Data Breaches A National Crisis, Really?

When Investigative Reporter Brian Krebs broke the news that Target Company had experienced a data breach, we at scamFRAUDalert asked the question, how pervasive this was? This was December 24, 2013. Fast forward nine months (9) later, we’ve now learned of JP Morgan Chase and there have been other breaches at Home Depot, Michael’s Stores, Signature Systems, Jimmy Johns, The Goodwill Stores, P.F. Chang’s, Neiman Marcus, SuperValu, and the list goes on and on of breaches unreported nationally. As of October 7, 2014, there have been 589 data breaches recorded by the Identity Theft Recourse Center (ITRC) as compare to 467 breaches in all of 2013.

Based on our experienced of monitoring cybercrimes, this is the new gold mine for these thugs. They seems to gravitate to where the action is.

Government agencies and companies worldwide should take an offensive approach to data security breaches. They should go after these thugs forcefully with the zest of a warrior rather then playing defense. They should follow Mircosoft lead. The internet touches our every day life and is a precious medium of communication to have it infested with just a  few criminals.  The consequences of not playing offense in the fight against cybercrime can be catastrophic. It simply going to get worse.

Our private information are at risk. These records are being SOLD all over the internet making them accessible to creeps, slimes, parasites, psychopaths, and cyber criminals.

In our opinion, this is not a national crisis, this is an imminent threat to our way of LIFE. We should not be going after these thugs after the fact. By then, it’s perhap too late.

Tell Us What You Think

Related:

Advertisements

WhoIs www.autosweblog.com

Address lookupscamalert4
canonical name autosweblog.com

aliases http://www.autosweblog.com
addresses: 162.243.30.135
Domain Whois record

Queried whois.internic.net with “dom autosweblog.com

Domain Name: AUTOSWEBLOG.COM
Registrar: MELBOURNE IT, LTD. D/B/A INTERNET NAMES WORLDWIDE
Whois Server: whois.melbourneit.com
Referral URL: http://www.melbourneit.com
Name Server: NS1.DIGITALOCEAN.COM
Name Server: NS2.DIGITALOCEAN.COM
Name Server: NS3.DIGITALOCEAN.COM
Status: ok
Updated Date: 06-jun-2014
Creation Date: 31-oct-2012
Expiration Date: 31-oct-2014

Last update of whois database: Sat, 06 Sep 2014 20:25:05 UTC
Queried whois.melbourneit.com with “autosweblog.com”…

Domain Name: autosweblog.com
Registry Domain ID: 1756124948_DOMAIN_COM-VRSN
Registrar WHOIS Server: whois.melbourneit.com
Registrar URL: http://www.melbourneit.com.au
Updated Date: 2014-06-07T03:22:24Z
Creation Date: 2012-10-31T18:01:05Z
Registrar Registration Expiration Date: 2014-10-31T18:01:05Z
Registrar: Melbourne IT Ltd
Registrar IANA ID: 13
Registrar Abuse Contact Email: abuse@melbourneit.com.au
Registrar Abuse Contact Phone: +61.386242300
Domain Status: ok

Registry Registrant ID:
Registrant Name: Fadli Idris
Registrant Organization: autosweblog
Registrant Street: Jl. Sultan Salahuddin No,32 Bitai Jaya Baru
Registrant City: Banda Aceh
Registrant State/Province: NAD
Registrant Postal Code: 23235
Registrant Country: ID
Registrant Phone: +1.6208126970717
Registrant Email: buzekhosting@yahoo.com

Registry Admin ID:
Admin Name: Fadli Idris
Admin Organization: autosweblog
Admin Street: Jl. Sultan Salahuddin No,32 Bitai Jaya Baru
Admin City: Banda Aceh
Admin State/Province: NAD
Admin Postal Code: 23235
Admin Country: ID
Admin Phone: +1.6208126970717
Admin Email: buzekhosting@yahoo.com

Registry Tech ID:
Tech Name: YahooDomains TechContact
Tech Organization: Yahoo! Inc
Tech Street: 701 First Ave.
Tech City: Sunnyvale
Tech State/Province: CA
Tech Postal Code: 94089
Tech Country: US
Tech Phone: +1.4089162124
Tech Email: domain.tech@yahoo-inc.com

Name Server: NS3.DIGITALOCEAN.COM
Name Server: NS1.DIGITALOCEAN.COM
Name Server: NS2.DIGITALOCEAN.COM
DNSSEC: unsigned
URL of the ICANN WHOIS Data Problem Reporting System: http://wdrprs.internic.net

Last update of WHOIS database: 2014-09-06T20:12:28Z
Network Whois record

Queried whois.arin.net with “n 162.243.30.135″…

NetRange: 162.243.0.0 – 162.243.255.255
CIDR: 162.243.0.0/16
OriginAS: AS14061, AS62567, AS46652
NetName: DIGITALOCEAN-7
NetHandle: NET-162-243-0-0-1
Parent: NET-162-0-0-0-0
NetType: Direct Allocation
Comment: http://www.digitalocean.com
Comment: Simple Cloud Hosting
RegDate: 2013-09-06
Updated: 2013-09-06
Ref: http://whois.arin.net/rest/net/NET-162-243-0-0-1

OrgName: Digital Ocean, Inc.
OrgId: DO-13
Address: 101 Ave of the Americas
Address: 10th Floor
City: New York
StateProv: NY
PostalCode: 10013
Country: US
RegDate: 2012-05-14
Updated: 2014-09-03
Comment: http://www.digitalocean.com
Comment: Simple Cloud Hosting
Ref: http://whois.arin.net/rest/org/DO-13

OrgNOCHandle: NOC32014-ARIN
OrgNOCName: Network Operations Center
OrgNOCPhone: +1-347-875-6044
OrgNOCEmail: noc@digitalocean.com
OrgNOCRef: http://whois.arin.net/rest/poc/NOC32014-ARIN

OrgTechHandle: URETS-ARIN
OrgTechName: Uretsky, Ben
OrgTechPhone: +1-646-397-8051
OrgTechEmail: abuse@digitalocean.com
OrgTechRef: http://whois.arin.net/rest/poc/URETS-ARIN

OrgAbuseHandle: URETS-ARIN
OrgAbuseName: Uretsky, Ben
OrgAbusePhone: +1-646-397-8051
OrgAbuseEmail: abuse@digitalocean.com
OrgAbuseRef: http://whois.arin.net/rest/poc/URETS-ARIN
DNS records

name class type data time to live
http://www.autosweblog.com IN CNAME autosweblog.com 1800s (00:30:00)
autosweblog.com IN SOA
server: ns1.digitalocean.com
email: hostmaster@autosweblog.com
serial: 1400433387
refresh: 3600
retry: 900
expire: 1209600
minimum ttl: 1800
1800s (00:30:00)
autosweblog.com IN NS ns2.digitalocean.com 1800s (00:30:00)
autosweblog.com IN NS ns1.digitalocean.com 1800s (00:30:00)
autosweblog.com IN NS ns3.digitalocean.com 1800s (00:30:00)
autosweblog.com IN A 162.243.30.135 1800s (00:30:00)
135.30.243.162.in-addr.arpa IN PTR autosweblog.com 86400s (1.00:00:00)
30.243.162.in-addr.arpa IN SOA
server: ns1.digitalocean.com
email: root@ns1.digitalocean.com
serial: 43
refresh: 10800
retry: 900
expire: 604800
minimum ttl: 86400
86400s (1.00:00:00)
30.243.162.in-addr.arpa IN NS ns2.digitalocean.com 86400s (1.00:00:00)
30.243.162.in-addr.arpa IN NS ns3.digitalocean.com 86400s (1.00:00:00)
30.243.162.in-addr.arpa IN NS ns1.digitalocean.com 86400s (1.00:00:00)
— end —

WhoIs ~ ns1.oknoorap.com (24)

name server: ns2.oknoorap.com

Displaying items 1 to 8, out of a total of 8

http://docsnap.net/
http://greenbumi.com/
http://mrvenom.com/
http://unimeme.com/
http://www.docsnap.net/
http://www.greenbumi.com/
http://www.mrvenom.com/
http://www.unimeme.com/

Address lookup
canonical name unimeme.com.
aliases
addresses:54.209.129.218
Domain Whois record

Queried whois.internic.net with “dom unimeme.com

Domain Name: UNIMEME.COM
Registrar: NAMEBREW LLC
Whois Server: whois.namebrew.com
Referral URL: http://www.namebrew.com

Name Server: NS1.PAGEJUNCTION.COM
Name Server: NS2.PAGEJUNCTION.COM

Status: clientTransferProhibited

Updated Date: 02-sep-2013
Creation Date: 01-sep-2013
Expiration Date: 01-sep-2014

Last update of whois database: Sat, 31 May 2014 10:15:47 UTC
Queried whois.namebrew.com with “unimeme.com

Domain Name: UniMeme.com
Registry Domain ID: 1824872504_DOMAIN_COM-VRSN
Registrar WHOIS server: whois.NameBright.com
Registrar URL: http://www.NameBright.com
Updated Date: 2013-09-02T00:00:00.000Z
Creation Date: 2013-09-01T00:00:00.000Z
Registrar Registration Expiration Date: 2014-09-01T00:00:00.000Z
Registrar: NameBrew LLC
Registrar IANA ID: 1580

Registrar Abuse Contact Email: abuse@NameBright.com
Registrar Abuse Contact Phone: +1.303.893.0547
Domain Status: clientTransferProhibited

Registry Registrant ID:
Registrant Name: Name Admin
Registrant Organization:
Registrant Street: 2635 Walnut Street
Registrant City: Denver
Registrant State/Province: CO
Registrant Postal Code: 80205
Registrant Country: US
Registrant Phone: 3038930552
Registrant Email: support@PageJunction.com

Registry Admin ID:
Admin Name: Name Admin
Admin Organization:
Admin Street: 2635 Walnut Street
Admin City: Denver
Admin State/Province: CO
Admin Postal Code: 80205
Admin Country: US
Admin Phone: 3038930552
Admin Email: support@PageJunction.com

Registry Tech ID:
Tech Name: Name Admin
Tech Organization:
Tech Street: 2635 Walnut Street
Tech City: Denver
Tech State/Province: CO
Tech Postal Code: 80205
Tech Country: US
Tech Phone: 303-893-0552
Tech Email: support@PageJunction.com

Name Server: ns1.pagejunction.com
Name Server: ns2.pagejunction.com
DNSSEC: unsigned
URL of the ICANN WHOIS Data Problem Reporting System:
http://wdprs.internic.net
— Last update of WHOIS database: 2014-05-31T10:15:55.228Z —

Network Whois record

Queried whois.arin.net with “n ! NET-54-208-0-0-2″…

NetRange: 54.208.0.0 – 54.209.255.255
CIDR: 54.208.0.0/15
OriginAS: AS16509
NetName: AMAZO-ZIAD4
NetHandle: NET-54-208-0-0-2
Parent: NET-54-208-0-0-1
NetType: Reallocated
RegDate: 2013-03-19
Updated: 2013-03-19
Ref: http://whois.arin.net/rest/net/NET-54-208-0-0-2

OrgName: Amazon.com, Inc.
OrgId: AMAZO-4
Address: Amazon Web Services, Elastic Compute Cloud, EC2
Address: 1200 12th Avenue South
City: Seattle
StateProv: WA
PostalCode: 98144
Country: US
RegDate: 2005-09-29
Updated: 2009-06-02
Comment: For details of this service please see
Comment: http://ec2.amazonaws.com/
Ref: http://whois.arin.net/rest/org/AMAZO-4

OrgTechHandle: ANO24-ARIN
OrgTechName: Amazon EC2 Network Operations
OrgTechPhone: +1-206-266-4064
OrgTechEmail: aes-noc@amazon.com
OrgTechRef: http://whois.arin.net/rest/poc/ANO24-ARIN

OrgAbuseHandle: AEA8-ARIN
OrgAbuseName: Amazon EC2 Abuse
OrgAbusePhone: +1-206-266-4064
OrgAbuseEmail: ec2-abuse@amazon.com
OrgAbuseRef: http://whois.arin.net/rest/poc/AEA8-ARIN

DNS records
name class type data time to live
unimeme.com IN NS ns2.namebrightdns.com 10800s (03:00:00)
unimeme.com IN NS ns1.namebrightdns.com 10800s (03:00:00)
218.129.209.54.in-addr.arpa IN PTR ec2-54-209-129-218.compute-1.amazonaws.com 300s (00:05:00)
129.209.54.in-addr.arpa IN NS x2.amazonaws.com 3600s (01:00:00)
129.209.54.in-addr.arpa IN NS x1.amazonaws.com 3600s (01:00:00)
129.209.54.in-addr.arpa IN SOA
server: dns-external-master.amazon.com
email: root@amazon.com
serial: 5
refresh: 3600
retry: 900
expire: 604800
minimum ttl: 900
900s (00:15:00)
129.209.54.in-addr.arpa IN NS x4.amazonaws.org 3600s (01:00:00)
129.209.54.in-addr.arpa IN NS pdns1.ultradns.net 3600s (01:00:00)
129.209.54.in-addr.arpa IN NS x3.amazonaws.org 3600s (01:00:00)

— end —

Add Adriana on Facebook

Name: Adrianascamalert2
Single: YES
Sexuality: Straight
Age: 26
Body Type: Natural
Status: Single
YAHOO MESSENGER: beach2205babe

This user has seen your profile and is interested in getting to know you better, please Addd her on Yahoo Messenger to Chat OR Visit Her Website.

Thank You
Your local dating site.

Unsubscribe: send email to usa_removal_2104@yahoo.com

MoneyMule ~ Extreme-groupinc.com

Excellent series of articles Brian.

Though careerbuilder.com does have alerts about these money mule jobs: http://www.careerbuilder.com/JobSeeker/Info/Fraud.aspx I do not believe that they are taking sufficient action to combat this epidemic. In my opinion, careerbuilder does not adequately vet employer applicant accounts. These criminals gain easy access to massive databases of resumes for targeting potential money mules. This activity has been going on for a long time.

For example, this same criminal operation that is listed here, was the subject of a report by a money mule on ripoffreport.com back in February 2009. That mule report lists how they recived a transfer of $9,300 taken from a company in TN., L S Starrett. The mule was then instructed to withdraw the cash and send it via Western Union to 3 recipients. Two in Chisinau, Moldova, and a third in Moscow, Russia.
http://www.ripoffreport.com/Miscellaneous-Companies/MMT-GROUP-INC/mmt-group-inc-scammers-pleas-479d3.htm

Besides Scope Group Inc aka scope-group.cn, these criminals have dozens of active fake recruiting websites.

An audit of a few of their active IP addresses shows the following fraud domains:

IP: 222.35.137.234

01. Cosco-groupli.com
02. Extreme-groupinc.com
03. Holding-groupmain.cn
04. Lime-groupnet.cn
05. Massive-groupsvc.cc
06. Premier-groupinc.com
07. Vision-groupsvc.com
08. Alliancegroupmain.cn
09. Entrust-group.cc
10. Entrust-groupsvc.cn
11. Vector-groupfine.cn

IP: 222.35.137.235

01. Extreme-groupco.cn
02. Invalda-groupli.com
03. Massive-groupsvc.cn
04. Melson-groupli.cn
05. Prime-groupco.com
06. Trans-groupinc.com
07. Cdi-groupmain.cn
08. Totalgroupinc.cn

IP: 222.35.137.236

01. Cosco-groupli.cn
02. Cosco-groupmain.com
03. Extreme-groupinc.cn
04. Massive-groupsvc.com
05. Regency-groupco.com
06. Rengo-groupli.com
07. United-groupnet.com
08. Alliance-group.cc
09. Alliance-groupmain.cn
10. Entrustgroup.cn
11. Scope-group.cn
12. Total-groupco.cn

IP:222.35.137.237

01. Affina-groupnet.com
02. Annuity-groupnet.cc
03. Holding-group.cn
04. Invalda-groupmain.com
05. Lime-groupnet.cc
06. Lime-groupsvc.com
07. Massivegroupsvc.cn
08. Puritan-groupinc.com
09. Redeye-groupco.com
10. Rengo-groupmain.com
11. Mena-groupsvc.com
12. Stock-groupmain.cc

IP: 222.35.137.238

01. Annuity-groupllc.com
02. Archway-groupinc.com
03. Integrity-groupsvc.com
04. Melson-groupli.com
05. Melson-groupmain.com
06. Saturn-groupsvc.com
07. Trans-groupmain.com
08. United-groupnet.cn
09. Alliance-groupmain.cc
10. Scope-groupmain.cn

Anyone recruited from resumes on file with careerbuilder.com by any of these entities, should be aware that they are recruiting money mules.

Source: SecurityFix – WashingtonPost

ieeecincinnati.org/buy-viagra-sale~hijacked

Drug Enforcement Agency

United States of America

The Ryan Haight Act Known as
Online Pharmacy Consumer Protection Act of 2008
Sec. 2. Requirement of a valid prescription for
controlled substances dispensed by means of the Internet.

Who's Behind These Online Pharmacies 

SUMMARY: The Ryan Haight Online Pharmacy Consumer Protection Act,
which was enacted on October 15, 2008,amended the Controlled Substances Act and Controlled Substances Import and Export Act by adding several new provisions to prevent the illegal distribution and dispensing of controlled substances by means of the Internet.
_________________________________

compromised ~ ieeecincinnati.org/buy-viagra-sale/ ~ hijacked ~ cyber-criminals
ieeecincinnati
(760) 284-3222
1-760-284-3222
44-203286-3820
  1. designinteractive.net/buy-viagra-sale/
  2. ieeecincinnati.org/buy-viagra-sale/
  3. brand-viagrasale-cp.com/
  4. oblatos.com/viagra
  5. http://www.schillingdouglas.com/serotonin-viagra-sale/‎
  6. ecoluffa.uz/viagra
  7. thesewingsourceinc.com/viagra
  8. azienda-casalino.com/viagra
  9. jakobskirken.dk/viagra
  10. http://www.henryetta.org/‎
  11. selvedge-game.com/viagra
  12. auracentermexico.com/viagra
  13. actupinsask.org/viagra
  14. oblatos.com/viagra
  15. actupinsask.org/viagra
  16. infiltration.org/techniques-drains.html‎
  17. snoislefoods.coop/viagra-sale-usa/‎
  18. schillingdouglas.com/buy-viagra-sale
  19. ptxgaming.com/viagra
  20. laryngologiabialystok.pl/viagra
  21. cateringbonillo.com/viagra
  22. http://www.bdsra.org/viagra-sale-prices
  23. bluerivermedia.ca/viagra
  24. archive.org/viagra
  25. http://www.edscantina.com/generica-viagra-sale‎
  26. dynamiteatv.net/gig/viagra-sale.html‎
  27. infiltration.org/techniques-drains.html
  28. eteglobal.com/viagra
  29. expgames.net/viagra
  30. chattanoogatent.com/online-sale-viagra/‎
  31. laryngologiabialystok.pl/viagra
  32. actupinsask.org/viagra
  33. h-engineering.net/estrogens
  34. eteglobal.com/viagra
  35. expgames.net/viagra
  36. laryngologiabialystok.pl/viagra
  37. actupinsask.org/viagra
  38. h-engineering.net/viagra
  39. squadcarsmotorgroup.co.za/viagra cheapest
  40. panoptikum-dance-club.com/viagra
  41. dl3-re.com/sidenafil
  42. eternalpvp.net/sildenafil
  43. tac-club.org/generic online uk buy viagra
  44. thesewingsourceinc.com/Buy Sildenafil Doctor Consult Online
  45. hsvmuseum.org/Real Viagra Online Order Cheap
  46. cross-culture.net/where to buy viagra online cheap
  47. wustl.edu/Cheap sildenafil citrate uk
  48. laryngologiabialystok.pl/cheap glyset buy online cheapest
  49. cmhl.ca/1# order viagra online usa!! viagra online japan
  50. laryngologiabialystok.pl/buy clomid 100mg cheap
  51. onlinehairysquid.com/Herbal Viagra FedEx NO PRESCRIPTION
  52. ojaifilmfestival.com/Order Viagra Online fast – Online buy Viagra
  53. ernestodogbaministries.org/can you buy viagra over the counter approved sildenafi
  54. laryngologiabialystok.pl/viagra Soft Pills Generic Online
  55. ojaifilmfestival.com/Order Viagra Online
  56. radio-mimy.net/Kunena :: Topic: Buy Sildenafil Cod Us Consul
  57. laportenormande.com/Prochaine assemblée générale
  58. madisonmft.com/Buy Viagra Online Cheap – Madison
  59. onepiece.ru/Просмотр темы – Buying Kamagra® Soft . Cheapest Sildenafil
  60. adsmallorca.com/buy viagra plus hong kong
  61. buyneocash.com/Sildenafil No Prescription
  62. marketingpublictransport.eu/Buy Online No Prescription
  63. arkitente.org/Buy Online No Prescription
  64. satrancdunyam.com/Buy Viagra Capsules or Order Wholesale Sildenafil Citrate
  65. sabzibazaar.com/Buy Terramycin cheap and easy
  66. fencing.net/Where To Buy Silagra With No Prescription
  67. desertregionalicon.com/Buy Viagra Cheap
  68. eydon.com/Brand Viagra – Buy Viagra online
  69. salvadorancoffees.com/where can i buy viagra super active ~> viagra
    phsar247.com/Buy Sildenafil Tabs
  70. mccallshorseworld.com/1# viagra super active pharmacy prices
  71. holyfamilythanet.org/Pfizer viagra online cheap
  72. d4kin.ca/viagracan you buy viagra sublingual in ireland cheap
  73. fencing.net/Sildenafil Purchase Usa. Where To Buy Sildenafil
  74. avvocatisenzafrontiere.it/buy viagra online
  75. theislamicforums.com/Get Now Sildenafil-duloxetine
  76. thefitnesscenter.ca
  77. tuxerklamm.at
  78. squadcarsmotorgroup.co.za
  79. shoreacres.net/sale-viagra‎
  80. snoislefoods.coop/viagra-sale-usa
  81. edwardcolver.com/buy-viagra-sale/‎
  82. brand-viagrasale-cp.com
  83. henryetta.org/
  84. ieeecincinnati.org/buy-viagra-sale/‎
  85. designinteractive.net/buy-viagra-sale/‎
  86. edexploresrq.com/serotonin-viagra-sale/‎
  87. edexploresrq.com/buy-viagra-sale/‎
  88. vscpr.com/50mg-viagra-sale/‎
  89. paragonandviva.com/serotonin-viagra-sale/‎
  90. mccsmiramar.com/canadian-viagra-50mg/‎
  91. mccsmiramar.com/viagra-for-sale/‎
  92. bretstateham.com/50mg-viagra-sale/‎
  93. joekindkid.com/viagra-sale/‎
  94. ysunews.com › News Briefs‎
  95. 79nm.com/serotonin-viagra-sale/‎
  96. englundscatering.com/buy-viagra-sale
  97. audreyquinnaudio.com/discount-viagra-sale
  98. ralphiemay.com/discount-viagra-sale/‎
  99. ultimate-generic-viagra.com/‎
  100. colliervillelibrary.org/discount-viagra-sale
  101. mediavision-usa.com/discount-viagra-sale-online/
  102. mccsmiramar.com/canadian-viagra-50mg
  103. vscpr.com/50mg-viagra-sale
  104. paragonandviva.com/serotonin-viagra-sale/
  105. ysunews.com/viagra
  106. bretstateham.com/50mg-viagra-sale/‎
  107. joekindkid.com/viagra-sale/‎
  108. sciencecomedian.com/viagra-sales
  109. ceas2013.org/serotonin-viagra-sale/
  110. springsblog.com/buy-viagra-sale/
  111. ts4arts.org/sales/
  112. lvsf.org/viagra-sale-prices
  113. wildwildweather.com/radar.htm
  114. animationnation.com/viagra-sale-buy‎
  115. asianresources.org/viagra-for-sale
  116. spacedogmusic.com/50mg-viagra-sale
  117. clinkevents.com/viagra-sale
  118. http://www.stackhousesaddles.com/?stc=466
  119. http://www.sunsetmarquis.com/how-much-is-viagra/‎
  120. andyduffy.com/viagra-sale-peru/‎
  121. blog.elementsprinceton.com/online-sale-viagra
  122. http://www.grassrootspress.net/viagra-for-sale
  123. http://www.502bar.com/overseas-viagra-sale