Internet Domain Registry

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Monday, 20 August 2007

Aggrevated Identity Theft Law in Action

Posted on 06:19 by Unknown
There are so many interesting angles to the story this week about a case in Tucson, Arizona. The conviction actually went down in March 2007, with Jacob Vincent Green-Bressler, now 21 years old, being one of the 16 individuals who had been indicted in 2005 for trafficking in stolen identities. (See: Global Web Fraud Case has 17 Local Indictments in the Arizona Star, November 8, 2005.

Green-Bressler and company were not identity thieves themselves. They were not putting together phishing sites. They instead served in the role of "cashiers". A "cashier" in the Identity Theft business is someone who is willing to perform the risky role of converting the stolen identity information into an ATM Card and using that counterfeit card to drain a bank account.

During their time of activity, Jacob's gang obtained identities for 4,500 individuals from criminal conspirators in at least 20 countries, including Vietnam, Pakistan, Jordan, Egypt, the Philippines, Macedonia, Romania, Estonia, Lebanon, Mexico, France and the United Kingdom. They then used those identities to create counterfeit ATM cards which they used to steal and send overseas nearly $300,000 from various banking accounts. As their commission on these services, Jacob and friends kept $148,000 -- a 50% commission!

So what does this have to do with the Aggravated Identity Theft Law?

Jacob's original sentence would have been sixty months for his crime, but because of Title 18 section 1028A - the Aggravated Identity Theft Act, a mandatory +2 years is added to the jail time. With criminals getting so many light sentences for cyber crimes, its nice to see someone getting the Extra Two.

That's one of the reasons the Attorney General supported this act back in 2002. See this Congressional Testimony from Dan Collins, the Chief Privacy Officer of the US Department of Justice at the time. S.2541, the "Identity Theft Penalty Enforcement Act" was a good idea, and one that should be used more often in the courts.

The full list of defendants in this case:

Robbin Shea Brown, 24
Jacob Vincent Green-Bressler, 19
Joshua Trever Lee Breshears, 20
David Lee Merrill, 25
Corrine Dazette Perez, 24
Richard Daniel Staton, 24
Rollin Edward Vaughn II, 23
Randi Michelle Rodela, 20
Joseph David Wallum, 20
Joseph Robert Jando, 21
Martin Corey Halula, 19
James Dennis Olsen, 19
Steven Don Olsen, 23
Christopher James Griffin, 23
Daniel Roy Leon Mendez, 20
Robin Duane Brown, 52
Ana Marie Honeycutt, 32

(See: http://www.usdoj.gov/usao/az/press_releases/2005/2005-199(Brown%20etal).pdf )

I look forward to seeing how many of the others also get a taste of the Aggravated Identity Theft penalties!
Read More
Posted in | No comments

Monday, 6 August 2007

AffPower Indictments Scare Affiliates!

Posted on 13:11 by Unknown
Today I heard the news that the "AffPower" drug network is being shut down, starting with 18 arrests in Texas, Florida, Colorado, New York, and Oregon.

Congratulations, Corbin A. Weiss, Special Assistant US Attorney with the Computer Crime and Intellectual Property Section of the DOJ! What a great indictment!

Here's a link to the full Indictment (caution: 124 pages!)

http://www.courthousenews.com/Affpower.pdf

I have to say, I LOVE to hear about scared bad guys, and THIS one has people scared who have previously considered themselves bulletproof. Why? Because the AFFILIATES are also being arrested.

The 18 are:

3 doctors
2 pharmacists
1 pharmacy operator
1 credit card processor
and
8 website affiliates

Mark Anthony Heredia, Manager and administrator in the Affpower enterprise in San Jose, Costa Rica;

William Polk Harrington and Todd Wurtzel, AKA "Sonny Gallo", recruited doctors and pharmacies to participate in the Affpower enterprise and managed the doctors they recruited;

Claude Covino, operated Saveon RX Pharmacy in Florida, part of the Affpower enterprise, and recruited other pharmacies to participate;

Dolores Lovin and Mary Aronson, owned, operated, and were licensed pharmacists working in St. Vrain Pharmacy in Colorado;

Subramanya K. Prasad, MD, Chandresh B. Shah, MD, and Gerald C. Morris, MD, were licensed medical doctors who issued prescriptions for controlled and non-controlled prescription drugs through and on behalf of the Affpower enterprise;

Philip James Bidwell, 50, of Frisco, TX, is accused of operating multiple affiliated websites and recruiting other affiliates to the enterprise and managing them. He has been released on $1 million bail.

Henriko Chung is charged with the same activities as Bidwell.

David Eldon Fisher, Richard Edward Koch, Jeffrey A. Light, (Name Withdrawn By Request),
Peter P. Bragansa, and Bessie K. Ricoarango were affpower affiliates who operated multiple affiliate websites

Nathan Jacobson was the owner and manager of RX Payments, Ltd, a credit card processing agency in Tel Aviv, Israel.

How hard are they hitting the Website Affiliates?

Jeffrey A. Light, 44, of Heath, TX, has been released on $1 million bail.

(Name withdrawn by request), 46, of Dallas, has been released on $500,000 bail.

Chandresh Shah faces additional charges in Georgia, Subramanya Prasad faces additional charges in Kentucky and Ohio, and Gerald Morris faces additional charges in Massachusetts, the states where each was licensed to practice medicine.

Dolores Lovin and Mary Aronson face additional charges in Colorado, and Claude Covino faces additional charges in Florida, the states where they were licensed in pharmaceutical practice.

ALL of the defendants face racketeering charges and much more in this 313 count indictment.

--------------

But does this really scare the bad guys? ABSOLUTELY! Let's drop in and visit a few websites where they bad guys talk about their pill-spamming and see what they are saying:

We'll start at RxAffiliateForum.com.

http://rxaffiliateforum.com/showthread.php?t=5280

ChesterCoperPot, an RXAffiliateForum member since 2003 whose made more than 400 posts to this forum, starts things off by quoting in bold text "AND EIGHT AFFILIATE WEBSITE OPERATORS".

Pillz, a "senior member" with over 200 posts, adds:
"BTW, the gov't is going for RICO on this."

RxRob, another "senior member" with over 1400 posts, says:
"OMFG, they charged Bess (WICKED on this forum). She was just an Affiliate!"

Rumple, trying to stem the panic, posts:

------------

"Settle down boys and girls......

Trying to win a case against an affiliate would be very hard to do, the reason you never hear about affiliates being charged is because it would be damn hard to prove without a doubt in a court that an affiliate new that Affpower was breaking the laws that they were breaking...

You didnt touch any of the money being moved into Dave's accounts and you didnt handle any of the drugs being shipped .........so stop worring

It would be a waste of time and effort for the government to even try to get a case against an affiliate that it could win, you would have to have direct business dealings with Dave for them to have something on you..."

--------

And that is EXACTLY what needs to happen if we are going to stop pill-spam. If the government is serious about wanting to stop this, they need to convince the jury and the sentencing judge that it doesn't matter if they "touched the money" or if they didn't "handle the drugs". What matters is that their behavior makes this entire scheme possible, and puts American lives in danger for their own greed.

Some of the websites involved include:

buyallprescriptions.com
us-meds.com
secureprescriptionsonline.com
ubuyrx.com
millennium-pharmacy.com
medlinedrugs.com
officialpillsrx.com
horizonmeds.com
valuetrustrx.com
drugprescribe.com
rxdrugstore.us
life-meds.com
secure-pills-online.com
dietprescriptions.org
expressdrugstore.biz
easyprescribe.com
weldonpharmacy.com
pillscouts.com
pills-discount.info
medsshop.com
medsource-pharmacy.com
orderonlinepharmacy.com
netmedsdirect.cojm
medsdirect-md.com
ndapharmacy.com
giantrx.com
rxmedcorp.com
thepillstore.com
drugdepot.com
cheappillsonline.com
american-meds-direct.com
cheap-us-pharmacy.com
realpills.com
silverdrugs.com
rx-listings.com
mgdrugstore.com
mrhappypill.com


==========================
Let's peek in on a couple more forums and see how they affiliates are taking the news so far:

-------

http://www.epharmacywatch.com/freeboard/ubbthreads.php/ubb/showflat/Number/536852

On ePharmacyWatch everybody wants to know WHICH WEBSITES are involved! They are also scurrying to see if the sites they are selling for do business in Cyprus.

Sadly, several of the posts make it clear that some of these poor suckers think they are "following the rules" and doing pill-spam for prescription drugs in a "legal" way! DOH!

(One Hundred Seventy Two users had logged in to this forum in the previous 30 minutes when I was reading it!)

------


http://www.drugbuyers.com/freeboard/ubbthreads.php/ubb/showflat/Number/536852

(182 registered users in the past 30 minutes!!!)

This thread is also mostly about posters wondering if what they are doing is really illegal or not! Amazing!

------

Shroomery.com laughs at them all and points out that Magic Mushrooms don't use prescriptions. (a photo of a cow says "This is my pharmacist!")

------
Read More
Posted in | No comments

Online Justice: Slow and Incomplete

Posted on 12:21 by Unknown
Last week the online media went nuts over the sentencing of Christopher William Smith, known to anti-spam researchers as "Rizler". I'd like to stand at the front of the line in congratulating Assistant US Attorney Nicole Engisch and US District Judge Michael Davis for sticking it to Rizler with a THIRTY YEAR SENTENCE!

Rizler has been spamming an enormous volume for a long time. The 211-page complaint against Rizler by AOL documented over 1.1 BILLION emails that Rizler had sent -- just to AOL subscribers!

Rizler was arrested in a raid on May 10th, 2005, in which his 85-employee company, Xpress Pharmacy Direct, was shut down and in which $4.2 Million in assets, including $1.8 Million in luxury automobiles was seized. Skipping bail to the Dominican Republic, it was only a matter of weeks before Rizler had restarted his spamming operations. His websites, such as rxorderfill.com, xpress-rx.com, digihealthcorp.com, mypillrefills.com, and netmeds.com, claimed to operate legally by having a real doctor read answers to your online profile questions, and prescribe your medications from his office in New Jersey. Rizler paid Dr. Philip Mach $7 per prescription for these services. . .more than 20,000 times in one four month period!

Spamhaus's Steve Linford told Silicon.com's Will Sturgeon back at that time, "Rizler was way up in our Top Ten". (Silicon.com The Spam Report, 06JUL05)

Good story, right?

Well . . . how is that Rizler is charged with operating a "continuing criminal enterprise" and "conspiracy", but there don't seem to be any co-conspirators?

Bernadette Hollis, who was in charge of acquiring the Hydrocodone for the online pharmacies, and who Smith confided in with his desire to kill one of the prosecutions chief witnesses, walks away with one year of probation and forty hours of community service.

Alton Scott Poe, was described as being an innocent office manager, who was brought in to instill good business practices. Apparently the judge bought this story, or perhaps nobody ever heard of the Online University that Poe ran? The Lawsuit against Alton Scott Poe and his brother lays out their online scheme for selling diplomas for between $300 and $500, complete with an imaginary transcript showing what grades you received in what classes! Innocent Office Manager? He'll do 6 months for assisting in the sale of millions of dollars of illegal drugs. I wonder what scheme he'll launch in six months and one day?
Read More
Posted in | No comments

Wednesday, 25 July 2007

GAO: CYBERCRIME Challenges

Posted on 01:51 by Unknown
On July 20, 2007 I began my first day of work at The University of Alabama at Birmingham as the Director of Research in Computer Forensics. The position came about as a result of one fundamental issue that we have been working on together between the chair of Computer & Information Sciences and the chair of Justice Sciences: How can we better equip CyberCrime Investigators to do their job? The first part of our answer was to encourage more Academic partnership, where students would seek a "Certificate in Computer Forensics" by studying courses from both departments. We called this initiative "Training Digital Detectives for the 21st Century". The second portion was to begin hosting more training on CyberCrime Issues, such as The Birmingham Conference on Phishing on March 13-15, 2007, and the Identity Theft Summit held June 10-11, 2007. The third part was to create my position, and to begin focusing our joint research efforts on topics that would provide better techniques, tools, and training for CyberCrime Investigators.



With that background, you can imagine how reinforcing it was to see Federal Computer Week's article on July 23, 2007 -- FBI, Secret Service must improve CyberCrime Training. The article begins:

The FBI, the Homeland Security Department and other federal agencies are underequipped and lack enough properly trained employees to combat cybercrime, according to a recent report by the Government Accountability Office.

GAO found that staffing was one of four major challenges to addressing cybercrime.


The publication being referred to was GAO-07-705: CYBERCRIME: Public and Private Entities Face Challenges in Addressing Cyber Threats. This document, from David Pownder's group at the Government Accountability Office, says "The annual loss due to computer crime was estimated to be $67.2 Billion for US organizations" with the majority of that, $49.3 billion, being related to Identity Theft, and $1 billion associated specifically with phishing. That same opening letter pointed out that in addition, we know "Chinese military strategists write openly about exploiting the vulnerabilities" used by our military computing infrastructure, and that "terrorist organizations have used cybercrime to raise money to fund their activities". In 2006, it is estimated that there were 9.9 Million US consumers who suffered from Identity Theft.

Its our economy that is at risk. In the reports background it lists that "150 million US citizens" use the Internet, and that in 2006, "total nontravel-related spending on the Internet was estimated to be $102 Billion". And spam, according to a Ferris Research report cited by GAO, has a "global cost of $100 billion worldwide, including $35 billion in the United States".

As president of the Birmingham InfraGard, and a recipient of the 2006 "Partnership Award" from the IC3 and NCFTA, I was pleased to see the report listing "Key Partnerships Established to Address CyberCrime":


  • Internet Crime Complaint Center (ic3.gov)
  • InfraGard
  • The National Cyber Security Alliance
  • National Cyber Forensics and Training Alliance (ncfta.net)
  • Electronic Crimes Task Forces


The key challenges listed in the report are:


  • Reporting CyberCrime
  • Ensuring adequate law enforcement analytical and technical capabilities
  • Working in a borderless environment with laws of multiple jurisdictions
  • Implementing information security practices and raising awareness


Reporting CyberCrime


When surveys say 9.9 Million Americans lost $49 Billion to Identity Theft last year, its astounding that the Internet Crime & Complaint Center only had $180 Million in loss reports filed from 260,000 consumers. Some of the reasons GAO gave for this under-reporting were:


  • Financial Market Impacts - (will my stock tank if I tell you I was hacked?)
  • Reputation or confidence effects - (will my customers flee if I tell the truth about my brand's phishing losses?)
  • Litigation concerns - (will my customers sue me?)
  • Signal to attackers - (will other hackers pounce on me?)
  • Inability to share information - (is my data sequestered by the legal process?)
  • Job security - (will my IT staff be fired?)
  • Lack of law enforcement action - (will the cops do anything? do they know what to do?)


LE Analytical and Technical Capabilities



From the report:


Federal and state law enforcement organizations face challenges in having the appropriate number of skilled investigators, forensic examiners, and prosecutors.

...

officials, once an investigator or examiner specializes in cybercrime, it can take up to 12 months for those individuals to become proficient enough to fully manage their own investigations.


Some of the key challenges mentioned include the great possibility that a trained cybercrime investigator will be lured to the private sector by the much higher salaries their skills may demand in that arena. Within the FBI, the policy of rotating new agents to one of the 15 largest offices within 3 years often means that an agent recruited for their cyber abilities is assigned to a non-cyber position in their new office! (This happened to one of our favorite cyber agents in Birmingham, who is now in a non-cyber post in Miami!) These same rotations also mean that agents brought in to fill these new cyber-vacancies may have little or no cyber training. Even senior agents (supervisory agents) are limited to serving a 5 year term in their role if they wish to seek career advancement.

Keeping Up to Date with Technology and Techniques



The report also expresses the concern that cybercrime is evolving at a rate which requires new equipment and tools "and agencies' need for them does not always fall into the typical federal replacement cycle". Some of the training gaps are being met creatively within agencies by having centralized talent pools, such as the DOD Cyber Crime Center (DC3.mil), FBI Cyber Action Teams, and the Secret Service training programs for federal, state, and local officials (such as the new Center just opened in Hoover, Alabama!) These are all great, but often the resources are still too limited for the scope. These are supplemented by "public/private partnerships, like the FBI’s Infragard and National Cyber Forensics Training Alliance and the Secret Service’s Electronic Crimes Task Forces, [which] provide ways to share expertise between law enforcement, the private sector, and academia."

Borderless Crime



Key challenge in this area are:


  • techniques that "make it difficult to trace the cybercriminals to their physical location".
  • "the multiplicity of laws and procedures that govern in the various nations and states" - such as the fact that not all states or nations have antispam or antispyware laws.
  • "Developing countries, for example, may lack cybercrime laws and enforcement procedures."

  • The "need to rely upon officials of other jurisdictions to further investigate the crime."
  • "Conflicting priorities also complicate cybercrime investigations and prosecutions."
  • "Cybercrime can occur without physical proximity to the victim, and thus a cybercriminal can operate without victimizing a citizen in the jurisdiction or federal judicial district in which the crime originated." - It is difficult to commit local resources to investigate crimes that have no local victims!


Raising Awareness


"Criminals prey on people's ignorance". Ignorance of vulnerabilities. Of how to detect phishing. Of how to report CyberCrime.



In response to this report, the FBI mentioned that Director Mueller has established five "career paths" for agents, one of which will be a Cyber track. This will allow cyber agents to remain where there skills can be made most effective.

The Secret Service also responded, stating that their Electronic Crimes Special Agent Program (ECSAP) will have 770 trained and active agents by the end of FY 2007. Their response also mentioned their 24 Electronic Crimes Task Forces, which "combine the resources of state and local police, as well as academia and private industry", and their importance in maintaining a continuity of investigative ability even as new ECSAP agents face their 4th year rotations.

The Birmingham Electronic Crimes Task Force meets Quarterly according to their website. More information about the next meeting from 731-1144 or "bhmecwg@einformation.usss.gov".
Read More
Posted in | No comments

Monday, 23 July 2007

CyberSecurity Enhancement Act of 2007

Posted on 05:21 by Unknown
Its time to rally the troops on the political front once again. Those of you who know me know that I believe we have primarily not a lack of laws but a lack of manpower and interest in enforcing those laws. Is it against the law to send spam with false headers in the United States? Yes. It is actively investigated and prosecuted? No. Is it against the law to steal someone's identity in the United States? Yes. Is it actively investigated and prosecuted? No. Unless you can show enormous losses.

So, on the one hand, I would like to see adequate resources applied to enforcing the laws that we currently have on the books. On the other hand, when I see a great Bill is introduced in the House or the Senate, I'd like to see it supported.

The CyberSecurity Enhancement Act of 2007 is worth supporting. It goes beyond our current CyberCrime Laws and attempts to bring in the aspects of Organized Crime and Conspiracy that are behind the individual acts we see everyday.

Someone registered a new domain in Hong Kong and used a bot-infected computer to host a phishing website. Hardly interesting from a prosecutorial perspective. But if there were laws on the books that let investigators more easily go after the Criminal Conspiracy that encouraged this action to be committed hundreds of times this year by a related group of co-conspirators, that would make these smaller acts more likely to be prosecuted. Assistant US Attorney Erez Liebermann, the chief of the New Jersey CHIPS unit (Computer Hacking and Intellectual Property Section), was recently interviewed by Information Week where he mentioned this Bill. In the July 20th article, he says that by adding CyberCrime to the RICO statutes, as this Act would do, criminal penalties for these activities would be enhanced.

Are you familiar with the "CyberSecurity Enhancement Act of 2007"? Most of us aren't.

You can read the Full Text of the Bill here.

HR 2290 was introduced May 14th by Adam Schiff, a Democrat from California. (GovTrack categorizes him a "Radical Democrat". I like Radical Democrats love for technology and for their desire to help the poor. I can work with anyone. Schiff co-sponsored National Human Trafficking Awareness Day, and a bill to make trade in illegal nuclear weapons a Crime Against Humanity. Of course he also introduced a Bill to express No Confidence in our Attorney General, so bi-partisan, this guy ain't.)

This bill is currently sitting with the House Committee on the Judiciary, along with 43 other proposed amendments to Title 18 (where most of our CyberCrime Laws are outlined).

One of those other versions is a Republican sponsored Bill with almost the same name, introduced by Republican Lamar Smith, HR 836, introduced back in February.

A key phrase which was present in both the Republican and the Democratic version of the Bill would modify the penalties so that they applied both to the successful criminal, and the criminal who "conspires to" or "attempts" to commit certain CyberCrimes.

Another huge part of the act addresses the concern I mention at the top of this post. Section 10 of this act would give an additional $10 Million EACH to the Secret Service, the FBI, and the Attorney General for the Criminal Division of the DOJ, specifically for fighting CyberCrime. If for no other reason than this, I would strongly encourage your support of this bill!

I'm pleased to see that one of my two Congressman, Artur Davis, is listed among the co-sponsors of HR 2290. (I claim the one in the zip code where I work, and the one in the zip code where I live both represent me. I had the pleasure of escorting my son's orchestra on a Capitol Tour as guests of Mr. Davis' office last month!) I'm also pleased to see that Ohio Republican Steven Chabot and California Republican Daniel Lungren, 2 of the 9 Republican co-sponsors of Smith's earlier bill, and both members of the sub-committee on Crime, Terrorism, and Homeland Security, have joined as part of the 6 Republicans who make a total of 19 co-sponsors of HR 2290.

The fact that the members of this committee, both Democrats and Republicans, are signed on as co-sponsors to this Bill encourages me that it might make it out of committee!

I would encourage folks to read the Bill, and if you agree that it should be law, please encourage your Representative to lend his voice of support to the Bill.

The Bill is currently sitting in a sub-committee of the House Judiciary Committee, called the "Crime, Terrorism, and Homeland Security Committee". Especially if you are in Michigan, where the Honorable John Conyers, the Chairman of the Judiciary, is from, or in Virginia, where the Honorable Robert C. Scott, the Chairman of the sub-committee, is from, it would be very useful to hear your voice in this matter.

Please take a minute to review the Bill, members of the Subcommittee, and your own Congressmen's contact information, and determine what the right course of action is for yourself.

Thanks for your help!

_-_
gar
Read More
Posted in | No comments

Wednesday, 18 July 2007

Buone Notizie! (Good News for Italian Bank Customers)

Posted on 07:21 by Unknown



In a press release issued July 13 (or 13 luglio 2007, if you're in Roma), the Commanding General of the Financial Guard of Milan announced that they had arrested 26 phishers. 18 Italian citizens, and 8 foreigners.

Here's my Babylon 6 assisted translation of the press release:

----------

The Provincial headquarters of the Guardia di Finanza in Milan has, in fact, executed 26 orders of custody to members of two criminal associations responsible for a series of fraud perpetrated on hundreds of users of home banking services, by technical means better known under the name of "phishing".

The operation has identified 18 Italian citizens and 8 Eastern European foreigners, who are regular residents in our country, which are exploiting the home banking personal access credentials to customers of Poste Italiane bank, sent fraudulently in response to randomly dispatched e-mails apparently sent by their financial institution.

Hackers from the group, during questioning, have confessed to having sent the e-mail messages, which appeared to originate from Poste Italiane, by using stolen login credentials for electronic mailboxes of ISPs operating in Italy but with servers abroad. They subsequently logged in to the accounts during the next 30 days and defrauded them out, by transferring the sums on cards specially created by other members of the Organization.

The means of offense were identified thanks to a tight cooperative investigation between the "fraud management" team of Poste Italiane and the officers of the Guardia di Finanza, which have monitored in real time the activations of the cards, initially in the territory of Milan and then on the whole national territory.

The orders of custody have been carried out in the provinces of Milan, Brescia, Novara, Como, Florence, Parma, Forlì and Pescara.

In the course of the searches they seized computers, removable media archives, magnetic cards used to set up credit cards and debit cards, hundreds of credit cards and prepaid cards of various banking institutions, CARDS one, false documents and mobile phones last generation.

------------------

This type of investigation is possible every day in the United States. What is necessary to make it a reality? The belief by the management in charge of the manpower of various investigative and prosecutorial agencies that "small crimes" are worth investigating -- because they lead to Big Criminals!

Well Done, Italy! May you serve as a model for us all!

_-_
gar


(original press release, in Italian, is available here:

Italian Press Release

Read More
Posted in | No comments

Tuesday, 17 July 2007

UAB Student Newspaper Interview

Posted on 11:41 by Unknown
Kaleidoscope, the UAB Student Newspaper, interviewed me on Identity Theft for their July 10, 2007 issue.

Adrian Thurstin did a very nice job with the interview, and wrote a great story focusing on issues of particular interest to students.

_-_
gar
Read More
Posted in | No comments
Newer Posts Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • Happy New Year! Here's a Virus! (New Year's Postcard malware)
    I've been busy this week looking at the various defacements (see ComputerWorld , and ABC News ) and other cyber attacks (see yesterday...
  • From Russia, With Love . . . new Postcard spam spies on your PC
    Isn't it nice to have friends who send you postcards? The UAB Spam Data Mine is especially fortunate in that way. Beginning the evenin...
  • Help stop the Osama bin Laden Videos on Facebook
    If you have teenage friends, or friends with poor security practices, you will probably notice that your wall has recently filled up with in...
  • Top Brands Imitated by Malicious Spam
    WebSense recently released an InfoGraphic titled "Top Five Subject Lines in Phishing Emails." for January 1, 2013 through Septemb...
  • A Dark and STORMy Night
    Just in time for the spookiest night of the year, the Storm botnet recruitment spam switched to a Halloween flavor. On the evening of Octobe...
  • TJX Update: The San Diego Indictments
    As promised, here is the update regarding the eight individuals charged in San Diego in connection with "the TJX bust". There wer...
  • Facebook Safety & Million Member Facebook Groups
    Two of my friends today invited me to join "Million User" facebook groups. Not that it matters really, but the two groups were: P...
  • Microsoft Security Intelligence Report 2H08
    The Microsoft Security Intelligence Report for the second half of 2008 has been released (the 184 PDF version, available from http://microso...
  • Operation Open Market: The Vendors
    When we wrote last week about Operation Open Market the court documents had not yet been released in a major multi-agency Identity Theft ca...
  • First 2008 Presidential Spam Campaign?
    Does Ron Paul suddenly have a strong support base among foreign computer owners with strange names and multiple personalities? or is it poss...

Categories

  • china
  • computer security careers
  • conficker
  • cyberwar
  • digital certificates
  • facebook
  • fake av
  • gumblar
  • koobface
  • law enforcement
  • malware
  • pharmaceuticals
  • phishing
  • public policy
  • spam
  • twitter
  • twitter malware
  • waledac
  • zbot

Blog Archive

  • ▼  2013 (21)
    • ▼  December (4)
      • Top Brands Imitated by Malicious Spam
      • 20 Million Chinese Hotel Guests have data leaked
      • Indian Banks targeted in multi-brand Phishing Attack
      • Paunch and the BlackHole/Cool Exploit Kit
    • ►  November (1)
    • ►  October (1)
    • ►  September (1)
    • ►  August (3)
    • ►  July (1)
    • ►  June (1)
    • ►  May (5)
    • ►  April (3)
    • ►  March (1)
  • ►  2012 (18)
    • ►  August (1)
    • ►  June (1)
    • ►  May (7)
    • ►  April (2)
    • ►  March (7)
  • ►  2011 (28)
    • ►  November (3)
    • ►  October (1)
    • ►  August (4)
    • ►  July (6)
    • ►  June (1)
    • ►  May (2)
    • ►  April (2)
    • ►  March (6)
    • ►  February (1)
    • ►  January (2)
  • ►  2010 (80)
    • ►  December (6)
    • ►  November (10)
    • ►  October (6)
    • ►  September (12)
    • ►  August (5)
    • ►  July (4)
    • ►  June (11)
    • ►  April (7)
    • ►  March (8)
    • ►  February (4)
    • ►  January (7)
  • ►  2009 (92)
    • ►  December (12)
    • ►  November (11)
    • ►  October (16)
    • ►  September (7)
    • ►  July (5)
    • ►  June (10)
    • ►  May (2)
    • ►  April (6)
    • ►  March (7)
    • ►  February (6)
    • ►  January (10)
  • ►  2008 (101)
    • ►  December (7)
    • ►  November (17)
    • ►  October (11)
    • ►  September (10)
    • ►  August (22)
    • ►  July (12)
    • ►  June (3)
    • ►  May (7)
    • ►  April (5)
    • ►  March (2)
    • ►  February (1)
    • ►  January (4)
  • ►  2007 (31)
    • ►  December (3)
    • ►  November (9)
    • ►  October (3)
    • ►  September (2)
    • ►  August (5)
    • ►  July (5)
    • ►  January (4)
  • ►  2006 (5)
    • ►  December (2)
    • ►  October (3)
Powered by Blogger.

About Me

Unknown
View my complete profile