PDA

View Full Version : Beyond CSI: Credit Card compromised..looking for suggestions :)



eblend
10-20-2010, 02:56 PM
Hi Guys,

So I login to my credit card website yesturday like I do every day, just to see what temp authorizations are happening as my card shows all authorizations against it right on the web, instead of just when they are actually posted. I noticed that I had a strange 1.01 dollar authorization from RN Real.com that I didn't recorgnize...so I did some googleing and found this page

http://www.consumercomplaints.in/complaints/rn-realcom-c90172.html

So looks like a scam. I did just update my ebay credit card information on ebay so didn't think much of it because ebay usually does a $1 dollar charge whenever you make a change to make sure the card is legit. Anyways, I thought that perhaps the RN real.com was some soft of a generic name until the actual charge is posted, possibly related to ebay, so I ignored it.

Today I was miding my own business, when all of the sudden I got an e-mail from Dell...I opened it up and sure enough, there is a "Here is your quote" e-mail for 2 x 15r laptops with the personal contact info of the agent who put the order through. As I sensed something was off, I quickly logged onto my credit card company website and sure enough, there is a $1400 preauthorization sitting there from DELL. I instantly called my credit card company to get my card canceled and tell them about the two fraudulant charges and the canceld the card right away.

I also called Dell and spoke to the agent who placed the call, and informed him that I did not order anything and that this is a case of fraud. He asked me to write back an e-mail to him so they have a record and that he will cancel the order right away (not like they could actually put it through anymore, since the card is already canceled and the laptops were not to ship until the 25th).

Anyways, looking at the dell "quote", it shows my billing information with my name and my address, as well as my cell phone number, and then shows my name and my phone number for shipping information, but an address in Ontario.

This is the address:

323, Cunningham Ave
Ottawa, On K1H6B2

I did a quick google maps search, and this seems to be the house:

http://maps.google.ca/maps?f=q&source=s_q&hl=en&geocode=&q=323+cunningham+ave++K1H6B2&sll=49.891235,-97.15369&sspn=31.998492,64.423828&ie=UTF8&hq=&hnear=323+Cunningham+Ave,+Ottawa,+Ottawa+Division,+Ontario+K1H+6B4&ll=45.388686,-75.657392&spn=0,0.015728&z=16&layer=c&cbll=45.38933,-75.658478&panoid=1dxdOfiYbNEx6xwDIzdEvw&cbp=12,20.87,,1,2.52

At any rate, this guy obviously somehow knows my address, phone number and obviously my old credit card number. I have no idea how they might have gotten all of that info, but regardless, I changed all my passwords on everything. Obviously the guy somehow also knew my e-mail address as the order came to my address...come to think of it, maybe he hacked my dell account, I will verify.

Anyways, with all of the information he has, is there anything I should do to protect myself? I work in IT so I keep my shit clean in terms of viruses on the computer and all that, so this is really a surprise to me.

Also, anyone live in ON and want to check out the house for me....see this scammer, maybe record an undercover video?

I am thinking of sending a package to him filled with shit (real stuff) (in a dell box from work), however the fact that he has my address is concerning. I could send it with a different address, but still, don't know if I am the only person he scammed or not. Any ideas, all welcome :)

Modelexis
10-20-2010, 03:01 PM
My guess would be a teen or pre teen lives there and has pretty crazy computer skills and managed to find a source to pull CC info from somewhere you're listed.

More skills than I had when I was a teen.
Best I ever did was open a few CD-rom drives and retrieve the admin password for the computer lab in highschool.

BrknFngrs
10-20-2010, 03:02 PM
Glad to hear you headed it off before any charges went through. Which bank are you with that you can see pre-authorizations before they actually post on your card? That sounds like a feature I'd really like to have.

eblend
10-20-2010, 03:08 PM
MBNA is the bank. It is an awesome feature, and is my primary reason to going with MBNA actually. I have their platinum cashback card which gets my 1% on everything and 3% on gas and groceries, works well and haven't had any issues until today.

It appears that perhaps my Dell account was compomised, as I logged into it and sure enough, the order is sitting in there. That account had this CC listed, as well as the e-mail. The dude never changed any passwords (that would be the first thing I do if I got access to someones account that I wanted to fuck over)

Dell has also e-mailed me back to confirm that that order is canceled.

AndyL
10-20-2010, 03:20 PM
Call the ottawa police - let the order ship and have a few officers waiting to haul the kid off to jail? :)

eblend
10-20-2010, 03:27 PM
Originally posted by AndyL
Call the ottawa police - let the order ship and have a few officers waiting to haul the kid off to jail? :)

Well the order won't ship anymore for sure since Dell canceled it, but can I still forward them the address and show them that this is fraud, would they care?

eblend
10-20-2010, 03:36 PM
I actually googled the Ottawa policy and found their site. They have an e-mail form, so I just asked them about thier opinion, hopefully they write back.

AndyL
10-20-2010, 03:38 PM
Call them - emails get nowhere... Dell might be willing to ship some empty boxes too :)

HHURICANE1
10-20-2010, 04:03 PM
Sounds like you are the victim of ID theft. Get your credit reports asap and report the incident to the police. The quicker you act the less impact it may have. There are guides on the net for how to deal with this. Your bank and credit card companies can help as well. Don't let it slide. If he has all that info he has all he needs to make your life hell.

eblend
10-20-2010, 04:18 PM
Originally posted by HHURICANE1
Sounds like you are the victim of ID theft. Get your credit reports asap and report the incident to the police. The quicker you act the less impact it may have. There are guides on the net for how to deal with this. Your bank and credit card companies can help as well. Don't let it slide. If he has all that info he has all he needs to make your life hell.

Don't really want to make a big stink out of it too much just yet. I am monitoring to see something more concrete. Ppls credit card numbers get stolen all the time, so I think that this might have just been a one off thing. I don't even throw away my bills, everything with my name gets destroyed by the shredder.

in*10*se
10-20-2010, 04:36 PM
http://www.zug.com/pranks/powerbook/

eblend
10-20-2010, 05:42 PM
So I initially got an order cancelled e-mail directly from the rep, and now got another one directly from the system, and what did I notice...it was sent to me....and to the fucking scammer!

[email protected]


I e-mailed the rep who was dealing with the dude and he varified that this is indeed the e-mail used to place the order (I guess maybe the dude didn't know that I had a dell account or something and the order was automatically placed under that..)

trying to see if I can get a phone number as well. With these key peices of information I should be able to file a police report at the least.

eblend
10-20-2010, 06:17 PM
Shit just got interesting. Please I ask that you guys don't e-mail him as I want this all to be a surprise to him.

At any rate, there is even an extra e-mail at the bottom of this chat session, which is what the fucker used to place an order under my name....so seems like my account was not compromised, just linked, and hence why the fucker got busted since it got e-mailed to my account e-mail as well as his! Look at the bottom for some juice IP addresses and another e-mail...interesting. gonna have to look that one up.

Here is the chat transcript thanks to a very helpful dell employee:

12:49:51 AM MyNameHere has Started Session
12:49:51 AM Agent Assigned Session
12:49:56 AM Agent Accepted Session
12:49:56 AM Agent Joined Session
12:50:00 AM Welcome to Dell's Sales Chat! I hope you are doing well and thank you for waiting. My name is Di****(Rep Extn:4162****) I will be your online Product advisor. Please allow me a moment while I respond to your query.
12:50:08 AM http://www1.ca.dell.com/content/topics/reftopic.aspx/gen/en/setrepcode?c=ca&l=en&s=dhs&rep_id=4162505&rep_type=CHAT&redirect_url=http%3A//www.dell.ca
12:50:13 AM HiHow are youI am glad you chatted today
12:50:24 AM Sure - I will be more than happy to assist you in your purchase
12:50:28 AM which system are you looking at
12:50:30 AM ok
12:50:54 AM inspiron 15R at $ 599
12:51:07 AM the one that ships fast in 48h
12:51:31 AM ok
12:51:36 AM have you customized the system
12:51:57 AM i want them as it is .
12:52:03 AM ok
12:52:18 AM How would you like to make payment for this system... Credit card, online money transfer or easy monthly installment option which we have.
12:52:37 AM credit cards
12:52:45 AM Sure
12:53:06 AM would you like to place the order online or shall I do the needful
12:53:24 AM online
12:53:35 AM but you can do the needful
12:54:04 AM Sure
12:54:20 AM May I now request you for your Home phone number (starting with the area code), complete name, Billing and shipping address (along with the postal/zip code) and your e-mail id so that I can create your Dell customer profile and send you all the details
12:55:23 AM MyNameHere Myaddress | Calgary |AB | Canada | T2**** | 403-***-****
12:55:59 AM same for billing and shipping ?
12:56:22 AM email address please
12:56:44 AM shipping is another adress: MyNameHere: 323 Cunningham ave / ottawa /ON / K1H6B2
12:58:38 AM e-mail is: [email protected]
12:58:52 AM thank you
12:59:18 AM just to confirm the fast track model of 15 R costing $ 599 each with no changes
12:59:29 AM yes please
12:59:33 AM Billing Address:MyNameHere MyaddressHere SW Calgary, AB T2****(403) ***-****
12:59:44 AM shipping phone number is the same as billing number
12:59:54 AM yes
1:00:00 AM Shipping Address:MyNameHere 323 CUNNINGHAM AVEOTTAWA, ON K1H 6B2(403) ***-****
1:00:10 AM yes
1:00:23 AM email sent - please check and confirm
1:01:14 AM e-mail: [email protected]
1:01:22 AM yes
1:01:34 AM the same you gave above
1:01:40 AM yes
1:01:50 AM shall we proceed ?
1:01:59 AM yes go ahead
1:02:07 AM card details please
1:02:38 AM Mastercard# ****-****-****-****
1:02:47 AM exp# 01/**
1:02:56 AM CVV and the expiration and the name as it appears on the card
1:03:07 AM cvv# ***
1:03:13 AM MyNameHere
1:03:57 AM thank you for the details
1:04:27 AM Congratulations
1:04:34 AM Confirmation email sent
1:04:43 AM let me check
1:05:16 AM i receive the dell quote
1:05:16 AM Please do
1:05:25 AM two more mail follow
1:05:34 AM ok
1:07:07 AM Got it ?
1:07:35 AM yes i got it sir
1:07:38 AM thank you
1:07:46 AM how long it will take to ship out
1:07:58 AM EDD is 25 of this month
1:08:10 AM ok. thanks you
1:08:35 AM Is there anything else I may assist you with regard to Dell products?
1:08:46 AM that was it . i appreciate it
1:09:16 AM Please forward any suggestions or feedback about myself or Dell to my manager, [email protected]
1:11:02 AM i will
1:11:17 AM Thank you for choosing Dell. Have a great day. Looking forward to serve you.
1:11:51 AM thank
1:32:44 AM Customer Left Session
1:32:44 AM End of Session
1:32:44 AM Agent Left Session


Information on Session Number: 395033**
Client Unified Client
Customer Name MyNameHere
Customer Email [email protected]
IP 68.71.52.74
Host 68.71.52.74
Enter URL
Language English - US
User Agent Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; GTB0.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; SRS_IT_E8790577B576585335AF98)
Browser Internet Explorer
PhoneNumber 403*******
Your Question i want to purchase 2 of the laptop in the ship fast section

eblend
10-20-2010, 06:22 PM
Here is some info about the IP...

IP address [?]: 68.71.52.74 [Copy][Whois] [Reverse IP]
IP country code: CA
IP address country: Canada
IP address state: Quebec
IP address city: Laval
IP postcode: h7w1k6
IP address latitude: 45.6000
IP address longitude: -73.7333
ISP of this IP [?]: Netelligent Hosting Services
Organization: Netco Solutions
Local time in Canada: 2010-10-20 20:21


Wonder if the ISP will give me any info...

Abeo
10-20-2010, 06:55 PM
try to drum up support on redliners.ca, its like a crappy little beyond for Ottawa

kolumbo69
10-20-2010, 07:49 PM
Contact the police here and get a case number started so it has been documented. He knows alot of your personal information he could steal your identity having a police file number will help you later on if anything should ever come up.

Mixalot27
10-20-2010, 08:06 PM
The house at that address is listed for rent:

http://www.thomasgroup.ca/rentals/index.php?action=listingview&listingID=169

http://ottawa.kijiji.ca/c-housing-house-rental-Alta-Vista-W0QQAdIdZ234924768

[email protected] - wonder if he drives a 2010 Lincoln Mkx?

gram
10-20-2010, 08:52 PM
This is a super old scam. What they do is find a house on their block or close to have something shipped to (hence the rental) The scammer in this case has your computer shipped there and hopes that they will leave a non-delivery card or tries to intercept the package as is, or hopes they leave it and picks it up later.

You must have given your credit card details to someone, it really sounds like your computer or maybe a friend's computer that you used your cc on got hacked to me.

Either way this is a very old scam called carding, they have been doing it for like 10 years.

A lot of times your card info is stolen at a restaurant by a skimmer and they probably just used your name and last name on the credit card to find your Calgary address if you are 100% sure about the no virus thing. (google your first anme, last name and Calgary and see if it works)


I would call equifax and experian and make damn sure you don't have other loans or loan applications under your name cause if you do it is going to take you months to fix it if you don't act quickly. You can also have them add a flag to your account so that if any new accounts are set up that they have to call you to make sure it is you setting up the acct.

I used to deal with this BS as part of my job so take it as it is. Chances are very high that you used said credit card at a restaurant and some jackass waiter stole your info.


The Pre-Auth that you see is them testing the card to see if it is valid before they call DELL etc too. :)

wintonyk
10-20-2010, 08:59 PM
this could get interesting

derpderp
10-20-2010, 10:20 PM
I wouldn't piss around, you should call the Polizei right away because of the risk of identity theft, it is much better to have it on police records ASAP

roopi
10-20-2010, 10:42 PM
How did you update your Ebay account. Was it a link through an email?

eblend
10-21-2010, 06:00 AM
Originally posted by roopi
How did you update your Ebay account. Was it a link through an email?

Nope, directly through eBay. I am well aware that noone should be clicking links to update personal info directly through e-mails. I always go to the source. Going to file a police report today. I wonder if they need any of the evidence I have, or if they would even care. I understand I can have a case number just in case with them, but would they actually follow up on this or anything?

I mean at the end of the day, so far no money has been lost as the activity was intercepted. Going to pull up my equifax today and verify all my crap on there is in order.