Man Charged in $11m Crypto Scheme that Featured Steven Seagal

Man Charged in $11m Crypto Scheme that Featured Steven Seagal

A California man has been charged with securities fraud after allegedly tricking cryptocurrency investors out of millions and using actor Steven Seagal to promote a fake company.

John DeMarr, 55, of Santa Ana, was charged in a complaint filed in the Eastern District of New York. He is said to have conspired with others to defraud victims out of $11.4m by persuading them to invest in dud companies.

The complaint alleged that between 2017 and 2018, DeMarr and others made “false and misleading representations” about two companies: Start Options and B2G.

Start Options was promoted as an online investment platform offering cryptocurrency mining, trading and digital asset trading services. B2G was marketed to investors as an ecosystem that would allow users to trade B2G tokens, use digital wallets and trade digital and traditional currencies “on a secure, comprehensive platform.”

Investors were apparently told that their money would be held for a specified contract period, after which they could withdraw major profits.

In fact, the funds were redirected accounts controlled by DeMarr and others, who used the money to fund lavish purchases of luxury sports cars, jewellery and renovations to DeMarr’s Californian home, according to the Department of Justice (DoJ).

To catch the eye of investors, the co-conspirators are said to have invented celebrity endorsements for Start Options, including a professional athlete whose name and image was used without their permission.

When the end of a Start Options contract approached, they allegedly tried to persuade investors to roll over their accounts into an Initial Coin Offering (ICO) for B2G.

Bizarrely, the scammers are reported to have recruited Steven Seagal, referred to in the DoJ release only as “an actor famous for martial arts films made in the 1980s and 1990s,” to promote B2G.

According to the DoJ, the co-conspirators falsely claimed that B2G could generate an 8000% return for investors within one year, and that Segal was a participant in the ICO. The actor is said to have moved on from the project in March 2018.

Incredibly, DeMarr then staged his own disappearance to avoid facing the wrath of angry investors, according to the complaint.

He’s said to have instructed others to release statements claiming that he had been assaulted and is now missing in Montenegro. However, all the while he’s believed to have been in California.

Seagal is reported to have settled with the FTC last year for his role in the ICO.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

FTC: #COVID19 Helped Double Identity Theft in 2020

FTC: #COVID19 Helped Double Identity Theft in 2020

The number of identity theft reports filed with US consumer protection authorities doubled over the past year thanks to the impact of the pandemic.

The Federal Trade Commission (FTC) said in an update yesterday that it received 1.4 million such reports last year, twice the number filed in 2019.

The surge in cases coincided with the country’s slip into recession and soaring unemployment rate as COVID-19 took hold early last year, the FTC claimed.

“After the government expanded unemployment benefits to people left jobless by the pandemic, cyber-criminals filed unemployment claims using other people’s personal information,” it continued.

“In 2020, we had 394,280 reports about government benefits fraud — overwhelmingly about identity theft involving unemployment benefits. Compare that with 12,900 reports in 2019.”

The FTC said it also received many reports from individuals whose personal and business information had been used fraudulently by scammers to receive money from the government’s small business loan programs.

“Last year, we had 99,650 reports of fraud involving business or personal loans, compared with 43,920 reports in 2019,” it added. “Not all of the new reports related to the government relief effort, but they were a big share of the increase.”

In fact, the fallout from this widespread fraud is still ongoing. In January alone, the Department of Justice released details of separate charges against several individuals who it said illegally obtained funds from the Paycheck Protection Program.

However, not all of these used the details of legitimate businesses and individuals in their schemes. Many of those accused are said to have simply made-up information when filing, such as inflating the number of workers their businesses employ.

The FTC also revealed that “tax identity theft” cases swelled significantly last year, up from just 27,000 in 2019 to over 89,000.  These are essentially the same attempts to steal individuals’ federal stimulus payments, but simply reported to the IRS rather than FTC.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

‘ValidCC,’ a Major Payment Card Bazaar and Looter of E-Commerce Sites, Shuttered

ValidCC, a dark web bazaar run by a cybercrime group that for more than six years hacked online merchants and sold stolen payment card data, abruptly closed up shop last week. The proprietors of the popular store said their servers were seized as part of a coordinated law enforcement operation designed to disconnect and confiscate its infrastructure.

ValidCC, circa 2017.

There are dozens of online shops that sell so-called “card not present” (CNP) payment card data stolen from e-commerce stores, but most source the data from other criminals. In contrast, researchers say ValidCC was actively involved in hacking and pillaging hundreds of online merchants — seeding the sites with hidden card-skimming code that siphoned personal and financial information as customers went through the checkout process.

Russian cybersecurity firm Group-IB published a report last year detailing the activities of ValidCC, noting the gang behind the crime shop was responsible for plundering nearly 700 e-commerce sites. Group-IB dubbed the gang “UltraRank,” which it said had additionally compromised at least 13 third-party suppliers whose software components are used by countless online stores across Europe, Asia, North and Latin America.

Group-IB believes UltraRank is responsible for a slew of hacks that other security firms previously attributed to at least three distinct cybercrime groups.

“Over five years….UltraRank changed its infrastructure and malicious code on numerous occasions, as a result of which cybersecurity experts would wrongly attribute its attacks to other threat actors,” Group-IB wrote. “UltraRank combined attacks on single targets with supply chain attacks.”

ValidCC’s front man on multiple forums — a cybercriminal who uses the hacker handle “SPR” — told customers on Jan. 28 that the shop would close for good following what appeared to be a law enforcement takedown of its operations. SPR claims his site lost access to a significant inventory — more than 600,000 unsold stolen payment card accounts.

“As a result, we lost the proxy and destination backup servers,” SPR explained. “Besides, now it’s impossible to open and decrypt the backend. The database is in the hands of the police, but it’s encrypted.”

ValidCC had thousands of users, some of whom held significant balances of bitcoin stored in the shop when it ceased operations. SPR claims the site took in approximately $100,000 worth of virtual currency deposits each day from customers.

Many of those customers took to the various crime forums where the shop has a presence to voice suspicions that the proprietors had simply decided to walk away with their money at a time when Bitcoin was near record-high price levels.

SPR countered that ValidCC couldn’t return balances because it no longer had access to its own ledgers.

“We don’t know anything!,” SPR pleaded. “We don’t know users’ balances, or your account logins or passwords, or the [credit cards] you purchased, or anything else! You are free to think what you want, but our team has never conned or let anyone down since the beginning of our operations! Nobody would abandon a dairy cow and let it die in the field! We did not take this decision lightly!”

Group-IB said ValidCC was one of many cybercrime shops that stored some or all of its operational components at Media Land LLC, a major “bulletproof hosting” provider that supports a vast array of phishing sites, cybercrime forums and malware download servers.

Assuming SPR’s claims are truthful, it could be that law enforcement agencies targeted portions of Media Land’s digital infrastructure in some sort of coordinated action. However, so far there are no signs of any major uproar in the cybercrime underground directed at Yalishanda, the nickname used by the longtime proprietor of Media Land.

ValidCC’s demise comes close on the heels of the shuttering of Joker’s Stash, by some accounts the largest underground shop for selling stolen credit card and identity data. On Dec. 16, 2020, several of Joker’s long-held domains began displaying notices that the sites had been seized by the U.S. Department of Justice and Interpol. Less than a month later, Joker announced he was closing the shop permanently.

And last week, authorities across Europe seized control over dozens of servers used to operate Emotet, a prolific malware strain and cybercrime-as-service operation. While there are no indications that action targeted any criminal groups apart from the Emotet gang, it is often the case that multiple cybercrime groups will share the same dodgy digital infrastructure providers, knowingly or unwittingly.

Gemini Advisory, a New York-based firm that closely monitors cybercriminal stores, said ValidCC’s administrators recently began recruiting stolen card data resellers who previously had sold their wares to Joker’s Stash.

Stas Alforov, Gemini’s director of research and development, said other card shops will quickly move in to capture the customers and suppliers who frequented ValidCC.

“There are still a bunch of other shops out there,” Alforov said. “There’s enough tier one shops out there that sell card-not-present data that haven’t dropped a beat and have even picked up volumes.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Greek Police to Introduce Live Facial Recognition

Greek Police to Introduce Live Facial Recognition

Police in Greece are to be issued new devices that will allow them to carry out real-time facial recognition and fingerprint identification while out on the beat. 

The plan to disseminate the new technology is part of the 4.5 million euro “Smart Policing” project announced in 2017 that aims to identify and verify the identity of citizens when stopped by the police. Most of the project costs (75%) are being covered by the Internal Security Fund (ISF) of the European Commission.

Currently, citizens who are not able to provide identification documents when stopped by the police in Greece have to be transferred to the nearest police station for their identity to be verified. By allowing identification in real time, the new devices will make the identification of citizens more time efficient. 

“Our goal is to verify individuals, vehicles and objects in real time. By doing that we improve police officers’ security, we reduce civilians’ discomfort, and we save human and material resources,” a Greek police official told non-profit research and advocacy organization AlgorithmWatch.

According to AlgorithmWatch, Greek police will initially be issued at least 1,000 devices, with an option to deploy a further 9,000 by this summer if the scheme proves to be effective. 

The devices, which are similar in appearance to smart phones, will be connected to 20 different databases belonging to international and national authorities, including the Greek Ministry of Transport, the Ministry of Foreign Affairs, Europol, the FBI, and Interpol.

Commenting to Infosecurity Magazine on the planned device rollout, Hank Schless, senior manager of security solutions at Lookout, said:  “It’s been noted that these devices will be connected to a handful of government databases. If compromised, one of these devices could serve as a backdoor into the greater database.”

“We see this with threat actors behind mobile phishing campaigns who socially engineer mobile users. Attackers convince victims to share login details or install malware to gain access to the entire infrastructure.”

In March last year, Greek non-profit digital rights advocacy organization, Homo Digitalis, filed a request to the Greek Data Protection Authority (DPA) expressing concern over the legality of the “Smart Policing” project.

Homo Digitalis argued in the request that “there is a strong possibility that the Greek police is violating EU laws regarding the processing of personal data” laid out in the Greek Constitution, national laws linked to the General Data Protection Regulation (GDPR), and the EU Charter of Fundamental Rights.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk