Showing posts with label identity theft. Show all posts
Showing posts with label identity theft. Show all posts

Thursday, May 15, 2014

Confessions of an identity thief.

Hey, you!  Yeah, I’m talking to you!  The guy sitting there in Starbucks checking his bank balance on his iPad.  Or the nice old lady waiting for her social security check to be delivered to her mailbox.  Or even the family who doesn’t shred their junk mail before tossing it out.  I’m going to let you in on a little secret – I’m going to steal your identity and then steal a lot of your money, and there are so many ways I can do it you’d be amazed.  In fact, me and my fellow identity theft friends steal about a gazillion dollars each year, and it’s getting easier – not harder – thanks to technology.  I’m feeling generous today so I’m going to share my secrets with you (and chances are you still won’t protect yourself.)  Game on! 

1. Simple theft.
I can steal your identity the old fashioned way by simply burglarizing your documents.  I see opportunities everywhere  - I can slip an arm through a car window when you leave it down on a hot day, check to see if your doors are unlocked, sneak into your house, or even grab your computer when you go to the bathroom at Starbucks.  Don’t get next to me on a crowded bus or street corner, because I’ll pickpocket your wallet without you feeling a thing! 

2. Employer information.
Your employer has so much of your data and is SO careless with it.  I can easily steal files, flash drives, and other records to get your social security number, address, work history, medical information, other valuable data.  I don’t have to break in to do this – I can hack into your employer’s electronic files or even bribe the disgruntled janitor to let me in.

3. Change of address.
One of my favorite tactics is to submit a change of address form with the post office.  I can do this easily and anonymously by filling out a simple card.  After that, all of your mail will be sent to MY new address, usually a P.O. Box under a false name so I won’t get busted if you call the police. 

4. Phishing.
For my technically savvy identity theft friends, phishing scams are popular.  They send you spam emails or set up pop up messages to appear as you browse the web, all asking for your personal information or logins and passwords. 

5. Social Media.
You may not realize it, but social media sites like Facebook, Instagram, etc. are goldmines for us identity thieves.  By taking bits and pieces of your personal information we can assemble a data profile that includes just about everything but your social security number.  You also aren’t aware that your photos tell so much about your life (car license plate numbers, address on your home, when you’re out of town and where, etc.)  When all else fails, you’d be shocked what public records reveal online!

6. Mail.
Back in the day, we’d just drive around nice neighborhoods after the postman made his rounds and grab your mail right out of your box.  Apartment building mailboxes were the best because we could jimmy them open late at night and get everyone’s mail!  These days, I have identity thief friends who even put out fake mailboxes!

7. Trash.
Dumpster diving for your discarded documents, mail, and financial records is messy but profitable!  By the way, thanks for only ripping up your credit card statement in half and thinking you shredded it!  haha       

8. Call somebody.
You’d be amazed how much information I can get on you just be calling up your financial institutions, friends, employers, and credit agencies and pretend to be your landlord or employer verifying information.  People are almost always too lazy to ask for verificiation!

9. Over your shoulder.
You know how you enter your password in the ATM machine and don’t really cover it up because you’re not worried about the people in line behind you?  Yeah, I love that.  I can easily see your password and some times even video it on my cell phone to watch it later just to be sure.  Oh, and I do the same thing when you’re on your smart phone, iPad, or computer in public!

10. Phony call centers.
I can call people all day claiming to be their bank, credit card company, or credit reporting agency.  I tell them there’s been some strange activity on their account (am I lying?!) and ask them to confirm personal information like passwords or social security numbers so I could freeze their account.  Then I call their credit card company and have some fun! 

11. Cloned cards. 
Do you realize how easy it is for me to make my own credit card?  I can press a duplicate in minutes with special foils and laminators, burning your name and card number onto blank cards that I buy online. 

12. Order checks.
This is too easy!  Once I have some of your basic information, I call your bank or credit card company and request an order of new checks.  I can either divert the mail or just pluck them out of your box!  Let’s spend some of your money!

13. Skimming.
No matter how smart you think your bank is, we’re smarter – always one step ahead.  We install plastic devices to regular ATM machines that allow us to register all of your bank information once you insert your card, called skimmers.  Sometimes we even put up a completely fake ATM machine for a few days before moving it to the next location before the heat is on.

14. Public Wi-Fi connections.
I have to thank you from the bottom of my heart for login in to your bank or credit card’s site to check your balance, or even checking your email with a public Wi-Fi connection.  It’s so easy to hack in and see exactly what you’re doing! 

15. My lovely assistant – the cashier.
Even when you use your credit card at legitimate stores, the cashier can be in on the act.  If they turn their back to you or take a little too long fumbling around behind the counter, they might be scanning your card into a handheld skimming terminal to harvest your information.  Or they can simply take a picture of the front and back of your card with their cell phone.  

Monday, May 5, 2014

The frightening truth about identity theft.


Let me paint you a picture.  You’re sitting at Starbucks and pull up your laptop and log in with their Wi-Fi to check email.  BOOM!  Your bank account information was just stolen.

Or you get a few credit card offers and other junk mail you don’t want so you rip it in half and throw it in the trash.  POW!  Someone just took out 5 credit cards in your name and maxed them.

Even scarier, you just go to your local store and buy a pair of jeans.  SHAZAM!  Just by that act, they record sensitive financial information in their database – your name, address, credit card numbers, and anything else they can gather, which is easy pickings for hackers. 

In fact, identity theft and crimes of financial and data theft are more prevalent than ever in the United States, where approximately 15 million people have their identities used fraudulently each year.  The bill on that theft is upwards of $50 billion dollars every year.  That’s three times more than the combined $14 billion in losses from all other types of consumer theft (burglary, motor vehicle theft, property theft, etc.) combined.  It takes a lot of time and often money to clear up the mess identity thieves leave behind.  Their credit report and score will be compromised, which can set off a domino effect of raising interest rates and even insurance premiums.  Debt collectors start calling and sending mail, or even taking them to court.  Some people get lucky and they’re able to clear their good name in a few weeks, but for others it becomes a nightmare that lasts years.

Just last year, more than 16 million people saw their identities compromised or stolen, which equals an astounding 7% of all adults in the U.S.A.  The financial toll to those people is high.  On average, each identity theft victim suffers direct losses of $9,650, up from just $3,500 a few years ago. 

Of course we have to be careful of where we log in, how we store and use our passwords and financial information, and even how we discard our mail, but what’s truly frightening is that we put ourselves at risk just by being consumers.  Stores and businesses are in the practice of data mining, or collecting every shred of information on their customers and the public, used for marketing purposes and to anticipate and control buying behaviors.  And we’re not even talking about governmental databases yet.  But these massive databases of your information are rich targets for hackers and thieves from all over the world.  About 100 million Americans have their personal information put at risk of identity theft each year from government or corporate databases. 

Unfortunately, the bad guys are pretty smart and technologically savvy these days Identity thieves used to dumpster dive for your mail, but now they have elaborate phishing and vishing computer scams.   They used to pickpocket your wallet, now they set up elaborate networks of botnets and malware that hijack your computer without being detected.  They used to set up phony call centers, now they hack right into those corporate and government databases that hold hundreds of millions of consumers’ personal and financial information. 

These days, they’re not just after your credit cards and bank accounts – identity theft has expanded to fraud involving cell phone service, cable TV, your power, gas, and water utilities, internet payment services, mortgages, medical insurance, auto financing, and government benefits.  There’s even a growing trend of thieves using your identity to obtain employment (and then stealing from the inside,) and evading arrest using your identity as a cover. 

So the big question is: who is there to protect you?  If you’re counting on bank and corporate protocols to keep your data secure, you might be sadly disappointed.  Only about 45% of data theft was discovered by financial institutions, who notified their compromised consumers.  If their information was used to open new, fraudulent accounts, the financial institution sounded the alarm only 15% of the time.   21% of victims were alerted to the malfeasance when an outside company or agency reach out, and 13% found out when they received unpaid bills in the mail.  

Once identity theft occurs, it’s difficult to trace the source of the leak.  Only 32% of identity theft victims ever find out how and where their information was stolen. 

What can consumers do to protect themselves? 

They should check their own credit reports at least three times a year, when consumers are entitled to free annual copies of their credit reports from the three major credit bureaus: Equifax, Experian and TransUnion.

They should use secure wifi when pulling up sensitive information online, use online security measures and strong passwords.

Shredding mail before you throw it away, and verify every email and phone call before you offering any information. 

But the best way to protect yourself is to use a great credit report monitoring and protection service, like those offered by Blue Water Credit.



Monday, April 28, 2014

New legislation hopes to shake up the credit reporting industry and help consumers.


U.S. consumers may be getting a valuable ally when it comes to correctly reporting their credit scores if newly introduced legislation gets passed.  A bill sponsored by U.S. Senators Sherrod Brown (D-OH) and Brian Schatz (D-HI,) among others, would call for accuracy and accountability from the credit bureaus when it comes to reporting consumers’ credit.  The Stop Errors in Credit Use and Reporting (SECURE) Act of 2014 would give the public an avenue for transparency in reporting, a way to access free credit reports, and a way to dispute and correct inaccuracies under protection of the law.  

Errors aren’t harmless since lenders, banks, and employers base their rates, premiums, and hiring decisions, on consumers' credit score.  The Federal Trade Commission (FTC) recently released a study that said up to 40 million Americans have error(s) on their credit reports.  At least 10 million of these errors would result in higher interest rates on loans or put them at other financial detriment.  Errors can take the form of duplicates, misreporting, identity errors and mix-ups, and outdated items. 

Under the current system, Credit Reporting Agencies (CRA’s) put very little man-hours or resources into fixing inaccuracies and errors, and there’s no minimum standard for to accurately match and report data.  However under the new act, there would be new procedures that CRA’s were legally mandated to follow, protecting consumers.

S. 2224 dovetails on a proposal by Senator Bernie Sanders (I-VT) which calls for free, verifiable credit reports and scores to all consumers one a year.  That differs from the current system where CRA’s provide a free report that is almost valueless.  They sell “educational” scores and reports to consumers that are rarely used by lenders.  Too often, consumers start by requesting a free copy of their credit score and end up duped into paid credit monitoring services.

The Act would:

“Ensure that agencies send consumers’ disputes and supporting documents to the creditor when there is an error on a report, so that they can thoroughly review the consumer’s claim.
Make it easier for consumers to spot errors in their credit reports by requiring that consumers receive a free copy of their credit report if anyone makes an unfavorable decision based on the report.
Give consumers the ability to request a free credit score along with their annual free credit report to see what credit they might be eligible for.
Give courts the ability to stop a credit reporting agency from reporting inaccurate information and provide the Federal Trade Commission with new authority to stop sloppy practices.”  
For instance, if a consumer filed a legitimate complaint for an error on their report, the CRA would only have 14 days to provide evidence of the reporting.  This would include debt collection agencies affiliated with the CRA’s. 
The SECURE Act is cosponsored by Senator Sanders as well as Elizabeth Warren (D-MA) and Richard Blumenthal (D-CT).  It’s also endorsed by the Consumers Union, the National Consumer Law Center, the National Association of Consumer Advocates, Consumer Action, and U.S. PIRG. 

The bill has been referred to the Senate Committee on Banking, Housing, and Urban Affairs.  You can read the complete Act here.

Monday, February 10, 2014

The 5 biggest data thefts in U.S. history.


An indictment came down last summer for what’s being called one of the biggest data theft operations in U.S. and international history, as four Russian men and one Ukrainian man were charged in a sophisticated hacking scheme that may cost its victims hundreds of millions – or even billions – of dollars.  The men stole data that included over 160 million credit card numbers from multinational corporations like Visa, J.C.Penny, JetBlue, 7-Eleven, and even NASDAQ, selling the information on the black market and defrauding countless consumers.
The men utilized custom malware and hacking tools to get on the corporate networks and rip blocks of credit card numbers, security info, and other private date, referred to as “dumps.”  They’d then sell the dumps to data theft wholesalers – or resellers – who resold it to individual buyers, called “cashers,” who would use the cards to make fraudulent purchases or withdraw funds.   According to the indictment, U.S. credit card data would cost $10 each while Canadian cards went for $15 and European bank or credit card access $50.
Their criminal ring took place from 2005 until 2012 where they tapped into computer networks of at least 17 payment companies, financial institutions, and retailers to get the credit card and debit card information.  The companies are still trying to add up their staggering losses, possibly in excess of $300 million for some of them.  The men are looking at a long paid vacation behind bars, but still the damage has been done. 
The scariest thing is that this kind of data and financial theft is not rare – online fraud and data piracy is the fastest growing branch of any crime, so prevalent that it’s highly recommended computer users and online shoppers take proactive measures to protect their financial data, their identity, and their credit scores.   
Let’s look a few of the other biggest data thefts in U.S. history:
U.S. Veterans Affairs - $25-$30 million
In 2006, the names, birth dates, and social security numbers of 17.5 million veterans were pirated from a single laptop that a Department of Veterans Affairs worker had taken home for the evening,  That one leak cost the VA an estimated $25-$30 million dollars if you add up the cost to fix the problem with reimbursements, call centers, mailing warnings, credit monitoring services for the victims, and other “clean up” well over $20 million dollars and counting.  The lesson?  Never take your work home.

Heartland Payment Systems - $140 million
This major payment-processing center was the victim of a cyber crime in 2008 that saw the loss of 100 million credit and debit cards.  A lone hacker from Miami, Albert Gonzalez, was apprehended, arrested, and sentenced to 20 years in Federal prison as the ringleader of the operation that defrauded TJX, 7-Eleven, and the grocery chain Hannaford Bros.  Heartland ended up paying out $140 in fines and restitution. 
TJX – $256 million or more
Speaking of Inmate Albert Gonzalez, the same man was a major player in 2007’s data heist at TJX, the retailer that has TJ Maxx and Marshalls under its umbrella.  Data hackers and Gonzalez stole about 45 million credit and debit card numbers that they used to buy millions of dollars worth of electronics from Wal-Mart and other chains.  The crime cost the company about $25 million in direct costs but the real price tag to consumers and insurance claimants stands to be over $250 million.
Epsilon - ???
The Dallas Marketing firm Epsilon was hacked for millions of names and e-mail addresses in 2011, which the criminal ring used to acquire sensitive financial data from consumers.  The information featured lists from banks and retailers like Best Buy, JPMorgan, TiVo, Walgreen, and Kroger.  The stolen data is still being rounded up and the damage assessed and addressed, so risk analysts estimate the total bill to be anywhere from $225 million dollars to upward of #4 billion once the dust settles.