14 ms·
Gift card gang extracts cash from 100k inboxes daily
- deleted 5y ago[deleted]
- owlninja 5y agoI could go for something that lets me know I have cash sitting in my bloated inbox.
- dylan604 5y agoSo search your inbox for the same items these scripts are.
- andai 5y agoSee, they could have made it into a business and split the profits!
- quickthrower2 5y agoBut the main growth hack is hacking into peoples email accounts.
- midasuni 5y agoThey’d have made more money with an IPO. 40m a year is peanuts.
- kjrose 5y agoIronically, I could see people actually paying for this service by splitting the "gift cards" etc. that are found. Essentially, it's an automated service to find all of the places where programs give you free stuff for little or no work, and then their system just watches your email and does it for you, splitting the final values in some fashion. Despite the extreme security issues around it, I could many people signing up for this.
- thebean11 5y agoI don't remember what it was called, but there was a service that did exactly this for price drop protection. They'd scan your purchases by monitoring your email, and when the price of something you purchased dropped within the protection period, they'd automatically file a claim with the credit card company, taking 20%.
- moneywoes 5y agoYes I actually had this service but can’t remember the name now
- kjrose 5y agoI really like the idea of automating these things, I am pretty sure I miss out on a ton of free deals and good opportunities to save money. However, the amount of trust I'd have to have in any system where they can scan all of my email with impunity.... Hooo boy. Ain't going to happen anytime soon.
- exitnode 5y agoImagine feeling like real badasses after stealing lots of money and then they call you "Gift Card Gang".
- satanic_pope 5y agoThat made me chuckle.
- micromacrofoot 5y agoSeriously, this is actually a rather complex and interesting scheme to have such a silly name applied... but I guess on the other hand you don't really want to stroke their egos.
- lotsofpulp 5y agoImagine caring about what someone else calls you. Unless you have some affiliation or need for them, why care?
- bluecatswim 5y agot. gift card gangster
- reroute1 5y agoImagine being a loser with endless pointless comments like this lol. get a life bro you don't know shit rofl
- dhosek 5y agoHarry: [Marv brings a load of stolen goods from the Murphy household to the van and Harry sees him laughing] What's so funny? What are you laughing at? You did it again didn't you? You left the water running. What's wrong with you? Why do you do that? I told you not to do it. Marv: Harry, it's our calling card! Harry: Calling card. Marv: All the great ones leave their mark. We're the wet bandits!
- reaperducer 5y ago
- tyingq 5y agoMakes me curious if Gmail tells you when new/suspicious IMAP connections are made. I know they do tell you for normal web logins. Off to disable IMAP where I don't need it...
- compsciphd 5y agomost people dont even need an imap password if using a client like thunderbird. It will juset pop up a webpage to generate an oauth token that it will use.
- jdavis703 5y agoEnable two-factor authentication and disable app passwords. That should be enough to stop this particular type of scam.
- lupire 5y agoGmail only allows connections OAuth clients, by default. https://support.google.com/a/answer/9003945?hl=en https://support.google.com/a/answer/9003945?hl=en
- pseudo0 5y agoI'm not sure about Gmail, but Outlook does, and it's kind of interesting to check out https://account.microsoft.com/security https://account.microsoft.com/security > Sign-in activity and see all the random IPv6 addresses unsuccessfully trying to connect via IMAP. My email was in some random db dump (with a password I didn't reuse) probably a decade ago and apparently people are still trying to cred stuff it.
- dhosek 5y agoI've gotten notifications from gmail when there were logins from outside the US to my account.
- tyingq 5y agoRight...for regular Gmail logins though, or IMAP ones?
- upofadown 5y ago>Microsoft declined to comment specifically on Bill’s research, but said customers can block the overwhelming majority of account takeover efforts by enabling multi-factor authentication. Or, of course, by not reusing passwords everywhere. ISPs can help by turning on some sort of brute force protection on SMTP and IMAP. They can also help by checking for completely obvious passwords (yes, by brute force cracking with a short list). Which brings us to this: >But you also know they are accessing their email exclusively through an email client. What do you do? You can’t flag their account for a password reset, because there’s no mechanism in the email client to affect a password change.” If only there was some way to communicate with a email customer...
- lupire 5y agosending email to a address controlled by a hacker isn't super effective.
- inetknght 5y agoIf your only method of contacting your customer is via email and the email is demonstrably controlled by a hacker then you have a hacker for a customer. If email isn't your only method of contacting your customer... then sending an email to an address controlled by a hacker isn't your only option.
- deleted 5y ago[deleted]
- IncRnd 5y ago> If your only method of contacting your customer is via email and the email is demonstrably controlled by a hacker then you have a hacker for a customer. That's obviously false. The context of this very discussion is that more than one person is able to log into an account for many email accounts.
- Tyr42 5y agoSure but the hacker can trash the email.
- justicezyx 5y agoGift card cannot be cashed out, right? I don't follow how this scam can be profitable. Are they reselling the gift card? I did not find mentioning that in the article.
- jonchang 5y agoQuote: Why go after hotel or airline rewards? Because these accounts can all be cleaned out and deposited onto a gift card number that can be resold quickly online for 80 percent of its value. “These guys want that hard digital asset — the cash that is sitting there in your inbox,” Bill said. “You literally just pull cash out of peoples’ inboxes, and then you have all these secondary markets where you can sell this stuff.”
- mjparrott 5y agoYes they resell the gift cards. If I quote the article: "... these accounts can all be cleaned out and deposited onto a gift card number that can be resold quickly online for 80 percent of its value" Additionally, a quick google search for "sell gift cards online" reveals many sites that offer the ability to sell your gift cards. One example: https://www.cardcash.com/sell-gift-cards/ https://www.cardcash.com/sell-gift-cards/
- duskwuff 5y agoSome gift cards can be cashed out conditionally. For example, California requires that gift cards under $10 be redeemable for cash. Outside of that, there's a huge grey market for "discounted" gift cards. That's probably where most of these are going.
- FalconSensei 5y agothey can sell a $50 gift card for $40 or something
- SilverRed 5y agoI have tried to do this legitimately for unwanted gifts and its a lot of work. Posting a gift card on the normal buy and sell sites attracts every scammer in the country who all pretend to have sent payments or send fake paypal emails to you and get angry when you don't hand over the code. And then even when they do pay you they could always tell paypal that the code didn't work.
- bemmu 5y ago> They’re actually automating the process of replying saying you completed this activity so they can bump up your point balance and get your gift card. What they're doing is terrible, but I felt a bit of respect for how clever this is.
- narrator 5y agoAt least it adds an extra fun dimension to our otherwise grim social credit score future.
- arglebarglegar 5y agoit’s kind of incredible! i wonder if it’s coming from someone somewhere inside the industry?
- mjparrott 5y agoTurns out it is more profitable to just take everyone's inbox cash than to offer them a service to make their own cash visible to them for a % fee
- lifeisstillgood 5y ago> (if the ISP blocks the account) “Those customers are likely going to get super pissed off and call up the ISP mad as hell,” Bill said. “And that customer service person is then going to have to spend a bunch of time explaining how to use the webmail service. As a result, very few ISPs are going to do anything about this.” If someone had copied your door key, and was breaking into your house each week to look for food, then you probably would want the police to change the lock. Or at least let you know you need to. This just strikes me as a regulatory issue - we have to be able to trust our online services. As such, the level of security needs to be upped by fiat. Its not a popular idea but a FIDO key for everyone in US / Europe would be within the bounds of feasible in next 10 years. Hell just SMS 2FA would massively cut back on this.
- tptacek 5y agoI don't believe it's the norm anywhere in the US for the police to change your locks by fiat, or to go lock your unlocked car doors. That's not something I think a lot of people want.
- lifeisstillgood 5y agoOK OK everyone - not a perfect analogy ... but I feel it's worth defending. No I don't want the cops to change my locks either - but imagine you lived in an apartment building whose rules that prevented say, adding a second lock. Even if you changed your lock, you could not give yourself the comfort of two-factor doors. If there were tens of thousands of such apartments being burgled each day I would be surprised if the answer was not requiring landlords to raise their security standards. Ultimately it frustrates me to find (yet another) area that criminal activity trivially siphons off cash to the extent we may as well call it a subsidy.
- reaperducer 5y agoBack when cops used to walk a beat, it was usual for them to check the doors of the closed businesses as they passed to make sure they were still locked. Whether they locked one if they found it unlocked, I do not know.
- 5y ago
- JumpCrisscross 5y agoAre stolen airline miles really that valuable?
- dhosek 5y agoYes. They can be turned into gift cards and resold online. I remember reading somewhere that most of an airline's profits come through their loyalty programs.
- tehwebguy 5y agoNormally? Yeah. Stolen? Yeah, sort of. Banks, hotels & a few airlines let you convert points to gift cards but the conversion rate for miles in particular is trash (less than $0.01 / mile). Using them for an international business / first class flight can easily pass $0.05 and often $0.10 or $0.20 per mile, but this makes it easy for the airline to cancel & return the miles unless someone is flying same-day.
- paulpauper 5y agoOf course, tons of queries for crypto exchanges
- gootler 5y agoUniversal Basic Income and Gun Confiscations will ultimately solve this.
- jvanderbot 5y agoA gift card was taken from our mail and spent nearby. Fun part is they resealed the envelope so we'd never have known had the sender not told us.
- codethief 5y agoI'm wondering… would the gift card gang also be interested in those "You won a $100 gift card!" emails in my spam folder? :) The idea of the gang and the spammer going on about who should drop their pants first ("Please send us the gift card" – "No you send me your bank account information first") makes me chuckle.
- WarOnPrivacy 5y agoI reclaimed one of these accounts for a customer of mine - literally 15 minutes ago. The first scam email was Hey. Catching up. Follow up email was I'm in a bind tonight. Unexpected bad thing happened. Can you order this gift card and send it to my relative for me? The initial phish was an bogus AOL email saying there's a system change coming up and the customer needs to log in and apply the change to their email account.
- hellbannedguy 5y agoI have a Comcast email account that was hacked years ago. They even got my password from Comcast. (I have been given Comcast $200 monthly, and just figured they had decent security?) I now have 2FA from Comcast, but I get hacking emails daily. I don't care about the emails. They keep me up to date on the latest scam. This email is not attached to anything important besides my doctor. Is there something a Russian hacker could do with my email address? I said Russian because they told me they were Russian. 15 years ago I responded to a friendship ad on CL, and that's how I got on the sucker list.
- jrmg 5y agoThis is making me wonder about the legitimacy of gift card resell sites like https://www.raise.com/ https://www.raise.com/
- Jay1234 5y agoHow does this work please
- joe_the_user 5y agoThe thing about this scheme is that it seems to amount to an extremely low tax on the accounts of the average user. The big downside isn't really that people might lose their gift cards but that other horrible things could happen at scale 'cause who knows who the Gift Card Gang are really. And the thing is here that the state, the broader authorities, are the only ones who have some incentive to act now about this. If it affected me, I'd shrug, I have no incentive. And the story everywhere with this is the state has become as short-term-ist as everyone else. And, what problems could possibly arise from that?? (posts and then checks outside for fire, poison gas and deadly disease).
- drewg123 5y agoI thought this was going to be about a different scam: Taking over an email account and messaging the contacts to send e-gift cards. This happened to my real estate agent. I got an email from her saying "I really need to get a (Google play gift card) for a friend who is a cancer patient.". That seemed super phishy, so I texted her, and she said her email was taken over. This was a verizon.net account that was migrated to aol. The hacker had reset her email password and created a hotmail account in her name, and was forwarding all incoming mail to the account he controlled. She regained control of the account, but he still had an active session and was still sending out phishing emails. I tried to help her, but I could not find any way to have AOL sign out all active sessions..
- rsync 5y agoCan we talk about who "Bill" (the source for the article) is ? If we read between the lines, it appears that someone sitting at a fairly large Internet choke point is grepping the flow of mail traffic for keywords (for lack of better terms since it's not literally grep). Presumably someone placed highly enough that they can do such analysis without management oversight ? Or are there compliance and security reasons to "grep" IMAP traffic for certain things and he just added some other keywords ? Where, in 2021, would a network admin own this much traffic and have this little oversight ? ----- EDIT: ... and now that I think about it, wouldn't this be fairly easy to suss out ? The source states: "So I’m seeing this traffic to just like 10 net blocks tied to Microsoft, which means I’m only looking at maybe 25 percent of Microsoft’s infrastructure," I have neither the time nor the inclination but if there is an ISP out there that is routing 25% of MS mail infrastructure, all I have to do is look at mail routes to MS for a few days and run some traceroutes and I could probably make some guesses as to which network "Bill" works for ...
- yencabulator 5y agoI would assume(/hope) IMAP would be TLS protected, these days. And since Bill doesn't seem to be inside Microsoft, he'd have to MITM the TLS sessions? To me, it sounds more like Bill broke into (some of) the "proxy network" (likely bots on home computers?) used by the attackers, and is spying on them.