- 12 myths about how the Internet works
- Smartphone smackdown: Storm vs. iPhone
- IETF: Should we ignore the Kaminsky bug?
- Top 10 wicked cool algorithms
- How to recession-proof yourself
A bank-card scammer using stolen Citibank account numbers and PINs netted hundreds of thousands of dollars, but was caught because he didn't spend enough on clothes, according to court documents.
Yuriy Ryabinin, who is charged with unauthorized use of the account information, was identified by the FBI because he always wore the same distinctive sweatshirt when he made the illegal withdrawals.
During a separate FBI investigation, agents using Google searches came across photos of Ryabinin posted on the Internet that were taken in 2002 in which he was wearing the very same sweatshirt. Those photos gave investigators a name to go with the man in the gray, zippered fleece that was captured in multiple ATM surveillance photos, according to affidavits filed by the FBI and the U.S. Secret Service.
Some of the numbers of the accounts Ryabinin is charged with pilfering were lifted from a compromised server set up to handle transactions Citibank customers made at ATM machines located in 7-Eleven stores. The bank has a deal with the convenience-store chain that lets Citibank customers use 7-Eleven ATMs without a fee.
The FBI initially came across Ryabinin's photo during an investigation of compromised accounts in First Bank in St. Louis. His photo -- with him wearing the telltale sweatshirt -- kept popping up on surveillance pictures shot when four First Bank accounts were being tapped at ATM machines in Brooklyn, N.Y.
During one five-minute spree in the early morning of Oct. 1 last year, the accounts were hit for $9,624, according to the FBI court filing. From the photos, the FBI knew it was the same person draining the accounts, but not who he was.
Later, photos of the same man showed up on surveillance tapes at ATMs where $750,000 in illegal withdrawals were made during February alone from accounts compromised by the Citibank 7-Eleven server.
Separately, law enforcement agencies were monitoring Web sites where thieves buy and sell stolen credit- and debit-card information. They flagged one participant who posted the user-ID number associated with the instant-messaging service he bought from ICQ. A cross-check with the ICQ directory showed that the number was associated with a person named Yuri.
Googling the user-ID number also resulted in a link between the number and a person using a certain ham-radio call sign. Googling the call-sign netted photos of Ryabinin at ham-radio conferences in Dayton, Ohio, in 2002 and 2003.
Partner Content
Brilliantly simple security and control solutions for email, web and endpoint
www.sophos.com
Stopping data leakage
Learn how to exploit your current security investment to control the information that flows into, through and out of your network.
Download the white paper.
Why detection rates aren't enough
Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.
Download the white paper.
Applications: taking back control
Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.
Learn more today.
Comment