Thursday, March 19, 2009

I got you once, and I will get you again!

"If a fraudster or fraud ring can successfully perpetrate fraud, you can pretty much assume they will continue to do so until you stop them." D.Montague

Red Bank, Oct. 30 2008/The FraudBlog Newsletter/- While the article, "The Hackers Mindset - I did nothing Wrong" by Jon Swartz of USA Today is not new news, it can provide good insight into the makeup of a cybercriminal. It focuses primarily on the TJX hackers and provides the typical definition of a cybercriminal as being young, male and very computer savvy. However typical, I found the background story on Gonzales having been caught before so engrossing I decided to test the profile myself.

So I thought I would take a look at a couple of other major cyber crime cases. In the past 60 days there have been three very public and big cyber crime cases. In these cases the cybercriminal was young, all under 30, male and they were very computer savvy. (Albert Gonzales - TJX Breach, Ehud Tenenbaum - Direct Cash Management Breach, Vladimir Tsastsin- EstDomain)

In all three of these cases the cybercriminal had been caught doing this before. In 2 of the 3 cases, Gonzales and Ehud Tenenbaum these individuals were actually given lighter sentences for their first transgression by working with law enforcement after being caught.

In all of these cases when the cybercriminal was later presented with a weakness in a business's fraud controls or security measures they exploited them. Regardless of the fact that they had been caught before, they believed they wouldn't get caught again. In all three cases they had escalated the scope and level of their schemes.

Lesson learned, they don't learn their lesson.

Use your ATM PIN only at ATMs or you'll pay the price!

Always save your PIN for ATM transactions only!

Red Bank, Sept. 1 2008/The FraudBlog Newsletter/- Every time I speak publicly, or when I tell people what I do for a living, I get asked this question. My answer has always been to use your credit card or your debit card, as a credit card, but save your pin for ATM transactions only. For us in the business we generally understand our rights and level of protection, but I would imagine few of us really understand the actual legal rights and limits for each payment type.

If fraudsters strike, you often have stronger protection with credit cards than with debit cards. With credit cards, under federal law, you're liable for no more than $50 if fraud occurs, though most issuers don't hold you liable for even that much. With debit cards, your maximum exposure is $50 if you report it within 48 hours. Report it after two days, and you could be liable for up to $500. Take longer than 60 days, and you could be responsible for the entire dollar amount of fraud.

When the Fraudster is Someone you Trust

Friendly fraud taken to new heights.

Red Bank, Aug. 15 2008/The FraudBlog Newsletter/- The number of articles related to internal fraud have been rising considerably over the past couple of months. If you are like most fraud managers, your focus has been on stopping the fraudster from coming in the door, and not paying attention to the fraudster lurking inside. It can be easy to overlook how easy it is for employees to copy down customer credit card information, to help a friend exploit a weakness in the companies systems or to directly steal from the company.

While I don't believe the individuals involved in these cases were criminals targeting these companies, I do believe they serve as a good example to putting in checks and balances to keep honest people honest...

To illustrate my point I have taken quotes from a recent case. These quotes were taken from the article "Former Sailor Gets 2 years for fraud with Navy Credit Card" by Austin Wright in the Virginia Post on August 10, 2008.

"I know that I'm a good person. I know that I made a bad decision," Gibbs said in court. "I'm aware of all my consequences.""Her supervisors encouraged this type of behavior," defense attorney David Price said in court. He elaborated after the sentencing that no one monitored what Gibbs and others were purchasing with the government-issued cards."For this to go on for as long as it did and for the amount of money that was involved - there's no excuse," Price said. "There are other people who didn't do their jobs right." Other cases in the news:

Customer Service Representative - An Alaska Airlines call center employee misused credit card data between August 2006 and June of 2008. When processing reservation changes, the employee allegedly diverted payments into her own personal bank account instead of the airline's. The fraud affects about 1,500 customers.

Receptionist - An Illinois Eye Center receptionist used patient information to obtain credit cards and then had the bills mailed to her home. Gast said the theft occurred from August until December of last year. Some of the victims didn't know their names had been used.
Mail Man - four counts of mail theft and one count of defrauding the U.S. Postal Service by using an agency credit card for personal use.

Administrative Assistant - charged more than $240,000 in personal expenses last year on a corporate credit card belonging to a pharmaceutical research and development company, a subsidiary of Johnson & Johnson. Federal prosecutors said she used the card to pay for a 1968 Ford Mustang and 1969 Chevrolet Camaro and to restore those vehicles. She also used company funds to pay for cosmetic surgery and a cruise vacation, a granite kitchen countertop, a residential air-conditioning unit and American Express gift cards..

Candidate for Sheriff - a candidate for the position of Navajo County sheriff, was arrested July 22 on charges of theft of a credit card and fraudulent use of a credit card, both felonies.
Bank Clerk - The clerk allegedly played a role in a conspiracy to embezzle funds from Sperry Marine Federal Credit Union by using other names to take out loans from the credit union.

Neighbor - Buellton California residents 47-year-old Karen Peterson and 49-year-old Debra Mangino are accused of stealing their one-time neighbor's mail and activating a credit card in his name.

Purchasing Agent - Navy sailor uses military credit card to steal hundreds of thousands of dollars from the government. Defense and prosecution lawyers agreed this could have been prevented through minimal oversight. From 2006 to 2007, she used the card to buy 162 notebook computers, 65 big-screen televisions and 22 digital cameras, items she and an unnamed co-conspirator sold for cash.

Father - A New York man says he used his son's Social Security number to obtain credit cards and loans from several banks, and from a firm that gave him loans to buy two cars. The crimes occurred between 1997 and 2005.

Credit Card Fraud Officer - A former senior Sussex Police officer who used his force credit card to buy goods for himself has been ordered to pay nearly £100,000. Sorority Sister - Danielle Sue All, 29, is believed to have charged more than $2,000 on a Purdue University sorority adviser's card reported missing Aug. 5.

Secret Service Informant - charged with breaking into the computer systems of nine of the nation's largest retail companies and stealing more than 40 million credit and debit card numbers.

Tuesday, June 17, 2008

Proxy Detection

Proxy Detection web services allow instant detection of anonymous IP addresses. While the use of a proxy is not a direct indicator of fraudulent behavior, it can be a useful indicator when combined with other data elements to determine if an individual is attempting to hide their true identity. The fact is, some of the most used ISPs, like AOL and MSN, are forms of proxies, and are used by both good and bad consumers.

The fraudsters know, that is very easy to make their IP geolocation information look like it is coming from the region where their stolen credentials originated. This ability makes them look authentic, when in fact they are using a proxy to mask their true location.

Again not all proxies are equal, some are very reputable, and to cut them off would be a death-nail to your sales conversion. The goal is to use this technique to distinguish which proxies are derived from compromised computers, or from proxies that are known to be highly used by fraudsters. The generic ability to identify an anonymous proxy provides little value.

Has Data Breach Legislation actually impacted ID Theft?

According to a recent paper published by Sasha Romanosky, Rahul Telang and Alessandro Acquisti of the Heinz School of Public Policy and Management at Carnegie Mellon University, the data breach legislation instituted from 2002 thru 2006 has had little effect on reducing ID theft.
While the legislation has not reduced ID theft cases the debate is still ongoing if has slowed the rate of increase. It seems the rate of increase is the same in states with legislation and in those without legislation.

A fascinating study showing how the legislation has made companies more aware, vigilant and proactive, but the net result is just plain lacking. Some of the more intersting findings from the paper were:

1. 44% of consumers ignore data breach notices, Choicepoint indicated that only 10% of consumers opted for the free credit watch services.
2. Most companies under estimate the costs associated with a data breach. Choicepoint reported a cost of $26 million related to their data breach and TJ Max reported a cost of 178 million related to their data breach.
3. The impact of a data breach on a companies overall performance, sales and stock performance are temporary typically lasting less than 4 quarters.
To read more on this article go to: "Do Data Breach Disclosure Laws Reduce Identity Theft?".

Monday, June 2, 2008

Telephone Identification

Telephone identifcation is the process of determining the type of phone being used by a consumer or end user. This technique looks up the phone number to determine where it was provisioned, and the type of phone it is associated with.
Telephone identification, or TNI, serves several important functions. First it authenticates that the number is a real "dialable" phone number. Second it will let you know where the phone was provisioned, the country, region, and city. Lastly, and most importantly it will tell you the type of phone the number is assigned to.

To read more on Device Identification: http://www.fraudpractice.com/gl-phoneID.html

PCI Compliance does not Gurantee Protection from breach

While the PCI standards have done a tremndous job at helping to secure sensitive credit card data, organiztions still need to take proactive measures to secure their systems from hacking. There have been several documented cases where PCI compliant organizations have been hacked and card data has been stolen. The most notable recent case involved Hannaford Food stores where 4 million credit cards / debit cards were comprimised when fraudsters loaded malicious software on the companies 300 servers. The software allowed the fraudsters to pull and store credit card and PIN data as it was being processed from the stores.

To read more on this article go to the CS Decisions website and view the May 2008 article from Pat Pape entitled: "Secure your System".