Friday, October 9, 2009

Anti-Marketing Campaign Against McDonald's - - McDonald's Australia "Leave Out Items" Memo Hoax

Summary:

Email forwarded supposedly contains a copy of a confidential inter-office memo in which a McDonald's manager advises staff to deliberately leave out products from customer orders as a means of increasing profits.



Commentary:
This widely circulated email supposedly contains a copy of a confidential memo in which a senior McDonald's manager named "Robert Trugabe" suggests that serving staff deliberately leave out items from customer orders as a means of increasing company profits. The memo, which is written on seemingly official McDonald's stationary, contains the following staff advice:
We need to discuss the drive through orders as well. If the girls leave one item out of every second or third order, this adds up to several thousand dollars per week revenue. On smaller orders if they leave out the hot apple pie or fires [sic] and larger orders just 1 burger from every third order this totals around $2,118.00 per day. We need to work out if there is a way of making this a procedure without making it documented.
However, the memo is not from McDonald's Australia and there is no McDonald's manager named "Robert Trugabe". I contacted McDonald's Australia to enquiry about the memo and received the following reply:
Thank you for your email. This memo is a complete fabrication. 'Robert Trugabe' is not a McDonald's Australia employee and never has been. Needless to say the contents of the letter are also completely fabricated. McDonald's practices the highest standards of consumer ethics and would never encourage employees to act in a way that undermines our core customer values.
McDonald's Australia has also published the following customer alert on its website:
The memo in circulation online and via email supposedly written by the Managing Director/Propietor of Frewville McDonald's in South Australia is a complete fabrication. 'Robert Trugabe' is not nor has even been a McDonald's Australia employee. The contents of the letter are also completely fabricated. McDonald's practices the highest standards of consumer ethics and would never encourage employees to act in a way that undermines our core customer values.
An examination of staffing information published on the McDonald's website confirms that there is no managing director named "Robert Trugabe". The name is seemingly a pun on the name of Zimbabwean dictator "Robert Mugabe".

Certainly, big companies can often be quite unscrupulous in their endeavours to maximize profits. However, it is absurd to suggest that a giant and very profitable company like McDonald's would engage in such a desperate and transparent scheme to glean a few extra dollars. Regular and returning customers at suburban McDonald's stores like the one at Frewville would likely be quick to discover any ongoing pattern of missed items. Moreover, in order to be effective, all staff would have to be complicit in the ongoing defrauding of customers and be willing to remain silent about such activities. It is very hard to believe that every one of the "girls" - the wording of the memo suggests that Frewville McDonald's only hires women which in itself is highly questionable - would meekly go along with instructions to deliberately defraud customers.

And, the figures quoted in the message are only realistic if people do not return to collect the items missed from their orders. While a few customers might not have the time or inclination to return to the store, many would certainly do so.

And, finally, it is also extremely hard to believe that any individual that is astute enough to make it to the position of managing director would be so amazingly stupid as to actually document a scheme to deliberately defraud customers thereby risking serious legal and career repercussions when the scheme was inevitable revealed.

Who actually created the fake memo is so far unclear.

Thursday, October 8, 2009

Online Payment Scams Growing in Europe According to EU Report


As the Internet increases in range and wealth of business opportunities, so do criminals up their efforts to develop more sophisticated and effective ways to scam online. Net credit card fraud is growing in Europe, according to an official European Commission report on the web sector, called "Report on fraud regarding non cash means of payments in the EU: the implementation of the 2004-2007 EU Action Plan." The report sums up the problem, saying: "Fraud against means of payment (payment fraud) remains a threat to the success of the internal market for payments. Payment fraud affects the consumer confidence in non-cash means of payment and ultimately the real economy."

While new laws fighting cyber crimes have been passed by many EU members, the European web remains a dangerous place for business, according to the Report. The details are eye-catching, including a figure of 10 million fraudulent web transactions costing EU merchants a 1.5 billion Euros ($2.2 billion) in losses per annum. The Report offers a snapshot of the activity in Net fraud and countermeasures taken between 2004 and 2007, which shows that while the number of fraud cases is a small percent, this illegal shadow still damages overall confidence for online buyers in the EU states.

One of the most problematic areas was the so-called "skimming fraud." The Report details this, saying, "In this situation, the magnetic stripe (not the chip) of cards is copied in payment terminals or, more often, in ATMs or unattended payment terminals (for example those in petrol stations). The copied data (in some cases the PIN code is also captured) are used for the production of counterfeit cards which are then either used in non-EMV terminals (in Europe or in countries where the EMV technology has not been implemented) or for non-face to face payments (e.g. mostly Internet transactions)."

Further, electronic payment fraud has evolved from interpersonal interactions to non face-to-face situations like Internet payments, says the report, with "card-not-present" type of fraud leading the way for growth. The EU is fighting back with several legislative actions addressing these cybercrime issues. One emphasis is meant to fight money-laundering. On this directive, the Report states, "The new directive on the prevention of money laundering of 2005 has introduced more detailed obligations for financial institutions in relation to customer due diligence which at the same time are more flexible and better adapted to the level of risk involved. The implementation of a sound "know your customer" policy by financial institutions should lead to a better management of the fraud risks involved, notably regarding identity theft type of fraud (e.g. when accepting new customers) or non-face to face situations (e.g. When monitoring customers' transactions)."

"The second directive is for services in the internal market (PSD) which was adopted in
2007. The Report states this is aimed at "ensuring that payments within the EU - in particular credit
transfer, direct debit and card payments - become as easy, efficient, and secure as domestic
payments within a Member State are today. By setting up a harmonised legal framework for
payments within the EU, the PSD will provide more transparency and will reinforce the rights
and protection of all the users of payment services (consumers, retailers, large and small
companies as well as public authorities)."

The Report describes these types of online credit card fraud and ID theft crimes as "a moving target," which occurs in many various ways. While identity theft/fraud is an enormous issues, a larger problem has arisen regarding "identity management." In association with the 10 million fraudulent transactions are 500 000 merchants being hit badly. If it becomes ingrained in the average European resident's mind that online transactions are inherently dangerous, it will effect consumer confidence and put the goal of a non-cash economy in danger. Therefore the EU must make sure it is tackling Internet fraud as aggressively as possible.

Nigerian Scams of Huge Lucrative Amounts - - Victims Lost Average of $5500


Have you ever received one of those so-called "confidential" e-mails from the African sub-continent (normally Nigeria) concerning a lucrative proposal? According to such e-mails, all you need to do is something simple and millions of US dollars are yours for the asking. Strange as it may seem, a sizeable number of recipients seem to fall for this approach.

According to the Internet Fraud Complaint Center (IFCC), a partnership that has been forged in the USA between the Federal Bureau of Investigation (FBI) and the National White Collar Crime Center, this type of fraud makes up nearly 15.5% of the 49 711 complaints it received in 2001. Total reported losses, including scams associated with deceptive practices and identify theft, are estimated to exceed $18 million a year.

The "Nigerian" scam usually asks victims for their assistance in transferring funds to an overseas bank account. This assistance is needed urgently, usually because of some tragic set of personal circumstances or because of a worsening political situation. Victims are asked for contact details (telephone number, fax number and address) and bank account information.

At some point, the victims are usually asked to contribute to miscellaneous expenses in the processing and transferring the money to the account. If the victims pay then further problems occur that require more money. This continues until the victims guess what is happening or run out of money; on average the scam nets $5500 a victim and, in one case, the victim lost $78 000.

Cybercrime: A Secret Underground Economy: Cybercriminals Are Making a Killing Off of Stolen Identities


If the word 'cybercrime' conjures up images of computer geeks trying to crash computers from their mothers' basements, think again.

Cybercrime has become a rapidly growing underground business built by savvy criminals, who buy and sell valuable stolen financial information from millions of unsuspecting Internet users every year in an on online black market.

"Most cybercriminals are very, very interested in financial gain by compromising customer accounts," said FBI special agent Austin Berglas, who supervises the Bureau's New York Internet crimes squad. "Believe it or not, there are people who fall victim to their scams, and we see it every day."

Because cybercriminals are so skilled at hacking into thousands of computers every day, the crime is potentially a billion-dollar business. If every stolen credit card and bank account had been wiped clean last year, that would have netted cybercriminals some $8 billion, according to data from Symantec, maker of the Norton antivirus software.

As a result of the lucrative payout, more and more online criminals are entering the game. In fact, the number of new Internet security threats rose nearly three-fold last year to 1.7 million.

Those cyber attacks mostly come from malware, or malicious software, that hands control of your computer, and anything on it or entered into it, over to the bad guys without you even knowing it. The most common forms of malware include keystroke logging, spyware, viruses, worms and Trojan horses.

How the deed is done. Once your information has been stolen, cybercriminals go onto an invitation-only Internet Relay Chat (like a chat group) to do commerce with other online criminals. Cybercriminals will often set up a hacker channel for a matter of days, do business, and then take it down to avoid detection. When active, hacker IRCs can get upwards of 90,000 cybercriminals talking to one another at a given time, according to Dave Cole, senior director of product management at Symantec.

Online criminals use the IRCs to sell or trade your credit card or bank account information. Credit cards are some of the cheapest commodities sold on the Internet Black Market, averaging about 98 cents each when sold in bulk. A full identity goes for just $10.

Credit cards and bank account information made up 51% of the goods advertised on the underground economy last year, up from 38% in 2007. Credit cards are most popular because they're the cheapest stolen commodity. Cards with expiration dates, CVV2 numbers and names go for more than ones with numbers only, but there is no honor in the underground online crime world -- oftentimes hackers will sell the same credit card information to multiple users, and many have already been canceled.

As a result, buyers and sellers on IRC channels will often give the information to a trusted third party for a fee. The third party will test the card information, often by charging a very nominal amount or by posing as a charity, and then verify the goods to the buyer.

After the information is purchased by a secondary criminal, that person can use a machine to print out a fake credit card with your information. But many use yet another tertiary person to wire stolen money into an overseas bank account.

That third person in the chain is usually called a "mule," who often doesn't even know he or she is part of an underground organized crime scheme. Many mules respond to the "make money from home" schemes, where stolen money is sent to their accounts, and they subsequently wire that money to an overseas account for a 10% to 15% fee.

Other mules are given phony ATM cards and are asked to retrieve cash for a small fee. But there is substantial risk involved -- law enforcement usually comes knocking on mules' doors first.

To catch a thief. The FBI is working undercover in many of these IRC channels in an effort to thwart the cybercriminals. And in many cases, captured criminals agree to work for the government in exchange for reduced sentences.

"After we make an arrest for someone cashing out at ATM machines, I'll tell them they can go to jail for 10 years or they can come work for Team America," said Berglas.

The strategy doesn't always work. Albert Gonzalez, the infamous TJ Maxx (TJX, Fortune 500) thief who stole 45 million credit card numbers and private information of 450,000 customers in 2007, was an FBI informant. He helped bring down a massive credit card theft scheme, but double-crossed the FBI, using insider information to help fellow criminals evade detection and carry out the TJ Maxx theft.

Security software also helps, but it far from solves the problem. To avoid detection, many cybercriminals will send out just a handful of viruses before modifying the code and sending it out again.

"The truth is that 'fingerprint' security technology is no longer effective," said Rowan Trollope, senior vice president of product development at Symantec. "The bad guys that got involved are organized professionals, and they figured out how to get around our technology."

Though Trollope said the new version of Norton's antivirus software helps address the problem by scanning for files' reputations, he said that Internet consumers also need know how how to keep their identities safe online.

"We do products really well, but the next step is education," said Trollope. "We can't keep the Internet safe with antivirus software alone."

Everyone Has To Know That "What Exactly Cybercriminals Are Doing Right Now?" To get Them Prepared for Counter Attack

Computer hackers are a ruthless bunch. They are continually on the look out for businesses whose defences are down - even by just a notch. Once they find one, they will go in and exploit them as much as possible, whether that is by stealing information and profiting from it elsewhere, or simply to cause trouble for trouble's sake.

It is no big secret to say that hackers are always progressing and always finding new ways to disrupt businesses and their systems. Many people don't bother to follow what they are doing in any great depth, but if you have your own business (which no doubt relies on computer systems on a daily basis) it may well be in your best interests to keep a finger on the pulse of the hackers and their activities.

By doing so you will have some insight into what the latest threats to your security are. It is a simple fact that whatever steps you take today to maintain your cyber security, those steps may still not be enough tomorrow. Depending on how well you are protected and how quickly you can update your systems to offer better security against what the hackers are currently doing, you may still be at risk of being compromised from time to time.

Unfortunately most of us don't have the time to keep up with the hackers and their tricks when we have a business to run. What's more, most business people don't know the first thing about hacking - unless of course it happens to them and they then have to deal with the consequences.

Fortunately there are ways to stay ahead of the cyber criminals without having to build up a lot of knowledge about them yourselves. If you enlist a team of internet security consultants to test your hardware and software, and perform regular checks on your systems to ensure they comply with all the current known threats that exist, then you stand an excellent chance of staying immune from the hackers that will crash your whole business if they are given half a chance.

Some people are loath to spend any money on making sure their online business is as secure as possible, and yet this can be disastrous. These same people don't think twice about putting security locks on all the doors and windows at their business premises, and perhaps even enlisting the services of a security guard (or several) right round the clock if needed.

Perhaps it is because the threat posed by cyber criminals is an unseen threat. After all, they could be hacking into your systems right now and you might not even realise it at first. This is the main reason why your internet security needs are easy to put on the back burner in favour of dealing with other matters first.

But the secret to combating the cyber criminals successfully is really not a secret at all. What you need to do is stay on top of them every step of the way - and keep yourself well protected as a result.

Netherlands Annual Lottery Promotion - - A Big Lottery Scam


Another Lottery Scam Email to alarm all of my readers that Be Ware! It's a Cyber World.

=================================
De Lotto (Electronic Lotreij)
Postbox 3074
2280 GB Rijswijk
The Netherlands
Ref: NL/8161/99
Batch: NL/BE12-11

Congratulation,

This is to officially notify you that you are amongst the 10 lucky winners
of this year Netherlands Annual Lottery promotion held on the 28Th April
2007. All the 10 winning email addresses were randomly selected from a
batch of 50,000,000 international emails, your email address emerged
alongside 9 others as a category B winner in this year Lotto.nl game draw
consequently, you have therefore been approved for a total pay out of
1,000,000.00 EUR (One Million Euros). In order to avoid unnecessary delays
and complications remember to quote your Ref and Batch number, Ref:
637409467-Nll / Batch 9484-9006-0076 to the fiduciary agent.

Your lucky winning number falls within our European booklet representative
office in Europe. In view of this, your 1,000,000.00 EUR (One Million
Euros) will be released to you by our payment offices in United Kingdom.

For a Dutch understanding winner, you can confirm your winning by Login to
the lottery Website: www.lotto.nl. For security reasons, you are advised to
keep your winning information confidential till your claims is processed
and your money remitted to you in whatever manner you deem fit to claim
your prize, this is part of our precautionary measure to avoid double
claiming and unwarranted abuse of this program.

Please be warned. Remember, all winnings must be claim not later than 15th
May 2007, after this date, unclaimed funds will be returned to the
Netherlands Promotional Headquater as an unclaimed prize, contact Mr. Pedro
Anthony the promotional officer with the details below for further advice.

Mr. Pedro Anthony.
Netherlands lottery Promotional Officer (UK)
Email: meritagency_uk1@yahoo.com

Congratulations once more on your winning award.

Accordingly.
Mrs. Maria Van Boer
Online Coordinator.
Netherlands Promo.

Cybercrime Story - - Steve Managed to Escape From Cyber Criminals Who Were Using "Look-a-Like Web Sites" or "Identical Websites" Weapon


Steve F. lives in the suburbs of Kansas City, Missouri, and is a retired government employee. Steve had antivirus software and a firewall, and kept them up to date. He knew not to click on an attachment in an email if he wasn’t expecting it, and he knew that this precaution applied to email from friends as well as "unknown" senders.

One day last September, Steve received an email that appeared to come from his bank, asking him to logon to his banking and investment account to update his personal information. He clicked on the URL in the email and went directly to his bank’s Web site - or so it seemed. In reality, the URL in the email took Steve to a ‘look-a-like’ Web site. The site looked identical to his own bank site, so when he was asked for his account number, username and password, he automatically started to type them in. Then he remembered something he had heard at a talk given at his local Rotary Club approximately two months before.

The featured speaker talked about pishing attacks – specifically mentioning look-a-like Web sites. The key to recognizing them, Steve remembered, was that a bank would never send its customers an email with a link in it asking customers to click and log in to their account. “If you receive such an email”, said the speaker, “simply discard it.” So he did.

Steve had just been the latest intended victim of the very thing he’d recently heard about - a phishing attack. However, he remembered just in time the simple rule that a bank should never send a Web link asking for personal information via email. Had he entered the information he was asked for, the cybercriminals would have everything they needed to manipulate his banking investment account.
Related Posts Plugin for WordPress, Blogger...