Click here to receive your FREE subscription to Campus Technology
Home > Phishing for Mules
Opinion
Phishing for Mules
10/12/2007
By Doug Gale
Tom was desperate. He and Mary had thought that they we pretty well set. But that was before he lost his job of 23 years when the plant closed and Mary got sick and had to stop working. Now Tom was working three part-time jobs, anything he could get, but without health insurance and mounting medical bills, they were sliding towards financial disaster. That's when he saw an online bulletin board ad for a "shipping manager" to help in product distribution. The job promised a $50 commission per package transfer plus a $2,000 per month base salary. No special skills were required, and it required no financial investment on his part. Best of all he could work from home, which made it easier for him to care for Mary. The prompt response to his query contained a personal information form and an application for employment. The first form requested his name, address, phone number, electronic contact information, and bank account number so that funds could be deposited in his account. The application for employment was standard and included a detailed list of his duties if hired. As merchandise arrived at his home he had to repackage it and ship it to an overseas address. Everything worked great for the first month. Tom spent a couple of hours a day reshipping high-end merchandise from regional stores to an address in Panama. He'd made almost $5,000 dollars and thought that he and Mary had turned the corner financially. Then the police showed up. It seems that the merchandise had been purchased with stolen credit card numbers, and the address in Panama turned out to be nothing more than an abandoned mail drop. When Tom pleaded that he didn't know that the merchandise was purchased illegally, he was told that even though he had nothing to do with the theft from another persons credit card account, he was still breaking the law.A variation on this theme is for mules to receive funds into their accounts and then send the money overseas by wire transfer. The mule receives a commission on each transaction. Ads for these mules might be for a "Financial Operations Manager" responsible for transferring money for young cancer patients in a foreign country.
This is money laundering and is illegal. It also leaves the "mule" holding the bag while the phisher walks. The quote incorrectly attributed to P.T. Barnum, "There's a sucker born every minute," seems to be true.
The
Bank Safe Online organization has developed the following guidelines for recognizing mule solicitations:
- Be wary of any unsolicited offers or opportunities for work, especially if the company is based overseas;
- Verify the details of any company that you are consider dealing with and never give your bank account details to someone you don't know or trust;
- Contact your bank immediately if you think that you may have become involved in a money mule scam;
- If you see an opportunity to make some easy money and the offer seems too good to be true, then it probably is!
It's unlikely that anyone reading this column would be tricked into becoming a mule. We do, however, have a responsibility to make sure that the general community can recognize, and hopefully ignore, these scams. It may be nothing more than counseling friends, but it could include speaking to local schools and community organizations. And since most of us are in education, we have a role in protecting students by not only making them aware of phishing but also explaining how fundamentally honest individuals can be suckered into criminal actions.
Doug Gale is president of Information Technology Associates, LLC (www.it associates.org) an IT consultancy specializing in higher education. He has more than 30 years of experience in higher education as a faculty member, CIO, and research administrator.
Cite this Site
Doug Gale, "Phishing for Mules," Campus Technology, 10/12/2007, http://www.campustechnology.com/article.aspx?aid=50794
copy text (above) for proper citation
Recommended Reading
- U Wyoming Students Vote To Implement Sonic Foundry's Mediasite for Lecture Capture
An overwhelming student vote for Mediasite will put the Webcasting platform from Sonic Foundry into University of Wyoming lecture halls this fall. Mediasite is a presentation capture tool that records and synchronizes audio, video, and slides and then allows the presenter to provide it online for on-demand viewing or in podcast form. The tool also enables the presenter to make the presentation available online as it happens.
- DNS Flaw Unfixed as Experts Argue Protocol
Speculation continues as to what the ultimate systemic Domain Name System (DNS) flaw could be. This flaw apparently allows Web surfers to be spoofed, directing them to fake Web sites to gain passwords and load malware on their computers.
- IT Cost Cuts in 2008 May Be a Trend, Study Says
A first-quarter 2008 survey conducted by Computer Economics suggests a possible slowdown in IT spending and staffing lies ahead.
- Microsoft Revamps Its Platforms Division, Loses Kevin Johnson
Microsoft announced late Wednesday a reorganization of its Platforms & Services Division (PSD), as well as the departure of Kevin Johnson, a 16-year Microsoft veteran and president of the PSD.
- Microsoft's DNS Fix Leads to More Problems
The blogosphere is awash with talk about the possible overall weakness of the Domain Name System (DNS) architecture. For its part, Microsoft's released a DNS fix in its patch slate for July, but Redmond seems to have problems just getting it to end users. Moreover, some users of the DNS fix have experienced additional difficulties.
- D2L Launches Mobile Learning Environment
Desire2Learn this week announced a new mobile application of its Desire2Learn Learning Environment. Called Desire2Learn 2GO, the application ties in with Learning Environment 8.3 to provide access via Blackberry. The company also announced that it's streamlining integration Respondus 3.5, a quiz- and test-building application.