<?xml version="1.0" encoding="utf-8" ?>

<rss version="2.0" 
   xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
   xmlns:admin="http://webns.net/mvcb/"
   xmlns:dc="http://purl.org/dc/elements/1.1/"
   xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
   xmlns:wfw="http://wellformedweb.org/CommentAPI/"
   xmlns:content="http://purl.org/rss/1.0/modules/content/"
   >
<channel>
    <title>It's Fixed in the Next Release - Frauds / Scams</title>
    <link>http://www.ambitonline.com/nextrelease/</link>
    <description>Observations on Everything</description>
    <dc:language>en</dc:language>
    <generator>Serendipity 1.0.1 - http://www.s9y.org/</generator>
    <pubDate>Tue, 15 May 2012 16:02:50 GMT</pubDate>

    <image>
        <url>http://www.ambitonline.com/nextrelease/templates/competition/img/s9y_banner_small.png</url>
        <title>RSS: It's Fixed in the Next Release - Frauds / Scams - Observations on Everything</title>
        <link>http://www.ambitonline.com/nextrelease/</link>
        <width>100</width>
        <height>21</height>
    </image>

<item>
    <title>Yellow Pages Group Latest to have a Data Security Problem</title>
    <link>http://www.ambitonline.com/nextrelease/archives/167-Yellow-Pages-Group-Latest-to-have-a-Data-Security-Problem.html</link>
            <category>Frauds / Scams</category>
            <category>Marketing</category>
    
    <comments>http://www.ambitonline.com/nextrelease/archives/167-Yellow-Pages-Group-Latest-to-have-a-Data-Security-Problem.html#comments</comments>
    <wfw:comment>http://www.ambitonline.com/nextrelease/wfwcomment.php?cid=167</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.ambitonline.com/nextrelease/rss.php?version=2.0&amp;type=comments&amp;cid=167</wfw:commentRss>
    

    <author>nospam@example.com (Alan Langford)</author>
    <content:encoded>
    &lt;p&gt;Another hit on the tracking address front. this time the co-victim and/or offender is the &lt;a href=&quot;http://www.ambitonline.com/nextrelease/exit.php?url_id=342&amp;amp;entry_id=167&quot; title=&quot;http://www.ypg.com&quot;  onmouseover=&quot;window.status=&#039;http://www.ypg.com&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;Yellow Pages Group&lt;/a&gt;.&lt;/p&gt;&lt;br /&gt;
&lt;p&gt;Let&#039;s start with the boring but still somewhat amusing part of the history:&lt;/p&gt;&lt;br /&gt;
&lt;ul&gt;&lt;li&gt;September 23, 1010: I create a tracking address and use it to set up a &quot;free&quot; listing for one of my businesses at YellowPages.ca.&lt;br /&gt;
&lt;/li&gt;&lt;li&gt;November 11, 2010: Yellow Pages Group sends a promotional email to the tracking address, trying to get me to move to a paid service. When I stop laughing, I unsubscribe and receive a confirmation message. &lt;strong&gt;We&#039;re done, right? Wrong!&lt;/strong&gt;&lt;br /&gt;
&lt;/li&gt;&lt;li&gt;January 17, 2011: I receive a message &amp;ndash; &lt;em&gt;in French&lt;/em&gt; promoting YPG services. I create a mail filter marking all communications to my tracking address as read. &lt;strong&gt;Note to YPG: &lt;em&gt;unsubscribe&lt;/em&gt;. un-sub-scribe. This means STOP sending mail. Duh.&lt;/strong&gt;&lt;br /&gt;
&lt;/li&gt;&lt;li&gt;April 28 and May 2nd, 2011: more mail, unnoticed until recently thanks to the mark-as-read rule. In hindsight, this is too bad, because &quot;Get a personalized Web site for less than $2 a day&quot; would have given me a good hard laugh. $60/month for a basic template-customized site? That makes text message charges look cheap! Oh, wait, YPG has its roots in Bell, doesn&#039;t it? That sure explains a lot!&lt;br /&gt;
&lt;/ul&gt;&lt;br /&gt;
&lt;p&gt;Yesterday May 14, 2012 this unique address, which is made from a contraction of &quot;Yellow Pages&quot; and &lt;em&gt;five random characters&lt;/em&gt; &amp;ndash; essentially un-guessable &amp;ndash; gets &quot;FREE participation to win an IPAD 3 16GB WI-FI !&quot; from no-reply@promohebdo.ca.&lt;/p&gt;&lt;br /&gt;
&lt;h3&gt;Bing! A Crime has been Committed!&lt;/h3&gt;&lt;br /&gt;
&lt;p&gt;I wish it was obvious &lt;em&gt;which&lt;/em&gt; crime it was, but the possibilities include:&lt;/p&gt;&lt;br /&gt;
&lt;ul&gt;&lt;li&gt;Lousy data security, which means some external party managed to mine their database(s). This from a company who wants you to entrust them with your web site. Yeah, right.&lt;br /&gt;
&lt;/li&gt;&lt;li&gt;Internal theft. Someone who had access to the data accepted payment for making a copy of it. I&#039;m sure there will be an internal investigation, YPG will come clean with a full public disclosures and the appropriate charges will be laid. Yeah, right.&lt;br /&gt;
&lt;/li&gt;&lt;li&gt;YPG sold the data to someone. Data they don&#039;t have a right to use. We can expect a comment full of evasive passive voice that attempts to disclaim responsibility. Meanwhile, they&#039;d never do that with the rest of the data under their control. I mean this is their data, they&#039;re very, very extra special trustworthy and would never sell information in their customer&#039;s databases. Yeah, right.&lt;br /&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;
&lt;p&gt;But my bet is they just hope this post stays on some ranter&#039;s back-water blog. So be it.&lt;/p&gt;&lt;br /&gt;
&lt;p&gt;We&#039;ll see. I&#039;ll post copies/scans of anything that comes in.&lt;/p&gt; 
    </content:encoded>

    <pubDate>Tue, 15 May 2012 11:02:50 -0500</pubDate>
    <guid isPermaLink="false">http://www.ambitonline.com/nextrelease/archives/167-guid.html</guid>
    
</item>
<item>
    <title>Canada Computers and Electronics Appears to Ignore Serious Security Breach</title>
    <link>http://www.ambitonline.com/nextrelease/archives/165-Canada-Computers-and-Electronics-Appears-to-Ignore-Serious-Security-Breach.html</link>
            <category>Frauds / Scams</category>
    
    <comments>http://www.ambitonline.com/nextrelease/archives/165-Canada-Computers-and-Electronics-Appears-to-Ignore-Serious-Security-Breach.html#comments</comments>
    <wfw:comment>http://www.ambitonline.com/nextrelease/wfwcomment.php?cid=165</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.ambitonline.com/nextrelease/rss.php?version=2.0&amp;type=comments&amp;cid=165</wfw:commentRss>
    

    <author>nospam@example.com (Alan Langford)</author>
    <content:encoded>
    &lt;p&gt;What&#039;s worse than a security issue? Ignoring it and hoping it will go away.&lt;/p&gt;&lt;br /&gt;
&lt;p&gt;First a bit of background. For years, I&#039;ve been tracking spam by generating unique forwarding addresses every time I register on a site. The intent was to be able to track the sources of spam and easily disable a compromised address. In practice, it&#039;s proven to be a tool for detecting all sorts of misbehaviour.&lt;/p&gt;&lt;br /&gt;
&lt;p&gt;Reports I&#039;ve sent have exposed a variety of things, from “overzealous” use of databases by partners, to criminal theft by disgruntled employees. To the best of my knowledge, the reports I&#039;ve sent to victimized companies have resulted in one firing, one set of criminal charges, and countless wrist slaps.&lt;/p&gt;&lt;br /&gt;
&lt;p&gt;Generally speaking, if a company takes the report seriously and takes some sort of action, I don&#039;t go public with it. The reverse is also true. Ignore a report and you wind up in a blog post, and this brings us to &lt;a href=&quot;http://www.ambitonline.com/nextrelease/exit.php?url_id=340&amp;amp;entry_id=165&quot; title=&quot;http://canadacomputers.com&quot;  onmouseover=&quot;window.status=&#039;http://canadacomputers.com&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot; target=&quot;_blank&quot;&gt;Canada Computers and Electronics&lt;/a&gt;. I have to say that it pains me to do this, because they &lt;strike&gt;are&lt;/strike&gt; were one of my favourite suppliers.&lt;p&gt;&lt;br /&gt;
&lt;p&gt;On February 24th, I received spam titled “Yum my  Dol l S ee ki ng   a L ove r”. The message contained just one image, a less discreet version of this one:&lt;/p&gt;&lt;br /&gt;
&lt;p&gt;&lt;img src=&quot;http://www.ambitonline.com/nextrelease/uploads/fhjjumcj_discreet.jpg&quot; style=&quot;float:right;padding:0 0 8px 16px;&quot; alt=&quot;&quot;  /&gt;The problem is that the message was sent to a tracking address that has only ever been used with my account at Canada Computers and Electronics. The specific address contains an abbreviation of their name, and a six character alphanumeric suffix. The suffix is there because one company I talked to claimed that “anyone” could have guessed my tracking address, and that therefore my report wasn&#039;t worth investigating. The suffix means that there&#039;s a &lt;strong&gt;one in two billion&lt;/strong&gt; (1:2,176,782,336 to be exact) chance of guessing the address, assuming the spammer also “guessed” that I had a business relationship with the company and “guessed” the abbreviation I used. Anyone doing this would be far better off guessing winning lottery ticket numbers.&lt;/p&gt;&lt;br /&gt;
&lt;p&gt;The conclusion from this spam is pretty obvious: &lt;strong&gt;someone has compromised the &lt;em&gt;customer&lt;/em&gt; database at Canada Computers and Electronics&lt;/strong&gt;. That&#039;s pretty serious stuff! That same day I sent a message to two addresses found on their web site, feedback@canadacomputers.com and corporate@canadacomputers.com. Since it was pretty late on a Friday I left it at that.&lt;/p&gt;&lt;br /&gt;
&lt;p&gt;The next Monday, after 4pm I sent another note expressing my concern about the lack of response to such an urgent matter and giving them a deadline of February 29th before public disclosure. At 5:36pm I received a response to my first message indicating that the report had been passed to management.&lt;/p&gt;&lt;br /&gt;
&lt;p&gt;Since then, nothing. Not even a message from someone saying that they&#039;re looking into it.&lt;/p&gt;&lt;br /&gt;
&lt;p&gt;It&#039;s highly probable that someone stole customer data from &lt;a href=&quot;http://www.ambitonline.com/nextrelease/exit.php?url_id=340&amp;amp;entry_id=165&quot; title=&quot;http://canadacomputers.com&quot;  onmouseover=&quot;window.status=&#039;http://canadacomputers.com&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot; target=&quot;_blank&quot;&gt;Canada Computers and Electronics&lt;/a&gt;, and they don&#039;t appear to be responding to the issue. I&#039;m not doing business with this company at least until they&#039;ve come clean and addressed the problem. I cant see why anyone else would either.&lt;/p&gt; 
    </content:encoded>

    <pubDate>Thu, 01 Mar 2012 12:14:22 -0600</pubDate>
    <guid isPermaLink="false">http://www.ambitonline.com/nextrelease/archives/165-guid.html</guid>
    
</item>
<item>
    <title>Alert: Hacker Phone Calls pretending to be Microsoft</title>
    <link>http://www.ambitonline.com/nextrelease/archives/159-Alert-Hacker-Phone-Calls-pretending-to-be-Microsoft.html</link>
            <category>Frauds / Scams</category>
    
    <comments>http://www.ambitonline.com/nextrelease/archives/159-Alert-Hacker-Phone-Calls-pretending-to-be-Microsoft.html#comments</comments>
    <wfw:comment>http://www.ambitonline.com/nextrelease/wfwcomment.php?cid=159</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.ambitonline.com/nextrelease/rss.php?version=2.0&amp;type=comments&amp;cid=159</wfw:commentRss>
    

    <author>nospam@example.com (Alan Langford)</author>
    <content:encoded>
    Microsoft must have finally gotten the upper hand in Windows security.&lt;br /&gt;
&lt;br /&gt;
I just talked with a non-technical friend who got a call from a call centre purporting to be Microsoft. The agent explained, in broken English, that Microsoft had &quot;detected a virus on her computer&quot;. He then attempted to direct her to &lt;a href=&quot;http://www.ambitonline.com/nextrelease/exit.php?url_id=327&amp;amp;entry_id=159&quot; title=&quot;http://www.teamviewer.com&quot;  onmouseover=&quot;window.status=&#039;http://www.teamviewer.com&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot; target=&quot;_blank&quot;&gt;TeamViewer&lt;/a&gt;, a remote desktop access application.&lt;br /&gt;
&lt;br /&gt;
It was at this point that she wisely terminated the call and got in touch with me.&lt;br /&gt;
&lt;br /&gt;
It&#039;s pretty easy to see where this was going. A victim, under the impression that the call was from Microsoft, trusts the advice, installs TeamViewer, and gives the hacker full, unrestricted access to their computer. Under instruction from the hacker, the user happily bypasses all the security warnings, and in only take a few seconds a trojan / back door is in place and &lt;strong&gt;the user&#039;s system is completely compromised&lt;/strong&gt;. The system is instantly open to credit card fraud, identity theft, spam relaying, and anything else these criminals can come up with.&lt;br /&gt;
&lt;br /&gt;
The good news is that Microsoft Windows security is now clearly at a point where a human factors attack is worth the expense. The bad news is that the percentage of users who are likely to fall for this scam is far too high, and the attack vector allows for the injection of any payload. Hackers can obfuscate this malware so that a virus scanner could have a very difficult time identifying it as malicious. Worse yet, the current target might be Windows, but there&#039;s no reason why this approach can&#039;t be equally effective with other platforms.&lt;br /&gt;
&lt;br /&gt;
This marks a new battleground for security in home computing. As with most other attacks, the first line of defence is education. If you have friends who are less technical, please warn them about this. 
    </content:encoded>

    <pubDate>Thu, 14 Apr 2011 15:54:35 -0500</pubDate>
    <guid isPermaLink="false">http://www.ambitonline.com/nextrelease/archives/159-guid.html</guid>
    
</item>
<item>
    <title>Nigerian Style Fraud Via Facebook</title>
    <link>http://www.ambitonline.com/nextrelease/archives/137-Nigerian-Style-Fraud-Via-Facebook.html</link>
            <category>Frauds / Scams</category>
            <category>Mundanity</category>
    
    <comments>http://www.ambitonline.com/nextrelease/archives/137-Nigerian-Style-Fraud-Via-Facebook.html#comments</comments>
    <wfw:comment>http://www.ambitonline.com/nextrelease/wfwcomment.php?cid=137</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.ambitonline.com/nextrelease/rss.php?version=2.0&amp;type=comments&amp;cid=137</wfw:commentRss>
    

    <author>nospam@example.com (Alan Langford)</author>
    <content:encoded>
    Since my &lt;a href=&quot;http://www.ambitonline.com/nextrelease/exit.php?url_id=321&amp;amp;entry_id=137&quot; title=&quot;http://www.ambitonline.com/nextrelease/archives/54-And-now...-Nigerian-Style-Fraud-via-Skype!.html&quot;  onmouseover=&quot;window.status=&#039;http://www.ambitonline.com/nextrelease/archives/54-And-now...-Nigerian-Style-Fraud-via-Skype!.html&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;Skype Fraud post&lt;/a&gt; is one of the most popular here, I thought I&#039;d throw in a few references to some other similar tricks. This one is particularly funny:&lt;br /&gt;
&lt;br /&gt;
&lt;a href=&quot;http://www.ambitonline.com/nextrelease/exit.php?url_id=322&amp;amp;entry_id=137&quot; title=&quot;http://consumerist.com/5263537/bad-luck-facebook-scammer-you-picked-a-target-who-reads-consumerist&quot;  onmouseover=&quot;window.status=&#039;http://consumerist.com/5263537/bad-luck-facebook-scammer-you-picked-a-target-who-reads-consumerist&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;Bad Luck Facebook Scammer, You Picked A Target Who Reads Consumerist&lt;/a&gt; with the wonderful phrase &quot;Once I deposit the funds, you can print it out of any colour printer and it&#039;s real money!&quot;&lt;br /&gt;
&lt;br /&gt;
Then there&#039;s the original article referenced in the one above: &lt;a href=&quot;http://www.ambitonline.com/nextrelease/exit.php?url_id=323&amp;amp;entry_id=137&quot; title=&quot;http://consumerist.com/5260397/nigerian-scammers-break-into-your-gmail-ask-your-friends-for-money&quot;  onmouseover=&quot;window.status=&#039;http://consumerist.com/5260397/nigerian-scammers-break-into-your-gmail-ask-your-friends-for-money&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;Nigerian Scammers Break Into Your Gmail, Ask Your Friends For Money&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
We can only hope that one of these days the scammers just go out of business because everyone has enough information to spot them and waste their time. Not likely, but one can hope. 
    </content:encoded>

    <pubDate>Thu, 21 May 2009 12:17:08 -0500</pubDate>
    <guid isPermaLink="false">http://www.ambitonline.com/nextrelease/archives/137-guid.html</guid>
    
</item>
<item>
    <title>Malware Injection: More Fun With Skype</title>
    <link>http://www.ambitonline.com/nextrelease/archives/97-Malware-Injection-More-Fun-With-Skype.html</link>
            <category>Frauds / Scams</category>
            <category>Internet Technology</category>
            <category>Mundanity</category>
    
    <comments>http://www.ambitonline.com/nextrelease/archives/97-Malware-Injection-More-Fun-With-Skype.html#comments</comments>
    <wfw:comment>http://www.ambitonline.com/nextrelease/wfwcomment.php?cid=97</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.ambitonline.com/nextrelease/rss.php?version=2.0&amp;type=comments&amp;cid=97</wfw:commentRss>
    

    <author>nospam@example.com (Alan Langford)</author>
    <content:encoded>
    &lt;div class=&quot;serendipity_imageComment_right&quot; style=&quot;width: 110px&quot;&gt;&lt;div class=&quot;serendipity_imageComment_img&quot;&gt;&lt;img width=&quot;110&quot; height=&quot;102&quot; src=&quot;http://www.ambitonline.com/nextrelease/uploads/irony.serendipityThumb.png&quot; alt=&quot;&quot;  /&gt;&lt;/div&gt;&lt;div class=&quot;serendipity_imageComment_txt&quot;&gt;Skype screen capture&lt;/div&gt;&lt;/div&gt;&lt;br /&gt;
This one probably isn&#039;t new, but it&#039;s worth noting. An associate recently got this bogus &quot;security warning&quot;. Appropriately named &quot;irony&quot;, the message warns the user that &quot;Security Center has detected Malware&quot; and directs the user to a site where they can download a patch. Click on the image for a full sized version.&lt;br /&gt;
&lt;br /&gt;
The &quot;patch&quot; will install malware on the user&#039;s computer. At least they can&#039;t forge the link as belonging to Microsoft, but this could easily fool an unsuspecting user. 
    </content:encoded>

    <pubDate>Thu, 29 May 2008 13:43:15 -0500</pubDate>
    <guid isPermaLink="false">http://www.ambitonline.com/nextrelease/archives/97-guid.html</guid>
    
</item>
<item>
    <title>The Single Best Way to Bust a Telephone Scam</title>
    <link>http://www.ambitonline.com/nextrelease/archives/94-The-Single-Best-Way-to-Bust-a-Telephone-Scam.html</link>
            <category>Frauds / Scams</category>
            <category>Mundanity</category>
    
    <comments>http://www.ambitonline.com/nextrelease/archives/94-The-Single-Best-Way-to-Bust-a-Telephone-Scam.html#comments</comments>
    <wfw:comment>http://www.ambitonline.com/nextrelease/wfwcomment.php?cid=94</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.ambitonline.com/nextrelease/rss.php?version=2.0&amp;type=comments&amp;cid=94</wfw:commentRss>
    

    <author>nospam@example.com (Alan Langford)</author>
    <content:encoded>
    This is simple and effective. If you suspect that the company who is calling you is not legitimate, ask the caller for their web site address.&lt;br /&gt;
&lt;br /&gt;
If the call is a fraud attempt, the &quot;agent&quot; probably won&#039;t be able to give it to you. One of these things will happen:&lt;br /&gt;
&lt;br /&gt;
&lt;ul&gt;&lt;li&gt;They won&#039;t &quot;remember&quot; it. For extra bonus fun, ask them if their sales manager knows it.&lt;br /&gt;
&lt;/li&gt;&lt;li&gt;They&#039;ll give you a legitimate site that isn&#039;t theirs. Ask them to hold on while you pop it up. If that doesn&#039;t make them hang up, ask them where the information relating to their offer is. They might tell you it&#039;s an exclusive offer that&#039;s not available on the web, but if the site has nothing that seems to be related to the offer, it&#039;s a big warning that they&#039;re not telling the truth.&lt;br /&gt;
&lt;/li&gt;&lt;li&gt;They&#039;ll give you a fake site that is theirs. This would be pretty stupid on their part, since it would provide the authorities with a path back to them. Do a search on the site to see what the world has to say about them. If they&#039;re not in the search index, then the site was probably set up a few days ago. More sophisticated users can do a &lt;a href=&quot;http://www.ambitonline.com/nextrelease/exit.php?url_id=324&amp;amp;entry_id=94&quot; title=&quot;http://www.canacweb.com/domain.php?action=whois&quot;  onmouseover=&quot;window.status=&#039;http://www.canacweb.com/domain.php?action=whois&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot; &gt;whois lookup&lt;/a&gt; on them... look at the registration date. Also if the site owner is masked for privacy, you can be sure it&#039;s not a large established company. Either way, report the site to your local authorities as soon as possible.&lt;br /&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;
These fraud schemes depend on leaving the smallest possible trail back to them. Legitimate businesses want to open as many possible channels of communication with their potential customers as possible.&lt;br /&gt;
&lt;br /&gt;
So it&#039;s as easy as this: no web site equals no legitimacy. Protect yourself. 
    </content:encoded>

    <pubDate>Thu, 24 Apr 2008 12:57:06 -0500</pubDate>
    <guid isPermaLink="false">http://www.ambitonline.com/nextrelease/archives/94-guid.html</guid>
    
</item>
<item>
    <title>Criminalize False Caller-ID Messages</title>
    <link>http://www.ambitonline.com/nextrelease/archives/82-Criminalize-False-Caller-ID-Messages.html</link>
            <category>Frauds / Scams</category>
            <category>Mundanity</category>
    
    <comments>http://www.ambitonline.com/nextrelease/archives/82-Criminalize-False-Caller-ID-Messages.html#comments</comments>
    <wfw:comment>http://www.ambitonline.com/nextrelease/wfwcomment.php?cid=82</wfw:comment>

    <slash:comments>2</slash:comments>
    <wfw:commentRss>http://www.ambitonline.com/nextrelease/rss.php?version=2.0&amp;type=comments&amp;cid=82</wfw:commentRss>
    

    <author>nospam@example.com (Alan Langford)</author>
    <content:encoded>
    Here&#039;s a crime for modern times: make the transmission of an intentionally false Caller-ID message a minor criminal offence.&lt;br /&gt;
&lt;br /&gt;
There&#039;s an established mechanism for blocking identity through caller ID, namely the &quot;Private Number&quot; message. Therefore the only conceivable use of false information is to mislead the person being called. Most of the fraudulent calls I receive use bogus, rather than private numbers.&lt;br /&gt;
&lt;br /&gt;
But what should the penalty be? How about something proportional to the impact on the victim? In and of itself, direct victim impact is pretty small, so how about &lt;em&gt;three hours in jail per occurrence&lt;/em&gt;?&lt;br /&gt;
&lt;br /&gt;
What, you say that&#039;s ridiculously low? Well then how about this: mandatory consecutive terms, no concurrent sentences. Fraudsters have to make a large number of calls in order to find victims (see footnote). Three hours in jail works out to about a year for every three thousand calls. These guys need to make tens of thousands of calls a day, so in a month or so they could easily rack up a sentence in excess of their entire lifespan.&lt;br /&gt;
&lt;br /&gt;
A slap on the wrist for people who flirt with the idea, major hard time for the fraudsters. Works for me.&lt;br /&gt;
&lt;br /&gt;
Footnote: One operation I led on started with an automated dialler, transfered to a &quot;qualifier&quot; who made sure I had a credit card, and then transfered to a &quot;closer&quot;, who was none too thrilled when I finally admitted that I was deliberately wasting their time, eight minutes in. 
    </content:encoded>

    <pubDate>Thu, 10 Jan 2008 10:37:45 -0600</pubDate>
    <guid isPermaLink="false">http://www.ambitonline.com/nextrelease/archives/82-guid.html</guid>
    
</item>
<item>
    <title>Sites Need to Custom Brand CAPTCHA Images</title>
    <link>http://www.ambitonline.com/nextrelease/archives/63-Sites-Need-to-Custom-Brand-CAPTCHA-Images.html</link>
            <category>Frauds / Scams</category>
            <category>Web Development</category>
    
    <comments>http://www.ambitonline.com/nextrelease/archives/63-Sites-Need-to-Custom-Brand-CAPTCHA-Images.html#comments</comments>
    <wfw:comment>http://www.ambitonline.com/nextrelease/wfwcomment.php?cid=63</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.ambitonline.com/nextrelease/rss.php?version=2.0&amp;type=comments&amp;cid=63</wfw:commentRss>
    

    <author>nospam@example.com (Alan Langford)</author>
    <content:encoded>
    In an absolutely brilliant but evil move, a &lt;a href=&quot;http://www.ambitonline.com/nextrelease/exit.php?url_id=325&amp;amp;entry_id=63&quot; title=&quot;http://www.heise-security.co.uk/news/98124&quot;  onmouseover=&quot;window.status=&#039;http://www.heise-security.co.uk/news/98124&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot; &gt;Trojan fools users into solving CAPTCHA images&lt;/a&gt;. Infected users think that they&#039;re entering codes to see a model undress, when actually they&#039;re helping crackers register for illegal Yahoo accounts. &lt;br /&gt;&lt;a href=&quot;http://www.ambitonline.com/nextrelease/archives/63-Sites-Need-to-Custom-Brand-CAPTCHA-Images.html#extended&quot;&gt;Continue reading &quot;Sites Need to Custom Brand CAPTCHA Images&quot;&lt;/a&gt;
    </content:encoded>

    <pubDate>Thu, 01 Nov 2007 09:14:46 -0500</pubDate>
    <guid isPermaLink="false">http://www.ambitonline.com/nextrelease/archives/63-guid.html</guid>
    
</item>
<item>
    <title>And now... Nigerian Style Fraud via Skype!</title>
    <link>http://www.ambitonline.com/nextrelease/archives/54-And-now...-Nigerian-Style-Fraud-via-Skype!.html</link>
            <category>Frauds / Scams</category>
            <category>Mundanity</category>
    
    <comments>http://www.ambitonline.com/nextrelease/archives/54-And-now...-Nigerian-Style-Fraud-via-Skype!.html#comments</comments>
    <wfw:comment>http://www.ambitonline.com/nextrelease/wfwcomment.php?cid=54</wfw:comment>

    <slash:comments>34</slash:comments>
    <wfw:commentRss>http://www.ambitonline.com/nextrelease/rss.php?version=2.0&amp;type=comments&amp;cid=54</wfw:commentRss>
    

    <author>nospam@example.com (Alan Langford)</author>
    <content:encoded>
    The great thing about Skype is that people can get in touch with you from just about anywhere, and that can lead to great friendships and business. The not so great thing is that any dork from anywhere on the planet can use this same convenience to rip people off.&lt;br /&gt;
&lt;br /&gt;
Here&#039;s a message I received today: &lt;br /&gt;&lt;a href=&quot;http://www.ambitonline.com/nextrelease/archives/54-And-now...-Nigerian-Style-Fraud-via-Skype!.html#extended&quot;&gt;Continue reading &quot;And now... Nigerian Style Fraud via Skype!&quot;&lt;/a&gt;
    </content:encoded>

    <pubDate>Mon, 20 Aug 2007 13:17:55 -0500</pubDate>
    <guid isPermaLink="false">http://www.ambitonline.com/nextrelease/archives/54-guid.html</guid>
    
</item>
<item>
    <title>Credit Card Scam of the Day: Interest Rate Reduction</title>
    <link>http://www.ambitonline.com/nextrelease/archives/52-Credit-Card-Scam-of-the-Day-Interest-Rate-Reduction.html</link>
            <category>Frauds / Scams</category>
            <category>Mundanity</category>
    
    <comments>http://www.ambitonline.com/nextrelease/archives/52-Credit-Card-Scam-of-the-Day-Interest-Rate-Reduction.html#comments</comments>
    <wfw:comment>http://www.ambitonline.com/nextrelease/wfwcomment.php?cid=52</wfw:comment>

    <slash:comments>21</slash:comments>
    <wfw:commentRss>http://www.ambitonline.com/nextrelease/rss.php?version=2.0&amp;type=comments&amp;cid=52</wfw:commentRss>
    

    <author>nospam@example.com (Alan Langford)</author>
    <content:encoded>
    The fun thing about organized criminal credit card fraudsters is that they always have to stay a step ahead. I guess people were starting to catch on to the &lt;a href=&quot;http://www.ambitonline.com/nextrelease/exit.php?url_id=326&amp;amp;entry_id=52&quot; title=&quot;http://www.ambitonline.com/nextrelease/archives/46-Credit-Card-Fraud-Its-Time-for-Banks-to-Play-Offence.html&quot;  onmouseover=&quot;window.status=&#039;http://www.ambitonline.com/nextrelease/archives/46-Credit-Card-Fraud-Its-Time-for-Banks-to-Play-Offence.html&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;&amp;quot;Free&amp;quot; Vacation&lt;/a&gt; scam, so they had to come up with a new one.&lt;br /&gt;
&lt;br /&gt;
Today I got to hear it for the first time. It&#039;s so simple it&#039;s brilliant. &lt;br /&gt;&lt;a href=&quot;http://www.ambitonline.com/nextrelease/archives/52-Credit-Card-Scam-of-the-Day-Interest-Rate-Reduction.html#extended&quot;&gt;Continue reading &quot;Credit Card Scam of the Day: Interest Rate Reduction&quot;&lt;/a&gt;
    </content:encoded>

    <pubDate>Tue, 17 Jul 2007 21:52:02 -0500</pubDate>
    <guid isPermaLink="false">http://www.ambitonline.com/nextrelease/archives/52-guid.html</guid>
    
</item>
<item>
    <title>Fighting Phishing with AJAX - A Call to Arms</title>
    <link>http://www.ambitonline.com/nextrelease/archives/47-Fighting-Phishing-with-AJAX-A-Call-to-Arms.html</link>
            <category>Frauds / Scams</category>
            <category>Internet Technology</category>
    
    <comments>http://www.ambitonline.com/nextrelease/archives/47-Fighting-Phishing-with-AJAX-A-Call-to-Arms.html#comments</comments>
    <wfw:comment>http://www.ambitonline.com/nextrelease/wfwcomment.php?cid=47</wfw:comment>

    <slash:comments>3</slash:comments>
    <wfw:commentRss>http://www.ambitonline.com/nextrelease/rss.php?version=2.0&amp;type=comments&amp;cid=47</wfw:commentRss>
    

    <author>nospam@example.com (Alan Langford)</author>
    <content:encoded>
    I have always wanted to beat &quot;phishers&quot; at their own game. Briefly, a phishing scam creates a page that looks like a legitimate site, requesting user name and password information. The scammers send phony requests via electronic mail under a variety of pretenses, urging customers to follow the enclosed link. Instead of going to your bank or eBay or PayPal, the link goes to their rogue server that looks like a legitimate site and the information is logged there for subsequent criminal activity.&lt;br /&gt;
&lt;br /&gt;
As a rule, if everyone who received a phising attempt (or a mortgage solicitation for that matter) took the time to follow the link, then &lt;em&gt;input bogus data&lt;/em&gt;, then the scam / solicitation would instantly be rendered ineffective. The criminals would be faced with sorting through thousands of garbage records in order to locate the actual victims.&lt;br /&gt;
&lt;br /&gt;
Unfortunately as a society, we&#039;re don&#039;t do all that well at things that benefit the &quot;collective good&quot;, so we&#039;re stuck with scams in our mailboxes.&lt;br /&gt;
&lt;br /&gt;
But AJAX changes that.&lt;br /&gt;
 &lt;br /&gt;&lt;a href=&quot;http://www.ambitonline.com/nextrelease/archives/47-Fighting-Phishing-with-AJAX-A-Call-to-Arms.html#extended&quot;&gt;Continue reading &quot;Fighting Phishing with AJAX - A Call to Arms&quot;&lt;/a&gt;
    </content:encoded>

    <pubDate>Thu, 07 Jun 2007 11:51:08 -0500</pubDate>
    <guid isPermaLink="false">http://www.ambitonline.com/nextrelease/archives/47-guid.html</guid>
    
</item>
<item>
    <title>Credit Card Fraud: It's Time for Banks to Play Offence</title>
    <link>http://www.ambitonline.com/nextrelease/archives/46-Credit-Card-Fraud-Its-Time-for-Banks-to-Play-Offence.html</link>
            <category>Frauds / Scams</category>
            <category>Mundanity</category>
    
    <comments>http://www.ambitonline.com/nextrelease/archives/46-Credit-Card-Fraud-Its-Time-for-Banks-to-Play-Offence.html#comments</comments>
    <wfw:comment>http://www.ambitonline.com/nextrelease/wfwcomment.php?cid=46</wfw:comment>

    <slash:comments>3</slash:comments>
    <wfw:commentRss>http://www.ambitonline.com/nextrelease/rss.php?version=2.0&amp;type=comments&amp;cid=46</wfw:commentRss>
    

    <author>nospam@example.com (Alan Langford)</author>
    <content:encoded>
    Every once in a while organized crime gives me a call. It&#039;s not that I&#039;m so special, they just happen to know my phone number. The call comes in &quot;Unknown number&quot; which is a warning sign in itself. Then I&#039;ve won a trip to Florida, Vegas, or wherever. Red flag. Press nine and you get a very happy and enthusiastic person who wants to give you a free trip, all you have to do is be a credit card holder.&lt;br /&gt;
&lt;br /&gt;
Stop right there. These people are offering you great sounding (and nonexistent) stuff for the sole purpose of capturing your name and credit card number so they can rip you off. &lt;br /&gt;&lt;a href=&quot;http://www.ambitonline.com/nextrelease/archives/46-Credit-Card-Fraud-Its-Time-for-Banks-to-Play-Offence.html#extended&quot;&gt;Continue reading &quot;Credit Card Fraud: It&#039;s Time for Banks to Play Offence&quot;&lt;/a&gt;
    </content:encoded>

    <pubDate>Wed, 23 May 2007 13:00:49 -0500</pubDate>
    <guid isPermaLink="false">http://www.ambitonline.com/nextrelease/archives/46-guid.html</guid>
    
</item>

</channel>
</rss>
