My Pages

Showing posts with label social engineering. Show all posts
Showing posts with label social engineering. Show all posts

Thursday, 1 February 2024

In the dead of the night, don't go changing money for strangers

It’s all on the money

It was a chance to eavesdrop on a conversation that left me wondering about human psychology and social engineering along with the ease with which one can so easily fall for scams or deceit by reason of vanity overwhelming essential self-awareness.

It was at first three people engaged in bargaining activity over money, I could hear the young man and the lady resist every entreaty, that I immediately thought the other man was trying to pawn off some baubles or contraband just to get cash in hand.

The couple was not persuaded and as they separated and this in the witching hour, the man wheeled his bicycle which I had not noticed before towards a black cab where he addressed the driver, and I got a full context of what was going on.

Pounding for a dollar in hand

He had a $100 bill that he wanted to exchange for Pounds Sterling cash and for some reason, this might have been so urgent that he was not ready to wait for a Bureau de Change to open for that business transaction, or so it would seem before my mind took a ponder on the brief scenario that I had witnessed.

The exchange rate at today’s prices suggests $100 would be exchanged for something between £77 and £82 and that is not accounting for transaction costs, commissions, and other charges. I heard the man negotiating from £80 down to around £60.

I won’t know what an authentic $100 bill looks like and how to account for whether it is legal tender or a counterfeit, then a stranger approaches you in the middle of the night with what seems like a bargain, you none the wiser of where he got the bill, beguiled by whatever sob story he has to regale, and your better instincts see you parting with £70 for this unverified paper purporting to be the almighty dollar, you hoping at your convenience you can walk up to a teller at a Bureau de Change and get £80 or maybe £85 for it.

The vanity of half-knowledge

I hate to think of the number of people who have been suckered into the laundering of counterfeit notes and this is not to say the bill in question was counterfeit. Then, many of us might deign to think ourselves seasoned numismaticians (which might read like a neologism, but it is in the Oxford dictionary, I checked), take any bill and give it the handling, feel, sight, light, and smell test, convinced in our assured dilettantism that we have the Real McCoy, only to find at the end of the conversation with the teller, the next day, the teller goes out of sight for a few minutes and next you are being frog-marched by the local constabulary to the station to answer questions, you would never have convincing answers for.

And indeed, that is the quandary, you never got the name of the stranger, he offered no personal details apart from the soothing repartee that eased you gently out of the suspicious and cautionary into the trusting and persuaded, by a total stranger who could easily have been a ghoulish apparition from the city graveyard donning flesh and apparel for the night, just returning from whatever meetings the dead attend.

Always see strangers at night as strange

Yes, I am totally wary of strangers in the dead of the night, striking up conversation with them is something I so totally avoid even as I could be already backslapping strangers in the daytime after a few minutes of engagement. The most I would aver is to tell the time when asked and at a good arm’s length away.

I cannot say if the man did get to change his $100 bill before the breaking of the dawn, but what coursed through my mind was the need to have the presence of mind not to even countenance the thought of exchanging money for strangers, give them something for an urgency, if that is the case, but if you at all listen to the tales and get carried away in the moment that your vanity trammels reason and good sense to assume you are qualified to undertake that transaction, I’ll like to hear that your story is nothing like that worst case scenario I allowed my thoughts to drift to, such that my appreciation of the innate goodness of strangers and humanity is ever so slightly hit.

This could easily have been another Coronavirus streets of Manchester blog. It isn’t.

Saturday, 25 August 2012

Social Media: Education is Always Better than Sanction


I originally wrote this for my Akin Consults Blog, however, whilst I was catching up on reading material that I usually share on Twitter by taking the headline, the URL and adding a short opinion of mine, I happened on this article 26 Internet safety talking points, it to me is one of the best articulated views on Internet usage and policing, some of which will apply to the topic covered further on in this blog.
I have because of this update changed the title of the blog to reflect these ideas and I think anyone who uses the Internet or anyone who is involved in formulating Internet policy will find these talking points quite useful.
Social media – the fall guy
Over the last couple of months, social media and by that I mean the use of Facebook, Twitter and Blogs has taken a bad rap in Nigeria.
From politicians uncomfortable the ease of access, freedom of expression, unrelenting scrutiny with the attendant abuse that would put Mosaic curses in the shade through its use by swindlers, kidnappers and murderers for incomprehensible ends.
The same social media has been exploited for political advantage too, for engaging the youth in the political process, for aspects of good and sometimes bad propaganda, for crowd-funding, crowd-sourcing and the dissemination of ideas.
The problem is use
However, it is the tragic case of Cynthia Osokogu that brings to the fore elements of usage that we need to very aware of. The young lady apparently met two men while interacting on Facebook, began a business transaction with them that involved her travelling to Lagos where she was picked up, drugged, raped, beaten up, murdered and then dumped in a mortuary where her family finally discovered her.
Fundamentally, the problem here is not social media, or Facebook in particular, Facebook just served as a medium of communication that could have been achieved by other means though maybe not with the same ease.
The problem with the use and I emphasise the word use of Facebook is people have by reason of the ease of interaction lowered the thresholds of trust they have such that they probably do not go through more stringent steps of ascertaining and verification of activities they get involved in.
Before social media they existed
Before any of the social media we have today, swindlers, confidence tricksters, kidnappers and murderers existed just as there were people to be taken advantage of through foolishness, ignorance, naivety or vulnerability.
We so easily let our guard down hoping that the social media vehicle we are using will take up the slack and do the vetting for us but there is no substitute for doing the basic things of not meeting strangers outside your comfort zone, informing people of what you are up to, documenting whatever you are involved in and taking a friend with you if need be for your safety.
When I am going to meet strangers, I always leave a sheet of paper on my table with all the contact details along with a backup element that can be found if there is a need for that.
Some basic analogies
The analogies to use are simple – you do not because you have bought a new knife use it recklessly, you are probably going to be more careful with its use lest you cut yourself. Likewise, the ease of communication offered by social media should have your suspicious and alert mechanisms at their most primed to ensure you are not sucked into a vulnerable situation from which you cannot extract yourself.
In the same vein, you do not because you have a fast car put your foot down on the accelerator and go over a cliff with glee, with a fast car comes better brakes and better control – if those controls are used wisely, you are in a safer vehicle for it protections rather than for its speed. Likewise, the ease with which you can share information should inform the carefulness involved in keeping some of that information back
Common-sense with social media
I have always worked on a simple principle – If in DOUBT, keep it OUT – there is just no need to dump all that information out there just as you do not have your home as thoroughfare for the public to walk through at will without restraint.
We are naturally careful about our private information, it should not be different from our adoption of social media and like our mothers used to say when were kids – Don’t take sweets from strangers – the same principle should apply to anywhere we interact with strangers – we do not know them well enough to trust them and God only knows what they have in mind for us.
Conversely, we should try to believe the best of everyone whilst retaining a modicum of suspicion, it does not have to border on paranoia, but a healthy dose of paranoia is not bad or the principle of personal safety and the possible elimination of dangerous situations.
The real problem
Without making little of the tragedy that befell Cynthia Osokogu, social media is not the problem, it has never been the problem, it the use of or the lack of knowledge of the common-sense uses of social media that is the problem and that is where people need the most education that it should not lower the needs to ascertain, determine, verify and be careful about the people we interact with and it cannot carry the burdens of trust and trustworthiness that come from being streetwise, smart and discerning of character, aims and intentions.
We once had letters, then telephones, then telegrams, then telex, then facsimile machines, then mobile phones and now the smorgasbord of easy communication untethered and free – we are however still human and have not metamorphosed into cyborgs – it means those very basic human characteristics still matter and years from now newer modes of communication will be created and hopefully human-beings will know not to abandon their gut instincts for the thrill of technology.
To Cynthia Osokogu – Rest in peace – no know can begin to think of the harrowing experiences you went through as those men took your life and to your family my heartfelt condolences.

Thursday, 15 March 2012

Social Engineering: Crooks preying on our parents


A menacing problem
I think this is becoming an emergency in Nigeria and it requires we begin to focus on the menace of unconscionable, unscrupulous and merciless confidence tricksters preying on the vulnerable sectors of our society.
Last year, somebody called my mother informing her of my being in trouble abroad and convincingly persuaded her to part with some money. Having tricked her the first time, they applied more pressure at which time she chatted to my siblings who were able to break her out of the spell she had fallen under and stop the criminal activity.
Using my blog, I tried to create a storm and though we never apprehended the nasty piece of work, the bank at least got involved enough for about 3 weeks trying to get hold of the person who for the pressure and bad publicity that had gone out regarding his identity was forced to go to ground.
My mother’s situation was not an exception, the fact is our once strong, able parents are now older and less agile in terms of things in their daily lives, there are people out there ready to create situations of distress, panic, anxiety or fear and by doing so getting our now vulnerable and sometimes lonely parents to part with their life’s savings.
Abductions and hypnoses
I heard today of another case where a fine and wonderful lady in her 70s had gone to withdraw some cash from a bank and as she left the bank, she was accosted by persons who abducted her and took her to some place she can no more recollect.
It is very possible she was hypnotised because she gave them the money she had withdrawn and then she was dropped off at home where the next day under some sort of influence she returned to the bank to withdraw 5 times what she withdrew before and handed it over to the gang.
At the end of the second day, she apparently came to and informed her daughter of what had happened but swore her daughter to secrecy about informing other siblings. Meanwhile the gang was trying again to get her to withdraw more money for them and thankfully to no avail.
Tackling the issue
At first one has to be thankful that she came to no physical harm but the mental anguish and scars of such an encounter will no doubt be more lasting. She is not as chatty as she used to be and she rarely leave her home; this is a lady who has travelled the world has been fiercely independent apart from the fact that she had been widowed for over 3 decades.
I do not think the case of my mother and that of this amazing lady are unique, I have the feeling it is happening a lot but the victims are not talking or telling anyone for the embarrassment, the shame or the realisation that they are a lot more vulnerable than they are ready to let on.
Banks must profile
Banks are usually the centres of this corrupt enterprise because that is where the money is with people being cajoled, blackmail, shaken-down or rustled. They need to be aware that people are targeting their customers usually gaining information about accounts or other pertinent details that will not draw suspicion to criminal activity preying on the vulnerability of the elderly.
Besides, I think banks have a greater duty of care and concern towards these vulnerable sections of society and it is important that they adopt measures that are sympathetic and cognisant of withdrawal patterns of these people – such as alerts to successive withdrawals of large sums of money, facilitation of wired transfers rather than the handling of large sums of cash and advising that senior citizens for their good be better accompanied to and from the banks.
They need to create better profiles of their customers of a certain age, install triggers to alert to unusual activity and have better levels of customer care and challenge/response scenarios to help their customers safeguard their wealth especially when things are somewhat out of the person’s control.
Any other ideas you might have towards helping our parents evade these crooks will be welcome and please post them as comments.
Thank you.
Related posts

Tuesday, 2 August 2011

Social Engineering: For the avoidance of Mrs Mary Williams

This is not for me

I just got an email with the subject Dear Customer: I would presume whoever is addressing me does not know my name; the email portends to be from MoneyGram with the email address of money326@msn.com which immediately indicates that it is really not from MoneyGram.

I will humour myself by reading the email and you will find my comments inline in parentheses, it will just pertain to the content of the email, I will not do much technical analysis to ascertain the genuineness of this email.

From Office Of The Money Gram Money Transfer. Accra-Ghana Republic / Address No 450 Ring Road Accra-Ghana.

[Now, I would have thought this would come from the office of the MoneyGram Money Transfer Bureau, emphasis on Bureau, which might be in Accra but is it not the Republic of Ghana?]

Appearances of deception

Website:WWW.money-gram.com/

[The genuine MoneyGram Money Transfer website is http://www.moneygram.com the one in this email does not exist.]

Phone:+233244841003.

[Yes, that is a Ghanaian phone number but I doubt I will be calling it.]

Email: mg179435@w.cn

[Now, I have a second email address and this is in a Chinese domain.]

Dear Customer:

[These people do not know me, here again I am being addressed as Dear Customer.]

The letter

Be inform[ed] that we have been giving [given] and [an] instruction by, Hon Ado Seth, DP Ministry of Finance Accra Ghana to start sending to you $5000usd everyday through money gram money transfer, Until your total amount sum ( $1.2 Million us Dollars, AID FUND) one million two hundred thousand united state dollars is completely transferred to your custody .

[I really cannot be bothered with correcting this, too many errors in this paragraph, I could do with a transfer of $5,000 into my custody and eventually my bank account everyday but I will settle for Paypal donations to made though clicking on the Donate button at the top right of this blog.

But read this, I am over a period of 240 days supposed to receive the sum of $1.2 million in daily deposits of $5,000; I suppose a vulture is a patient bird but I doubt it will wait for the egg to be laid, incubated, hatched and the full lifecycle of the bird to carcass before it feeds.

The poor Ghanaians whose aid pornography pictures have moved aid agencies to sympathy to donate to their plight are not going to get sight of the aid, it is about to be drip-fed $5,000 a time into the account of Dear Customer, Yours Truly.]

Affected by an avoidance

Today our department have affected [Why can’t they avoid affording the misuse of affected for effected?] your first transfer of $5000usd to your name, Transfer Reference below.

[Indeed, they need to be reminded of my name which they never knew before.]

Sender First Name=Dr Victor

Sender Second Name =Ike

Amount=$5000.00 USD

Question=Code

Answer=233.

[Who is Dr Victor Ike?]

Contact Dr Victor Ike, Foreign Operation Manager on the below address, to issue to you, your Fund Clearance Certificate and give to you your Money Gram Transfer Control Number to pick-up your first payment of $5000 us dollars.

[So, Hon Ado Seth (Don’t be deceived by titles, this man is hardly Honourable by any stretch of the imagination.) in corrupt enterprise with Dr Victor Ike are in this together and looking further down, the latter is the Foreign Operation(s) Manager at MoneyGram in Ghana – Interesting.]

Dr Victor Ike{Foreign Operation Manager Money Gram Accra Ghana}

E-mail {mg179435@w.cn}

[And though he works in Ghana he has a Chinese email address.]

Tell-+233244841003.

She’s a scammer

Cheers

Mrs Mary Williams.

[Mary Williams? Cheers? Maybe I am being pedantic here but you cannot without knowing me end up closing an apparently formal letter with Cheers. Who the heck is Mrs Mary Williams and to what do I owe this random windfall from three unknown people in Ghana?]

Like they say, if it is too good to be true, it probably isn’t worth your while. To close, I just attempted a search on Mrs Mary Williams and before I finished typing, the suggestion of “Mrs Mary Williams email” was offered by Google and well, she appears to have a reputation for scamming people.

Mrs Mary Williams, please go take a running jump off Fort Elmina, you’ll be doing yourself the greatest favour.

Tuesday, 5 April 2011

Social Engineering: That Epsilon email data breach

Another data breach and scare

News that Epsilon [1], an email marketing service provider had suffered a security breach that involved the loss of data has been received with some angst and the analysis of security of data on corporate systems.

This firm handles the email marketing for quite a number of big names in the US like Target, Chase, Marriott & Tivo referring to the names that came up in the opinion pieces that form my source for this blog.

It is interesting to note that the first article dealt with the matter of Outsourcing email [2]; this is just a matter of responsibility, the data is vulnerable no matter whose system it is on but where the data is hosted in-house, after the fire-fighting and damage control there might be a person or department to take the blame with the possible rolling of heads in mock absolution for faults.

This is a big deal

The second article dwells on the value of an email address [3] but only in reference to the service provider from reputation, through information management to the possible loss of custom – the figures are high but they hardly address the more important point which is how it affects the customer.

Another news story suggests Epsilon sends out [4] over 40 billion emails annually from over 2,500 clients which include 7 of the Fortune 10 companies. This is big business at first and quite a large customer base too.

You’ve got mea culpa mail

In one instance the writer had received an apologetic email from Epsilon and seemingly exculpatory emails from three other organization which whom he had registered for some service that used his email as part of the transactional and interaction process.

Interestingly, even one comment suggested the receipt of emails from organisation they thought they had already cancelled subscriptions to, in effect, cancelling a subscription only stops emails from going out, it does not expunge the host database of the email information.

Where it gets worrisome is that what was exposed to unauthorised access was email addresses and/or customer names.

Proof you exist

There are a number of inalienable facts that derive from this piece of information, the fact that it was on Epsilon systems means there is a likelihood that the addresses are active and where a customer name is attached, it serves enough as a uniqueness identifier just for a spammer to use or purvey and even conduct more extensive searches that can match that information to home addresses and other personal information that could be found online.

This is the equivalent of looking through a telephone directory which probably contains current and valid information to use a service or contact a person.

Over a year ago, my phone number strayed into the hands of scammers in Ghana, one of whom called me at an unholy hour, the moment I answered the call, I had validated the working order of that number and for 5 consecutive days I received calls from different people in Ghana and it was my ignoring the subsequent calls that fed back into that network that it was useless calling me.

Another analogy is the having an email address with a customer name is the equivalent of knocking on a door and knowing there is an occupant of that premises that offers the opportunity for the criminal to watch out for when they might burgle the premises.

Getting familiar

Beyond that, having a customer name allows for the spammer to send friendlier and more familiar type communication that can break down the usual resistance to spam email.

Where the customer has different email addresses with particular ones being used for trusted Internet activity, receiving spam emails on those addresses can be rather irksome.

By the time the customer has been irredeemably spammed even important emails would have ended up in the bin whilst ameliorating acts of changing email addresses can be fraught with unnecessary administrative problems of reviewing all subscriptions, informing all contacts and many other troublesome issues.

The cost to the customer is high and I have in certain instances had to discontinue the use of a service provider just because they were doing nothing to stem the flow of spam.

Remediation is fraught

However, as it stands, there is really no compensation for the inconvenience of the expected deluge of spam from a new set of spam addresses and who because they now have customer names could suggest they have established a relationship with the victims of these criminal activities.

I am saddened that of most the computer press I have read about this data breach have not really addressed this angle of the matter, it is the multitude of customers that give the companies the business they have, they seem to have been forgotten in their face-saving and damage-limitation quests.

Taking care

Customers should beware of phishing email, check that URLs in emails are really from where they purport to come from, never send any personal details to anyone seeking such information via email, at least not before verifying that with the company via a telephone call.

You should never have to share your security number, home address, credit card numbers or personal identity numbers with anyone either by email or on the phone, if in doubt, ignore the email especially if it reads like a threat and if on a phone call, excuse yourself from the call, recompose yourself and call at another time – the taker of your call should never fill you with additional angst and anxiety.

Sources

[1] Epsilon is a subsidiary of Alliance Data - Wikipedia, the free encyclopedia

[2] Outsourcing email: Do the benefits outweigh the risks? | ZDNet

[3] Epsilon data breach: What's the value of an email address? | ZDNet

[4] Massive Breach at Epsilon Compromises Customer Lists of Major Brands | SecurityWeek.Com

Monday, 13 September 2010

Social Engineering: Appealing to my vanity

So much spam

The process of moving my blog to http://akinblog.nl has been slow and fraught but it is beginning to gain some traffic and recognition. Hopefully, with time it would become the primary reference point of searches that have usually gone to http://akin.blog-city.com

One thing I have noticed about hosting my new blog on Google’s Blogger facility is the amount of spam that comes round most of which seems to appeal to different aspects of one’s masculine vanity.

One good look in the folder of spam messages captured on my gmail email account shows about 75% of the emails recommending some augmentation to the male protuberance either for length or stamina to be able to as it were satisfy your partner.

Appealing to my physical vanity

Indeed erectile dysfunction can be an issue when pleasure is truncated by the premature incidence of orgasm just when you thought you could go on for longer, it probably dwells on many a mind and it could be frustrating.

For those who are otherwise blessed the receipt of such odious and unflattering emails is annoying but the spam filters seem to be putting in their hours.

On the blog front however, each comment logged each particular blog creates a notification which does not end up in the spam folder and incurs the additional work of management even though the blog commenting system might well recognise the comment as spam.

Appealing to my mental vanity

That is just one side of appealing to ones vanity, the other part came in a comment I received on my blog this morning.

As follows: Anonymous has left a new comment on your post "Thought Picnic: Vulnerability offering opportunity...":

I usually do not leave a comment, but the ideas really rocks, also I have a few questions like to ask, what's your contact details?

-Johnson

Anonymous who has signed off as Johnson probably does not have a Google blog, nor does he (if a first name) or her (if a surname) have a website they are willing to publish as part of receiving feedback for the comments they have left.

Comments appealing to vanity

There is probably nothing to read from the comment but the basic compliment until one has a second or third reading and then it begins to matter a lot more than it seems. This is a generic comment can be left on any and every blog with one singular aim in mind.

Indeed, one of the signs of having a following comes from people commenting on your blogs and this supposed fan rarely leaves comments but now decides to do so in the quest for something other than the views expressed in the blog.

Given that the person does offer the passing opinion masquerading as praise that “the ideas really rocks”, I am really confused about the urban language with the apparent number confusion as to the idea and the context that the person is referring to.

Having appealed to my vanity with the notion of my rocking ideas, the person has a few questions to ask, fair enough and somehow expects me with the additional request to publish my contact details in response.

One can only wonder what questions that person has to ask that cannot be put in the comments or forwarded as an email, because those details are not that difficult to get if the person does try.

Generic comments as social engineering

Between you are me, this is another classic case of social engineering; having appealed to my vanity and flattered me in some way, just as the title of the blog goes, it has provided a window of vulnerability offering the opportunity to request my contact details which I am supposed to foolishly volunteer to some non-descript stranger to ask personal questions.

It was a good try but this will not work with me and it really should not work on anyone else too, if anyone wants to engage you on matters so personal the need for full-disclosure is paramount and it should be initiated by the enquirer and not by you.

Otherwise, this is just another case of Johnson probably leaving a similar generic comment on as many blogs as he/she can to harvest details for some nefarious activity beyond which the victim has little control.

Beware of the flattery that leaves you vulnerable to volunteering information you should best keep for your protection and safety.

Friday, 30 July 2010

Social Engineering Skype Trusted Contact Inquiry


Even if it was, I don’t care
Yesterday night, I was almost a victim of social engineering based on trusted connections with a contact on Skype.
The question came, “is this you on picc??..” Then a URL constructed to have Facebook in the address.
I should have been suspicious of this because my friend from whom this apparently came does his punctuation and rarely uses strange words, but my basic feeling of trust overrode the logic to my thinking.
I clicked on the link and rather than it going to a page it downloaded a file with the .exe extension, which really got me suspicious – How could he have asked if I was on a picc or picture and then send an executable file rather than a picture or a webpage?
Persuasion of the friendly kind
The genius of social engineering here is that I was first persuaded by reason of the fact that this message came from a trusted contact asking a question that would rouse ones curiosity regardless of if you were on Facebook or not.
He had apparently received this code through his Yahoo email from a trusted contact and inadvertently ran the code but not realised that he had infected his system despite the warning he received from his Antivirus utility. It is possible that the utility might just have said opening a file of that type is unsafe rather than that it was malicious.
The clean-up
We all have the tendency to override such warnings and almost always have to pay dearly for it. His Antivirus utility did not detect the problem after a full scan, however, I also asked him to download Destroy which is a free utility that inoculates web browsers and searches for malware.
The utility detected Bredolab.fb which is a kind of credential logger, it was removed and we can safely assume the system is clean. However, I happen to be one of two people whose Skype profile was online on my friend’s system who received this stuff and like me, we reacted before we questioned the real provenance.
The significance of the second link is that, when I did not fall for the redirect URL on the first inquiry it used the TinyURL link shrinker to give the same reference but deceptively named like a picture (JPG) on Facebook, but I was not taking that bait twice.
The graphic of the situation appears below.
Skype Malware

Thursday, 8 July 2010

Social Engineering UPS delivery

Showing fishy emails

I have decided that each time I see receive an email that threatens to expose me to scamming by reason of the genius of its construction, I will post the email and annotate it to expose the suspect activity, without getting too technical.

Looking through my inbox which receives close to 80 emails a day from so many email accounts there was one that appeared to arrive at my business account from UPS, the courier company.

From the header, I noticed there was no subject – No business with any sort of organised system should ever send a customer an email with a subject, on a personal basis, it is rude, in a business setting it is unprofessional.

Appearances and realities

The email appeared to come from UPS Support with the name of the sender, it looked official enough with a UPS.com email address too.

If you get an email from any organisation and the email domain does not reflect the organisation or business name, the sender is an impostor. Many lottery wins and collect emails do not use company email domains they can be classed as scams no matter how too good to be true the content might be. Yahoo, Hotmail, and MSN addresses should be ignored.

Where is my name in this email, they should know who they are delivering to, this is a delivery company for crying out loud. It looks like a fishing exercise.

PDF or broke

This email had an attachment with the name invoice. Be careful with attachments, the safest ones to open are ones with the PDF extension, anything else treat as suspicious, is probably a virus or a keylogger ready to steal your passwords to email or bank accounts. It would be safe to just delete those emails.

Nowadays, invoices must be emailed in PDF format, they are never too large to be undeliverable because of email service restrictions. ZIP files are like Trojan horses, open them and you can end up running a program that ruins your system or worse. EXE files, just NEVER open them. If they are TXT files, sometimes it is best to save the attachment first and then observe that they are really the format they say they are before you open them.

You must always have an up-to-date virus scanner on your system that scans emails too. AVG offers a free edition but the professional editions are inexpensive too.

Drawing you by the bait

Now to the social engineering part of this email; I have been informed that “Unfortunate we failed to deliv” then the rest of the text is obscured by an opaque grey box.

Out of frustration or curiosity, you will be tempted to find out what this was all about and find yourself opening the suspect attachment and you have been had – hook, line, and sinker.

I think it is a work of evil genius because many would end up opening the attachment, but I did not; there were two separate messages in this email.

The first was the text about a delivery and one I was not expecting, and the second was an invoice for something I cannot say I paid for.

No effect without cause

The invoice if I paid for anything should have come from the company, I bought stuff from and not from UPS except if I had engaged the services of UPS which I did not.

So, on the balance of probability, this is a scam, if UPS were unable to deliver a product, it would have arrived at my address and a note left in my post-box not an email sent to me.

The more this email looks authentic the more I am suspicious of its origins. In the worst-case scenario, I have replied to this email asking for it to be sent in legible text, with a PDF invoice and a letter sent by post explaining why they could not deliver the service. If your name is not in the email you received, do not sign off with your name.

Don’t give them more

They do not need my name or address in the reply, they should already have it – do not volunteer excess information to suspect situations.

People are looking to have you, so ensure you are not had by innocuous emails masquerading as authentic customer support emails. Benign as this might seem, it screams scamming to the rafters at best, I cannot think of what the worst of their intentions might be.

Thursday, 17 June 2010

Social Engineering email scam


I don’t know you
I thought I would post this before dashing out to catch my plane to Berlin for the weekend.
This email arrived in my mailbox with the premise that one of my web mail accounts might have been illegally accessed.
That kind of information, I would like to know if my email provider is monitoring strange activity on my account, but when it is addressed to undisclosed recipients, one has to get suspicious and when they ask for your password, well, it is a scam.
Don’t believe a word
This is a classic social engineering means of instilling fear to obtain information from the unassuming, not only can this be used to obtain private details as passwords, it can be extended to more intimate information as account details, identification numbers and more.
Just class the email as junk mail and a scam attempt, NEVER give your personal details to anyone, you might be offered the opportunity to verify or change information but never to give that information for any type of administration.
The service is theirs to offer but the access codes are yours to keep and never to be shared with anyone except under the duress of the law where all adequate measures have been taken to protect your rights.
The graphic below shows my views of what I read of the email. Beware!
Admin email scam

Tuesday, 15 August 2006

Was that the Real Story?

When documentaries sensationalise rather than educate
I did not see the Real Story episode that was broadcast last night, but the snippets that were shown in the news stories during that day did have a touch of sensationalised histrionics to it.
It is a well-known fact that certain enterprising but dishonest Nigerians have been involved in what is known as Advanced Fee Fraud or 419 in the local parlance.
Part of what I saw showed a raid on an Internet café in Nigeria where officials of the EFCC (Nigerian Fraud Squad) had everyone vacate the computers; they asked everyone to put up their hands facing the walls and then as one of the suspects remonstrated an EFCC official assaulted the man with a slap in the face commanding him to shut up.
This is a poor reflection on the Nigerian criminal justice system that suspects can be assaulted but law enforcement agents with impunity and very little recourse for justice.
My take on 419
Back to 419 - This is where using the human susceptibility to greed and gullibility, a victim receives a request to supposedly launder ill-gotten gains from bogus contracts or stashes of frozen sums of money by providing their bank account details and paying an upfront fee for the administration of the process. Some are so sophisticated in their ploys that it becomes too good to be true – anything that has that feel to it has my radar homing in on something fishy.
Many have fallen for this get-rich-quick scheme and lost large sums of money, but I have no sympathy for both the perpetrator and the victim, they were both about to engage in a criminal act. However, there are cases where the contracts do look real, but when you are about to invest money, especially in Nigeria, you have to have your wits about you and seek an independent, impartial review of the whole thing – involve lawyers and investigators you can trust before you part with your cash.
The Real Story episode revealed that people’s details were being sold for as little as 20 Pounds, the details were supposedly gleaned of hard disks which would have been in used and second-hand computers exported to Nigeria.
Your details can be used anywhere
The fact is the information on hard disks can be read in any country and can be used by any set of criminals either in Nigeria or elsewhere. Having completed a module on Computer Forensics, I am very well aware of the fact that it takes a lot more to delete data off a hard disk.
There are tools to recover long removed data and special tools are required to wipe hard disks to the security standard of the Department of Defence, in fact, in most cases, the hard disk would be melted if the data that it once contained is considered secret.
Besides, identity fraud is probably an issue closer to home than in faraway Nigeria. All you have to do to rummage through a bin and find letters, bank statements, if not credit card PIN slips that give enough information about a person – this is called bin raiding – a further search on the Internet can reveal birth date, birthplace and parents if the genealogy, census, birth, marriage and death registrations are online.
A letter posted to my cousin in England from Nigeria some 20 years ago ended up in the hands of a lodger who used that information to obtain a National Insurance number in my name – so identity theft does not have to be so complicated or sophisticated.
Developing a sense of security to protect privacy
People who generally would lock their doors when they go out and pull the curtains to keep prying eyes out, apparently, do not apply the same principle to their information, data, computers and personal details.
Everyone who receives a letter of any importance must invest in a paper shredder and shredders do have different security ratings from strips to pulp – I never dispose of any paper that has not been shredded and I have been doing that for at least 7 years.
Your computer when online is like an open door with drawn curtains and open windows; you need more than just any popular anti-virus software because virus developers test their malevolent programs against popular anti-virus software to prevent detection.
The general idea is to develop the fortress principle to your computer, an outer wall (a firewall), the doors and windows (an anti-virus software) and then the protection of valuables within the home (malware detectors).
Use good tools
In my case, I do use a hardware firewall found in my wireless router and enable the software firewalls on all computers, I have installed the well known McAfee VirusScan Plus and Trend Micro PcCillin Internet Security ensuring that the updates run every day at night.
Malware is software that gets installed inadvertently on your system through opening a suspicious email or visiting an innocuous web site, they can install key loggers which record all the keystrokes you have typed and send that information to a harvesting system where the information can be replayed as if it were you logging on to your bank account or some other security service. These are really the identity theft perpetrators.
I use Lavasoft Ad-Aware and SpyBot – Search and Destroy, with all that attention to detail, I still find that a keylogger still ends up on my laptop every few days – you just need to keep ahead of the criminals – time after time.
In addition, to remove all references to sites, I have visited and files I have opened on an operational system, I use CleanUP.
If you are done with your computer, you can recycle it, but before you do, search for a secure hard disk deletion tool as this write-up suggests – Purge hard drives before recycling.
Common sense approach to social engineering
In all, you have your identity to protect, ensuring that the people privy to your secrets are authorised to access that information with discretion under the contract of confidentiality, not of which should violate your right to privacy.
Where people, emails or forms ask for information that should be personal and known only to you like your PIN numbers, do not under any circumstances reveal that information because that that time you would be seriously compromised – they might want information about who you are where name, address, date of birth and account number might suffice, but that should only be divulged to those your have ascertained through obtaining their own details first.
Always err on the side of caution, err of the side of keeping the information than giving it out.
References