10.08.2013 Views

NESTA Crime Online - University of Brighton Repository

NESTA Crime Online - University of Brighton Repository

NESTA Crime Online - University of Brighton Repository

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

“It isn’t hard to copy – look at the real Amazon and copy it. If it looks like Amazon,<br />

people accept that it is Amazon. They log in as a returning customer so we’ve got their<br />

password too and plenty <strong>of</strong> people use the same password for everything so that can be<br />

handy. Then they get a screen that says they need to put their details in again for<br />

security purposes, they press ‘click’ and that’s their name, address, bank details and<br />

everything else that we needed sent straight to us.”<br />

Source: 192.com, The Fraudster’s Modus Operandi, p.6.<br />

Criminal gangs have also developed a smart s<strong>of</strong>tware-based tool to extract and collate<br />

the personal data posted on the web <strong>of</strong> unsuspecting victims. Such data may be used for<br />

a multitude <strong>of</strong> purposes, including identity theft and credit card fraud.<br />

Your CV belongs to us and it’s for sale!<br />

Hackers have turned the harvesting <strong>of</strong> personal information from Monster.com and other<br />

large US jobsites into a lucrative black market business.<br />

A Russian gang called Phreak has created an online tool that extracts personal details<br />

from CVs posted onto sites including Monster.com, AOL Jobs and many others. As a<br />

result the personal information (names, e-mail addresses, home addresses and current<br />

employers) on hundreds <strong>of</strong> thousands <strong>of</strong> job seekers has been compromised, according<br />

to net security firm PrevX.<br />

Phreak has begun selling its ‘identity harvesting services’ to fraudsters, charging $600<br />

for data that might be applied to targeted phishing attacks, ID fraud or other illicit<br />

purposes. Would-be clients are able to contact the gang on special underground forums.<br />

For a fee the gang will filter its database for entries that refer to a particular country or<br />

particular employer.<br />

The filtering technology is quite sophisticated and smart as it is able to extract and<br />

collate only useful data for credit card fraud and identity theft found in CVs, according to<br />

PrevX. "Phreak is selling its services to people running higher-end [targeted] spear<br />

phishing attacks."<br />

Page 68

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!