Did the government sit on the ‘scareware’ case too long?

Analysis
Jun 21, 20104 mins

Critic says authorities took too long to break cyber ring

A few weeks ago when I wrote about federal criminal charges being brought against two alleged cyber criminals in Russia and one in Ohio, I wrote that we could “Score one for the good guys” because law enforcement caught up with some of the often elusive perpetrators of online fraud.

But one commentor, “Joseph,” wrote that the authorities waited too long to nab Bjorn Daniel Sundin, 31, of Sweden, Shaileshkumar P. Jain, 41, an American living in the Ukraine, and James Reno, 26, of Amelia, Ohio.

Because they waited too long to act, authorities enabled the criminal enterprise known as Innovative Marketing Ukraine (IMU) to “flourish,” which, Joseph argues, “has established a culture of crime and malware success on the Internet.”

In other words, because John Dillinger robbed so many banks, he made a lot of money, thus making bank robbery pervasive and successful. So it’s the cops’ fault. Okay, but Mr. Dillinger is still as dead today as he was when he was shot leaving the Biograph Theater in Chicago in 1934. And the people charged in the IMU case are still in really, really big trouble.

True, the trio indicted in, coincidentally, Chicago in late May have not been convicted, but Joseph argues that IMU operated for years “with tacit government and industry approval.” And by industry, he means companies like Microsoft, whose systems are often hacked, and Symantec, the computer anti-virus software company.

According to a May 27 announcement of the indictments by the U.S. Attorney’s Office, the trio charged in the IMU case allegedly bilked customers in 60 countries out of about $100 million by tricking them into thinking their computers were infected with malware and getting them to buy expensive but ineffective software to protect those computers. This so called “scareware” scheme “is widely regarded as one of the fastest-growing and most prevalent types of Internet fraud,” read a statement from the feds.

IMU operated as an “open secret” in Kiev, Russia, for years, Joseph argued, and then advised me that my colleague “Jeremy in London” could fill me in. Jeremy is Jeremy Kirk, the London-based correspondent for our sister news organization IDG News Service,– who believes Joseph is an attorney who fights cyber fraud with civil suits. Kirk’s covered the story along with Bob McMillan at the IDG News Service bureau in San Francisco. McMillan reported that the indictments were the culmination of a 10-year investigation of IMU, which also resulted in the company closing its doors after the 2008 filing of a federal lawsuit against it by the Federal Trade Commission.

Kirk directed me to a Reuters story, which offers a richly detailed account of how IMU operated in a bustling three-floor suite of offices in a downtown Kiev building. The report depicts a cluttered, chaotic office with 100 “computer geeks” writing code in a place that could resemble just about any startup here in Silicon Valley. Except they were committing crimes.

The Reuters story, published in March, explains that the FTC succeeded in retrieving $117,000 by settling its charges against Reno, one of the defendants in the FTC suit. That did not protect Reno from being indicted two months later in Chicago.

I don’t think that amounts to what Joseph considers “tacit government … approval” of IMU’s actions. Sure, other people were taken in by the scareware scams while the authorities were doing their investigating and that’s unfortunate. But I think the authorities would say they have to do as thorough an investigation as they can to make sure that when they issue charges, they stick. And while cyber crime like this indeed remains rampant, the hope is that each successful prosecution of people, like those charged in the IMU case, informs the investigation and prosecution of more cyber criminals going forward.