By John P. Mello Jr. TechNewsWorld Part of the ECT News Network
12/30/03 7:53 AM PT
Although fraud complaints are rising, more fraud is being stymied than ever before, according to Susan Henson, a spokesperson for the New York-based Merchant Risk Council, whose members include Best Buy, Barnes & Noble and American Express.
eMarketer Whitepaper: Optimizing the E-Commerce Experience
From the Web to the Contact Center, are you prepared to proactively engage and keep your savvy customers? Read how e-commerce leaders are optimizing their sites with ratings, reviews, live help, Web analytics, mobile and more.
The past year was a good year for bad guys on the Web. Fraud complaints surged 60 percent to 120,000 from 75,000 a year ago, according to the Internet Crime Complaint Center in Fairmont, West Virginia.
The Center, which changed its name last week from the Internet Fraud Complaint Center, maintains a database on Internet crime and acts as a clearinghouse for forwarding cases to various law enforcement jurisdictions.
Founded in May 2000, the agency is a partnership between the FBI and the National White Collar Crime Center, a federally funded, nonprofit organization.
Holiday Crescendo
Illegal activity on the Internet appears to have reached a crescendo at the end of the year, according to the Anti-Phishing Working Group. In a statement released last week, the group reported that more than 60 million e-mail fraud attacks were launched to exploit the holiday season.
Two weeks prior to Christmas, the group said, 60 unique e-mail fraud attacks using a technique known as "phishing" were instigated against consumers.
Phishing attacks involve the mass distribution of spoofed e-mail messages with return addresses, links and branding that all appear to come from banks, insurance agencies, retailers or credit card companies.
These fraudulent messages are designed to fool the recipients into divulging personal data, such as credit card numbers, bank account numbers, passwords and social security numbers.
Because these e-mails look "official," an average of 5 percent of recipients respond to them, resulting in financial losses, identity theft and other fraudulent activity.
Dangerous Phishing
"Consumer phishing attacks are dangerous and are quickly increasing both in number and in sophistication," Dave Jevans, chairman of the Anti-Phishing Working Group and a senior vice president at Tumbleweed Communications (Nasdaq: TMWD) in Redwood City, California, said in a statement.
"To most Internet users, the e-mails and Web sites are indistinguishable from legitimate business communications," said Jevans. "The spam epidemic has rapidly evolved from a nuisance to a real security threat with the shift from dubious advertising to financial crime and identity theft."
Although fraud complaints are rising, more fraud is being stymied than ever before, according to Susan Henson, a spokesperson for the New York-based Merchant Risk Council, whose members include Best Buy (NYSE: BBY), Barnes & Noble (NYSE: BKS) and American Express (NYSE: AXP). "Our merchants are employing more and more sophisticated fraud-detection methods that are catching more of the fraud before losses actually occur," she told TechNewsWorld.
"Smaller companies have seen an increase in fraud," she continued, "but larger companies who have put much more emphasis on fraud prevention technology have seen their fraud go down."
Changing Attitudes
There was a marked change last year in the attitude of Internet miscreants, according to Tony Magallanez, a systems engineer in the San Jose, California, office of F-Secure, a data security firm headquartered in Helsinki, Finland.
In the past, the typical motive for a writer of malware was popularity and bragging rights, he told TechNewsWorld. "This year, the clear motive is profit," he said. "People are stealing credit card information, or they're turning machines into spam mail forwarders and then selling the location of those machines to third parties."
He cited the SoBig worm as an example of the new malware writer ethic. The worm contained an expiration date, a strategy that was unheard of in the virus-writing community since part of the "kick" of creating a worm was to see how far and how long it would spread.
But the longer a virus lives and the further it travels, the more likely it is that it will be discovered and destroyed -- and the writers of the SoBig worm wanted it to remain undiscovered by the operators of the machines it infected.
"One of the things that a lot of people didn't know about the SoBig worm is that every single version put on each machine it infected had an e-mail spamming tool," Magallanez said. "It allowed spammers to send their e-mail through the infected machines."
2004 Growth Market
"Throughout the year, we found people who bought lists off the black market of computers infected with SoBig," he added. "The only way to get that information is through the writers themselves."
In the coming year, credit card fraud will continue to be a growth market for Web grifters, Magallanez said.
In the past, he explained, fraudsters could generate their own credit card numbers that would pass muster through the merchant-verification system. But merchants got wise to that practice and have thwarted it -- which has boosted the market for stolen credit card numbers.
"That's one of the things that we saw this year," Magallanez said. "There was a very large increase in the theft of credit numbers."
I see internet fraud is being blamed on the hackers and general scum of the internet only. ...
Next Article in Security
Hackers Gone Phishing - Again December 29, 2003
"It's pretty clear that organized crime is behind a big portion of this," Dave Jevans, chairman of the Anti-Phishing Working Group, told the E-Commerce Times. "We're seeing the involvement of the Secret Service in the investigation."
Related Stories
The Most Trusted Companies in E-Business December 22, 2003
Amazon and eBay have built their loyal followings not because of the products they sell, but because so many people have used them regularly without incident.
Outsourcing Network Protection: An Interview with MessageLabs CTO Mark Sunner December 08, 2003
"Often seen as two different groups, the line between spammers and virus writers is beginning to blur as each makes use of tactics usually employed by the other," MessageLabs CTO Mark Sunner told TechNewsWorld. "SoBig.F, which hit in August, was the first widely successful example of a converged threat."
Diebold Retracts Legal Threats Over Voting Machine Flaws December 02, 2003
Diebold Elections Systems spokesperson David Bear told TechNewsWorld that the company simply "chose not to pursue legal action" that was based on copyright protection and the Digital Millennium Copyright Act (DMCA).
Feds Round Up Suspects in Net Fraud Sweep November 21, 2003
The FBI said it worked with a host of other agencies on Operation Cyber Sweep, including 34 states' attorneys general, the U.S. Postal Inspection Service, the Secret Service and local agencies.
Related News Alerts
More by John P. Mello Jr.
Mouse Meets Multi-Touch November 09, 2009
Apple's latest peripheral, the Magic Mouse, takes the concept of multi-touch that the iPhone and iPod touch popularized and merges it with a button-free mouse. As one's mouse is a direct point of contact between human and machine, any changes made to it can be a divisive issue. Some users love the new abilities Magic Mouse brings to the table; others just can't stand the thing.
Samsung Intrepid: Sleek Hardware Makes Up For Uncomfy OS November 09, 2009
Samsung has built its Intrepid smartphone with a solid set of hardware. Its physical keyboard is comfortable for thumb-typing, and its camera sports a number of advanced features for a phone cam. The Windows Mobile 6.5 OS it's saddled with can be uncomfortable and unintuitive at times, but it may be at least a familiar interface for the business users the Intrepid targets.
McAfee Gives Enterprise Macs a Bodyguard November 02, 2009
When it comes to Mac use in an enterprise environment, running third-party security software isn't just a matter of using an abundance of caution. It may also be a matter of complying with governance mandates and regulations. McAfee's new Endpoint Protection for the Mac targets enterprise systems handling large amounts of sensitive data.