Friday, March 28, 2008
The value of one Social Security Number in ID theft
A Chicago area man racked up just under under $300,000 in debt with one womans Social Security number. His purchases included a Range Rover and a home.
Apparently this has been going on since June 2005.
An unfortunate event like this points out how far one person can go with one very crucial piece of information. While most studies point out that losses are generally much smaller, those numbers are averages and will be meaningless to this victim.
She is left picking up the pieces of this man's crime spree. Will she be out the $300,000? Definitely not, but she will be required to file numerous complaints and documents to prove she was not involved or had nothing to do with this crime. She has to exonerate herself first before any financial institution will release her from these debts.
She will spend many hours with various agencies clearing the debris from this. In the end it will cost her time, energy, anxiety, and frustration. She will likely need to take time off from work to handle certain situations.
Will she be out any money? To a large extent no, but what about time from work especially if she is self employed, gas money to travel to a police station to file an affidavit, a trip to a attorneys office, possibly a bank visit, cost of parking an so on. It can add up. Every step of the way will be filled with anger and frustration that she has to go through all this for something that she had nothing to do with.
What she should realize somewhere along this journey, is that people can do things to either avoid this, or prevent it from getting out of control.
This thief obtained her number from somewhere. The fact that he used this one for so long indicates it was likely the only one he had and found it somewhere, either in the mail, trash, on an old document, maybe in a wallet he found or stole.
Where she went wrong was allowing this to go on for 30 months. If she had been actively checking her credit reports, or had a credit freeze placed on her accounts, or fraud alerts put in place, much of this would have been avoided. She should also reflect back on where she may have provided her SSN or lost any personal information.
A little bit of prevention or mitigation would have gone a long way. It is up to you to defend your identity. This unfortunate circumstance with one person and one SSN is why.
Friday, January 25, 2008
Prudential’s rock crumbles when it comes to securing personal information
Prudential Financial gets a spot on our office’s Identity Defense Wall of Shame this month. They had a temp worker collect personal information from a customer then the temp worker stole the customer’s identity to go on a three month, $70,000 spending spree!
According to the article about this event, Prudential takes customer information and security very seriously. We see that clearly from the end result of this encounter between a Prudential temp employee and a Prudential customer.
Stop and think about what happened here. A financial conglomerate worth $36 billion does not have the sense of how to secure personal information that it receives. Collecting customer information is the most volatile point in a transaction because it is up to the person who collects it as to how the information is treated. This is where Prudential’s security falls apart. The people collecting information should be trusted, longer term, well paid employees, who hopefully, will want to keep their job and have little or at least minimal incentive to steal. Instead they gave that crucial task to a 23 year old temp worker, who obviously did not care about his temp job and felt he needed to supplement his income.
I’m sure they spend millions on data security, and backup systems and passwords and encryption etc. As a financial institution they are required to have secure systems on all fronts. But no matter how big your walls are, or how many lines of defense you have, if you can’t complete step 1 and put the information into secure areas, it is useless. Picture your bank having the tellers leave all the money on the counters at night and still go lock the safe.
If Prudential has procedures in place, the management team is not reading the company manual. To be fair, this could easily happen with just about any employee and it is where a significant portion of all ID theft occurs. But when you assign tasks to someone who is not even an employee, then any incentive to do the right thing is minimized because there is no long term bond.
For the sake of all of their existing customers let’s hope they have a better system in place for securing their personal information.
Monday, August 20, 2007
Apple Online Lawsuit Brings to Light Another Threat of Identity Theft
All businesses need to heed this as an example of things to come and protect their clients' personal information in any way that they can after a class action lawsuit, case number 07-22040, was brought against Apple Store online last week in Florida Federal Court alleging that the stores violated the Fair Credit Reporting Act (FCRA). The FCRA is a federal law designed to help ensure that consumer reporting agencies act fairly, impartially, and with respect for the consumer's right to privacy when preparing consumer reports on individuals.
In 2003, an amendment was added that states, "No person that accepts credit cards or debit cards for the transaction of businesses shall print more than the last five digits of the card number or the expiration date upon any receipt provided to the card holder at the point of sale or transaction."
It was this amendment that Apple Store online was violating. Apple Store was apparently printing credit card expiration dates on the receipts, in addition to the other personal information. Companies were given a three-year grace period to comply with the law and the cost is so miniscule to make the change that most have made the change well in advance of the deadline. Apple Store, as of last week, was still not in compliance.
Identity thieves are getting smarter and smarter. Consumers must stay one step ahead and protect themselves from the financial devastation of identity theft. Consumers expect businesses to uphold the law and do what they can to protect personal information they acquire.
While no proof of a specific identity theft has stemmed from Apple Store's non-compliance, it is a recipe for disaster that reminds consumers to take every precaution when making an online purchase or any purchase with a credit card. The federal government has made efforts to protect citizens from identity theft but consumers must be on the offense and take matters into their own hands.
Place yourself in a situation to protect your personal information from theft and learn to practice fire prevention versus firefighting.
Wednesday, August 8, 2007
Burden of Proof with Identity Theft
We are all familiar with our legal system where the burden of proof is up to the prosecution for the people and you are innocent until proven guilty.
But with identity theft you are guilty or liable until you prove your innocence.
It doesn’t really seem to make sense but if you look at the logic, it does make sense. Although it puts the victim in a difficult, tedious, and time consuming position of defending themselves while all the while feeling violated because they are a victim.
Our financial system is set up and regulated by the federal government to provide easy and convenient transactions to keep the economy moving along without interruption. You can thank federal laws that limit your exposure to credit card fraud. They enacted those laws long ago to make people feel comfortable with using credit cards when they were first introduced. If people felt liable they would have been reluctant to use the system. Now our economy is completely tied to credit.
Those laws are visible in other areas as well. Take check cashing scams for example. The thieves take advantage of federal laws that require funds for checks to be made available quickly again, to keep the flow of commerce moving. People get taken due the expediency that banks provide funds for check presented, but then find out weeks later that the check was returned as a fraudulent device. You become ultimately liable for any fraudulent check that you present for funds.
In both cases of checks or credit cards you were given the benefit of the transaction in real time while it may be quite some time before the bank or you determine fraud has occurred. In the case of credit card fraud you need to prove that you did not actually make the fraudulent charges and with a check the bank relies on you to know who you are conducting business with.
The banking system really is set to benefit you, so when something goes awry you need to prove you were not involved. Most people never consider that when they conduct transactions. Who is to say that you where not involved in a fraudulent transaction and were not colluding with the perpetrator from the start.
If you become a victim of identity theft, you are really a victim in the eyes of others only after you prove it, and that will never feel good.
Monday, July 9, 2007
GAO Reports on Identity Theft, Sort of
Sounds a bit odd, but breach notification would most likely just give you a heads up a bit sooner if you are a victim. Many times a data breach notification is the first time a victim looks at a bank or credit card statement, balances a checkbook for the first time in ten years, or obtains a credit report.
The GAO was asked to examine three distinct areas
(1) The incidence and circumstances of breaches of sensitive personal information
(2) The extent to which such breaches have resulted in identity theft
(3) The potential benefits, costs, and challenges associated with breach notification requirements.
The GAO used various sources for the research and came up with an earth shattering discovery; data thefts are rampant and occur frequently and are probably underreported due to lack of voluntary or mandatory disclosure.
They also determined they can’t directly link identity theft to many of the data thefts they reviewed because there is not clear and conclusive evidence that directly links those breaches with identity theft. Apparently the identity thieves are not disclosing the abundant sources of their windfall.
There you have it, if it is not conclusive then it must not have occurred, or at least they can’t say it occurred. It does not mean that it didn’t.
They even admitted that the lack of reporting on the part of victims also leads to skewed and invalid data that cannot be used to create a valid statistical picture.
So how do many interpret this : “GAO finds little identity theft results from data breaches”.
Apparently there are a lot of thieves going to a lot of trouble stealing personal data, then changing their minds finding religion and doing nothing with it after all.
But if that is the case, then where did all that personal stolen information come from that results in the billions of dollars in personal losses from the millions of actual victims each year? There was not a place to include them in this report.
Monday, May 28, 2007
Fraud Alert Gives False Sense of Security
The county did do the right thing by disclosing it immediately; they fell extremely short when offering advice.
They told everyone who may be impacted by this to place a fraud alert on their credit report. They also mentioned providing credit monitoring.
Did they really understand what a fraud alert meant? Do they recognize that credit monitoring is an after the fact service?
A fraud alert is a notice you place on your credit report that technically REQUESTS additional verification by the lender with you personally when new credit is applied for.
Go into a store and request a store credit card, the lender who transacts credit for the store will check your credit report for viable credit. If there is a fraud alert on your account they have the OPTION of contacting you to verify that you have actually applied for credit at this store. Note the word OPTION, not mandatory nor legally required. If the lender cannot reach you at the phone numbers they have on file, they can go ahead and issue credit at their discretion.
So if everything works correctly for a thief they could obtain credit in your name despite a fraud alert. Remember it is at the lenders option and they want to issue credit, that is what they do. It only adds an optional extra step, but doe not guarantee a thief will not be able to open up an account in your name.
The name used for this notification is misleading. Local county officials thought it sounded like worthy all encompassing advice to offer to 7,000 victims.
Monday, May 14, 2007
The Hidden Costs of Identity Theft
Just think about all the other costs, the unseen, uncalculated, or unaccounted costs, we could be referring to a value that in some instances would be unbelievable.
Let’s look at time alone. Depending on what statistical survey you refer to, the time spent per victim usually averages in the range of 500 hours to clear all the hurdles to restore their name and credit and obtain any restitution. When do they do this? Many during normal business hours. An employer of a victim, and many are employed, will lose thousands in lost time and productivity due to phone calls, paperwork, making copies, faxing information and police reports. Also time off for trips to court, an attorney’s office, or police department. Think of the time loss and cost to the self employed.
Emotional costs are also not included in his figure. I was at an event recently and spoke with many individuals about identity theft, and I was truly amazed at how many had been victims or knew a victim directly. One woman had the most emotionally charged story about a close relative who stole her identity. She was forced to press police charges against that close relative, otherwise she could not get the $6,000 in theft cleared from her name and she did not have the funds to cover it either. She was extremely distraught because she knew the negative impact it would have on her if she did not press charges, but she also knew the lifelong damage the close relative would endure for this one event.
Others feel violated, hurt, constantly suspicious, untrusting and the list goes on.
So what impact do those feelings that now have on the economy? Many of these people will stop using credit or debit cards, will not buy online, will not do many things that will impact the economy much like a recession.
And for the cost to the vendors that do actually pay for or cover losses, where does he think that money will ultimately come from? We all bear the burden of paying for the costs of identity theft. Much in the same manner we share the costs for insurance when a major hurricane hits even a majority were never impacted by it.
So in the grand scheme of identity theft the impact of the actual dollar amount may only be a small part of the total cost, but everyone who gets hit with identity theft pays a price.
Tuesday, April 3, 2007
The costly disparity of debit and credit cards
All this starts with the cards looking identical to consumers. This leads many to the conclusion that because they look alike they are alike. The biggest difference to them is one gets billed and the other comes from their checking account. What else could there be?
Under the Fair Credit Reporting act you cannot be held responsible for unauthorized charges to your credit card. The burden you face is to prove you did not make the charges, file a police report etc. Your liability is generally limited to $50 per card.
The people who had their debit cards compromised fall into a whole different category of liability. Within the first 2 days you liability is capped at $50. Up to 60 days it is capped at $500, after the 60 day window you are wide open for unlimited liability or the balance of your account. Those clocks start ticking the day you notify your bank of the theft, or the date of your first paper or online statement where the unauthorized charges appear. You become "notified" even if you don't open up the envelope or bother looking!
Remember , the "Zero Liability" card you have is not a mandate to the bank from the government, only a courtesy from your bank. Even then, it is at their discretion who is truly liable.
I'm sure many do not bother to review their charges or statements because they feel "protected" and have "zero liability". I would like to hear from some victims of the TJX fiasco to see how well they made out with these policies. I'm sure many looked at those statements for the first time in a long time when they heard about the breach and were quite surprised.
The easiest solution, review your statements regularly. They are your best defense to a costly theft!