Latest Post
Showing posts with label Crime. Show all posts
Showing posts with label Crime. Show all posts

Sanford Wallace Indicted for hacking 500,000 Facebookers

Written By Unknown on Friday, 5 August 2011 | 03:40

Sanford_wallace
One of the first figures to plaster the internet with millions of spam messages before being driven underground has been criminally charged for hacking some 500,000 Facebook accounts, stealing their personal information, and sending 27 million unwanted advertisements.

Sanford Wallace, now 43, first figured out a way to evade Facebook's spam filters and then employed a script that automatically logged in to the accounts he had compromised and retrieve a list of all the users' friends, according to an indictment filed Thursday in federal court in San Jose, California. He then allegedly posted junk messages on each of the friends' Facebook wall.

When people clicked on a link in the message, they were directed to a website that phished their name, and account credentials, prosecutors said. He allegedly carried out the scheme in just five months, starting in November 2008.

“Wallace continued his spamming scheme by storing the information provided by Facebook users, such as email addresses and passwords,” the indictment stated. “Wallace then used the user's email address and password to log into Facebook in order to continue to send spam messages.”

The indictment comes almost two years after Facebook was awarded $711m in damages from Wallace after suing him over the alleged scam. He faced a similar lawsuit from MySpace that in 2008 resulted in a $230m judgement. It's doubtful the company has recovered a dime of either judgement.

Wallace surrendered to FBI agents in Las Vegas on Thursday. He made his initial appearance in court a little while later and was released on $100,000 bail. He was ordered not to access Facebook or MySpace.

The indictment charges Wallace with six counts of fraud and two counts of intentional damage to a protected computer. He was also charged with two counts of criminal contempt for logging in to Facebook after the federal judge in the civil action brought by the site ordered him not to. One of the forbidden logins occurred while Wallace was aboard a Virgin Airlines flight from Las Vegas to New York.

If convicted, he faces a maximum of three years in prison and a $250,000 fine for each fraud count and 10 years and a $250,000 fine for each intentional damage count. Penalties for the contempt charges are up to the judge.

Microsoft Warns the Public on Support Tech Scams

Written By Unknown on Thursday, 16 June 2011 | 08:59

A survey from Microsoft reveals just how widespread the fake tech support call scam is becoming.

The crooks cold-call people at home and claim to be calling from Microsoft or a well-known security firm and offering "free security checks".

The software giant surveyed 7,000 computer users in the UK, Ireland, US and Canada and found an average of 16 per cent of people had received such calls. In Ireland this rose to a staggering 26 per cent.

More than a fifth of those who received such a call, or 3 per cent of the total surveyed, were tricked into following the crooks instructions which ranged from allowing remote access of their machines, downloading dodgy code or in some cases giving credit card information in order to make purchases.

Microsoft said if someone claiming to be from Windows or Microsoft Tech Support calls you: "Do not purchase any software or services. Ask if there is a fee or subscription associated with the 'service'. If there is, hang up."

Redmond said 79 per cent of those tricked suffered financial loss – the average loss was $875 (£542). Losses ranged from just $82 (£51) in Ireland to a whopping $1,560 (£967) in Canada.

Microsoft warned that while the gangs were currently targeting English-speaking countries it was just a matter of time before they go after other countries.

The company advised anyone who had already fallen for such a scam to change their passwords, scan their machines for malware and contact their bank and credit card providers.

Citi Credit Card Data Breached for 200,000 Customers

Written By Unknown on Thursday, 9 June 2011 | 19:02

Citigroup said Thursday hackers acquired personal information on about 200,000 credit-card holders, the financial institution’s second announced breach this week.

The attack, first reported by the Financial Times, comes amid a host of cyber intrusions into well-known companies, including Google, Sony, EMC, Lockeheed Martin and L-3.

Citi said no birth dates, Social Security numbers or card security codes were accessed by the hackers last month. They got away with account numbers and e-mail addresses. The financial institution said it would provide new cards to affected customers.

Citi said it has “implemented enhanced procedures to prevent a recurrence of this type of event,” but declined to elaborate.

Meanwhile, federal prosecutors announced Tuesday that four individuals, three from Romania and one from Austria, were apprehended and charged in an ATM-skimming scheme in which they got away with $1.5 million from JPMorgan Chase and Citibank, a unit of Citigroup.

“One method the defendants and their co-conspirators allegedly used involved going into bank branches and surreptitiously replacing the bank’s teller PIN pads with identical-looking PIN pads equipped with technology that — unbeknownst to the banks and their customers — recorded the customer’s account-related information and corresponding PIN each time he or she used the compromised PIN pads,” federal authorities said.

Photo: Gregalicious/Flickr

Chinese Hackers Targeted U.S. Officials in Gmail Phishing Attack

Written By Unknown on Thursday, 2 June 2011 | 10:07

Google has detected a targeted campaign to collect hundreds of personal Gmail passwords, many of them belonging to senior US government officials, Chinese political activists, military personnel, and journalists.


The accounts may have been compromised using spear phishing techniques in which victims received highly personalized messages that contained links to counterfeit Gmail pages, according to a blog post published in February that Google cited when disclosing the attacks on Wednesday. Google said the campaign “appears to originate from Jinan, China” but didn't share any evidence supporting that claim.

“The goal of this effort seems to have been to monitor the contents of these users' emails, with the perpetrators apparently using stolen passwords to change people's forwarding and delegation settings,” Google's blog post, titled “Ensuring your information is safe online,” stated. “Google detected and has disrupted this campaign to take users' passwords and monitor their emails. Company officials have alerted the victims and “relevant government authorities.”

According to the February blog post, some of the phishing pages were hosted using the free dyndns.org service and contained images and text that were almost indistinguishable from those hosted on the real Google service. The links were “customized and individualized for each target,” independent security researcher Mila Parkour wrote.

Once accounts were compromised attackers created rules to automatically forward all received email to accounts under their control, Parkour said. The attackers then used the purloined email to “gather information about the closets associates and family/friends” and exploited “the harvested information for making future mailings more plausible.”

Parkour's post showed a half-dozen emails exchanged in the campaign, several of which contained Pentagon and US State Department addresses.

“This is the latest version of the State's joint statement,” one fraudulent email read. “My understanding is that State put in placeholder econ language and am happy to have us fill in but in their rush to get a cleared version from the WH, they sent the attached to Mike.”

The email contained what appeared to be a Microsoft Word document as an attachment.

The incident harkens back to a separate attack Google disclosed in January 2010, that targeted the company's source code and the Gmail accounts of human rights activists in China. Unlike the most recent phishing campaign, the “highly sophisticated and targeted attack” from 2010 exploited vulnerabilities on Google's network to gain unauthorized access. Dozens of other companies were also targeted in the earlier attack.

Google's blog post provides a variety of tips for keeping accounts secure. They include use of a two-step verification procedure when logging in to accounts to add an extra layer of security to the login process. Gmail also warns users of suspicious logins to their accounts.

Gmail isn't the only free email service to be targeted recently. Last month, attackers exploited a vulnerability in Microsoft's competing Hotmail that allowed them to steal confidential correspondences and user contacts without warning. The in-the-wild attacks came to light only after they were disclosed by third-party researchers.

Microsoft has yet to say how many users were affected or whether it alerted authorities and compromised users of the attacks.
 
Support : Creating Website | Johny Template | Mas Template
Copyright © 2011. Turorial Grapich Design and Blog Design - All Rights Reserved
Template Created by Creating Website Published by Mas Template
Proudly powered by Blogger