spacer
 HOME PAGE
Today’s columns, news and more
 BASICS
Build your financial know-how
 INVESTING
Tips and tools for your portfolio
 YOUR FINANCES
Latest rates and money-saving tips
 PLANNING
Put your financial goals into action
 SPENDING
Research home, car and other purchases
 TOOLS
Calculators for financial decisions
 COLUMNS
Advice and commentary from Kiplinger's experts
 COMMUNITY
Ask a question or answer one
 EMAIL UPDATES
Sign Up!
 PUBLICATIONS
Subscribe, renew, buy books and software
 CONTACT US
Customer service, feedback, letters to the editor
 ABOUT US
Company privacy and advertising info
 

BOOST YOUR 401(K)
New online course
from Kiplinger helps
you make the most
of your savings.
See how...

Try a Free IssueKiplinger Store:
Give a Gift Subscription
for Just $10

Your Finances:   YIELDS & RATES   CREDIT & BANKING   TAXES   INSURANCE  
MAGAZINE
 

February

February 2005

bullet Magazine
bullet Contents
bullet Web Links
bullet Past Issues
bullet Try a Free Issue
bullet Customer Service
bullet Feedback

GETTING STARTED
bullet Pocket the Best Plastic
bullet How to Fix a Credit Report Error
bullet How to Adjust Your Withholding
bullet Life Insurance Made Simple
bullet Fill the Holes in Your Homeowners Insurance
bullet More...
TOOLS
bullet Search for the best credit card
bullet Should I pay off debt or invest in savings?
bullet How much life insurance do I need?
bullet 2004 survey of state tax burdens
bullet The true cost of paying the minimum
bullet Research your bank
spacer
WHICH SITE IS PHISHY?
 Think you can spot a phony? Take our phishing quiz and find out. We'll show you two sites side by side. Select the site you think is a fraud. When you're done, we'll point out the subtle tells of phishy Web pages.
  Email this  Print this
License or reprint this article

SCAMS
Can you Smell the Phish?
(Page 2 of 4)

Phishermen

Perpetrators fall into two categories: Think of one group as rod-and-reel hobbyists, and the other as an international fleet of commercial trawlers. The former are far easier for law enforcement to catch.

Alec Scott Papierniak, a 21-year-old student at Minnesota State University, in Mankato, got caught after sending e-mails to thousands of PayPal users, prodding them to "update" account information. His bogus PayPal page captured victims' user names and passwords and e-mailed them to an online account he controlled. Then he hijacked the accounts to make fraudulent purchases or transfer cash to himself. Papierniak is serving an 18-month sentence at the federal prison in Duluth, Minn., and has been ordered to pay $25,000 in restitution.

Francisco Chacin, a 21-year-old from Hialeah, Fla., pleaded guilty last year to phishing for eBay user names and passwords, then setting up fraudulent auctions under those users' identities. The items up for auction didn't exist; Chacin simply collected the winning bidders' money and ran. He's serving 30 months in prison and was ordered to pay more than $33,000 in restitution.

Helen Carr, a 56-year-old woman in Akron, Ohio, lived in her 80-year-old mother's home and told the FBI that she made her living sending pornographic spam from computers located in her basement. Her phishing scheme sent mass e-mails to AOL subscribers, seeking credit-card numbers and other personal information. (Each mailing to thousands of subscribers netted 20 to 50 credit-card numbers.) Carr was caught when one of her e-mails landed in the AOL account of an FBI agent, who was curious enough to track her down. She is currently serving 46 months in Alderson Federal Prison, in West Virginia.

Van T. Dinh, a 20-year-old resident of Phoenixville, Pa., picked a victim's e-mail address from an online stock-charting forum and sent a message inviting him to participate in a "beta test" of a new charting tool. Instead of a program, the investor unwittingly downloaded a key-logging virus that captured his TD Waterhouse log-in name and password. Dinh then wiped out the account's $47,000 balance by buying worthless Cisco options that allowed Dinh to unload a losing position in his own brokerage account. Dinh pleaded guilty and was sentenced to 13 months in prison. He was also ordered to pay restitution and a $3,000 fine.

Don't assume it takes a computer whiz to be a phisher. Most of these small-time identity thieves aren't masterminding their own attacks. In hacker lingo, they're known as "script kiddies," amateurs who download do-it-yourself "phishing kit" software from the Internet and point and click their way to an e-mail fraud. The kits include all the Web code, logos and text needed to build a bogus site, and spamming software to cast a wide net.

"It's the difference between buying a set of lock picks and making your own," says Matthew Parrella, an assistant U.S. attorney in San Jose, Cal., who prosecuted Papierniak and Chacin. Many phishing e-mails look and sound alike because they come from a common source, Parrella says.

 BACK      1  2   3  4        NEXT   

ADVERTISEMENT

  Find This Article Helpful?
  Sign up for email delivery of our columns and site updates.

  There's plenty more where that came from.
  Subscribe to Kiplinger's Personal Finance magazine at a low introductory rate.

  SPONSORED LINKS

Customer Service | Subscribe by phone:  800-544-0155
All contents © 2005 The Kiplinger Washington Editors, Inc.