Online scammers prep for Gustav, say researchers
Nearly 100 domains registered, perhaps for repeat of Katrina phishing attacks
August 31, 2008 12:00 PM ETComputerworld - Nearly 100 domains related to Hurricane Gustav have been registered in the past 48 hours, security experts said Sunday, some of which may be used by bogus charity and relief scams after the storm strikes the U.S. Gulf Coast.
According to television station KTAL in Shreveport, La., the office of Louisiana's Attorney General Buddy Caldwell has warned residents of Gustav phishing attacks already in progress.
On Saturday, Marcus Sachs, director of the SANS Institute's Internet Storm Center (ISC), noted that numerous domains containing the word "gustav," "charity," "hurricane" and "relief" had been recently registered.
"On the day [Hurricane] Katrina hit New Orleans [in 2005] hundreds of donation sites appeared online, many if not most were scam sites," said Sachs in a post yesterday to the ISC research blog. "Well, this time around, it looks like the people who like to register domain names in anticipation of a storm's arrival have already started registering them for Gustav."
By Sunday, Sachs had listed almost 100 Gustav sites culled from the DomainTools' Web site. "Most of these sites are parked domains and many of them are for sale," he said. "They will be worth monitoring, particularly if 'donate here' messages appear."
Several of the domains, in fact, do appear to be parked, or registered but not fleshed out with content. Others, including helpgustavictims.com and helpgustavvictions.net, were for sale on eBay as of midday Sunday.
A few, however, led to legitimate charities. The domain gustavcharity.com, for example, redirected users to the Web site of the evangelical Christian organization "Samaritan's Purse," while contributegustav.org took users to the Baton Rouge Area Foundation's site.
Another security expert, Gary Warner, director of research in computer forensics at the University of Alabama at Birmingham, also posted a list of parked domains that may be used for scamming purposes. "Anytime we've seen a natural disaster, we've been on the lookup for domains which might be abused for fraud," said Warner Sunday on his blog. "It was only natural then that I retuned my settings at DomainTools yesterday to alert on Gustav domains."
Warner also pointed out a handful of domains that led to legitimate content.
Three years ago, before and after Hurricane Katrina slammed into New Orleans, security researchers noted a similar run-up of domain registrations. Enough were used for phony relief scams, often by identity thieves hoping to trick consumers into divulging personal information, that the U.S. Department of Justice set up a Katrina antifraud task force.
More than a year later, two brothers were convicted on federal charges for running a fake Salvation Army site that solicited money, supposedly for Katrina relief efforts. The pair, Steven and Bartholomew Stephens, were sentenced to more than 100 months in prison for the scam last December.
Hurricane Gustav
Additional Resources



White Papers & Webcasts
Data Protection is not an insurance policy -you cannot buy-back lost data
Find out why you need to maintain access to critical information to run your business and remain competitive.
Essential Archive Requirements for E-Discovery
Register Now!
Strategic ECM Webinar
Learn what new strategic business benefits can be realized through ECM!
CIO Strategies for the Retention and Deletion of Email
Register Now!
Rethinking Business Continuity and High Availability in Storage - HP and Forrester Pre-Recorded Webcast
Download it.
CIO Viewpoints: Exchange 2007 Risks and Mitigation Strategies
Download This Whitepaper Today!
5 Architecture Issues that Impact BES performance
Register to attend this LIVE Webinar to learn 5 Architecture Issues that Impact BES performance!
The Power/Density Paradox: The Result of High Density without Power Efficiency
Download this brief to explore what the power/density paradox is and how IT professionals can mitigate the risk.
Four Principles for Reducing Storage TCO
View cost reduction strategies in this video! Provided by Hitachi Data Systems.
