The Fraud Supply Chain
bam.kalzumeus.com
bam.kalzumeus.com
To paraphrase the steps involved, because the description doesn't quite make it clear how the casher gets paid without getting caught:
1. Casher sets up as merchant on e-commerce platform like Amazon.
2. Casher takes order from customer.
3. Customer pays with their own credit card.
4. Casher fulfills the customer order by ordering from another merchant (shipper), paying with the stolen card number. The casher creates a brand new account with the shipper just for this purpose. The casher gives the customer's contact information to the shipper.
5. Customer receives order from the shipper.
6. Shipper receives payment from stolen card.
7. Casher receives payment from customer card.
So the casher is paid by the customer, and the shipper is paid with the stolen card. To the shipper, it looks like the customer paid with a fake card. To the customer, it looks like the order was fulfilled as expected.
The shipper gets a chargeback from the card company. If it's not aware of the scam, it's likely to just accept and move on. But if the shipper gets a lot of these chargebacks and knows about the scheme, it can contact the customer (via the mailing address) to ask which e-commerce site the item was ordered from. This may or may not work because some customers will be reluctant to discuss that kind of thing over the phone. So the casher needs to spread the fraud around to lots of shippers and thereby make the investigation not worth the effort.
https://mashable.com/article/nespresso-money-mules-ebay-cred...
1. You order a product, preferably something expensive and easy to sell. You request delivery to a package locker and payment via standard bank transfer. The site you're ordering from gives you an account number to transfer to, as well as an ID to put in the reference field.
2. You list something at the same price on our local equivalent of Craigslist.
3. When you find a customer, you tell them that you only accept payment via standard bank transfer. You give them the account number and reference ID from step 1. You never ship the offered item.
4. The customer makes the transfer and the item ordered in step 1 is delivered to a locker of your choosing. You can retrieve it and sell it legitimately.
5. When the customer from Craigslist doesn't receive the item they paid for, they go to the police. However, there's nothing linking you to their transaction, the seller of the item in step 1 is the primary suspect, as they're the ones who took their money in the first place. Even if they discover that there was a third person involved, they're usually extremely hard to find, as the footage from any CCTV equipment near the locker will be long gone.
Fraudsters would setup a Cash -> Bitcoin transaction on local Bitcoin. Scam someone else into fulfilling the payment, then run off with the Bitcoin.
Then the victim looses their money, the Bitcoin seller is now in possession of effectively stolen funds. You don’t want to be the seller in this equation because from the banks perspective you look like the fraudster, and it’s likely you have bank accounts closed.
Those traditional bank transfers are set up by a payment gateway (Przelewy24, DotPay, Payu), which is linked to the marketplace (eBay, Allegro), on which the seller actually operates.
The seller definitely doesn't get your payment info, not sure about the marketplace, but I don't think they do.
Besides, if you live in Poland and opt for payment via traditional, old-style bank transfer, you're probably a very unsophisticated customer. Most likely, you're completely unbanked and will hand over cash to a relative who will make the transfer for you. Most people who own a bank account and have enough tech skills to make a purchase over the internet will use a different payment method.
And such payments can also be entirely legitimate, e.g. when Joe is a kid who wants to buy a gaming console and Bob is their father who pays for it.
Many electrical products come with a plug adaptor for the main three types of electrical sockets and range of voltages, obviously due to British ties, there is English speaking manuals but manu manuals in practice have a range of languages in the documentation, and for all intents and purposes the product will work perfectly fine if used in the UK, yet exchange rates & taxes (or lack of) means its cheaper to get the product from Hong Kong and then ship to the UK.
People in Hong Kong ship goods in bulk from Hong Kong so they are already in the UK and then operatives in the UK set up an Ebay account so even Ebay or Amazon dont know.
If the vendor can't handle warranty obligations then (depending on your jurisdiction) they might be in trouble, but it still isn't fraud.
In the US, grey market good are generally legal (under first-sale doctrine). In the UK they aren't (under R vs C and others).
Whilst its not fraud, the fact anyone including the former directors of now deceased company can also appoint their own liquidators, and liquidators generally work for who ever is paying the bill, it is all but fraud in name.
They were selling power smart generators for <$100 USD. Both listing an address in Canada, but having a PayPal address that seems to go to someone in China, and not properly setup so any purchase becomes “goods”.
I couldn’t figure out exactly what the scam was… but it’s suddenly making sense !
You could get to a point where there is enough fraud in the marketplace, you might have one fraud seller, buy from another fraud seller, human centipede style. It would be really interesting if it formed a closed loop. I’m sure it’s happened.
You could avoid that by making a network of fraudsters, who know about each other and can avoid each other. But then you’re only as strong as the weakest link. As soon as someone gets caught, the authorities have the full list of the network, and everyone gets taken down.
Wasnt there something years back about merchants refusing to ship to addresses not associated with the payment method? Why would you ship something to midwest after being paid by the card registered to CA resident?
People do subjectively weird things, all the time at Internet scales.
Here’s a very real example: Amazon account opened in 1996 from Illinois. Credit card billing address in Chicago. Has never purchased electronics or anything over $200. Almost dormant for several years. 2007 rolls around and the account is accessed from a novel IP address in Nagoya and buys a $2k laptop for a person with an unrelated name living in Ohio.
Place your bets: was this transaction fraud?
No, it was not. I bought that laptop, on behalf of a coworker, an Indian woman working with me in Nagoya who had no credit card and no U.S. banking relationship. She had a member of her extended family, living in the U.S., and wanted to buy them a laptop to celebrate their entrance into University. She gave me physical yen for the laptop.
Impressively, IMHO, Amazon let this transaction go through without stopping me, though I was on pins and needles (and told her as much). I assumed this would trip every possible flag, and (as a Japanese salaryman) $2k was a lot of money to both of us.
I've had multiple occasions where my Amazon purchases should have thrown red flags - mixed up Amazon accounts, wrong ip, wrong country, wrong name and it still went through.
-Students studying in a different city/state for college but keeping their parent's home for billing purposes
-Recent relocation
-Staying with friends/family for a few weeks around holidays
etc.. Tons of valid reasons. Of course you reduce fraud as a merchant if you do that, but you also reduce your sales by quite a significant amount (and anger your customers), sometimes it's just not worth it.
Oh here I am moved to Kansas in my new company provided house as part of relocation, but there are still somethings we need here I can see that already I will just pay for it with my CA card because I haven't got a new local one yet.
Obviously all these are edge cases but probably so are all those problems with paypal, google, amazon cancelling some customer's stuff and we get all upset about it here. So cancelling something because it looks suspicious is pretty unfair to people who haven't done anything wrong.
I know BestBuy.com is able to do SMS 2FA with my Bank of America Visa credit cards.
Maybe that will happen at scale if more card issuers decide the inconvenience/friction to legitimate card users makes it worthwhile per the level of fraud they're seeing.
But, the solution to the address problem here assumes the current state of things.
And, there are other issues involving addresses that strictly validating the credit card wouldn't solve (like unsolicited package and brushing scams), as well as things I'm sure we've yet to consider.
In general, it would probably be a good thing for people to have better control of who can send what to their address.
Heh. I knew that'd be the first question.
Yeah, that's one of the caveats. The auth email or SMS to the previous owner would allow them to indicate they moved. That would probably handle most cases quickly. But, if no response in x time, it could default to allow and/or if the new owner wants to be proactive, they can send proof of residence. A little bit of a PITA, but doesn't add much to the PITA moving already is. And, moving is pretty infrequent.
There's also billing address validation, as that frequently matches shipping address anyway.
This kind of validation would also help with other scams.
VisionPlus or one of the many other systems that may be employed in the chain of payment are configurable for many many such triggers or rules, change of address IIRC is a pretty basic one.
Previously they had another good scam going were some kind of "glitch" in android g maps would end up with the company phone number being clicked and ready to call. Did you know that a billion people found your business on gmaps? Buy our ad vouchers now.
The level specialization only seems to have risen since. When you have that, you get so many aspects that just look like legitimate office or tech work. Amazing considering that all those layers of abstraction must make it difficult to even comprehend. There must be smart people out there who really get it though, and they must occupy particularly safe niches in that ecosystem.
I have no idea how effective this has been, but at least here [Hungary] banks went all in basically.
"That sounds like a very hand-wavy claim, Patrick."
U.S. gold mine production in 2020: ~200 metric tons, which is about 6.4M troy ounces. $1.8k an ounce currently. That's +/- $11B.
Payment fraud worldwide is +/- $25B and the US has the plurality of it.
But the person you were replying to wasn't saying that payments fraud wasn't huge. They were saying that the bulk of payments fraud was no longer stolen credit cards, because now payments fraud happens mostly with cryptocurrencies. I have no idea if their point is correct, but I think you weren't really addressing it.
(No seriously speaking, would love to write a book someday, but not sure it would be this book, and between the day job and two young children I don't have a book in me at the moment unless I can clean the calendar for many months in a row and that doesn't seem rational given other uses of my calendar.)
What does this mean? Are we breaking payments fraud down by countries? Continents? Currencies? Those can all have different "pluralities". There is no lower limit on what "the plurality of $25B" is.
Having worked in a similar role, I can tell you he’s spot on. Payment fraud is huge and pervasive, especially in the US where the industry has found a way of shifting most of the cost on to consumers.