On last.fm: Interview with the mini mall rap guy!
BNET Business Network:
BNET
TechRepublic
ZDNet

May 27th, 2008

Scam calls... something we've forgot about?

Posted by Nathan McFeters @ 10:23 am

Categories: Data theft, Governments, Phishing, Privacy, Spam and Phishing, United States of America

Tags: Do-Not-Call, Credit Card, Phishing, Government, Identity Theft, Sales Channel, Cyberthreats, Financial Services, Spam, Security

I was thinking about the problem of identity theft today and looked back at notes I took during Nitesh Dhanjani and Billy Rios’s presentation at Black Hat and Blue Hat recently and I came to the realization that our government should be doing more about this crap.

You see, identity theft is an economy itself.  It has demand, thieves trying to use the stolen information for their own financial gain, and supply, the stolen IDs.  In fact, there’s a whole sales process of selling phishing kits, IDs, skimmers, etc.  Think of all the places that keep record of your personal information… banks, your employer, your cell phone provider, your cable company, your apartment complex, the government, your doctor, etc. etc. etc.; now also think of all the places where you readily scan your information to be stored, ATMs, the Redbox, etc.  All of these data warehouses are potential places where your data could be stolen from.  The attacks are well known these days, phishing, web application compromise, skimming, etc., but we’ve forgotten about something.  Scam calls.

For the past 20 days I’ve been getting calls from the number 480-543-1320, listed as SSPL.  It appears I’m not alone.  For me, I’ve never heard anything but dead line on the other end.  Calls back have been met with a busy tone.  However, for others, they’ve received prank calls, calls asking for their social security number or credit card directly (not very intelligent callers it would seem), claiming the call recipient has won a free cruise (just provide your SSN and credit card number), or claiming the call recipient has won free gas (just provide your SSN and credit card number).

You know, I thought this crap was illegal.  Apparently it is, but only if you are on the “Do Not Call” list… well, I joined that a long, long time ago.  There’s also been  a lot of complaints registered against this number, yet nothing has been done.  I thought it was interesting and thought, maybe I should investigate the 480 area code (Arizona).  The list of scam calls from that area code is absurd, but I have no idea if it is any more than any other.

Being a security consultant in my primary job, I know just how easy it is to social engineer someone into giving you something you want.  I hope our government is considering more proactive measures than this “Do Not Call” registry, as obviously all the complaints against this number have done nothing to punish those making the calls.

-Nate

Nathan McFeters

Nathan McFeters is a Senior Security Advisor for Ernst & Young's Advanced Security Center in Chicago. The views and opinions expressed in this article are his own and do not represent the views and opinions of Ernst & Young Advanced Security Center or Ernst & Young, LLP. Nathan has performed web application, deep source code, Internet, Intranet, wireless, dial-up, and social engineering engagements for numerous clients in the Fortune 500 during his career at Ernst & Young and has spoken at a number of prestigious conferences, including Black Hat, DEFCON, ToorCon, and Hack in the Box. He can be found at his Pwn* blog and XS-Sniper, a blog with Billy Rios. See his full profile and disclosure of his industry affiliations.

  • Talkback
  • Most Recent of 85 Talkback(s)
RE: Scam calls... something we've forgot about?
How about some Common Sense? DO NOT give personal data to anyone you did not contact First. (i.e) Credit Card Co.,Utilities,Gov. Agencies,ETC... (Read the rest)
Posted by: roscoedelong@... Posted on: 06/15/08 You are currently: a Guest | | Terms of Use
Keeping Telemarketers At Bay with Asterisk  D. T. Schmitz | 05/27/08
What about Obelisx?  DigitalPenGuy | 05/27/08
Folks, you'll have to go read up on Asterix to get anything from that  D. T. Schmitz | 05/27/08
Asterix  mike.sherman@... | 05/28/08
NOT RELEVANT  NGENeer | 05/28/08
Not even close to being relevant  D. T. Schmitz | 05/28/08
Are you kidding!?  zdnet@... | 05/28/08
Asterix and Obelix  NGENeer | 05/28/08
RE: Scam calls... something we've forgot about?  lmenningen | 05/27/08
Pretty sure they can...  nmcfeters | 05/27/08
They can and they should but they won't...  ja4509 | 05/28/08
and that's the sad truth...  Four-Eyes | 05/28/08
Correct  nmcfeters | 05/29/08
People don't care  rpmyers1 | 05/27/08
People do care...  nmcfeters | 05/27/08
Bad process  rpmyers1 | 05/27/08
I hate to support s***ybank but,  bernalillo | 05/28/08
Agreed  nmcfeters | 05/28/08
re-read the post  library assistant | 05/28/08
I reread it.  bernalillo | 05/28/08
I don't see that  nmcfeters | 05/28/08
Easy for scammers  damon_76@... | 05/28/08
Yeah, so that is def. a problem  nmcfeters | 05/29/08
Back to basics folks  bernalillo | 05/29/08
Thing is...  nmcfeters | 05/29/08
Agreed,  bernalillo | 05/30/08
Care?  darkmoonman | 05/28/08
Bankcard Calls  Ganon08 | 05/28/08
Yep, agreed  nmcfeters | 05/29/08
RE: Scam calls... something we've forgot about?  hubarlow | 05/27/08
RE: Scam calls... something we've forgot about?  walkerjian@... | 05/27/08
Scam calls... to disabled/aged/young/poor/retired people  PhilippeV | 05/28/08
Yep  nmcfeters | 05/28/08
RE: Scam calls... something we've forgot about?  kadaro | 05/28/08
Caller ID  NGENeer | 05/28/08
Actually, where they messed up -  library assistant | 05/28/08
Breaking up Ma Bell -  NGENeer | 05/28/08
Merger...ha!  kadaro | 05/28/08
Everyone should read "Caller ID" first!  bellboy | 05/29/08
RE: Scam calls... something we've forgot about?  adr5@... | 05/28/08
It isn't  library assistant | 05/28/08
RE: Scam calls... something we've forgot about?  serenitylodge@... | 05/28/08
Death Penalty!  jlgalloway | 05/28/08
I dunno - how about this?  library assistant | 05/28/08
That wouldn't solve anything  Crash2100 | 05/28/08
Combined Approach  nmcfeters | 05/29/08
RE: Scam calls... something we've forgot about?  jaykmiller@... | 05/28/08
RE: Scam calls... something we've forgot about?  algeo37 | 05/28/08
What I do  library assistant | 05/28/08
RE: Scam calls... something we've forgot about?  KingmanRoss | 05/28/08
try *57 Call Trace  jaybyrd | 05/28/08
RE: Scam calls... something we've forgot about?  drhowell2008@... | 05/28/08
Send in the Marines  jgwinner | 05/28/08
Goverment must do nothing but bank institution.  magallanes | 05/28/08
RE: Scam calls... something we've forgot about?  davidc@... | 05/28/08
RE: Do not call registry expiring  NGENeer | 05/28/08
Do Not Call List Irrelevant  archetuthus | 05/28/08
Tracing scam calls  NGENeer | 05/28/08
RE: Scam calls... something we've forgot about?  fkarkota@... | 05/28/08
Google Map  opnhonest | 05/28/08
Nice work, will update  nmcfeters | 05/28/08
RE: Scam calls... something we've forgot about?  narbytrout@... | 05/28/08
RE: Scam calls... something we've forgot about?  narbytrout@... | 05/28/08
Public execution  rickroberts_mcse@... | 05/28/08
RE: Public Execution  bfilipiak@... | 05/28/08
RE: Scam calls... something we've forgot about?  don.boykin@... | 05/28/08
Your'e right....  qtrback | 05/28/08
RE: Scam calls... something we've forgot about?  frj111@... | 05/28/08
Television and radio PSAs!!  archetuthus | 05/28/08
RE: Scam calls... something we've forgot about?  bevaa72@... | 05/28/08
RE: Scam calls... something we've forgot about?  bevaa72@... | 05/28/08
RE: Scam calls... something we've forgot about?  bevaa72@... | 05/28/08
RE: Scam calls... something we've forgot about?  jhussher@... | 05/28/08
Foney Toner  Doug Buck | 05/28/08
RE: Scam calls... something we've forgot about?  n9joy@... | 05/28/08
RE: Scam calls... something we've forgot about?  bill757@... | 05/28/08
RE: Scam calls... something we've forgot about?  bill757@... | 05/28/08
Uwe Boll Laws  FateJHedgehog@... | 05/29/08
RE: Scam calls... something we've forgot about?  bill757@... | 05/28/08
RE: Scam calls... something we've forgot about?  ohpleaseagain@... | 05/28/08
RE: Scam calls... something we've forgot about?  fcorless@... | 05/28/08
RE: Scam calls... something we've forgot about?  fcorless@... | 05/28/08
RE: Scam calls... something we've forgot about?  frits@... | 05/29/08
Very weird  John Musbach | 06/01/08
RE: Scam calls... something we've forgot about?  roscoedelong@... | 06/15/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

  • Thought-provoking progressive ideas on diverse topics that intersect with technology, business, and life, and matter to the world at large. Visit SmartPlanet
  • More from IBM
  • Innovate your business' process model, play against the market, compete against others on our scoreboards and WIN! Try INNOV8 2.0: A BPM Simulator
  • Enabling Real-World Business Transformation through IBM Service Management Read the EMA Analyst Report
Click Here