Home > Phishing for Mules

Opinion

Phishing for Mules

10/12/2007

We all know, or should know, about phishing, a fraudulent attempt, frequently through legitimate looking e-mail requests, to obtain personal information such as a credit card number, a social security number, or a bank account number and PIN.  The following is one that I received the other day.
Warning Notification

It has come to our attention that your Community National Bank account information needs to be updated as part of our continuing commitment to protect your account and to reduce the instance of fraud on our website.  If you could please take 5-10 minutes out of your online experience and update your personal records you will not run into any future problems with the online service.

However, failure to update your records will result in account suspension.  Please update your records before: Sunday, [October 14, 2007].

Once you have updated your account records, your account activity will not be interrupted and will continue as normal.

Click here to update your account information
As incredible as it sounds, people respond to e-mails like this.  A recent Harvard study found that 90 percent of the phishing recipients don't recognize a well constructed phish.  What I found even more surprising was that neither education, age, sex, previous experience, nor hours of computer use showed a statistically significant correlation with vunerability to phishing.  

The real problem for the phisher isn't getting the information; it's how to convert ill-gotten information into cold cash.  One way is to simply sell the information on the black market where the going price for a credit card number is around $1. That is what apparently happened to some of the 47.5 million plus credit card numbers stolen from TJX several years ago.  More information raises the value.  A card with a three-digit code brings around $5. while additional security information such as a mother's maiden name can raise the value another $10.  A working PIN can drive the price to more than $100.

In any case, at some point the stolen information needs to be translated into cash or merchandise that can be resold.  In March of this year a Florida gang was charged with using credit card numbers from the TJX theft to steal $8 million in small transactions at stores in Florida.  

The fact that they were caught underscores the phisher's problem.  It is hard to make serious money without being noticed--and being caught and sent to jail.  (In Florida it was a Wal-Mart clerk in Gainesville who became suspicious of multiple gift-card purchases that led to a review of store surveillance tapes.)  

To take full advantage of stolen information, the crook, who is frequently operating from a foreign country, needs "mules."  A mule is someone, preferably in the same country as the victim, to handle money transfers or ship items to the phisher.  The more tenuous the money trail, the more likely it is that crook can get away with it.  I made up the following narrative, but it is based on real events.


Recommended Reading
  • Fixed-Mobile Convergence: Dartmouth Beefs Up Cell Coverage, Cuts Costs

    Problems with cell phone coverage aren't uncommon on college campuses. There are two main reasons: The beefy structure of historic buildings can block cellular reception within walls, and, on more remote campuses outside cities, signal coverage can be light.

  • Thompson Rivers U Deploys Unified Digital Campus for ERP

    Thompson Rivers University (TRU) in British Columbia has selected SunGard Higher Education's Banner Unified Digital Campus (UDC) to integrate its ERP systems.

  • DV Kitchen Web Video Publishing System Released

    DVcreators.net has released DV Kitchen, a new video encoding and publishing application for Mac OS X designed specifically for creating materials to be posted on the Web.

  • NEC Debuts 4 Education Projectors

    NEC this week debuted four new projectors targeted toward education applications, along with a new MultiSync LCD display. The new NP-series projectors are entry-level models started at $899 but are designed to provide high light output, support for closed captioning, and built-in networking capabilities.

  • Security Researchers Uncover Spring Framework Vulnerability

    Software frameworks are enjoying enormous popularity these days among a range of developers. It's popularity well earned; frameworks provide powerful tools for building more flexible and less error-prone applications. They generally enhance developer productivity with out-of-the-box functionality. And they can free developers to focus on features instead of common coding tasks.

  • 3PAR Server Arrays Integrate Fat-to-Thin Processing

    Utility storage provider 3PAR has announced the release of the 3PAR InServ T400 and T800 Storage Servers. The new hardware is built on the company's third-generation InSpire architecture, featuring the 3PAR Gen3 ASIC with integrated fat-to-thin processing.