Showing posts with label Spamming. Show all posts
Showing posts with label Spamming. Show all posts

Sunday, September 10, 2017

Facebook Engagement-For-Hire Economy Has Generated More Than 100 Million Fake Likes

After Facebook CEO Mark Zuckerberg earlier this week confirmed allegations that the company had sold at least $100,000 of ads to a Russia-backed troll farm – igniting a firestorm of liberal sanctimony as pundits like Rachel Maddow proclaimed that they had finally found the “smoking gun” proving that Russians had swayed the election in President Trump’s favor – researchers at the University of Iowa have pulled back the curtain on the seedy underbelly of Facebook"s illicit influence-peddling economy.


In a study reported by USA Today, the researchers described a thriving ecosystem of websites that allow users to generate millions of fake "likes" and comments. Working with a computer scientist at Facebook and one in Lahore, Pakistan, the team discovered a thriving community of 50 sites offering free, fake "likes" for users" posts in exchange for access to their accounts, which were used to falsely "like" other sites in turn.



The results have been staggeringly effective:





“The scientists found that these “collusion networks” run by spammers have managed to harness the power of one million Facebook accounts, producing as many as 100 million fake "likes" on the systems between 2015 and 2016.”



Why is this a problem? The answer is simple economics. As USA Today explains, Facebook’s algorithm is designed to favor posts that garner a lot of likes, amplifying their visibility and possibly driving legitimate engagement. Many social media “influencers” rely on their followings to justify marketing partnerships with brands and other lucrative deals.


And in what the researchers described as a recent development, the scammers have found a way to “turbocharge” the process by automatically looping in third-party applications like Spotify. Previously, this process had to be done manually in resulted in far fewer likes.


After joining the community, users who are in good standing can essentially generate likes and engagement on demand.





“When you become part of this network, you can say ‘Give me likes on this post and as soon as you request it, you get thousands of likes on a specific post,” said Zubair Shafiq, a professor of computer science at the University of Iowa in Iowa City who documented the automated networks.”



“Users think it’s relatively benign, but actually they’re handing over full control of their Facebook account,” said Shafiq.



“They can also access all the information that’s available on your profile, see your posts, get your friends list, even read your private messages. We can"t tell if this information is being collected and sold to others,” he said.



In another example of the company’s penchant for dissembling, Facebook told USA Today it had stamped out the type of activity described in the research. The company added that it is investigating smaller-volume techniques that could be used for a similar purpose, and said it would take every action necessary to ensure that all activity on its platform, which the company claims has more than 2 billion monthly active users.


But an independent investigation by USA Today promptly confirmed that Facebook’s claim was bulls---.





“However at least some similar techniques still function as USA TODAY was able to join one of the networks and get 50 likes on a post to a newly-created Facebook page within one minute.



The services operate outside of the United States but hide their locations. They also disguise the fact that people who use them are engaged in activity prohibited by Facebook.”



Compounding the ridiculousness of Facebook’s denial, USA Today also found that the sites operate relatively openly.





“The sites operate openly, and researchers found them by entering a Google search for phrases such as "Page Liker." Among the 50 so-called collusion networks listed researchers listed was djliker.com, which described itself as "a social marketing system that will increase likes, comments and increase visits to pages.”




The sites rely on a “freemium” business model, profiting off of ads posted on their sites, but also from subscription fees from power users.





“Their business model is basic: They make their money by posting ads on their sites and also selling "premium" services that allow users to get even more "likes" than they allow their regular users. Some also allow users to create fake comments that can be added to the post of their choice.”



The research will be presented at the Association for Computing Machinery Internet Measurement Conference in London in November. Nektarios Leontiadis, one of the study’s authors, is a threat research scientist at Facebook.
 

Sunday, June 11, 2017

Tracking Hacking: Visualizing The World's Biggest Data Breaches

The graphic below shows a timeline of some of the biggest data breaches on record. As Visual Capitalist"s Chris Matei notes, each bubble represents the number of records lost in any given breach, with the most sensitive data clustered toward the right side.


This data visualization comes to us from Information is Beautiful. Go to their site to see the highly-recommended interactive format that visualizes the same data, while providing additional details on each specific hack.





Before 2009, the majority of data breaches were the fault of human errors like misplaced hard drives and stolen laptops, or the efforts of “inside men” looking to make a profit by selling data to the highest bidder. Since then, the volume of malicious hacking (shown in purple) has exploded relative to other forms of data loss.


FROM MILLIONS TO BILLIONS


Increasingly sophisticated hacking has altered the scale of data loss by orders of magnitude. For example, an “inside job” breach at data broker Court Ventures was once one of the world’s largest single losses of records at 200 million.


However, it was eclipsed in size shortly thereafter by malicious hacks at Yahoo in 2013 and 2014 that compromised over 1.5 billion records, and now larger hacks are increasingly becoming the norm.


SMALL BUT POWERFUL


The problems caused by hacks, leaks and other data breaches are not just ones of scale. For example, the accidental 2016 leak of information from spam/email marketing service River City Media stands out at an alarming 1.37 billion records lost. However, sorting by data sensitivity paints a different picture. The River City leak – represented by the larger blue dot below – is surpassed in severity by hacks at Yahoo, at web design platform Weebly, and even at adult video provider Brazzers.



Much of the data lost in the River City hack was made up of long lists of consumer email addresses to be used for spam email distribution, while the other hacks listed compromised items like account passwords, banking information, addresses, phone numbers, or health records. While having your email address become the target for spam exploitation is a serious annoyance, the hacking of much more sensitive personal data has quickly become the norm.


The fact that more and more of our data is being stored “in the cloud” and among devices on the Internet of Things means that increasingly sensitive types of data are now more vulnerable than ever to being hacked. This looks to be even more cause for concern than the rapidly rising volume of records that have been exposed, whether intentionally or by accident.

Saturday, June 3, 2017

Robocalling is out of control: End the robo call spam fraud virus attacks

(GLOBALINTELHUB.COM) - 6/2/2017 Robocalling is out of control.  Once the domain of sophisticated telemarketers, now it has spread to include cyber fraud, international telemarketing, and some unknown services that just "dial" numbers with no reason (this appears to be the most bizarre).


The spam phone calls have become so out of control, it"s even common now for people to get a landline or other number just to use as their phone number, in that case what"s the point of having a phone?  The issue here needs to be looked into at the network level, by telcos like ATT (T), Verizon (VZ), and others.  How spammers, fraudsters, and barely legal telemarketers (who often cross the lines of "regulation") use the networks to harass legitimate users needs to be stopped.  The "Do Not Call" list is a joke - it"s not enforced and not used.  Registration will stop a small percentage of legitimate telemarketers who use the lists and go through the compliance process, but the problem is that it doesn"t protect anyone from the "black" side of the robocalling industry, which is organized largely outside of the legal borders of USA.


Global Intel Hub interviewed our parent company about this issue, Elite E Services.  EES has many registered domains, for more than 15 years with a Godaddy reseller FX System Hosting (a brand).  Godaddy is now a public company Godaddy Inc (NYSE:GDDY), so they are subject to the same complaints and oversight as any public company.  And Godaddy needs to be careful, as this is a potentially toxic legal issue.


Godaddy sells "privacy" for each domain, making the owner of record "private" - showing only a proxy company operated by Godaddy "Domains by Proxy" - it"s possible to break this veil of privacy only in extreme cases such as a subpoena or matters of national security.  But why would the average domain owner want to keep their records private, especially since the idea of having a website at all is usually for the purposes of marketing (or at least, having your business information become public).  Recently, the answer has been in order to stop the spam calls and emails.  Godaddy makes the whois records public, which are somehow picked up by these foreign robocallers automatically, and the calls start.  They don"t know what is DNC and they don"t speak English.  Half of the time when you actually answer these calls they just disconnect.  Other times, a scratchy connection as one would hear when calling Afghanistan in the 80s from a phone booth, a man speaking broken English is asking if you need website design.  An agent of Elite E Services asked for this man"s name ansector 5d address to which he replied "Sector 5, Calcutta - Justin Smith" - with a little Google research at least Sector 5 really is a real place.  Justin Smith, doesn"t sound like an Indian name though.  When confronted with this fact he says "My fathers" name is Joseph Thomas Smith we are Christian" - maybe, but anyway who is to know?  And why are they calling a number that is on the Do Not Call list?


That"s not all.  Another "foreign" US caller, when asked that we be removed from their list, said "No, no no no.. no - NO .. no no no .. I WILL NOT remove you from my list (click)." at which point the really aggressive calls started, saying that we could be arrested due to an IRS issue, call this number immediately, 202 334 4562 (has been shut down).  "Sometimes we can get 20 or 30 spam calls a day," says an anonymous agent working for Elite E Services, "Sometimes, they will call 2 or 3 times in a row, you can"t block them - they use another number."


Supposedly, Trump"s appointee is doing something about this:



Ajit Pai, the FCC chairman appointed by President Trump, called robocalls a "scourge" in a blog post earlier this month. He noted that an estimated 2.4 billion robocalls are placed to Americans each month.


"There is no reason why any legitimate caller should be spoofing an unassigned or invalid phone number," Pai wrote. "It"s just a way for scammers to evade the law."


The FCC currently prevents phone companies from proactively blocking calls. The new rule would let phone companies block any robocaller that uses a number that has not been assigned to any customer or that has a nonexistent area code.


The FCC"s approach was developed in partnership with a "robocall strike force" of tech, cable and telecom companies formed last year. Members include Apple (AAPLTech30), Google(GOOGLTech30), Microsoft (MSFTTech30), Verizon (VZTech30) and AT&T (TTech30).


The rules probably won"t be finalized and approved for at least a few months.



Meanwhile, the calls continue.  And since most of the callers are hiding behind the international wall of stupidity erected around the USA"s legal system, there"s little US phone users can do except turn off their phones.


This is a bad sign for the telecom sector and for Godaddy, at a time when the "telephone" struggles for its place in a busy digital world.  


If you would like a free consultation from a consumer rights law firm, visit Fortis Law Group @ www.fortisconsumerlaw.com


For all your online shopping needs, bookmark www.pleaseorderit.com YOUR STOP for Amazon orders with great savings and special offers!

Saturday, April 8, 2017

For Sale On The Dark Web: Your Tax Refund And Social Security Number

After death, and taxes, we can now add a third "certainty" to life - identity theft.


Amid the business of tax season, it"s not just accountants that are toiling hard to collect their fees. As Bloomberg reports, tax season is hog heaven for cybercriminals. The thought of all that personal data just sitting around, unmolested in tax documents, inspires a torrent of creepy scammer creativity.


The Krebs on Security blog provided a glimpse earlier this year of how our tax data is bought and sold, and what scammers charge other scammers for our data.


Founder Brian Krebs came across something he hadn’t seen before on the Dark Web: Bulk sales of W-2 forms.



A scammer had phished a tax preparation firm, Krebs discovered, and was offering for sale 3,600 Florida W-2s in this cyber netherworld which, while connected to the everyday web, requires special software or authorization to access.


Bloomberg notes that the fruits of all the successful phishing attempts wind up on the Dark Web.


These offers can look run of the mill, complete with star ratings for sellers. Here is a screenshot showing sellers and their illegal wares, such as W-2s, taken from IBM’s report:



The Dark Web has its own selling language. “Fullz” means complete information on an individual, including, according to the IBM report, “payment card information, address and contact details, and other additional pieces of personally identifiable information, such as Social Security number, a driver’s license number, and any other information sold along with the set.”




An individual’s tax data is far more valuable than their credit card data. Stolen credit card data might sell for $1 or be given away to establish credibility on the Dark Web, said Limor Kessem, executive security adviser of IBM Security. Credit card accounts can be closed or frozen, and thus have a short criminal-shelf life.





“Tax filing information is probably the most premium type of record criminals can buy on the underground,” said Kessem, who has been tracking this world for eight years.



“It goes for $40 or $50, and unlike credit cards, never expires. People can try and get loans in someone’s name, make fake IDs in people’s names, get credit.” And of course, the top target is filing a tax return in someone"s name and getting the refund.



With phishing attacks on the rise, Bloomberg suggests a consumer’s best defense is a good offense. One of the simplest, when it comes to tax refund fraud: File your taxes early to beat would-be scammers to the punch.

Monday, March 13, 2017

Up To 15% Of Twitter Accounts Are Fake, Study Finds

In January, when we exposed that up to 350,000 Twitter accounts could be fake, the social media world started to question its own reality. Now, a study from USC and Indiana University, that Twitter has roughly 48 million active bot accounts. That"s 15% of reported active users that are not human at all...


Earlier this year, a computer scientist in London has stumbled upon massive networks of fake Twitter accounts - with the largest consisting of over 350,000 profiles - which may have been used to "fake" numbers of followers, send spam, and boost interest in trending topics. On Twitter, bots are accounts that are run remotely by someone who automates the messages they send and activities they carry out.


Some people pay to get bots to follow their account or to dilute chatter about controversial subjects.



As The BBC reported, UK researchers accidentally uncovered the lurking networks while probing Twitter to see how people use it.


But now, as CNBC reports, a much bigger big chunk of those "likes," "retweets," and "followers" lighting up your Twitter account may not be coming from human hands.



Researchers at USC used more than one thousand features to identify bot accounts on Twitter, in categories including friends, tweet content and sentiment, and time between tweets. Using that framework, researchers wrote that "our estimates suggest that between 9% and 15% of active Twitter accounts are bots."


Since Twitter currently has 319 million monthly active users, that translates to nearly 48 million bot accounts, using USC"s high-end estimate. The report goes on to say that complex bots could have shown up as humans in their model, "making even the 15% figure a conservative estimate." At 15 percent, the evaluation is far greater than Twitter"s own estimates.


In a filing with the SEC last month, Twitter said that up to 8.5 percent of all active accounts contacted Twitter"s servers "…without any discernable additional user-initiated action."


Since that equates to roughly 20 million more bot accounts than Twitter"s own assessment, that could be an issue in light of analyst concerns about user growth. In a recent research report, Nomura Instinet analysts wrote that "Twitter"s revenue growth has slowed to the mid-single digits, as the platform has struggled to attract new users over the past year…"


The research could be troubling news for Twitter, which has struggled to grow its user base in the face of growing competition from Facebook, Instagram, Snapchat and others. But, of course, Twitter itself tried to spin this as a positive?





A Twitter spokesperson said that while bots often have negative connotations, "many bot accounts are extremely beneficial, like those that automatically alert people of natural disasters…or from customer service points of view."



The real concern, as Axios notes, is whether audience measurement companies should take bots into consideration as part of user traffic numbers, which affect advertising potential, if their behaviors mimic that of real human users.