March 9, 2008

It'll Never Happen to Me

This morning, Brigitta noticed a charge from yesterday for $9.87 on our online bank statement. The company name was 'www.photosmix.com', and the purchase was made with a debit card she rarely uses. A quick search, and she finds this thread at broadbandreports.com discussing a whole network of their sites and several other people with the mysterious $9.87. This appears to be similar to a known fraud technique...
"This group is also using the same deflecting tactic as the globus group, by telling victims someone registered on the site with their car. More than likely any victim who bought that lie and got a credit will have been hit with a second charge the next month. Any subsequent second hit names and full info is vital in following the trail."
Obviously, we canceled the card and reported the fraud to Bank of America and the FBI, but now I'm kind of obsessed with catching these bandits. I'm not sure how they got the card number, possibly by taking a picture of her debit card at an ATM or department store sometime over the last year. All you need is the number and expiration date to process a credit, I do it all the time when I order (cheese) pizza.

Looks like photosmix.com is currently down, but there are still plenty more sites with the same generic 'stock photo' template. They probably only keep them up until enough complaints roll in and things get suspicious. It doesn't look like GoDaddy has made any attempt to take down these domains, but if they are stealing credit cards, I'd guess they are using those to buy the domains as well. The newer sites seem to be registering with Domains by Proxy to protect their identities. What's a few extra bucks when it's not yours in the first place?

I may need to dedicate a little time to this caper tomorrow.

1 comments: