By Mark J. Welch - updated January 20, 1997
This is a story about an angry junk email vendor and the damage he did in one week. But maybe it is really a story about how not to run an internet service business.
On January 1, 3, 4, and 5, 1997, someone sent huge volumes of junk email "spam" using an IBM.NET access account. Two different spams were sent: one promoted a baldness cure (the "Minoxydil" / "Thinning Hair" message) and the other appeared to promote an "adult" web service (the "El Cheepo" message).
The "Thinning Hair" message was extremely long, and was sent repeatedly, each time accompanied by a huge list of the email addresses to which that specific message was sent (the same message was sent to many different lists of email addresses). The "El Cheepo" spam was also sent multiple times, also accompanied by a list of email addresses; the "El Cheepo" message text was was shorter but deliberately more offensive than the "Thinning Hair" spam.
The "El Cheepo" spam was forged to show a return address of "JOES@JOES.COM" and was intended to sound as if it promoted a web site (hosted at a domain called HE.NET), but in fact it was sent in order to harass the owner of the "Joe's" web site -- apparently because JOES.COM had terminated the "baldness cure" web page of Yuri Rutman, after Mr. Rutman repeatedly sent unsolicited commercial email (the "Thinning Hair" spam). The "El Cheepo" message ended with a specific statement that the sender would not remove names from his list, but would continue to spam with impunity.
The "El Cheepo" email appears to have been sent deliberately to provoke an aggressive response. And that's exactly what happened. Huge numbers of complaints were sent to JOES.COM and HE.NET (Hurricane Electric), and as a result, the JOES.COM domain was completely cut off to prevent tens of thousands of "mailbombs" from completely stopping all traffic at the HE.NET site..
But many web-literate recipients immediately reported that the "El Cheepo" message was suspicious, because it looked more like "flame-bait" than solicitation. And a quick review of the message showed that it was broadcast entirely through the IBM.NET network, and not from any computers associated with JOES.COM or HE.NET. One suspicious sign: the "El Cheepo" and "Thinning Hair" spams were both sent from exactly the same IBM network nodes (at ny.us.ibm.net, which serves the entire eastern US).
IBM As Villain: Some users -- including me -- submitted multiple reports of these abuses to IBM.NET -- and were ignored. I even called IBM.NET (IBM Global Network) and asked to speak to the network operations center or security department, but I was repeatedly told I could not do so.
At one point, Jim Howle ("email@example.com") posted a message stating that the user originating these spams had been "warned," which was clearly not an appropriate action since the spam was continually and repeatedly being broadcast to the same people. (He later wrote to report that the offending account had been terminated, but by mid-week, his email address was disabled, probably due to angry mailbombing after the original inadequate reply.)
Later in the week, I received the following explanation from ReneBoer@IBM.Net: "The bad thing is that this spam hit just before the weekend. During the weekend the legal department is closed, and they are the only once that are allowed to investigate SPAMS and close the accounts used by offenders. Jim Howle you are referring to on your Web page is one of the people in the leagal depertment." [sic]
Earlier, on Saturday and Sunday, the lack of any response or action by IBM -- and the continuing re-broadcast of these same offensive messages from the same IBM.NET nodes -- fueled a sense of outrage in many webmasters. Some Internet Service Providers (ISPs) began adding filters to block all incoming mail from IBM.NET -- beginning the process of cutting IBM's internet customers from email access to the internet.
I called IBM for the third time on Sunday evening and again was told there was no way I could speak with anyone in security or in the network operations center. I had forwarded about 50 copies of the "El Cheepo" and "Thinning Hair" spams to IBM.NET, and I also forwarded copies of many reports suggesting the source of the spam (see below) to IBM.NET, but I received no response at all, even to the earliest complaints submitted more than 48 hours earlier.
By Sunday evening, the consensus among those who were victimized by these spams was that IBM.NET was taking no action whatsoever, and the spams would continue. And many ISPs reported adding filters to block these spams, either by automatically deleting all email routed from any IBM.NET server, or by deleting every message that was routed through IBM's "ny.us.ibm.net" server (which apparent serves the entire eastern US).
And thus, IBM.NET gradually began to be cut off from the Internet. IBM's reaction in the next week will probably determine whether its customers will retain even partial access to the internet during the coming months. If IBM.NET continues to stonewall, I expect that even companies like Netcom, AOL, MSN, Prodigy, and CompuServe will begin filtering out any email from IBM.NET customers, in order to protect their customers from spam attacks.
Update: On Sunday evening, after I called and demanded to speak to a supervisor, from whom I demanded immediate action from IBM.NET treating this as an emergency, I received a return call from "Jason" at IBM.NET, and he worked diligently throughout the evening to resolve the issue; he called back later that evening to report that two accounts for this spammer had been terminated -- one earlier that morning after the most recent spam was sent, and the other after discovering it was an account for the same user. He said IBM.NET would look into further action (perhaps even legal action) on Monday.
In a January 10 article in Network World Fusion, the damage done by this spam is discussed by Mike Leber, owner of Hurricane Electric (HE.NET) (which hosts JOES.COM).
Yuri Rutman (aka Bela Rutman): At the same time that anger was being poured at IBM.NET for failing to stop the spam, many users were trying to track down the source of the spam. The webmaster for JOES.COM (the victim of the "El Cheepo" spam) quickly released copies of two email messages he received after disabling a web page created by Yuri Rutman (firstname.lastname@example.org) after that user repeatedly broadcast illegal unsolicited commercial email messages promoting his "baldness cure" web site at JOES.COM.
Click here for copies of the headers from the "El Cheepo" and "Thinning Hair" spams, and for complete copies of Yuri Rutman's angry email messages to "Joe@Joes.Com" announcing the revenge spam (you can compare his angry email to email@example.com with the reply he wrote below (which he acknowledged writing when he called to threaten me on Wednesday, January 7).
Who Is Yuri Rutman/Bela Rutman? He has been posting newsgroup messages and classified ads, using his email address firstname.lastname@example.org for nearly a year, promoting several quite different "business enterprises." One of them, not surprisingly, is a baldness cure. Another set of email messages seek investors to contribute funding for a variety of Chicago-area and "international" movie projects. Another group of newsgroup postings asked writers to submit works to a "literary agency." And a recent set of messages posted in "hacker" newsgroups sought assistance in cracking SMTP gateways and software codes. Earlier, he posted messages seeking independent contractors to design web sites and related work.
Yuri Rutman does use one address consistently for his varied enterprises: 6829 N. Lincoln-Suite 135, Lincolnwood, IL 60646,USA, telephone (847) 679-3916 (this is a recently-changed area code; some older messages still refer to the 708 area code). He also uses the address: 6421 St. Louis, Lincolnwood, IL 60645.
As of 1/9/96, it appears that all known email addresses for Yuri Rutman have been deactivated. Rutman had created two separate IBM.NET accounts, email@example.com and firstname.lastname@example.org (both were terminated by IBM.NET on 1/5/96). Earlier, in December 1996, he had used two forged IBM.NET email addresses when posting messages in newsgroups (email@example.com and firstname.lastname@example.org) but specified the return address of "email@example.com" in all those messages ("reductase" was his address throughout 1996 and is the name of the baldness cure he promotes). Rutman also operates an "autoresponder" mailbox at mailto:firstname.lastname@example.org, one of many junk-email servers run by Sanford Wallace's Cyber Promotions.
Try searching DejaNews (both the "current" and "old" datbases) for "email@example.com".
Are You Sure? At first, I worried that Yuri Rutman might not actually be responsible for these spams, but both in a phone call to me and in a January 9 interview by Network World Fusion reporter Todd Wallack, Rutman admitted that he sent the "thinning hair" spams, and he claimed that "former employees" had sent the "El Cheepo Web Site" spam. He said he fired those employees, yet he also said that there was nothing wrong with his spams. (I doubt that an "operator" like Rutman ever had employees, and from the information I have -- which is all posted on this site -- I personally believe that Yuri Rutman personally sent all the spams.) Rutman also acknowledged to me that he wrote the email reproduced below.
So, What Should I Do? If you received one of these spams, be sure to forward copies (with complete headers) to firstname.lastname@example.org or email@example.com -- and if you have suffered damage or loss, file a complaint with law enforcement officials. To expedite processing of your complaint, wait until IBM sends you a "ticket number" for your complaint, and then call IBM at 800-821-4612 or 800-727-2222 and ask to have your complaint upgraded to "severity one."
Who Is the Villian? Clearly, Yuri Rutman is the chief "villain" behind this harassment campaign -- and he told Network World that he would be happy to talk to people who are upset with him, if they call him at (847) 679-3916.
But another villain has been clearly identified: IBM.NET, which allowed this spam to continue to flow for 3 days without taking any meaningful action, and which continues to stonewall any complaints. IBM must take immediate action to provide prompt response to internet abuse complaints, or else its customers will find themselves shut off from the rest of the internet. IBM needs to post a public apology and provide detailed information on how to complain about internet abuses by its users, and it must train its staff to be responsive to severe abuses.
Here is one of Mr. Rutman's "tamer" email messages, which I think was intended to blame an unnamed former employee for sending all the spam using one or more of Mr. Rutman's accounts. I note that the writing style appears identical to the author of the threatening letter to "firstname.lastname@example.org" attributed to Mr. Rutman on Friday, January 3 (see http://www.markwelch.com/yuri_hd.htm).
Subject: To Don Juneau/Dave Cooley
From: email@example.com (yuri rutman)
Message-Id: < firstname.lastname@example.org >
References: < 32cbf80f.651740@news-S01.ny.us.ibm.net > < email@example.com > < firstname.lastname@example.org >
< Pine.BSI.3.95.970104020702.1064Qemail@example.com >
Organization: The Microsoft Network (msn.com)
all these posts have recently come to my attention as well as your "investigation" of me. In a way I hope you read the posts I posted to the other freaks, but I can say that I thank you for researching the "other" posts apparently made by me. Since I indicated my involvement with this whole matter should be absolved, allow me to respond to your KOOKA KABAl or whatever.
Case in point: I have had numerous employees over the last year and a half who had unrestricted access to my email account, most of them were indeed part time college students. The research that you came up with which originated from my account was virginal when I saw it several minutes ago. I have no idea about any posts to the groups you described except for a solicitation of literary materials. Because of legal reasons, I cannot give out the names of the individuals responsible for those posts, but at the same time, aside from them no longer working for me, as I have changed all my email passwords, sans a few people who are partners in the firm, I can only say that these were humurous things, but I thank you for bringing everything to my attention.
I was on vacation for the last several weeks and when I opened my mailbox and discovered the unmanly accusations from David Cooley, I had absolutely no idea what was going on until I traced the etiological source of the responsible party from my organizations who took it upon themselves to do whatever they may have pleased. I have no idea what this entire Joe;s thing is about, but I have subsequently dismissed the two individuals who I believe were responsible.
Nonetheless, even though you approached this matter with a bit of intelligence and informed me of posts that originated from my account, I can only say that I am not going to take these matters seriously. That's the point of my emails to Cooley and Sahlavee, which they weren't man enough to post on these groups, besuase I was sick of the harassing and immature way they and about a hundred others who emailed me dealt with the situation, which I subsequently posted. You have been nothing short of a gentleman with your investigation, as I am further conducting an in-house matter regarding all that has come to my attention.
p.s.---In regards to all the harassment I've been receiving by David "GQ MODEL" Cooley, who is extremely distraught at his admittance of not being a real man, my offer still stands that if anyone, anyone, has any doubts as to my responsibility for any of this crap, i will meet them in a designated location in Chicago and they can confront me with the matter to my face, instead of assuming untruths behind my back like socially inept freaks like Dvaid Cooley or Sahlavea who are nothing more than Freud's definition of having an Electra complex. Sans that, i am leaving town for several days and if you have any mor einfo as to the origination of what actually happened, please let me know. thanks don
Mark Welch's Junk Email Index Page