Risk
4/4/2008
04:18 PM
Connect Directly
Google+
LinkedIn
Twitter
RSS
E-Mail
50%
50%

Internet Fraud Loss For 2007 Tops $239 Million

The dollar loss reported from Internet crime reached an all-time high in 2007, while the number of reported crimes was lower than in each of the last three years.

The dollar loss reported from Internet crime reached an all-time high in 2007, according to the Internet Crime Complaint Center's (IC3) 2007 Internet Crime report.

The IC3 serves to field complaints about online crime on behalf of the Federal Bureau of Investigation and the National White Collar Crime Center.

The IC3 received 206,884 complaints in 2007 through its Web site, fewer than the number submitted in 2006 (207,492), 2005 (231,493), or 2004 (207,449). With the addition of other methods of complaint, IC3 received 219,553 complaints last year.

IC3 referred 90,008 complaints to the appropriate law enforcement authorities for investigation, most of which alleged fraud and financial loss. The dollar loss for referred complaints totaled $239.09 million, with a median loss of $680 per complainant. This represents an increase over the 2006 total of $198.44 million.

James E. Finch, assistant director of the FBI's cyberdivision, appears to believe that a significant number of people are not reporting Internet crimes. "The Internet presents a wealth of opportunity for would-be criminals to prey on unsuspecting victims, and this report shows how extensive these types of crime have become," he said in a statement. "What this report does not show is how often this type of activity goes unreported. Filing a complaint through IC3 is the best way to alert law enforcement authorities of Internet crime."

The report indicates that in complaints that could be linked to a perpetrator, more than 75% of cybercriminals were men and that half resided in California (15.8%), Florida (10.1%), New York (9.9%), Texas (7%), Illinois (3.6%), Pennsylvania (3.5%), or Georgia (3.1%).

When perpetrators were measured per 100,000 people, the District of Columbia had the most, with 99.10 per 100,000, followed by Nevada (65.45), Delaware (41.98), and Florida (40.73).

Counting by country, the United States had the most cybercriminals, with 63.2%, followed by the United Kingdom (15.3%) and Nigeria (5.7%).

It bears repeating that these numbers do not reflect overall Internet crime activity in these countries. Rather, they represent statistics drawn specifically from the more than 90,000 IC3 complaints investigated.

Men reported larger losses than women, with their median losses coming to $765 and $552, respectively.

E-mail was the most common means (73.6%) by which cybercriminals made contact with their victims, followed by Web pages (32.7%), phone contact (18%), and postal mail (10.1%). "The anonymous nature of an e-mail address or a Web site allows perpetrators to solicit a large number of victims with a keystroke," the report explains.

By far the most common type of fraud reported was auction fraud (35.7%) and nondelivery of merchandise (24.9%). Compared with 2006, these figures represent a 20.5% decrease and a 31.1% increase, respectively.

Other types of fraud reported were confidence fraud (6.7%), credit/debit card fraud (6.3%), check fraud (6%), computer fraud (5.3%), identity theft (2.9%), financial institution fraud (2.7%), threat (1.6%), and Nigerian letter fraud (1.1%).

The report notes that auction fraud may be overrepresented among complaints because eBay, the leading online auction site, provides its users with links to the IC3 site as part of its anti-fraud efforts.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading December Tech Digest
Experts weigh in on the pros and cons of end-user security training.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2010-5312
Published: 2014-11-24
Cross-site scripting (XSS) vulnerability in jquery.ui.dialog.js in the Dialog widget in jQuery UI before 1.10.0 allows remote attackers to inject arbitrary web script or HTML via the title option.

CVE-2012-6662
Published: 2014-11-24
Cross-site scripting (XSS) vulnerability in the default content option in jquery.ui.tooltip.js in the Tooltip widget in jQuery UI before 1.10.0 allows remote attackers to inject arbitrary web script or HTML via the title attribute, which is not properly handled in the autocomplete combo box demo.

CVE-2014-1424
Published: 2014-11-24
apparmor_parser in the apparmor package before 2.8.95~2430-0ubuntu5.1 in Ubuntu 14.04 allows attackers to bypass AppArmor policies via unspecified vectors, related to a "miscompilation flaw."

CVE-2014-7817
Published: 2014-11-24
The wordexp function in GNU C Library (aka glibc) 2.21 does not enforce the WRDE_NOCMD flag, which allows context-dependent attackers to execute arbitrary commands, as demonstrated by input containing "$((`...`))".

CVE-2014-7821
Published: 2014-11-24
OpenStack Neutron before 2014.1.4 and 2014.2.x before 2014.2.1 allows remote authenticated users to cause a denial of service (crash) via a crafted dns_nameservers value in the DNS configuration.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Now that the holiday season is about to begin both online and in stores, will this be yet another season of nonstop gifting to cybercriminals?