DHS watchdog’s fraud hotline spoofed in ID theft scam

The inspector general’s office in the Department of Homeland Security is warning that identity thieves and fraudsters are spoofing caller ID systems to make it look as if victims are being called from the IG’s anonymous tipline. “The perpetrators of the scam represent themselves as employees with ‘U.S. Immigration,’” the office states in a press release circulated Wednesday, and “demand to obtain or verify personally identifiable information from their victims through various tactics, including by telling individuals that they are the victims of identity theft.” “Many of the scammers reportedly have pronounced accents,” states the press release. The office said it wanted to remind the public that it “never uses its hotline number to make outgoing calls — the phone line is only used to receive information from the public.” The hotline remains “perfectly safe” for reporting “fraud, waste, abuse, or mismanagement within DHS components or programs,” the statement concludes. The office […]

The post DHS watchdog’s fraud hotline spoofed in ID theft scam appeared first on Cyberscoop.

Continue reading DHS watchdog’s fraud hotline spoofed in ID theft scam

How would someone be able to call (or spoof) from a phone number they do not own

I recently got a call from a lady who claimed I called her and demanded her credit card information and that she owed me money. I did not make the call, but I did verify that on her phone my number did appear to make the call… Continue reading How would someone be able to call (or spoof) from a phone number they do not own

Acoustic Attack Against Accelerometers

Interesting acoustic attack against the MEMS accelerometers in devices like FitBits. Millions of accelerometers reside inside smartphones, automobiles, medical devices, anti-theft devices, drones, IoT devices, and many other industrial and consumer applications. Our work investigates how analog acoustic injection attacks can damage the digital integrity of the capacitive MEMS accelerometer. Spoofing such sensors with intentional acoustic interference enables an out-of-spec… Continue reading Acoustic Attack Against Accelerometers

Dealing with a fraudulent email that went to vendors

Recently a business I’m working with had an email that was sent to some vendors of theirs using emails that were remarkably similar to their own emails. The attackers used letter substitution to mimic the business’s domain (e.g. exarnple@dornain.com — notice the use of “r” and “n” to imitate an “m”).

Luckily, the vendors contacted by these people were diligent enough to catch the mismatched email addresses. However, I’m concerned that similar attacks will hit other vendors of our that might not have the same protocols in place.

Aside from contacting every one of vendors, is there anything the business can do on their end to mitigate these attacks? Or are they reliant on vendors being diligent with double-checking their contacts?

Continue reading Dealing with a fraudulent email that went to vendors