Showing posts with label data hacks. Show all posts
Showing posts with label data hacks. Show all posts

Thursday, May 15, 2014

Confessions of an identity thief.

Hey, you!  Yeah, I’m talking to you!  The guy sitting there in Starbucks checking his bank balance on his iPad.  Or the nice old lady waiting for her social security check to be delivered to her mailbox.  Or even the family who doesn’t shred their junk mail before tossing it out.  I’m going to let you in on a little secret – I’m going to steal your identity and then steal a lot of your money, and there are so many ways I can do it you’d be amazed.  In fact, me and my fellow identity theft friends steal about a gazillion dollars each year, and it’s getting easier – not harder – thanks to technology.  I’m feeling generous today so I’m going to share my secrets with you (and chances are you still won’t protect yourself.)  Game on! 

1. Simple theft.
I can steal your identity the old fashioned way by simply burglarizing your documents.  I see opportunities everywhere  - I can slip an arm through a car window when you leave it down on a hot day, check to see if your doors are unlocked, sneak into your house, or even grab your computer when you go to the bathroom at Starbucks.  Don’t get next to me on a crowded bus or street corner, because I’ll pickpocket your wallet without you feeling a thing! 

2. Employer information.
Your employer has so much of your data and is SO careless with it.  I can easily steal files, flash drives, and other records to get your social security number, address, work history, medical information, other valuable data.  I don’t have to break in to do this – I can hack into your employer’s electronic files or even bribe the disgruntled janitor to let me in.

3. Change of address.
One of my favorite tactics is to submit a change of address form with the post office.  I can do this easily and anonymously by filling out a simple card.  After that, all of your mail will be sent to MY new address, usually a P.O. Box under a false name so I won’t get busted if you call the police. 

4. Phishing.
For my technically savvy identity theft friends, phishing scams are popular.  They send you spam emails or set up pop up messages to appear as you browse the web, all asking for your personal information or logins and passwords. 

5. Social Media.
You may not realize it, but social media sites like Facebook, Instagram, etc. are goldmines for us identity thieves.  By taking bits and pieces of your personal information we can assemble a data profile that includes just about everything but your social security number.  You also aren’t aware that your photos tell so much about your life (car license plate numbers, address on your home, when you’re out of town and where, etc.)  When all else fails, you’d be shocked what public records reveal online!

6. Mail.
Back in the day, we’d just drive around nice neighborhoods after the postman made his rounds and grab your mail right out of your box.  Apartment building mailboxes were the best because we could jimmy them open late at night and get everyone’s mail!  These days, I have identity thief friends who even put out fake mailboxes!

7. Trash.
Dumpster diving for your discarded documents, mail, and financial records is messy but profitable!  By the way, thanks for only ripping up your credit card statement in half and thinking you shredded it!  haha       

8. Call somebody.
You’d be amazed how much information I can get on you just be calling up your financial institutions, friends, employers, and credit agencies and pretend to be your landlord or employer verifying information.  People are almost always too lazy to ask for verificiation!

9. Over your shoulder.
You know how you enter your password in the ATM machine and don’t really cover it up because you’re not worried about the people in line behind you?  Yeah, I love that.  I can easily see your password and some times even video it on my cell phone to watch it later just to be sure.  Oh, and I do the same thing when you’re on your smart phone, iPad, or computer in public!

10. Phony call centers.
I can call people all day claiming to be their bank, credit card company, or credit reporting agency.  I tell them there’s been some strange activity on their account (am I lying?!) and ask them to confirm personal information like passwords or social security numbers so I could freeze their account.  Then I call their credit card company and have some fun! 

11. Cloned cards. 
Do you realize how easy it is for me to make my own credit card?  I can press a duplicate in minutes with special foils and laminators, burning your name and card number onto blank cards that I buy online. 

12. Order checks.
This is too easy!  Once I have some of your basic information, I call your bank or credit card company and request an order of new checks.  I can either divert the mail or just pluck them out of your box!  Let’s spend some of your money!

13. Skimming.
No matter how smart you think your bank is, we’re smarter – always one step ahead.  We install plastic devices to regular ATM machines that allow us to register all of your bank information once you insert your card, called skimmers.  Sometimes we even put up a completely fake ATM machine for a few days before moving it to the next location before the heat is on.

14. Public Wi-Fi connections.
I have to thank you from the bottom of my heart for login in to your bank or credit card’s site to check your balance, or even checking your email with a public Wi-Fi connection.  It’s so easy to hack in and see exactly what you’re doing! 

15. My lovely assistant – the cashier.
Even when you use your credit card at legitimate stores, the cashier can be in on the act.  If they turn their back to you or take a little too long fumbling around behind the counter, they might be scanning your card into a handheld skimming terminal to harvest your information.  Or they can simply take a picture of the front and back of your card with their cell phone.  

Monday, February 10, 2014

The 5 biggest data thefts in U.S. history.


An indictment came down last summer for what’s being called one of the biggest data theft operations in U.S. and international history, as four Russian men and one Ukrainian man were charged in a sophisticated hacking scheme that may cost its victims hundreds of millions – or even billions – of dollars.  The men stole data that included over 160 million credit card numbers from multinational corporations like Visa, J.C.Penny, JetBlue, 7-Eleven, and even NASDAQ, selling the information on the black market and defrauding countless consumers.
The men utilized custom malware and hacking tools to get on the corporate networks and rip blocks of credit card numbers, security info, and other private date, referred to as “dumps.”  They’d then sell the dumps to data theft wholesalers – or resellers – who resold it to individual buyers, called “cashers,” who would use the cards to make fraudulent purchases or withdraw funds.   According to the indictment, U.S. credit card data would cost $10 each while Canadian cards went for $15 and European bank or credit card access $50.
Their criminal ring took place from 2005 until 2012 where they tapped into computer networks of at least 17 payment companies, financial institutions, and retailers to get the credit card and debit card information.  The companies are still trying to add up their staggering losses, possibly in excess of $300 million for some of them.  The men are looking at a long paid vacation behind bars, but still the damage has been done. 
The scariest thing is that this kind of data and financial theft is not rare – online fraud and data piracy is the fastest growing branch of any crime, so prevalent that it’s highly recommended computer users and online shoppers take proactive measures to protect their financial data, their identity, and their credit scores.   
Let’s look a few of the other biggest data thefts in U.S. history:
U.S. Veterans Affairs - $25-$30 million
In 2006, the names, birth dates, and social security numbers of 17.5 million veterans were pirated from a single laptop that a Department of Veterans Affairs worker had taken home for the evening,  That one leak cost the VA an estimated $25-$30 million dollars if you add up the cost to fix the problem with reimbursements, call centers, mailing warnings, credit monitoring services for the victims, and other “clean up” well over $20 million dollars and counting.  The lesson?  Never take your work home.

Heartland Payment Systems - $140 million
This major payment-processing center was the victim of a cyber crime in 2008 that saw the loss of 100 million credit and debit cards.  A lone hacker from Miami, Albert Gonzalez, was apprehended, arrested, and sentenced to 20 years in Federal prison as the ringleader of the operation that defrauded TJX, 7-Eleven, and the grocery chain Hannaford Bros.  Heartland ended up paying out $140 in fines and restitution. 
TJX – $256 million or more
Speaking of Inmate Albert Gonzalez, the same man was a major player in 2007’s data heist at TJX, the retailer that has TJ Maxx and Marshalls under its umbrella.  Data hackers and Gonzalez stole about 45 million credit and debit card numbers that they used to buy millions of dollars worth of electronics from Wal-Mart and other chains.  The crime cost the company about $25 million in direct costs but the real price tag to consumers and insurance claimants stands to be over $250 million.
Epsilon - ???
The Dallas Marketing firm Epsilon was hacked for millions of names and e-mail addresses in 2011, which the criminal ring used to acquire sensitive financial data from consumers.  The information featured lists from banks and retailers like Best Buy, JPMorgan, TiVo, Walgreen, and Kroger.  The stolen data is still being rounded up and the damage assessed and addressed, so risk analysts estimate the total bill to be anywhere from $225 million dollars to upward of #4 billion once the dust settles.