Large companies (un?)knowingly hire spammers

This morning, CSO and MacKeeper published joint articles on a massive data leak from a marketing company. (Update: 2019: both articles are gone, a cached version of the CSOnline link is at https://hackerfall.com/story/the-fall-of-an-empire-spammers-expose-their-entire)  This company, River City Media (RCM), failed to put a password on their online backups sometime. This leaked all of the company’s data out to the Internet at large. MacKeeper Security Researcher, Chris Vickery discovered the breach back in December and shared the information with Spamhaus and CSO online.
The group has spent months going through the data from this spammer. As of this morning, the existence of the breach and an overview of the extent of their operation were revealed by CSO and MacKeeper. Additionally, Spamhaus listed the network on the Register of Known Spamming Operations (ROKSO).

There are a couple interesting pieces of this story relevant to legitimate marketers.
The biggest issue is the number of brands who are paying spammers to send mail from them. The CSO article lists just some of the brands that were buying mail services from RCM:

[…] Nike, LifeLock, Liberty Mutual, Fidelity, MetLife, Victoria’s Secret, Kitchen Aide, Yankee Candle, Bath & Body Works, Gillette, Match.com, Dollar Shave Club, Dewalt, DirecTV, Covergirl, Clinique, Maybelline, Terminix, and AT&T.

This shouldn’t be a surprise to anyone who has been paying attention to the industry. We described this many years ago in a series of articles about mainstream spam. (Note: the organization in the article has cleaned up their act and no longer uses affiliates).
Addresses were collected through many ways, including the use of co-reg. Chris Vickery explains:

Well-informed individuals did not choose to sign up for bulk advertisements over a billion times. The most likely scenario is a combination of techniques. One is called co-registration. That’s when you click on the “Submit” or “I agree” box next to all the small text on a website. Without knowing it, you have potentially agreed your personal details can be shared with affiliates of the site.
You are never told who the affiliates are and groups like River City Media capitalize on that aspect. One line of the leaked chat logs explains it all very succinctly:
“The key is sincerity.  Once you can fake that…”

Legitimate companies do buy co-reg data, still. The problem is that there’s no real permission associated with the address. In the absolute best case scenario, permission is taken by the co-reg provider rather than given by the recipient. All too many co-reg vendors go out of their way to hide the fact that they will sell the addresses in their privacy policies. This isn’t transparent. This isn’t real permission.
One argument I’ve heard over and over about laws, particularly CASL, is that it’s targeting the wrong companies. As the argument goes, the real problem with spam is spammers, not legitimate companies. But CASL and other laws target legitimate companies. I never really bought into that argument as it’s clear to me a lot of the money supporting spammers comes from the legitimate companies spending real marketing funds.
Legitimate companies are paying third parties to send spam on their behalf and are profiting. For a long time brands have pretended they’re not responsible for the mail. This recent breach shows that they are paying spammers to send mail on their behalf.
Looks like maybe the laws are targeting the right companies.

After this was posted, River City Media sued Chris Vickery and others. https://www.courtlistener.com/docket/4685667/1/river-city-media-llc-v-kromtech-alliance-corporation/. The case was settled in September 2018. 

Related Posts

The 10 worst …

Spamhaus gave a bunch of us a preview of their new “Top 10 worst” (or should that be bottom 10?) lists at M3AAWG. These lists have now been released to the public.
sh_logo1
The categories they’re measuring are:

Read More

One way to deal with B2B spam

We’ve been talking a lot about B2B spam recently. I’ve posted repeatedly, Steve wrote a post about it yesterday. It’s in the forefront of our minds because we’re dealing with just so much of it. Multiple emails a day asking for “just 10 minutes of your time.” Of course, the 10 minutes isn’t really just 10 minutes. Sure, the call might be 10 minutes, but there’s overhead to that call that will probably eat 20 – 30 minutes of time. That’s at best.
Because they’re using providers who don’t notice or don’t care about the spam, there’s little to be done. No one is going to stop them from mailing me. They are required to comply with the law, but 99% of the mail doesn’t. Which gave me an idea.
I’ve started replying to every incident of “just 10 minutes of your time” with a pleasant email thanking them for their interest in our CAN SPAM verification program. I point out that I have noticed at least one violation and we’re happy to consult with them on how to fix it for a fee.
Wait? You mean they’re not interrupting my time simply to receive a sales pitch? Well. Gee. I’m just replying to them.
It seems petty, but we’re less than 2 weeks into 2017 and I already have over a dozen of these “one time” emails. If history tells me anything, these same people will follow up in a week, and then 2 weeks, and then a month. Meanwhile, new people are going to be sending me a request for 10 minutes of my time, and their followups and in a month I’ll be getting a dozen emails a week. In two months I’ll be getting 2 dozen. In 3 months it will be 4 dozen.
And, yeah, most of these messages do violate CAN SPAM. Most of them by not including an unsubscribe links, which makes getting the mail to stop a challenge. There’s no way to unsubscribe, so it’s either answer it or just keep getting contacted. I wrote last year about the woman who continued to email me for months. She even announced she was going to call 911 because clearly I was injured and unable to answer her mail.  Multiple times she promised to stop mailing me, but never did.
I do feel bad for many of these senders. They’ve been sold on a prospecting tool by vendors who fail to provide them with a minimal level of guidance. Even just mentioning that there are laws regulating email, and they should comply with them would be better than nothing.
In many ways I find this kind of spam more annoying than the viagra or the malware that ends up in my mailbox. Those can be selected and deleted pretty easily. These, however, have subject lines that look just like my legitimate business mail. I have to read them and figure stuff out. It’s a total PITA.
EDIT: And it’s not even effective according to some experts.

Read More

CBL issues

I started seeing some folks complain about false CBL listings a few hours ago. I’m now seeing the same folks saying the listings are being removed.
The symptoms look similar to what happened in November (mentioned here), but it appears the CBL team are on top of things and are working to rectify things quickly.

Read More