Webster

The Constitution was made to guard the people against the dangers of good intentions." --American Statesman Daniel Webster (1782-1852)


Showing posts with label Scams. Show all posts
Showing posts with label Scams. Show all posts

Thursday, April 16, 2026

"Stolen Identity Refund Fraud" (SIRF)

 

Since it is Tax season, I figured I would add this to my blog read, I shamelessly clipped this from "MalwareBytes Lab"  Every 2 weeks I get a news info from my employer on the latest scams that are running today and I make an attempt to stay informed.  I am amazed on the creativity of the scammers.  I cut and pasted the article, I hope the entire article came through, it is very informative.  

Your tax forms sell for $20 on the dark web

 | March 19, 2026
Tax scams on the dark web

Tax season is also peak season for identity theft. Criminals use stolen personal data to file fake tax returns and claim refunds before the real taxpayer does. Here’s how the fraud works, and how to protect yourself.

What is Stolen Identity Refund Fraud (SIRF)?

Stolen Identity Refund Fraud (SIRF) is a type of tax fraud where criminals steal someone’s personal information—such as a Social Security number and date of birth—and use it to file a fake tax return in that person’s name in order to claim a tax refund.

The fraudsters usually submit the false return early in the tax season before the real taxpayer files, so the refund is issued to them instead of the legitimate person.

The money is often sent to bank accounts, debit cards, or addresses controlled by the criminals. Victims usually discover the fraud only when their real tax return is rejected or when the tax authority, like the US Internal Revenue Service (IRS), reports that a refund has already been issued in their name.

How is it even possible? 

As Americans scramble to meet the annual tax filing deadline, a hidden ecosystem on the Dark Web kicks into overdrive, transforming tax season into a lucrative period of the year for international cybercriminals.  Shahak Shalev, Global Head of Scam and AI Research at Malwarebytes, said:

“People are expecting messages about taxes, refunds, and filings, which makes phishing emails and fake IRS alerts much easier to believe. At the same time, the personal data needed to commit tax fraud is shockingly cheap on the dark web. It’s no surprise scammers treat tax season like an annual opportunity.”

Behind the sudden influx of fraudulent refund claims lies a highly organized criminal supply chain deeply rooted in Russian-language underground forums. These specialized platforms act as the primary enablers of tax fraud.  

Rather than harvesting data from scratch, fraudsters can simply purchase massive datasets of stolen Personally Identifiable Information (PII), complete with ready-to-use W-2 and 1040 forms. For more sophisticated operations, Initial Access Brokers (IABs) auction off direct network access to compromised Certified Public Accountants (CPAs) and accounting firms.  

Beyond raw data and access, this underground economy provides a full suite of “fraud-as-a-service” tools—including on-demand services to forge supporting financial documents and dedicated instructional hubs featuring step-by-step tutorials. 

The black market of PII 

At the epicenter of this illicit commerce is one of the premier Russian-language underground forums, which serves as the definitive marketplace for fraudsters to buy and offload tax-related PII. The commoditization of this data is staggering in its efficiency, operating much like a traditional e-commerce platform.  

Our research team has captured several compelling samples of this trading activity, highlighting a clear pricing tier based on the freshness of the data and the target demographic. In one recently observed listing, a threat actor advertised a bulk package of 100 complete tax forms for $2,000—effectively pricing a fully documented stolen identity at just $20.  

Conversely, older data dumps from the 2024 tax year are heavily discounted to clear inventory; highly sensitive records specifically belonging to wealthy retirees and pensioners from that period are currently being traded for less than $4 per identity. 

Access for sale 

This staggering volume of tax-related data must originate from somewhere, and threat actors have identified the ultimate jackpot: US companies that handle tax preparation and accounting procedures.  

From an attacker’s perspective, it is infinitely more efficient to breach a dedicated business that serves as a centralized vault for this sensitive information than to cast a wide net trying to trick individual citizens into handing over their personal details. 



Our research team recently intercepted a prime example of this strategy in action, identifying a Dark Web listing for compromised network access to a US-based tax service firm. The victimized organization is a small business; a typical target of criminals looking for easy access for exploitable information.

Exploiting these systemic weaknesses, the threat actor was able to quietly infiltrate the company’s internal infrastructure and is now auctioning off direct access to a database containing the complete, highly sensitive PII of over 1,600 clients. 

A threat actor auctioning off access to a database of PII of more than 1,600 customers
A threat actor auctioning off access to a database of PII of more than 1,600 customers

Additional data for sale 

Even when threat actors encounter roadblocks during the fraud process—such as a missing piece of PII or a highly specific financial document required for verification—the cybercrime underground offers a comprehensive suite of on-demand services to seamlessly solve these issues.  

Our research team has tracked a dedicated black market known as “Cypher – Fullz and Docs,” which specializes in selling complete, ready-to-use sets of stolen US identities (commonly referred to in the underground as “fullz”) for as little as $0.75 per set.  

However, having the basic data is sometimes not enough to bypass required checks.

When additional paperwork is required to legitimize a fraudulent claim, threat actors simply turn to specialized forgery services like “Fakelab.” For a nominal fee ranging between $20 and $40, Fakelab operates as an illicit digital design studio, meticulously forging any tax-related document an attacker might need, from customized W-2s to realistic bank statement, ensuring the scam can proceed without a hitch. 

Tutorials and guidance 

The culmination of the tax fraud lifecycle—and often the most precarious phase for the attacker—is the cashout. To successfully finalize the scam and extract the stolen funds, fraudsters require a robust financial infrastructure, typically relying on compromised “drop” bank accounts and supplementary financial tools designed to launder the money and obscure their tracks.  

Unsurprisingly, the Dark Web ecosystem provides not just the tools but the detailed education necessary to execute this critical phase. Our research team identified a dedicated underground resource known as “Flava,” which serves as a centralized instructional hub. This platform is brimming with comprehensive, step-by-step tutorials specifically detailing how to orchestrate these complex cashout schemes targeting US citizens and residents. 

A Russian-language marketplace related to financial fraud techniques.
A Russian-language marketplace related to financial fraud techniques.

How to stay safe

Stolen Identity Refund Fraud is a reminder that identity theft doesn’t just lead fraudulent purchases. It can impact something as fundamental as filing your taxes.

Cybercriminals take advantage of underground marketplaces that sell stolen personal data, compromised business access, and tools designed to support fraud. It makes it easier for criminals to file fake tax returns quickly and at scale.

For taxpayers, the best defense is limiting the amount of personal data available to criminals, filing your taxes early, and paying attention to any warning signs that someone may be trying to use your identity.

Tax fraud often depends on criminals getting access to your personal information first. The less data they have, the harder it is for them to impersonate you. Here are some steps that can help reduce your risk:

  • File your taxes early. Submitting your legitimate tax return early makes it much harder for criminals to file one in your name first.
  • Protect your Social Security number. Avoid sharing your Social Security number unless it’s absolutely necessary.
  • Watch out for phishing emails and texts. Scammers often pose as the IRS, banks, or tax services to trick people into revealing personal data.
  • Use strong, unique passwords. If criminals gain access to your email or financial accounts, they may be able to collect the information needed to impersonate you.
  • Monitor your accounts and credit reports. Unexpected tax notices, rejected returns, or unfamiliar financial activity can all be warning signs of identity theft.
  • Consider an IRS Identity Protection PIN (IP PIN). An IP PIN adds an extra verification step when filing your tax return, helping prevent criminals from filing in your name.

Note: These dark web screenshots have been roughly translated from Russian. 


What do cybercriminals know about you?

Use Malwarebytes’ free Digital Footprint scan to see whether your personal information has been exposed online.

Saturday, April 19, 2025

"Delete All Text on your phone if you see these 2 words."

 

I don't know about y'all but I keep geting these stupid text saying that my "Peachpass" isn't paid and I need to settle up now before I get tickets and lose my license.  Any state that uses any kind of toll system will get these scams.  See they have several *tells*  First the urgency, YOU MUST PAY IMMEDIATELY*  Then they warn of the consequences...YOU WILL GET TICKETS AND LOSE YOUR LICENSE. They prey on the those that frighten easily.  those are a couple of the *Tells* and then they furnish a hyperlink in the text so you can pay the bill, it will take you to an "official looking website: but if you look closely at the address line of the site, it ain't gonna match or if you hover a curser over it it will show the embedded link inside the words.  This is just an example of a scam

    I'm gonna show y; all another, scam is from the movie "The BeeKeeper" with Jason Statham, 


  This shows how a scam runs on one of those *fake Virus* sites  Dang good movie btw.  You notice that she hesitated, her gut was telling her that something was wrong but she ignored her gut and did it anyway.  

    I saw this article on on Forbes, it was the genesis for todays post.


Update: Republished on April 18 with multiple new warnings as threat soars.

iPhone and Android users across the U.S. and elsewhere are now under attack from organized networks of Chinese criminals. These attacks come at you by text, and while they may seem trivial — a few dollars for an undelivered package or unpaid toll, they will steal your credit card details, your passwords and even your identity.

New research into one such gang — Smishing Triad — warns that there has been a “massive fraud campaign expansion” since the beginning of 2025, using more than 60,000 different web domains, “making it difficult for platforms like Apple and Android to block fraudulent activity effectively." This is why you will have seen so many news articles on the spate of toll fraud sweeping across America.

Zimperium’s Kern Smith told me that “the latest wave of mobile SMS scams is a stark reminder that mobile devices and apps are uniquely vulnerable — and often under protected — against attackers," while the new reports “show the continued investment by cybercriminals in targeting mobile users.”

Each dangerous text includes a lure — the unpaid toll for example — and a link. The text will pretend to come from a brand or goverment agency and the link will be crafted to match the lure, likely a long URL with the right keywords contained within.

Even if the text itself seems plausible, the link is a telltale red flag. It will usually use a top level domain (TLD) from outside the U.S., and it will not match the core domain you would associate with the brand or agency.

To get around that problem, attackers are using dashes to trick users into thinking this is a legitimate link using that core domain. And the most dangerous dash follows a “.com”. That makes you think it links the normal .com domain to a subdomain, but that’s not the case. It’s a ruse to hide a full legitimate domain within a malicious link.

This trick is flying. The latest quarterly report from SpamHaus lists the top-2o phishing terms included in malicious links, warning that “com-track” is a new entry that has gone straight to number one on its list. This would allow an attacker to copy delivery or ecom brand followed by its usual .com, but with an added “-track” after the legitimate URL.

If you ever see “com-track” in a link, delete the text immediately per the FBI’s advice. It’s a scam. Similarly, “com-toll” is another new entry on the list and you can expect more of the same to be added quickly as these others take hold.

The other telltale warning sign is a Chinese TLD — albeit you won’t realize it’s Chinese from the TLD itself. Look out for “.TOP” in particular as that’s the TLD favored by cybercriminals and again is cause on its own for you to delete a text.

According to the Anti-Phishing Working Group (APWG), a Chinese top level domain is “one way to spot these scam messages.” Look for “lesser-known TLDs such as .TOP, .CYOU, and .XIN.” The .TOP domain in particular "has a notable history of being used by phishers.” APWG says “ICANN issued a breach letter to .TOP Registry in July 2024, citing .TOP’s failures to comply with abuse reporting and mitigation requirements, and as of March 2025 the case is still listed as unresolved on ICANN’s Web site.”

Unsurprisingly, the problem is quickly getting worse. America’s Federal Trade Commission (FTC) has just reported that new data “shows that in 2024, consumers reported losing $470 million to scams that started with text messages.” And while “the most commonly reported type of text scam was fake package delivery,” others included “fake ‘fraud alert’ messages sent to consumers warning about a suspicious purchase or an issue with their bank; warnings about fake unpaid tolls with a link to pay them; and ‘wrong number’ scams that start as a seemingly misdirected message.”

According to Silent Push, one Chinese phishing gang alone, Smishing Triad, “generated over one million page visits within a period of only 20 days, averaging 50,000 per day. Based on this data, we believe the actual number of messages sent may be significantly higher than the current public estimates of 100,000 SMS messages sent per day.”

An alarming new report from Trend Micro warns that “March saw a massive 247% increase in scam texts… With the adoption of AI, scammers are constantly shifting their tactics to stay ahead, and it shows, with more consumers falling into a false sense of security – making it easy for cyber criminals to strike.”

Building on the tracking lure per those top phishing terms, Trend Micro reports that “the newest edition to our list is Chinese clothing manufacturer Shien. Scammers have recently been posing as Shein with fake delivery updates, attempting to catch unsuspecting shoppers out. These texts have been seen to include links to phishing sites that steal personal or payment details. It can be difficult to navigate Shien texts as the company does send its customers updates via SMS. If you haven’t ordered recently or have found a message that feels off, it’s best to delete it — Shein won’t text you out of the blue with suspicious links.” The same is true for almost all blue chip retailers.

March is not a one off — just a quickly accelerating theme. According to the research team, “SMS scams [in February] increased by 73% compared to January… Prize, lottery, and survey scams continue to be the most common, consistently deceiving consumers with fraudulent offers. This type of scam remains popular among cyber criminals due to its effectiveness in luring unsuspecting victims. In total, these scams accounted for nearly half of all the fraudulent messages sent in February.”

But while many SMS attacks follow these traditional lures, crypto has also become an increasing focus just as we see in all other areas of cyber. “Cryptocurrency exchanges are now a frequent victim of impersonation attacks… The messages may claim that there is unusual activity on the account, urgent verification is needed, or withdrawal pending. The purpose of these scams is to cause panic, prompt users to click on spoofed links, and convince them to reveal login credentials or one-time passwords. These scams are particularly dangerous in that they are targeting users on their phones directly, bypassing normal email spam filters.”

Even the new trade war and tariff battle has become a theme for such attacks. According to BforeAI, “cybercriminals have launched a wave of scam and hate campaigns leveraging the ripple effects of tariff interest and coverage. A significant surge totaling 301 domain registrations was seen in the first three months of 2025. Surprisingly, only one typosquat, ‘tarrif’, was identified, indicating the cybercriminals’ preference in taking a more direct approach to support the scams.”

Don’t take any risks. Don’t click links in texts. These scams have been industrialized and are fast becoming the most likely way you’ll be defrauded.

Friday, June 2, 2017

Trump Pulled us out of the Paris agreement....

Well accoording to the angry left, Trump shafted our grand-kids and retreated from the world stage by pulling us out of the Paris accords and they are having an apocalyptic fit from the news and Drudge.

    My attitude......Good!, the climate change is income distribution on a grand scale from the industrialized world to the 3rd world,  The leaders fly around in their jets especially Al the hypocrite Gore and every time he flies somewhere he barfs out more carbon than the average American family does in a year....but somehow we have to be on the hook for it?
      These climate change fanatics think that man controls the weather. Nope. Look up in the sky. See that big yellow ball? That is what controls the weather. Six hundred years ago the planet was warmer than it is now. At that time Greenland was actually green. That is how it got its name. It was self-sufficient. Was the world a worse place back then? Nope. Were there a lot of SUVs and coal fired power plants back then? Nope. Then, the Little Ice Age hit. Greenland was no longer self-sufficient. The climate in Vineland (the part of North America the Vikings visited) was no longer benevolent.
Back in the 70’s the big worry was global cooling as the Environmental fanatics thought we were headed into another ice age. All of the climate models showed it. Now, we’re heating up. Except we are not. That’s why they had to change the name from global warming to global cooling to climate change. "Climate Change" is just a scam to cripple capitalist economies and to scam them into giving money to Third World countries. Of course, that money won’t go to the countries but to their corrupt rulers. The real science deniers are the Climate change crowd who won’t release their raw climate data and refuse to subject it to rigorous scientific testing.
     A volcano spews more CO2 into the atmosphere than man does. And where does this crap that CO2 is bad comes from? It is an essential gas for life on this planet.   I swear these people are the new "Chicken Littles" of the modern age.    The scientist that have bought into the "global warming" scam do it to guarentee funding and if anybody disagrees with them, OMG,,"Heresy" and the offenders are "Tarred and feathered" professionally.  It is like the witch hunts of the modern era, if you disagree with dogma the modern age inquisition pays you a visit.
      Now I will tell what I believe will happen...Trump will revisit this in a few months and make a new deal and then pass it to the senate for ratification as it should have been done in the first place and let the democrats that are in danger of losing their seats vote "Yes" or "No".  This will be constitutionally sound and give him political cover.

Tuesday, October 23, 2012

The Taxpayer subsized green energy failures...





It is no secret that President Obama’s and green-energy supporters’ (from both parties) foray into venture capitalism has not gone well. But the extent of its failure has been largely ignored by the press. Sure, single instances garner attention as they happen, but they ignore past failures in order to make it seem like a rare case.
The truth is that the problem is widespread. The government’s picking winners and losers in the energy market has cost taxpayers billions of dollars, and the rate of failure, cronyism, and corruption at the companies receiving the subsidies is substantial. The fact that some companies are not under financial duress does not make the policy a success. It simply means that our taxpayer dollars subsidized companies that would’ve found the financial support in the private market.
So far, 34 companies that were offered federal support from taxpayers are faltering — either having gone bankrupt or laying off workers or heading for bankruptcy. This list includes only those companies that received federal money from the Obama Administration’s Department of Energy and other agencies. The amount of money indicated does not reflect how much was actually received or spent but how much was offered. The amount also does not include other state, local, and federal tax credits and subsidies, which push the amount of money these companies have received from taxpayers even higher.
The complete list of faltering or bankrupt green-energy companies:
  1. Evergreen Solar ($25 million)*
  2. SpectraWatt ($500,000)*
  3. Solyndra ($535 million)*
  4. Beacon Power ($43 million)*
  5. Nevada Geothermal ($98.5 million)
  6. SunPower ($1.2 billion)
  7. First Solar ($1.46 billion)
  8. Babcock and Brown ($178 million)
  9. EnerDel’s subsidiary Ener1 ($118.5 million)*
  10. Amonix ($5.9 million)
  11. Fisker Automotive ($529 million)
  12. Abound Solar ($400 million)*
  13. A123 Systems ($279 million)*
  14. Willard and Kelsey Solar Group ($700,981)*
  15. Johnson Controls ($299 million)
  16. Schneider Electric ($86 million)
  17. Brightsource ($1.6 billion)
  18. ECOtality ($126.2 million)
  19. Raser Technologies ($33 million)*
  20. Energy Conversion Devices ($13.3 million)*
  21. Mountain Plaza, Inc. ($2 million)*
  22. Olsen’s Crop Service and Olsen’s Mills Acquisition Company ($10 million)*
  23. Range Fuels ($80 million)*
  24. Thompson River Power ($6.5 million)*
  25. Stirling Energy Systems ($7 million)*
  26. Azure Dynamics ($5.4 million)*
  27. GreenVolts ($500,000)
  28. Vestas ($50 million)
  29. LG Chem’s subsidiary Compact Power ($151 million)
  30. Nordic Windpower ($16 million)*
  31. Navistar ($39 million)
  32. Satcon ($3 million)*
  33. Konarka Technologies Inc. ($20 million)*
  34. Mascoma Corp. ($100 million)
*Denotes companies that have filed for bankruptcy.
The problem begins with the issue of government picking winners and losers in the first place. Venture capitalist firms exist for this very reason, and they choose what to invest in by looking at companies’ business models and deciding if they are worthy. When the government plays venture capitalist, it tends to reward companies that are connected to the policymakers themselves or because it sounds nice to “invest” in green energy.
The 2009 stimulus set aside $80 billion to subsidize politically preferred energy projects. Since that time, 1,900 investigations have been opened to look into stimulus waste, fraud, and abuse (although not all are linked to the green-energy funds), and nearly 600 convictions have been made. Of that $80 billion in clean energy loans, grants, and tax credits, at least 10 percent has gone to companies that have since either gone bankrupt or are circling the drain.
CORRECTION:
Figures for four companies have been updated: Beacon Power received $43 million from the U.S. government, not $69 million as originally reported. Azure Dynamics received $5.4 million from the federal government, not $120 million as originally reported. Compact Power Inc. received $151 million as part of the stimulus, not $150 million as originally reported. Willard and Kelsey Solar Group received $700,981 in government funding, not $6 million as originally reported.
The following companies have been removed from the original list: AES’s subsidiary Eastern Energy, LSP Energy and Uni-Solar did not receive government-backed loans, based on additional research. The National Renewable Energy Lab did received $200 million in stimulus funding, but it is a government laboratory.