Showing posts with label debit card. Show all posts
Showing posts with label debit card. Show all posts

Monday, January 28, 2008

Attention grabbing survey sites could set the stage for ID theft

There are a number of sites that quiz you about yourself and then tell you something about yourself in return. Our site does that as well. We ask you information about your personal daily habits and use proprietary algorithms backed by research to gage your risk for ID theft with an output that is in an easy to understand ID Risk Level. No ads, no personal information requested, not even email.

Someone emailed me recently asking about other sites that have quizzes and pointed out a few in particular and asked me how safe they are even if just for fun.

Some sites, by piquing your interest in certain, even silly subjects, are looking for something. There are a number of sites that purport being able to tell you when you are going to die! Wonderful, that information will certainly come in handy. It makes my retirement investment planning so much easier.

Well, you’re not gullible, but you went there for fun, as a joke, just to see, etc. All in good fun as long as you are not giving them any personal information.

So what could a site like this really be after? Mainly ad revenue. By getting thousands of people to go through the site and take the “date of your death survey”, they land you in a seemingly never ending, page after page of offers for everything from free laptops to a cruise around the world to magazines and so on. The catch is you have to get past saying no to these or fill out a few with your personal information like name, address, phone number, email etc. and what seems to be fairly harmless information. Only, once you go past the myriad of ads asking you to fill in information will you get your “calculated” date with the grim reaper.

So I tried it at a site this person asked me about. I answered the few simple questions and then waited for my results, it had to be calculated, apparently they have a long connection to go through and the grim reaper’s WiFi was down. In the meantime, they graciously had me take review some of their fine offers and click “no” if not interested. I counted 97 (yes, I counted because I assumed it was going to be big) offers that I said “no” to and still was not given my much awaited date with death. I even filled in a few with some random misinformation thinking if they got me on one maybe they would cough up that date! Nothing. I literally gave up as it was appearing to be more and more of a perpetual scam. I guess I’ll need to keep my retirement plans in place for now.

Seriously though, what was really happening was a massive operation to get you to provide just the basics of personal information. Now the company that runs the site may only be a conduit and collecting ad dollars from the marketing agency who is the real culprit in this operation. Fill one out correctly with real information and you have just asked to receive a minimum of 100,000 emails with other exciting offers include. Hey, you asked!


That information may possibly be used by them directly for ID theft, Spamming, phishing, etc. They may sell it to others who will use it unscrupulously. Worse yet, you will be put on a sucker list. This is a list created about people who willingly provide information thinking they are going to win a prize. AKA in their business “a sucker”. ID thieves love suckers. They know they are the easiest of easy targets. The people who think they will really get something for nothing, the same people who ultimately will give the thieves the keys to their identity in much the same way. The thieves already know you are an optimists, and play that hand against you to the fullest.


So the next time you go to a site and think you are providing information that is harmless, looking for that humorous “date of your death” you may find out a new date, when your identity was stolen.

Friday, January 25, 2008

Prudential’s rock crumbles when it comes to securing personal information

Prudential Financial gets a spot on our office’s Identity Defense Wall of Shame this month. They had a temp worker collect personal information from a customer then the temp worker stole the customer’s identity to go on a three month, $70,000 spending spree!

According to the article about this event, Prudential takes customer information and security very seriously. We see that clearly from the end result of this encounter between a Prudential temp employee and a Prudential customer.

Stop and think about what happened here. A financial conglomerate worth $36 billion does not have the sense of how to secure personal information that it receives. Collecting customer information is the most volatile point in a transaction because it is up to the person who collects it as to how the information is treated. This is where Prudential’s security falls apart. The people collecting information should be trusted, longer term, well paid employees, who hopefully, will want to keep their job and have little or at least minimal incentive to steal. Instead they gave that crucial task to a 23 year old temp worker, who obviously did not care about his temp job and felt he needed to supplement his income.

I’m sure they spend millions on data security, and backup systems and passwords and encryption etc. As a financial institution they are required to have secure systems on all fronts. But no matter how big your walls are, or how many lines of defense you have, if you can’t complete step 1 and put the information into secure areas, it is useless. Picture your bank having the tellers leave all the money on the counters at night and still go lock the safe.

If Prudential has procedures in place, the management team is not reading the company manual. To be fair, this could easily happen with just about any employee and it is where a significant portion of all ID theft occurs. But when you assign tasks to someone who is not even an employee, then any incentive to do the right thing is minimized because there is no long term bond.

For the sake of all of their existing customers let’s hope they have a better system in place for securing their personal information.

Wednesday, August 8, 2007

Burden of Proof with Identity Theft

Victims of identity theft often feel victimized twice when identity theft happens to them.

We are all familiar with our legal system where the burden of proof is up to the prosecution for the people and you are innocent until proven guilty.

But with identity theft you are guilty or liable until you prove your innocence.

It doesn’t really seem to make sense but if you look at the logic, it does make sense. Although it puts the victim in a difficult, tedious, and time consuming position of defending themselves while all the while feeling violated because they are a victim.

Our financial system is set up and regulated by the federal government to provide easy and convenient transactions to keep the economy moving along without interruption. You can thank federal laws that limit your exposure to credit card fraud. They enacted those laws long ago to make people feel comfortable with using credit cards when they were first introduced. If people felt liable they would have been reluctant to use the system. Now our economy is completely tied to credit.

Those laws are visible in other areas as well. Take check cashing scams for example. The thieves take advantage of federal laws that require funds for checks to be made available quickly again, to keep the flow of commerce moving. People get taken due the expediency that banks provide funds for check presented, but then find out weeks later that the check was returned as a fraudulent device. You become ultimately liable for any fraudulent check that you present for funds.

In both cases of checks or credit cards you were given the benefit of the transaction in real time while it may be quite some time before the bank or you determine fraud has occurred. In the case of credit card fraud you need to prove that you did not actually make the fraudulent charges and with a check the bank relies on you to know who you are conducting business with.

The banking system really is set to benefit you, so when something goes awry you need to prove you were not involved. Most people never consider that when they conduct transactions. Who is to say that you where not involved in a fraudulent transaction and were not colluding with the perpetrator from the start.

If you become a victim of identity theft, you are really a victim in the eyes of others only after you prove it, and that will never feel good.

Monday, July 9, 2007

GAO Reports on Identity Theft, Sort of

Recently the US Government Accountability Office released its findings of a study on the net effect of data breaches, stolen data, and unaccounted for data and how much actual identity theft resulted from such occurrences. They undertook this task to help Congress decide if a federal law should be considered for a national breach notification requirement. Some states already have laws in effect to various degrees requiring notification of data lost so that consumers can take immediate actions to see if they’ve become a victim.

Sounds a bit odd, but breach notification would most likely just give you a heads up a bit sooner if you are a victim. Many times a data breach notification is the first time a victim looks at a bank or credit card statement, balances a checkbook for the first time in ten years, or obtains a credit report.

The GAO was asked to examine three distinct areas

(1) The incidence and circumstances of breaches of sensitive personal information

(2) The extent to which such breaches have resulted in identity theft

(3) The potential benefits, costs, and challenges associated with breach notification requirements.

The GAO used various sources for the research and came up with an earth shattering discovery; data thefts are rampant and occur frequently and are probably underreported due to lack of voluntary or mandatory disclosure.

They also determined they can’t directly link identity theft to many of the data thefts they reviewed because there is not clear and conclusive evidence that directly links those breaches with identity theft. Apparently the identity thieves are not disclosing the abundant sources of their windfall.

There you have it, if it is not conclusive then it must not have occurred, or at least they can’t say it occurred. It does not mean that it didn’t.

They even admitted that the lack of reporting on the part of victims also leads to skewed and invalid data that cannot be used to create a valid statistical picture.

So how do many interpret this : “GAO finds little identity theft results from data breaches”.

Apparently there are a lot of thieves going to a lot of trouble stealing personal data, then changing their minds finding religion and doing nothing with it after all.

But if that is the case, then where did all that personal stolen information come from that results in the billions of dollars in personal losses from the millions of actual victims each year? There was not a place to include them in this report.

Tuesday, June 12, 2007

Can Check Fraud Become Obsolete?

I am still amazed as I stand in any line at a store and the person in front of me pulls out a checkbook and writes a check, has to dig out a shopper ID card or some other form of ID, then hands it to the cashier. The cashier, with a puzzled look, takes all the documents and writes down information on the check. The cashier hands any ID back to the patron then sticks the paper check into the register 3 different ways.

At about the midway point through this production, I realize why I don’t write checks anymore and the person who invented the debit card should win the Nobel prize. What an incredibly antiquated and outdated system that is still being used by millions of people despite all the pitfalls.

Beyond the fiasco at the register, look at what else this dinosaur system burdens us with:

The number of checks stolen or forged each year is about 500 million checks and over $10 billion in lost revenue. Check fraud in itself is expected to grow at a rate of about 2.5% each year.

The average number of fraudulent checks written daily is about 1.4 million equaling $27.3 million worth of fraudulent checks written everyday.

According to the National Check Fraud Center, check fraud and counterfeiting are the largest and fastest growing problem that the United States financial system now faces. The estimated losses produced annually are over $10 billion and is expected to continue to rise.

Sure checks have their place in very few instances but these statistics coupled with the surge in identity theft, makes me wonder why the banks and other businesses still embrace them.

Why does the public still embrace them as well? The alternative for many will result in anxiety and fear. Debit cards with PIN numbers, all the talk about loosing information in data breaches, plus identity thieves looking over my shoulder at the checkout, all give the feeling of fear.

Reality paints a different picture, because these are the same people who write checks in regular ink, place them in the mailbox in the morning before work, put that red flag up, and never give a thought that they could be contributing to the above statistics by the end of the day.

What can you pro-actively do to help make check fraud obsolete?

1)Switch to an online billpay system
2)Use a debit or credit card for all merchant transactions
3)Have companies that you pay monthly like a utility debit your checking account


But …..if you must still use checks:

1)Don’t put them in your mailbox in the morning and raise that red flag
2)Lock up all checks and deposit slips in your home
3)Don’t carry a checkbook around in a purse or leave it in your car
4)Use a black ink Bic Rollerball or a gel pen to write out any checks, they can’t be washed off


If your are a victim of identity theft and check fraud is one of the causes:


Report stolen checks, and close unauthorized checking and savings accounts.
If you have had checks stolen or bank accounts set up fraudulently, report it to your bank or to one of the check verification companies listed below. (If a merchant rejects your check, ask for the name of the check verification company.)
When you do contact any major check verification companies listed below, request that they notify retailers using their databases not to accept your lost or stolen checks. Place immediate stop payments on any outstanding checks that you have not written.


• CrossCheck: 1-707-586-0551
• International Check Services: 1-800-526-5380
• National Check Fraud Service: 1-843-571-2143
• SCAN: 1-800-262-7771
• Equifax Check Systems: 1-800-437-5120
• TeleCheck: 1-800-710-9898 or 1-800-927-0188
• Chexsystems: 1-800-428-9623

Monday, May 14, 2007

The Hidden Costs of Identity Theft

Recently I read a news article written about a seminar recently given on identity theft by an attorney from the Federal Trade Commission. While I will save my opinion of his stated facts about the cost of identity theft for another post, he said 99 percent of identity theft victims pay nothing, and if there is any cost vendors pay for it! WHAT? Did he just fall out of the sky and crash land on planet earth, head first?

Just think about all the other costs, the unseen, uncalculated, or unaccounted costs, we could be referring to a value that in some instances would be unbelievable.

Let’s look at time alone. Depending on what statistical survey you refer to, the time spent per victim usually averages in the range of 500 hours to clear all the hurdles to restore their name and credit and obtain any restitution. When do they do this? Many during normal business hours. An employer of a victim, and many are employed, will lose thousands in lost time and productivity due to phone calls, paperwork, making copies, faxing information and police reports. Also time off for trips to court, an attorney’s office, or police department. Think of the time loss and cost to the self employed.

Emotional costs are also not included in his figure. I was at an event recently and spoke with many individuals about identity theft, and I was truly amazed at how many had been victims or knew a victim directly. One woman had the most emotionally charged story about a close relative who stole her identity. She was forced to press police charges against that close relative, otherwise she could not get the $6,000 in theft cleared from her name and she did not have the funds to cover it either. She was extremely distraught because she knew the negative impact it would have on her if she did not press charges, but she also knew the lifelong damage the close relative would endure for this one event.

Others feel violated, hurt, constantly suspicious, untrusting and the list goes on.

So what impact do those feelings that now have on the economy? Many of these people will stop using credit or debit cards, will not buy online, will not do many things that will impact the economy much like a recession.

And for the cost to the vendors that do actually pay for or cover losses, where does he think that money will ultimately come from? We all bear the burden of paying for the costs of identity theft. Much in the same manner we share the costs for insurance when a major hurricane hits even a majority were never impacted by it.

So in the grand scheme of identity theft the impact of the actual dollar amount may only be a small part of the total cost, but everyone who gets hit with identity theft pays a price.

Tuesday, April 3, 2007

The costly disparity of debit and credit cards

I can't help but wonder how many of the 45.7 million cards stolen from TJX were split between debit and credit cards. The number was lumped together as a whole as if they were all the same. To TJX there was no difference, they said sorry for the inconvenience, and moved on. Not so fast, because to the victims there was potentially a huge difference.

All this starts with the cards looking identical to consumers. This leads many to the conclusion that because they look alike they are alike. The biggest difference to them is one gets billed and the other comes from their checking account. What else could there be?

Under the Fair Credit Reporting act you cannot be held responsible for unauthorized charges to your credit card. The burden you face is to prove you did not make the charges, file a police report etc. Your liability is generally limited to $50 per card.

The people who had their debit cards compromised fall into a whole different category of liability. Within the first 2 days you liability is capped at $50. Up to 60 days it is capped at $500, after the 60 day window you are wide open for unlimited liability or the balance of your account. Those clocks start ticking the day you notify your bank of the theft, or the date of your first paper or online statement where the unauthorized charges appear. You become "notified" even if you don't open up the envelope or bother looking!

Remember , the "Zero Liability" card you have is not a mandate to the bank from the government, only a courtesy from your bank. Even then, it is at their discretion who is truly liable.

I'm sure many do not bother to review their charges or statements because they feel "protected" and have "zero liability". I would like to hear from some victims of the TJX fiasco to see how well they made out with these policies. I'm sure many looked at those statements for the first time in a long time when they heard about the breach and were quite surprised.

The easiest solution, review your statements regularly. They are your best defense to a costly theft!