Attacks/Breaches

2/8/2019
04:00 PM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
50%
50%

US Law Enforcement Busts Romanian Online Crime Operation

Twelve members of 20-person group extradited to US to face charges related to theft of millions via fake ads other scams.

US and international law enforcement authorities have dismantled a group operating mostly out of Romania that over the past five years allegedly stole millions of dollars from American citizens using false advertisements for goods online.

Twenty people, including 15 Romanians and 1 Bulgarian national, have been indicted for their roles in the operation. Twelve of the foreign nationals have been extradited to the US and are set to face trial later this year. The arrests stem from a 24-count indictment that a federal grand jury in Kentucky returned in July 2018.

This is the second win against online crime in recent weeks for US law enforcement and their counterparts in other countries. In January, the government announced it had taken down xDedic, one of the Internet's largest sites for stolen goods.

The latest indictments allege that the Romanian group — identified in charging documents as the Alexandria Online Auction Fraud Network — engaged in numerous activities designed to defraud Internet users in the US and elsewhere by posing to sell goods that didn't exist.

The most common scam was to place fake advertisements for automobiles and other items on online auction sites and multiple business-to-consumer and consumer-to-consumer sites, including eBay, Craigslist, and Amazon.

Often, the group used stolen identity information belonging to US residents to create online accounts for posting these advertisements and establishing email addresses, the US Department of Justice (DoJ) said in a statement.

Emails and invoices they sent to victims would contain the trademarks of reputable operations, like AOL Motors and EBay Motors, to trick victims into believing they were engaged in a legitimate transaction. The invoices would include phone numbers and email addresses for questions and contain language that guaranteed refunds and indicating the seller was a "verified" or "certified" seller on the particular platform.

The money that victims sent was converted to bitcoins and deposited in overseas accounts.

Members of the Alexandria Online Auction Fraud Network often assumed the personas of individuals working with the US armed forces to try and add credibility to their ads. One of the gang members, for instance — identified in a DOJ press release Thursday as Ionuţ Ciobanu, 28, of Romania — allegedly communicated with victims about potential vehicle sales, using the persona of "Sgt. Judith Lane," a supposed member of the US Air Force. Ciobanu even created a Facebook profile for Judith Lane and posted at least two Facebook advertisements listing vehicles for sale. Another gang member pretended to be a "Sgt. Logan Burdick" when attempting to sell nonexistent goods.

"These members would convince American victims to send money for the advertised goods by crafting persuasive narratives, for example, by impersonating a military member who needed to sell the advertised item before deployment," the DOJ said.

The 24-count indictment unsealed this week in US District Court for the Eastern District of Kentucky charges members of the Romanian group with racketeering and criminal conspiracy, wire fraud, money laundering, and aggravated identity theft. Some of the charges carry up to 20-year sentences in federal prison. The aggravated ID theft charges carry a mandatory two-year sentence that will be tacked on to the end of any other prison term the individual might receive.

Related Content:

 

 

 

 

Join Dark Reading LIVE for two cybersecurity summits at Interop 2019. Learn from the industry's most knowledgeable IT security experts. Check out the Interop agenda here.

Jai Vijayan is a seasoned technology reporter with over 20 years of experience in IT trade journalism. He was most recently a Senior Editor at Computerworld, where he covered information security and data privacy issues for the publication. Over the course of his 20-year ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Crowdsourced vs. Traditional Pen Testing
Alex Haynes, Chief Information Security Officer, CDL,  3/19/2019
BEC Scammer Pleads Guilty
Dark Reading Staff 3/20/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
5 Emerging Cyber Threats to Watch for in 2019
Online attackers are constantly developing new, innovative ways to break into the enterprise. This Dark Reading Tech Digest gives an in-depth look at five emerging attack trends and exploits your security team should look out for, along with helpful recommendations on how you can prevent your organization from falling victim.
Flash Poll
The State of Cyber Security Incident Response
The State of Cyber Security Incident Response
Organizations are responding to new threats with new processes for detecting and mitigating them. Here's a look at how the discipline of incident response is evolving.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-10010
PUBLISHED: 2019-03-24
Cross-site scripting (XSS) vulnerability in the PHP League CommonMark library before 0.18.3 allows remote attackers to insert unsafe links into HTML by using double-encoded HTML entities that are not properly escaped during rendering, a different vulnerability than CVE-2018-20583.
CVE-2019-9978
PUBLISHED: 2019-03-24
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_options swp_url parameter, as exploited in the wild in March 2019. This affects Social Warfare and Social Warfare Pro.
CVE-2019-9977
PUBLISHED: 2019-03-24
The renderer process in the entertainment system on Tesla Model 3 vehicles mishandles JIT compilation, which allows attackers to trigger firmware code execution, and display a crafted message to vehicle occupants.
CVE-2019-9962
PUBLISHED: 2019-03-24
XnView MP 0.93.1 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to VCRUNTIME140!memcpy.
CVE-2019-9963
PUBLISHED: 2019-03-24
XnView MP 0.93.1 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to ntdll!RtlFreeHeap.