Google Search

Showing posts with label Revenge. Show all posts
Showing posts with label Revenge. Show all posts

Friday, June 1, 2012

How internet revenge by an ex-partner can lead to horrific violence

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Evil man. Image from ShutterstockThe headline of the Craigslist "Casual Encounters" ad:

"Do me!!! - m4m - 28 (JP)."

The translation, for those unfamiliar with internet sex dating truncations: a 28-year-old male - a virgin, the ad went on to say - who "want [sic] it hard" was looking for another male, of any race or age, to sodomize him, first come, first served.

The phone started ringing as my boyfriend, John, and I were grocery shopping on a lovely April afternoon. It continued to ring for over a day.

The ad, together with a handful of others offering unrealistic pay for unskilled labor, was taken out in John's name, with his phone number, by an acquaintance with a drinking problem.

The phone calls were unnerving, as was the acquaintance's stubborn denial that he had placed the ads, even after John irrefutably linked him to the cloaked Craigslist email address listed in the ads.

I spent the night researching identity fraud and cyberstalking. We went to the police station to file a report. Although the police hadn't raised a finger, the calls eventually tapered off.

We got off easy. The damage done to our psyches was trifling, compared to the violence that some have suffered at the hands of cyberstalkers who take out ads soliciting sexual encounters - sometimes violent - in their victims' names.

It all came back to me when I saw a recent Forbes article on horrific crimes committed by jilted boyfriends, who now have the internet to use as a tool that enables identity fraud and even harassment via crowd-sourcing.

Forbes article

Forbes details two disturbing cases that have led to prosecution: The first is the case of Shawn Sayer, of Maine, who harassed his ex-girlfriend for years after they split up.

Sayer went so far as to crowd-source his revenge - i.e., he took out fake ads in his ex's name so that unwitting dupes would gang up on her.

Here's a description of how Sayer managed to keep up his retaliation after his ex moved to a new state, from a court order from Judge Brock Hornby:

After Sayer's former girlfriend changed her name and moved from Maine to Louisiana to escape him, the defendant Sayer, still in Maine, created fictitious internet advertisements and social media profiles using [the victim's] name and other identifying information. The fictitious internet postings included [the victim's] address and invited men to come to her home for sexual encounters.

According to Forbes reporter Kashmir Hill, the ads included the victim's photo, directions to her house, and a list of sexual acts she would perform when interested individuals showed up. Sayer also posed as his victim in chats and emails.

The Portland Press Herald reported that the first man who showed up on her doorstep as a result of the fraudulent ad groped her in a dark hallway. Fortunately, she escaped by running to a friend's apartment.

CraigslistHill details the fate of another, less fortunate victim who was violently raped after her ex-boyfriend, a former Marine, posted a rape fantasy ad on Craigslist on her behalf.

That tale has multiple victims, one of whom is a 27-year-old Wyoming man who answered the ad, which solicited "a real aggressive man with no concern for women."

Similarly to Sayer, the spurned ex-boyfriend posed as his victim and corresponded with the Wyoming man, who thought he had the victim's consent when he went to her home and raped her at knifepoint, leaving her bound on her living room floor.

In that case, both the ex and the man he used to carry out his crimes have been sentenced to 60 years in prison.

What makes these crimes particularly frightening is that the typical advice for avoiding identity theft just doesn't cut it when you're dealing with a former lover or friend: i.e., somebody who doesn't have to phish for your personal identifying information.

My guess is that these crimes are under-reported and substantially under-prosecuted, given the response that I received from the local police when my boyfriend and I filed a report on his harassment.

Police car lights. Image from ShutterstockThe officer who took our report didn't think any of the actions against John - taking out an ad in his name, with his phone number, to solicit homosexual acts - sounded illegal. The officer knew nothing of identity fraud or cyberstalking laws.

Nor did he think anything could be done to stop the harassment. He suggested we go to the local court house in the morning.

Perhaps that's how many of these cases unfold: clueless local police pass the buck until the victims give up and walk away, impotent, still vulnerable.

When we do hear about a successful prosecution, it's likely because somewhere along the buck-passing line, somebody knew that there are federal laws against cyberstalking and identity theft, and somebody knew that police departments have computer crime units, as does the FBI.

We can't rely on every police officer in every local police department to know about federal law or the appropriate channels for reporting computer crimes. We need to become fluent enough with the law ourselves to avoid being stonewalled.

To that end, if you ever have need to educate law enforcement regarding what is and isn't legal when you're reporting a cyberstalking or identity theft crime, here are some pertinent US laws and resources. There are many more, so feel free to add them to the comments section:

In choosing to torment his ex-girlfriend, Sayer faced a maximum of 15 years in federal prison. That includes ten years on the cyberstalking charge, five years on the identity theft charge, plus a potential $250,000 fine on each charge, according to a press release from the Maine Assistant US Attorney.

To this day, the man who committed identity fraud on my boyfriend by taking out fraudulent Craigslist ads on his behalf thinks it was all a funny joke.

John and I failed to grasp the humor, but I did come away from the encounter with a few ideas of how victims might be better served:

Craigslist never responded to our requests that the fraudulent ad poster be barred from posting further ads. Nor did the company respond to my questions about what processes are used to protect victims in these situations. If Craigslist is committed to protecting those who are victimized by fraudulent ads, I call on the company to set up a transparent means of reporting abuse that results in rapid remediation. Craigslist promptly takes down bogus ads but has no apparent means to revoke an abuser's posting privileges. Law enforcement at every level, be it local, state or federal, should receive training in handling cyberstalking, identity theft and other computer-related crimes. We don't need every police officer to be familiar with the nuances of every federal law, but we should expect them, at the very least, to be able to inform victims of the existence of computer crime units that are conversant in such matters.

Finally, a word of warning about sharing passwords.

The New York Times in January described a new form of intimacy: Sharing passwords to email accounts, Facebook or other social media networks.

Bad idea. If you want to show somebody you trust them, do something like fall over backwards into their arms.

The worst you can get from that will likely be a bruise and a valuable lesson regarding whom you can and can't trust.

The worst you can get from a malicious ex posing as you online can be orders of magnitude more vicious.

Follow @LisaVaas

Evil man and police car lights images courtesy of Shutterstock.


View the original article here

Thursday, July 7, 2011

Arizona Immigration Law Revenge Seeking Hackers Strike Police for Third Time - Fox News

Arizona authorities have confirmed a third attack against police officers in the state by computer hackers who say they are striking out in part in retaliation against an immigration law that has sparked a national controversy.

The latest hacking was revealed Thursday night after a group calling itself AntiSec issued a news release saying it was defacing eight Arizona Fraternal Order of Police websites, and releasing a master list of more than 1,200 officer's usernames, passwords and e-mail addresses.

This is the second breech of Arizona law enforcement data that the group is claiming in as many days. AntiSec said in an online posting Wednesday that it exposed information including "names, addresses, phone numbers, passwords, social security numbers, online dating account info, voicemails, chat logs, and seductive girlfriend pictures."

And an attack last week by a group calling itself Lulz Security targeted Arizona Department of Public Safety officer's email accounts.

The hackers said the Thursday attack was a strike against Arizona's heavily-scrutinized immigration policy, known as SB1070, which requires police in the course of enforcing other laws to use "reasonable suspicion" as a basis for checking a person's immigration status.

The hackers also say they want a world free from police, prisons and politicians.

The state Fraternal Order of Police said steps are being taken to find those responsible for hacking into their site.

"The FOP is already cooperating fully with every law enforcement body that is currently investigating this," said David Leibowitz, FOP spokesman, in an interview Friday with The Associated Press.

"Obviously we're taking steps internally to make sure the information is protected," Leibowitz said.

Also, the police organization said in a statement that it will not be intimidated by the cyber-attack.

Arizona state law enforcement Capt. Steve Harrison said Friday that some of his Department of Public Safety officers are members of the Fraternal Order of Police, but the latest computer attack was not limited to his agency's employees.

Harrison told the AP that it too early to tell how many Public Safety officers have had their personal information compromised by the data breech.

Agency officials added they are unable to say for certain that AntiSec was actually the group that infiltrated the computer system.

The most recent attacks are similar to a breech last week by the hacking collective Lulz Security.

Many of the files posted online in the LulzSec attack included invitations to conferences and inspirational messages. Others focused on the activity and habits of drug cartels and homeland security threats.

Those officers had access to their accounts through remote hookups. That practice has now stopped and no access is allowed from outside a secure agency network, Harrison said.

There is no evidence that the Public Safety main servers which can access criminal files, driver's license information and vehicle registration records have been compromised, Harrison said.

The cyber attackers calling themselves AntiSec said they were specifically targeting the department because of Arizona's immigration enforcement law "and the racial profiling anti-immigrant police state that is Arizona."

For its part, LulzSec has previously taken credit for hacking into Sony Corp. where more than 100 million user accounts were compromised and defacing the PBS website, as well as a cyber-attack aimed at the CIA website and the U.S. Senate's computer system.

This is based on a story by The Associated Press.

Follow us on twitter.com/foxnewslatino
Like us at facebook.com/foxnewslatino


View the original article here