Please wait while the page is being loaded Skip this advertisement >
Saturday | 22 November, 2008
ARN

Man arrested for P-to-P ID theft

A Seattle man has been charged with using P-to-P networks to steal sensitive information from victims.
Robert McMillan (IDG News Service) 07 September, 2007 08:37:42

A man from Seattle, Washington, faces as many as 29 years in prison after being charged with using the LimeWire and Soulseek P-to-P (peer-to-peer) networks to commit identity theft.

Gregory Kopiloff was arrested Wednesday on charges of mail fraud, accessing a protected computer without authorization and two counts of aggravated identity theft, said Emily Langlie, a spokeswoman with the U.S. Attorney's Office for the Western District of Washington. This is the first case that Langlie's office is aware of that involves P-to-P identity-theft charges, she said.

In court filings, federal prosecutors alleged that Kopiloff began the scam around March 2005, using the P-to-P networks to search for victims who had accidentally configured their software to share sensitive documents. Hard drives were searched for "federal income tax returns, student financial aid applications and credit reports that had been stored electronically," court filings state.

Using that information, Kopiloff would fill out online credit-card applications, and then buy products such as iPods or computer hard drives, which he then resold for cash, typically at about US$0.50 on the dollar, federal prosecutors claim.

And Kopiloff wouldn't steal just anybody's identity, according to Kathryn Warma, assistant US attorney for the Western District of Washington. During a conference call Thursday, she claimed that he'd first run credit checks on potential victims to ensure that they had at least US$150,000 in annual income. "Mr. Kopiloff was no slouch," she said.

Kopiloff was allegedly able to buy more than US$73,000 worth of merchandise using online credit-card accounts he'd set up using the identities of at least 83 victims.

It's easy for unsophisticated users to accidentally share sensitive information via P-to-P networks said Christopher Boyd, director of malware research with FaceTime Communications. "Some P2P programs have 'share folder' options and if you accidentally hit it, bam -- it's out there without you even knowing about it," he said in an instant-message interview.

But luckily there's an easy fix for the problem. Boyd recommends that P-to-P users place all of their sensitive documents on a stand-alone drive, separate from the main PC. "It's about the best way to ensure you don't accidentally share your life story with the rest of the world via P2P," he said.

While Kopiloff may be the first to be arrested for this type of P-to-P crime, others have caught on to the idea. P-to-P network monitoring company Tiversa Inc. recently spent 13 days monitoring queries on P-to-P networks, logging more than 55,000 searches for the term "credit card," and more than 70,000 searches for credit card names such as Visa or American Express.

"We were able to see people searching for credit card information," said Tiversa CEO Robert Boback during the Thursday conference call. "We were also able to see this credit card information," he added.

Related Stories
  • +

    True crime: The botnet barons 04 January, 2008 07:03:57

    Two weeks ago, the feds revealed the names of eight people who had used botnets to engage in nefarious activity. Here are their stories
    When federal agents announced on November 29 that they'd indicted or convicted eight individuals accused of using botnets (networks of computers infected with Trojan horse applications) to engage in criminal activity, the press release barely explained the nature and extent of the men's crimes -- or the investigations that led to arrests in an operation the FBI and other law enforcement agencies have termed Bot Roast II.
  • +

    The 2007 security hall of shame 27 December, 2007 07:47:46

    Bad breaches, ghastly gaffes and five people we'd like to forget
    How bad was 2007 for breaches, vulnerabilities and similar mayhem? On the bright side, it was better than 2008 is forecast to be. With more of every sort of meltdown predicted -- more criminalization of the hacker community, more Web-application attacks, more phishing, more spamming, more zero-day attacks and more virtualization-related threats -- we're happy to tell you that you are likely to look back on 2007 as the peaceful old days.
Additional Resources
ARN Library
Newsletter Subscription
Sign up for our ARN newsletters!
RSS Feeds
Market Place
 
Panel Sessions
  • ARN Panel Sessions: Day 3

    The last of our panel sessions recorded live at CeBIT 2008. Today, the topic is storage. Data is growing at an enormous rate, so what does the future hold?

Play
ARN news
Play
Channel Watch
Play
Business Continuity & Disaster Recovery Zone

When an IT disaster occurs, how handy it would be to push a button and start again as if nothing had happened.
Discover and learn more about CA XOSoft today.
ARN Vendor Directory
ARN Library

Understanding Email Marketing: A Guide for SMBs

Email marketing is often viewed as a marketers silver bullet. If used effectively, email campaigns will provide strong results for a limited spend each and every time. Download this white paper to discover how email marketing can work for you and your business.

Sponsored Links