Mumbai Be careful who you share your PAN (permanent account number) card details with. There are ways in which it can be misused. One of them, as the Anti-Corruption Bureau of the Central Bureau of Investigation (CBI ACB) recently found, is to file fake income tax returns and obtain illegal refunds in the name of a PAN card holder, all this with the help of I-T officials.
In mid-February, the CBI unearthed such a scam allegedly involving a small-time television actor, a senior tax assistant and officials of the income tax department. The fraud so far amounts to Rs3 crore, but investigating officials believe the figure is likely to touch Rs14 crore.
The CBI ACB arrested Dilip Vyas, a Dahisar (East) resident and the lead player in this case, on February 17. He has been remanded to police custody till March 3. On Sunday, television artiste Manoj Sangtiyani, senior tax assistant Rajesh Pillai and I-T officials Pramod Prabhakar and Raju Nagpure were also held. It is learnt that Vyas and Sangtiyani were business partners, involved in bill discounting and supply of construction materials. Mohan Ghatge, Ninad Dalvi, Sandeep Roy and another I-T official identified only as Shrikant, are still wanted in the case.
Interestingly, there were no ‘real’ victims in this case. Vyas, it appears, had used the PAN details of only those who were known to him, superintendent of police, CBI ACB, Anil Modak, told DNA. “He told the PAN card holders that he wanted to use their bank accounts to deposit some money and had promised one per cent of the deposited amount in return,” Modak said. Given their acquiescence in this conspiracy, even the real PAN card holders may be charged with abetting the crime.
Modak said that Vyas and Sangtiyani, with the help of their
assistants Dalvi and Roy, collected the PAN and bank details of 23 persons, as well as blank signed cheques from them. He then made fake income computations of the PAN card holders, stating fake transactions through which income had been generated. He then used these documents to file fake I-T returns on those PAN cards. The transactions shown were those that reduced the tax liability, thereby generating refunds. The e-refunds were then deposited in the concerned bank accounts.
The network grew after Vyas, who also claimed to be a chartered accountant, met Sangtiyani, who was known to Prabhakar and Nagpure at the terminal branch of the I-T department, at the Bandra Kurla Complex, Modak said.
Vyas provided PAN numbers, bank details and the fake I-T returns along with enclosures to Prabhakar (the I-T officials) through Sangtiyani,” said CBI joint director (west zone) Rishiraj Singh.
A CBI officer explained that Prabhakar, along with his assistants Nagpure and Shrikant, visited the BKC branch where they managed to break into the network access of the department, known as RSA Code. “But in order to access it, they required an identity and password. Pillai played a crucial role here, as he was close to an I-T official working there; they used his ID and password to log in,” he said.
They then entered the said data into the computer system and generated the e-refund, which would be electronically transferred to the respective bank accounts, said the official. “The money was then withdrawn and deposited by the accused into their bank accounts. There was no income tax deposited against these returns,” Singh said.
About Rs3 crore was credited to the bank accounts of the 23 PAN holders which was then withdrawn by using signed blank cheques. The bank accounts were mainly with the United Bank of India, Dahisar branch, and Kotak Mahindra Bank, Kalba Devi branch.
The scam came to light because of the amount of e-refunds generated.“Since such huge e-refunds are never migrated from the Central Circle office, this raised suspicion among senior I-T officers, who then informed the I-T commissioner about the fraud. He then got in touch with the CBI ACB,” said a CBI official, requesting anonymity.
How well do you know your CA?
How safe is the money of a common man who files his income tax returns, trusting his chartered accountant? “In this fraud, the PAN holders were close to the accused and had permitted them to use their documents and bank accounts through the greed of money (as they had been promised a commission). The common man should understand to what extent a person can be trusted as far as filing tax returns or getting refunds is concerned,” said Anil Modak, SP, CBI.
Holes in the I-T dept’s computer system
According to the CBI, this scam has revealed inherent loopholes in the income tax department’s computer system. For instance, even after one logs out of the network facilitating refunds, the machine will remain valid for processing for about four hours. In this time, any person having knowledge of the username and password of the assessing officer can access the network. What’s worse is that the officers do not change their passwords as required. They prefer to function on the default which is known to many, including their assistants.
22 February, 2010
PAN card holders play conspirators in I-T fraud
Posted by siva at 8:46 PM 0 comments
21 February, 2010
A year of UID: Much more than a number
The Unique Identification Authority of India (UIDAI), set up to issue a unique identification (UID) number to all 1.2 billion Indian residents, completes a year this month.
“We will be issuing the first set of UIDs between August 2010 and February 2011,” asserts former Infosys co-chairman Nandan Nilekani, who now heads the UIDAI. It’s a little over six months since he took charge, and he expects to issue 600 million UIDs over the next five years.
His team is being expanded; the headquarters is in Delhi and it has eight regional offices. During the 2009-10 budget, Rs 120 crore was allocated.
The project is also breathing life into other areas. For instance, the human resource development ministry will take its help to introduce educational reforms. Foremost among its goals is to use UID to bring the over eight million “out of school” children into the education system. Nilekani was also recently asked to head a National Highways Authority of India panel to select a technology to unify toll plazas across the country.
Discovery of Indians
Key points about the UID project
* Enrolment will not be mandated: The UIDAI approach will be a demand-driven one, where the benefits and services that are linked to the UID will ensure demand for the number. This will not however, preclude governments or Registrars from mandating enrolment
* The UIDAI will issue a number, not a card: The Authority’s role is limited to issuing the number. This number may be printed on the document/card that is issued by the Registrar
* The number will not contain intelligence: Loading intelligence into identity numbers makes them susceptible to fraud and theft. The UID will be a random number
* The Authority will only collect basic information like name, date of birth, gender, photo and fingerprints
* Process to ensure no duplicates: Registrars will send the applicant’s data to the central repository. The CIDR will perform a search on key demographic fields and on the biometrics for each new enrolment, to ensure that no duplicates exist
The bid to eliminate duplicate and fake identities, reasons Nilekani, could annually save the government exchequer upwards of Rs 20,000 crore. As an example, he says the ministry of petroleum could save the Rs 1,200 crore a year in subsidies now reportedly lost on cooking gas cylinders registered under duplicate or ghost identities.
The project is also expected to become a catalyst to achieve financial inclusion, he says. For instance, online authentication could be done even through a cellphone. And banks could have business correspondents (BCs) in villages, equipped with a mobile phone, a finger print reader and an ATM kind of software, to enable cash transactions in the village itself. Any NREG worker, notes Nilekani, could go to any BC and withdraw money, because UID would be an open architecture. Any shop owner could be appointed a BC, and there is no need to open branches in mofussil areas.
The approach
UIDAI leverages the existing infrastructure of government and private agencies. It will be the regulatory authority managing a Central ID Data Repository (CIDR), which will issue UID numbers, update resident information, and authenticate identities as required. “Tenders have been floated for various purposes. This is an ongoing process. The tender for a Consultant for the CIDR has already been called,” says Nilekani.
Registrars will be state governments or central government agencies such as the petroleum ministry and Life Insurance Corporation. Registrars may also be private sector participants such as banks and insurance companies. “The process of entering into MoUs with state governments is underway,” says Nilekani. He has also enlisted the assistance of close to 30 information technology professionals in the task, with the help of software body Nasscom.
The UID number will be issued to all residents who satisfy the verification procedure, explains Nilekani. “The number does not confer citizenship or nationality. Its primary purpose is to establish the identity of the person,” he clarifies. While enrolment into the UID system will not be online, authentication of identity will be online. The UIDAI itself will not be issuing cards.
How will it work?
Based on initial estimates, the enrolment of each resident may cost between Rs 20 and Rs 25, leading to a potential total enrolment cost of Rs 3,000 crore. The strategy will explore if the various beneficiaries could fund this. The Registrars have the option here of charging for the cards they issue. UIDAI may issue guidelines around such pricing.
Once the UID number is assigned, the authority will forward the resident a letter which contains his/her registered demographic and biometric details and a tearaway portion with the UID number, name, photograph and a 2D barcode of the fingerprint minutiae.
Residents can also update their information with UIDAI. The UID number is a lifetime number, but the biometric information contained in the central database will have to be regularly updated. Children may have to update their biometric information every five years, while adults do so their information every 10 years.
The Biometrics Standards Committee set up by UIDAI has also given its recommendations. The UIDAI would be taking the face, all 10 fingerprints and both iris scans for the biometrics of each person.
It will employ a GIS internet-based visual reporting system to track enrolment trends and patterns across India, as the project is rolled out. The GIS system will show all UID enrolments by state, as well as by Registrar. The system will also be able to drill down within states and into districts.
Revenue potential
UIDAI pegs its annual revenue potential, through both address verification and biometrics confirmation, at Rs 288 crore. It has identified three transaction types. The basic ID confirmation will be free, where the potential user agencies could be, for instance, the airlines which do passenger check-ins. The second type of transaction is that of ‘address verification’, which will cost Rs 5 and can be levied by banks when users open accounts. The third one comprises ‘biometrics confirmation’, which will be charged Rs 10. Its potential user agencies can be credit card companies.
Registrars and service providers will also be able to charge for the cards they issue residents with the UID number. Such pricing will be within UIDAI guidelines, states a draft paper.
Business opportunity
Biometrics (which includes fingerprint, face and iris recognition) and computing power hold the keys to the UID project, which is estimated to offer a Rs 15,000-20,000 crore opportunity to computing, database, smartcard and storage vendors besides systems integrators. For every rupee of IT spend on the project, industry experts estimate, around 60 per cent of this will go to hardware vendors.
Nilekani also speaks of “online authentication which has not been done anywhere in the world till date”. Online authentication is currently being tested out by researchers in institutes abroad. This will require added computing power, data connectivity.
The real business opportunities will start flowing once various government departments start using UID numbers to issue smartcards to citizens, says Ashok Chandak, Senior Director, Global Sales & Management, NXP Semiconductor.
Many government departments, for instance, will have to issue smartcards — for driving licences, for health insurance, for ID cards, etc., — and all these smartcards will draw on the UID database. Many other companies like Genpact, Microsoft, Google, TCS, Wipro and even Infosys have evinced interest in the project.
Privacy concerns
Experts are sceptical about the protection of the private data once the rollout of UID numbers begins towards the later half of the current calendar year. They fear the UID number which will be issued based on personal information given by a person might be leaked to various other agencies.
“If the UID is used by 10 different agencies for 10 different purposes, then a cross-linking of that data will, some time or other, happen. A common man won’t be able to take legal measures for the violation of privacy happening out of the data leakage,” cautioned Dinesh Charak, legal counsel for Nokia in India, at a recent discussion.
The UID Authority says it is trying to collect personal data in a very limited manner, to make sure there is no leakage. “We are not going to collect information about a person’s religion, but only names, gender, date of birth and address. It is just the basic information, whereas a lot of countries have loaded up their ID cards with a lot of (more) information,” says Deepika M of its legal team
Posted by siva at 10:42 AM 0 comments
Lankan national held for credit card fraud
The Chennai City Police on Wednesday arrested a 30 year old Sri Lankan national involved in a string of credit card frauds across the southern states.
One Sanjay Kanth hailing from Sri Lanka was picked up by sleuths of the Central Crime Branch(CCB) of the Chennai City Police at a shop on Pantheon Road, in Egmore , where he was trying to purchase a laptop and computer peripherals.
According to CCB officials, Sanjay is a B.Com graduate who was staying in a rented house in Alapakkam. On Wednesday afternoon, he went to a shop in Egmore to purchase a laptop and other accessories. When the three credit cards he gave in succession did not work, the shop owner grew suspicious and informed his bank.
The bank's risk manager informed the CCB, sleuths came to the store and nabbed Sanjay. Police then raided Sanjay's house and seized a laptop, pen drive, credit card encoding machine, 177 credit cards and Rs 1.63 lakh Indian currency, among other things.
"This person ran a fake credit card unit at home. He got details of bank accounts of people living abroad through his friends,' said a police officer.
"He encoded the same using the machine in his house, and would then use the fake card to withdraw money from ATMs in Chennai", the official added.
Sanjay has made purchases in Karnataka, Andhra Pradesh, Kerala and Tamil Nadu, and is said to have been involved in credit card fraud since 2001.
This is not the first instance of a Sri Lankan being arrested for credit card fraud. On December 24, 2009, CCB sleuths nabbed Vijay Kanth (29), another Sri Lankan national, for possessing fake credit cards and indulging in illegal business for seven monthsPosted by siva at 10:39 AM 0 comments
IT officials involved in scam
Mumbai, Feb 21 – The Central Bureau of Investigation (CBI) has arrested one person and detained four income tax (IT) department officials in connection with a Rs.30 million-IT refund scam, a top official said here Sunday.
The IT officials work in the information technology and other departments of the department in Mumbai, said CBI Western Region Director Rishi Raj Singh.
One of them had managed to secure the confidential password of the IT refunds assessing officer and it was used to process many forms using the IT PAN Card details of 23 ordinary people, he said.
‘By this, the accused managed to transfer over Rs.30 million worth of IT refunds to their personal accounts,’ Singh said.
The officials detained were Pramod Prabhakar, a senior IT inspector, Rajesh Pillai, Raju Nagpure and Manoj Santgiyani. They were undergoing CBI interrogation.
Their associate – Dilip Vyas, who acted as middleman in the scam – has been arrested.
The CBI is on the lookout for Vyas’ associates Sandeep Roy, Mohan Ghatge, an IT official Shrikant and one Ninad Dalvi who arranged the PAN cards.
‘The fraud was possible due to loopholes in the internal information technology systems of the IT department,’ Singh observed.
Investigations into the fraud are still underway and the IT department expects it to touch Rs.100 million and the number of PAN cards used in the scam could be more than 100.
The CBI acted on a complaint lodged by the IT Department Feb 4. The accused have been charged under various Indian Penal Code sections pertaining to cheating and committing fraud.
Posted by siva at 10:34 AM 0 comments
14 February, 2010
PIN NO MORE A SECURITY MEASURE
A fatal flaw in the chip and PIN technology that is supposed to guarantee the security of millions of credit and debit cards has been identified by scientists.
The loophole means stolen cards can be used in shop terminals and bank cash machines without being identified, it is claimed.
In theory, thieves would be able to make purchases and cash withdrawals without needing to key in the four digit PIN or being detected.
The chip and PIN system became universal on Valentine's Day 2006, replacing the use of signatures to authorise purchases.
At the time banks said the introduction of the PIN system would reduce card fraud because even if a card was stolen it could not be used by a thief who did not know the number.
Card fraud did fall initially, however, the figure rose 43 per cent by the end of 2008 to £610million and is thought to have risen even higher last year.
Professor Ross Anderson, from the Cambridge University Computer Lab, has uncovered a number of ways in which the system can be beaten. However, he claims the latest discovery is shocking in its simplicity.
Prof Anderson claims the banks may now need to rewrite the security software around the entire chip and PIN system in order to make it fully secure.
The researchers discovered that a small circuit board containing a computer chip and transmitter can be attached to the chip on the plastic card and concealed up the sleeve.
This communicates with a computer stored in a backpack worn by the criminal when using the card at a till or cash machine.
When the user is asked for the four digit PIN to authorise the transaction, they only need to key in a random code.
The software attached to the card then signals to the till terminal that a correct PIN has been used.
'We think this is one of the biggest flaws that has ever been uncovered against the PIN system and I have been in this business for 25 years,' said Prof Anderson.
Details of the flaw were revealed on BBC's Newsnight programme last night. It showed how four different cards could be authorised for purchases in a Cambridge University canteen by using a fake PIN of 0000.
Consumer lawyer, Stephen Mason, told the programme: 'The loopholes in the chip and PIN system are serious and I don't think they have been properlyaddressed by the banks. They really have to think about this seriously.'
The introduction of chip and PIN brought with it a greater risk that victims of card fraud would have to carry the cost of any losses.
Some banks have refused to refund losses where they argued consumers had been careless with their cards or failed to keep their PIN a secret.
Prof Anderson added: 'The banks have been lying about the security of their systems and the industry regulators have been completely gullible.'
But the banks trade body, the UK Cards Association, denied the discovery was serious.
'We believe that this complicated method will never present a real threat to our customers cards,' it said.
Posted by siva at 12:05 PM 0 comments