<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Krebs on Security &#187; Other</title>
	<atom:link href="http://krebsonsecurity.com/category/other/feed/" rel="self" type="application/rss+xml" />
	<link>http://krebsonsecurity.com</link>
	<description>In-depth security news and investigation</description>
	<lastBuildDate>Thu, 09 Feb 2012 22:39:50 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Happy 2nd Birthday, KrebsOnSecurity.com!</title>
		<link>http://krebsonsecurity.com/2011/12/happy-2nd-birthday-krebsonsecurity-com/</link>
		<comments>http://krebsonsecurity.com/2011/12/happy-2nd-birthday-krebsonsecurity-com/#comments</comments>
		<pubDate>Thu, 29 Dec 2011 16:25:39 +0000</pubDate>
		<dc:creator>BrianKrebs</dc:creator>
				<category><![CDATA[Other]]></category>
		<category><![CDATA[Krebs on Security LLC]]></category>

		<guid isPermaLink="false">http://krebsonsecurity.com/?p=13163</guid>
		<description><![CDATA[I'm taking a short break from some year-end downtime to observe that KrebsOnSecurity.com turns two years old today!]]></description>
			<content:encoded><![CDATA[
<div class="topsy_widget_data topsy_theme_silver" style="float: left;margin-right: 0.75em; background: url(data:,%7B%20%22url%22%3A%20%22http%253A%252F%252Fkrebsonsecurity.com%252F2011%252F12%252Fhappy-2nd-birthday-krebsonsecurity-com%252F%22%2C%20%22shorturl%22%3A%20%22http%3A%2F%2Fbit.ly%2FuRsBCH%22%2C%20%22style%22%3A%20%22big%22%2C%20%22title%22%3A%20%22Happy%202nd%20Birthday%2C%20KrebsOnSecurity.com%21%22%20%7D);"></div>
<p>I&#8217;m taking a short break from some year-end downtime to observe that KrebsOnSecurity.com turns two years old today!</p>
<p><a href="http://krebsonsecurity.com/wp-content/uploads/2011/12/twocropped.jpg"><img class="alignright size-full wp-image-13166" title="KrebsOnSecurity.com Turns Two!" src="http://krebsonsecurity.com/wp-content/uploads/2011/12/twocropped.jpg" alt="" width="194" height="250" /></a>This past year, KrebsOnSecurity.com has featured more than 200 blog posts, and attracted 5,000+ reader comments. It has been humbling to watch the audience here steadily grow and mature into a community. The expertise and conversations offered by readers in the blog comments have added immeasurably to the value and usefulness of this site.</p>
<p>My research and reporting involved more than a dozen public speaking events around the globe in 2011. The highlights of my work-related travel included trips to Austria, Canada, Poland, Russia, and The Netherlands. 2012 promises more interesting destinations.</p>
<p>When I founded Krebs On Security LLC in late 2009, I had no idea if it would work out. This past year, I&#8217;ve respectfully turned down some very flattering offers to work at important publications. The money and (apparent) stability those opportunities held out were certainly enticing, but I&#8217;m having way too much fun on my own, and today I can scarcely imagine doing anything else.</p>
<p>I look forward to continuing my investigative reporting on cybercrime, cybersecurity, and the underground economy. Most of all, I look forward to your continued readership and support. Thank you.</p>
<p>In case you missed them, here are some of the most-read investigative stories on KrebsOnsecurity.com from 2011:</p>
<p><a title="Russian Cops Crash Pill Pusher Party" href="http://krebsonsecurity.com/2011/02/russian-cops-crash-pill-pusher-party/" target="_blank">Russian Cops Crash Pill Pusher Party</a></p>
<p><a title="SpamIt, GlavMed Pharmacy Networks Exposed" href="http://krebsonsecurity.com/2011/02/spamit-glavmed-pharmacy-networks-exposed/" target="_blank">SpamIt, Glavmed Pharmacy Networks Exposed</a></p>
<p><a title="Is Your Computer Listed &quot;For Rent&quot;?" href="http://krebsonsecurity.com/2011/04/is-your-computer-listed-for-rent/" target="_blank">Is Your Computer Listed &#8220;For Rent&#8221;? </a></p>
<p><a title="Rent-a-Bot Networks Tied to TDSS Botnet" href="http://krebsonsecurity.com/2011/09/rent-a-bot-networks-tied-to-tdss-botnet/" target="_blank">Rent-a-Bot Networks Tied to TDSS Botnet</a></p>
<p><a title="Who's Behind the TDSS Botnet?" href="http://krebsonsecurity.com/2011/09/whos-behind-the-tdss-botnet/" target="_blank">Who&#8217;s Behind the TDSS Botnet?</a></p>
<p><a title="Gang Used 3D Printers for ATM Skimmers" href="http://krebsonsecurity.com/2011/09/gang-used-3d-printers-for-atm-skimmers/" target="_blank">Gang Used 3D Printers for ATM Skimmers</a></p>
<p><a title="Digital Hit Men for Hire" href="http://krebsonsecurity.com/2011/08/digital-hit-men-for-hire/" target="_blank">Digital Hit Men for Hire</a></p>
<p><a title="Beware of Juice-Jacking" href="http://krebsonsecurity.com/2011/08/beware-of-juice-jacking/" target="_blank">Beware of Juice-Jacking</a></p>
<p><a title="Coordinated ATM Heists Net Thieves $13M" href="http://krebsonsecurity.com/2011/08/coordinated-atm-heist-nets-thieves-13m/" target="_blank">Coordinated ATM Heists Net Thieves $13 Million</a></p>
<p><a title="Rustock Botnet Suspect Sought Job at Google" href="http://krebsonsecurity.com/2011/06/rustock-botnet-suspect-sought-job-at-google/" target="_blank">Rustock Botnet Suspect Sought Job at Google</a></p>
<p><a title="Apple Took 3+ Years to Fix FinFisher Trojan Hole" href="http://krebsonsecurity.com/2011/11/apple-took-3-years-to-fix-finfisher-trojan-hole/" target="_blank">Apple Took 3+ Years to Fix FinFisher Trojan Hole</a></p>
<p><a title="Advanced Persistent Tweets: Zero-Day in 140 Characters" href="http://krebsonsecurity.com/2011/05/advanced-persistent-tweets-zero-day-in-140-characters/" target="_blank">Advanced Persistent Tweets: Zero-Day in 140 Characters</a></p>
<p><a title="Pro-Grade (3D-Printer Made?) ATM Skimmer" href="http://krebsonsecurity.com/2011/12/pro-grade-3d-printer-made-atm-skimmer/" target="_blank">Pro-Grade (3D-Printer Made?) ATM Skimmer</a></p>
<p><a title="How Much Is Your Identity Worth?" href="http://krebsonsecurity.com/2011/11/how-much-is-your-identity-worth/" target="_blank">How Much is Your Identity Worth?</a></p>

]]></content:encoded>
			<wfw:commentRss>http://krebsonsecurity.com/2011/12/happy-2nd-birthday-krebsonsecurity-com/feed/</wfw:commentRss>
		<slash:comments>48</slash:comments>
		</item>
		<item>
		<title>NY ID Theft Ring Used Insiders, Gang Members</title>
		<link>http://krebsonsecurity.com/2011/12/ny-id-theft-ring-used-insiders-gang-members/</link>
		<comments>http://krebsonsecurity.com/2011/12/ny-id-theft-ring-used-insiders-gang-members/#comments</comments>
		<pubDate>Fri, 16 Dec 2011 22:42:35 +0000</pubDate>
		<dc:creator>BrianKrebs</dc:creator>
				<category><![CDATA[Other]]></category>

		<guid isPermaLink="false">http://krebsonsecurity.com/?p=13050</guid>
		<description><![CDATA[Authorities in Manhattan today unsealed indictments against 55 people suspected of operating an identity theft and financial fraud ring, including a number of insiders at banks and companies throughout New York who allegedly helped to steal more than $2 million from hundreds of customers and clients. Prosecutors say the 18-month-long investigation is notable because it [...]]]></description>
			<content:encoded><![CDATA[
<div class="topsy_widget_data topsy_theme_silver" style="float: left;margin-right: 0.75em; background: url(data:,%7B%20%22url%22%3A%20%22http%253A%252F%252Fkrebsonsecurity.com%252F2011%252F12%252Fny-id-theft-ring-used-insiders-gang-members%252F%22%2C%20%22shorturl%22%3A%20%22http%3A%2F%2Fbit.ly%2Ftc7LFr%22%2C%20%22style%22%3A%20%22big%22%2C%20%22title%22%3A%20%22NY%20ID%20Theft%20Ring%20Used%20Insiders%2C%20Gang%20Members%22%20%7D);"></div>
<p>Authorities in Manhattan today unsealed indictments against 55 people suspected of operating an identity theft and financial fraud ring, including a number of insiders at banks and companies throughout New York who allegedly helped to steal more than $2 million from hundreds of customers and clients.</p>
<p><a href="http://krebsonsecurity.com/wp-content/uploads/2011/12/cashgraf.jpg"><img class="alignright  wp-image-13057" title="cashgraf" src="http://krebsonsecurity.com/wp-content/uploads/2011/12/cashgraf.jpg" alt="" width="283" height="212" /></a>Prosecutors say the 18-month-long investigation is notable because it underscores the ways in which traditional street crooks are moving their activity online: New York authorities maintain that more than a dozen of the defendants have violent criminal records and belong to different street gangs in Brooklyn.</p>
<p>At the center of the alleged conspiracy are employees at New York institutions that had access to large amounts of sensitive consumer and business data. Among those being arraigned today in a New York state court are <strong></strong><strong>JP Morgan Chase</strong> employees <strong>Karen Chance</strong>, <strong>Mercy Adebandjo</strong> and <strong>Joanna Gierczack</strong>; <strong>Tracey Nelson</strong>, an employee of the <strong>United Jewish Appeal-Federation</strong>; <strong>Roberto &#8220;Robbie&#8221; Millar</strong>, a car salesman for <strong>Open Road-Audi in Brooklyn</strong>; and Nicola Bennett, a compliance officer employed by <strong>AKAM Associates Inc.,</strong> a residential property management company.</p>
<p>&#8220;These insiders used their positions to gain access to client data, and then sold that data to make money for themselves and their accomplices,&#8221; District Attorney Vance<strong></strong> said in <a href="http://www.manhattanda.com/press-release/da-vance-and-nypd-55-defendants-indicted-widespread-%E2%80%9Cinsider%E2%80%9D-cyberfraud-scheme" target="_blank">a written statement</a>. &#8220;We will continue to work with our partners to build significant cases to disrupt identity theft and dismantle these criminal organizations.”</p>
<p>The indictments allege that middlemen named in the conspiracy purchased personal information on customers and donors from Nelson and Millar, and then either re-sold the data or used it themselves to commit fraudulent financial transactions.</p>
<p>Prosecutors also charge that the Chase employees abused their access to steal personal data on account holders, and sold the information to counterfeit check makers and to individuals who specialized in setting up and executing fraudulent bank transfers.</p>
<p>Some of the defendants are alleged to have recruited other indicted members for the purpose of using their bank accounts to conduct fraudulent transactions. Prosecutors say the recruiters played a dual role: trafficking in stolen personal information bought from others, and recruiting people to provide bank accounts through which they could commit fraud.</p>
<p>These so-called &#8220;collusive account holders&#8221; &#8212; effectively complicit money mules &#8212; make up the bulk of the individuals named in the indictments. New York authorities charge that when defendants wanted to withdraw money quickly from collusive accounts, they purchased US Postal Service money orders with the debit cards linked to the accounts.</p>
<p>The indictments state that some the defendants arraigned today used automated systems set up by <strong>Citibank</strong> and <strong>TD Bank</strong> to change the personal information on ID theft victims&#8217; bank records, including the victims&#8217; contact address, phone numbers and email addresses.</p>
<p>For example, prosecutor alleged that one of the defendants,  <strong>Josiah &#8220;Pespi&#8221; Boatwains</strong>, would request that stolen credit cards be mailed to an address where a co-conspirator Richard Ramos, an employee at <strong>United Parcel Service</strong> (UPS) would intercept the cards on Boatwain&#8217;s behalf in exchange for money.</p>
<p>Boatwains and two other defendants allegedly then used those stolen cards to purchase luxury items that other defendants sold to co-conspirators named in the indictments. Other defendants allegedly used hijacked credit card account numbers to make online purchases buying airline tickets, movie ticket, credit reports, pizza and iTunes products.</p>
<p>A statement of facts filed with the New York State Supreme Court notes that there is a large amount of violent activity that surrounds the defendants in this case. The statement reads:</p>
<blockquote><p>&#8220;During the course of our investigation 2 targets of the investigation were murdered. One of the deceased was brutally murdered. When his body was found by the police, they recovered personal identifying information of victims linked to our case. Specifically, on his person, a copy of a check was found that was from one of our identity theft victims that had donated to the United Jewish Appeal.&#8221;<span id="more-13050"></span></p>
<p>&#8220;In addition, we are informed by the police department that many of these defendants are members of the Brooklyn Gang called &#8220;The Outlaws,&#8221; and others are Bloods and Crypts [sic]. Many of our defendants have violent criminal convictions.&#8221;</p></blockquote>
<p>New York authorities say they expect the dollar losses to increase as the investigation continues.</p>

]]></content:encoded>
			<wfw:commentRss>http://krebsonsecurity.com/2011/12/ny-id-theft-ring-used-insiders-gang-members/feed/</wfw:commentRss>
		<slash:comments>13</slash:comments>
		</item>
		<item>
		<title>Ukrainian General Arrested in Cyber Heists</title>
		<link>http://krebsonsecurity.com/2011/12/ukrainian-general-arrested-in-cyber-heists/</link>
		<comments>http://krebsonsecurity.com/2011/12/ukrainian-general-arrested-in-cyber-heists/#comments</comments>
		<pubDate>Fri, 16 Dec 2011 05:06:52 +0000</pubDate>
		<dc:creator>BrianKrebs</dc:creator>
				<category><![CDATA[Other]]></category>
		<category><![CDATA[Konstantin Ossipov]]></category>
		<category><![CDATA[Matei Vitalie]]></category>
		<category><![CDATA[Roy Snell]]></category>
		<category><![CDATA[Society of Corporate Compliance and Ethics]]></category>
		<category><![CDATA[Valeriu Gaichuk]]></category>

		<guid isPermaLink="false">http://krebsonsecurity.com/?p=13030</guid>
		<description><![CDATA[A decorated Ukrainian general was arrested last week in Romania along with two other men suspected of being part of an organized cybercrime gang that laundered at least $1.4 million stolen from U.S. and Italian firms. Apprehended in Iasi, Romania last week were Matei Vitalie, 37, of Moldova; Konstantin Ossipov, a 42-year-old Israeli citizen; and [...]]]></description>
			<content:encoded><![CDATA[
<div class="topsy_widget_data topsy_theme_silver" style="float: left;margin-right: 0.75em; background: url(data:,%7B%20%22url%22%3A%20%22http%253A%252F%252Fkrebsonsecurity.com%252F2011%252F12%252Fukrainian-general-arrested-in-cyber-heists%252F%22%2C%20%22shorturl%22%3A%20%22http%3A%2F%2Fbit.ly%2FtHsU53%22%2C%20%22style%22%3A%20%22big%22%2C%20%22title%22%3A%20%22Ukrainian%20General%20Arrested%20in%20Cyber%20Heists%22%20%7D);"></div>
<p>A decorated Ukrainian general was arrested last week in Romania along with two other men suspected of being part of an organized cybercrime gang that laundered at least $1.4 million stolen from U.S. and Italian firms.</p>
<div id="attachment_13032" class="wp-caption alignright" style="width: 297px"><a href="http://krebsonsecurity.com/wp-content/uploads/2011/12/gaichuk2.png"><img class=" wp-image-13032" title="gaichuk2" src="http://krebsonsecurity.com/wp-content/uploads/2011/12/gaichuk2-600x399.png" alt="" width="287" height="190" /></a><p class="wp-caption-text">Gen. Valeriu Gaichuck, far right.</p></div>
<p>Apprehended in Iasi, Romania last week were <strong></strong><strong>Matei Vitalie</strong>, 37, of Moldova; <strong>Konstantin Ossipov</strong>, a 42-year-old Israeli citizen; and 54-year-old <strong>Valeriu Gaichuk</strong>, a Ukrainian general who, according to <a href="https://www.facebook.com/gaichuk" target="_blank">his Facebook page</a>, once studied at Florida International University in Miami.</p>
<p>Romanian prosecutors allege that the men created fake companies and business contracts to help to launder funds that were stolen from at least two firms, including $952,800 from the <strong>Society of Corporate Compliance and Ethics</strong>, an organization based in Minneapolis. <strong><strong>Roy Snell, </strong></strong>the society&#8217;s chief executive, declined to comment for this story.<strong></strong></p>
<p><strong><span id="more-13030"></span></strong></p>
<p>Romanian authorities, working with the FBI and Italian special forces, were tipped off by banks in Italy, which denied a request allegedly by the accused to transfer $400,000 from a victim company there to a fictitious firm. According to <a title="Incheiere-penala_pg-1_4.pdf" href="http://krebsonsecurity.com/wp-content/uploads/2011/12/Incheiere-penala_pg-1_4.pdf" target="_blank">documents</a> <a title="Incheiere-penala_pg-5_10.pdf" href="http://krebsonsecurity.com/wp-content/uploads/2011/12/Incheiere-penala_pg-5_10.pdf" target="_blank">released</a> by <a title="http://krebsonsecurity.com/wp-content/uploads/2011/12/" href="http://krebsonsecurity.com/wp-content/uploads/2011/12/Incheiere-penala_pg-11_18.pdf" target="_blank">prosecutors</a>, the men were caught red handed on Dec. 9 trying to withdrawn nearly $1 million stolen from the American company.</p>
<p>A U.S. law enforcement investigator familiar with the case who spoke on condition of anonymity said keystroke logging Trojans were used to steal the online banking credentials of the victim organizations, and that the case is connected to at least one other cyber fraud investigation that is still pending. <strong></strong></p>
<p>The judge overseeing the case approved the prosecutor&#8217;s request to have the men <a title="Google Translate of adevarul.ro story" href="http://translate.google.com/translate?sl=ro&amp;tl=en&amp;js=n&amp;prev=_t&amp;hl=en&amp;ie=UTF-8&amp;layout=2&amp;eotf=1&amp;u=http%3A%2F%2Fwww.adevarul.ro%2Flocale%2Fiasi%2FGeneralul_ucrainean-pericol_social_0_608339641.html" target="_blank">detained for at least 29 days</a> pending further investigation, saying that authorities have information that the defendants belong to much larger organized criminal group.</p>

]]></content:encoded>
			<wfw:commentRss>http://krebsonsecurity.com/2011/12/ukrainian-general-arrested-in-cyber-heists/feed/</wfw:commentRss>
		<slash:comments>12</slash:comments>
		</item>
		<item>
		<title>Bugs Money</title>
		<link>http://krebsonsecurity.com/2011/12/bugs-money/</link>
		<comments>http://krebsonsecurity.com/2011/12/bugs-money/#comments</comments>
		<pubDate>Tue, 13 Dec 2011 05:01:31 +0000</pubDate>
		<dc:creator>BrianKrebs</dc:creator>
				<category><![CDATA[A Little Sunshine]]></category>
		<category><![CDATA[Other]]></category>
		<category><![CDATA[Black Hat]]></category>
		<category><![CDATA[Brown University]]></category>
		<category><![CDATA[CCBill]]></category>
		<category><![CDATA[defcon]]></category>
		<category><![CDATA[Facebook bug bounty]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[Mozilla]]></category>
		<category><![CDATA[Neal Poole]]></category>
		<category><![CDATA[Niebezpiecznik.pl]]></category>
		<category><![CDATA[Paypal]]></category>
		<category><![CDATA[Piwik]]></category>
		<category><![CDATA[Szymon Gruszecki]]></category>
		<category><![CDATA[western union]]></category>
		<category><![CDATA[Whitehat debit card]]></category>

		<guid isPermaLink="false">http://krebsonsecurity.com/?p=12688</guid>
		<description><![CDATA[Talk about geek chic. Facebook has started paying researchers who find and report security bugs by issuing them custom branded "White Hat" debit cards that can be reloaded with funds each time the researchers discover new flaws.]]></description>
			<content:encoded><![CDATA[
<div class="topsy_widget_data topsy_theme_silver" style="float: left;margin-right: 0.75em; background: url(data:,%7B%20%22url%22%3A%20%22http%253A%252F%252Fkrebsonsecurity.com%252F2011%252F12%252Fbugs-money%252F%22%2C%20%22shorturl%22%3A%20%22http%3A%2F%2Fbit.ly%2FuKQZ6P%22%2C%20%22style%22%3A%20%22big%22%2C%20%22title%22%3A%20%22Bugs%20Money%22%20%7D);"></div>
<p>Talk about geek chic. <strong>Facebook</strong> has started <a title="Facebook Bug Bounty Program" href="https://www.facebook.com/security/posts/238039389561434" target="_blank">paying researchers</a> who find and report security bugs by issuing them custom branded &#8220;White Hat&#8221; debit cards that can be reloaded with funds each time the researchers discover new flaws.</p>
<div id="attachment_12938" class="wp-caption aligncenter" style="width: 610px"><a href="http://krebsonsecurity.com/wp-content/uploads/2011/12/facebookbugbountycard.png"><img class="size-medium wp-image-12938" title="facebookbugbountycard" src="http://krebsonsecurity.com/wp-content/uploads/2011/12/facebookbugbountycard-600x449.png" alt="" width="600" height="449" /></a><p class="wp-caption-text">Facebook&#39;s Bug Bounty debit card for security researchers who report security flaws in its site and applications.</p></div>
<p>I first read about this card on the Polish IT security portal <a href="http://www.niebezpiecznik.pl" target="_blank">Niebezpiecznik.pl</a>, which recently published an image of a bug bounty card given to <strong>Szymon Gruszecki</strong>, a Polish security researcher and penetration tester. A sucker for most things credit/debit card related, I wanted to hear more from researchers who&#8217;d received the cards.</p>
<p>Like many participants in Facebook&#8217;s program, Gruszecki also is hunting bugs for other companies that offer researchers money in exchange for privately reporting vulnerabilities, including <a title="Google Rewarding Web Application Security" href="http://googleonlinesecurity.blogspot.com/2010/11/rewarding-web-application-security.html" target="_blank">Google</a>, <a title="Mozilla Bug Bounty" href="https://www.mozilla.org/security/bug-bounty.html" target="_blank">Mozilla</a>, <a title="CCBill Vulnerability Reward Program" href="http://www.ccbill.com/developers/security/vulnerability-reward-program.php" target="_blank">CCBill</a> and <a title="Piwik Security" href="http://piwik.org/security/" target="_blank">Piwik</a>. That&#8217;s not to say he only finds bugs for money.</p>
<p>&#8220;I regularly report Web app vulnerabilities to various companies [that don't offer bounties], including Microsoft, Apple, etc.,&#8221; Gruszecki wrote in an email exchange.</p>
<p>The bug bounty programs are a clever way for Internet-based companies to simultaneously generate goodwill within the security community and to convince researchers to report bugs privately. Researchers are rewarded if their bugs can be confirmed, and if they give the affected companies time to fix the flaws before going public with the information.</p>
<p>As an added bonus, some researchers &#8212; like Gruszecki &#8212; choose not to disclose the bugs at all.</p>
<p><span id="more-12688"></span>&#8220;My rule #1 as participant of bug bounties: Don&#8217;t tell details about reported bugs,&#8221; he replied, when asked about the details behind his most recent Facebug find. &#8220;This is my personal decision, but perhaps in the future I change my mind. So I prefer to fix the bugs silently, but it&#8217;s nice that they can mention about me by putting my name on their <a title="Facebook Whitehat List" href="https://www.facebook.com/whitehat/" target="_blank">White Hat list</a>.&#8221;</p>
<p>Gurszecki said that as cool as the White Hat card is, he has asked Facebook to send his earnings another way, saying that using the card carried too many fees in his country.</p>
<p>&#8220;I have found the card is too expensive to use in Poland, and chose another way to get my reward,&#8221; he said. &#8220;The Facebook team sent me the card only as a souvenir.&#8221;</p>
<p><strong>Neal Poole</strong>, a junior at Brown University, has reported close to a dozen flaws to Facebook, and also recently received a White Hat card. Poole has earned cash reporting flaws to Google and Mozilla, but unlike Gruszecki he <a href="https://nealpoole.com/blog/category/vulnerability-writeups/" target="_blank">blogs about each vulnerability</a> he finds after they are fixed, detailing every step of his discovery and interaction with the affected vendor.</p>
<p>Poole&#8217;s research and diligent write-ups eventually caught the attention of Facebook&#8217;s recruiters: Next summer, he&#8217;ll be interning at Facebook, working directly with the company&#8217;s security team.</p>
<p>The New York native welcomed the bug bounty card, which makes it a bit easier to get paid. Initially, he&#8217;d asked to be paid via Western Union, but he ended up having the payment sent via PayPal. Now he just takes the card into <strong>JP Morgan Chase</strong> (the issuer of the card) and has them dump the cash into his bank account. &#8220;It was a little confusing at first for the people at my bank. They&#8217;d never seen one of these cards before.&#8221;</p>
<p>The young researcher said although the White Hat card definitely carries some geek cred, he won&#8217;t be flashing it at security conferences to buy drinks for his contemporaries anytime soon.</p>
<p>&#8220;I don&#8217;t think I&#8217;d want to use card like that at [hacker conventions like] Black Hat or DefCon,&#8221; Poole said. &#8220;It&#8217;d probably get cloned, or I&#8217;d feel like if you pulled out the card it you would immediately become a target.&#8221;</p>

]]></content:encoded>
			<wfw:commentRss>http://krebsonsecurity.com/2011/12/bugs-money/feed/</wfw:commentRss>
		<slash:comments>14</slash:comments>
		</item>
		<item>
		<title>Loopholes in Verified by Visa &amp; SecureCode</title>
		<link>http://krebsonsecurity.com/2011/12/loopholes-in-verified-by-visa-securecode/</link>
		<comments>http://krebsonsecurity.com/2011/12/loopholes-in-verified-by-visa-securecode/#comments</comments>
		<pubDate>Fri, 02 Dec 2011 19:37:38 +0000</pubDate>
		<dc:creator>BrianKrebs</dc:creator>
				<category><![CDATA[Other]]></category>
		<category><![CDATA[Web Fraud 2.0]]></category>
		<category><![CDATA[3 Domain Secure]]></category>
		<category><![CDATA[3DS]]></category>
		<category><![CDATA[Carder.pro]]></category>
		<category><![CDATA[MasterCard SecureCode]]></category>
		<category><![CDATA[Rik Ferguson]]></category>
		<category><![CDATA[trend micro]]></category>
		<category><![CDATA[Verified by Visa]]></category>

		<guid isPermaLink="false">http://krebsonsecurity.com/?p=12721</guid>
		<description><![CDATA[Trend Micro's Rik Ferguson posted a good piece on Thursday about a major shortcoming in credit card security programs maintained by MasterCard and Visa. Although the loophole that Ferguson highlighted may be unsettling to some, fraudsters who specialize in stealing and using stolen credit cards online have been exploiting it for years.]]></description>
			<content:encoded><![CDATA[
<div class="topsy_widget_data topsy_theme_silver" style="float: left;margin-right: 0.75em; background: url(data:,%7B%20%22url%22%3A%20%22http%253A%252F%252Fkrebsonsecurity.com%252F2011%252F12%252Floopholes-in-verified-by-visa-securecode%252F%22%2C%20%22shorturl%22%3A%20%22http%3A%2F%2Fbit.ly%2FsmZYhU%22%2C%20%22style%22%3A%20%22big%22%2C%20%22title%22%3A%20%22Loopholes%20in%20Verified%20by%20Visa%20%26%20SecureCode%22%20%7D);"></div>
<p>Trend Micro&#8217;s <strong>Rik Ferguson </strong>posted a good piece on Thursday about a major shortcoming in credit card security programs maintained by <strong>MasterCard</strong> and <strong>Visa</strong>. Although the loophole that Ferguson highlighted may be unsettling to some, fraudsters who specialize in stealing and using stolen credit cards online have been exploiting it for years.</p>
<p><a class="lightbox" href="http://krebsonsecurity.com/wp-content/uploads/2011/12/scenroll.png"><img class="alignright size-medium wp-image-12723" title="scenroll" src="http://krebsonsecurity.com/wp-content/uploads/2011/12/scenroll-300x159.png" alt="" width="300" height="159" /></a>At issue is a security protocol called &#8220;3 Domain Secure,&#8221; (3DS), a program designed to reduce card fraud and shift liability for fraud from online merchants to the card issuing banks. Visa introduced the program in 2001, branding it &#8220;Verified by Visa,&#8221; and MasterCard has a similar program in place called &#8220;SecureCode.&#8221;</p>
<p>Cardholders who chose to participate in the programs can register their card by entering the card number, filling in their ZIP code and birth date, and picking a passcode. When a cardholder makes a purchase at a site that uses 3DS, he enters the code, which is verified by the issuing bank and is never shared with the merchant site.</p>
<p>But as Ferguson notes, people are human and tend to forget things, especially passcodes and passwords, and it is the password reset function that eliminates any security provided by Verified by Visa or SecureCode. From <a title="Countermeasures blog: Verified by Visa?" href="http://countermeasures.trendmicro.eu/verified-by-visa/" target="_blank">his blog</a>:</p>
<p>&#8220;<em>What would a criminal do if they access to your card details but not your password? Of course, there’s that handy “I forgot my password” link. Let’s see how well protected that is.&#8221;</em></p>
<p><a class="lightbox" href="http://krebsonsecurity.com/wp-content/uploads/2011/12/secondstep.png"><img class="alignleft size-medium wp-image-12724" title="secondstep" src="http://krebsonsecurity.com/wp-content/uploads/2011/12/secondstep-273x300.png" alt="" width="273" height="300" /></a><em>The first step in the password reset procedure is to enter your card number, obviously to ensure you are resetting the password for the correct account. Once that number is entered the system now requires some corroborating data to be sure that you are the legitimate account holder, let’s have a look at that “Identification” phase.&#8221;</em></p>
<p><em>&#8220;Oh noes, this doesn’t look good at all! Three out of four of the items of information used to verify my identity are <strong>all contained in the credit card data itself</strong>, embossed or printed on the card and contained in the magnetic stripe data. Wouldn’t the criminal already have access to this? So what remains? One piece of information that is not included on the card. Trouble is, it’s information that is not only widely shared on social networks, surveys, sign-up forms and a myriad of other places, but also freely available in public records. We cannot and should not consider our date of birth to be a secret.&#8221;</em></p>
<p><em>&#8220;Having entered the required information all that remains is to enter a new password of your choosing and your transaction is authorised. Worse still, no email notification is sent to alert the cardholder that their account has been accessed or modified. The cardholder need never know until they check their statements.&#8221;</em></p>
<p>This would all be very shocking if it wasn&#8217;t already painfully obvious to today&#8217;s cyber crooks. When I read the Trend blog post, I began searching for several screen shots I had taken of a discussion on an underground carding forum more than two years ago, which explained very clearly how to get around this added level of card security. The tutorial in the screen shot below was posted by an administrator from the carding forum <strong>carder.pro</strong> on Halloween, 2009:</p>
<p><span id="more-12721"></span></p>
<p><a class="lightbox" href="http://krebsonsecurity.com/wp-content/uploads/2011/12/vbvhaha.png"><img class="aligncenter size-full wp-image-12725" title="vbvhaha" src="http://krebsonsecurity.com/wp-content/uploads/2011/12/vbvhaha.png" alt="" width="598" height="380" /></a></p>
<p>Programs like these are a good example of security that is designed to make people feel more secure but that add little in the way of real security, or merely shift the risk to another party. Supporters of 3DS would do well to adopt the password reset advice offered in the Trend post, and to absorb the main points in a paper released last year by researchers at the University of Cambridge, &#8220;<a title="Securecode paper (PDF)" href="http://www.cl.cam.ac.uk/~rja14/Papers/fc10vbvsecurecode.pdf" target="_blank">Verified by Visa and MasterCard SecureCode: How Not to Design Authentication</a>&#8221; (PDF).</p>

]]></content:encoded>
			<wfw:commentRss>http://krebsonsecurity.com/2011/12/loopholes-in-verified-by-visa-securecode/feed/</wfw:commentRss>
		<slash:comments>33</slash:comments>
		</item>
		<item>
		<title>How Much is That Phished PayPal Account?</title>
		<link>http://krebsonsecurity.com/2011/10/how-much-is-that-phished-paypal-account/</link>
		<comments>http://krebsonsecurity.com/2011/10/how-much-is-that-phished-paypal-account/#comments</comments>
		<pubDate>Wed, 05 Oct 2011 04:03:21 +0000</pubDate>
		<dc:creator>BrianKrebs</dc:creator>
				<category><![CDATA[Other]]></category>
		<category><![CDATA[Web Fraud 2.0]]></category>
		<category><![CDATA[blackservice.su]]></category>
		<category><![CDATA[Gambit Systems]]></category>
		<category><![CDATA[iProfit.su]]></category>
		<category><![CDATA[Paypal]]></category>

		<guid isPermaLink="false">http://krebsonsecurity.com/?p=11737</guid>
		<description><![CDATA[Compromised PayPal accounts are a valuable commodity in the criminal underground, and crooks frequently trade them in shadowy online forums. But it wasn't until recently that I finally encountered a proper Web site dedicated to selling hacked PayPal accounts.

Many of the PayPal accounts for sale at iProfit.su have a zero balance, but according to the proprietor of this shop these are all "verified." PayPal "verifies" an account when a customer agrees to attach a bank account to it; PayPal then sends a micropayment the bank account, and asks the user the value of that mini deposit. A bonus feather: all the hacked PayPal profiles currently for sale at iProfit.su are advertised as having a credit card attached to them, which is another way PayPal accounts can be verified.

The creator of iProfit.su also advertises private, bulk sales of unverified PayPal accounts; currently he is selling these at $50 per 100 accounts - a bargain at only 50 cents apiece.]]></description>
			<content:encoded><![CDATA[
<div class="topsy_widget_data topsy_theme_silver" style="float: left;margin-right: 0.75em; background: url(data:,%7B%20%22url%22%3A%20%22http%253A%252F%252Fkrebsonsecurity.com%252F2011%252F10%252Fhow-much-is-that-phished-paypal-account%252F%22%2C%20%22shorturl%22%3A%20%22http%3A%2F%2Fbit.ly%2FmX5Jt0%22%2C%20%22style%22%3A%20%22big%22%2C%20%22title%22%3A%20%22How%20Much%20is%20That%20Phished%20PayPal%20Account%3F%22%20%7D);"></div>
<p>Compromised <strong>PayPal</strong> accounts are a valuable commodity in the criminal underground, and crooks frequently trade them in shadowy online forums. But it wasn&#8217;t until recently that I finally encountered a proper Web site dedicated to selling hacked PayPal accounts.</p>
<div id="attachment_11743" class="wp-caption aligncenter" style="width: 610px"><a class="lightbox" href="http://krebsonsecurity.com/wp-content/uploads/2011/10/paypalshop2.png"><img class="size-full wp-image-11743" title="paypalshop2" src="http://krebsonsecurity.com/wp-content/uploads/2011/10/paypalshop2.png" alt="" width="600" height="393" /></a><p class="wp-caption-text">Compromised PayPal accounts for sale at iProfit.su</p></div>
<p>Many of the PayPal accounts for sale at<strong> iProfit.su</strong> have a zero balance, but according to the proprietor of this shop these are all &#8220;verified.&#8221; PayPal &#8220;verifies&#8221; an account when a customer agrees to attach a bank account to it; PayPal then sends a micropayment the bank account, and asks the user the value of that mini deposit. A bonus feature: all the hacked PayPal profiles currently for sale at iProfit.su are advertised as having a credit card attached to them, which is another way PayPal accounts can be verified.</p>
<p>The creator of iProfit.su also advertises private, bulk sales of unverified PayPal accounts; currently he is selling these at $50 per 100 accounts &#8211; a bargain at only 50 cents apiece.</p>
<p>Accounts are sold with or without email access (indicated by the &#8220;email&#8221; heading in the screenshot above): Accounts that come with email access include the username and password of the victim&#8217;s email account that they used to register at PayPal, the site&#8217;s proprietor told me via instant message. The creator of iProfit.su told me the accounts for sale were stolen via phishing attacks, but the fact that accounts are being sold along with email access suggests that at least some of the accounts are being hijacked by password-stealing computer Trojans on account holders&#8217; PCs.</p>
<p><span id="more-11737"></span></p>
<p>It&#8217;s not clear how this guy prices the verified PayPal accounts. In the accounts I saw advertised (see screenshot above), the prices started at $2.50 for verified accounts with a balance from $0 to $10. Higher-balance verified accounts appear to be priced at between 8 to 12 percent of their total balance. For example, one account &#8212; apparently taken from a hapless victim named Abigail &#8212; has a current balance of $121.07, and is being sold for $15.</p>
<p>Another account, from Gwynn in Tallmadge (Ohio?) has a hefty balance of $1,102.37; its sale price was set at $45. Taking a look at the domain name in Gwynn&#8217;s email address, I decided she must work at or for <a title="Gambit Systems" href="http://www.gambit.net/index2.asp" target="_blank">Gambit Systems</a>, a software development firm in Akron, Ohio. I  sent an email to the administrator at that company, who passed on the information and confirmed that PayPal had since locked down Gwynn&#8217;s account.</p>
<p>The proprietors of iProfit.su also run <strong>blackservice.su</strong>, a &#8220;carding&#8221; forum where members can sell all kinds of stolen goods and illegal services, from stolen credit cards to services that will look up Social Security numbers and birthdays. Readers may have noticed that both of the Web sites mentioned in this story end with the &#8220;.su&#8221; top-level domain (TLD): This TLD identifies the Soviet Union; it&#8217;s a holdover from the country-code TLD that was created for the Soviet Union in 1990. It was long considered dead, but .su is <a href="http://tech.slashdot.org/story/08/04/19/230208/su-lives-on-stronger-than-ever" target="_blank">now quite popular</a>, particularly among sites catering to Russian-language cybercrime forums.</p>
<span id="last"></span><div id="slidebox"><a class="close"></a></p>
<h4>Have you seen:</h4>
<p><a title="Vendor of Stolen Bank Cards Hacked" href="http://krebsonsecurity.com/2011/08/vendor-of-stolen-bank-cards-hacked/" target="_blank">Vendor of Stolen Bank Cards Hacked</a>&#8230;I recently wrote about an online service that was selling access to stolen credit and debit card data. That post received a lot of attention, but criminal bazaars are a dime a dozen. The real news is that few of these fraud shops are secure enough to keep their stock of stolen data from being pilfered by thieves.</p>
<p></div>

]]></content:encoded>
			<wfw:commentRss>http://krebsonsecurity.com/2011/10/how-much-is-that-phished-paypal-account/feed/</wfw:commentRss>
		<slash:comments>65</slash:comments>
		</item>
		<item>
		<title>22 Reasons to Patch Your Windows PC</title>
		<link>http://krebsonsecurity.com/2011/08/22-reasons-to-patch-your-windows-pc/</link>
		<comments>http://krebsonsecurity.com/2011/08/22-reasons-to-patch-your-windows-pc/#comments</comments>
		<pubDate>Tue, 09 Aug 2011 20:15:13 +0000</pubDate>
		<dc:creator>BrianKrebs</dc:creator>
				<category><![CDATA[Other]]></category>
		<category><![CDATA[Time to Patch]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[MS11-057]]></category>
		<category><![CDATA[MS11-058]]></category>

		<guid isPermaLink="false">http://krebsonsecurity.com/?p=11067</guid>
		<description><![CDATA[Microsoft today released 13 software updates to fix at least 22 security flaws in its Windows operating system and other software. Two of the flaws addressed in the August patch batch earned Microsoft's most dire "critical" rating, meaning that attackers can exploit them to break into systems without any help from users.]]></description>
			<content:encoded><![CDATA[
<div class="topsy_widget_data topsy_theme_silver" style="float: left;margin-right: 0.75em; background: url(data:,%7B%20%22url%22%3A%20%22http%253A%252F%252Fkrebsonsecurity.com%252F2011%252F08%252F22-reasons-to-patch-your-windows-pc%252F%22%2C%20%22style%22%3A%20%22big%22%2C%20%22title%22%3A%20%2222%20Reasons%20to%20Patch%20Your%20Windows%20PC%22%20%7D);"></div>
<p><strong>Microsoft</strong> today released 13 software updates to fix at least 22 security flaws in its <strong>Windows</strong> operating systems and other software. Two of the flaws addressed in the August patch batch earned Microsoft&#8217;s most dire &#8220;critical&#8221; rating, meaning that attackers can exploit them to break into systems without any help from users.</p>
<p><a href="http://krebsonsecurity.com/wp-content/uploads/2010/01/winicon.jpg"><img class="alignright size-full wp-image-409" title="winicon" src="http://krebsonsecurity.com/wp-content/uploads/2010/01/winicon.jpg" alt="" width="139" height="123" /></a>Among the critical updates is <a title="MS11-057" href="http://go.microsoft.com/fwlink/?LinkID=221946" target="_blank">a cumulative patch for Internet Explorer</a> that plugs at least five security holes in the browser. The update is considered critical for IE versions 7, 8 and 9 (oddly enough, it earned an overall &#8220;important&#8221; rating on the insecure IE6).</p>
<p>The other critical patch fixes <a title="MS11-058" href="http://www.microsoft.com/technet/security/bulletin/ms11-058.mspx" target="_blank">a serious problem with the DNS server</a> built into <strong>Windows Server 2003</strong> and <strong>Windows Server 2008</strong> systems (consumer systems such as Windows XP, Vista and Windows 7 are not affected by the flaw). Although the DNS bug is rated critical, Microsoft considers it unlikely that attackers will develop functioning code to exploit the flaw.</p>
<p>Nine other flaws earned Microsoft&#8217;s <a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx" target="_blank">important rating</a>, and six of those ranked high on Microsoft&#8217;s <a title="exploitability index" href="http://technet.microsoft.com/en-us/security/cc998259.aspx" target="_blank">exploitability index</a>, meaning the company believes it is likely that attackers will develop code designed to exploit them to break into Windows PC</p>
<p>As always, if you experience any issues during or after applying the updates, please leave a note in the comment section about it. A summary of all patches released today is available <a href="http://www.microsoft.com/technet/security/bulletin/ms11-aug.mspx" target="_blank">at this link</a>.</p>

]]></content:encoded>
			<wfw:commentRss>http://krebsonsecurity.com/2011/08/22-reasons-to-patch-your-windows-pc/feed/</wfw:commentRss>
		<slash:comments>31</slash:comments>
		</item>
		<item>
		<title>New Tool Keeps Censors in the Dark</title>
		<link>http://krebsonsecurity.com/2011/08/new-tool-keeps-censors-in-the-dark/</link>
		<comments>http://krebsonsecurity.com/2011/08/new-tool-keeps-censors-in-the-dark/#comments</comments>
		<pubDate>Tue, 02 Aug 2011 04:43:12 +0000</pubDate>
		<dc:creator>BrianKrebs</dc:creator>
				<category><![CDATA[Other]]></category>
		<category><![CDATA[DynaWeb]]></category>
		<category><![CDATA[Telex]]></category>
		<category><![CDATA[Tor]]></category>

		<guid isPermaLink="false">http://krebsonsecurity.com/?p=10935</guid>
		<description><![CDATA[A new approach to overcoming state-level Internet censorship relies, ironically enough, on a technique that security experts have frequently associated with government surveillance. Current anti-censorship technologies, including the services Tor and Dynaweb, direct connections to restricted websites through a network of encrypted proxy servers, with the aim of hiding who&#8217;s visiting such sites from censors. [...]]]></description>
			<content:encoded><![CDATA[
<div class="topsy_widget_data topsy_theme_silver" style="float: left;margin-right: 0.75em; background: url(data:,%7B%20%22url%22%3A%20%22http%253A%252F%252Fkrebsonsecurity.com%252F2011%252F08%252Fnew-tool-keeps-censors-in-the-dark%252F%22%2C%20%22style%22%3A%20%22big%22%2C%20%22title%22%3A%20%22New%20Tool%20Keeps%20Censors%20in%20the%20Dark%22%20%7D);"></div>
<p>A new approach to overcoming state-level Internet censorship relies, ironically enough, on a technique that security experts have frequently associated with government surveillance.</p>
<p><a href="http://krebsonsecurity.com/wp-content/uploads/2011/08/credtech.png"><img class="alignright size-full wp-image-10990" title="credtech" src="http://krebsonsecurity.com/wp-content/uploads/2011/08/credtech.png" alt="" width="224" height="243" /></a>Current anti-censorship technologies, including the services <a title="TorProject" href="https://www.torproject.org/" target="_blank">Tor</a> and <a title="DynaWeb" href="http://www.dongtaiwang.com/loc/download_en.php" target="_blank">Dynaweb</a>, direct connections to restricted websites through a network of encrypted proxy servers, with the aim of hiding who&#8217;s visiting such sites from censors. But the censors are constantly searching for and blocking these proxies. A new scheme, called <strong>Telex</strong>, makes it harder for censors to block communications by disguising traffic destined for restricted sites as traffic meant for popular, uncensored websites. It does this by employing the same method of analyzing packets of data that censors often use.</p>
<p>&#8220;To route around state-level Internet censorship, people have relied on proxy servers outside of the country doing the censorship,&#8221; says <strong>J. Alex Halderman</strong>, assistant professor of electrical engineering and computer science at the University of Michigan. &#8220;The difficulty there is, you have to communicate to those people where the proxies are, and it&#8217;s very hard to do that without also letting the government censors figure out where the proxies are.&#8221;</p>
<p>The Telex system has two major components: &#8220;stations&#8221; at dozens of Internet service providers (ISPs)—the stations connect traffic from inside nations that censor to the rest of the Internet—and the Telex client software program that runs on the computers of people who want to avoid censorship.</p>
<p><em>This is an excerpt from a piece I wrote that was published today in <strong>MIT Technology Review</strong>. Read the full story <a href="http://www.technologyreview.com/communications/38207/?p1=A1" target="_blank">here</a>.</em></p>

]]></content:encoded>
			<wfw:commentRss>http://krebsonsecurity.com/2011/08/new-tool-keeps-censors-in-the-dark/feed/</wfw:commentRss>
		<slash:comments>10</slash:comments>
		</item>
		<item>
		<title>More Than 100 Arrested in Fake Internet Sales</title>
		<link>http://krebsonsecurity.com/2011/07/more-than-100-arrested-in-fake-internet-sales/</link>
		<comments>http://krebsonsecurity.com/2011/07/more-than-100-arrested-in-fake-internet-sales/#comments</comments>
		<pubDate>Fri, 15 Jul 2011 15:18:56 +0000</pubDate>
		<dc:creator>BrianKrebs</dc:creator>
				<category><![CDATA[Other]]></category>
		<category><![CDATA[Adevarul.no]]></category>
		<category><![CDATA[fbi]]></category>
		<category><![CDATA[justice department]]></category>
		<category><![CDATA[moneygram]]></category>
		<category><![CDATA[Râmnicu Vâlcea]]></category>
		<category><![CDATA[Romania]]></category>
		<category><![CDATA[western union]]></category>
		<category><![CDATA[wired.com]]></category>

		<guid isPermaLink="false">http://krebsonsecurity.com/?p=10734</guid>
		<description><![CDATA[Law enforcement officials in Romania and the United States arrested and charged more than 100 individuals in connection with an organized fraud ring that used phony online auctions for cars, boats and other high-priced items to bilk consumers out of at least $10 million.]]></description>
			<content:encoded><![CDATA[
<div class="topsy_widget_data topsy_theme_silver" style="float: left;margin-right: 0.75em; background: url(data:,%7B%20%22url%22%3A%20%22http%253A%252F%252Fkrebsonsecurity.com%252F2011%252F07%252Fmore-than-100-arrested-in-fake-internet-sales%252F%22%2C%20%22style%22%3A%20%22big%22%2C%20%22title%22%3A%20%22More%20Than%20100%20Arrested%20in%20Fake%20Internet%20Sales%22%20%7D);"></div>
<p>Law enforcement officials in Romania and the United States have arrested and charged more than 100 individuals in connection with an organized fraud ring that used phony online auctions for cars, boats and other high-priced items to bilk consumers out of at least $10 million.</p>
<p>According to <a title="Organized Romanian Criminal Groups Targeted by DOJ and Romanian Law Enforcement" href="http://www.justice.gov/opa/pr/2011/July/11-crm-926.html" target="_blank">a statement</a> from the Justice Department, the scams run by this ring followed a familiar script. Conspirators located in Romania would post items for sale such as cars, motorcycles and boats on Internet auction and online websites. They would instruct interested buyers to wire transfer the purchase money to a fictitious name they claimed to be an employee of an escrow company. Once the victim wired the funds, the co-conspirators in Romania would text information about the wire transfer to co-conspirators in the United States known as “arrows” to enable them to retrieve the wired funds. They would also provide the arrows with instructions as to where to send the funds after retrieval.</p>
<p><span id="more-10734"></span>The arrows in the United States would then visit wire transfer services such as <strong>Western Union</strong> or <strong>MoneyGram</strong>, provide false documents including passports and drivers’ licenses in the name of the recipient of the wire transfer, and grab the cash. They would subsequently wire the funds overseas, typically to individuals in Romania, minus a percentage kept for commissions. The victims would not receive the items they believed they were purchasing. In some cases, co-conspirators in Romania also directed arrows to provide bank accounts in the United States where larger amounts of funds could be wired by victims of the fraud.</p>
<p>Since February 2011, FBI agents and U.S. Justice Department authorities in Florida, Pennsylvania and Texas have arrested or charged at least 21 Romanians and Moldovans in the U.S. who were allegedly members of the ring. Thirteen of those charged have pleaded guilty, and three remain at large.</p>
<p>The Bucharest news agency <strong>Adevarul.ro</strong> has <a title="Google translated version of Adevarul story" href="http://translate.google.com/translate?js=n&amp;prev=_t&amp;hl=en&amp;ie=UTF-8&amp;layout=2&amp;eotf=1&amp;sl=ro&amp;tl=en&amp;u=http%3A%2F%2Fwww.adevarul.ro%2Flocale%2Fbucuresti%2FPerchezitii_in_Capitala_si_in_opt_orase_90_de_hoti_prinsi_de_FBI_si_adusi_la_DIICOT-_au_furat_pe_internet-de_la_americani-peste_20_de_milioane_de_dolari_0_517148293.html" target="_blank">more details</a> on the 90 Romanians arrested by authorities there in nine different cities. The Romanian authorities say the group stole almost $20 million, about twice as much as the Justice Department estimates.</p>
<p>Some of the Romanians arrested were from the town of <a href="http://maps.google.com/maps?q=R%C3%A2mnicu+V%C3%A2lcea,+V%C3%A2lcea,+Romania&amp;oe=UTF-8&amp;ie=UTF8&amp;hl=en&amp;geocode=FVI-sAIdBPFzAQ&amp;split=0&amp;sll=37.0625,-95.677068&amp;sspn=23.875,57.630033&amp;hq=&amp;hnear=R%C3%A2mnicu+V%C3%A2lcea,+V%C3%A2lcea,+Romania&amp;ll=45.104546,24.367676&amp;spn=10.932144,17.687988&amp;z=6">Râmnicu Vâlcea</a>, a location that has become synonymous with online auction fraud. In January, <em>Wired</em> published <a title="How a Remote Town in Romania Has Become Cybercrime Central" href="http://www.wired.com/magazine/2011/01/ff_hackerville_romania/all/1" target="_blank">a fascinating and readable article</a> on how this remote town of 120,000 residents has become cybercrime central, earning the town the nickname &#8220;hackerville.&#8221;</p>

]]></content:encoded>
			<wfw:commentRss>http://krebsonsecurity.com/2011/07/more-than-100-arrested-in-fake-internet-sales/feed/</wfw:commentRss>
		<slash:comments>10</slash:comments>
		</item>
		<item>
		<title>Spammers Sell More Non-Lifestyle Drugs in U.S.</title>
		<link>http://krebsonsecurity.com/2011/07/spammers-sell-more-non-lifestyle-drugs-in-u-s/</link>
		<comments>http://krebsonsecurity.com/2011/07/spammers-sell-more-non-lifestyle-drugs-in-u-s/#comments</comments>
		<pubDate>Tue, 12 Jul 2011 00:47:57 +0000</pubDate>
		<dc:creator>BrianKrebs</dc:creator>
				<category><![CDATA[A Little Sunshine]]></category>
		<category><![CDATA[Other]]></category>
		<category><![CDATA[Chris Kanich]]></category>
		<category><![CDATA[MIT Technology Review]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[UCSD]]></category>

		<guid isPermaLink="false">http://krebsonsecurity.com/?p=10648</guid>
		<description><![CDATA[Spam may be synonymous with male enhancement drugs, but new research shows that Americans are far more likely than buyers in other countries to turn to spam-advertised pharmacies to obtain pills to treat serious ailments–a trend that reflects differences in government health care and prescription drug policies. Researchers at the University of California, San Diego, [...]]]></description>
			<content:encoded><![CDATA[
<div class="topsy_widget_data topsy_theme_silver" style="float: left;margin-right: 0.75em; background: url(data:,%7B%20%22url%22%3A%20%22http%253A%252F%252Fkrebsonsecurity.com%252F2011%252F07%252Fspammers-sell-more-non-lifestyle-drugs-in-u-s%252F%22%2C%20%22style%22%3A%20%22big%22%2C%20%22title%22%3A%20%22Spammers%20Sell%20More%20Non-Lifestyle%20Drugs%20in%20U.S.%22%20%7D);"></div>
<p>Spam may be synonymous with male enhancement drugs, but new research shows that Americans are far more likely than buyers in other countries to turn to spam-advertised pharmacies to obtain pills to treat serious ailments–a trend that reflects differences in government health care and prescription drug policies.</p>
<p>Researchers at the University of California, San Diego, have collected the first data showing which drugs consumers most often buy from spam advertisements, and how much they spend at shadowy online apothecaries.</p>
<p>&#8220;People are going to them when they&#8217;re either too embarrassed to talk to a doctor, or when it would be far too expensive to buy these drugs otherwise,&#8221; said <strong>Chris Kanich</strong>, a PhD candidate at UCSD&#8217;s computer science department, and lead researcher of the study.</p>
<p>Previous estimates of monthly revenue from spam have varied dramatically, from $300,000 to more than $58 million. The UCSD researchers found that the largest rogue Internet pharmacies generate between $1 million and $2.5 million in sales each month, although they caution that their estimates are conservative.</p>
<p>Kanich says the figures show that although the spam-advertised market is substantial, it is not nearly as big as some have claimed, and falls short of annual expenditures on technical anti-spam solutions by corporations and ISPs.<br />
<em><br />
This is an excerpt from a piece I wrote that was published today in <strong>MIT Technology Review</strong>. Read the full story <a href="http://www.technologyreview.com/web/38023/?p1=A3" target="_blank">here</a>. The UCSD paper is available at <a title="Show Me the Money: Characterizing Spam-Advertised Revenue" href="http://cseweb.ucsd.edu/~savage/papers/UsenixSec11-SMTM.pdf" target="_blank">this link</a> (PDF).<br />
</em></p>
<p><a href="http://krebsonsecurity.com/wp-content/uploads/2011/07/ucsdspamrevenue.jpg"><img class="aligncenter size-full wp-image-10671" title="ucsdspamrevenue" src="http://krebsonsecurity.com/wp-content/uploads/2011/07/ucsdspamrevenue.jpg" alt="" width="600" height="227" /></a></p>

]]></content:encoded>
			<wfw:commentRss>http://krebsonsecurity.com/2011/07/spammers-sell-more-non-lifestyle-drugs-in-u-s/feed/</wfw:commentRss>
		<slash:comments>10</slash:comments>
		</item>
	</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached (User agent is rejected)
Database Caching 1/40 queries in 0.012 seconds using memcached
Object Caching 1303/1405 objects using memcached

Served from: krebsonsecurity.com @ 2012-02-11 12:46:38 -->
