E-mail account hacked

Scammers cracked Val’s Gmail account yesterday, and sent mail to several (possibly all) people in her address book begging for money and saying she was stranded in Scotland.

This has happened to several other people I know, and I doubt that anyone we know would fall for this scam, but here’s a warning just in case. Most of the scam letters sent out seem to say that the owner of the e-mail account is stranded there, so perhaps the scammers are themselves based there.

Update

Here is an update, posted on 19 June 2010. It illustrates what I was talking about in the previous message about “identity theft”. In this case the “phisher” was personating Google.
Val’s gmail account was hijacked a couple of days ago by someone on a phishing expedition using the e-mail address

malowoseloseyi@live.co.uk

and was apparently using this Gmail address:

fvgoogglequaltycontrolpanel@gmail.com (note the gg in googgle)

He sent an e-mail, ostensibly from Gmail itself, asking for name and
password details:

=== quoted phishing message ====
From: Google Quality Control Panel
Date: Sun, Jun 13, 2010 at 10:29 AM Subject: Warning: from Google Quality
Control Team To:

Our Google Data network has encountered a problem due to suspicious and malicious activities. Therefore Gmail Control Team want to verify your domain details with the details on our system. Please help us with the verification process by filling out the details below so as to make a correspondence with the your details. Full Name-
Password-
Phone Number-
Country-

Thanks for using Gmail.

– The Gmail Team. –>

=== end of quoted phishing message ===

If you get a message like this, do not reply to it, but click on the arrow next to the “reply” button and select “Report phishing” and send it there.

I am sending this to all the people in my address book who have G-mail addresses. If you were in Val’s address book as well you have probably already received some spam my now.

Val’s account has now been restored, BUT the phisher also redirected all incoming mail to his account, and deleted it from Val’s G-mail account, so she’s now going through the Trash folder to restore the mail.

Also, her address book was empty, which probably means that they have the contacts list, so Val’s contacts will probably continue to receive spam.

See also the previous message on identity theft and family history.

Identity theft and family history

One of the families I am interested in is Growden, and so I was interested in this article Identity thieves prey on everyone, advocate stresses | Local News | Cumberland Times-News:

Last week, a LaVale woman arrived home from her vacation in Virginia Beach, Va., to find charges on her credit card from ITunes. She did some further research and discovered other charges from a bank overseas. Somewhere, on her otherwise restful vacation, a thief had stolen her credit card number and made fraudulent charges. The local woman became the latest victim of identity theft. It happened that quickly.

“And that woman was me,” said Desiree Growden, the coordinator of the local Communities Against Senior Exploitation program. A national effort, CASE was launched in 2002 in Denver and introduced to Allegany County through the local state’s attorney’s office in 2009. Growden said the intent of the CASE program is to educate people on the dangers of identity theft.

Actually, “identity theft” is something of a misnomer. The danger here is not so much identity theft, as impersonation, or as it is sometimes called in criminal law, personation. To personate someone is to assume their identity with intent to deceive. To impersonate someone is a more everyday thing, and not necessarily done with criminal intent. So, for example one gets Elvis impersonators. But what is sometimes called “identity theft” is actually, in most cases, personation.

I’ve often read scare stories about “identity theft”, and have found that it is usually a question of simple personation. Someone who has pretended to be you has bought goods in your name, so that the account goes to you. Or they have withdrawn money from your bank account, pretending to be you.

Identity theft is a lot more serious. If someone steals something from you, you no longer have the use of it. If someone steals your car, you can’t drive anywhere, but have to walk. If someone steals your identity, you are no longer you, or at least no one believes you are you. This is the kind of thing that sometimes happens in science fiction or horror stories – a man goes on a journey and returns home to find that someone has stolen his identity, and is living in his house, with his wife, and his children call the stranger “daddy”, and no longer recognise their real father. That is identity theft, and of course it is personation as well. But someone who personates you in order to withdraw money from your bank account has stolen your money, not your identity. You are still you.

But there are scams that involve identity theft, and they were quite common a few years ago. One was when someone personates you to take out a life insurance policy on your life. Then they get a forged death certificate, and claim on the policy. And they might try to do several other things with it. And suddenly, to a lot of people, you are no longer you, because “you” are dead. In that kind of case, your identity really has been stolen, because even if you know who you are, nobody believes you.

But whether it is simple personation, or actual identity theft, it is still nasty, and something one needs to take precautions against.

How does it affect family history?

One example is that went I moved to where I am living now, I opened a bank account at a local bank, and on the application form I had to give my mother’s maiden name. They didn’t say why they wanted it, but I later discovered that if someone came into the bank claiming to be me, the bank would allow them to operate my account if they could tell the bank my mother’s maiden name. Now that was really stupid on the part of the bank. They thought it provided security and would make it harder for scammers to personate their clients. But family historians know the maiden names of most of the mothers in their family, and are anxious to find out the rest. So using the mother’s maiden name as a security question was really stupid. I think the banks have learnt a few lessons since then, and are not quite so naive about it. But if at the time they had told me that that was why they wanted me to put my mother’s maiden name on the application form, I could have told them how stupid it was.

If one is putting a family tree in a public place, like a web site, then most programs that create them allow one to avoid showing full information about living persons, and it is wise to do that, precisely because of the danger of personation.

We have a Growden family internet forum, with a mailing list, and a place to exchange files and photographs and to share information throuigh databases. But it is a “members only” forum. You have to say what your interest in the family is before you can join.

I have sometimes had requests from complete strangers, asking me to send them all the information on the Xxxx family. My response to such requests is to ask how they are linked to that family, and whether they are related, and what their relationship is. If they can show that they actually are related, then I will gladly share family history information with them, but it must be a two-way thing. I won’t give my research unless they are prepared to give me theirs. The ones who simply ask for “all the information” on the Xxxx family” might be naive newbies, who pick a branch of a family that isn’t really theirs, and latch on to it, or else they are scammers looking for information to try to personate someone in the family for criminal purposes. So my rule is, don’t share your family information with people who aren’t prepared to share theirs with you. If you take reasonable precautions like that, you are unlikely to fall victim to personation because of your family history.

The greater danger is phishing, with phony e-mails pretending to be from your bank or something, and asking for your account and password details. I got one like that yesterday.

Dear Customer,
Absa bank technical department will be carrying out a systematic
upgrade on our Network server from 7am today to 5am tomorrow morning to
avoid hackers from accessing your online account.
To take your account through this update process,
Please click on the link below
https://ib.absa.co.za/ib/tvn_upgrade
*Note. Absa Bank will not be responsible for loss of funds to online Phishers
as a result of failure to comply with this new directive.
You will also need to verify your TVN upon request.
Thank You

But hovering the cursor over the URL they asked you to click on showed this:

http://thoughtbroker.com.au/upgrades.absa/absa-banking-update/logonform.do/ibank-login.php

Now why would a South African bank (where I don’t have an account anyway) have an address at a web site called “thoughtbroker.com.au”? That’s a dead giveaway, and it’s as phishy as hell.

And some of the phishers are even more naive, and send their bogus messages from webmail addresses like gmail or yahoo. No reputable bank would send a message from an address like that, though some of the victims of the phishers are apparently even more naive, and fall for that sort of thing.

To get back to family history: be careful, but don’t be paranoid. Within the last month I’ve made contact with four distant cousins, in either my family or my wife’s, because they discovered links either on this blog or on one of our other family web sites. And because we’ve agreed to share information, once we have established the links, we’ve learnt a lot more about hitherto unknown branches of our family, and so have they about theirs. If we’d been over-suspicious, we might have missed a lot.

But a few years ago I had a couple of strange and rather frustrating encounters with over-suspicious family history researchers. One (no names, no pack drill) complained that I had posted information about “their” family (which was mine as well) on the web, and said I ought to have informed them of this, when I hadn’t even known they existed. But they themselves had posted family history queries on all sorts of web sites and magazines, without informing me, and it was in fact through one of the queries that they had posted in a magazine that I had managed to make contact with them at all, and discovered descendants of a branch of the family that connected with mine in the 1830s. They mentioned concerns about identity theft, but posting family details from the 1830s is hardly likely to help identity thieves, and they had posted more than I had. It was rather sad, because by sharing information we could probably both advance our research.

Another example was even more strange and frustrating was correspondence with someone I knew only as “visionir”, and was researching the Stooke family. I mentioned which branch I was interested in, and got this reply:

I have that branch quite straight and have been in contact with the
descendants of the children Mary and Sarah.
The William I am claiming was 7, in Love Street, Clifton in 1851.
His father was Thomas age 38 born Westbury, Salop.

The Mary in question was my great grandmother, Mary Barber Stooke who married William Allen Hayes, and the Sarah was her sister. I didn’t have that branch quite straight, and wasn’t in contact with their descendants, and would dearly love to learn more, but “visionir” wasn’t telling. In that case I don’t think it was oversuspiciousness or malice, but just being rather scatty and disorganised, and assuming that everyone already knew everything that they knew. Eventually I did manage, about 10 messages later, to get out of him/her that Sarah Stooke had married someone called Charlie Parker who kept a pub in Bristol. And I wasn’t able to help “visionir” much because the information he/she gave was too disconnected to make any sense of.

In neither of these cases did the people concerned use computers to keep track of their genealogy, though they did use the Internet to contact others. This led to some weird assumptions. For example the first lot took offence that my genealogy program put my contact address at the bottom of a family group sheet I sent them to show what I had on that branch of the family. They accused me of “claiming” their research. I think that is carrying the hermeneutic of suspicion too far.

Axholme Ancestry

A few days ago I found the web site of a hitherto unknown cousin, Penny Howell, who is also descended from the Vause family, and in following up some loose ends on that family discovered another web site that deals with Isle of Axholme family history, Axholme Ancestry. It seems to be a remarkably useful site for anyone whose ancestors come from the Isle of Axholme.

Epworth, Lincolnshire, England (May 2005)

Our Vause ancestors seem to originate in Epworth in the Isle of Axholme, which is north-west Lincolnshire in England. There seem to be several Vause families in Epworth and in the neighbouring town of Belton, and the Axholme Ancestry site lets everyone put their families into a single database, which should make it easier to find out if there are any links between them.

St Andrew's Church, Epworth

Though they started in Epworth our Vause family moved around a bit, because they also lived in Fishlake and Thorne in Yorkshire, and my great-great grandfather, Richard Vause (1822-1886), was born in Hull, across the river Humber, in the East Riding of Yorkshire. The whole area is sometimes called Humberside, which is a good geographical name, though some people objected to it because it was a short-lived administrative county that took people out of their traditional counties. But the Axholme Ancestry web site covers a lot of the neighbouring towns and cities as well, because ours wasn’t the only family that moved around.

St Oswald's Church, Crowle, Lincolnshire

Richard Vause’s father, John Vause (1784-1863), was born in Epworth. He was a maltster of Myton in Hull at the time his eldest son Richard was born. He lived at Thorninghurst, near Thorne, Yorkshire from about 1825-1835, then moved to Crowle, where he was an innkeeper of the Cross Keys commercial hotel.

There were other Vause families that lived at Crowle too, the database at Axholme Ancestry may make it a bit easier to find links between them.

Early history of the Vause family

I recently came across another Vause cousin on the web, Penny Howell in Canada and have been looking again at the earliest Vause ancestors we have recorded.

The earliest member of the Vause family that we know of is Robert Vause, of Kelsey in South Lincolnshire, who voted in Epworth in the election of the Knights of the Shire, and died in 1748.

But that is open to question.

The information came from Arthur Wyatt Ellis who compiled (or had compiled) a family tree which made its way to several members of the family in South Africa. Don Stayt had a photocopy, as did Mollie Vause-Doyle. The information may have come from the will of this Robert Vause of South Kelsey, who apparently left his lands in Epworth to his son Robert. The tree shows two other sons, Richard and Thomas. Richard is our ancestor.

Arthur Wyatt Ellis was born about 1880 in Reynoldston, Glamorgan, Wales (according to the 1880 census), the son of Henry Vause Ellis, who was himself the son of Phineas Samuel Ellis and Fanny Vause. He obviously maintained some contact with the family in South Africa, since his family tree made its way here.

But it seems more likely that Richard and Thomas were the sons of John Vause and Anne Gilliott of Epworth, who were married in Epwoth in 1702. If  so, then there were two other brothers, John and Alexander, but no Robert. Perhaps this will be answered if we can find the will of Robert Vause of South Kelsey.

For more on this see the Vause family page on our family Wiki.