Analytics // Security Monitoring
2/10/2014
01:14 PM
Connect Directly
RSS
E-Mail
50%
50%

Florida Sting Nabs Alleged Bitcoin Money Launderers

Florida undercover agents posed as fraudsters seeking to convert cash -- supposedly from stolen credit cards -- into the anonymous, cryptographic currency.

Two men were arrested February 6 in what Florida authorities said was the first state-level money-laundering case in the country that involves bitcoins.

In separate cases, police arrested Pascal Reid ("proy33") and Michel Abner Espinoza ("michelhack") on money-laundering charges after they allegedly offered to turn criminal proceeds into bitcoins for police officers and US Secret Service agents, working undercover, who posed as fraudsters seeking to convert cash obtained by using stolen credit card numbers.

"Criminals are always seeking new ways to make their activities profitable," said Florida's state attorney, Katherine Fernandez Rundle, in a statement. "Bitcoins are just a new tool in the cybercriminal's toolkit."

Bitcoins are a cryptographic currency that's seeing increased use by a number of legitimate businesses, both in the United States and abroad, something the Florida state attorney's charging documents against the two men emphasizes. But those same documents also highlight how the anonymity offered by bitcoins makes them "ideally suited for illegal purchases," because it's "virtually impossible to trace bitcoin transactions to the owner of the bitcoin address."

[Learn from the Target breach. See Target Breach Takeaway: Secure Your Remote Access.]

Accordingly, authorities appear to be targeting people who facilitate the buying and selling of bitcoins for anyone engaged in criminal activities.

In these two cases, authorities said they located both men via an online directory of bitcoin buyers and sellers called www.localbitcoins.com, through which Reid, using the handle proy33 and Esponoza, using the handle "michelhack," allegedly posted listings. In the listing posted by proy33, for example, the seller offered to meet "anytime" to exchange bitcoins, saying he preferred to meet in "public places such as Starbucks, an Internet cafe, a restaurant, a mall, or a bank," and posted a cellphone number where he could be reached.

According to court documents, on December 10, a Secret Service agent working undercover -- and named in the documents only as "Kramer" -- met proy33 at a Starbucks in Sunny Isles, Fla. The man converted $600 into bitcoins for Kramer, taking a commission of 20% above the bitcoins' market value. Authorities said that as part of a surveillance operation they followed proy33 to his home, then identified him as being Reid, who's Canadian.

(Source: zcopley)
(Source: zcopley)

According to court documents, Kramer again met Reid on January 5, this time asking to convert $1,000 into bitcoins. The undercover agent also claimed to be in the business of selling stolen credit card numbers, and offered to sell some to Reid, who allegedly declined. But Reid allegedly didn't balk at continuing to offer bitcoin exchange services, as well as to break deposits up into multiple transactions, to help evade banks' anti-money-laundering controls.

According to court documents, the two men met again on February 4, with Kramer telling Reid that he wanted to convert $30,000 that he claimed to have earned by using credit card numbers obtained via the Target breach into bitcoins.

At that point, "Reid pulled out his Chrome (brand) laptop computer in order to observe the current bitcoin exchange rates," according to the charging documents, after which Kramer showed him a "flash roll" of $30,000 -- composed of $100 bills -- which Reid inspected for authenticity, before selling Kramer $25,000 in bitcoins, minus about $5,000 for his 20% commission. Reid allegedly also expressed interest in purchasing fake US passports and Florida driver's licenses from Kramer. Reid was arrested two days later.

According to court documents, Espinoza's bust went down the same way, with a Miami detective posing as the buyer, except that the suspect didn't believe the proffered roll of $100 bills was real. Instead, he requested that the buyer return with $20 bills. But the detective allegedly talked Espinoza into agreeing that if a Bank of America ATM accepted $2,400 of the cash for deposit into an account to which Espinoza had access, then he would convert the $30,000 into bitcoins. Less than an hour after first meeting the detective, Espinoza was arrested.

Both Reid and Espinoza face two money-laundering charges, as well as one charge of running an unlicensed money service business.

The state angle aside, this isn't the first case to involve bitcoins and money laundering charges. Last month, for example, Robert M. Faiella (a.k.a. "BTCKing") was charged with offering Bitcoin exchange services to users of Silk Road, a notorious "dark net" site -- reachable only via the Tor anonymizing network -- that reportedly facilitated that sale of illegal narcotics. Faiella reportedly sold the bitcoins at a 9% markup.

As part of that case, Charlie Shrem, formerly the CEO and compliance officer of Bitcoin exchange company BitInstant -- which closed shop in October 2013 -- was charged with helping Faiella launder more than $1 million in profits by processing the trades via BitInstant. Prosecutors accused Shrem of allowing people to swap cash anonymously for bitcoins without verifying their identities, as is required by federal law for any transaction that involves $3,000 or more.

InformationWeek Conference is an exclusive two-day event taking place at Interop where you will join fellow technology leaders and CIOs for a schedule packed with learning, information sharing, professional networking, and celebration. Come learn from each other and honor the nation's leading digital businesses at our InformationWeek Elite 100 Awards Ceremony and Gala. You can find out more information and register here. In Las Vegas, March 31 to April 1, 2014.

Mathew Schwartz is a freelance writer, editor, and photographer, as well the InformationWeek information security reporter. View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
<<   <   Page 2 / 2
Lorna Garey
50%
50%
Lorna Garey,
User Rank: Ninja
2/11/2014 | 2:14:39 PM
Re: Impact
Exactly - Bitcoins seem more akin to buying a stock than to currency. Even that analogy is flawed though because a share of stock, like a greenback, has something behind it, even if that "something" is an intangible "full faith and credit" promise that the GOP House doesn't seem to think means much.

What exactly is behind a Bitcoin?
Ariella
50%
50%
Ariella,
User Rank: Apprentice
2/11/2014 | 8:50:59 AM
Re: Impact
@Whoopty it's still worth far more than it was this past summer, and if you had bought it earlier, you'd have made an even bigger killing. However, the huge fluctuations that can make it appealing as an instrument of speculation are not working in favor of it becoming adopted as a mainstream currency. 
Whoopty
50%
50%
Whoopty,
User Rank: Moderator
2/11/2014 | 8:16:17 AM
Impact
I wonder what impact this news had on the current bitcoin value slump compared to the Mt Gox halting of withdrawals? 
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Strategist
2/11/2014 | 3:55:14 AM
Hmm...
FWIW, I have to wonder about the moral and legal implications of the setup here on Reid and Espinoza, and what was really going on.  It appears, from the description in the article of the chronology of events, that Reid was not told about the "stolen credit card numbers" until the second meet.  And that (if I am understanding correctly) he was not explicitly told that the money he was changing came directly from stolen credit card numbers until the third meet.

So imagine if you're a totally innocent person in that situation.

Imagine thinking, "Oh, crap, this guy's a criminal.  And I've already done business with him and changed money for him.  And he knows me."

Would you be brave enough to say no?

Maybe I'm being more of an apologist than Reid and Espinoza deserve.  Maybe they're truly bad guys and they were all too happy to help launder money for profit.

Regardless of the situation with these two particular defendants, however, this sequence of events suggests that officials just wanted a bust -- and didn't care if they got a "real" bad guy or just a scared innocent in over his head.
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Strategist
2/11/2014 | 3:44:27 AM
Re: Chromebooks have arrived
@Thomas: How big an endorsement is this really, though?  After all, he got arrested.  ;)
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Strategist
2/11/2014 | 3:41:45 AM
Re: The Purpose of Bitcoins
@Gary: And, for that matter, why are people complaining about things like the Patriot Act and secret FISA courts and widespread NSA phone and email surveillance?  What are these people hiding?

ಠ__ಠ
Gary_EL
50%
50%
Gary_EL,
User Rank: Apprentice
2/11/2014 | 12:15:27 AM
The Purpose of Bitcoins
Aside for making it easier for spouses to keep secrets from each other, what is the purposes of Bitcoin, other than to attempt to hide criminal activity or to commit tax fraud of one type or other??
Thomas Claburn
50%
50%
Thomas Claburn,
User Rank: Moderator
2/10/2014 | 4:32:20 PM
Chromebooks have arrived
When the crypocurrency crowd starts using Chromebooks, that's a sign they approve of the security model.
<<   <   Page 2 / 2
Register for Dark Reading Newsletters
Partner Perspectives
What's This?
In a digital world inundated with advanced security threats, Intel Security seeks to transform how we live and work to keep our information secure. Through hardware and software development, Intel Security delivers robust solutions that integrate security into every layer of every digital device. In combining the security expertise of McAfee with the innovation, performance, and trust of Intel, this vision becomes a reality.

As we rely on technology to enhance our everyday and business life, we must too consider the security of the intellectual property and confidential data that is housed on these devices. As we increase the number of devices we use, we increase the number of gateways and opportunity for security threats. Intel Security takes the “security connected” approach to ensure that every device is secure, and that all security solutions are seamlessly integrated.
Featured Writers
White Papers
Cartoon
Current Issue
Dark Reading's October Tech Digest
Fast data analysis can stymie attacks and strengthen enterprise security. Does your team have the data smarts?
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-3304
Published: 2014-10-30
Directory traversal vulnerability in Dell EqualLogic PS4000 with firmware 6.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the default URI.

CVE-2013-7409
Published: 2014-10-30
Buffer overflow in ALLPlayer 5.6.2 through 5.8.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in a .m3u (playlist) file.

CVE-2014-3446
Published: 2014-10-30
SQL injection vulnerability in wcm/system/pages/admin/getnode.aspx in BSS Continuity CMS 4.2.22640.0 allows remote attackers to execute arbitrary SQL commands via the nodeid parameter.

CVE-2014-3584
Published: 2014-10-30
The SamlHeaderInHandler in Apache CXF before 2.6.11, 2.7.x before 2.7.8, and 3.0.x before 3.0.1 allows remote attackers to cause a denial of service (infinite loop) via a crafted SAML token in the authorization header of a request to a JAX-RS service.

CVE-2014-3623
Published: 2014-10-30
Apache WSS4J before 1.6.17 and 2.x before 2.0.2, as used in Apache CXF 2.7.x before 2.7.13 and 3.0.x before 3.0.2, when using TransportBinding, does properly enforce the SAML SubjectConfirmation method security semantics, which allows remote attackers to conduct spoofing attacks via unspecified vect...

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Follow Dark Reading editors into the field as they talk with noted experts from the security world.