clients' tastes and needs, thereby enabling us to guarantee high quality service.
As well as providing individually programmed trips for families, groups of friends, incentive groups and major university study tours, our business consists also of all the necessary ground tour arrangements, such as hotel accommodation, conference facilities, restaurants, deluxe motorcoaches and first class limousine services.
About your work in our company.
In this moment we have not office in [country] and also we have not bank accounts in your country, and now we can not receive money from our clients. But now we have a lot of clients from [country] and we offer you help in our bussines and earn good money with us.
Essence of your work it acceptance and processing of the payments(bank transfer, Money Orders, Western Union, Checks and etc) and other from our clients. Work will borrow some hours per day, earnings some thousand per month.
You will be earn 8% of each tranfers after received this one, and after two test week your salary will be 500 USD per week plus commission(8% of each transfer).
In the beginning of your work(1-2 weeks) your earnings ~ 1000-2000 USD per week.
Please note, that I have sent you contract with this e-mail. Please download this attachment, read and sign it, if you want work with us.
After reception of the contract signed by you, you become the employee of our company.
You can send your contract to this e-mail or to our fax in Italy: +390295441457.
IF YOU SEND CONTRACT BY FAX INFORM US BY E-MAIL ABOUT IT.
Please look plan of your work in our company:
1. Our client will make transfer money to your bank account(prefer method)
2. Our manager will send you all information about transfer by e-mail and will call you and inform about it.
2. You would go in bank with your passport and receive this payment(get cash).
3. After bank you should will go in Western Union(WU) branch and send money to our office or one of it branches in the world.
4. When you complete WU transfer, you would send all details about transfer by e-mail.
5. Your commission and charges WU you would deduct from total amount of transfer.
You would check your e-mail every day, some time per day. And Also you would always will be able by your phones.
If you will carry out all these rules you easily can earn more than 1000 USD per week.
Please ask any questions if you have.
Looking forward to hearing from you soon!
Best Regards,
Dominico Barcelo

The portion of the above text marked in italics is plagiarised directly from Italian Travel Team. When someone is setting up a fake company like this, it's common to base the fake operation on a real operation. Italian Travel Team has the dubious honour of being imitated in this case.

Speaking of plagiarism, Italian Travel Team isn't being entirely original in their description of their company. It so happens that a bunch of "Destination Management Companies" seem to have wound up using exactly the same phrases in key parts of their respective websites. Consider the following section of text.

Founded in [year] and based in [place], [company] is a Receptive Tour Operator and Destination Management Company specializing in Incentive, Ad-Hoc, Professional and Leisure Travel Programs.

The originator of this description appears to be AgenTours, but somewhere along the line the Italian Travel Team decided to appropriate it. It's not clear whether they copied AgenTours directly, or Taste of Belgium, who have plagiarised the AgenTours "about us" page pretty much in its entirety. Here's a hint, guys: if you plagiarise, you wind up looking like the job-scam fraudsters who do the same thing.

Back on the subject of the job scam, the sections of the letter that I've put in bold text are the key warning signs that the job is a money laundering scam. The transfer of money into the "employee" account can be traced, but the Western Union transfer can be done in such a way that the recipient can pick it up anywhere in the world without disclosing his identity.

I'd post the "employment contract" here as well, but it's really not all that interesting. It's a poor imitation of a real contract, included mostly to lend the arrangement an air of legitimacy. If you showed it to a lawyer, they'd tell you that it's a piece of rubbish pretending to be a contract.

2006-05-06

Info: Corporate Flight Attendant Job Scams

Matt Keegan writes to inform me of a job scam he's seen, somewhat like the cruise ship job scams I've documented here previously, only this time offering jobs as corporate jet flight attendants. This is a case of advance fee fraud: the "employer" wants to offer you the job, but you first have to send them money so they can purchase an airline ticket for you to go to a job interview. If you pay up, you'll find there is no ticket waiting for you in the arranged place. Your money is gone, and that's the end of that. At the moment, this scam seems to be limited to one particular scumbag operating in the USA, but he's been at it for a year or more.

Be warned that job scams like this aren't limited to distribution via spam. Sometimes, as in this case, the scammers will use legitimate job marketplace facilities to post their job offer. If you want to avoid being ripped off, treat any "job offer" that requires any sort of money up front with extreme suspicion. Seek solid proof that such a job offer is genuine and legitimate before sending anything -- not just an absence of "red flags", but positive assurance that the company exists, is legitimate, and is represented by the person with whom you have made contact. Be doubly paranoid if the outgoing payment is to be made via Western Union, as such payments can be impossible to trace.

2006-03-01

Info: Cruise Ship Job Scams

My interest was piqued by a couple of recent odd-looking job scams. Usually job scams offer you a position which involves illegal money laundering (under the guise of "financial officer" or similar), but these recent scams talk about jobs on cruise ships. A little bit of digging reveals that this is a case of Advance Fee Fraud: if you apply for the job, they'll tell you that you need to pay a certain amount of money to get government approval for something or other, and then something else, and something else, and so on for as long as they can keep bleeding cash out of you. At the end of the day, you'll have a pile of expensive fake documents and no job.

Source: Cruise Ship Employment Scam.

2005-07-13

Info: New Phishing Threat

I'd like to provide you with an executive summary of a new phishing threat that has been put forth in an article fom SearchSecurity.com. Earlier this year, a database of customer information at a payment processing facility was compromised. This is bad news, in and of itself, since it means that the culprits have obtained credit card numbers and the address information of the holders. But although the culprits have, no doubt, used the information to their own benefit in a direct manner, they are also phishing for further data. The author of the linked article puzzles as to what kind of information they could want, given that so much information was already compromised in the original breach. His hypothesis: they want Social Security Numbers, since this is the missing piece of the puzzle, and would enable outright identity theft.

In practice, the phishing threat discussed here will come in the form of an email message from your bank, containing a warning about your credit card, and will include a persuasive amount of detail, including your credit card number! This is because these details have already fallen into the hands of the enemy. The message will then, in the usual manner, coax you to follow a link to their website, where you can allegedly "reactivate" your account. This is where they will ask you to provide your SSN as a "security measure". If you divulge this information, you not only demonstrate that your other details are true and correct, but you provide them with enough information to obtain credit in your name, thus landing you in bad credit hell.

If you receive such an email, I recommend that you notify your financial institution immediately, using a medium other than the Internet to do so.

2005-07-08

Info: the CDGT situation

I've been contacted by one Francisco Moreira of Spam Daily News, in relation to the ongoing CDGT stock spam (reported frequently in this blog). Spam Daily News has already run a couple of articles on the subject, the first in which a law firm retaliates for being used as the "from" address in some of the spam, and the second in which CDGT strikes back with accusations of defamation and whatnot. Francisco asks my opinion on the matter.

Spamming is a nasty business, and the ugly brawl into which the CDGT affair has degenerated demonstrates this admirably. So far as I can tell, the only party that seems to be getting any real benefit from the situation is the spammer. I can only observe the facts and draw inferences, but for what it's worth, here are my inferences in this case.

I don't think the CDGT spam is "pump and dump" in the usual sense of that term. Where traditional pump and dump is concerned, the fraudster obtains a significant quantity of very low-value stock, then publicises a story about how that stock is suddenly going to rise for some reason or other. If people take the bait, then the stock does rise as a consequence of sudden buyer interest. The fraudster then dumps his stock at a profit, and lets everyone else deal with the aftermath.

The pattern of spamming in the case of CDGT doesn't match this scenario. For one, the stock isn't the kind of penny stock that pump-and-dumpers prefer to use, where a few cents difference can mean a 100% gain. Also, the spam has been staggeringly persistent, arriving time and time again. This isn't so much "pump and dump" as "pump and pump and pump and pump".

A big clue as to what's going on here lies in the SDN article entitled China Digital Media Corporation: 'We are not a spammer!', in which we see the following.

...Ng confirmed that his company hired a stock promoter but denied having anything to do with sending spam with Ziegler as the return address. He did not name the promoter and apologized for any embarrassment.

The obvious surmise from this state of affairs is that Ng's "stock promoter" is a spammer, or hires the use of a spammer. Degrees of separation like this are a frequent problem in spam. If party X hires party Y to perform promotion, and party Y is a spammer, party X may become offended when the rest of the world accuses him of spamming. Party X may deny it, as in the following statement from Daniel Ng.

Using spam is not how we operate our businesses. We are building value for shareholders through the old fashioned methods of hard work and skillful execution of our business plan.

Sadly, Mr Ng appears to have employed a spammer, and I don't see any practical or moral difference between "using spam" and "using a spammer". Maybe he didn't know he was hiring a spammer at the time, and he seems dead keen on denying it, but CDGT spam has been flooding the Internet for many months now. I personally have a large swag of CDGT spams (and PGCN spams obviously sent by the same spammer) in my inbox right now. It's possible that a spammer has been acting of his own initiative here, but to what end? The most reasonable explanation is the obvious one: Ng's "stock promoter" is (or uses) a spammer.

In the same article, we see the following statement from Mr Ziegler.

I was amazed that somebody spammed with an e-mail address that was a real e-mail address, thinking that there would be no ramifications.

Understand, Mr Ziegler, that spammers are relentlessly pragmatic, and untainted by the slightest trace of empathy. They deliberately use real email addresses (other than their own) as the sender address, since obvious forgeries are very likely to be blocked by anti-spam measures. If they want to be particularly spiteful, they will use the address of some anti-spam activist who has annoyed them, but any real address will do, in general.

As for "ramifications", spammers such as the CDGT spammer tend to use networks of compromised computers, sometimes called "zombies", to do their dirty work. Thus, even if you know which computer the spam came from, you haven't traced the spammer. Spammers are non-trivial to trace, and they know it. The ramifications of address forgery, along with most of the other negative ramifications of spam in general, tend to naturally fall upon parties other than the spammer. And, being the sociopaths they are, that state of affairs suits them nicely.

If Mr Ziegler goes ahead with this legal action -- and I see no reason why he shouldn't -- my one piece of advice would be as follows: follow the money. Don't just settle for nailing CDGT; use whatever legal means are available to discover who CDGT is paying (directly or indirectly) to send the spam. Nailing an actual spammer makes the world a better place.

2005-05-30

Info: Proof That Lottery Scams are 419s

Up until quite recently, I was categorising lottery scams in the same group as advance fee fraud. I still refer to the people behind both these scams as "419ers" -- and I've now got proof positive that the same people are behind both types of scam. Specifically, a lottery scam that's just arrived (and which I will document shortly) came from the same IP address as the earlier queenmakeni 419 spam. Coincidence? Well, a correspondent informs me that he performed a search for the address 62.81.235.112 after receiving a lottery scam spam (to be documented shortly) from that address, and found that my Ali Salaki 419 had originated at the same address.

I don't know of anyone who has expressed serious doubt that these two scams are variations on the same theme run by the same criminals. However, if there was doubt, this evidence should prove it beyond reasonable doubt, as they say in the courts.

2005-05-10

Info: Degree/Diploma Mills

The sale of fake academic qualifications is a multi-million dollar industry. Like much fraud, it thrives in situations which cross jurisdictional boundaries. Fake educational institutions in the UK can sell to unwitting saps in the USA with nigh-impunity. Even within the USA, operating between states can present enough of a hurdle that a fraudster can rake in millions for years without facing justice. The global nature of the Internet makes it ideal for such dodgy dealing: spam and websites relating to fake academic qualifications are rife. It is usually possible for these shonky institutions to place advertisements for their services (both online and in print) in the same channels used by the real instiutions, including some prestigious publications.

Fake educational institutions sell certificates, not education. Further, they make no effort to certify that the recipient of the award actually has any knowledge in the field of the award. This is why they are often called "diploma mills", or "degree mills": they simply churn out impressive-looking pieces of paper in volume. Most of them invent a credible-sounding name for their virtual institution, then churn out awards. Some go so far as to invent a credible-sounding institution to accredit their institution. (In the USA, tertiary institutions are not directly accredited or established by the government, which is what makes this kind of fraud feasible.) Others take the more direct approach of producing "replacement" certificates for those you claim to have lost, and these can be any degree from just about any institution.

Here are some useful sources of information on the problem of diploma mills.

2005-03-21

Info.: Trends in 419 scamming

The following information was recently posted on the Spam Research mailing list by active anti-spammer Suresh Ramasubramanian. The archives of that list are only available by subscription, so I've obtained permission from Suresh to re-publish here.

I've seen 419ers muscle in on a whole lot of things now that the "I'm the widow of a dead dictator" is so twentieth century ..

  • Buy stuff (anything from cars / pedigreed dogs to hookers^W escort services) on the Internet, pay using stolen credit cards / fake cashiers checks. Only, if the car costs $6000, he'll give you a fake check for $10000 and con you into wiring him the remaining money using western union. You fall for that and you only find out after the check is presented to the remote bank for clearing, and then bounced back.
  • Post on singles lists / bbs / newsgroups pretending to be a guy looking for friends online. Hook the friend with a lot of BS about the hard time they're facing in Nigeria, and either get them to wire some money over "as a loan", or maybe get them to sponsor the 419er for an entry visa to the States. That visa then gets used to get a scam artist into the states for random other purposes, none of which involve visiting the sucker.
  • Same thing with universities / conferences etc - any fairy story will do in order to get a visa to the states, or maybe pull fake check scams on the university admissions office or conference organizer. I see that first hand every year .. I chair the fellowships committee for the APRICOT asia pac netops conference (www.apricot.net). Every year I get fellowship applications from obvious nigerian scam artists, each of them with weird and wonderful reasons why they want to attend the conference
  • Phishing. I'm working with western union, which is facing a rash of nigerians using standard boiler room sending techniques (lots of guys sending from free webmail accounts - we run 40 million of those) to pretend they're western union bidpay, and trying to steal id.

2005-03-11

Why?

So I've decided to try out a "blog". Why? Because I suspect that it's the right tool for this job. The "job" in this case is the job of shining a spotlight on deceptive Internet practices, with particular reference to email and web-related nasties. There is, at present, a thriving industry in separating victims from their money by means of online deception. "Phishing" emails, where a big fat liar sends you email and claims that he's your bank (or similar), are one such form of deception. As I stumble across these deceptive practices, I'll document them here. That way, the next person to encouter suspicious activity might do a search and find that the fraud has already been exposed.

Be careful out there, folks.