Online Fraud | Tizersecure.com
Add to Technorati Favorites Tizersecure.com

Online Fraud

Hacker Has 1.5 Million Facebook Accounts For Sale

by Shelley Koerber on Apr.26, 2010, under Computer Security, Cyber Attack, Hacker Scam, Online Fraud, Social media scam

A Russian hacker is believed to have stolen 1.5 million Facebook logins, meaning one out of every 300 accounts.  The hacker, who calls himself “kirllos” and currently lives in New Zealand, says he can sell you 1,000 Facebook logins for $25 or an account for as little as 25 cents each.  Pricing depends on how many friends the account holder has.  About 700,000 accounts have been sold so far on an underground website but it is unknown if they are legitimate accounts for real Facebook users.

According to Facebook’s Simon Axten, Facebook is investigating the specific accounts kirllos has put up for sale and will block access to those that have been hacked until they can be restored to their original users.  In one previous Facebook scam, criminals sent out messages from a compromised account telling friends that they were trapped in a foreign country and needed money.  Hackers also send out links to malicous software to friends of the account holder.

Someone can obtain a Facebook account for very cheap.  There are 400 million users worldwide and many fall victim to scams each day.  Only add friends that you know, make sure your privacy settings protect your personal information, and don’t click on suspicious links.

Leave a Comment :, , , , more...

Microsoft Researcher Thinks Password Changes are Pointless

by Shelley Koerber on Apr.19, 2010, under Computer Security, Hacker Scam, Online Fraud, Spam

Changing your passwords regularly is important, right?  Frequent password changes are intended to increase computer security, but users hate having to do it.  The most commonly used passwords are password, 12345, qwerty, and abc123.  Surprisingly, a recent study done by a Microsoft researcher states that changing your password is not necessary for password security.  He claims user education is not working and scheduled password updates offer little benefit in exchange for the effort and time they require.

In the report, Cormac Herley says “Security advice is a daily burden, applied to the whole population, while an upper bound on the benefit is the harm suffered by the fraction that become victims annually. When that fraction is small, designing security advice that is beneficial is very hard. For example, it makes little sense to burden all users with a daily task to spare 0.01% of them a modest annual pain.” The full report can be found here.

Some websites even prompt users to change their password often.  Passwords can be stolen through phishing or keylogging and once a password is stolen, the strength of it is irrelevant.  If a hacker obtains a password they will most likely use it immediately and not hold onto it for weeks or months.  Use different, complex passwords for each of your accounts and consider using a password manager that can generate them for you.  Some users even write their new password on sticky notes and put them on their computer, which is not a good idea.  Have a password that is easy for you to remember but not easy to guess.  The strongest passwords contain both letters and numbers and have some upper and lower case letters.  Many websites even show password strength meters, which give users an idea of the quality of their password.  The study also calculates that a task like changing a password and requiring one minute per day from every working adult in the U.S. costs about $15.9 billion per year.

Leave a Comment :, , , more...

Survey Discovers Millions of Email Users Intentionally Open Spam

by Shelley Koerber on Apr.09, 2010, under Botnet, Computer Security, Hacker Scam, Online Fraud, Spam

Online users are still opening spam email intentionally, despite awareness of the consequences.  The Ipsos Messaging Anti-Abuse Working Group (MAAWG) conducted a 2010 survey in the US, Canada, and Western Europe and found some shocking results.  They found that almost half of all North American and Western European users admitted to having opened spam intentionally to either unsubscribe, out of curiosity, to complain to the sender, or out of actual interest in the products or services offered.  About 18% wanted to “see what would happen” if they opened spam, while 4% are actually replying to spam.

Out of all six countries that were surveyed, 84% were aware of computer bots.  One-third say they consider it likely they will be infected but one in five are unsure how they would recognize a bot infection on their computer.  The continuous actions done by email users that receive spam are leading to the increase in botnets.  Less than half of email users think that stopping viruses is their own responsibility.  Nine in ten said their antivirus software was updated regularly, with 46% saying it is done automatically.  A good 43% report they would turn to their antivirus software company to get their computer repaired.  About 44% consider themselves “somewhat experienced” when it relates to internet security, while 20% considered themselves “very experienced.”   Many users do not even flag or report spam.

Who should be responsible for stopping the spread of viruses, fraudulent email, spyware, and spam?  About 65% feel it’s the ISPs and ESPs responsibility, 54%  feel antivirus companies are responsible, and 48% hold themselves responsible.  A great deal of importance is placed on emails containing receipts or shipping details for purchases (70%).  Those under the age of 35 are more likely to think billing notifications and marketing materials are important, while those aged 55 and older feel newsletters are important.  The survey also found that Canadian users are most likely to avoid posting their email address online, whereas more internet users in the US, Canada, and Germany are likely to set up another email address to avoid receiving spam.  How often do you click on a spam message?

Leave a Comment :, , , more...

Facebook Email Scam Downloads Malicious Software

by Shelley Koerber on Mar.19, 2010, under Botnet, Computer Security, Cyber Attack, Free tools, Hacker Scam, Malware, Online Fraud, Rootkit, Social media scam, Virus

Fake emails that claim to be from Facebook are being sent to users that read “Facebook Password Reset Confirmation, Customer Support,” encouraging them to click on an attachment to view their updated password.  What happens when you click on the attachment to retrieve your new password? It downloads a “password stealer” that will steal not only your Facebook password, but any other stored passwords you may have including email and banking passwords.

Hackers are utilizing Facebook because it is the most popular social networking website with about 400 million users.  The Facebook security page on the company website warns users of the spoofed email going around and reminds you that Facebook will never send a new password in an attachment. They suggest social networking users warn their friends about the scam.  The attachment in the email infects computers without any clear signs of what is happening so the user has no idea.  This spam is believed to have been sent using botnets  Cutwail and Rustock, which have the ability to control groups of computers to send out spam like this.  Tizer™ Rootkit Razor was just updated to be able to detect the latest rootkits Rustock and 4DW4R3 that have these hacker capabilities.  Download it free here to scan your computer.

You can expect that out of 400 million Facebook users, a good 10% will click on the attachment and be infected by this malicious virus.  That would mean 40 million computers infected, giving hackers such a large amount of personal information.

Leave a Comment :, , , more...

FBI Says Online Fraud Doubled in 2009

by Shelley Koerber on Mar.15, 2010, under Computer Security, Cyber Attack, Hacker Scam, Online Fraud

According to FBI reports last week, losses from online fraud rose from $264.6 million in 2008 to $559.7 million in 2009. Last year the Internet Crime Complaint Center (IC3) received 336,655 complaints, a big 22.3% increase from the year before. The IC3 is a partnership between the FBI and National White Collar Crime Center.

The highest percentage of complaints, 16.6%, were email scams that falsely claimed to be from the FBI to gain personal information. The top five categories of reported offenses included non-delivered merchandise and/or payment at 19.9%, identity theft, 14.1%, credit card fraud, 10.4%, auction fraud, 10.3%, and computer fraud, 7.9%.

One popular scam was a phone pitch made by someone sounding like President Barack Obama, encouraging people to visit a website for government stimulus money. Those who visited and paid the $28 in fees after handing over their personal information did not get the promised stimulus check. Another commonly reported scam was fake pop-up ads for malicious anti-virus software. Victims receive ads warning them of threatening viruses on their computer that end up downloading malicious code to their computer after clicking.

Over 86.7% of complaints reported to law enforcement showed a loss of $5,000 or less. The median dollar loss was $575. More than half of the complaints came from males, and 92% came from the United States.  Anyone who uses the internet can be a victim of cybercrime.  Tizer Secure™ offers internet security protection to help keep your personal information safe.

The full internet crime report can be found here.

Leave a Comment :, , , , more...