Wednesday 22 April 2015

Edis and a money mule recruiting website

This conversation was passed to me by some associates, and I am reproducing it here as an example of how some hosts can react to being informed that criminals are abusing their services. You'd think that they'd appreciate being told of such violations, and most are. Sometimes, however, things can take on a strange twist. This was Edis' reponse over a fake employment site being used to recruit money mules, which they hosted. (Note: any editing done by myself has been placed inside <> brackets.)
"Hello,

I have doubts that this violates any laws in Italy (where this server is hosted) and Austria (where we are based), please obtain a court order for shutdown (or a credible person that sends us the abuse - You, from a <free email address> without any signature, are *not* credible.)

(It might violate US laws but No, we will not accept *any* US court orders, we obviously do not care about your funny US laws in Europe.)

Mit freundlichen Grüßen / Yours sincerely

--
EDIS GmbH"
"Wow!

A bit unexpected. Is it your website?

It is a fake company trying to lure gullible/desperate people into helping criminals to launder money.

If you don't care about that then that is your problem.

Regards"
"Considering that we are one of the largest hosting providers in multiple EU countries and the largest one in Austria... no, it is obviously a customer, simple as that.

However, unlike the US laws work different here - We don't take websites down when we get some mail from an unknwon source, from a free mail provider with no signature or anything (and no proof either for anything), this is plain and simple illegal as you have no authority over us and we have no authority to shut a customer down for this sort of abuse (there is an EU abuse template for a reason.).

You should also note that we as provider are never liable in Europe for any content (German: Providerprivileg, see German Telemediengesetz §8 and Austrian ecommerce §116 ) unless we ignore a court order - So i want one from you for it, what is the problem with that?
If it is illegal it should be easy for you to get one or simply report it to the police and have them do it, i really don't see your problem unless you have something to hide or lie to us.
"
"Dear <Edis>
Let's not get over excited.

I do not expect you to take my word for it - which is why I provide the evidence in the form of an abuse report and ask you to investigate.

I am not an arm of Big Brother. I work as a volunteer with www.scamwarners.com to identify, warn about, and try to shut down criminal run sites taking advantage of people's niaivity/greed/stupidity.

If I thought that reporting a site to the police would help I would do so. But I certainly do not have the resources to get court orders etc.

Most registrars and hosts consider and respond to evidence in abuse reports
A few actually seem proud of supporting criminals

So good luck to you and your great big hosting provider
Best wishes"
"Again, what ressources?
You just report it to them, you don't have to pay anything - you don't even have to state a name or any personal data to them.
Don't tell me they don't take this serious - I work daily with Austrian police and Europol in money laundry cases (they happen to use a lot of VPN providers) and they are always well informed and interested

It's certainly nice what you do, this however does not change that i still have zero proof of illegal activity under _EU_ law (let me just for completion add again that we do not care a single % about US laws).

I see your text which might be right, i see a website which might be full of lies (which would not be illegal, even for financial advise) or criminal or a normal website...
It is not my job, no - not even my RIGHT, to judge if this site is illegal or not - that's why i want a court order.
You need to understand that you can go to JAIL here for shutting down customers without the correct reponse time to abuse and without specific proof as you disturb his business - Once we judge the decision is final, no matter if good or bad.
So we simply go the legal, easy and better way and let courts handle it while we enjoy our protection."
"Dear <Edis>,

Calm down. Keep things in proportion - speak to your supervisor. You are ranting like an idiot. You would spend your time better investigating sites rather than arguing with me.

Read the abuse report. Look at the job description for "Financial Agent" and the associated FAQ. See the same template on Bobbear from 4 years ago. If you don't recognise money mule then you are in the wrong job.

The registrant will have given false details, possibly paid for hosting with a stolen credit card, and will not complain if the domain is suspended. Don't hide behind the law, it makes you a moron.

Or is it more fun arguing than doing your job?
"
"There is no supervisor for me, i *AM* the highest person for this already...
And yes, thanks, i know what money mules do - I also know perfectly fine how this industry works, what their income is, money laundry operations involving stolen bank accounts and Cyprus/Panama corporations, the persons behind it like Flyman in St. Petersburg, the companies they use... all nothing new.
As said, we deal often with police and europol.

I gave you enough hints now, so here it is clear: This site is *MONITORED BY EUROPOL* - Even if i WANTED i CANNOT DO ANYTHING without a court order.
"
 At this point a second associate stepped in to assist.
"Hello,

It appears that your web contact form is not working.
A colleague of mine submitted an abuse report concerning a fraudulent domain hosted by Edis.at,

She was concerned that your abuse department representative, a Mr [name removed to protect the guilty], was being over protective of a clearly fraudulent domain and might be under some pressure from the criminal owners of the domain.

I copy her abuse report below and ask that you treat the matter sensitively.

Kind regards"
"Hello,

we will deal with this case tomorrow morning, anyway be assured there's no pressure from anyone to keep specific domains/services up and running, we just to need to give our client the chance to remove the content.

Yours sincerely
[Boss]
EDIS GmbH"
The final email from Edis Abuse to the first associate.
"Hello,

It should be noted that i actually HAVE verified this with a lawyer and this website is perfectly legal under Italian laws where it is hosted (not due to laws FOR it, but there don't exist any laws AGAINST it), the VPS was suspended (in fact, by myself, look at the other mail) for a similar, but non visible illegal matter.

Also, i am the head of abuse here - So please stop complaining.

Mit freundlichen Grüßen / Yours sincerely
[Abuse contact]
"
The website was finally suspended.

"Go get a court order" or "report it to the police" is a common response from hosting providers and registrars alike. It's understandable, no one wants to be responsible for disrupting a legitimate website. However, when it comes to fraudulent sites, there are a number of problems, the first of which is the global nature of the internet. There is no internet police or court system, establishing which jurisdiction in which you would need to file such a claim is often beset with difficulties. The police there may not have the resources, or be interested in investigating without victims in their country. There is the time and expense required in order to get your court order, during which the website is still operating and ensnaring victims. Finally, once you have said court order and issue it to the hosting company and registrar, they may or may not recognise it's validity, because they may not even be in the same country, or the site will simply move to a different hosting company or reappear with a new registration, requiring the process to start over again.


No comments:

Post a Comment