Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

2/8/2019
04:00 PM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
50%
50%

US Law Enforcement Busts Romanian Online Crime Operation

Twelve members of 20-person group extradited to US to face charges related to theft of millions via fake ads other scams.

US and international law enforcement authorities have dismantled a group operating mostly out of Romania that over the past five years allegedly stole millions of dollars from American citizens using false advertisements for goods online.

Twenty people, including 15 Romanians and 1 Bulgarian national, have been indicted for their roles in the operation. Twelve of the foreign nationals have been extradited to the US and are set to face trial later this year. The arrests stem from a 24-count indictment that a federal grand jury in Kentucky returned in July 2018.

This is the second win against online crime in recent weeks for US law enforcement and their counterparts in other countries. In January, the government announced it had taken down xDedic, one of the Internet's largest sites for stolen goods.

The latest indictments allege that the Romanian group — identified in charging documents as the Alexandria Online Auction Fraud Network — engaged in numerous activities designed to defraud Internet users in the US and elsewhere by posing to sell goods that didn't exist.

The most common scam was to place fake advertisements for automobiles and other items on online auction sites and multiple business-to-consumer and consumer-to-consumer sites, including eBay, Craigslist, and Amazon.

Often, the group used stolen identity information belonging to US residents to create online accounts for posting these advertisements and establishing email addresses, the US Department of Justice (DoJ) said in a statement.

Emails and invoices they sent to victims would contain the trademarks of reputable operations, like AOL Motors and EBay Motors, to trick victims into believing they were engaged in a legitimate transaction. The invoices would include phone numbers and email addresses for questions and contain language that guaranteed refunds and indicating the seller was a "verified" or "certified" seller on the particular platform.

The money that victims sent was converted to bitcoins and deposited in overseas accounts.

Members of the Alexandria Online Auction Fraud Network often assumed the personas of individuals working with the US armed forces to try and add credibility to their ads. One of the gang members, for instance — identified in a DOJ press release Thursday as Ionuţ Ciobanu, 28, of Romania — allegedly communicated with victims about potential vehicle sales, using the persona of "Sgt. Judith Lane," a supposed member of the US Air Force. Ciobanu even created a Facebook profile for Judith Lane and posted at least two Facebook advertisements listing vehicles for sale. Another gang member pretended to be a "Sgt. Logan Burdick" when attempting to sell nonexistent goods.

"These members would convince American victims to send money for the advertised goods by crafting persuasive narratives, for example, by impersonating a military member who needed to sell the advertised item before deployment," the DOJ said.

The 24-count indictment unsealed this week in US District Court for the Eastern District of Kentucky charges members of the Romanian group with racketeering and criminal conspiracy, wire fraud, money laundering, and aggravated identity theft. Some of the charges carry up to 20-year sentences in federal prison. The aggravated ID theft charges carry a mandatory two-year sentence that will be tacked on to the end of any other prison term the individual might receive.

Related Content:

 

 

 

 

Join Dark Reading LIVE for two cybersecurity summits at Interop 2019. Learn from the industry's most knowledgeable IT security experts. Check out the Interop agenda here.

Jai Vijayan is a seasoned technology reporter with over 20 years of experience in IT trade journalism. He was most recently a Senior Editor at Computerworld, where he covered information security and data privacy issues for the publication. Over the course of his 20-year ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Why Cyber-Risk Is a C-Suite Issue
Marc Wilczek, Digital Strategist & CIO Advisor,  11/12/2019
DevSecOps: The Answer to the Cloud Security Skills Gap
Lamont Orange, Chief Information Security Officer at Netskope,  11/15/2019
Attackers' Costs Increasing as Businesses Focus on Security
Robert Lemos, Contributing Writer,  11/15/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Navigating the Deluge of Security Data
In this Tech Digest, Dark Reading shares the experiences of some top security practitioners as they navigate volumes of security data. We examine some examples of how enterprises can cull this data to find the clues they need.
Flash Poll
Rethinking Enterprise Data Defense
Rethinking Enterprise Data Defense
Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-19071
PUBLISHED: 2019-11-18
A memory leak in the rsi_send_beacon() function in drivers/net/wireless/rsi/rsi_91x_mgmt.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering rsi_prepare_beacon() failures, aka CID-d563131ef23c.
CVE-2019-19072
PUBLISHED: 2019-11-18
A memory leak in the predicate_parse() function in kernel/trace/trace_events_filter.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption), aka CID-96c5c6e6a5b6.
CVE-2019-19073
PUBLISHED: 2019-11-18
Memory leaks in drivers/net/wireless/ath/ath9k/htc_hst.c in the Linux kernel through 5.3.11 allow attackers to cause a denial of service (memory consumption) by triggering wait_for_completion_timeout() failures. This affects the htc_config_pipe_credits() function, the htc_setup_complete() function, ...
CVE-2019-19074
PUBLISHED: 2019-11-18
A memory leak in the ath9k_wmi_cmd() function in drivers/net/wireless/ath/ath9k/wmi.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption), aka CID-728c1e2a05e4.
CVE-2019-19075
PUBLISHED: 2019-11-18
A memory leak in the ca8210_probe() function in drivers/net/ieee802154/ca8210.c in the Linux kernel before 5.3.8 allows attackers to cause a denial of service (memory consumption) by triggering ca8210_get_platform_data() failures, aka CID-6402939ec86e.