Showing posts with label Scam. Show all posts
Showing posts with label Scam. Show all posts

Sunday, April 27, 2025

Cybersecurity: AI Dulls Our Critical Thinking and Enables Scammers to be More Effective (Microsoft Warned Us!)

The rise of "AI" (mostly Large Language Models, or LLMs, like ChatGPT, Claude, Perplexity, and so on) does enable a lot of "productivity hacks". However, Microsoft had warned us back in Jan 2025 that the most you rely on them, the more atrophied your critical thinking skills. Most "knowledge workers" who admitted to using AI tools, only use their own critical thinking skills to "fact-check" the LLMs. This suggests that the "average user" may be doing even less than that. 

This bodes ill for the average user, as they seem to regard ChatGPT and LLMs as some sort of generic "expert", when it is nothing of the sort. Indeed, merely by browsing /r/cybersecurity_help there are a number of topics where the poster openly admitted to "I checked my logs with ChatGPT..." when they lacked even the skills to fact-check the LLM they used. They suspected something, and they wanted ChatGPT to confirm their suspicions. 

But that's not the actually worrying part. Instead, Microsoft security is ringing the alarm: scammers are using LLMs to craft their latest scams to enhance their social engineering... by leveraging every sort of fakery possible, from fake website to fake job posting to fake customer service chatbots, because making them is so much easier with LLMs consolidating such knowledge. 

Be wary out there. 

Tuesday, January 21, 2025

Cybersecurity: Hilarious (to me) Explanation for Attempted Verification Code Fraud

One of the scams that had been around a while was the verification code scam/fraud. To make a long story short, scammers, who cannot get a new account because they had abused their own account, would attempt to trick other people into "verifying" them by entering the victim's phone number when registering a new account, then claim "I'm just verifying you are real, gimme that code you just got". If you do give them that code, you just helped them get a new account to scam from, and now YOUR phone number is associated with them (and that also means you may not be able to register an account later on that service because your phone number's been "used" (and blacklisted due to abuse). 

Today, I just ran into a new spin on this old scam that gave me a chuckle. On reddit's /r/cybersecurity, someone, who may be romance scammed, wrote that someone, who claimed to be in the (US) army, sent her something he claimed to be a STIR verification code, "to verify you exist". 

Clearly, this is a scammer who tried to do the "verification code scam", but this STIR angle is new. 

So what is STIR? It has nothing to do with verification code, at least the type you send via SMS. 

STIR/SHAKEN is a protocol that was being implemented by phone carriers to "authenticate" callers, to combat the spam call problem. Similar to a website using HTTPS instead of regular HTTP, each phone carrier for a business is supposed to link a certificate to the main phone number. So when that caller calls out, the recipient's phone service can look up the certificate, verify it with public key encryption, and thus authenticate that the call did indeed came from that business. STIR is the outbound phase, and SHAKEN is the reverse-lookup/authenticate phase. Once the caller was authenticated, you get a "caller verified" checkmark as your phone receives the actual call. Obviously spammer who spoofed their caller ID cannot pass this authentication, and thus, no checkmark. 

Needless to say, we advise her to drop the scammer like a hot potato. The verification is nonsense and a lie. 

Wednesday, June 5, 2024

Another Suspected Employment Scam, This Time on Craigslist?

Previously I've told you about a suspected bogus job listing on LinkedIn. Well, I am still looking for a job. And this time, I ran into another suspected bogus job listing on Craigslist. 

On May 30th, I replied to a "technical support" position on Craigslist with my resume. The description was a little vague, but not vague to raise suspicion. 

Today, a "Scott" replied, implying he's the employer, but made no specific references to which company he may be replying for. However, I watermark all of my email addresses and resumes so was able to track it back to the job listing on May 30th via Craigslist. (You may want to do that in your future submissions)

Scott basically said that while they have choose their candidates and it was an overwhelming response, he was intrigued by my resume that he's going to refer me to a different guy who's also hiring, except this guy offers to pays double of the original CL job listing. Feel free to use him as a reference, include this email as proof, etc. etc. 

Something sounds fishy already... If you find my resume intriguing, YOU could have forwarded my resume to that guy and put in a good word for me. Why sent it back to me, with instruction to to contact that guy myself? That's just extra rounds of email? 

So I decided to dive deeper, and it's muddy waters indeed. This other guy has a email address with a domain name that IDs as an oil company. 

Googling the oil company shows an actual stock symbol, and a website, AND a LinkedIn Profile... except the website is only one page, no contact info, one address, at the famous New York 55 5th Ave building. The website contains no shot of the office, only of the building. 

The suite number is specifically listed by the leasing office as a SAMPLE UNIT available for lease. 


And the domain name was only registered in January 2024, for ONLY 12 months, and all private details blocked via proxy registar PrivacyGuard. 

Further research shows that the company was merged into a different oil company in 2012, and effectively ceased to exist then. It was headquartered in Texas, and registered as a corporation in Delaware. It was NEVER in New York. 

This is a fake company. And I've been referred to a fake person. 

Which means Scott, who referred me, is very likely fake as well. 

And now he has my resume, and god knows how many other people's resume who sent it in hoping it's a real job offer. 

P.S. "Scott" actually tried to ping me again, asking me did I get hold of his buddy. I did not bother replying. 



Monday, December 12, 2011

When scams attack: using DDOS on critics

One of my most visited websites, BehindMLM.com, is down, and so did its companion site.

As it had worked for months and months without a hiccup, and today is on the eve of a MAJOR announcement in a scam it is tracking, either this is a terrible coincidence, or someone unleashed the "low orbit ion cannon" on it to prevent it from comment on the news.

If this is indeed what happened, this would be a SECOND time an Indian scam has unleashed a cyberattack on a website that criticized the scam. The first time was TVI Express unleashing LOIC on Ted Nuyten's website in the Netherlands.

UPDATE: FALSE ALARM

BehindMLM.com is back, apparently some sort of DNS screwup.

Thursday, November 25, 2010

Another day, another "scam": Hexagonal Water Revitalizer

A local TV station is showing "Water Revitalizer" which supposedly produces a purer "hexagonal water" which is supposedly better for you. (in case you are in the SF Bay Area, it's on the ICN channel, I think it's 26-4 or something like that)

First of all, there is no such thing as hexagonal water. It's something invented by quacks as "pseudo-science" to explain the hexagonal shape crystals the water forms when it freezes, and claims if you can generate hexagonal water it's better for you. Why? Nobody can actually explain.

Chemically it's exactly the same as normal water. It doesn't go through any sort of filter or purification in this special pitcher. All it does, as far as I can tell, is it uses induction to 'spin' the water (kinda like that Nu Wave oven demo). How that generates hexagonal water? No ****ing clue.

Yet you can find one for sale on Amazon for $500 USD ?!?!?!  AND books that touts the supposedly benefits.

It's gotten so bad, even WIRED magazine have an article busting this scam.
Enhanced by Zemanta