skip to content
rss Subscribe print Printer Friendly Share this Page

Fight Identity Theft Blog

Think only the uneducated can be caught in a criminal's web? Hardly...

This is the sad story of "The Doctor" and "The General." The doctor, in this case, is an internationally recognized psychiatrist, 89 year-old Dr. Louis A. Gottschalk. The general is a anonymous figure Dr. Gottschalk met in Nigeria known only as "The General."

According to papers filed by his son, Dr. Gottschalk has been a ten year victim of a Nigerian Advanced Fee Scam, losing up to $3,000,000. Like the last victim we talked about, Dr. Gottschalk is also accused of destroying bank records in order to hide the crime. Understandably, his son is trying to wrest control of the family partnership before more money is lost to the criminals.

Gottschalk was first contacted in 1995 by Nigerian fraudsters. He traveled to Nigeria and Amsterdam to "show them that he was sincere so he would get the money." Early on, he admitted to his family that he had given "The General" $300,000. After being convinced he was being conned, he promised not to give any more money.

Nigerian Email Scam
Dr. Louis Gottschalk, Nigerian Scam Victim

Unfortunately, time passed and Dr. Gottschalk continued to send money to his "partners" in Nigeria.

Why would someone do that - especially someone as educated as Dr. Gottschalk? Here's one assessment from Anthony Pratkanis, a fraud expert from UC Santa Cruz:

"There's a line that gets crossed when they send in the money and then they're caught in a rationalization trap," Pratkanis said. "One way to convince yourself the scam is for real is to send more money, ironically enough."

Makes sense to me. Evidently it made sense to Dr. Gottschalk as well. When asked by his son as late as October 2005 about the money, he replied:

"Don't worry, everything will be all right on Thursday because I will be getting $20 million."

Dreams die hard, don't they? Here's a link to the whole story from KTLA.

March 10, 2006

As cities work to scrape up every little bit of revenue, they're now going after library fines and overdue parking tickets.

How are they going after this money? With collection agencies.

Is it working? The Wall Street Journal says yes:

A handful of cities, including San Diego and Chicago, have worked with collection agencies since the late 1990s. But the trend is spreading rapidly around the country as strapped local governments look for creative ways to boost revenue without raising taxes and fees. Over the past few years, local governments in places including Seattle; Anchorage, Alaska; Austin, Texas; and Florida's Miami-Dade County have contracted with private agencies to collect late parking tickets and court fees. In New York City, Baltimore and Dallas, libraries use private collection firms to recover fines. New York state recently hired a collection company to pursue overdue E-ZPass toll bills.

While shaking down citizens over small debts might sound petty, hundreds of cities around the country are owed millions of dollars in unpaid fines. Since 1997, when Chicago began using a collection agency to track down unpaid parking fines, ticket revenue has more than doubled, rising from $68 million to $154 million last year. (The total number of parking tickets issued has dropped slightly over the period.) Since the Omaha, Neb., public-library system hired a private collection company in March, it has collected more than $40,000 in fines and recovered about $75,000 worth of overdue books and materials.

Yep, they're bringing in the big boys in order to collect on millions of dollars of small fines that many of you have ignored... until now. If you decide to ignore a collection agency, that $20 library fine could show up as a collection account on your credit report.

How will will single collection account for a stupid small overdue fine affect your credit score? It could lower it by as much as 100 points. Ouch! That's gonna hurt.

It appears that Equifax is the sole credit bureau that feels this may be a bit of overkill. Also from the Wall Street Journal:

Equifax Inc., the third credit bureau, makes an effort to weed out small charges like library books and parking violations from credit files. The company says it is not fair to include them in credit reports since municipal fines are reported unevenly around the country.

Well, that won't help too much because you never know which bureau a potential creditor will use to look at your credit.

So what should you do?

  • Pay your fines, no matter how small
    Your city could start using a collection agency at any time. Your fines - even years old - could then be sent to collections.
  • Call and negotiate
    If you do get a collection notice, call and negotiate with the agency. Make sure they agree that if you pay the fine they will remove the collection from your credit file.
  • Review your credit
    Make sure you review your credit report from all three bureaus months before you apply for a car or home loan. You want to have time to resolve issues like this before applying.
February 24, 2006

It's our favorite time of year here in the U.S. - TAX TIME!

Along with tax season comes the predictable onslaught of IRS scam emails. No, these don't come from the IRS. They are from the same old bad guys trying to separate you from your money.

Here's an email that just arrived today:

IRS Email Scam

They're only offering a refund of $63.80??? Those crooks!

I would have thought a higher amount, like $630.80 would better peak our interest in recovering the money. Oh well, I'm sure they do extensive testing to determine the cash amount that draws the most clicks...

Once you click the link you'll see a beautiful reproduction of the IRS site along with a form asking for your:

  • SSN
  • Credit card number
  • Credit card expiration date
  • Credit card CVV security code from the back of the card
  • Credit card ATM PIN

This looks like a clear credit card fraud attempt. With this information they can purchase items over the internet or withdraw cash from your account.

What should you do if you receive an email like this?

The IRS, unfortunately, doesn't currently have an easy way to report these emails. The best you can do right now is call 800-366-4484 to report it, but the number was busy each time I tried to call. Not good.

The IRS has placed this kind of phishing scam in their "Dirty Dozen" tax scams for 2006. Here's what they had to say:

Phishing. Phishing is a technique used by identity thieves to acquire personal financial data in order to gain access to the financial accounts of unsuspecting consumers, run up charges on their credit cards or apply for new loans in their names. These Internet-based criminals pose as representatives of a financial institution and send out fictitious e-mail correspondence in an attempt to trick consumers into disclosing private information.

Sometimes scammers pose as the IRS itself. In recent months, some taxpayers have received e-mails that appear to come from the IRS. A typical e-mail notifies a taxpayer of an outstanding refund and urges the taxpayer to click on a hyperlink and visit an official-looking Web site. The Web site then solicits a social security and credit card number.

In a variation of this scheme, criminals have used e-mail to announce to unsuspecting taxpayers they are “under audit” and could make things right by divulging selected private financial information. Taxpayers should take note:

The IRS does not use e-mail to initiate contact with taxpayers about issues related to their accounts. If a taxpayer has any doubt whether a contact from the IRS is authentic, the taxpayer should call 1-800-829-1040 to confirm it."

Since the IRS is so lame in trying to shut down sites, I thought I'd do something.

It appears the servers are based in Korea and I've emailed the ISPs that manage the IP involved, but I'm not holding my breath.

The last word... enjoy tax season, just don't try to claim an early refund from scammers.

February 22, 2006

Here's a scam story with a happy ending... kind of.

Harrison Odiawa (aka Abu Belgore), pictured below, was convicted in a Lagos, Nigeria court to 376 years for advance fee fraud, obtaining by false pretence, conspiracy and forgery.

Nigerian Scammer Goes to Jail

So why isn't this a happy story?

It turns out the victim, a U.S. citizen named Robert Blick, has been serving a 30 month jail sentence himself for defrauding his own business partners in order to give over $2,000,000 to the scammers.

The story begins on March 21, 2003, when Blick received an e-mail from a person in Nigeria by the name of Taye Owo, looking for a foreign contractor to transfer $20.5 million out of Nigeria.

Sound familiar?

Unfortunately, Blick hadn't heard of the scam and became excited about getting 20 million dollars for nothing. Don't we all?

After many emails, phone calls, and faxes back and forth, the scammers provided a certificate of incorporation for Blick's American company in Nigeria as well as a job completion certificate. With those, Blick believed he was ready to pick up the 20 million and decided London was the place to make it happen. Once in London, however, the deal played out just like it always does...

The scammers "... told him that he would need £10,000 for his agent to open a bank account, and another $18,750.00 as a trust processing fee when the money transaction took place.

Blick, who came to London with only £10,000, had to stop around London with his credit cards to raise another £20,000 to meet these demands. From this moment on, Blick was in the net of the fraudsters and they milked and milked him until he started selling his personal property and dipping his hand into the account of the company he co-owned with his partners in America.

First, they showed him an aluminium strong box, which he thought contained the money. They also opened it and showed him two bundles, which he confirmed were genuine. They could not, however, pay him because one document - International Clearance and Policy Certificate (ICP) number was not available. It had to come from Nigeria, so the payment was cancelled. Next, he was informed on April 7, 2003 that a sum of $ 410, 000 was required before the ICP could be issued. He paid $195,000 as his own share. Belgore was to pay the rest."

Like all "Advanced Fee" schemes, the big payoff gets closer and closer, but never quite materializes.

The milking continued until Blick's American corporate partners became suspicious and called the FBI. Luckily the FBI was able to knock some sense into Blick, but not until he had given $2,092,894 million of his and his company's money to the scammers.

In January, 2004 Blick was charged with wire fraud along with conspiracy to draud the Nigerian government. After all, the scam Blick went along with supposedly involved stealing the 20 million dollars from the Nigerian government. Blick was convicted in September, 2004 and sentenced to 30 months in jail.

Enough talk about the "victim." Now back to our scammers...

Once Blick was convicted, the FBI alerted the Nigerian Economic and Financial Crimes Commission (EFCC) regarding Odiawa, alias Abu Belgore, the man behind the fraud. With evidence provided by Blick and others, Odiawa was convicted and sentenced to the 376 years.

Does this story have a happy ending? Sort of...

  • A scammer has been brought to justice.
  • A victim has been taught a painful and valuable lesson about greed.
  • The public gets another case study on how to avoid scams and scammers.

The victim and the scammer both received their comeuppance. Hopefully the family of the victim and his business partners get back their $2,000,000.

For all the gory details of the case, see the EFCC web site.

February 14, 2006

Remember that scene in National Treasure where Nicolas Cage pulls a thumb print off Diane Kruger's champagne glass and uses it to get into the super-secret room housing the Declaration of Independence? If not, rent it tonight and take a look.

So, is that really possible or is it just one of those movie-inspired myths? Unfortunately for security vendors, it's pretty close to the truth.

A study at Clarkson University revealed that fingerprint scanners were fooled 90% of the time by fake fingerprints created from gelatin, dental plaster, or even Play-Doh! Another option is for a thief to just cut one of your fingers off and use it on the scanner.

So should you care about this high-tech biometrics stuff? What does this have to do with your life? Well, the Albertsons grocery store chain has recently implemented a biometric finger scan for payment and identification in some stores and both Wal-Mart and Costco are supposedly discussing doing the same thing.
Biometric security password protection

Before there's wide-spread adoption, hopefully these security questions will be resolved. One company trying to do that is Luminetx. They recently patented their vein scanner (designed initially for medical purposes) for use in biometric scans. Evidently your vein layout is extremely unique and can't be faked or bypassed (so far).
Whether it's your finger, eyeball, or arm, get ready for high-tech features at your local grocery or big box store. They're coming.

February 2, 2006

I've seen a number of stories, most recently in yesterday's Times Online, that describe surprise and fear over what Google knows about its users.

This is silly, in my opinion.
Is Google Evil?

Sergey Brin and Larry Page - Founders of Google

The Times Online headline is "Big Google is Watching You" and the article states:

"Google has an extraordinary amount of information about its users. It logs all the searches made on it and stores this information indefinitely. Because every computer has a unique IP (internet protocol) address, every visit to every website can be traced back to the computer making it — a fact which is well known in geek circles but remarkably under-publicised outside them."

and

"Users of Google’s Gmail service, who are already having their e-mails scanned to place targeted ads, have given the company their identity, a full record of all their searches and copies of all their e-mails, stored indefinitely. Users of Google’s Toolbar are inadvertently giving the company a list of not just all their searches but also of every single website they visit. And, as the lawsuit makes clear, all this information is potentially vulnerable to subpoena."

Maybe I'm one of those geeks that realizes that this happens on virtually EVERY web site you visit.

What's a Log File and What Does it Look Like?
When you visit a web site, most will keep a log of what information is requested along with the IP address of who requested it. What does the log file look like? Here's a real sample from the Fight Identity Theft site:

192.168.1.100 - - [29/Sep/2005:09:56:28 -0400] "GET /how-to-report-scams.html HTTP/1.1" 200 22806 " http://search.yahoo.com/search?p=how+to+report+a+scam" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0)"

So here's what this glob of code shows...

  • First is the person's IP address (I changed it to protect the visitor's privacy)
  • The date and time of the request
  • What was requested (in this case, our "How to Report Scams" page)
  • The referring web site (in this case, the person did a Yahoo search for "how to report a scam")
  • The type of browser being used (Microsoft Internet Explorer 6)
  • And the operating system (Windows NT 5.0 = Windows 2000)

This is how web sites work. They collect data and log the data for later analysis (e.g. "How many people visit my homepage?" "What did a person search for to find my web site?", etc.)

What Information Are You Sharing and Can You Hide It?
So what information are you sharing as you browse the web? ShowIpAddress.com is one of many sites that will show you what a log file can capture about you. The only personally identifiable piece of information is your IP address. That number is assigned to you by your Internet Service Provider (ISP). One way or another that number can be traced back to you as an individual, even if you are surfing during work at a Fortune 500 company or other large organization.

Does that make you scared, angry, or just plain nervous? Maybe it should, maybe it shouldn't. In either case, you can browse anonymously if you choose.

There are many products and services that allow you to web surf anonymously. Most will route your requests through their servers, thus hiding your IP address. Anonymizer.com has been around for a long time and they provide a service where you can use their site to browse anonymously for free.

But, back to Google...

Are they evil because they log this information? Powerful, yes, because so many people use their services, but I wouldn't say evil.

When I choose to sign up for a service like Gmail, I know that they will be reading my email content so they can serve up related ads. That's how they make money. That's how I can have a 2.5 gigs of free storage for my messages. Yahoo has a similar policy. Same with MSN Hotmail.

When I choose to use Google search I have to know that they log what I'm searching for and analyze it to spot user patterns. The same thing happens at Yahoo and MSN.

I have to realize that sites, like Google, store this information and will use it to improve their product and to make money. I also have to realize that it could be handed over to the government.

This is all part of the trade-off we make every day between security/privacy and convenience. If you are extremely concerned with privacy you probably shouldn't be using the internet and you certainly shouldn't sign up for a service that clearly states it will read and store your email messages. If you're concerned that your search history or email messages could be revealed at a later date you should consider using a product that protects your anonymity, like Anonymizer.

Here's the bottom line...

When information is aggregated, abuses, information leaks, subpoenas, and profiteering can occur. When it does occur it should be exposed and fought. I just don't see where Google has done anything evil or different than any other web site on the internet.

Feel differently? Then please append a comment to this story.

January 31, 2006

Derrell and Terrell Brittenum of Memphis, TN have been charged with forgery, theft by deception and financial identity fraud for purchasing a 2005 Dodge Magnum last June 2005 in Atlanta using someone else's identity.

The twins recently appeared on the most-watched show in America - American Idol. Evidently they were excellent performers and had moved on to the next round in Hollywood, CA. Unfortunately for them they've now been dropped from the show based on their actions.

Here's a before photo:

American Idol Derrell and Terrell Brittenum

And an after photo:

American Idol Twins mug shot

E!Online reports that:

"Both brothers were released from jail on bond Sunday morning and were preparing to travel to Los Angeles for the next round of eliminations when they received word that their presence was no longer welcome.

Though the twins may have blown their shot at Idol worship, they reportedly have other opportunities to consider. Bennett claims to have been contacted by "several" record labels interested in signing the brothers."

Great! Evidently some record labels are still interested in these gentlemen. Maybe their arrests will give them additional "street cred."

Whatever sells records, I guess...

January 28, 2006

The U.S. Federal Trade Commission reported earlier today that they received more than 255,000 complaints regarding identity theft in 2005. That's up from 247,000 reported in 2004. Total fraud reports topped 686,000.

So what trends show up in the report? Well, here are a few:

  • Identity theft again was the top vote-getter with 37% of all fraud complaints. No surprise there.
  • More fraud involving wire transfers. The percentage of Internet-related fraud complaints with “wire transfer” as the reported payment method more than tripled between calendar years 2003 and 2005, increasing by 12 percentage points. Be careful before wiring money to anyone! Most lottery scams and Nigerian email scams usually involve wiring money to people. Don't do it!
  • Geographic areas with the highest per-capita problems with identity theft? Phoenix-Mesa-Scottsdale, AZ; Las Vegas-Paradise, NV; and Riverside-San Bernardino-Ontario, CA.
  • Number of complaints where no money was lost went up from 24% in 2003 to 32% in 2005. Some of you are getting smarter!
  • Email is increasing as a means to scam you. It is the #1 method to reach victims and has increased from 26% to 35% in the past 2 years.

The complete report can be downloaded in Adobe Acrobat format from the FTC web site.

January 27, 2006

Can five million Britians be duped? Yes, according to a study done by the British consumer protection organization Which?. Which? contacted more than 1000 Brits to see how widespread the scam problem is in the U.K. The results?

  • More than 28 million of 60 million citizens had been exposed to one or more scams.
  • Five million of those 28 fell victim to a scam.
  • The most popular scam related to "an automated phone call that invites people to claim a prize. A third of adults have received such a call and two million have responded, usually by calling a premium-rate number, which can cost up to GBP 1.50 ($2.70 U.S.) a minute."

The funny thing is that I've even seen people outside the U.K. fall victim to these international lottery scams. Here's a typical email that arrived in our honeypot inbox this week:

British Lottery Scam Email

As I was saying, I've received email from U.S. residents wondering if they'd really won after receiving an email like this. They never questioned how they'd won even though they weren't residents of the country where the lottery was held and had never even entered the lottery.

Greed makes us stupid, doesn't it? That's what the scammers count on.

UPDATE!
Many of you have also received snail mail versions of this scam. In this scam you receive a letter saying you've won as well as a check for $3,000 - $4,000 dollars to cover the taxes and processing fees - supposedly.

Anyway, listen up people.

This is a scam. The check is fake.

It may initially be accepted at your bank but will eventually be worth absolutely nothing. So when you deposit it and then send them a check from your account, you will lose money.

Ask yourself... Why would they send you a check and then have you send them a check right back for the same amount? Does that make sense? It does if you're trying to scam someone.

January 25, 2006

No, this won't be a post about some political scandal in Iraq.

Instead, I wanted to post an scam email — one where a supposed American soldier wants to share some of Saddam Hussein's booty (booty here meaning "Plunder taken from an enemy in time of war.")

Here's the email:

FROM: Sgt. Donald Greene To whom it may concern. I am an American soldier, I am serving in the military of the 1st Armored Division in Iraq, as you know we are being attacked by insurgents everyday and car bombs. We managed to move funds belonging to Saddam Hussein_s family. The total amount is US$7.2Million dollars in cash, mostly 100 dollar bills. We want to move this money to you, so that you may invest it for us and keep our share for banking.We will take 60%, my partner and I. You take the other 40%. No strings attached, just help us move it out of Iraq, Iraq is a war zone. We plan on using diplomatic courier and shipping the money out in one large silver box, using diplomatic immunity. If you are interested I will send you the full details, my job is to find a good partner that we can trust and that will assist us. Can I trust you? When you receive this letter, kindly send me an e-mail signifying your interest including your most confidential telephone/fax numbers for quick communication also your contact details. This business is risk free. The box can be shipped out in 48hrs. Respectfully, Sgt. Donald Greene Private Email: donald22greene@netscape.net

I haven't seen an email like this since "Bradon Curtis" a "special forces commando" working in Afghanistan wanted to send us some Taliban money a few years ago.

As always, these emails should produce more laughs than greed as they land in your in-box. The scam is one of the oldest in the book and will involve you giving up more and more money as you try to get your grubby, greedy mitts on 7.2 million of Saddam's money.

Learn more here...

January 24, 2006