Anatomy of a Spam Viagra Purchase(technologyreview.com)
technologyreview.com
Anatomy of a Spam Viagra Purchase
http://www.technologyreview.com/blog/editors/26785/
27 comments
I just wanted to say that I really appreciated this research--thanks for doing this work.
It sounds like you purchased items from email spam; have you considered doing a similar study for items that are spamming search engines instead of email?
It sounds like you purchased items from email spam; have you considered doing a similar study for items that are spamming search engines instead of email?
We focused on email spam because that's been our area of expertise for the past few years. Some of these programs are well represented in SEO spam as well - with affiliate programs like these, they don't much care how you bring them the customer traffic as long as it arrives. We haven't, however, looked into the programs that are exclusively advertised via SEO but it's definitely on our list. Most of our methodology will carry over, we just have to straighten out how to create some sort of canonical feed of SEO'd pharma links.
I'd also like to personally thank you for your employer's generosity in supporting this research :).
I'd also like to personally thank you for your employer's generosity in supporting this research :).
Based on your research:
What's the chance of actually receiving the ordered meds?
What's the chance that the meds would be of reasonable quality (right formula, etc)?
What's the chance that the card used for transaction would be defrauded? I.e. charged another sum after some time or whatever.
To answer your questions: very high chance of actually receiving, the active ingredient is correct and in the correct concentration (we didn't test the binder/other trace elements), and in a pilot study we saw a LOT of fraudulent charge attempts, but during and after the 3 month period of this study we did not see any fraudulent transactions (we were specifically watching for this as we had seen it in the pilot study).
I found it surprising that product was actually shipped. I've always assumed they'd take your money and run.
Fascinating work. Thanks.
Fascinating work. Thanks.
What was the difference between pilot study and the "regular" study?
I wonder where did that difference in fraud/no fraud came from.
I wonder where did that difference in fraud/no fraud came from.
The biggest difference is that we were using the same cards several times, and in this study we only used the cards once each. At this point everything is speculation, so I really can't say anything one way or another as to why this happened.
Did you asked your bank to cancel the payments? If you haven't I'll hold you personally responsible for encouraging all those spammers ;-)
We (and also I am pretty sure our lawyer) consider that to be defrauding the spammers, and even though some people might consider that ethical, we don't (also we're pretty sure it's not legal either).
If Visa or MC wanted to fix this, they would merely need to issue a small number of "fraud" cards world-wide to various people who would _only_ use it for suspected frauds.
Instantly flag the merchant acct, bank acct, open a report, all while looking like a legitimate sap buying from spam.
I look forward to my "Death-card, by Visa(tm)" in the mail.
Instantly flag the merchant acct, bank acct, open a report, all while looking like a legitimate sap buying from spam.
I look forward to my "Death-card, by Visa(tm)" in the mail.
That would bridge the contracts Visa and MC have signed with the processing bank.
It would have been interesting if they tested the drugs as well, to see how they chemically compared with the domestic ones.
FTA: "The customers get the products they were paying for (albeit counterfeit versions)."
They're fakes!
They're fakes!
No, they're generics produced to look like the brand name version.
This is correct: mass spec analysis showed that the correct active ingredient was present in roughly the same concentration in the pills we ordered compared to the store-bought brand version of the drug.
Interesting to know! In my mind, counterfeit == fake == placebo. Thanks.
I'll ask the question that nobody else is crass enough to: Assuming I order and pay, what are the chances that I get a pill delivered to me that gives me an erection?
The article implies that the drugs are effective.
> The customers get the products they were paying for (albeit counterfeit versions). If they aren't complaining, there's not immediately a reason for banks to intervene.
> The customers get the products they were paying for (albeit counterfeit versions). If they aren't complaining, there's not immediately a reason for banks to intervene.
I'm surprised the spammers actually sent something.
They basically always send something, as these are credit card transactions and easily reversed by the customer in the case of fraud, either not getting anything or not getting what you ordered.
Even if it's a black market of counterfeit items there is still the need for repeat customers or referrals.
Having read the paper I'm interested in the fact that a card issuer was actually willing to work with you on this. Especially with providing far more details about each transaction than a consumer can normally obtain.
Do you have any further details about this issuer and the details they were willing to provide? Or have they asked to remain anonymous?
Do you have any further details about this issuer and the details they were willing to provide? Or have they asked to remain anonymous?
Unfortunately I can't speak directly to this. Our correlation was done using the acquiring bank's BIN, and this information is readily available on some normal VISA cards, and even some prepaid cards (due to the CARD act, these are almost exclusively currently for use inside the US only). This isn't some super secret information, the specialty issuer helped the most with creating several one-off cards in specific values and other logistical concerns.
Here's John Markoff's writeup for the nytimes, it doesn't seem linked from the techreview site: http://www.nytimes.com/2011/05/20/technology/20spam.html