FBI indicts 19 for internet related fraud

A federal grand jury in Dallas returned an indictment this week charging 19 individuals with conspiracy to commit wire and mail fraud. 15 of the defendants are charged with email fraud. All in all, these defendants are accused of defrauding various companies, from telcos to web developers, of $15,000,000.

[I]f convicted, the conspiracy charge carries a maximum statutory sentence of 30 years in prison and a $1 million fine. Each of the obstruction charges carries a maximum statutory sentence of 20 years in prison and a $250,00 fine. If a defendant is convicted on a felony and also on false registration of a domain name, the penalty for that felony conviction is doubled, or increased by seven years, whichever is less. Restitution could be ordered.

False registration of a domain name will add up to 7 years onto any sentence. This is probably one reason so many spammers are now hiding behind domains by proxy. That won’t add to their jail time if they end up convicted of a felony.
This description from the FBI press release sounds very familiar:

The conspirators created, purchased and used  shell companies to hide the true identity of the owners or operators of the companies, or the relationships between the companies. They also established P.O. Boxes, commercial remailer services, shell offices, apartments, or other physical locations to hide owners’ or operators’ identity or the relationships between the companies. They assumed multiple fake identities to hide true ownership of the shell companies and made materially false representations to their victims, by mail, fax, telephone, e-mail, or other communications, to obtain goods and services from them.

I know a number of spammers who have a series of shell companies in order to hide the relationships between their various websites. They have one shell that’s used for their advertisers. They have another shell that’s used for their affiliates and they have lots of shell companies and domains that are used in their emails.

Related Posts

A blast from the past

I’m sitting here watching Iron Chef (the real one, not the American version) and surfing around on SFGate.com. It’s a slow night catching up on all the news I’ve missed this week while off traveling. I see a link on the front page: “Web marketer ordered to pay Facebook $711M.” As I click I wonder if I know the web marketer in question. A former client? A name I recognize?

Read More

TWSD: Privacy protection for commercial domains

One of my major pet peeves is supposedly legitimate companies hiding behind privacy protection in their whois records. There is absolutely no reason for a legitimate company to do this. There are lots of reasons a non-legitimate company might want to hide behind privacy services, but I have never heard a good reason for legitimate companies to hide.
Look, a company sending any commercial email is required by law to provide a physical postal address in every email they send. What point is there, then, to hiding addresses in whois records? The only thing it does is make a sender look like a spammer. If a sender is a business, then they need to have a real business address anyway, and that address should be available in their domain registration.
It may seem like a trivial point, it may seem minor, but spammers use domain privacy services to hide the various tendrils of their businesses. They don’t want anyone to be able to tell that domain A is related to domain B is related to domain C. Proxy services let them trivially hide their identities. This is the major business use of privacy protection. Real companies don’t need to hide behind privacy services.
Using domain privacy services make senders look like spammers. One trivial thing that ISPs can do is stop providing FBLs or whitelistings to domains behind privacy services. This will weed out spammers without doing harm to real senders. Certification services can refuse to certify companies that hide their identity. My small contribution to the cause is to refuse to represent any company to an ISP if their domain is behind a privacy service.
Just to be clear, I have no problem with personal, non-business domains using privacy services. There are valid reasons individuals may want to hide their physical location. But businesses? Step up and quit hiding.
On the subject of privacy services, Mickey recently reviewed a court ruling that commented on the legality of using privacy services. The court says:

Read More

Cyber Monday inundation

The cyber monday inundation of mail has hit my mailbox. There’s been a clear increase in marketing mail over the last week. Unfortunately for those marketers, it’s too much and I am just scanning subject lines and marking as read. I don’t have the time to read all this mail.

Read More