This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Organized Crime Steals Millions From Online Brokers

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://www.techweb.com/article/printableAr…_section=700028
October 24, 2006
"Criminals have broken into customer accounts at several American online brokers, including E*Trade, and made off with millions, brokers have acknowledged. Federal authorities are investigating. Last week during a conference call with financial analysts, New York-based E*Trade noted that it had taken a one-time charge of $18 million due to online fraud. "We have experienced a serious increase in fraud relating to identity theft," said Mitchell Caplan, E*Trade's chief executive, in the earnings call last Wednesday. That fraud, said Caplan, has been traced to a "concerted ring in Eastern Europe and Thailand," but new processes and technology had nearly eliminated the fraud. "In the last three weeks, we've seen that level of fraud drop to almost zero," Caplan claimed. Both the FBI and the Securities and Exchange Commission (SEC) are looking into the fraud, he said.
According to reports by Bloomberg News*, Omaha, Neb.-based TD Ameritrade has also been hit by fraudsters out of Europe and Asia. The criminals are using a number of profitable techniques, said Ameritrade and other sources quoted by Bloomberg, including a "pump-and-dump" scheme where thieves used customers' funds to drive up the prices of marginal stocks. The criminals would then sell shares they had purchased earlier for a large profit. The scheme typically sets off few or no security alerts at online brokers because no money is withdrawn from the compromised accounts, Bloomberg said. In other ploys, identity thieves open accounts using stolen names, then use those accounts for illegal trading or money laundering. Any investigation leads authorities to the victim, who appears to be responsible. Customer fraud losses were made good by E*Trade and TD Ameritrade, both of which announced earlier this year that they would reimburse customers. Federal law does not require brokers to refund customers…"
* http://www.bloomberg.com/apps/news?pid=206…As&refer=us

:( :ph34r:
More…

- http://www.washingtonpost.com/wp-dyn/conte…6102301257.html
October 24, 2006
"…These emerging Internet stock schemes appear to be new versions of the widely used "pump-and-dump" e-mail scams, in which spammers send out mass e-mails containing bogus news alerts intended to manipulate stock prices. Stark said perpetrators are breaking into customer accounts and buying shares of thinly traded, microcap securities, also known as penny stocks. The hacker gains access using the customer's user name and password, then liquidates that person's existing stock holdings and uses the proceeds to buy shares in the microcap. The goal, regulators said, is to boost the price of a stock the hacker has already bought at a lower price in another account. The hacker then liquidates the stock and wires the money either to an offshore account or through a series of straw men, or dummy corporations, Stark said. The straw man may not know he is participating in fraud; he may have been told he is helping, say, an offshore business. The entire operation can take a matter of minutes, or at most, hours… Online financial fraud has grown so serious that the Federal Financial Institutions Examination Council, a government entity that establishes standards for banks, has given U.S. financial institutions until Dec. 31 to tighten security measures for accessing online accounts…"

:ph34r:
FYI…

Scams Target Latest Upgrades in E-Banking Security
- http://blog.washingtonpost.com/securityfix…web_bankin.html
October 27, 2006
"Financial institutions across the country are scrambling to meet a Dec. 31 deadline set by banking industry regulators to have security processes in place for online banking that go beyond simply requiring customers to enter a user name and password. While some of the protections being adopted should help people -feel- more confident about online banking, there are signs that criminals already are adapting their techniques to defeat those measures… Take, for example, a phishing e-mail from earlier this week targeting Bank of America customers with the usual message urging the recipient to "update their account information," in this case due to a supposed "server update" by the bank. Users who click on the included link are brought to a page that prompts the visitor to reset their account data by supplying their "old" password and user name, as well as their "previous" two SiteKey questions and answers… It would be interesting to compare the results of the anti-phishing technology built into the latest releases of both Microsoft's Internet Explorer 7 and Mozilla's Firefox 2.0 browsers. When I visited this particular site in Firefox, I received a pop-up alert from Netcraft's anti-phishing toolbar, but also from Firefox, which flagged the scam site as a "suspected web forgery" and included links I could click on to earn more about phishing scams. When I visited the Bank of America scam site in IE7, I received no such alert."

:ph34r: