For most people, a scam has a pretty straightforward structure: The scammer offers a good or service, or claims the victim owes them a debt, and the victim hands over money or valuables under the guise of a legitimate transaction. You buy an expensive stereo in a parking lot and it turns out to be a cheap stereo with a new badge glued on. Someone calls you saying they’re with the IRS and you must pay them or you’ll go to jail. If you ask someone to describe a scam, this is typically the format they’ll describe. The hallmarks are misleading communication or outright lies and a willing, if coerced, exchange.
The Taxonomical Hole
What I described before is not the currently used definition of a scam, just a type of scam. Even in the context of infosec, a scam is generally any scheme designed to mislead someone to allow them to steal something. Consider the following:
SomeBank customer gets a call and the caller ID reads, “SomeBank Fraud Department.” The customer answers the phone and is told that there has been some suspicious activity on their account. The customer then is walked through providing sensitive information, like their account numbers, security questions and answers, and other information about their accounts. They thank them for confirming the information, end the call, and then drain the victim’s account using the stolen information.
This is a scam, and on the surface, it looks almost the same as I described earlier. However, in a classical scam, the transaction is the crime and the goal, but that’s not where our example ends. If it ended at the transaction, the scammer’s job would not be complete.
If the transaction portion is not where it ends, I’d argue this is something that requires a definition for itself. It’s not a scam in the same sense, but not something else entirely. It’s fraud for sure, and still a scam by broad definition, but it’s also a specific format that may not align with the warning bells people have in their minds about scams. Technically, most versions have a component of phishing as well, but it doesn’t fit cleanly under just phishing either.
Gateway Fraud: The Hallmarks
I’ve decided I like the name Gateway Fraud, because it fits the differentiator from a classical scam: The scam isn’t the end, but a gateway to the goal.
Gateway fraud is, simply, engaging with a victim under the guise of legitimacy in order to have them willingly turn over information or take action that will be used to steal assets.
Another example, in a different format:
An old friend on Steam messages, and says, “Hey man! I’ve been working on this game for a while, but need some play testers. Can you give me some feedback? Here’s the link.”
The link looks legitimate. It seems like they’ve really been putting the work in on this tower defense game. You’re convinced, so you download it and run the provided executable. Nothing happens at first. You message them saying it’s not working and get no reply. Suddenly, you get logged out of Steam. You get an email saying someone has logged into Steam on your account from somewhere halfway around the world. By the time you regain access to your account, your $2000 inventory of CS2 items are gone.
Our victim never turned over their Steam information, and never committed to a transaction where they give the attacker assets. All they agreed to give the attacker was some of their time and effort, taking a seemingly minimal action. The transfer of their assets was unwilling.
The exact hallmarks:
- Communication under a guise of legitimacy: The fabricated scenario or trusted persona used to bypass suspicion.
- Willing participation: The victim actively, if coerced, taking the requested action or providing the requested information.
- An intermediate transaction: The acquisition of access or information, which is then used to acquire what they are actually after.
- The use of the information: The information is used to steal the asset(s) they were actually after.
A rose by any other name…
If someone says their email was hacked and they no longer have control of it, not much additional information is communicated. If someone says they were phished and lost control of their email, you immediately understand the broad strokes of the attack. Similarly, if someone says they were scammed, it can be somewhat ambiguous what happened, aside from losing some asset. If they say they were a victim of gateway fraud, you immediately understand the structure of the attack, if not the exact details.
Being able to efficiently and specifically communicate can be very important when combatting bad actors. It can make it clearer why your rules and policies exist, make it easier to find resources on recovery, and reduce friction in communicating about attacks.
This specific formula of attack is something that I feel deserves a name.
Leave a comment