Comment by jmward01

1 month ago

So, this is a crime right? Why isn't there a well known '911' for cybercrime to report things like this to and get help? Society needs to catch up with the actual dangers out there and build support networks for this ASAP. This is organized crime and needs organized defense to deal with it.

Unfortunately most evil cybercriminals know the "one weird trick" of "do your crimes in countries that don't care about the crimes"

  • I see several comments like this implying nothing can be done. But that is far from the truth. First, an agency that actually answered the phone could coordinate directly with LinkedIn and other tech companies to quickly take down these fake accounts and minimize harm to others. We all know how incredibly hard it is to contact a tech company. Second, an agency that answers the phone could help less technical people find what may have been compromised and push people towards support services if needed. And finally, maybe, they could do the hard job of combining leads and working with appropriate agencies to maybe find and prevent these things over time.

    • Taking things down doesn't help much unless the platform has something in place to make it hard to recreate them.

      >they could do the hard job of combining leads and working with appropriate agencies to maybe find and prevent these things over time

      At least in the U.S., everyone will cry government overreach and no one will fund it. In other countries, they should probably just ban U.S. platforms unless they're reachable and actually resolve these type of problems.

      3 replies →

    • Won't that require laws that allow the said agency to compel LinkedIn or whatever tech company to actually pay attention and take action? Like laws compelling tech companies to unlock the bootloader once they stop supporting a device.

      I wonder why such common sense laws don't exist and who is preventing them from being introduced and passed despite wide public support in general?

      2 replies →

    • > But that is far from the truth

      Just install a Russian locale on your computer to prevent malicious programs even starting and get on with your day because it's the truth.

      Snowden is a free man in 2026 despite the United States of America very much wanting to put him in jail.

      1 reply →

    • Sounds like socializing the harms instead of requiring these companies to bear the burden themselves. Could still be a valid approach but I'm afraid it will make them take less responsibility, not more.

    • whilst reducing crime is an honorable objective, as we all know, increasing the wealth of tech billionaires must take priority.

  • Something I've always wondered, because I'm a bit of a contrarian and I wonder if we're really any different: Could an American citizen hack and steal from Iranians and Russians with impunity from America? The issues that prevent the US from extraditing Russians who hack us -- don't they work both ways?

    • Legally speaking, no - it would still be a criminal offence.

      Practically speaking, there is zero chance that the USA would extradite someone to Iran, even if they weren't currently at war with them. Whether they did anything about it would probably depend on exactly what the situation was - there's a big of difference between targeted IRGC or defence systems and ransomwaring an Iranian hospital or scamming random citizens.

      Where they'd probably get you is if you tried to monetise it, and get stolen/extorted cryptocurrencies (or whatever) into your bank account. But that could easily fall under tax evasion laws rather than computer misuse ones, because they'd be a lot easier to prove in court.

      2 replies →

    • As far as I know it has never happened. On the contrary, when Alejandro Caceres admitted to ddosing North Korea - taking down all their public websites for a week - he was questioned by the FBI who decided to take no further action.

      https://www.wired.com/story/p4x-north-korea-internet-hacker-...

      So hostile countries should be fair game for Americans who want a side-hustle. Plenty of Russian targets that could be profitable.

https://www.ic3.gov

You won't hear back from them, though. But, at least for US citizens (and possibly for anyone?), this is as far as I know the closest thing there is to an "Internet 911".

  • > You won't hear back from them

    You might. (I have.) They were able to get a wire sent to a fraudster reversed. (Not my wire.)

To put it bluntly and perhaps a bit cynically, on the tree of bad things that people do to other people, this is pretty high-hanging fruit. Right up there next to scam phone calls that prey on the elderly while claiming to be from Microsoft support.

It's basically impossible to catch suspects because they are either smart enough to cover their tracks very well, or (more often) live in countries whose governments don't care about their citizens (even pay them for) scamming westerners.

  • Hard disagree on the scam phone calls. It would be trivial to eradicate them almost completely if the phone operators did the bare minimum to fight against it. At any point in time, any given US phone number is handled by exactly one phone carrier. There is nothing stopping that carrier from requiring name and address to issue that phone number. They already do for 99.99% of their legitimate customers. It would be very easy to make it so that every single phone call originating from the US, including all VOIP calls made with US phone numbers, can be traced back to a specific business or person that can later be sued or prosecuted.

    And no, number spoofing isn't an excuse either. We literally solved the much harder problem of email spoofing already. There are, what, 3 carrier networks in all of US? And they cannot do with each other what DMARC did for the hundreds of thousands disjoint organizations that comprise the internet? Please.

    • Number spoofing is not a solved problem because some carriers, which appear legitimate in all other respects, make a business out of routing your traffic over TDM trunks that don't support caller ID verification, and will claim it's extremely expensive to upgrade these to VOIP.

      5 replies →

    • >It would be trivial to eradicate them almost completely

      Absolutely true, but droning their data centers might have some policy repercussions.

      2 replies →

    • KYC just for a phone number opens the door for societal ostracization and essentially blacklisting of people from infrastructure. This is on par with being unable to open a bank account if the capability is matured. I'd advise that you think long and hard about the consequences of this system being applied against you maliciously before signing on the dotted line.

      3 replies →

  • Saw Microsoft has a dedicated scam reporting page - guess it was damaging their brand https://reportfraud.microsoft.com/en-us

    Wonder if they’re effective in going after reports. I’d still report to IC3/FBI/powers that be, too. Just in case someone somewhere has the resources to do something… perhaps a high hope

    • I get more calls from Google Security than any other thing. Oddly the Pixel's built in scam detection and call screening lets them through without fail. I normally don't have my phone even ring unless it's in my contacts, but saying you are calling from Google is like a magic code.

      1 reply →

  • I always wondered why US cannot pressure India to crack down on those scammers? They use phone network, it should not be difficult to find them. Some youtubers even hack into their computers and extract all the info. US probably has a leverage here, they could simply ban Indian companies from working with US if they don't cooperate.

    US was so angry about "unfair" tariffs why are they not angry about criminals stealing from Americans?

the main issue is that we lack a global '911'.

secondary is the effort asymmetry between spinning up one of these scams (near 0 effort) and catching/prosecuting these scams (big effort, astronomical cost)

  • > the main issue is that we lack a global '911'.

    911 is for emergencies. I don’t think the global 911 service would give any attention to a LinkedIn scam.

  • what about the outcome asymmetry between spinning up one of these scams (get one guy's computer) and getting caught (jail for life)

    • you arent getting jail for life for this, even in the extremely remote chance you are caught. you are probably getting more than one guy's computer, though.

    • I’m sure they’ve gotten more than one hot wallet from out of work crypto bros. Probably a profitable venture.

  • I don’t know but the us kidnaps ehhh arrests people on foreign land on a regular basis… and brings them to the US to stand trial. So if it’s “important” enough it will be aced upon…

There is but the FBI is horrible at responding to cybercrime. They have IC3 but its basically useless. They arent going to help or even contact you if you report a crime to them.

In the Netherlands there's an official government agency that allows a simple mail or report: https://www.ncsc.nl/en/report-an-incident-to-ncsc-nl

I presume more countries have this, not sure about the US though (CISA maybe? CERT/CC?). CERT is the overarching org that manages local agencies like this Dutch NCSC. Though I am not sure if and how easy it is, globally, to report incidents.

The amount of crime in the world -that requires arguably "low skill" time to resolve- that just gets filed away because of low resources is insane. How are forces going to stand up high skill task forces for these kinds of things?

You mean organized crime like NSO Group? Sorry, governments all over the world are too busy using them to spy on opposition to care.