Developing a Critical Disposition

This morning, I received a photo (found below – I added the watermark) from a catfishing victim. She received it from a scammer who had used many of my personal and professional photos to form an online, intimate relationship with her for the purpose of defrauding her out of money. The victim finally clued into the scam after already sending him thousands of dollars. While it may seem ridiculous to fall for such a scam, I receive hundreds of similar reports every year, and if you know of my ongoing saga, you will understand that I have tried my best to bring the problem to the attention of Facebook, Google, elected officials, law enforcement, etc. None of these organizations or agencies seem to be willing or able to do anything about this problem, and thus I feel the responsibility of teaching about such Internet scams must continue to be taken up by educators in K-12 and post-secondary institutions.

Over the years, I have seen teachers make great use of interesting “fake sites” designed to help students develop information literacies/skills. Some of these include DHMO.org, Save the Endangered Pacific Northwest Tree Octopus, Feline reactions to bearded men, and DehydratedWater.com. And while these are still great resources that can be used with some success, given the abundance of fake news and internet scams that inundate our digital society, there are plenty of opportunities to use fresh and authentic examples in class.

For instance, using the example of the photo above, students could employ some very basic info/digital literacy skills to identify the picture as a fake (i.e. photoshopped) picture through a reverse image search. In this Youtube video, I’ve previously demonstrated how to use Google Images to run a reverse image search, but I also wanted to highlight TinEye as an alternative tool for this task. To try out TinEye for this purpose, I would suggest that you download the above photo to your computer (ctrl-click+save or drag+drop), visit the TinEye site, and then upload the image to TinEye (there is also a TinEye Chrome extension available that makes the process a little quicker). In the case of the photo above, using TinEye produces the following results:

Exploring the resulting links, you will quickly discover that the original image shows Anders Breivik, who killed 77 people in Norway in a terror attack in 2011. Further investigation also reveals many additional photos of Breivik in custody, making it clear which version of the image is the photoshopped one (if the tiny size of my head compared to my body wasn’t already enough proof).

So there you have a component of a very basic information/digital literacy lesson that you could use in the classroom. However, I’d like to stress that these important tools and/or processes will likely not become first-nature to our students unless we help our students develop the disposition to approach the world with a critical eye. Recent studies have shown that young people are not, on the whole, very good at detecting fake news – and the stories that emerged regarding fake news about the U.S. presidential election being written by teens in Macedonia have made it clear that adults are equally vulnerable. There is little doubt that information/digital literacy will become more and more important in the years to come.

I’d love to hear from you. What strategies are you using in your classroom to help students become critical consumers and creators of information and media? 

Are you being catfished?

This post was written jointly with Katia Hildebrandt and also appears on her blog.

Catfishing schemes, or romance scams, continue to plague social networking services. In fact, the issue has become so common that there’s a good chance that one of your recent “friend” requests actually came from a scammer versus someone who is actually interesting in pursuing a genuine friendship. Unfortunately, social networks on the whole seem content to turn a blind eye on the problem, despite the fact that people lose thousands of dollars to these types of scams every day. So, due to this alarming issue and utter lack of response from social networking sites, we’ve compiled a few tips, techniques and questions to ask yourself when evaluating an online profile. We hope that this information might prove be useful for both personal use and as an instructional tool.

Step 1: Assess the authenticity of the profile picture

This is really the easiest place to start. Drop the picture into Google’s reverse image search to see where else the image appears. TinEye, a dedicated reverse-image search engine, is also a great tool that can be used for to perform this search. If the picture is associated with many different names or profiles, it’s likely that you’re dealing with a scam account.

Step 2: Critique the bio

Catfishing accounts often use similar biographical components. Some red flags include:

  • A relationship status of “widowed” or “divorced” (obviously not all widowed or divorced people are catfishers, but this status in combination with other red flags might be an indication of a fake account)
  • A job that is of exceptional status and that may require a great deal of travel and/or periods without communication (e.g., military, engineer, oil worker, self-employed, shipping), making it easy for the scammer to make excuses for being absent, unavailable, or out of the country.
  • An “about” section that includes clichéd, romantic statements such as “looking for love” or statements that may stereotypically reinforce one’s integrity (as in this scammer profile below; also note that he describes himself as “God-fearing” and that there are obvious spelling mistakes in the name of the supposed alma mater – which we discuss more later):

1

Step 3: Investigate the profile name

The name on the account can also be a clue about the legitimacy of the account:

  • Many catfishers seem to pull from a list of popular names. If you search for the profile name on Facebook and lots of other profiles with the same name and similar occupations pop up, you may want to look more closely. At the time of writing, numerous “Nelson Colbert” profiles appear on Facebook and all seem to be fake profiles made up similar components discussed so far (e.g., stolen profile photo, suspect occupation, etc.).

2

  • Check to make sure that the name on the profile matches the name in the URL. Otherwise, it might be a sign that the scammer has had to change their profile name when a victim found them out.

3Google the profile name. Most people have at least some sort of digital footprint these days. Can you find the person? Does what you find match up with what they are telling you?

Step 4: Investigate the profile page

Some other elements of the profile to watch out for include:

  • Number of friends: Does the person have few friends? Do their friends interact authentically with them on their page, or do you only see the same people commenting/liking over and over again?
  • Types of friends: Often, if you are able to see the scammer’s friend list, it will consist overwhelmingly of people of the opposite gender (the target victims), as in this screenshot of a male scammer’s friend list:

4

  • Age of the profile: Is the profile brand new, or is there a history of photo uploads, status updates, posts from others, etc? Also, note that profile posts can be backdated and locations can be faked (as seen in the image below) to make a profile seem like it has a longer history than it actually does. However, the year that the (Facebook) profile was created can’t be faked.

5

  • Photos: Does the profile have only a few photos, or are there a variety of photos, including photos with others (watch out for pictures with children, as this can be part of the scam)? Do the photos look photoshopped (see “ghost dog” example below)?

    6
  • Mutual friends: Do you have any mutual friends? Note that having a small number of mutual friends isn’t necessarily a sign of legitimacy: scammers will sometimes friend a victim’s friends to make themselves seem more legit. If you have only a small number of mutual friends, it’s a good idea to contact those friends to see if they actually know the person. In many cases, your friend may have accepted the fake profile, due to less discerning personal protocols regarding “friending” or simply in error.
  • Language/grammar: Many scammers do not speak English as a first language. If you notice many spelling or grammar mistakes even though the person claims to be from an English-speaking country, proceed with caution.
  • Religious affiliation: Scammers will also often pose as devoutly religious individuals and sometimes use scripture or religious language to appear more trustworthy or to manipulate their victims through shared belief-systems. In fact, religion-specific dating sites such as Christian Mingle, JDate, or Shaadi are often used by scammers.

Step 5: Watch for tell-tale behaviours

Scammers often follow predictable patterns of behaviour, and there are some common red flags:

  • Use of a private messaging platform: A scammer will often quickly try to move the interactions over to email, SMS, or a different instant messaging platform. This is done so that if the original profile is identified as a fake account and removed by the social network, the scammer will not lose direct contact with their potential victim.
  • Rushing towards commitment: Scammers will try to move online relationships forward very quickly. It’s not uncommon for a catfisher to bring up marriage or to profess their love after only a few days or interactions; this helps to build a great sense of attachment and obligation, making victims more likely to agree to help the scammer later on.
  • Refusal to use video communication: Catfishers will often refuse to use anything but text or voice-based communication and will give excuses about poor connections to avoid having to Skype.
  • Out-of-sync, glitchy, or looped video: If a scammer does agree to video chat, their stream will generally be of very poor quality. This is because the scammer is usually using stolen footage that they found on Youtube or elsewhere online in order to fake a live conversation. In such cases, if audio is also present, it will appear to be out of sync with the video. Scammers may also cut video conversations short and complain of connectivity issues.
  • Repeated excuses to avoid meeting face to face: Catfishers will often make plans to meet up with their victims, but these plans will always fall through at the last minute for one reason or another.
  • Requests for compromising photos/videos: Often, scammers will request nude images or ask victims to participate in video chats of a sexual nature. These images or videos can then later be used to blackmail the victim, for instance, by threatening to send the files to the victim’s entire contact list or employer.
  • Emergencies: Once the catfisher has hooked their victim, they will likely be involved in some type of “emergency” situation. This might be an illness, loss of job, or the need to leave a location suddenly. In many cases, the scammer’s “children” may be involved.
  • Requests for money: This is obviously the top indication that you are dealing with a scammer. The request can take a variety of forms; two common techniques include advanced-fee fraud and requests for a money transfer through a company like Moneygram or Western Union (to make the money difficult to trace). Often, the victim will be told to send the money to someone other than the scammer (since the scammer is using a fake name).

Step 6: Ask for confirmation of identification

If you still aren’t completely sure whether or not you are dealing with a scammer, you can always ask for some form of confirmation.

  • Passport: Often scammers will provide a photoshopped passport as proof of identity (as in the image below). If the passport seems questionable, you can find images of real passports from various countries and compare them. You can also check out the passport photo guidelines for various countries (for instance, here are the US guidelines), which can help you determine if the photo meets the size/shape requirements.

7

  • Real-time photo or video: To verify identity, you can ask the individual to provide a real-time photo (with a newspaper with that day’s date, or holding up a certain number of fingers) or to perform certain actions while on video (raise one hand, clap hands, etc.). As well, if the scammer does provide a photo, be sure to check for signs of photoshopping, like in this picture below where the head has been (poorly) photoshopped onto the body and thus seems inordinately large.

8

  • At this point, we also can’t stress enough the need to use your common sense. If a profile just seems too good to be true, it unfortunately probably is (just like you don’t really have a secret relative who is the king of an African country and wants to share his wealth with you).

Step 7: Block, report, and warn others

Once you have determined that you are communicating with a scammer profile, there are a few steps you should take:

  • Report: Most social networking or dating sites have some sort of reporting tool. Often, reporting a profile will lead to it being taken down, preventing future scams on that account. As well, many victims report fake profiles to sites like Romance Scam or to Facebook groups set up to share information on scammers.
  • Block: Once you have reported the profile, you should unfriend and block the user. You may believe that the damage is already done, but if you do not unfriend and block the scammer, they will still have access to your photos, account info, and friends list. As well, people may see that you are friends with the scammer and take this as a sign that they can safely friend the account themselves.
  • Warn others: Another good step is to warn others in your circle of friends, especially if you notice that the scammer is attempting to connect with other members of your contact list.
  • Be vocal: Although there have been many attempts to improve policies at social networking services (we’re looking at you, Facebook), ultimately it will likely take a critical mass of complaints, media coverage, and awareness in order to achieve real change. So make you voice heard!

Other things to look out for:

  • Scammer “families”: In some cases, scammers will create an elaborate network of friends and family in order to bring legitimacy to the scammer profile. For instance, the fake Alex Gallart’s circle of contacts included his mother, friend, and daughter (of these, only the mother’s profile, Maria Gallart, is still up). In this case, scammers were actually using real photos of Alec’s family members to build the fake family.
  • Twinned accounts: One technique we’ve seen more of recently is when scammers create accounts that are essentially doubles of existing accounts. For instance, see these two photos:

9

Scammers will use these profiles to connect with the real person’s friends and family, who simply think they are (re)connecting with the victim. Then, the scammer can use a variation on the “grandparent scam”in order to ask friends and family to send money to deal with an emergency.

Facebook Is Still Broken …

I received this email a few minutes ago (and a few hours after I noticed that my Facebook account was down).

Katia_Hildebrandt_says___

For the fourth time, Facebook has disabled my account because the company doesn’t believe I am who I say I am.

Yes, apparently I’m the one with the fake account.

Not “Obrien Gary Neil” or “Michael Walter” or “Nelson Colbert” or “Trofimov Sergei” or “Anne Landman” or “Dounas Mounir” or “Kyle W. Norman” or one of the hundreds of other fake accounts that I have reported to Facebook for using my images to scam vulnerable women across the globe. No. Once again, Facebook has decided to disable my account for using a fake name.

Despite the fact that I’ve already had to submit my government-issued ID to Facebook in each previous case.

Despite the fact that my account is nearly a decade old and linked to 2000+ Facebook friends.

Despite the fact that I’ve had countless media interviews about the problem.

If it can happen to me, it could certainly happen to you.

I’m starting to feel like a broken record, but I really need your help. Please share so that we can get Facebook’s attention. The reporting system is badly flawed, and as I’ve written previously, Facebook really needs to get it fixed.

The Future of Identity Theft

I’ve written and spoken extensively about my problems with romance scammers, criminals who have used my photos (and the photos of many others) to create fake profiles and trick victims into sending them significant amounts of money. In my research, I’ve learned that many potential victims ask for a video chat with scammers as a way for them to prove their identities. In fact, participating in a video chat and then asking supposed suitors to perform particular actions on request (e.g., hold up two fingers on your left hand) is often touted on anti-scammer sites as a way to ensure that the person that you are talking to is in fact who they say they are and not a scammer who may be using recorded video as their video source (a common and frightening possibility).

Well, verifying identity online has just become even more complex. As you have already likely discovered, there are a number of freely available apps (e.g., Snapchat, FaceSwap Live, MSQRD) that allow for live face-swapping. In fact, MSQRD was recently purchased by Facebook, and there have been suggestions that face-swapping could become more directly integrated into the social network. If you have used one of these apps, you’ll likely agree that face-swapping can be a lot of fun, but these are fairly touchy/glitchy apps and their use could be easily detected. However, this may not be the case for long.

Researchers from Stanford University recently released a project that works to “animate the facial expressions of the target video by a source actor and re-renders the manipulated output video in a photo-realistic fashion.” The results are incredible, but the implications for identity theft are incredibly frightening, in effect allowing scammers to become puppet masters who manipulate the faces and bodies of their fake profile avatars. Takes the idea of “authentic identity” to a whole new level, doesn’t it?

Would The Real ‘Alec Couros’ Please Stand Up?

Last September, I wrote a post about how scammers had been using my photos to lure women into online, romantic relationships for the purpose of ‘borrowing’ or extorting money. Since that time, the scams have continued. I get, on average, one new report a day from women (and occasionally men) who have been tricked, or nearly tricked, into sending money. In many cases, individuals have reported forming deep attachments or even falling in love with these scammers. This has been a frustrating predicament that has been going on for many years now. In this post, I thought I would share a few of the things that I’ve learned about the scams, the scammers, and their potential victims. Here we go.

  1. These scams are likely not perpetrated by a single individual. In fact, they are most likely perpetrated by groups of individuals, or even gangs, most likely situated in Nigeria or Ghana. These are typically known as “romance scams“, and I feel strongly that recognizing and understanding these types of scams are essential skills for digitally literate individuals.
  2. These scams take place over a number of popular social networking and communication tools. While I’ve taken down nearly 50 fake Facebook profiles, I’ve also had my photos appear in profiles set up on dating sites such as eHarmony, Christian Mingle, Match.com, and Plenty Of Fish. There are also dozens of Skype accounts that have been created using my photos. The ones that concern me the most are those that actually use my name and photos. For instance, if you search ‘alec couros’ on Skype, you will get five accounts under my name. Only one of them is mine (‘aleccouros’ is legit, btw), and three have photos of me. It worries me that my friends or professional contacts may connect to one of the fraudulent accounts.
    Searching 'alec couros' on Skype gets these results

    Searching ‘alec couros’ on Skype gets these results

     

  3. Continue reading