Internet Fraud Schemes
AUCTION AND RETAIL SCHEMES ONLINE
DANGER SIGNS OF FRAUD
The fraudsters use various methods. You can protect yourself by learning how to recognize some danger signs of fraud.
- False emails pretending your bank needs you to verify and upgrade personal information.
- False emails from a Web Site where you earlier have paid electronically with your credit card
- False Web Sites. Customers need to remember that just because something appears on Internet, and no matter how impressive a Web Site looks - it does not have to be true!
The avalibility of software allows anyone to set up a professional-looking website. This means that criminals can make their Web Sites as impressive and professional as those of legitimate e-commerce merchants!
- When you are told to give your credit card number in order to verify that you are not a minor.
- False Internet Auctions where you are manipulated into bidding on products that do not exist
- Business Opportunity »Work At Home« Online
- Good offers you »cannot« miss, - sometimes the fraudsters really urge you to buy and pay immediately. Do not be pressured, because demands that you act immediately are danger signs of fraud.
- Stock sale online. It is stock manipulation, and you will definitely loose money.
- Lottery sale online
- When you are informed that you have won a price in a lottery - e.g. a holiday to whatever destination - which might result that you in the end will have to pay for the whole journey incl. taxes and other unbelievable fees.
- When you are informed that you have been selected to get a loan with low interest, and is being encouraged to visit the website linked to the scam email - in order to confirm your curiousity and interest.
- Investments in projects and companies that do not exist.
- Investments in Ponzi/Pyramids where investors are promised abnormally high profits on their investments. Such systems always collapses, since no investment is actually being made.
- In cases where you are the seller, and the buyer wishes to pay with a cheque or other insecure methods of payment. Do not accept these methods!
- A fake Web Site - which often is linked to a scam email - encouraging you to load down the latest technology, and you follow their instruction. It results in Crimeware (malware) which automatically installes itself on your computer when you open an attachement or link in an email, install a program or visit a fake Web Site. Such a program give the fraudsters the opportunity to extract your passwords and other personal information.
- Be cautions when dealing with unknown individuals and with individuals outside of your own country.
Avoid the Threats of Auction and Retail Schemes
- Auctions Online where you are being manipulated into bidding - on products that do not exist
- Good offers you »cannot« miss, - sometimes the fraudsters really urge you to buy and pay immediately. Do not be pressured, because demands that you act immediately are danger signs of fraud!
- If an offer sounds suspecious and too good to be true - it usually is too good to be true!
- If a Seller or Buyer conceals his true identity, be especially careful!
- If someone sends you an email using an emailaddress with no useful data (e.g. Kara Karland »jfldinkzpohg@argyll.eng.sun.com«), it is an indication that the person does not want to leave any information that would allow you to contact them later - when you have a dispute over underlivered goods for which you have already paid.
- Do not pay for any products in forehand!
- Do not give your personal data online when you are asked to provide sensitive information as credit card number, bank account number, social security number. Secure transactions with known e-commerce sites are fairly safe especially if you use credit card - but nonsecure messages to unknown recipients are not safe!
- Do not walk blindly into the trap, when the Seller - who can post the auction from anywhere in the world - claims he is away on business or holiday and therefore must post the auction under another name; of a family member or friend, and informs you to transfer the funds to another individual.
- When you are informed by the Seller to transfer funds directly to him via bank-to-bank wire transfer, Western Union, or MoneyGram, - do not transfer any money! Money sent via wire transfer can be picked up anywhere in the world , and leave little recourse for the victim.
- Look carefully at the Seller who wants you to send checks or money orders immediately to a post office box, before you receive the goods or services you have ordered.
- Avoid Buyers and Sellers who acts as representatives of factories or autorized dealers in countries where such factores and dealers are not established.
- Avoid also Buyers who asks for the purchase to be shipped by using a certain method to avoid customs and taxes inside another another country.
- Be suspecious and demand other and more secure ways of payment, when the address of card holder does not match with shipping address. Before shipping any products, you should always have received the card holder`s authorization.
- Keep in mind that a WebSite, no matter how professional it looks, can be fake! Phony escrow service can be one of their activities. Once the money are wire-transferred to the fake escrow WebSites, the seller discontinues contact.
FRAUDULENT ORDERS
All online businesses will sooner or later run into a visitor trying to make fraudulent purchases on their website at some point. Hopefully the transaction or situation can be identified and corrected before it ever becomes a real problem.
It is very important for a business to be on the alert and be able to identify fraudulent situations and orders. Some danger signs of fraudulent orders are:
- Free Email Address (hotmail, gmail, yahoo, etc.)
- Email Address Without Relevance to the Company Name
- Fake Sounding Name (Ex: Ricky Dickson, Lucy Vellegas, Bob Monsen)
- Persons who are Requesting a List of Products From You First.
- Incorrect or Fake Phone Number
- Incorrect or Fake Fax Number
- Fake WebSite
- Abnormally High Ticket Price
- Different Shipping and Billing Addresses
- Orders from Nigeria, Anywhere in Africa, Indonesia, the Philippines, or foreign orders in general
- Unprofessional, Poor English Command, Misspellings
- Requesting Expedited Shipping
- Offering More Than the Listed Price for the Product.
- Unusual Quantity or Type of Product Ordered.
DO YOUR RESEARCH TO ENSURE THE LEGITIMACY OF THE COMPANY
The costs of frauds that can cause a great loss to your business, and it is definitely worth the time you use to take som extra steps for preventing it. If you receive a suspicious order - no matter small or large - we recommend you to do the following:
- Obtain the name, address and phone number of the company
- Contact a Business Agency to determine legitimacy of the company.
- Research the individual and company to ensure they are authentic.
- Call the customer to verify who they are.
- Ask for name of other customers of the company or the individual and contact them.
- If you find it unpleasant to speak with them, ask them kindly to forward by fax a copy of their drivers licence and a copy of their invoice.
- Be cautious when dealing with individuals outside your own country. You might believe that precautions like yours are not appropriate, but we believe that most customers will be happy to verify their information to you, as prevention of fraud is a matter of great concern to us all.
- Keep in mind - the perfect customer can fit the profile of someone ordering fraudulently.
CREDIT CARD FRAUD
By using an unlawfully obtained credit card number to order goods and services, - variations of online auction schemes will occure. Credit card numbers can be stolen from unsecured websites, or obtained in an identity theft scheme.
A variant of Identity Theft is when a fraudster has all the information necessary about you - enough information to be able to apply for a credit carn in your name - without your knowledge.
CREDIT CARD TESTING
Testing of Credit Cards is a type of fraud that many online businesses are not aware of, which is a systematic testing of credit card numbers with the purpose of finding a valid credit card number combined with a expiration date. Card testing can have devastating effects on a business even though the business may never ship out any products due to the fraudulent transaction. Within one day can ten thousands of credit card tests be made, without the knowledge of the victimized merchants who later will be charged for every transaction, whether they are declined or approved.
COUNTERFEIT CASHIER`S CHECK
The Counterfeit Cashier`s Check Sceme targets individuals that use Internet advertisements to sell merchandise. Often will such a check be sent to an unwitting victim who is instructed, on some pretext, to deposit it at his bank and return some of the funds. The victim is more likely to trust an "official" money order than a regular check. Because money orders are paid through the postal service rather than the usual check clearing system, they often take longer to "bounce" than an ordinary check. When this finally occurs it is charged back to the victim, who may already have sent back the funds, for which the victim must take the loss. For this reason banks are now applying increased security to incoming money orders, and are becoming more reluctant to accept them.
DEBT ELIMINATION
The potential risk of Identity Theft is high because the victims provide all their personal information. Debt Elimination generally involves websites or spam advertising a legal way to dispose of credit card debts and mortage loans.
FAKE BANKS AND ESCROW SERVICE FRAUD
In an effort to persuade a wary Internet auction participant, the fraudster can purpose the use of a third party escrow service to facilitate the exchange of money and merchandise. Be aware of fake banks and fake escrow services! Banks must be registered with the appropriate authorities in the country which they are located. If a bank or an escrow service are not registered/regulated it means that they are FAKE. Remember - Fake WebSite can be created within a few hours, and the WebSite you are being mislead to may be created to closely resemble a legitimate escrow service. To be absolutely certain that the information you have received is correct, telephone the regulatory authority in that country. If the bank or escrow service is real - check on the phone numbers or employee names that has been given to you - because fraudsters will often pretend to work for actual companies!
If it is not a legitimate service, you may risk, if you are the seller, sending the merchandise and await for the money - which you will never receive. Or if you are the buyer - you will pay through the fake bank or escrow service - but never receive any merchandise.
Some fake banks and escrow services also abuse the logos/seals of SSL Certification companies. Look up and check to see if they are really listed on their pages.
Look out for any of the following to IDENTIFY ABUSE of their seals:
- The WebSite you are investigating does not own a digital certificate.
- The information on the Seal Information Page does not match the information of the site.
- When the Trusted Site Seal is clicked, there is no information page that pops-up.
- There have been illegal (or any) modifications to the Trusted Site Seal.
- The Seal is being used to promote Spam, illegal activities or other questionable behaviour.
- If you mean you have found a WebSite of a company that is abusing the seals of the SSL Certification companies, please report to these SSL Certification companies immediately!
IDENTITY THEFT AND PHISHING/SPOOFING
Identity Theft is the wrongful obtaining and use of another`s personal information in ways that involves fraud schemes, typically for economic gain. Very often, victims are led to believe that they are providing their sensitive personal information to a legitimate business, when they are responsing to an email for updating membership information, or when applying for a fraudulent Internet job opportunity.
Phishers also use fake web sites to fool recipients into providing sensitive personal information and financial information such as credit card numbers, account usernames and passwords, social security numbers, etc. They abuse the trusted brands of well-known banks, online retailers, and credit card companies to convince recipients to respond to their requests of sensitive information.
WHAT YOU CAN DO TO AVOID IDENTY THEFT
- Do not provide any personal or financial information by email.
- Do not respond to email solicitations for your personal or financial information.
- Do not provide any personal information or information about your organization, including its structure or networks, unless you are certain of a person's authority to have the information
- Don't send sensitive information over the Internet before checking a web site's security.
- Pay attention to the URL of a web site. Fake web sites may look identical to a legitimate site, but the URL may use a variation in spelling or a different domain.
- Be suspicious of unsolicited phone calls, visits, or emails from individuals asking about employees or other internal information. If any unknown individuals claim to be from legitimate organizations, try to verify the person`s identity directly with the company.
- Do not use a contact information provided on a web site connected to the request for your personal information, instead check previous statements for contact information
- .If you are unsure whether an email request is legitimate, try to verify it by contacting the company directly. But do not use contact information provided in an email or on a web site, instead you should check previous statements for contact information.
- Install and Maintain Anti-Virus Software, Firewalls, and Email Spam Filters to reduce some of the unsolicited emails.
REPORT PHISHING/SPOOFING
- If you might have revealed sensitive information about your organisation, report it immediately to your employer.
- If you have releaved sensitive personal and financial information about yourself and believe that you financial accounts may be compromised, contact your financial institution immediately and close all account that may have been compromised.
- Report scam emails and websites with attempts of phishing to US CERT, which coordinates defense against and responses to caber attacks. If you have received a phishing email and would like to submit it to US Cert, please visit their website and follow their instructions for forwarding the phishing emails and websites. http://www.us-cert.gov/nav/report_phishing.html
INVESTMENT FRAUD
Online offers with false and fraudulent claims to solicit investments or loans, providing for purchase, use or trade of forged or counterfeit securities.
You may receive an email offering you a loan with low interest - encouraging you to visit their website to confirm your curiousity or interest. An example of such a phishing and fraudulent scam email is.
»My Dear, you have been approved for a $400,000 Home Loan for as low as $917 per month. This offer is being presented to you right now! Your credit history is now way a factor. Bad credit OK! To take advantage of this Limited Time Opportunity, please take a minute and confirm your curiosity and intention to take this loan, at the following website: ...."
MARKET MANIPULATION SCHEMES
There are two main methods for trying to manipulate stock and securities markets:
- Dissemination of false and fraudulent information to cause price increases in thinly traded stocks, before they sell off their holdings of these stocks (dumping) to realize substantial profits before the stock price falls back to its natural low level.
- Short-selling, by disseminating false and fraudulent information in an effort to cause price decreases in a particular company`s stock
LOTTERIES
A Thumb-Rule: IF you have NOT participated in a Lottery - How could you Win?
Fraudster who conduct this scheme randomly contact email addresses, advising people that they (or their email addresses) have been selected as the »winners« of an International Lottery. The »winners« will be advised to contact the processing company selected to process his winning. The agency˙s name, phone and fax number, and email address follow - and the »winners« are requested to pay an initial fee to initiate the process and additional fee requests after the process has begun.
JOB AND BUSINESS OPPORTUNITIES, WORK-AT-HOME SHCEMES ONLINE
Fraudulent schemes often use Internet to advertise Job and/or Business opprtunities, AND Work-At-Home Schemes, which claim to allow indivuals to earn thousands of dollars or euro in a months. Such schemes typically require individuals to pay an amount of money, or /and provide sensitive personal information, - but fail to deliver the materials or information that would be needed for the Job, the potential Business Opportunity or the Work-At-Home venture.
NIGERIAN LETTER, 419
419 derives from the section of Nigerian Law which covers fraud. The fraudulent scheme is called Nigerian Letter 419 scam, because the email scam promising a percentage of the cash if you help move money out of the country originated in Nigeria. The Nigerian Letter is written by individuals claiming to be Nigerian or foreign governments officials, and offer the recepient the »opportunity« to share in a percentage of millions of dollars, soliciting for help in placing a large amount of money in overseas bank accounts. The recipient is encouraged to send informations to the author of the letter, such as blank letter stationary, name of bank and account numbers, or other information, to a telefax number provided in the Nigerian letter.
PONZI/PYRAMID
A Ponzi scheme is a fraudulent investment operation that involves paying returns to investors out of the money raised from subsequent investors, rather than from profits generated by any real business. An advertisement is placed promising extraordinary returns on an investment - for example 20% for a 30 day contract. The precise mechanism for this incredible return can be attributed to anything that sounds good but is not specific: "global currency arbitrage", "futures trading", "high yield investment programs", or similar. The reality of the scheme is that the "return" to the initial investors is being paid out of the new, incoming investment money, not out of profits. There is no "global currency arbitrage", "futures trading", or "high yield investment" actually taking place.
The catch is that at some point one of three things will happen: (a) the promoters will vanish, taking all the investment money (less payouts) with them; (b) the scheme will collapse of its own weight, as investment slows and the promoters start having problems paying out the promised returns (and when they start having problems, the word spreads); or (c) the scheme is exposed, because much of the "assets" that are on the accounting records of the so-called enterprise do not (cannot) really exist
SPAM
Spam can act as vehicles for accessing computer and servers without autorization and transmitting viruses and botnets.
PROTECT YOUR COMPUTER!
- Do not open spam
- Do not click on on attachements or link in the spam
- Delete all spam when you receive them
- Keep your Browser and Computer up-to-date
- Visit the Web Site of your browser company, and make sure that your Browser is as secure as possible with the newest updates.
- At the PC-level, use Anti-Virus, Anti-Spam, Personal Firewall Software.
- Keep the Virus Protection Software up-to-date
- Use Virus Protection Software to Scan your computer regularly
- Use a Router to give your hardware an outer shell.
- Create different and unique Passwords for each one of your online accounts by using combinations of numbers and letters
- Keep your Passwords for yourself and do not share them with others
- Change your Passwords often
- Put Monitors in your network to know exactly what information was stolen and which people to contact in the event customer data is compromised.
- Encrypt e-mail, especially if it contains proprietary information.
- Take Back-up of your documents and photos regularly.