Showing posts with label Internal Revenue Service. Show all posts
Showing posts with label Internal Revenue Service. Show all posts

Tuesday, January 13, 2009

Identity Theft During Tax Season

Christmas time for identity thieves is now upon us. W-2's, tax forms, financial statements, all come out this special time of year for just about every person in the country.

Many will think very little about putting all of their personal records in a folder and taking them to a preparer sitting in a kiosk or booth at the mall or at a store that has set up this temporary area to capitalize on tax season.

I was observing one such place recently and was shocked at what I saw.

For starters there was no shredder anywhere to be found and I saw papers just tossed in a garbage can close by. I was not about to sift through it but I am sure there were worksheets and other discarded items from the preparer that should have been shredded. Items that contained plenty of personal information and enough for a savvy thief to use.

I saw her and her clients leave the "booth" and documents were left out in the open on the desk for anyone to walk up sit down pretend to be waiting and with a simple pen and paper copy social security numbers down.

If you feel compelled to have your taxes completed in such an environment, try to be aware of your surroundings and who can see. Take all your papers with you when you leave, even the scraps and worksheets. Be sure the preparer has not left any of your information laying around.

Most importantly, keep in mind that many of these temporary stations are staffed by temporary workers. You may be providing your personal information to someone who has just been hired. While I have to believe that there was some screening process, that is no guarantee that your information will be kept safe.

These people are hired and trained to complete tax returns, collect a fee and do it as quickly as possible. Information safety and security is probably not very high on the list. I'm sure they were told about it, handed a sheet of paper on it, and technically speaking "trained" to handle it properly, but if the goal is something other than that, one has to keep in mind how diligent are they really going to be.

You really need to decide if this is the environment you want to have your personal information exposed too.

Saturday, February 23, 2008

FTC Identity Theft Data Causes Skewed Views

The FTC has issued the latest report for 2007 on Consumer Fraud and Identity Theft Complaint Data. With no great shock or surprise identity theft is still the number one complaint by a long shot being 32% of the reported 813,899 total complaints reported. The next closest category was Shop at Home/ Catalog Sales with a mere 8%. There were 20 categories in all and the bottom 13 categories were each 2% or less.

This is a good report as it paints many pictures but at the same time skews the reality due to how the information is collected.

Certain areas of the US have more information available to consumers or police agencies that promote reporting identity theft to the FTC.

Because the reporting is entirely voluntary lends more of an explanation as to why some states have more incidences than others. The reality of identity theft crime statistics goes much deeper than the simplistic overview of the charts of this report.

A Skewed View

I have read a number of articles from various states that have had a decrease in the number of incidences reported to the FTC are feeling incredibly good about it. They are utilizing this information to pat themselves on the back. In Wisconsin one state that experiinced a decrease, had the administrator of the Division of Trade and Consumer Protection claiming they like to think they are getting the word out better, but also claims she does not know why they ended up so low in the rankings. She obviously needs to take a class on Understanding Reports 101, or is just looking to get a promotion. Statements like this coming from someone who is the head of consumer protection for the state should be a bit unnerving for the residents of Wisconsin.

But kudos goes to the Wisconsin Bankers Association who says the FTC information does not reflect what they are seeing.

Take a state such as Colorado with this same view. They have 4 of the top 50 metropolitan areas in the US reporting identity theft. Of those 4 areas, they all had a highly disproportionate number of reports compared to the other 46 areas. That does not directly indicate it is a state with an unusually high rate of identity theft, but likely a state that is actually educating consumers on what to do and encouraging reporting to the FTC.

No signs of abatement

One thing can be said with certainty is that identity theft is not showing any significant signs of abatement.

With all of the services available to stop this, and alert you of that, and the thousands that are paying monthly fees, one would expect this number would be dropping dramatically, or at least see a slight dent in the numbers.

But then again if you rely on some reporting agency with a subscription service you pay monthly to tell you someone has your information and tried to open some type of account in your name, the theft has already happened and is likely eligible to be reported to the FTC anyway. Paying money each month to have someone tell you a theft has occurred will not change the fact that a thief already has your information.

Reporting to the Police

What is still shocking in this report is the number of people who did not report the crime to a police agency which was 65% or 158,535. Why they chose not to is a mystery that we are looking into, but even more disturbing was the revelation that of the 35% that did take the time to report the crime 8% of those did not get a report taken from the police.

The reality of what was going on at the time is the police are looking around the precinct when a victim calls or shows up. They see they have 2 muggers, a car thief, and an arsonist all waiting to be booked and processed. An identity theft victim comes in declaring a theft that by appearances likely occurred across state lines or out of the country. The probability of an arrest is remote, but the headache of the extra paperwork 100% guaranteed.

The message sent is this is a crime to be treated lightly by consumers and the some (not all) police agencies are not be doing enough to encourage or educate people in how to protect themselves. If thousands are turned away and led to believe the police can do nothing, then a feeling of helplessness will likely prevail.

The best defense is self defense. A majority of identity theft starts with people leaving the gates to their identity open and allowing the fraud to occur.

Thursday, January 31, 2008

Federal government rebate scams continue to grow and flourish

Two days ago I wrote about the issue of all the talk of the federal rebates and how fraudsters, scammers and ID thieves would come out of the woodwork to capitalize on it from unsuspecting and eager individuals. I had listed the common tactics that thieves will be using as reminders for what to be cautious about but it is already going well beyond those and getting people engaged from every possible angle.

Here is a list of the latest scams brought to the attention of the IRS:

Rebate Phone Call

At least one scheme using the word "rebate" as part of the lure has been identified. In that scam, consumers receive a phone call from someone identifying himself as an IRS employee. The caller tells the targeted victim that he is eligible for a sizable rebate for filing his taxes early. The caller then states that he needs the target´s bank account information for the direct deposit of the rebate. If the target refuses, he is told that he cannot receive the rebate.

This phone call is a scam. No legislation has yet been enacted that would allow the IRS to provide advance payments to taxpayers or that determines the details of those payments. Moreover, the IRS does not force taxpayers to use direct deposit. Those who opt for direct deposit do so by completing the appropriate section of their tax return, with bank routing and account information, when they file; the IRS does not gather the information by telephone.



Refund e-Mail

The IRS has seen several variations of a refund-related bogus e-mail which falsely claims to come from the IRS, tells the recipient that he or she is eligible for a tax refund for a specific amount, and instructs the recipient to click on a link in the e-mail to access a refund claim form. The form asks the recipient to enter personal information that the scamsters can then use to access the e-mail recipient´s bank or credit card account.

In a new wrinkle, the current version of the refund scam includes two paragraphs that appear to be directed toward tax-exempt organizations that distribute funds to other organizations or individuals. The e-mail contains the name and supposed signature of the Director of the IRS´s Exempt Organizations business division.

This e-mail is a phony. The IRS does not send unsolicited e-mail about tax account matters to individual, business, tax-exempt or other taxpayers.

Filing a tax return is the only way to apply for a tax refund; there is no separate application form. Taxpayers who wish to find out if they are due a refund from their last annual tax return filing may use the "Where´s My Refund?" interactive application on this Web site, IRS.gov. The only official IRS Web site is located here at www.irs.gov.



Audit e-Mail

Another new scam brought to IRS attention contains features not seen before by the IRS. Using a technique calculated to get almost anyone´s attention, the e-mail notifies the recipient that his or her tax return will be audited. This is the first scam of which the IRS is aware that uses this to get the victim to respond.

Unusual for a scam e-mail, it may contain a salutation in the body addressed to the specific recipient by name. Most scam e-mails seen by the IRS are sent using the same technique used by spammers, in which hundreds of thousands of messages are sent to potential victims based on Internet address. Because of the volume, the typical scam e-mail is not personalized.

This e-mail instructs the recipient to click on links to complete forms with personal and account information, which the scammers will use to commit identity theft.

This e-mail is a phony. The IRS does not send unsolicited, tax-account related e-mails to taxpayers.




Changes to Tax Law e-Mail

This bogus e-mail is addressed to businesses, accountants and "Treasury" managers. It instructs them to download information on tax law changes by clicking on a series of links to publications on businesses, estate taxes, excise taxes, exempt organizations and IRAs and other retirement plans. The IRS believes that clicking on a link downloads malware onto the recipient´s computer. Malware is malicious code that can take over the victim´s computer hard drive, giving someone remote access to the computer, or it could look for passwords and other information and send them to the scamster. There are other types of malware, as well.

The urls contained in the link are not legitimate IRS Web addresses. All IRS.gov Web page addresses begin with http://www.irs.gov/.




Paper Check Phone Call

In a current telephone scam, a caller claims to be an IRS employee who is calling because the IRS sent a check to the individual being called. The caller states that because the check has not been cashed, the IRS wants to verify the individual´s bank account number. The caller may have a foreign accent.

In reality, the IRS leaves it entirely up to the individual to choose to cash or not cash a paper check. The IRS has no business need to know, and does not ask for, bank account or similar information, except when taxpayers indicate on their tax return that they are opting for the direct electronic deposit of their refund. In that case, however, it is the individual´s responsibility to provide the IRS with the correct bank routing and account numbers on the tax return; the IRS does not contact taxpayers to verify the information.




What to Do

Anyone wishing to access the IRS Web site should initiate contact by typing the IRS.gov address into their Internet address window, rather than clicking on a link in an e-mail or opening an attachment.

Those who have received a questionable e-mail claiming to come from the IRS may forward it to a mailbox the IRS has established to receive such e-mails, phishing@irs.gov, using instructions contained in an article titled "How to Protect Yourself from Suspicious E-Mails or Phishing Schemes." Following the instructions will help the IRS track the suspicious e-mail to its origins and shut down the scam. Find the article by visiting IRS.gov and entering the words "suspicious e-mails" into the search box in the upper right corner of the front page.

Those who have received a questionable telephone call that claims to come from the IRS may also use the phishing@irs.gov mailbox to notify the IRS of the scam.

Tuesday, January 29, 2008

Talk of federal government rebates gives identity thieves a fresh angle

It is on the news almost nightly, in the newspaper daily, and on the internet. We are hearing about it just about every day. To stimulate the economy, President Bush is working very hard to seal the deal for many Americans to get rebate checks from the federal government.

For many Americans all the talk of a bonus $600-$1200 check from the federal government is exciting news. Many would like to get it today if that were possible. Everyone wants to be sure the government has their correct name, address, and all the other pertinent information so there will not be a delay. Unfortunately, many will end up with their identity stolen instead.

The thieves will play on that anticipation of you wanting the extra cash as soon as possible and will deploy all the traditional and still effective tactics.

The more common and widespread tactics that will be used:

1)Phishing: Hundreds of millions of emails will go out across the country claiming to be from the IRS or the federal government and will direct you to a special website to verify your personal information. If you click on the link you will end up at an official looking site with all the federal seals making it look authentic. Some phishing sites will even have warning about identity theft on them to give them a more secure look to any visitor.

Red Flag: People have many different email accounts, the government does not use email to contact anyone. You do not supply an email on you tax return!

2)Vishing: This is like the email hunt for information, but you will get a phone call instead. It may be a live person, it may be a recording, it may be a recording asking you to call an 800 number back and verify your information. They may ask for your social security number, bank account number where you would like your check deposited, even a pin number for a debit account.

Red Flag: The federal government will not call you for anything like this, ever. What makes this method even more dangerous, thieves can purchase any name they want to appear on your caller ID, such as IRS Rebate, Federal Rebate Office, US Gov’t Rebate, or any combination of words to get you to believe the call is authentic.

3)Websites: There will be scores of websites popping up using search terms to get you to visit them. Such terms will be “IRS rebate” ,“Federal Rebate”, “ Government Rebate” to name a few. They will bank on people using searches in Google and MSN and Yahoo, to find out more information. The sites may bait people in by claiming if you enter your information now, you will get a check in 2 or 3 weeks. That expediency will be extremely enticing to many so they will get drawn in and become victims.

Red Flag: The only sites that may have any information about this program will be an existing one with quite a bit of other information as well. It will end with a .GOV suffix. Examples are IRS.Gov, SSA.Gov, WhiteHouse.Gov. Any site with an official sounding name but a different suffix is not a federal site. Example is IRS.com which is owned by banks.com and is a play to get you to use their services for tax filing.

4)US Postal Service Mail: You may get a letter or a post card in the mail asking you to verify your bank account or social security number or other sensitive information. It may ask you to call a specified number or go to a website and enter in information.

Red Flag: The government will be using tax returns from previous years records to determine eligibility and addresses. They are not going to mount a new campaign to update records and personal information. If you do get something in the mail from the IRS or other federal agency, take the time to verify the validity prior to acting on it.

None of these tactics are new, but the event that will trigger their upsurge is. Basically this is an extra bonus for identity thieves to prey on victims who will not see this coming because they are blinded by the thought of the dollar sign.

The only real way to combat this offensive is to think about the details before you act. Ask yourself a few common sense questions, and practice fire prevention vs. firefighting.

The best defense for your identity is self defense.

Monday, August 13, 2007

Credit Freeze Not the Only Solution to Identity Theft Prevention

Many people who live in states that allow you to freeze your credit are recognizing the benefits of such actions. But a lot are stopping there and not doing any more feeling they have covered the bases and have done what they can to protect themselves.

Governor Deval Patrick from Massachusetts recently signed into law comprehensive identity theft prevention legislation. This new law will require Massachusetts state residents be notified immediately if their personal information has been lost or stolen via security breaches with businesses and government agencies.

As a part of the legislation, the law also states that consumers have the right to freeze their credit reports to prevent new accounts from being fraudulently opened and also puts into effect strict standards for businesses when disposing of personal information.

The portion of the law that puts into place the standards for disposing of personal information is a step in the right direction to identity theft prevention. But allowing a consumer to freeze their credit report does not prevent the theft.

Personal information can already be in the hands of the wrong people. When personal information, such as social security numbers, drivers' license numbers or bank account information is used for widespread fraud, an emotional and potentially expensive mess is left for the victim to clean up.

Of the millions of victims of identity theft last year, many of them had crimes committed against them that had nothing to do with a credit card or loan. This would not be picked up by on credit report which is the focal point of a credit freeze. The black market is booming for individuals' names and IDs for thieves to sell and the buyers will use them for many different types of identity theft. That could include medical treatments, prescriptions, arrests, and theft of existing or open accounts.

One major solution to the problem is for people to practice self defense when it comes to their personal information. Society has become so accustomed to keeping droves of information available we are leaving it laying around us everywhere. The identity thieves are everywhere picking it up.

When it comes to your identity you need to think in terms of fire prevention and not firefighting.

Saturday, April 14, 2007

National identity theft awareness week

While identity theft is a year round event, this coming week, could just qualify for National Identity Theft Awareness Week. The week could get this designation because it is becoming one of the more prevalent ones for identity theft due strictly to the time of year. No, there is no such week, but if there were any good time to raise awareness, this week is it.

We wouldn’t be human if we did not have some worry this time of year regarding filing our income taxes.

The forms, the documents, the receipts, the calculator, the room you barricade yourself in, and vow not to emerge until the deed is done. Those are all recurring items that we’ve been through before and will go through again, but we still feel anxiety regardless.

While getting your taxes done is paramount for this time of year, you need to be on alert for more than just an audit. The thieves and con artists go into overdrive this time of year. They feed on your sense of commitment and urgency to get that return done and in on time.

So what should you be concerned about? Here are my top 10 awareness items to think about this week for protecting yourself from an identity thief:

1) Shred all those printed copies that you found mistakes on, and had to reprint.

2) Keep your hard copy of your tax returns locked up.

3) If you use a tax preparer or a CPA, be sure they are securing your information, after you leave the office. Look around to see and verify that they use a shredder. Ask them how they secure your information when they are done for the night.

4) Give some consideration to where you are copying a tax return. It has recently come to light that copiers retain digital information of every copy they make, and some are not being properly erased.

5) If you used software at home on your own PC, save your tax returns to a disc and delete it from your hard drive. Keep in mind if you loose a laptop do you want your tax return available to anyone who acquires it?

6) Ignore and delete emails from the IRS. They don’t have your email address, do you remember providing it to them?

7) Only eFile through the links on the IRS website http://www.irs.gov/ . Recently thieves have been setting up fake eFile sites and collecting your information.

8) Don’t provide any information to any who calls claiming to be from the IRS.

9) Don’t leave your return in your mailbox. Take it to the post office directly.

10) Use a reputable tax preparer. Remember that you are handing them the keys to your identity, if you don’t know them, they may just drive off with it, or sell the information to a third party.

Tuesday, April 10, 2007

The IRS does not use email?

Around this time every year millions of emails arrive proclaiming the IRS needs you to verify your information, needs more information, has money to give back to you, and the list goes on and on. To conform, all you need to do is cough up some very valuable information.

They all invoke some type of high emotion, either fear or excitement. Both can cloud clear judgment, and reasoning. And it works, all too well.

Lets look at this from a logical and simple point of view. What is the main goal of the IRS? To collect tax revenue. What else do they do? Audit you to try and collect more tax revenue. Have you ever heard of them doing anything else?

Those two functions just about wrap it up.

So if we look at what they don’t do here is my simple list of 5 rules, and read rule #1 at least 50 times:

Rule 1)The IRS doesn’t ask for an email address on your 1040
Rule 2)The IRS doesn’t ask for missing information via email (See rule #1)
Rule 3)The IRS doesn’t ask for more information via email (See rule #1)
Rule 4)The IRS certainly doesn’t offer additional refund money via email (See rule #1)
Rule 5)The IRS absolutely doesn’t locate bonus or extra money just for you


Now go back and read rule #1 above again. If you can remember that, you can be assured that any message you get proclaiming anything from the IRS is a fake and a phishing scam.

So when you see the words IRS in an email for any reason instantly think of my IRS #1 rule and then hit the DELETE key.