Internet Certificate - Fraud
Discussion
Hi can anyone advice.
A friends company name is being used to commit fraud. We know of a couple of cases and the amounts are large. One which failed when the target got suspicious was for almost £100k. He has reported it to action fraud but since he has not lost anything they have just said they will add it to their intelligence reports. He has reported it to the FCA since it relates to regulated activities and they will look into it.
The fraudster has set up a web site using the company name. They have even included the company registered address and number.
Looking at the web site it is "https" and I can see the lock box which shows the details of the certificate provider. They have a web site and the certificate is from the UK subsidiary which has been in existence since 2000.
He tried emailing the company abuse addy but it bounced.
I had always assumed the certification gave a level of security, is this correct? If it does, does anyone regulate UK certificate providers.
A friends company name is being used to commit fraud. We know of a couple of cases and the amounts are large. One which failed when the target got suspicious was for almost £100k. He has reported it to action fraud but since he has not lost anything they have just said they will add it to their intelligence reports. He has reported it to the FCA since it relates to regulated activities and they will look into it.
The fraudster has set up a web site using the company name. They have even included the company registered address and number.
Looking at the web site it is "https" and I can see the lock box which shows the details of the certificate provider. They have a web site and the certificate is from the UK subsidiary which has been in existence since 2000.
He tried emailing the company abuse addy but it bounced.
I had always assumed the certification gave a level of security, is this correct? If it does, does anyone regulate UK certificate providers.
Mrr T said:
Hi can anyone advice.
A friends company name is being used to commit fraud. We know of a couple of cases and the amounts are large. One which failed when the target got suspicious was for almost £100k. He has reported it to action fraud but since he has not lost anything they have just said they will add it to their intelligence reports. He has reported it to the FCA since it relates to regulated activities and they will look into it.
The fraudster has set up a web site using the company name. They have even included the company registered address and number.
Looking at the web site it is "https" and I can see the lock box which shows the details of the certificate provider. They have a web site and the certificate is from the UK subsidiary which has been in existence since 2000.
He tried emailing the company abuse addy but it bounced.
I had always assumed the certification gave a level of security, is this correct? If it does, does anyone regulate UK certificate providers.
First level of SSL certificate only proves you have access to the domain. If you can receive the email for that domain, then you will get a certificate issued.A friends company name is being used to commit fraud. We know of a couple of cases and the amounts are large. One which failed when the target got suspicious was for almost £100k. He has reported it to action fraud but since he has not lost anything they have just said they will add it to their intelligence reports. He has reported it to the FCA since it relates to regulated activities and they will look into it.
The fraudster has set up a web site using the company name. They have even included the company registered address and number.
Looking at the web site it is "https" and I can see the lock box which shows the details of the certificate provider. They have a web site and the certificate is from the UK subsidiary which has been in existence since 2000.
He tried emailing the company abuse addy but it bounced.
I had always assumed the certification gave a level of security, is this correct? If it does, does anyone regulate UK certificate providers.
Other levels require paperwork.
Is it a .uk domain? If so Nominet have a dispute resolution service and could act.
I am assuming here it is a new domain that sounds like your friends company, rather than being their actual domain.
A bog standard Domain Verified SSL doesn't have any checks on the actual company requesting the certificate - All it checks is that they have control over the domain (Usually by way of a DNS record or uploading a file to a specific path).
In theory, I could register Goooggle.com and get a DV SSL for that domain for free and try and impersonate Google.
Unless it's an Extended Validation certificate (Green bar/padlock), don't guarantee it's not a scam site (Neither do EVs really, but they do some basic checks)
In theory, I could register Goooggle.com and get a DV SSL for that domain for free and try and impersonate Google.
Unless it's an Extended Validation certificate (Green bar/padlock), don't guarantee it's not a scam site (Neither do EVs really, but they do some basic checks)
No ideas for a name said:
First level of SSL certificate only proves you have access to the domain. If you can receive the email for that domain, then you will get a certificate issued.
Other levels require paperwork.
Is it a .uk domain? If so Nominet have a dispute resolution service and could act.
You might need to explain more not my areas of expertise. It's just a website. It has a section to ask them to contact you but I did not want to use it because I know its a fraud. I know they have contacted other by email but not seen the mail. Other levels require paperwork.
Is it a .uk domain? If so Nominet have a dispute resolution service and could act.
So all I am looking at is the certificate on the lock box in the Url. It's a com.
Mrr T said:
You might need to explain more not my areas of expertise. It's just a website. It has a section to ask them to contact you but I did not want to use it because I know its a fraud. I know they have contacted other by email but not seen the mail.
So all I am looking at is the certificate on the lock box in the Url. It's a com.
If you want to PM me with the details I can do a bit of digging for you.So all I am looking at is the certificate on the lock box in the Url. It's a com.
Simply ref the certificate... the process goes along the lines of applying for an SSL cert for a host (web site) and generating some info of who you are [or pretend to be] ... a Certificate Request. The mail records for that domain are queried and the SSL provider sends an email to that domain... the owner picks that up, and replies to authorise it. It then gets issued.
Not really much proof of anything.
It depends who is providing the certificate.
In practice as noone bothers to check the provider, all it proves is who controls the domain name (as you can always get automated certificates from lets encrypt etc.)
If you do a whois (easiest way is probably http://who.is ) you should be able to find out who the domain name registrar is (e.g. godaddy.com is the registrar for pistonheads). They should have a complaints procedure, which hopefully should allow the company being fraudulently misrepresented to (eventually...) take over the domain registration for the standard fee... (Likely a lot easier than going after the https certificate provider).
In practice as noone bothers to check the provider, all it proves is who controls the domain name (as you can always get automated certificates from lets encrypt etc.)
If you do a whois (easiest way is probably http://who.is ) you should be able to find out who the domain name registrar is (e.g. godaddy.com is the registrar for pistonheads). They should have a complaints procedure, which hopefully should allow the company being fraudulently misrepresented to (eventually...) take over the domain registration for the standard fee... (Likely a lot easier than going after the https certificate provider).
put another way - if your friends company is called Joe Bloggs and he owns joebloggs.com then I can buy other similar domains:
- joebloggs.net
- joebloggs.co.uk
- joebloggscompany.com
- shopatjoebloggs.com
etc. (assuming no-one else has them)
any domain I can buy, I can get an SSL certificate for it...
there is basic verification in buying a domain - so if you register joebloggscompany.com with a registrant of Fred Brown at Fred Brown's address, there may be a verification process to confirm that Fred Brown is linked to that address - but there is no verification as to Fred Brown's right to register joebloggscompany.com
the only issues with domains etc. will be in the fields of trademarks / passing off / etc. but that is the content, not the domain name on its own as one trademark may not be a trademark in another market (hence the reason that apple.co.uk was not owned by Apple for many years) so it is perfectly legitimate to buy / own a domain name which could be used inappropriately... if someone then does so the line of pursuit can be in several places but would be based on passing off / fraud / trademark abuse / etc. - the domain issuer will probably have zero interest - though the hosting company might be more interested esp. if you threaten a takedown notice on them - but a lawyer should be first point of contact anyway...
- joebloggs.net
- joebloggs.co.uk
- joebloggscompany.com
- shopatjoebloggs.com
etc. (assuming no-one else has them)
any domain I can buy, I can get an SSL certificate for it...
there is basic verification in buying a domain - so if you register joebloggscompany.com with a registrant of Fred Brown at Fred Brown's address, there may be a verification process to confirm that Fred Brown is linked to that address - but there is no verification as to Fred Brown's right to register joebloggscompany.com
the only issues with domains etc. will be in the fields of trademarks / passing off / etc. but that is the content, not the domain name on its own as one trademark may not be a trademark in another market (hence the reason that apple.co.uk was not owned by Apple for many years) so it is perfectly legitimate to buy / own a domain name which could be used inappropriately... if someone then does so the line of pursuit can be in several places but would be based on passing off / fraud / trademark abuse / etc. - the domain issuer will probably have zero interest - though the hosting company might be more interested esp. if you threaten a takedown notice on them - but a lawyer should be first point of contact anyway...
Thank you all for your explanations. I understand now.
I am surprised by the total lack of any validation but this is 2020 and no one commits fraud!!!!
I am sure everyone on here is to bright to be caught. However, if you hear anyone is looking at buying bank bonds issued some years ago when interest rates where much higher at par. Then its a fraud and please PM me.
I am surprised by the total lack of any validation but this is 2020 and no one commits fraud!!!!
I am sure everyone on here is to bright to be caught. However, if you hear anyone is looking at buying bank bonds issued some years ago when interest rates where much higher at par. Then its a fraud and please PM me.
Forums | Speed, Plod & the Law | Top of Page | What's New | My Stuff


