Showing posts with label internet crime. Show all posts
Showing posts with label internet crime. Show all posts

Tuesday, March 15, 2011

US-CERT Provides Advice About Identifying Online Donation Scams

In the aftermath of the tragic earthquake and tsunami in Japan, US-CERT would like to remind users to apply the same caution when e-donating to relief efforts that they would exercise when making any other online transaction.  Cyber criminals have already used email scams as well as fake antivirus and phishing attacks to steal American donations for Japan’s relief efforts.  Phishing emails and websites requesting donations for bogus charitable organizations commonly appear after these types of natural disasters.

US-CERT encourages Internet users to take the following precautions to ensure that their donations end up in the right hands:

Do not follow unsolicited web links or attachments in email messages.
Maintain up-to-date antivirus software.
Refer to the Recognizing and Avoiding Email Scams (pdf) document for additional information on avoiding email scams.
Review the Federal Trade Commission's Charity Checklist.
Verify the legitimacy of the email by contacting the organization directly through a trusted contact number. Trusted contact information can be found on the Better Business Bureau National Charity Report Index.

US-CERT will provide additional information as it becomes available.

Wednesday, March 09, 2011

Online Sexual Predator Arrested

SAN JUAN, PR—On March 8, 2011, MARCOS E. DAVILA-PASCUAL, age 32, was arrested at his residence in Toa Alta, Puerto Rico by FBI agents. DAVILA-PASCUAL is charged with online sexual enticement and coercion of a minor for the purpose of engaging in sexual activity.

The criminal complaint alleges from July 13, 2010 through March 6, 2011, DAVILA-PASCUAL, who used the Internet alias of “Marcos,” met and communicated online with an individual whom he believed was a 15-year-old minor. During his online chatting with the minor, DAVILA-PASCUAL expressed an interest on several occasions in meeting the minor for the purpose of having sex. When chatting online with the minor, DAVILA-PASCUAL used very explicit language in Spanish as to the type of sexual acts he wished to engage and perform with the minor.

The complaint further states DAVILA-PASCUAL was willing to meet and pick up the minor in a vehicle and they could either go to his house, a motel, or have sex in his car. On several occasions, DAVILA-PASCUAL discussed and planned meeting with the minor. On one occasion, after pre-arranging with the minor to meet at a certain location, DAVILA-PASCUAL traveled to a restaurant to meet with the minor, however, the minor never went to the meeting location.

If convicted, the defendant faces a maximum of 10 years’ imprisonment.

Anyone with any relevant information regarding MARCOS E. DAVILA-PASCUAL, or any minors or the parents of a minor who believe that their children may have had contact with him, are strongly encouraged to contact the FBI at (787) 754-6000 or 1-877-324-7577.

This case is being prosecuted by Assistant United States Attorney Dina Avila-Jimenez, and is being investigated by the FBI.

The public is reminded a criminal complaint contains only charges and is not evidence of guilt. A defendant is presumed to be innocent until and unless proven guilty. The U.S. government has the burden of proving guilt beyond a reasonable doubt.

Wednesday, February 23, 2011

Texas Man Pleads Guilty to Hacking into Computer Servers of Local Company and NASA

MINNEAPOLIS—United States Attorneys B. Todd Jones, of the District of Minnesota, and Rod J. Rosenstein, of the District of Maryland, announced that earlier today in federal court in St. Paul, Minnesota, a 26-year-old Texas man pleaded guilty to hacking into computer networks at a Minnesota business and at NASA. Jeremey Parker, of Houston, Texas, pleaded guilty to one count of wire fraud. He was indicted in the District of Minnesota on October 13, 2010.

In his plea agreement, Parker admitted that from December 23, 2008, through October 15, 2009, he hacked into the computer network of SWReg, Inc., a subsidiary of the cyber-based company Digital River, Inc., of Eden Prairie, Minnesota, in an effort to steal money. SWReg. pays independent software developers who write code. Royalties owed to those developers are accumulated at SWReg. The software developers have the ability to go online, view the royalty balances in their SWReg accounts, and, ultimately, cash out those accounts. When a particular developer cashes out an account, SWReg electronically transfers the money to the developer’s bank account, mails the developer a check, or has the developer’s PayPal account credited. Parker hacked into SWReg’s system, created the money by crediting the SWReg accounts, and then caused that money to be wire transferred to his bank account instead of the accounts of several developers. Parker stole approximately $275,000.

In addition, Parker admitted that on September 24, 2009, he hacked into two computer servers at the National Aeronautics and Space Administration’s Goddard Space Flight Center in Greenbelt, Maryland. The servers supported access to data being sent to Earth from satellites gathering oceanographic data. The servers did not have any control over the satellites themselves but, rather, allowed paying members of the scientific community to access the stream of data coming from those satellites. After a period of time, the data was freely available to anyone who wished to log onto a specific NASA website. Once the breach of its computer system was discovered, NASA spent approximately $43,000 to repair the damage. During the time the website was down for repairs, approximately 3,300 users were denied access to the oceanographic data.

Parker was not officially charged in the District of Maryland in connection with the NASA incident, but the two U.S. Attorneys agreed to have the activity treated as relevant conduct for sentencing purposes in the District of Minnesota. For his crimes, Parker faces a potential maximum penalty of 20 years in prison on the wire fraud charge and 10 years on the computer hacking charge. U.S. District Court Judge Richard H. Kyle will determine Parker’s sentence at a future hearing, yet to be scheduled.

The Minnesota case is the result of an investigation by the Federal Bureau of Investigation. It is being prosecuted by Assistant U.S. Attorney John Docherty. The Maryland case was investigated by the NASA Office of Inspector General, and was prosecuted by Assistant U.S. Attorney Bryan Foreman.

The Justice Department vigorously investigates and prosecutes cyber crimes. It created the Task Force on Intellectual Property (http://www.justice.gov/dag/iptaskforce/) to aid in combating intellectual property crimes both at home and abroad. According to the FBI’s Internet Crime Complaint Center’s annual report, the FBI received 22.3 percent more cyber crime complaints in 2009 than in 2008, and the total dollar loss from all cases referred to law enforcement ($559.7 million) was more than twice the 2008 figure ($264.4 million). The FBI and the Minnesota U.S. Attorney’s Office want to remind people to protect themselves from cyber crime. For more information, visit http://www.justice.gov/criminal/cybercrime/index.html.

Monday, February 14, 2011

Internet Crime Complaint Center's (IC3) Scam Alerts

This report, which is based upon information from law enforcement and complaints submitted to the IC3, details recent cyber crime trends and new twists to previously-existing cyber scams.

Social Network Misspelling Scam
During December 2010, the IC3 discovered misspellings of a social network site being used as a social engineering ploy. Misspelling the domain name of this site would redirect users to websites coded to look similar to the actual website. The website users were redirected to answer three or four simple survey questions. Upon answering those questions, users were offered a choice of three free gifts. Multiple brands were observed as being offered as gifts, including gift cards to retail stores and various brands of laptops.

After clicking on one of the gifts, users were further redirected to other websites claiming to give free gifts for completing surveys. The surveys typically asked for name, address, phone number, and e-mail address. A user could spend hours filling out multiple surveys and never receive any of the gifts advertised.

Fake Online Receipt Generator Targets Unsuspecting Online Marketplace Merchant
A new scam aims to swindle online marketplace sellers by generating fake receipts. This Receipt Generator is an executable file that has been circulating on hacking forums recently. This is a particularly interesting scam - because it does not target regular PC users, it targets the sellers on online marketplace websites. This is what the would-be social engineer sees when running the program:

The social engineer can fill in a variety of information, including item name, price, and the date the order was taken. Additionally, it allows them to choose between the .com, .co.uk, .fr, and .ca marketplace portals. When they hit "Generate," an HTML file is created in the program folder which looks like this:

The program produces what appears to be a genuine marketplace receipt and a copy of the "Printable Order Summary," similar to the documents resulting from legitimate marketplace purchases. Note the small details, such as "Total before tax," "Sales tax," and other particulars that make the receipt convincing.

Many sellers on these markets will ask the buyer to send them a copy of the receipt should the buyer run into trouble, have orders go missing, lose the license key for a piece of software, and so on. The scammer relies on the seller to accept the printout at face value without checking the details. After all, how many sellers would be aware someone went to the trouble of creating a fake receipt generator?

Sellers must remain ever vigilant about this scam, which has been a popular topic in recent hacker forums. The VirusTotal detection rate is currently 1/43 – detected as Hacktool.Win32.Amagen.A.

Malicious Code In .gov E-mail
A recent malware campaign, disguised as a holiday greeting from the White House, targeted government employees. The recipient received the below e-mail with links to what masqueraded as a greeting card, but when they clicked on the link, it attempted to download a file named "card.exe." The executable program proved to be an information-stealing Trojan, which would disable the recipient’s computer security notifications, software updates, and firewall settings. The malware also installed itself into the computer’s registry, enabling the code to be executed every time the computer was rebooted. At the time of review, this particular malicious code sample had a low antivirus detection rate of 20%, with only 9 out of 43 antivirus companies reporting detection.

“From: sender@whitehouse.gov [mailto: sender@whitehouse.gov]
Sent: Wednesday, December 22, 2010
To: recipient's name
Subject: Merry Christmas, recipient's name

Recipient’s name here,

As you and your families gather to celebrate the holidays, we wanted to take a moment to send you our greetings. Be sure that we're profoundly grateful for your dedication to duty and wish you inspiration and success in fulfillment of our core mission.

Greeting card:

hxxp://xtremedefenceforce.com/card/
hxxp://elvis.com.au/card/

Merry Christmas!
___________________________________________
Executive Office of the President of the United States
The White House
1600 Pennsylvania Avenue NW
Washington, DC 20500”

For more information regarding online scams visit our Press Room page for the most current Public Service Announcements.

This article was sponsored by Police Books.

Wednesday, April 16, 2008

Public Safety Technology in the News

Online Missing Persons System Unveiled
The Daily Gazette, (04/07/2008), Carl Scribner

In conjunction with the seventh annual New York State Missing Persons Day, specialists from the University of North Texas, Center for Human Identification, gave a presentation on the National Missing and Unidentified Persons System (NamUS) database. The system, operated by the National Institute of Justice (NIJ), will be available in 2009 and will act as a central warehouse of records on unidentified remains and missing person reports. System data will be searched for any possible matches. The system will also use
DNA, gathered from a family member, as a part of the identification process. NIJ plans to provide sample collection kits, requiring a swab inside the mouth of a family member, to family members free of charge. The public can log on to www.namus.gov to view and tour the site and preview the records currently on the system.
www.dailygazette.com/news/2008/apr/07/0407_database/

FBI Unveils N-DEx Rollout
Government Computer News, (04/02/2008), Wilson P. Dizard III

The first increment of the National Data Exchange (N-Dex) Network System has been launched. N-Dex is sponsored by the FBI's
Criminal Justice Information Division. This first increment will allow 50,000 users access to a system that provides Federal, State, tribal, and local law enforcement with the ability to share information that is presently housed in individual agency data systems. Working with law enforcement nationwide, the FBI and Raytheon established the needs of the users and implemented these capabilities in the N-Dex system, which is scheduled for incremental release over the next 3 years. Raytheon indicates that the system will eventually support 200,000 investigators from about 18,000 agencies across Federal, State, tribal, and local jurisdictions.
www.gcn.com/online/vol1_no1/46052-1.html

Internet Scams Cost Consumers $240M
The Mercury News, (04/06/2008), Christine Simmons

The number of reported Internet scams was down last year in comparison to past years, but the dollar amount lost was up by $40 million, to a new high of $240 million, according to a government report that used data gathered from the
Internet Crime Complaint Center. Other statistics from the report indicate an increase in ploys that involved pets, check cashing, and online dating. Furthermore, the amount lost by males was on average higher than females, and the overall amount lost increased with age.
www.mercurynews.com/nationworld/ci_8829968

Electronic Ticketing System Puts
Police in the Fast Lane
Journal & Courier, (04/02/2008), Dorothy Schneider

Indiana State
Police in West Lafayette adopted the use of e-ticketing earlier this year, which allows officers to scan licenses, capture images, and print citations from their cruiser. Once they find funding, other local departments hope to tap into the technology to support the purchase and use of such a system. The system has reduced the amount of time spent by officers issuing citations and warning by about half.
www.jconline.com/apps/pbcs.dll/article?AID=/20080402/NEWS/804020334

Kansas City Crime Lab Gets New Technology
KCTV Kansas City, (04/03/2008)

The
Kansas City (Missouri) Crime Lab has received U.S. Department of Justice funding to help with investigating crimes in the city. One grant has helped the lab hire a full-time network caseworker to handle investigations that involve shell casing evidence. These casing can be checked against the National Ballistics Information Network. The second grant has helped the city purchase two new DNA robots that are capable of collecting and analyzing DNA evidence efficiently.
www.kctv5.com/news/15787833/detail.html

DNA Project Proves Effective in Case of Missing Stewartville Teenager
Post-Bulletin, (04/04/2008), Janice Gregorson

The year-old Minnesota Bureau of
Criminal Apprehension's Missing Persons DNA Project, designed to assist with identifying matches between missing people and unidentified remains, registered its first successful match between a missing teen and year old remains found in Florida. The process relies on DNA fingerprinting to make the matches. This project allows the family of a missing person to obtain closure, while assisting individual departments in solving cases and using resources effectively.
www.postbulletin.com/newsmanager/templates/localnews_story.asp?z=2&a=335852

Old Room, New Purpose
MonroeNews.com, (04/04/2008)

Monroe County (Michigan) Sheriff Tilman Crutchfield is repurposing the vacant central dispatch room and creating a secure
crime lab for his new crime unit. Since the department has investigators trained in the field of forensic computer examination, the department felt that the empty space would give investigators the space necessary to perform their tasks. Although the most prevalent computer crimes are those involving sexual predators, computer crime expands beyond that area. For example, one case being investigated by the unit began online with words and threats, but escalated to an actual physical assault. The creation of this unit signals a shift toward fighting crime of a specialized nature.
www.monroenews.com/apps/pbcs.dll/article?AID=/20080404/NEWS01/506322489/-1/NEWS

The Value of Video System Allows Inmates to Appear in Court Without Ever Leaving Jail
The Eagle-Tribune, James A. Kimble

The installation and use of video conferencing in the Rockingham County (New Hampshire) Superior Court is the subject of debate. Prosecutors and jail officials believe it is needed from a cost savings and improved security standpoint. However, superior court officials see it as useless and costly. Rockingham County jail spends $275 a month on its system, which is wired with district courts in Salem and Portsmouth. Because of the belief in the effectiveness of the system, the Portsmouth District Court was brought onboard using $20,000 in funding from the jails budget. With the rise in the cost of gas and the amount of time needed to transport prisoners, jail officials and county attorneys feel the savings to the county would be significant, especially for those court appearances that are mandatory, but brief in nature. The superior court did have a system in place in 2001; however, the system was only in one court room, and setting up the system and shuttling judges from o! ne court to another was not timely or efficient. For these reasons the system was not used effectively, and was eventually dropped. However, because of changes in costs to support the system, rising gas costs, and the added
security the system would provide, prosecutors and jail officials feel it is time to reevaluate the technology's use in the superior court.
www.eagletribune.com/punewsnh/local_story_096213634.html?keyword=secondarystory

Firearms Training Simulator Gives Police Recruits Experience With Guns in Tough Situations
Daily Freeman, (04/14/2008), Kyle Wind

Using a simulator purchased by Ulster County Community College, the Ulster County (New York)
police academy trains officers and recruits on how to handle tough situations. The scenarios on the system are taken from 500 to 600 real-life situations from throughout the country. System equipment includes a retrofitted 9mm Glock pistol that is connected to the computer, and the computer projects the scenario to a wall or screen. Because the system is connected to the weapon, it can track the officer's shots, as well as muzzle location. This is useful when demonstrating to recruits exact muzzle location during a situation and the concept of muzzle drift. The scenarios also help to improve the trainees' powers of observation, but most importantly they learn in the controlled chaos of the simulation, when it is okay to make mistakes in order to learn. Future features of the system will allow officers the chance to train using less-than-lethal alternatives.
www.dailyfreeman.com/site/news.cfm?newsid=19481099&BRD=1769&PAG=461&dept_id=74969&rfi=6

Lynchburg Police Disappointed Over Silent Partner Alert System Response
The News & Advance, (04/01/2008), Carrie Sidener

Five hundred citizens have signed up to participate in the Silent Partner Alert system implemented by the Lynchburg
Police Department 2 years ago, as opposed to the thousands that the department believed would sign up. The system provides the department with the ability to send mass e-mail messages to subscribers with information about anything from robberies and car crashes on major roads to missing person alerts. The messages can be sent to PDAs, computers, Blackberries, cell phones, or other devices capable of receiving e-mail. Because of the speed with which these alerts can be sent, they can help police solve a crime. Lynchburg was the second department to sign up for the service; currently seven departments in Virginia participate.
www.newsadvance.com/lna/news/local/article/lynchburg_police_disappointed_over_silent_partner_alert_system_response/3831/

Threats Go High-Tech
The Herald, (04/13/2008), Julia Reynolds

The new canvas for threatening gang graffiti is proving to be hard for
police to patrol. Gangs are using the Internet, and specifically sites like YouTube. Police can pull a video from the site quickly if it is identified as a violation of policy. However, for police to act on these threats, the act must "cause victims to fear for their safety," according to Monterey County Deputy Assistant District Attorney Terry Spitz. Another issue is lack of enough resources for police to patrol not only sites like YouTube, but the Web as a whole. Salinas (California) police have a unit of computer forensic investigators that can work on such threats, but unit staff must also handle homicides or other major crime. If during the course of an investigation the threats seem credible, staff notify the victim, but this action is not required by law. These postings can, however, be used by detectives to gather information about local gangs, or as evidence should a crime occur.
origin1.montereyherald.com/news/ci_8909961?nclick_check=1