Our Favorite Scammers
head-fi.org
head-fi.org
A start-up that I worked for got taken for over $100K by a scam artist who, believe it or not, used a picture of a famous middle-eastern leader on a fake driver license to open an account - I'm not kidding. The guy was instantly recognizable from any recent TV news story, and yet the scam artist pasted that picture onto a drivers license (that had otherwise legit information on it) and faxed that in when he opened an account. After opening the account, the scam artist then filed a change of address, which shifted the shipping destination from a swanky neighborhood full of mansions (where the scam artist had stolen an identity from) to a dilapidated building in a really bad part of town. The operations team didn't catch any of this, and shipped the merchandise.
They were only able to get the feds to catch the guy when he showed up and tried to pull off a second heist a few months later.
I have no idea why they used that picture - they took a template driver license, populated it with the guy's personal information, pasted the picture on it, then faxed it to us. I suppose they figured it would be so grainy from the fax that it wouldn't be obvious, or maybe they just did it for the lulz.
This happens with any mid-high ticket item you sell, unfortunately. I ran a hosting company for 6 years and we had rampant fraud even back then. The "tells" were often the same--high-$ orders submitted by someone who hadn't talked to you first, etc.
I do remember a couple of gems from my time running the company. Once, I had a friend who lived in the UK at the time call during UK business hours to verify that a customer had actually placed a large order. (This was back >10 years ago when calling the UK from the US was quite expensive--it was easier and cheaper to have my friend call!) It turned out the order was for real, and we got a happy new customer.
On the flip side, we had a customer order and pay for a server for 6 months with no usage. Suddenly he started using it--for spam! Usually when this happens it means the server has been hacked. Not in this case, however. The dude was a bona fide spammer wanted by the FBI. We seized the server, called the FBI and reported it.
The guy had the nerve to then charge back ALL of his 6 months of hosting through Amex. (Turns out that was part of the scam--Amex allows you to charge back exactly 6 months of purchases.) We filed a counterclaim with Amex, but they sided with him (any merchant who accepts Amex will not be surprised by that story.) We contacted Amex directly letting them know their card holder was a spammer, but he charged tens of thousands of dollars a month on the card and we got nowhere. I suspect in this day and age of social media, we would have gotten a lot farther with it.
Years later, I heard Microsoft, of all companies, finally tracked him down and got him arrested: http://www.nbcnews.com/id/18955115/ns/technology_and_science... He had the nerve to use his real address with us, too, which I hope helped the FBI's case. I have the dubious honor of having talked to him on the phone when he was spitting mad after we shut his server down.
There are some real whackjobs out there. Unfortunately, you'll often meet them when you run an online business.
My experience having a merchant account that accepted credit cards was that payment processors accept absolutely NO liability. The merchant pays 2-3% (more for AMEX) and is usually on the hook for 100% of the fraud.
Further, your monthly fees and percentage may go up if your chargeback rate is not kept at a reasonable rate... IIRC there is a fairly direct relationship there. If you can manage to be a low-chargeback account, you can negotiate better deals.
The Book of Schiit TOC is here: http://www.head-fi.org/t/701900/schiit-happened-the-story-of...
Disclaimer: I have a Schiit Bifrost Uber USB and Schiit Asgard 2 on my desk. They are amazing, worth every penny.
Got me thinking that this is a kind of an open-source business. Apart from financials pretty much everything else is done openly through this "ongoing book": R&D, production issues, sales, customer support. Kudos to this guy and a big thank you for sharing all this.
(Though I still don't get the reasoning behind the name of the company. I honestly wouldn't have bought anything from them if not this brilliant book.)
First of all, you don't block the order if billing and shipping addresses are the same, even if blacklisted. Another important thing would be, an address is blacklisted only in the case of a proven fraud, not just suspected. Next, apartment/house sharing would be problematic for the tenants, well then co-habitants or the landlord will have a good reason to throw the fraudster out.
But how would the landlord or co-inhabitants know? And even if it were proven, it would still not be a straightforward task to deal with such people.
The aggressive self-righteousness described in the article is very typical of criminal types. This makes them very convincing at playing the victim when they are challenged. They can very easily turn the tables on you, even to the point where you are the one facing sanctions, and even paying compensation.
They're not perfect though, so you get some false-positives and they'll let through some e.g. Spammers sign up for web hosting in my experience.
However, they're usually curated and distributed for enterprise customers, which means you may be paying a huge subscription fee (6 figures yearly wouldn't be uncommon) for access to that list.
Fraud is such a big problem that companies can easily charge a massive premium for anti-fraud services and software.
If anyone experiences things like this, or are wary of it happening to your business/startup/whatever, and would like some advice on how to either avoid it or identify it, my email's in my profile.
I wrote the book.
Obviously, I only have a Canadian credit card. In the past, this was settled via a quick passport and/or credit card scan. And I understand you guys... but please understand me as well.