Fraudulent Automated Clearing House (ACH) Transfers Connected to Malware and Work-at-Home Scams

11/3/2009 FBI Press Release:

As part of a continuing effort to identify the latest cyber crime trends and warn the public, the FBI today released the following information:

Within the last several months, the FBI has seen a significant increase in fraud involving the exploitation of valid online banking credentials belonging to small and medium businesses, municipal governments, and school districts. In a typical scenario, the targeted entity receives a “spear phishing” e-mail which either contains an infected attachment, or directs the recipient to an infected website. Once the recipient opens the attachment or visits the website, malware is installed on their computer. The malware contains a key logger which will harvest each recipient’s business or corporate bank account login information. Shortly thereafter, the perpetrator either creates another user account with the stolen login information or directly initiates funds transfers by masquerading as the legitimate user. These transfers have occurred as both traditional wire transfers and as ACH transfers.

Further reporting has shown that the transfers are directed to the bank accounts of willing or unwitting individuals within the United States. Most of these individuals have been recruited via work-at-home advertisements, or have been contacted after placing resumes on well-known job search websites. These persons are often hired to “process payments,” or “transfer funds.” They are told they will receive wire transfers into their bank accounts. Shortly after funds are received, they are directed to immediately forward most of the money overseas via wire transfer services such as Western Union and Moneygram.

Customers who use online banking services are advised to contact their financial institution to ensure they are employing all the appropriate security and fraud prevention services their institution offers.

The United States Computer Emergency Readiness Team (US-CERT) has made information on banking securely online available at: http://www.us-cert.gov/reading_room/Banking_Securely_Online07102006.pdf

Protecting your computer against malicious software is an ongoing activity and, at minimum, all computer systems need to be regularly patched, have up-to-date anti-virus software, and have a personal firewall installed. Further information is available at: http://www.us-cert.gov/nav/nt01/

If you have experienced unauthorized funds transfers from your bank accounts, or if you have been recruited via a work-at-home opportunity to receive transfers and forward money overseas, please notify the Internet Crime Complaint Center by filing a complaint at: http://www.ic3.gov.

For a detailed analysis of this scam please visit http://www.ic3.gov/media/2009/091103-1.aspx

WORK-AT-HOME SCAMS Job One: Don’t Take the Bait

FBI 4/17/2009 Headline:

Everyone’s seen them—seductive work-at-home opportunities hyped in flyers tacked to telephone poles, in newspaper classifieds, in your e-mail, and all over the web, promising you hundreds or thousands of dollars a week for typing, stuffing envelopes, processing medical billing, etc. And it’s just a phone call or mouse click away…

share.gif

Might be tempting during these uncertain economic times, but beware of any offers that promise easy money for minimum effort—many are scams that fill the coffers of criminals.

Here are a few of the most common work-at-home scams.

  • Advance-fee: Starting a home-based business is easy! Just invest a few hundred dollars in inventory, set-up, and training materials, they say. Of course, if and when the materials do come, they are totally worthless…and you’re stuck with the bill.
  • Counterfeit check-facilitated “mystery shopper:” You’re sent a hefty check and asked to deposit it into your bank account, then withdraw funds to shop and check out the service of local stores and wire transfer companies. You keep a small amount of the money for your “work,” but then, as instructed, mail or wire the rest to your “employer.” Sound good? One problem: the initial check was phony, and by the time your bank notifies you, your money is long gone and you’re on the hook for the counterfeit check.
  • Pyramid schemes: You’re hired as a “distributor” and shell out big bucks for promotional materials and product inventories with little value (like get-rich quick pamphlets). You’re promised money for recruiting more distributors, so you talk friends and family into participating. The scheme grows exponentially but then falls apart—the only ones who make a profit are the criminals who started it.
  • Unknowing involvement in criminal activity: Criminals—often located overseas—sometimes use unwitting victims to advance their operations, steal and launder money, and maintain anonymity. For example, they may “hire” you as a U.S.-based agent to receive and re-ship checks, merchandise, and solicitations to other potential victims…without you realizing it’s all a ruse that leaves no trail back to the crooks.

Add identity theft to the mix. As if these schemes aren’t bad enough, many also lead to identity theft. During the application process, you’re often asked to provide personal information that can be used to steal from your bank account or establish new credit cards in your name.

On the job. A host of law enforcement and regulatory agencies, including the FBI, investigate these schemes and track down those responsible. But the most effective weapon against these fraudsters is you not falling for the scams in the first place.

A few tips:

  • Contact the Better Business Bureau to determine the legitimacy of the company.
  • Be suspicious when money is required up front for instructions or products.
  • Don’t provide personal information when first interacting with your prospective employer.
  • Do your own research into legitimate work-at-home opportunities, using the “Work-at-Home Sourcebook” and other resources that may be available at your local library.
  • Ask lots of questions of potential employers—legitimate companies will have answers for you!

And if you think you’ve been the victim of a work-at-home scam, file a complaint with the Federal Trade Commission’s Consumer Sentinel or our Internet Crime Complaint Center.