The security breach that hit Target Corp. during the holiday season appears to have been part of a broader and highly sophisticated scam that potentially affected a large number of retailers, according to a report published by a global cyber intelligence firm that works with the U.S. Secret Service and the Department of Homeland Security.
The report, made public Thursday by iSight Partners of Dallas, offers more insight into the breach at Target. That attack affected 40 million credit and debit card accounts and led to the theft of personal information, including email addresses and names, of as many as 70 million customers.
The report said that a malicious program vacuuming personal data from terminals at store check-out stations was "almost certainly derived" from BlackPOS, a crude but effective piece of software that contained malware scripts with Russian origins.
"The use of malware to compromise payment information storage systems is not new," the report said. "However, it is the first time we have seen this attack at this scale and sophistication."
Starting in June, iSight noticed the malicious software codes on the black market, the report said.
Criminals bought the original malware on the black market and then created their own attack method to target retailers' terminals at store checkout stations, iSight Partners' CEO John P. Watters said.
"It's less about the malware, but more about the sophistication of the attacks," Watters said in an interview with The Associated Press.
The report noted that because this kind of software can "cover its own tracks," it's not possible to determine the scale, scope and reach of the breach without detailed forensic analysis.
"Organizations may not know they are infected," the report said. "Once infected, they may not be able to determine how much data has been lost."
Last week, Neiman Marcus said thieves stole some of its customers' payment information and made unauthorized charges over the holidays. At the time, it said that was working with the Secret Service on the breach.
The iSight report doesn't list the names of retailers and the intelligence firm says it can't discuss whether the malicious software specifically affected Target, Neiman Marcus and other retailers. However, the report offers the latest evidence that the attacks on Target and Neiman Marcus are related and that other retailers may have been victims of a broader data scheme.
Molly Snyder, Target spokeswoman, said that the retailer did not have any details to share on the report at this time.
Neiman Marcus Group said Thursday that, to its knowledge, customers' Social Security numbers and birthdates were not stolen in the security breach.
The luxury retailer, based in Dallas, also confirmed that customers who shopped online do not appear to have been affected, and said personal identification numbers, or PINs, were never at risk because the retailer does not require PIN pads in its stores.
Neiman Marcus's spokeswoman Ginger Reeder declined to say how many people were affected by the scam, noting that the investigation is still ongoing.
Showing posts with label scam. Show all posts
Showing posts with label scam. Show all posts
Friday, January 17, 2014
Monday, December 2, 2013
Tips to Avoid Being Scammed This Holiday Season
In advance of the holiday season, the FBI reminds shoppers to beware of cyber criminals and their aggressive and creative ways to steal money and personal information. Scammers use many techniques to fool potential victims, including fraudulent auction sales, reshipping merchandise purchased with a stolen credit card, sale of fraudulent or stolen gift cards through auction sites at discounted prices, and phishing e-mails advertising brand name merchandise for bargain prices or e-mails promoting the sale of merchandise that ends up being a counterfeit product.
Fraudulent Classified Ads or Auction Sales
Internet criminals post classified ads or auctions for products they do not have. If you receive an auction product from a merchant or retail store rather than directly from the auction seller, the item may have been purchased with someone else’s stolen credit card number. Contact the merchant to verify the account used to pay for the item actually belongs to you.
Shoppers should be cautious and not provide credit card numbers, bank account numbers, or other financial information directly to the seller. Fraudulent sellers will use this information to purchase items for their scheme from the provided financial account. Always use a legitimate payment service to protect purchases.
Diligently check each seller’s rating and feedback along with their number of sales and the dates on which feedback was posted. Be wary of a seller with 100 percent positive feedback if they have a low total number of feedback postings and all feedback was posted around the same date and time.
Gift Card Scam
The safest way to purchase gift cards is directly from the merchant or authorized retail merchant. If the merchant discovers the card you received from another source or auction was initially obtained fraudulently, the merchant will deactivate the gift card number and it will not be honored to make purchases.
Phishing and Social Networking
Be leery of e-mails or text messages you receive indicating a problem or question regarding your financial accounts. In this scam, you are directed to follow a link or call the number provided in the message to update your account or correct the problem. The link actually directs the individual to a fraudulent website or message that appears legitimate; however, any personal information you provide, such as account number and personal identification number (PIN), will be stolen.
Another scam involves victims receiving an e-mail message directing the recipient to a spoofed website. A spoofed website is a fake site or copy of a real website that is designed to mislead the recipient into providing personal information.
Consumers are encouraged to beware of bargain e-mails advertising one day only promotions for recognized brands or websites. Fraudsters often use the hot items of the season to lure bargain hunters into providing credit card information. The old adage, "If it seems too good to be true, it probably is," is a good barometer to use to legitimize e-mails.
Black Friday has traditionally been the "biggest shopping day of the year." The Monday following Thanksgiving has more recently (2005) been labeled Cyber Monday, meaning the e-commerce industry endorses this special day to offer sales and promotions without interfering with the traditional way to shop. Scammers try to prey on Black Friday or Cyber Monday bargain hunters by advertising "one day only" promotions from recognized brands. Consumers should be on the watch for too good to be true e-mails from unrecognized websites.
Along with online shopping comes the growth of consumers using social networking sites and mobile phones to satisfy their shopping needs more easily. Again, consumers are encouraged to beware of e-mails, text messages, or postings that may lead to fraudulent sites offering bargains on brand name products.
Tips
Here are some tips you can use to avoid becoming a victim of cyber fraud:
For more information on e-scams, please visit the FBI’s New E-Scams and Warnings webpage at www.fbi.gov/scams-safety/e-scams.
Fraudulent Classified Ads or Auction Sales
Internet criminals post classified ads or auctions for products they do not have. If you receive an auction product from a merchant or retail store rather than directly from the auction seller, the item may have been purchased with someone else’s stolen credit card number. Contact the merchant to verify the account used to pay for the item actually belongs to you.
Shoppers should be cautious and not provide credit card numbers, bank account numbers, or other financial information directly to the seller. Fraudulent sellers will use this information to purchase items for their scheme from the provided financial account. Always use a legitimate payment service to protect purchases.
Diligently check each seller’s rating and feedback along with their number of sales and the dates on which feedback was posted. Be wary of a seller with 100 percent positive feedback if they have a low total number of feedback postings and all feedback was posted around the same date and time.
Gift Card Scam
The safest way to purchase gift cards is directly from the merchant or authorized retail merchant. If the merchant discovers the card you received from another source or auction was initially obtained fraudulently, the merchant will deactivate the gift card number and it will not be honored to make purchases.
Phishing and Social Networking
Be leery of e-mails or text messages you receive indicating a problem or question regarding your financial accounts. In this scam, you are directed to follow a link or call the number provided in the message to update your account or correct the problem. The link actually directs the individual to a fraudulent website or message that appears legitimate; however, any personal information you provide, such as account number and personal identification number (PIN), will be stolen.
Another scam involves victims receiving an e-mail message directing the recipient to a spoofed website. A spoofed website is a fake site or copy of a real website that is designed to mislead the recipient into providing personal information.
Consumers are encouraged to beware of bargain e-mails advertising one day only promotions for recognized brands or websites. Fraudsters often use the hot items of the season to lure bargain hunters into providing credit card information. The old adage, "If it seems too good to be true, it probably is," is a good barometer to use to legitimize e-mails.
Black Friday has traditionally been the "biggest shopping day of the year." The Monday following Thanksgiving has more recently (2005) been labeled Cyber Monday, meaning the e-commerce industry endorses this special day to offer sales and promotions without interfering with the traditional way to shop. Scammers try to prey on Black Friday or Cyber Monday bargain hunters by advertising "one day only" promotions from recognized brands. Consumers should be on the watch for too good to be true e-mails from unrecognized websites.
Along with online shopping comes the growth of consumers using social networking sites and mobile phones to satisfy their shopping needs more easily. Again, consumers are encouraged to beware of e-mails, text messages, or postings that may lead to fraudulent sites offering bargains on brand name products.
Tips
Here are some tips you can use to avoid becoming a victim of cyber fraud:
- Do not respond to unsolicited (spam) e-mail.
- Do not click on links contained within an unsolicited e-mail.
- Be cautious of e-mails claiming to contain pictures in attached files, as the files may contain viruses. Only open attachments from known senders. Always run a virus scan on attachment before opening.
- Avoid filling out forms contained in e-mail messages that ask for personal information.
- Always compare the link in the e-mail to the web address link you are directed to and determine if they match.
- Log on directly to the official website for the business identified in the e-mail, instead of "linking" to it from an unsolicited e-mail. If the e-mail appears to be from your bank, credit card issuer, or other company you deal with frequently, your statements or official correspondence from the business will provide the proper contact information.
- Contact the actual business that supposedly sent the e-mail to verify that the e-mail is genuine.
- If you are requested to act quickly or there is an emergency, it may be a scam. Fraudsters create a sense of urgency to get you to act impulsively.
- If you receive a request for personal information from a business or financial institution, always look up the main contact information for the requesting company on an independent source (phone book, trusted Internet directory, legitimate billing statement, etc.) and use that contact information to verify the legitimacy of the request.
- Remember if it looks too good to be true, it probably is.
For more information on e-scams, please visit the FBI’s New E-Scams and Warnings webpage at www.fbi.gov/scams-safety/e-scams.
Labels:
bail,
bonds,
holiday season,
New Jersey,
NJ,
rapid,
release,
scam
Tuesday, October 22, 2013
Former Orthodontist Convicted of Attempting to Scam the IRS of $36 Million
ALBANY, NY—Richard S. Hartunian, United States Attorney, Northern District of New York, announces that on October 21, 2013, before Senior U.S. District Court Judge Tomas J. McAvoy, a jury convicted Glenn Richard Unger (62, of Ogdensburg, New York) of the following offenses: obstructing and impeding the Internal Revenue Service (IRS); filing false claims against the United States; tax evasion; and passing fictitious obligations.
The evidence at trial showed that Glenn Richard Unger engaged in a multi-year scheme to obstruct and impede the IRS by filing numerous false and fraudulent claims with the IRS for payment of a refund of taxes totaling approximately $36 million. Between 2007 and 2011, Glenn Richard Unger filed 14 false tax returns claiming that he earned substantial income reported on IRS Forms 1099-OID, had substantial withholdings on that income, and was entitled to $36 million in tax refunds. Despite numerous warning letters from the IRS that his returns were frivolous, he continued filing false tax returns.
In addition to obstructing the IRS by filing false and fraudulent claims for refund, the evidence at trial also showed that Glenn Richard Unger attempted to evade payment of taxes he owed to the IRS. During 2004 and 2005, Glenn Richard Unger earned income and failed to file tax returns reporting that income. The IRS assessed taxes for those two years and also assessed penalties for filing frivolous tax returns. After the IRS filed a tax lien against Glenn Richard Unger, the defendant attempted to file a false document with the Saratoga County Clerk’s office attempting to release the lien. Evidence at trial also showed that Glenn Richard Unger tried to pay off a debt to another orthodontist with a fictitious document purported to be worth $200,000.
As a result of the conviction, the defendant is facing a statutory maximum term of imprisonment of 25 years and a maximum fine of $250,000. Sentencing is scheduled for March 10, 2014 in Albany, New York.
This prosecution resulted from an investigation conducted by the Internal Revenue Service, Criminal Investigation, New York Field Office; the Federal Bureau of Investigation, Albany Field Office; the New York State Police, and the Treasury Inspector General for Tax Administration. The case was prosecuted by Assistant United States Attorney Ransom P. Reynolds (Northern District of New York) and Jeffrey Bender (Department of Justice Tax Division).
The evidence at trial showed that Glenn Richard Unger engaged in a multi-year scheme to obstruct and impede the IRS by filing numerous false and fraudulent claims with the IRS for payment of a refund of taxes totaling approximately $36 million. Between 2007 and 2011, Glenn Richard Unger filed 14 false tax returns claiming that he earned substantial income reported on IRS Forms 1099-OID, had substantial withholdings on that income, and was entitled to $36 million in tax refunds. Despite numerous warning letters from the IRS that his returns were frivolous, he continued filing false tax returns.
In addition to obstructing the IRS by filing false and fraudulent claims for refund, the evidence at trial also showed that Glenn Richard Unger attempted to evade payment of taxes he owed to the IRS. During 2004 and 2005, Glenn Richard Unger earned income and failed to file tax returns reporting that income. The IRS assessed taxes for those two years and also assessed penalties for filing frivolous tax returns. After the IRS filed a tax lien against Glenn Richard Unger, the defendant attempted to file a false document with the Saratoga County Clerk’s office attempting to release the lien. Evidence at trial also showed that Glenn Richard Unger tried to pay off a debt to another orthodontist with a fictitious document purported to be worth $200,000.
As a result of the conviction, the defendant is facing a statutory maximum term of imprisonment of 25 years and a maximum fine of $250,000. Sentencing is scheduled for March 10, 2014 in Albany, New York.
This prosecution resulted from an investigation conducted by the Internal Revenue Service, Criminal Investigation, New York Field Office; the Federal Bureau of Investigation, Albany Field Office; the New York State Police, and the Treasury Inspector General for Tax Administration. The case was prosecuted by Assistant United States Attorney Ransom P. Reynolds (Northern District of New York) and Jeffrey Bender (Department of Justice Tax Division).
Tuesday, September 17, 2013
FBI Atlanta Warns Consumers of Green Dot MoneyPak Scam
ATLANTA—Special Agent in Charge (SAC) Mark F. Giuliano, FBI Atlanta Field Office, in an effort to provide an alert or warning to consumers, is providing the following details of an emerging scam that has been reported throughout the country and is now making an appearance in Georgia.
On September 12, 2013, 10 retail stores in Savannah, Georgia, each received telephonic bomb threats. In each case, the caller asked to speak to the store manager, demanding that 10 Green Dot MoneyPak cards each be activated and loaded with $500 and that the card numbers be read aloud over the phone. The caller threatened to blow up the stores if the managers did not comply and also threatened the store employees’ homes and families. The managers of all the stores described the caller as a male between 20 to 30 years of age and with a foreign accent. No manager complied with the demands, and no explosive devices were found.
Subsequent investigation has determined that these calls mirrored a number of similar telephonic threats made to various drug stores and retail outlets nationwide. One such call placed to a discount department store in Snellville, Georgia, was identified as an overseas Voiceover IP (VoIP) telephone number. To date, no explosive devices have been found anywhere in the country linked to this type of threat.
While the above incidents involved bomb threats, the types of threats vary. Green Dot MoneyPak cards are reloadable and available at most retail outlets throughout the country and, like money wire transfers, are just as untraceable. These cards are not associated with any bank, meaning that the money is in the card. Users of these Green Dot MoneyPak cards are reminded to never give anyone those numbers associated with those cards in that doing so gives them instant access to the money on those cards.
Anyone with information regarding this type of emerging scam can provide a report or complaint to the FBI at www.IC3.gov.
On September 12, 2013, 10 retail stores in Savannah, Georgia, each received telephonic bomb threats. In each case, the caller asked to speak to the store manager, demanding that 10 Green Dot MoneyPak cards each be activated and loaded with $500 and that the card numbers be read aloud over the phone. The caller threatened to blow up the stores if the managers did not comply and also threatened the store employees’ homes and families. The managers of all the stores described the caller as a male between 20 to 30 years of age and with a foreign accent. No manager complied with the demands, and no explosive devices were found.
Subsequent investigation has determined that these calls mirrored a number of similar telephonic threats made to various drug stores and retail outlets nationwide. One such call placed to a discount department store in Snellville, Georgia, was identified as an overseas Voiceover IP (VoIP) telephone number. To date, no explosive devices have been found anywhere in the country linked to this type of threat.
While the above incidents involved bomb threats, the types of threats vary. Green Dot MoneyPak cards are reloadable and available at most retail outlets throughout the country and, like money wire transfers, are just as untraceable. These cards are not associated with any bank, meaning that the money is in the card. Users of these Green Dot MoneyPak cards are reminded to never give anyone those numbers associated with those cards in that doing so gives them instant access to the money on those cards.
Anyone with information regarding this type of emerging scam can provide a report or complaint to the FBI at www.IC3.gov.
Art Dealer Pleads Guilty in Manhattan Federal Court to $80 Million Fake Art Scam, Money Laundering, and Tax Charges
Preet Bharara, the United States Attorney for the Southern District of New York, announced that art dealer Glafira Rosales pled guilty today in Manhattan federal court to participating in a scheme to sell more than 60 fake works of modern art to two New York art galleries. Her victims paid more than $80 million for the fake works. Rosales also pled guilty to conspiracy to sell the fake works, conspiracy to commit money laundering, money laundering, and several tax crimes related to the fake art scheme. Rosales pled guilty before U.S. District Court Judge Katherine P. Failla.
Manhattan U.S. Attorney Preet Bharara said, “With her guilty plea today, Glafira Rosales acknowledges her role in a sprawling fraud that involved the commission of phony artworks she represented as real and her efforts to hide the proceeds of this massive scam in foreign bank accounts. Rosales’s plea shows that no matter how wide-ranging the deception, this office will continue to bring the perpetrators of fraud to justice.”
According to the allegations contained in the complaint, indictment, superseding indictment, and statements made in court:
Rosales was an art dealer who, starting in 1994 and continuing through 2009, sold more than 60 never-before-exhibited and previously unknown works of art (the “works”) that she claimed were by the hand of some of the most famous artists of the 20th century, such as Jackson Pollock, Mark Rothko, and Robert Motherwell. She sold the works to two prominent Manhattan art galleries for approximately $33.2 million. The galleries, in turn, sold the works to victims of Rosales’ crime for more than $80 million.
The works were fakes created by a painter (the “painter”) who resided in Queens, New York. Rosales conspired with her long-time companion, identified as a co-conspirator (“CC- 1”) in the superseding Indictment, to procure and sell the Works and to launder the proceeds of the fraud. CC-1 first met and befriended the painter in Manhattan in the 1980s while the painter was painting on the street. The painter, who received formal art training at an art school in New York, created the works for Rosales and CC-1 at the painter’s home in Queens. In some instances, the painter signed the purported artist’s name to the works, such as Jackson Pollock, but in other cases, CC-1 applied the false signatures. After Rosales and CC-1 retrieved the works from the painter, CC-1 gave the works the false patina of age by subjecting the works to a number of different treatments.
The provenance that Rosales supplied for the works was also false. In selling some of the works, she purported to represent a particular client who was associated with Switzerland, had inherited the paintings and wanted to sell them, but also wished to remain anonymous (the “purported Swiss client”). For the remainder of the paintings, Rosales purported to represent a Spanish collector (the “purported Spanish collector”). She further claimed that a portion of the price paid by the Manhattan galleries would be a commission to her for selling the paintings and that the remainder would be passed along to her clients. In truth and fact, the purported Swiss client never existed and the purported Spanish collector never actually owned any of the works.
Rosales also filed tax returns that falsely and fraudulently tended to show that she had not kept all or substantially all of the proceeds from the sale of the works, when, in fact, Rosales kept several million dollars of the proceeds.
Rosales received most of the proceeds from the sale of the works in a foreign bank account that she hid from and failed to report to the IRS. United States taxpayers are required to report to the IRS the existence of any foreign bank account that holds more than $10,000 at any time during a given year by the filing of a Report of Foreign Bank and Financial Accounts, Form TD F 90-22.1.
Rosales, 57, of Sands Point, New York, pled guilty to nine counts, including: one count of conspiracy to commit wire fraud, one count of wire fraud, one count of conspiracy to commit money laundering, and one count of money laundering, each of which carries a maximum sentence of 20 years in prison; three counts of filing false federal income tax returns, each of which carries a maximum sentence of three years in prison; and two counts of willful failure to file Report of Foreign Bank and Financial Accounts, Form TD F 90-22.1, each of which carries a maximum sentence of five years in prison. Rosales’ total maximum term of imprisonment is 99 years. She also agreed to forfeit $33,200,000, including her home in Sands Point, New York, and to pay restitution in an amount not to exceed $81 million. Rosales will be sentenced by Judge Failla on March 18, 2014, at 2:30 p.m.
Mr. Bharara praised the outstanding efforts of the Federal Bureau of Investigation and the Internal Revenue Service-Criminal Investigation in the investigation, which he noted is ongoing.
This case is being handled by the Office’s Complex Frauds Unit. Assistant U.S. Attorney Jason P. Hernandez is in charge of the prosecution.
Manhattan U.S. Attorney Preet Bharara said, “With her guilty plea today, Glafira Rosales acknowledges her role in a sprawling fraud that involved the commission of phony artworks she represented as real and her efforts to hide the proceeds of this massive scam in foreign bank accounts. Rosales’s plea shows that no matter how wide-ranging the deception, this office will continue to bring the perpetrators of fraud to justice.”
According to the allegations contained in the complaint, indictment, superseding indictment, and statements made in court:
Rosales was an art dealer who, starting in 1994 and continuing through 2009, sold more than 60 never-before-exhibited and previously unknown works of art (the “works”) that she claimed were by the hand of some of the most famous artists of the 20th century, such as Jackson Pollock, Mark Rothko, and Robert Motherwell. She sold the works to two prominent Manhattan art galleries for approximately $33.2 million. The galleries, in turn, sold the works to victims of Rosales’ crime for more than $80 million.
The works were fakes created by a painter (the “painter”) who resided in Queens, New York. Rosales conspired with her long-time companion, identified as a co-conspirator (“CC- 1”) in the superseding Indictment, to procure and sell the Works and to launder the proceeds of the fraud. CC-1 first met and befriended the painter in Manhattan in the 1980s while the painter was painting on the street. The painter, who received formal art training at an art school in New York, created the works for Rosales and CC-1 at the painter’s home in Queens. In some instances, the painter signed the purported artist’s name to the works, such as Jackson Pollock, but in other cases, CC-1 applied the false signatures. After Rosales and CC-1 retrieved the works from the painter, CC-1 gave the works the false patina of age by subjecting the works to a number of different treatments.
The provenance that Rosales supplied for the works was also false. In selling some of the works, she purported to represent a particular client who was associated with Switzerland, had inherited the paintings and wanted to sell them, but also wished to remain anonymous (the “purported Swiss client”). For the remainder of the paintings, Rosales purported to represent a Spanish collector (the “purported Spanish collector”). She further claimed that a portion of the price paid by the Manhattan galleries would be a commission to her for selling the paintings and that the remainder would be passed along to her clients. In truth and fact, the purported Swiss client never existed and the purported Spanish collector never actually owned any of the works.
Rosales also filed tax returns that falsely and fraudulently tended to show that she had not kept all or substantially all of the proceeds from the sale of the works, when, in fact, Rosales kept several million dollars of the proceeds.
Rosales received most of the proceeds from the sale of the works in a foreign bank account that she hid from and failed to report to the IRS. United States taxpayers are required to report to the IRS the existence of any foreign bank account that holds more than $10,000 at any time during a given year by the filing of a Report of Foreign Bank and Financial Accounts, Form TD F 90-22.1.
Rosales, 57, of Sands Point, New York, pled guilty to nine counts, including: one count of conspiracy to commit wire fraud, one count of wire fraud, one count of conspiracy to commit money laundering, and one count of money laundering, each of which carries a maximum sentence of 20 years in prison; three counts of filing false federal income tax returns, each of which carries a maximum sentence of three years in prison; and two counts of willful failure to file Report of Foreign Bank and Financial Accounts, Form TD F 90-22.1, each of which carries a maximum sentence of five years in prison. Rosales’ total maximum term of imprisonment is 99 years. She also agreed to forfeit $33,200,000, including her home in Sands Point, New York, and to pay restitution in an amount not to exceed $81 million. Rosales will be sentenced by Judge Failla on March 18, 2014, at 2:30 p.m.
Mr. Bharara praised the outstanding efforts of the Federal Bureau of Investigation and the Internal Revenue Service-Criminal Investigation in the investigation, which he noted is ongoing.
This case is being handled by the Office’s Complex Frauds Unit. Assistant U.S. Attorney Jason P. Hernandez is in charge of the prosecution.
Labels:
bail,
bonds,
fake art,
money laundering,
New Jersey,
NJ,
rapid,
release,
scam,
tax charges
Subscribe to:
Posts (Atom)