Search This Blog

Showing posts with label fake. Show all posts
Showing posts with label fake. Show all posts

Tuesday, March 20, 2012

T.S.A. Is Considering Automating ID Checks

Excerpt from an article in

The New York Times
Tuesday, March 20, 2012

T.S.A. Is Considering Automating ID Checks

By SUSAN STELLIN The Transportation Security Administration has spent a lot of money on technology to keep dangerous items off planes — with mixed results — but has been slower to address another risk: travelers who are using a fake boarding pass or identification.

Despite announcing plans last fall to test machines that can electronically verify passengers’ documents, the agency still relies on its agents to visually inspect boarding passes and IDs, and confirm that each traveler matches the photo on a driver’s license or passport. At a busy airport, one employee may check several hundred documents an hour.

The repetitiveness of that task has left plenty of room for human error, as Michael Krug and his colleague discovered when they were on a Delta flight in February and realized they each had a boarding pass for seat 12C, both printed with Mr. Krug’s name.

“The person at security didn’t notice that my co-worker’s boarding pass had my name on it and he had an ID with his name,” Mr. Krug said.

The two men checked in as part of a group and figured that the agent must have handed them two copies of the same boarding pass, a mistake that was overlooked at the security line and then again at the gate. That triple error may be rare, but it highlights a security flaw that has been publicized many times.

Last year, for instance, a Nigerian man managed to fly free from New York to Los Angeles with an expired boarding pass in someone else’s name, but was arrested a few days later at Los Angeles International Airport when he tried to fly to Atlanta using another expired pass.

Travelers, security specialists and the news media have reported many other instances when T.S.A. agents failed to notice a fake or expired boarding pass or improper identification, a vulnerability that has been a concern since it was discovered that many of the 9/11 hijackers had obtained fraudulent IDs.

With the advent of online check-in, it became easy to digitally alter a real boarding pass with a different name or new travel date and print a copy that would get through security. There have even been Web sites that generated a fake boarding pass or provided instructions on how to make one at home.

The T.S.A. said it was working to address this problem as part of its shift toward a more risk-based approach to screening passengers, which gives higher scrutiny to travelers the government knows less about.

In October, the agency announced that it was spending $3.2 million to buy 30 document authentication systems from three vendors, which it planned to test in airports in early 2012. Those tests are now expected at select airports “in the coming months,” said Greg Soule, an agency spokesman.

“The technology is designed to read security features embedded in both the boarding pass and ID to verify their authenticity and ensure the names match,” Mr. Soule said in an e-mail.

Tuesday, February 21, 2012

News Release from Panda Security

  1

One Bot To Rule Them All

  • The Ainslot.L bot scans computers and removes any other bots it finds
  • It spreads in a fake email purporting to come from UK clothing company CULT
  • The message is very well crafted to avoid raising suspicion
PandaLabs, the anti-malware laboratory of Panda Security –The Cloud Security Company– has reported on a new bot called Ainslot.L. This malware is designed to log user activities, download additional malware and take control of the system. Additionally, it acts as a banker Trojan, stealing log-in information related to banks. It also scans the computer looking for and removing other bots so that it becomes the only bot on the system.
“The fact that Ainslot.L removes other bots from infected systems definitely caught our attention”, explained Luis Corrons, technical director of PandaLabs. “It eliminates all competition, leaving the computer at its mercy. It reminds us of the popular ‘Highlander’ movies, – There can be only one –.”
It spreads in a fake email purporting to come from UK clothing company CULT. The message, which is very well crafted, informs users that they have placed a £200 order on CULT’s online store and the invoice amount will be charged to their credit card. The text includes a link to view the order which actually downloads the bot onto the computer.
According to Corrons, “Phishing emails are not usually so well done. There is no doubt that this time fraudsters have been very careful to try to make these messages look as real as possible to get as many bites as they can”.
More information is available in the PandaLabs Blog.

Saturday, January 21, 2012

Closing a "Crime Superstore"

From FBI blog:


01/10/12


They hijacked identities on the other side of the globe…faked drivers’ licenses and other documents…built bogus credit histories and boosted the scores in clever ways…then used it all to open bank accounts and credit lines they could loot at will.


In the end, they created what our Newark (NJ) Special Agent in Charge Mike Ward called a ‘crime superstore,’ a sophisticated way to rob financial institutions, retailers, car leasing companies, and even the IRS out of millions of dollars.


Following an undercover investigation led by the FBI and its partners, it all came crashing down in September 2010, when 43 members of the criminal ring were charged in this complex scheme. Another 10 individuals were charged for various related offenses at the same time during a coordinated takedown. And on Monday, the leader of the band of thieves—San-Hyun Park, known to his criminal colleagues as “Jimmy”—pled guilty in federal court in Newark.


The Park criminal enterprise started by stealing Social Security numbers from unsuspecting individuals—usually from China—who were employed in American territories in Asia like Saipan, Guam, and the Philippines. They then sold these identities to its customers in the U.S. for $5,000 to $7,000. Although the stolen identities were Chinese, the vast majority of Park’s customers were Korean-Americans. The ring would use the phony Social Security numbers to obtain authentic driver’s licenses, identification cards, and other identity documents from various states…or manufacture counterfeit licenses and other documentation.
Based in Bergen County, New Jersey, Park’s organization was subdivided into different cells, each with a unique role. First, there were the customers who paid Park and his co-conspirators for fake identity documents. Then, there were the brokers, suppliers, and manufacturers of the phony identity documents—like Social Security cards, immigration documents, and driver’s licenses. A third group included merchants who colluded with the organization by knowingly swiping phony credit cards in return for a fee called a “kkang.” The credit card buildup teams made up the fourth group, fraudulently inflating credit scores to help open the bank and credit accounts.


The buildup teams would take one of the stolen Social Security numbers—and the Chinese identity attached to it—and add that person’s name as an authorized user to other co-conspirators’ credit card accounts. These co-conspirators, who knew their accounts were being used to commit fraud, received a fee for their service.


After the credit buildup was completed, the Park criminal enterprise conspired with its customers to use the fraudulent identities to apply for checking accounts, bank and retail credit cards, debit cards, lines of credit, and loans. Members of the criminal conspiracy used their sizeable proceeds to live large, buying such luxury items as fancy cars, expensive liquor, and designer shoes.


The multi-agency investigation made use of cooperating witnesses and an undercover federal agent, as well as court-authorized wiretaps, to record incriminating conversations among members of the crime ring and others. The FBI partnered with several federal agencies and local police departments in New Jersey, among others. We also worked cooperatively with the major banks, credit card companies, and department stores targeted by this criminal organization.