Katrina scams proliferate
PC World - Hurricane Katrina is still wreaking havoc online weeks after its initial punch. Katrina scams are showing up in inboxes and on Web sites, preying on the good-willed, the vulnerable, and even sometimes the greedy.
Scams include identity theft, Trojan horses, bogus investments, and credit card fraud. Some experts warn of upcoming rip-offs like thousands of severely water-damaged (and smelly) cars from Louisiana being hawked online as in good condition.
Phishing scams
The most popular scam seems to be a ploy to get you to divulge your credit card number or PayPal account information. Many phishing scams in which people receive e-mails that link to Web sites that look similar to legitimate charity sites have been reported.
Missouri and Florida both took action earlier this month to shut down Web sites with names such as katrinahelp.com and katrinafamilies.com. On Sept. 2, Florida Attorney General Charlie Crist filed a civil lawsuit in Nassau County, Florida Circuit Court against Robert Moneyhan, the Webmaster for katrinahelp.com, katrinadonations.com, katrinarelieffund.com, and katrinarelief.com. Moneyhan allegedly used these sites to direct donations to his private PayPal account.
Bogus sites
Suspicious Katrina help sites are commonplace, law enforcement officials say. The Federal Trade Commission warns that con artists are taking advantage of the disaster to rip off people who want to help victims of the hurricane.
The FBI says 60% of the 2,000 sites it has reviewed that claim to offer aid to Katrina victims are registered to people outside the U.S.. In a statement, the agency warns that these sites are likely to be fraudulent.
More than 2,500 storm-related sites have been registered since August, including 450 domains with the word Katrina in them, according to the SANS Institute's Internet Storm Center. The majority of those sites are still "under construction," says the ISC.
News leading to Trojan horses
There have increasingly been reports of hackers pasting news about the hurricane into e-mails with "read more" links. Those who click on the links are unwittingly taken to Web sites that secretly install Trojan horse software that gives hackers control over their computer.
For example, experts at both OnlyMyEmail and F-Secure report that they have seen e-mail containing news stories about the Katrina disaster efforts, with a link to "read more" that sends readers to a site that uses a browser security exploit to install the malicious Phel program.
Illegitimate investments
Some con artists are trying to persuade people to invest in post-Katrina stock scams. The Security and Exchange Commission recently issued a warning about investment scams tied to



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Overcome Top 7 Admin Challenges of Active Directory
- As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
- Insiders Can Ruin Your Company. Take Action.
- Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
- Top Solutions and Tools to Prevent Devastating Malware
- Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
- X-Ray of the PCI Process-4 Proactive Steps
- This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into...
- Identity Governance: The Business Imperatives
- This white paper describes the business challenges and opportunities that are driving interest in Identity Governance while discussing considerations your organization should make... All Security White Papers
- Live Webcast
Playing Defense: Staying on Top of Your Disaster Recovery Game - When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing...
- Introduction to VMware vCenter Site Recovery Manager 5
- Traditional disaster recovery solutions are often too expensive, complex and unreliable to meet business requirements. As a result, IT departments are hesitant to...
- The Top Ten Secrets to Avoiding SAN Performance Problems
- Maintaining peak performance while simultaneously addressing the root cause of SAN errors is challenging. Learn the most common SAN problems and explore new...
- Deduplication Without Compromise
- Go inside Quantum's scalable, high-performance, multi-protocol new DXi deduplication appliances, designed to make backup much more effective. Discover how the new future-proof DXi6700...
- Director of Disk Products Discusses DXi6700
- Discover how the new DXi 6700 series of deduplication appliances provide investment protection and a future-proof feature set, all while delivering fast, scalable,...
- Playing Defense: Staying on Top of Your Disaster Recovery Game
- When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing... All Security Webcasts