Showing posts with label Fraud. Show all posts
Showing posts with label Fraud. Show all posts

Friday, March 28, 2008

The value of one Social Security Number in ID theft

People need to understand how valuable that simple 9 digit social security number really is to an identity thief.

A Chicago area man racked up just under under $300,000 in debt with one womans Social Security number. His purchases included a Range Rover and a home.

Apparently this has been going on since June 2005.

An unfortunate event like this points out how far one person can go with one very crucial piece of information. While most studies point out that losses are generally much smaller, those numbers are averages and will be meaningless to this victim.

She is left picking up the pieces of this man's crime spree. Will she be out the $300,000? Definitely not, but she will be required to file numerous complaints and documents to prove she was not involved or had nothing to do with this crime. She has to exonerate herself first before any financial institution will release her from these debts.

She will spend many hours with various agencies clearing the debris from this. In the end it will cost her time, energy, anxiety, and frustration. She will likely need to take time off from work to handle certain situations.

Will she be out any money? To a large extent no, but what about time from work especially if she is self employed, gas money to travel to a police station to file an affidavit, a trip to a attorneys office, possibly a bank visit, cost of parking an so on. It can add up. Every step of the way will be filled with anger and frustration that she has to go through all this for something that she had nothing to do with.

What she should realize somewhere along this journey, is that people can do things to either avoid this, or prevent it from getting out of control.

This thief obtained her number from somewhere. The fact that he used this one for so long indicates it was likely the only one he had and found it somewhere, either in the mail, trash, on an old document, maybe in a wallet he found or stole.

Where she went wrong was allowing this to go on for 30 months. If she had been actively checking her credit reports, or had a credit freeze placed on her accounts, or fraud alerts put in place, much of this would have been avoided. She should also reflect back on where she may have provided her SSN or lost any personal information.

A little bit of prevention or mitigation would have gone a long way. It is up to you to defend your identity. This unfortunate circumstance with one person and one SSN is why.

Saturday, February 23, 2008

FTC Identity Theft Data Causes Skewed Views

The FTC has issued the latest report for 2007 on Consumer Fraud and Identity Theft Complaint Data. With no great shock or surprise identity theft is still the number one complaint by a long shot being 32% of the reported 813,899 total complaints reported. The next closest category was Shop at Home/ Catalog Sales with a mere 8%. There were 20 categories in all and the bottom 13 categories were each 2% or less.

This is a good report as it paints many pictures but at the same time skews the reality due to how the information is collected.

Certain areas of the US have more information available to consumers or police agencies that promote reporting identity theft to the FTC.

Because the reporting is entirely voluntary lends more of an explanation as to why some states have more incidences than others. The reality of identity theft crime statistics goes much deeper than the simplistic overview of the charts of this report.

A Skewed View

I have read a number of articles from various states that have had a decrease in the number of incidences reported to the FTC are feeling incredibly good about it. They are utilizing this information to pat themselves on the back. In Wisconsin one state that experiinced a decrease, had the administrator of the Division of Trade and Consumer Protection claiming they like to think they are getting the word out better, but also claims she does not know why they ended up so low in the rankings. She obviously needs to take a class on Understanding Reports 101, or is just looking to get a promotion. Statements like this coming from someone who is the head of consumer protection for the state should be a bit unnerving for the residents of Wisconsin.

But kudos goes to the Wisconsin Bankers Association who says the FTC information does not reflect what they are seeing.

Take a state such as Colorado with this same view. They have 4 of the top 50 metropolitan areas in the US reporting identity theft. Of those 4 areas, they all had a highly disproportionate number of reports compared to the other 46 areas. That does not directly indicate it is a state with an unusually high rate of identity theft, but likely a state that is actually educating consumers on what to do and encouraging reporting to the FTC.

No signs of abatement

One thing can be said with certainty is that identity theft is not showing any significant signs of abatement.

With all of the services available to stop this, and alert you of that, and the thousands that are paying monthly fees, one would expect this number would be dropping dramatically, or at least see a slight dent in the numbers.

But then again if you rely on some reporting agency with a subscription service you pay monthly to tell you someone has your information and tried to open some type of account in your name, the theft has already happened and is likely eligible to be reported to the FTC anyway. Paying money each month to have someone tell you a theft has occurred will not change the fact that a thief already has your information.

Reporting to the Police

What is still shocking in this report is the number of people who did not report the crime to a police agency which was 65% or 158,535. Why they chose not to is a mystery that we are looking into, but even more disturbing was the revelation that of the 35% that did take the time to report the crime 8% of those did not get a report taken from the police.

The reality of what was going on at the time is the police are looking around the precinct when a victim calls or shows up. They see they have 2 muggers, a car thief, and an arsonist all waiting to be booked and processed. An identity theft victim comes in declaring a theft that by appearances likely occurred across state lines or out of the country. The probability of an arrest is remote, but the headache of the extra paperwork 100% guaranteed.

The message sent is this is a crime to be treated lightly by consumers and the some (not all) police agencies are not be doing enough to encourage or educate people in how to protect themselves. If thousands are turned away and led to believe the police can do nothing, then a feeling of helplessness will likely prevail.

The best defense is self defense. A majority of identity theft starts with people leaving the gates to their identity open and allowing the fraud to occur.

Thursday, January 31, 2008

Identity Theft “Prevention” Defined Accurately

Everybody that talks about prevention uses the word in a different way. It is about perspective. Here is an example:

Think about how you would feel if this scenario happened: Your bank called and said “someone infiltrated your savings account and they have been making withdrawals regularly for the last three months. Your account has been drained of $25,000 but due to our diligence we stopped it and you still have $15,000 left. We have effectively prevented the thief from draining your account. We thought you’d like to know we mitigated your loss.”

Was there any prevention here? Absolutely! Are you going to be happy about it? I doubt it. People are paying big money for a false sense of the word “prevention”. They are really paying for and getting “mitigation”.

Now let’s compare the words “prevention” and “mitigation”:

pre·ven·tion [ pri vénshən ] (plural pre·ven·tions)

action that stops something from happening: an action or actions taken to stop somebody from doing something or to stop something from happening

  • the prevention of crime

mit·i·gate [ mítti gàyt ] (past and past participle mit·i·gat·ed, present participle mit·i·gat·ing, 3rd person present singular mit·i·gates)

  • to mitigate a loss

lessen something: to make something less harsh, severe

When put in the context of identity theft: Everyone uses the word prevention when they are referring to credit freeze, fraud monitoring and credit reports, and credit monitoring, data scouring etc.

Now let’s look at it from the context of the consumer: Prevention would be keeping my information completely secure and preventing it from being stolen in the first place.

Real prevention is thwarting the theft of your personal information. Securing your name so nobody uses it for anything. That is what ID theft “prevention” truly is.

If I rely on a credit report, a fraud alert or a credit freeze to stop something from happening, that means that SOMEONE ALREADY HAS OBTAINED MY PERSONAL INFORMATION ! A CRIME HAS ALREADY OCURRED! Now that does not sound like identity theft prevention at all, it most definitely is mitigation. Sure it may have plugged a small hole but in the grand scheme of the information that thief still has, it is like putting a bandage on a bullet wound.

So how can credit freeze, fraud monitoring and credit reports, and credit monitoring qualify as prevention? Well, they stopped something from happening, and that has some limited value, but now who has this information and where are they going with it next? Keep in mind if they have gone to the effort to steal your info, they are going to use it. A car thief does not steal a car and drive around in it until it runs out of gas. They are going to use the stolen device until it no longer meets their needs. The same with your identity, it could be used next for medical services, prescriptions, getting arrested, forging a check, and so on.

An ID theft recovery company stated under the guise of “prevention” that they look for changes in your existing accounts and they look for new accounts and transactions in your name. By doing this, they can detect someone's attempt to steal your identity before it gets too far and before any damage has been done. Sorry people, but if any of this is detected, the damage has been done. SOMEONE HAS ALREADY STOLEN YOUR IDENTITY! THEY HAVE YOUR PERSONAL INFORMAION AND ARE PUTTING IT TO USE! This should not be sugar coated as identity theft “prevention”. The prevention ship has sailed, it is now time to mitigate.

You will still have to wonder when or where they may use it next. And you still may have work to do, to get everything closed down, changed, modified etc. and you may never be completely sure you’ve plugged the gaps because how do you know your personal information has not been passed around or sold on the black market?

So how much is “mitigation” really worth? It is up to you, but most will pay much more for “prevention”.

True identity theft “PREVENTION” is about stopping the crime from occurring, and that starts with preventing and keeping your information out of the hands of the thieves to start with. True prevention is up to you! True prevention starts with you doing the right things with your personal information.

Don’t confuse paying for mitigation services and expect prevention. You may not end up being happy with the results.

Tuesday, January 29, 2008

Talk of federal government rebates gives identity thieves a fresh angle

It is on the news almost nightly, in the newspaper daily, and on the internet. We are hearing about it just about every day. To stimulate the economy, President Bush is working very hard to seal the deal for many Americans to get rebate checks from the federal government.

For many Americans all the talk of a bonus $600-$1200 check from the federal government is exciting news. Many would like to get it today if that were possible. Everyone wants to be sure the government has their correct name, address, and all the other pertinent information so there will not be a delay. Unfortunately, many will end up with their identity stolen instead.

The thieves will play on that anticipation of you wanting the extra cash as soon as possible and will deploy all the traditional and still effective tactics.

The more common and widespread tactics that will be used:

1)Phishing: Hundreds of millions of emails will go out across the country claiming to be from the IRS or the federal government and will direct you to a special website to verify your personal information. If you click on the link you will end up at an official looking site with all the federal seals making it look authentic. Some phishing sites will even have warning about identity theft on them to give them a more secure look to any visitor.

Red Flag: People have many different email accounts, the government does not use email to contact anyone. You do not supply an email on you tax return!

2)Vishing: This is like the email hunt for information, but you will get a phone call instead. It may be a live person, it may be a recording, it may be a recording asking you to call an 800 number back and verify your information. They may ask for your social security number, bank account number where you would like your check deposited, even a pin number for a debit account.

Red Flag: The federal government will not call you for anything like this, ever. What makes this method even more dangerous, thieves can purchase any name they want to appear on your caller ID, such as IRS Rebate, Federal Rebate Office, US Gov’t Rebate, or any combination of words to get you to believe the call is authentic.

3)Websites: There will be scores of websites popping up using search terms to get you to visit them. Such terms will be “IRS rebate” ,“Federal Rebate”, “ Government Rebate” to name a few. They will bank on people using searches in Google and MSN and Yahoo, to find out more information. The sites may bait people in by claiming if you enter your information now, you will get a check in 2 or 3 weeks. That expediency will be extremely enticing to many so they will get drawn in and become victims.

Red Flag: The only sites that may have any information about this program will be an existing one with quite a bit of other information as well. It will end with a .GOV suffix. Examples are IRS.Gov, SSA.Gov, WhiteHouse.Gov. Any site with an official sounding name but a different suffix is not a federal site. Example is IRS.com which is owned by banks.com and is a play to get you to use their services for tax filing.

4)US Postal Service Mail: You may get a letter or a post card in the mail asking you to verify your bank account or social security number or other sensitive information. It may ask you to call a specified number or go to a website and enter in information.

Red Flag: The government will be using tax returns from previous years records to determine eligibility and addresses. They are not going to mount a new campaign to update records and personal information. If you do get something in the mail from the IRS or other federal agency, take the time to verify the validity prior to acting on it.

None of these tactics are new, but the event that will trigger their upsurge is. Basically this is an extra bonus for identity thieves to prey on victims who will not see this coming because they are blinded by the thought of the dollar sign.

The only real way to combat this offensive is to think about the details before you act. Ask yourself a few common sense questions, and practice fire prevention vs. firefighting.

The best defense for your identity is self defense.

Monday, January 28, 2008

Attention grabbing survey sites could set the stage for ID theft

There are a number of sites that quiz you about yourself and then tell you something about yourself in return. Our site does that as well. We ask you information about your personal daily habits and use proprietary algorithms backed by research to gage your risk for ID theft with an output that is in an easy to understand ID Risk Level. No ads, no personal information requested, not even email.

Someone emailed me recently asking about other sites that have quizzes and pointed out a few in particular and asked me how safe they are even if just for fun.

Some sites, by piquing your interest in certain, even silly subjects, are looking for something. There are a number of sites that purport being able to tell you when you are going to die! Wonderful, that information will certainly come in handy. It makes my retirement investment planning so much easier.

Well, you’re not gullible, but you went there for fun, as a joke, just to see, etc. All in good fun as long as you are not giving them any personal information.

So what could a site like this really be after? Mainly ad revenue. By getting thousands of people to go through the site and take the “date of your death survey”, they land you in a seemingly never ending, page after page of offers for everything from free laptops to a cruise around the world to magazines and so on. The catch is you have to get past saying no to these or fill out a few with your personal information like name, address, phone number, email etc. and what seems to be fairly harmless information. Only, once you go past the myriad of ads asking you to fill in information will you get your “calculated” date with the grim reaper.

So I tried it at a site this person asked me about. I answered the few simple questions and then waited for my results, it had to be calculated, apparently they have a long connection to go through and the grim reaper’s WiFi was down. In the meantime, they graciously had me take review some of their fine offers and click “no” if not interested. I counted 97 (yes, I counted because I assumed it was going to be big) offers that I said “no” to and still was not given my much awaited date with death. I even filled in a few with some random misinformation thinking if they got me on one maybe they would cough up that date! Nothing. I literally gave up as it was appearing to be more and more of a perpetual scam. I guess I’ll need to keep my retirement plans in place for now.

Seriously though, what was really happening was a massive operation to get you to provide just the basics of personal information. Now the company that runs the site may only be a conduit and collecting ad dollars from the marketing agency who is the real culprit in this operation. Fill one out correctly with real information and you have just asked to receive a minimum of 100,000 emails with other exciting offers include. Hey, you asked!


That information may possibly be used by them directly for ID theft, Spamming, phishing, etc. They may sell it to others who will use it unscrupulously. Worse yet, you will be put on a sucker list. This is a list created about people who willingly provide information thinking they are going to win a prize. AKA in their business “a sucker”. ID thieves love suckers. They know they are the easiest of easy targets. The people who think they will really get something for nothing, the same people who ultimately will give the thieves the keys to their identity in much the same way. The thieves already know you are an optimists, and play that hand against you to the fullest.


So the next time you go to a site and think you are providing information that is harmless, looking for that humorous “date of your death” you may find out a new date, when your identity was stolen.

Friday, January 25, 2008

Prudential’s rock crumbles when it comes to securing personal information

Prudential Financial gets a spot on our office’s Identity Defense Wall of Shame this month. They had a temp worker collect personal information from a customer then the temp worker stole the customer’s identity to go on a three month, $70,000 spending spree!

According to the article about this event, Prudential takes customer information and security very seriously. We see that clearly from the end result of this encounter between a Prudential temp employee and a Prudential customer.

Stop and think about what happened here. A financial conglomerate worth $36 billion does not have the sense of how to secure personal information that it receives. Collecting customer information is the most volatile point in a transaction because it is up to the person who collects it as to how the information is treated. This is where Prudential’s security falls apart. The people collecting information should be trusted, longer term, well paid employees, who hopefully, will want to keep their job and have little or at least minimal incentive to steal. Instead they gave that crucial task to a 23 year old temp worker, who obviously did not care about his temp job and felt he needed to supplement his income.

I’m sure they spend millions on data security, and backup systems and passwords and encryption etc. As a financial institution they are required to have secure systems on all fronts. But no matter how big your walls are, or how many lines of defense you have, if you can’t complete step 1 and put the information into secure areas, it is useless. Picture your bank having the tellers leave all the money on the counters at night and still go lock the safe.

If Prudential has procedures in place, the management team is not reading the company manual. To be fair, this could easily happen with just about any employee and it is where a significant portion of all ID theft occurs. But when you assign tasks to someone who is not even an employee, then any incentive to do the right thing is minimized because there is no long term bond.

For the sake of all of their existing customers let’s hope they have a better system in place for securing their personal information.

Monday, August 20, 2007

Apple Online Lawsuit Brings to Light Another Threat of Identity Theft

A recent lawsuit alleges Apple Store is not in compliance with Fair Credit Reporting Act, thereby making it easier for identity thieves to gather more personal information on consumers.

All businesses need to heed this as an example of things to come and protect their clients' personal information in any way that they can after a class action lawsuit, case number 07-22040, was brought against Apple Store online last week in Florida Federal Court alleging that the stores violated the Fair Credit Reporting Act (FCRA). The FCRA is a federal law designed to help ensure that consumer reporting agencies act fairly, impartially, and with respect for the consumer's right to privacy when preparing consumer reports on individuals.

In 2003, an amendment was added that states, "No person that accepts credit cards or debit cards for the transaction of businesses shall print more than the last five digits of the card number or the expiration date upon any receipt provided to the card holder at the point of sale or transaction."

It was this amendment that Apple Store online was violating. Apple Store was apparently printing credit card expiration dates on the receipts, in addition to the other personal information. Companies were given a three-year grace period to comply with the law and the cost is so miniscule to make the change that most have made the change well in advance of the deadline. Apple Store, as of last week, was still not in compliance.

Identity thieves are getting smarter and smarter. Consumers must stay one step ahead and protect themselves from the financial devastation of identity theft. Consumers expect businesses to uphold the law and do what they can to protect personal information they acquire.

While no proof of a specific identity theft has stemmed from Apple Store's non-compliance, it is a recipe for disaster that reminds consumers to take every precaution when making an online purchase or any purchase with a credit card. The federal government has made efforts to protect citizens from identity theft but consumers must be on the offense and take matters into their own hands.

Place yourself in a situation to protect your personal information from theft and learn to practice fire prevention versus firefighting.

Monday, August 13, 2007

Credit Freeze Not the Only Solution to Identity Theft Prevention

Many people who live in states that allow you to freeze your credit are recognizing the benefits of such actions. But a lot are stopping there and not doing any more feeling they have covered the bases and have done what they can to protect themselves.

Governor Deval Patrick from Massachusetts recently signed into law comprehensive identity theft prevention legislation. This new law will require Massachusetts state residents be notified immediately if their personal information has been lost or stolen via security breaches with businesses and government agencies.

As a part of the legislation, the law also states that consumers have the right to freeze their credit reports to prevent new accounts from being fraudulently opened and also puts into effect strict standards for businesses when disposing of personal information.

The portion of the law that puts into place the standards for disposing of personal information is a step in the right direction to identity theft prevention. But allowing a consumer to freeze their credit report does not prevent the theft.

Personal information can already be in the hands of the wrong people. When personal information, such as social security numbers, drivers' license numbers or bank account information is used for widespread fraud, an emotional and potentially expensive mess is left for the victim to clean up.

Of the millions of victims of identity theft last year, many of them had crimes committed against them that had nothing to do with a credit card or loan. This would not be picked up by on credit report which is the focal point of a credit freeze. The black market is booming for individuals' names and IDs for thieves to sell and the buyers will use them for many different types of identity theft. That could include medical treatments, prescriptions, arrests, and theft of existing or open accounts.

One major solution to the problem is for people to practice self defense when it comes to their personal information. Society has become so accustomed to keeping droves of information available we are leaving it laying around us everywhere. The identity thieves are everywhere picking it up.

When it comes to your identity you need to think in terms of fire prevention and not firefighting.

Monday, July 9, 2007

GAO Reports on Identity Theft, Sort of

Recently the US Government Accountability Office released its findings of a study on the net effect of data breaches, stolen data, and unaccounted for data and how much actual identity theft resulted from such occurrences. They undertook this task to help Congress decide if a federal law should be considered for a national breach notification requirement. Some states already have laws in effect to various degrees requiring notification of data lost so that consumers can take immediate actions to see if they’ve become a victim.

Sounds a bit odd, but breach notification would most likely just give you a heads up a bit sooner if you are a victim. Many times a data breach notification is the first time a victim looks at a bank or credit card statement, balances a checkbook for the first time in ten years, or obtains a credit report.

The GAO was asked to examine three distinct areas

(1) The incidence and circumstances of breaches of sensitive personal information

(2) The extent to which such breaches have resulted in identity theft

(3) The potential benefits, costs, and challenges associated with breach notification requirements.

The GAO used various sources for the research and came up with an earth shattering discovery; data thefts are rampant and occur frequently and are probably underreported due to lack of voluntary or mandatory disclosure.

They also determined they can’t directly link identity theft to many of the data thefts they reviewed because there is not clear and conclusive evidence that directly links those breaches with identity theft. Apparently the identity thieves are not disclosing the abundant sources of their windfall.

There you have it, if it is not conclusive then it must not have occurred, or at least they can’t say it occurred. It does not mean that it didn’t.

They even admitted that the lack of reporting on the part of victims also leads to skewed and invalid data that cannot be used to create a valid statistical picture.

So how do many interpret this : “GAO finds little identity theft results from data breaches”.

Apparently there are a lot of thieves going to a lot of trouble stealing personal data, then changing their minds finding religion and doing nothing with it after all.

But if that is the case, then where did all that personal stolen information come from that results in the billions of dollars in personal losses from the millions of actual victims each year? There was not a place to include them in this report.

Monday, June 25, 2007

Ohio’s state government places a value on personal information

The latest in the string of embarrassing data breaches involves the state of Ohio whose officials allowed a storage device to be stolen from a car.

This story keeps getting worse as at first it was thought that only 64,000 state employees personal information was on the device, but now they are realizing that a few hundred thousand Ohioan’s information was also on the device. Depending on the source the number varies from 200k to 500k. No matter what it ends up being it is a PR nightmare for the state government and elected officials.

At to add more embarrassment to the situation the person who had it stolen was an intern.
To me an intern is a student or a recently graduated individual who is now working for the state government as an apprentice to learn the ropes, the rules, gain exposure, acquire experience, and even earn college credits. In other words, a rookie.

So with all of the people that work in the state government, an intern is chosen to carry the storage device as a security measure to have copies of data in case something terrible happens. It just didn’t cross anyone’s mind that they were not paying attention to the security of the data at both ends. And something did happen, just not at the end they were expecting.

So with all of the concern about protecting this information they hand it over to an intern who leaves it in a car (by some accounts unlocked) and it disappears. Did the intern even know what they were taking home? Did anyone bother to tell the intern? What was the value of that information on the device if it could be handed over for safekeeping to an intern? The state must have felt it was very little since they gave it to the lowest person on the ladder. But now the value is starting to mount as the state is already spending hundreds of thousands on services to protect individuals and that is just the start.

If whoever took that device does crack into it successfully and spreads the wealth of information all over the internet, you can be assured that institutions that will start to bear the brunt of costs associated with this will surely look to the state for restitution.

Ohio is now falling into the same path as millions of Americans who do not bother to take pro-active steps, but then spend millions on reactions once a breach occurs.

Monday, June 18, 2007

Think before filling out that Free Prize or Sweepstakes Card

When you are walking through the mall, or at a fair, or even online, chances are you’ll get asked to fill out a form for a chance to win some wonderful prize or receive something for free.

And why not, it costs you nothing and someone’s got to win that new laptop, or the car, or the trip to the moon. A pen in hand and 60 seconds later you feel like you may be getting a call or letter for some fantastic prize. And you were sure to put down your phone number, so when you win, they’ll call right away.

We all like to be optimistic. We all want to think we have got a shot at the big one! I don’t know what the big one is, but it’s big!

Now let’s take a walk to the other side of the isle called reality. In reality there is no real prize, or the person who won it lives in the Arctic circle and the company cannot deliver it. If there is a prize, the barriers to get it may be out of reach. You get the picture, they are trying to get your personal information for a much bigger catch.

But what you may ultimately end up with, is your identity stolen, and you’ll become the victim of identity theft.

When you filled out that form for a prize, you labeled yourself as an optimist. The company who requested the information, may be legitimate, and there may be the prize,, and but may sell that list of names collected to a marketing company. You may end up on a “sucker list”.

Identity thief rings buy “sucker lists” from direct marketing companies. You’ll then be a target for a phone scam or “vishing”. You’ve already given them a good reason to call because you are optimistic or in their terms a “sucker”. Now your wide open, and they will throw every trick in the book at you. This is what they do, this is what they are good at.

The odds of getting your identity stolen are much greater than winning anything, so don’t bother trying to win by giving up information. You will have taken a significant step in defending your identity.

Tuesday, June 12, 2007

Can Check Fraud Become Obsolete?

I am still amazed as I stand in any line at a store and the person in front of me pulls out a checkbook and writes a check, has to dig out a shopper ID card or some other form of ID, then hands it to the cashier. The cashier, with a puzzled look, takes all the documents and writes down information on the check. The cashier hands any ID back to the patron then sticks the paper check into the register 3 different ways.

At about the midway point through this production, I realize why I don’t write checks anymore and the person who invented the debit card should win the Nobel prize. What an incredibly antiquated and outdated system that is still being used by millions of people despite all the pitfalls.

Beyond the fiasco at the register, look at what else this dinosaur system burdens us with:

The number of checks stolen or forged each year is about 500 million checks and over $10 billion in lost revenue. Check fraud in itself is expected to grow at a rate of about 2.5% each year.

The average number of fraudulent checks written daily is about 1.4 million equaling $27.3 million worth of fraudulent checks written everyday.

According to the National Check Fraud Center, check fraud and counterfeiting are the largest and fastest growing problem that the United States financial system now faces. The estimated losses produced annually are over $10 billion and is expected to continue to rise.

Sure checks have their place in very few instances but these statistics coupled with the surge in identity theft, makes me wonder why the banks and other businesses still embrace them.

Why does the public still embrace them as well? The alternative for many will result in anxiety and fear. Debit cards with PIN numbers, all the talk about loosing information in data breaches, plus identity thieves looking over my shoulder at the checkout, all give the feeling of fear.

Reality paints a different picture, because these are the same people who write checks in regular ink, place them in the mailbox in the morning before work, put that red flag up, and never give a thought that they could be contributing to the above statistics by the end of the day.

What can you pro-actively do to help make check fraud obsolete?

1)Switch to an online billpay system
2)Use a debit or credit card for all merchant transactions
3)Have companies that you pay monthly like a utility debit your checking account


But …..if you must still use checks:

1)Don’t put them in your mailbox in the morning and raise that red flag
2)Lock up all checks and deposit slips in your home
3)Don’t carry a checkbook around in a purse or leave it in your car
4)Use a black ink Bic Rollerball or a gel pen to write out any checks, they can’t be washed off


If your are a victim of identity theft and check fraud is one of the causes:


Report stolen checks, and close unauthorized checking and savings accounts.
If you have had checks stolen or bank accounts set up fraudulently, report it to your bank or to one of the check verification companies listed below. (If a merchant rejects your check, ask for the name of the check verification company.)
When you do contact any major check verification companies listed below, request that they notify retailers using their databases not to accept your lost or stolen checks. Place immediate stop payments on any outstanding checks that you have not written.


• CrossCheck: 1-707-586-0551
• International Check Services: 1-800-526-5380
• National Check Fraud Service: 1-843-571-2143
• SCAN: 1-800-262-7771
• Equifax Check Systems: 1-800-437-5120
• TeleCheck: 1-800-710-9898 or 1-800-927-0188
• Chexsystems: 1-800-428-9623

Thursday, May 31, 2007

Identity Thieves in Your Safety Zone?

When I ask people to describe an identity thief I usually end up with a wide array of answers and descriptions. They range from thinking they must be from another country, or are in organized crime rings, or gang members, drug addicts, low income or poverty stricken etc. Truth is, because identity thieves come from many diverse backgrounds, you could say just about anything and not be wrong.

But everyone just about left off a description of a thief they would know best. Someone close to them!

If you’re a victim of identity theft, there is a chance you know the thief. The thief was someone close to you. How close do I mean? Well maybe not intimate close, but close enough for them to be inside your self imposed safety zone. What is that safety zone? Most likely your home, apartment, dorm room, anyplace you call home is your safety zone, the area you feel comfortable in enough to leave personal items lying out in the open because you’re inside your own personal zone.

Ever sit and think who you let into that zone? I’ll create a fictitious, but realistic list for you:

1) Aunts and Uncles plus their spouses
2) Cousins plus spouses
3) Nieces and nephews
4) Brothers and sisters plus Brother and Sister – in Laws
5) Step brothers, step sisters
6) Mother
7) Father
8) Nanny
9) Baby sitter
10) House sitter
11) Painter
12) Plumber
13) Repair Person
14) Friends
15) Co-workers
16) Teenagers friends
17) Housekeeper
18) Maintenance
19) Neighbors
20) Clergy
21) Sales people
22) Parents of your children’s friends

Now that we’ve looked at it in a little more detail, it’s a pretty big list. Probably much bigger than you envision.

Why these people? Why not? They represent a good diverse cross section of society. And in society there are plenty of people with bad and devious habits. Most bad habits are hidden from others and often require funds. Funds they do not have readily available so they have to become creative to get those funds. This new age of identity theft is giving these people easy access to funds.

Because you allow them into your safety zone, you never bother to put up your guard.

By leaving your personal information unlocked or in plain view, you are potentially inviting somebody from that list above to turn you into a victim of identity theft.

The easiest step would be to keep personal information from those people in the first place. Sounds easy but approximately 1.5 – 2 million people last year didn’t think about it and found out the hard way what people from that list were capable of.

Monday, May 28, 2007

Fraud Alert Gives False Sense of Security

Recently in a local community a laptop belonging to a county agency was stolen from a community center that had the names and personal information of 7,000 people who had applied for a state health insurance program dating back from 2003 to the present. It does not sound astonishing, but the community has about 45,000 people in it.

The county did do the right thing by disclosing it immediately; they fell extremely short when offering advice.

They told everyone who may be impacted by this to place a fraud alert on their credit report. They also mentioned providing credit monitoring.

Did they really understand what a fraud alert meant? Do they recognize that credit monitoring is an after the fact service?

A fraud alert is a notice you place on your credit report that technically REQUESTS additional verification by the lender with you personally when new credit is applied for.

Go into a store and request a store credit card, the lender who transacts credit for the store will check your credit report for viable credit. If there is a fraud alert on your account they have the OPTION of contacting you to verify that you have actually applied for credit at this store. Note the word OPTION, not mandatory nor legally required. If the lender cannot reach you at the phone numbers they have on file, they can go ahead and issue credit at their discretion.

So if everything works correctly for a thief they could obtain credit in your name despite a fraud alert. Remember it is at the lenders option and they want to issue credit, that is what they do. It only adds an optional extra step, but doe not guarantee a thief will not be able to open up an account in your name.

The name used for this notification is misleading. Local county officials thought it sounded like worthy all encompassing advice to offer to 7,000 victims.

Thursday, May 24, 2007

P2P Networks Significantly Increase Risk of Identity Theft

Ask someone who has a child in middle school up through college what P2P is and chances are you’ll get a look of uncertainty. Chances are they will not know what you are talking about and if they do the details will be scant.

If they do know what P2P is, do they truly understand the dangers of it outside of the fact the kids are likely using it to obtain copyrighted material for free and most likely illegally. There are legal ways to use P2P networks for sharing photos and video clips and other homemade material, but it is used mainly for illegal downloading of copyrighted material without paying for it.

P2P is an abbreviation for Peer to Peer networking. How it works in simple terms, you expose folders on your PC to other peoples PC’s on a network, and you copy anything you find in their folder back to your PC, generally music files. But anything else in that folder is fair game to anyone on the network who wants to look at your PC. And depending on how the PC user allows others to view files, your entire hard drive could be read like an open book to anyone on the internet. Nothing scary there! You might just as well go post files of last years tax returns in a chatroom of identity thieves and set a timer to see how quick someone becomes you.

The network is set up by a third party service who just acts as a hub that all the users pass through to get to other PC’s on the network. They are everywhere and becoming harder to shut down due to ruling in court cases and the ability to operate in a manner that cannot be easily detected.

P2P has been around for a long time, remember the name Napster in the news a few years back? They brought P2P file sharing to the mainstream. The recording industry got them shut down because of the massive losses in music sales all blamed on illegal P2P usage.

So what has changed since then? P2P is growing among younger PC users and exposing their own or their parents personal information to identity thieves. The thieves scour P2P networks looking for personal information in folders that your 9th grader has exposed unknowingly.

According to a recent study released by Dartmouth business school researchers, P2P users have increased from 4 million in 2003 to approximately 10 million today.

So no surprise that along with it, identity theft has also been on the rise. It is an epidemic in this country. Is P2P responsible for that? It sure has added to the ease in which the thieves are obtaining information.

So now what? Any sensible adult who has any child engaged in P2P file sharing of any sort, particularly illegal music, should shut it down and close that door immediately. The lure of free (illegal) music for the kids will pale in comparison if you bank account get drained by an identity thief. There are plenty of safe and secure site to buy music from at extremely reasonable prices.

It is up to individuals to protect themselves and keep tabs on what is happening on the family PC. Go take a look before it’s too late.

Monday, May 14, 2007

The Hidden Costs of Identity Theft

Recently I read a news article written about a seminar recently given on identity theft by an attorney from the Federal Trade Commission. While I will save my opinion of his stated facts about the cost of identity theft for another post, he said 99 percent of identity theft victims pay nothing, and if there is any cost vendors pay for it! WHAT? Did he just fall out of the sky and crash land on planet earth, head first?

Just think about all the other costs, the unseen, uncalculated, or unaccounted costs, we could be referring to a value that in some instances would be unbelievable.

Let’s look at time alone. Depending on what statistical survey you refer to, the time spent per victim usually averages in the range of 500 hours to clear all the hurdles to restore their name and credit and obtain any restitution. When do they do this? Many during normal business hours. An employer of a victim, and many are employed, will lose thousands in lost time and productivity due to phone calls, paperwork, making copies, faxing information and police reports. Also time off for trips to court, an attorney’s office, or police department. Think of the time loss and cost to the self employed.

Emotional costs are also not included in his figure. I was at an event recently and spoke with many individuals about identity theft, and I was truly amazed at how many had been victims or knew a victim directly. One woman had the most emotionally charged story about a close relative who stole her identity. She was forced to press police charges against that close relative, otherwise she could not get the $6,000 in theft cleared from her name and she did not have the funds to cover it either. She was extremely distraught because she knew the negative impact it would have on her if she did not press charges, but she also knew the lifelong damage the close relative would endure for this one event.

Others feel violated, hurt, constantly suspicious, untrusting and the list goes on.

So what impact do those feelings that now have on the economy? Many of these people will stop using credit or debit cards, will not buy online, will not do many things that will impact the economy much like a recession.

And for the cost to the vendors that do actually pay for or cover losses, where does he think that money will ultimately come from? We all bear the burden of paying for the costs of identity theft. Much in the same manner we share the costs for insurance when a major hurricane hits even a majority were never impacted by it.

So in the grand scheme of identity theft the impact of the actual dollar amount may only be a small part of the total cost, but everyone who gets hit with identity theft pays a price.

Thursday, May 10, 2007

Homeland Security Department Not So Secure

Last week the Transportation Security Administration had lost a computer hard drive containing data and payroll information for about 100,000 employee records. They use the term lost, but seeing who is involved in looking for it, stolen is probably the better word choice. They may find it being used as a bookend somewhere.

The data was on employees who worked at the agency between January 2002 and August 2005 and included Social Security and bank account numbers, names, dates of birth, salaries, benefit deductions, and bank routing information.

In case you don’t recall, the TSA is a part of the Homeland Security Department. That does not sound reassuring at all. The agency that was chartered after 911 to protect us is not even protecting itself.

But if you look at a short chronology from the last 3 weeks you could not make up this entire string of events that has just rolled out of our elected government.

- April 23, 2007 The President’s Identity Theft Task Force – Combating Identity Theft a Strategic Plan – 120 pages of what Washington wants everyone to do

- April 2007 Government Accountability Office – Privacy – Lessons Learned about Data Breach Notification – 78 pages of how and when to notify people the next time it happens! They were planning on it!

- May 4, 2007 TSA notifies 100,000 of a lost hard drive

- May 9, 2007 The American Federation of Government Employees (AFGE), along with four security screeners, charged that the TSA had recklessly violated the Privacy Act and also violated the Aviation and Transportation Security Act. The class action suit was filed in U.S. District Court in Washington on Wednesday 5/9/07.

President Bush has to be in the White House banging his head on the oval office walls. He would ask Attorney General Gonzales, but he has his own issues to worry about, and he issued that 120 page report, so he’s off the hook. So who else can take responsibility for this? Typical reaction is to roll a head or two in the management ranks. What does that solve? It only keeps the same inept individuals still guarding the data, which they didn’t do so well to start with.

What really needs to happen is people who are truly responsible for this, at the office level, get fired, loose their pensions drain their 401’s. If you were handed information and told your financial future depended on keeping it safe, you can be sure there would be people keeping better track of that data better than their wallet.

Lack of accountability breeds lack of responsibility.

Friday, March 30, 2007

TJX added to our ID Wall of Shame

TJX owns T.J. Maxx, Marshall's and other stores in North America and the United Kingdom, and have great stores but they have proven without a doubt they have a PR machine that is compromised just like their computer system.

They do not publicly disclose the extent of the record breach but attempt to slip it into a regulatory filing, hoping it will go unnoticed. Sure 45.7 million cards represent an ugly number. But they backed themselves into a corner by having to explain it once it was plucked from the filing. TJX didn’t think to tell anyone about that ahead of time, but since you found it in our SEC form 10-K and brought it up we’ll have to talk about it now.

So that was not such a great move, but what was a bit more unsettling was they have openly stated they cannot offer any assistance to anyone who has been “inconvenienced” by a theft. They refuse to talk anymore about that due to litigation. You want a piece of them? You’ll have to get in line with the 20 plus lawsuits filed to date.

And the pitiful PR icing on the cake is they only offer free credit monitoring for 1 year for the 455,000 who lost personal information, drivers license numbers, military ID numbers, etc, which could be used to commit identity fraud.

What is that really worth? If the pattern follows through from the other 45 million card theft only victims, they probably will not help out if your identity is stolen but they will pay for a service that informs you about ID fraud after it has occurred. If that’s the case, once again it will be up to the victims to rectify the situation, incur the cost and the headaches to say the least. Something sound familiar here?

Haven’t they been down this road before? They may never learn.

While credit monitoring is one of many useful tools to combat fraud, there is much more they should be doing for all of those who may be “inconvenienced”. For that we have added TJX to our ID Wall of Shame.