Home > Phishing for Mules

Opinion

Phishing for Mules

10/12/2007

We all know, or should know, about phishing, a fraudulent attempt, frequently through legitimate looking e-mail requests, to obtain personal information such as a credit card number, a social security number, or a bank account number and PIN.  The following is one that I received the other day.
Warning Notification

It has come to our attention that your Community National Bank account information needs to be updated as part of our continuing commitment to protect your account and to reduce the instance of fraud on our website.  If you could please take 5-10 minutes out of your online experience and update your personal records you will not run into any future problems with the online service.

However, failure to update your records will result in account suspension.  Please update your records before: Sunday, [October 14, 2007].

Once you have updated your account records, your account activity will not be interrupted and will continue as normal.

Click here to update your account information
As incredible as it sounds, people respond to e-mails like this.  A recent Harvard study found that 90 percent of the phishing recipients don't recognize a well constructed phish.  What I found even more surprising was that neither education, age, sex, previous experience, nor hours of computer use showed a statistically significant correlation with vunerability to phishing.  

The real problem for the phisher isn't getting the information; it's how to convert ill-gotten information into cold cash.  One way is to simply sell the information on the black market where the going price for a credit card number is around $1. That is what apparently happened to some of the 47.5 million plus credit card numbers stolen from TJX several years ago.  More information raises the value.  A card with a three-digit code brings around $5. while additional security information such as a mother's maiden name can raise the value another $10.  A working PIN can drive the price to more than $100.

In any case, at some point the stolen information needs to be translated into cash or merchandise that can be resold.  In March of this year a Florida gang was charged with using credit card numbers from the TJX theft to steal $8 million in small transactions at stores in Florida.  

The fact that they were caught underscores the phisher's problem.  It is hard to make serious money without being noticed--and being caught and sent to jail.  (In Florida it was a Wal-Mart clerk in Gainesville who became suspicious of multiple gift-card purchases that led to a review of store surveillance tapes.)  

To take full advantage of stolen information, the crook, who is frequently operating from a foreign country, needs "mules."  A mule is someone, preferably in the same country as the victim, to handle money transfers or ship items to the phisher.  The more tenuous the money trail, the more likely it is that crook can get away with it.  I made up the following narrative, but it is based on real events.


Recommended Reading
  • Digital Arts Alliance Adds Fordham U

    The Digital Arts Alliance, a consortium led by the Pearson Foundation that promotes digital arts in K-12 education, is expanding its membership with the addition of Fordham University. This follows on the heels of three other organizations joining the group back in July--the National Education Association (NEA) Foundation, the Foundation for Investor Education, and Employers For Education Excellence (E3).

  • Payment Card Security Toughens with DSS 1.2 Release

    Opinions are mixed on what the new Payment Card Industry (PCI) DSS 1.2 standard will mean for security pros going forward. However, the mandate is clear: protect data.

  • 6 Universities Join NASA Astrobiology Institute

    Research teams from six universities have been selected by NASA to become members of its Astrobiology Institute with the aim of exploring the "origins, evolution, distribution, and future of life in the universe." Teams were each awarded five-year grants, averaging $7 million each, according to NASA.

  • Amazon To Host Microsoft Solutions in the Cloud

    Amazon announced Wednesday that it is conducting a private beta test of Microsoft's server products running on Amazon's hosted computing platform, which is called Amazon Elastic Compute Cloud (EC2). Amazon expects to offer companies the ability to run their applications on EC2 using Microsoft Windows Server or Microsoft SQL Server sometime in the fall, according to an announcement issued by the company.

  • CRM Pushing into New Areas of Higher Ed

    Implementing a customer relationship management (CRM) solution can require "difficult or even painful behavioral challenges" for administrators in higher education, according to Nicole Engelbert, a lead analyst with research and analysis firm Datamonitor. "It means re-orienting yourself to your students. That can be tough, so you need to be ready for that."

  • Integrated Collaborative Environment Leverages Web 2.0

    Here's a bit of trivia for your next high-tech happy hour: A "nog" (in addition to being a Christmas favorite) is a wooden block built into a masonry wall so that joinery structure can be nailed to it. For the founders of Piscataway, N.J.-based startup Bluenog this obscure bit of carpentry nomenclature was the perfect metaphor for an integrated software suite that includes a content management system (CMS), rich portal features and business intelligence (BI) capabilities.