Who is ArcoJedi? A life-journeying Christian, ecstatic husband, proud father of four, web guru, all-around geek and Star Wars fanatic. Read these thoughts that he felt were worthwhile. Then wonder why he thought that way.

2022/09/27

For a Developer, What Does Identity Theft Look Like?

I love the Internet, I really do. deep breath But...

It does by it's nature allow a certain kind of terrible identity theft to take place. Please read through the following blog post and collection of investigative material. For clarity, the "me" in the headline is not referring to me personally.

Someone is pretending to be me.

-Source: hackernews

The commonly understood version of identity theft as far as I'm aware of it, is that someone gets your personal information, like your address, birthdate and social security details and signs up for accounts or credit in your name. This steals money from the creditors and steals (or ruins) credit reputation for the victim. The goal is usually short-term and monetary.

However, the story described in the linked post seems much more insidious. In this era of remote development work that has been around since well before the pandemic, there have been many a developer or coder that has worked for a company and never actually met any of the stakeholders face-to-face. Online portfolio websites, online resumés, and public LinkedIn profiles have created an option for some nefarious actors to entirely pretend to be someone else specifically for the sole purpose of soliciting development work based on the reputation of the victim. The specific victim in the blog post linked above was luckily warned by a potential accomplice that was refused to be roped in.

Long story short, a supposed freelance development company (the bad actors here), were attempting to hire a developer named Andrew (the accomplice) to interview and interface with potential clients (so far, so good), all while pretending (uh-oh) to be a developer named Connor (the victim). Once Andrew got the full picture of what was going on, he backed out and contacted Connor directly to warn him. Connor was lucky.

So I previewed the document and it was scary. It was a document intended for someone to have a cheat sheet for an interview on how to act as me.

  • It included a subset of my personal information.
  • It included my education history.
  • It included my employment history.
  • It included my certifications.
  • It included a fake cover letter.
  • It included a fake email/address that was "near" mine.
  • It included information about the company interviewing for.
-Source: connortumbleson.com

Connor was very lucky, and smart enough to follow up and investigate all the possible details of the bad actors, and put them on blast. It's a good job of shaming them publicly. But ultimately the criminals in this case can simply move on, rebrand and start working on gathering work on the reputation of the next victim. Ultimately, the independent developer victims lose money because they aren't really the ones getting hired, and their reputations are most likely hurt given that the work is shoddy.

This is very scary. The only way to combat this is to raise awareness of the existence of this scam. I don't exactly have a big reputation or portfolio footprint at this exact moment so it's unlikely I'd be a target. But it's important me and professionals like me to be aware. It's also important for corporations large and small to be aware and do a proper investigation of who it is they are hiring. Since the bad actors are getting hired as "independent contractors" there's no HR investigation or other due diligence, no verifications. Here's more from Connor...

So it seemed like I was starting to understand the picture now.

  • A person/company sets up fake Upwork profiles of real people.
  • They apply to jobs in hopes to get an interview using that fake profile.
  • They find suspecting victims on GitHub who are willing to go along with this.
  • That person uses the identity of someone else to land the job.
-Source: connortumbleson.com

Connor's blog post was only first published a few weeks ago, and updated 9 days ago, so this is all very new and continues to develop. He will likely update the post as more details become available. Everyone be careful out there.

No comments:

Labels

family (33) Star Wars (28) web development (28) technology (24) blogs (22) blogger (21) movies (21) funny (20) Internet (19) google (18) del.icio.us (16) music (15) video (15) baby (14) random (14) reviews (13) friends (12) life story (12) rant (12) Lucas (11) news (11) MonsterCommerce (10) Reese (9) books (9) Samuel (8) domains (8) politics (8) google/pagerank (7) television (7) Charter (6) Facebook (6) MO ECHO (6) birthday (6) church (6) coworkers (6) local (6) zyilimusic (6) #MOECHOLINEUP (5) Sudden Infant Death Syndrome (5) christian (5) comics (5) employment (5) photos (5) Internet\AOL (4) Lisa (4) Olivia (4) election (4) job (4) marketing (4) microsoft (4) music/artists (4) quotes (4) television\American Idol (4) trombone (4) Barack Obama (3) Holidays/Christmas (3) Network Solutions (3) movies\Harry Potter (3) tattoo (3) xkcd (3) Happy Is The Bride (2) Holidays/New-Year (2) Integrity (2) International Date Format (2) Internet\AT+T (2) SoTel Systems (2) archive (2) customer service (2) google/maps (2) google/music (2) google/play (2) history (2) instant messenger (2) karaoke (2) movies\300 (2) poetry (2) polls (2) projects (2) quiz (2) video games (2) weather (2) 1982 (1) 1986 (1) 2012 (1) 2013 (1) 2014 (1) Angelcare monitor (1) Boy Scouts (1) Career Day (1) Dirty Soap (1) Earthquake (1) Free Champagne (1) Holidays/Halloween (1) Jon (1) Mad Men (1) Mom (1) NASA (1) Netflix (1) New Orleans Brass Band (1) Quincy Illinois (1) Rod and the Satalites (1) SEO (1) Salesforce Marketing Cloud (1) Sleep Apnea monitor (1) Star Trek (1) TED (1) autobiography (1) billionaires (1) blues (1) css (1) d+d (1) design (1) dining (1) divorce (1) eat the rich (1) economics (1) entertainment (1) environment (1) evolution (1) flickr (1) google/plus (1) hoax (1) html (1) identity theft (1) imgur (1) immigration (1) library (1) linkedin (1) ministry (1) money (1) movies\Batman (1) npr (1) pinterest (1) preface (1) proud (1) rain (1) reddit (1) reggae (1) rob thomas (1) science (1) ska (1) snow (1) social media (1) spring (1) tax the rich (1) television\Mad Men (1) telvision (1) tornado (1) trillian (1) tumblr (1) twitter (1) wishlist (1) woot (1) yahoo (1) youtube (1)

Some Other Things to See

© 2003-2021 James A. Arconati

You've reached the end of this page.

[ This page is powered by Blogger. Isn't yours? ]