The iovation Site
HOME  |  ABOUT  |  CONTACT  |  RSS  |  VISIT IOVATION

Posts Tagged ‘identity theft’

Recent Bust Reveals the Anatomy of an Online Crime Site

Thursday, January 28th, 2010

After a three-year investigation by the FBI and the UK’s Serious Organized Crime Agency (SOCA), British authorities announced they have arrested the sophisticated network of cyber criminals behind DarkMarket, one of the world’s top criminal websites. The site, which operated out of an unassuming London Internet café, was an international cyber supermarket for stolen credit card and bank account information that officials say has cost the banking industry tens of millions of dollars. (more…)


UK Launches NRFC Hotline for Reporting Internet Fraud and e-Crime

Tuesday, January 19th, 2010

How much money has the world lost to e-crime so far? … A trillion dollars. That’s the estimated annual cost of e-crime worldwide, according to a recent article, “National online-fraud helpline to launch in April.” Despite the staggering losses attributed to online crime, victims of such crimes—both individuals and businesses—have not had a simple option for reporting them. Hopefully this is about to improve, with the UK’s new Action Fraud helpline, one of the first attempts at streamlining a call-in process for victims to report online crime.

I commend the National Fraud Reporting Centre (NFRC) for getting the hotline going. The helpline will allow individuals and small businesses to report cyber crime to a central agency, simplifying what would otherwise be a confusing process involving potentially several different government ag encies. A similar effort in the U.S., the Internet Crime Complain Center (IC3), currently allows individuals to file complaints of internet fraud through its website. (more…)


Video Game Consoles are Hot Commodity for Fraudsters

Thursday, December 17th, 2009

If you’re curious to know what’s topping people’s wish lists this holiday season, just take a look at online sales. No big surprise, electronics are where it’s at. Based on information provided by fraud prevention experts (and iovation partner) Retail Decisions (ReD), the top-ten list of products sold online during Black Friday was dominated by GPS systems, televisions, digital cameras and video game consoles.

Besides providing statistics on what online purchases people were spending their hard-earned money on during Black Friday, ReD also noted that online criminals were out in force, busy spending other people’s money. “Whilst online retailers witnessed a huge upturn in sales this Black Friday, fraudsters are also ’spending’ more, with an average value of $248 per transaction online, 23% more than the average genuine customer,” said ReD’s CEO, Carl Clump. (more…)


Understanding the Difference Between Identity Theft and Identity Fraud

Tuesday, December 8th, 2009

Identity theft occurs offline, but online fraud targets primarily online businessesThere was a blog post recently on Wallet Pop titled “Online theft not the main cause for identity fraud.” In it, author Josh Smith does a good job calling out the differences between identity theft and identity fraud. In short, identity theft is when someone’s personal identity information has been stolen; identity fraud is when that stolen information is used to commit financial fraud or some other kind of crime. While the two are inevitably related to one another, they are not the same thing.

In the case of identity theft, it’s a common myth that malware, botnets, and other internet scams are to blame; however, Smith cites a study done by Travelers Insurance that actually shows that the majority (78%) of incidents of identity theft actually occur offline. This indicates that peoples’ fears may have been, at least in part, misplaced. Individuals would benefit from an increased awareness and vigilance in all aspects of their life, not just online.

This being said, there still remains the question of identity fraud: what happens once someone’s personal information has been compromised? This is where online businesses still need to be on high alert, because online sites (and not physical stores) will likely remain the No. 1 target of identity fraud. Here’s why:  (more…)


Online Fraud Fears Didn’t Deter Shoppers – WSJ Reports e-Commerce Climbed 11% on Black Friday

Tuesday, December 1st, 2009

Online fraud fears did not deter shoppersGood news for online retailers came this weekend as reports showed that this year’s online sales during Black Friday were up 11% from last year, with U.S. shoppers ringing up $595 million worth of orders throughout the day. The bulk of the increases, not surprisingly, went to the largest stores. As the blog on the Wall Street Journal reports:

The retail sites for Amazon.com, Apple, Best Buy, Target and Wal-Mart each saw more than 4 million unique visits Friday, comScore said, with Amazon receiving the most traffic (up 28% from 2008). Apple, Best Buy and Wal-Mart sites also experienced double-digit traffic gains. According to Experian Hitwise, another Web monitoring firm, other e-commerce standouts included Sears, Staples and Dell.

These results are welcome news for retailers who have been concerned that fear of identity theft could have a noticeably negative impact on sales. Just last week SC Magazine predicted overall online spending to be down this year because of such fears. Luckily, so far, this does not appear to be the case. (more…)


‘Tis the season … for fraud

Monday, October 26th, 2009

'Tis the season ... for fraudOn the heels of our previous post about increased shipping fraud during the holidays, eWeek has just reported that click fraud is also anticipated to increase dramatically in the coming months:

    “As we head into Q4 and the busiest season for online shopping and Internet use by those considered inexperienced users, click fraud will likely run rampant as scammers seek to tap into the increased attention, experts warned.”

Click fraud (which is when affiliate sites dishonestly increase online ad traffic in order to gain unearned revenue) is one of many types of fraud becoming more common with the use of botnets. In addition to click fraud, many other types of fraud—including spam, phishing attacks, and identity theft—are gaining in prevalence with the use of botnets. The result is that consumer PCs are under siege and individuals and businesses alike bear the cost. (more…)


Holiday Season Means Increased Shipping Fraud for Retailers

Friday, October 23rd, 2009

Holiday Season Means Increase In Shipping FraudHoliday shopping season is upon us; combine that with the current unemployment rate, and online fraud is likely to reach an all-time high this year. This correlation may not immediately make sense, since many people think Internet crime is only perpetrated by organized fraud rings and overseas master criminals, using botnets and committing identity theft.

But while that kind of fraud certainly does exist, there is another type of fraud that can be equally troublesome and, to some extent, even harder to combat: fraud committed by individuals using their own legitimate information. A very common example of this kind of crime is shipping fraud and it takes several different forms. Here are a few examples and tips on how companies can address this problem. (more…)


UK Kicks Off National Identity Fraud Prevention Week

Wednesday, October 14th, 2009

In the UK, identity fraud has been identified as one of the fastest growing crimes in 2009. In response to this alarming news, the UK government is kicking off a National Identity Fraud Prevention Week to try to raise awareness about the issue and focus on what individuals and businesses can do to protect themselves.

With a website devoted to the new campaign, it’s easy to take a quick look at some statistics about fraud in the UK, and some of them are quite frightening. While the information on the site is based on UK numbers, the concerns that those statistics raise are likely applicable in many countries, as identify theft is a world-wide problem. (more…)


Is Australia an example of the consequences of inadequate investment in fraud prevention? Maybe not.

Monday, October 5th, 2009

“More than one in five people (in Australia) have fallen victim to credit card fraudsters or computer hackers.” This statistic comes from an article on Australian news site AdelaideNow, which details the findings of a recent report on credit and identity theft in the country. Apparently credit card fraud is up 23 percent from last year, and the blame is being placed on “Australia’s lapse in deploying anti-fraud technology.” (more…)


Largest Credit Card Theft Ever – Over 130 Million Credit Card Numbers Stolen

Friday, August 21st, 2009

This week the Associated Press reported that a Miami man and two Russian co-conspirators stole over 130 million credit card numbers in the largest theft of credit information ever.

Anyone who doesn’t think that online crime has transitioned into big time business should take note.  Online criminals are coordinated and remarkably well organized. They are becoming increasingly adept and efficient at not only obtaining, but sharing, valuable data: namely credit and identity information.

The extent to which online commerce companies rely on their ability to trust in this very same data cannot be overstated. Today, most online transactions are checked for fraud based upon credit and identity checks. If trust in that data is undermined, then the business models of hundreds of thousands of online retailers will suffer. (more…)


When Fighting Online Fraud Not All Device Reputation is Equal

Thursday, May 14th, 2009

I have recently answered several questions from individuals asking about device reputation. They have asked about the value of reputation data built by identifying infected PCs, i.e. botnets, as opposed to identifying PCs that have been used to commit actual online fraud or abuse. iovation pioneered the use of device fingerprinting in a shared database to build device reputations in 2004 and we have a lot of experience with this issue. There is a big difference between the two types of reputations and their relevant value. (more…)


Social Networks and Malware a Potent Combination

Wednesday, May 13th, 2009

Yesterday, SC Magazine reported that malware distributed on social networks was 10 times more effective than the same malware distributed through e-mail. They report that it is a big threat to the future of social networks and hypothesize that its effectiveness is due to the trust relationships that exist on these sites.

While the trust between friends on sites like Facebook and MySpace certainly contributes to the problem, there are probably three other factors that should be mentioned: (more…)


New Phishing Scam Spoofs Social Security Administration

Monday, May 11th, 2009

An SC Magazine article, out today, reports that a new phishing attack is now targeting individuals who will be receiving an economic payout later this month.

Phishing attacks are usually at the forefront of identity collection in today’s Fraud as a Service process. Phishing utilizes social engineering, which is both one of the oldest forms of security attack and is one of the hardest to fix. Social engineering tricks users into giving up sensitive data that online criminals would normally have a very difficult time obtaining in any other way. Today, the users personal information is the target of choice, but this is also very effective for obtaining account information and passwords.

Combating phishing isn’t difficult, it just requires the user to keep in mind that online businesses simply will not ask for sensitive information in an e-mail or link to a page that collects that data from an e-mail.


Is PCI Effective at Stopping Online Fraud? Congress Says No.

Thursday, April 2nd, 2009

Looks like congress feels like credit card companies haven’t done enough to stop online fraud and identity theft. The general feeling from lawmakers was that while the PCI standard does provide guidelines on how to protect customer card data and personal information, it isn’t effective at addressing ever changing threats. Lawmakers used an example of a company that had recently passed PCI compliance and was compromised while the actual certification was being granted.

Predictably representatives from the PCI council and the cards industry defended the standard and said that any company that had been shown to be breached was in violation of one of the standards at the time.

The reality of this all is that evidence of a breach doesn’t invalidate a standard. No regulation is going to stop online fraud, but it can dramatically reduce the risk as opposed to the absence of the standard. The real question should be how many breaches would have occurred without the standard and how must the standard evolve to be more effective and meet the worlds changing threat.


Is iPhone the Catalyst for Ubiquitous Multi-factor Authentication?

Tuesday, March 31st, 2009

This week alone, I have seen two separate iPhone apps enabling multi-factor authentication for the likes of your accounts at AOL, eBay, PayPal and Blizzard, the provider of the popular online game World of Warcraft. The first application is provided by Verisign and provides multi-factor authentication for AOL, eBay, and PayPal to combat identity theft and account takeover. This could easily be expanded to include other sites and is a significant improvement over the options that were previously available. The second application is provided by Blizzard to authenticate users to their popular online games, like World of Warcraft, and is intended to address their account takeover problems.

Before these mobile applications, sites could either provide a separate hardware token for multi-factor authentication which was expensive and difficult to manage, or it could provide this capability through a text message on the phone which could be costly for both the consumer and the company. This application solves the token problem by attaching itself to something that most users always have in their possession (their mobile phone) and solves the cost problem by bypassing costly text messages and embedding the password generation intelligence in the mobile app. There is a beta version of the Verisign app for some BlackBerry models and for another 40 phones in development. The Blizzard version is currently only available for the iPhone and iPod touch, but other models will likely follow.  The ease of adoption for the iPhone could be the difference make in this instance and it could be a positive step in the direction at combatting online fraud and more specifically account takeovers.