Modern Day Internet Identity Theft

. Friday, May 2, 2008
0 comments

I came across an article talking about a recent report on a new Trojan virus going around. What makes this one special is how sophisticatedly composed it is. It makes us step back and almost admire what a journey Internet scams have been through to develop to what it can do now. Some features of this virus include how it is able to steal identity information even if it's encrypted using safe mode "https". The virus can be installed to your computer simply by visiting an infected website, and you won't have any idea it's there. It can also collect loads of information and send it to a main computer located in Russia, which also contains an efficient interface that lets identity thieves to purchase the stolen data with ease. Sound scary? There's even more.

This program, nicknamed "Gozi", automatically and discretely installs itself on your computer. And immediately following, it programs your computer to execute the program every single time it is rebooted. The execution is completely hidden from the user and the user has absolutely no way of detecting it! The reporter watched as Gozi logged smoothly into a bank account and monitored everything coming in and out of the computer like a router. This sentence gave me shivers: "Each time some information is provided to the bank site, such as username or password, the same information is also transmitted to Gozi’s home server". Imagine the countless data that could be collected. How are they ever going to stop this?

Thousands and thousands of computers have been breached and probably more who don't realize they are infected yet. Anti-virus and anti-spyware softwares were tested in an experiment to identify Gozi. But out of the 30 programs who analyzed Gozi, most had a warning saying it was some kind of unknown threat, while 5 found no threat. Who knows what kind of people can go and purchase this information? It is surreal to me that they systematically collect bank account login details! With this information, how can we prevent fraudulent financial transactions at all? Aren't the possibilities of this simply endless?

A Closer Look

. Tuesday, April 29, 2008
0 comments

Who knew that when more than 60 innocent individuals applied for a job posting that was listed online, they were to become victims of Internet identity theft. That is just ridiculous to me. But it's what happened in a case that took place in Ottawa since 2002. These applicants were notified that they were suitable candidates for the $70,000-a-year job position, and were asked to fill out an application form with a $20 processing fee. These positions obviously did not exist, and served the purpose of luring people in. Although the process sounds convincing as it is, job postings on the Internet cannot be as easily trusted without a thorough check on the hiring company's background.

This is clearly a very clever way of luring that doesn't take much ignorance of the Internet to fall for. It doesn't seem very sketchy to me, at least, to post a job listing on the web. This only tells us that we need to be even more skeptical about things we find on the Internet and question anything and everything.

Another example is in 2005, when 6 men who operated “shadowcrew.com”, one of the largest websites for trafficking in stolen credit and bank card numbers and identity information, pleaded guilty in federal court. The online marketplace has reportedly trafficked at least 1.5 million stolen credit and bank card numbers that resulted in losses of more than $4 million. At least there is some bright side to this. “These individuals proved in a big way that the Internet can be a dangerous place where consumers can be victimized without warning,” said U.S. Attorney Christopher J. Christie. “But as this case also shows, criminals operating in the virtual world of the Internet are not ultimately anonymous. Their crimes can be traced and documented, and they can be tracked down, arrested, prosecuted and sent to prison.”

Unsurprisingly, the more cases I've read on Internet identity theft, the more I am concerned about my own safety browsing the net. It is no wonder my parents dislike any purchasing made on the web and encourage me to avoid it as much as possible. Before, I ultimately thought they worry too much like most parents and just needed to relax. As long as you're careful and the website isn't sketchy, there's nothing wrong with giving out credit card numbers. But these cases get scarier and scarier, I have no doubt in my mind that someone out there has my personal information stored on some database just waiting to be used in one way or another. A scary thought.

What it is and how it works

. Monday, April 28, 2008
2 comments

Perhaps you might not have known previously, but your computer contains all sorts of information on your hard drive. When surfing the Internet, it collects files like cache, browser history, and other temporary Internet files and stores them hidden deep in your memory. These files can contain information about you such as login IDs and passwords, even credit card numbers. People can get at this information in one of two ways. One is when your Internet connection is being sent over an insecure connection. The other is by installing spyware or other software on your computer that will collect information automatically and send it right back to the thief.

As the Internet becomes more and more prominent in our daily lives, identity theft will become more an issue than ever. According to the FTC ( Federal Trade Commission ), as many as 1 in 8 Americans in the past 5 years has been affected by Internet identity theft. That is a pretty big number to me, and it is scary to think that you have been a victim, but you don't even know it.

Identity theft can lead to devastating results. Thieves can manipulate your information and invade your personal and financial life. They can use stolen identities to go on shopping sprees and commit other even more serious crimes. Even if they didn't do anything illegal with my information, I know I wouldn't want anyone to pretend to be me. As Internet users, we must educate ourselves about this issue in order to prevent and protect ourselves from being victims of Internet identity theft.

During the next little while, I will go in depth with more research on this problem and focus on different aspects such as: prevention, victims, popular methods, phishing, particular cases etc. Stay tuned.