Showing posts with label scams. Show all posts
Showing posts with label scams. Show all posts

Thursday, January 31, 2008

Federal government rebate scams continue to grow and flourish

Two days ago I wrote about the issue of all the talk of the federal rebates and how fraudsters, scammers and ID thieves would come out of the woodwork to capitalize on it from unsuspecting and eager individuals. I had listed the common tactics that thieves will be using as reminders for what to be cautious about but it is already going well beyond those and getting people engaged from every possible angle.

Here is a list of the latest scams brought to the attention of the IRS:

Rebate Phone Call

At least one scheme using the word "rebate" as part of the lure has been identified. In that scam, consumers receive a phone call from someone identifying himself as an IRS employee. The caller tells the targeted victim that he is eligible for a sizable rebate for filing his taxes early. The caller then states that he needs the target´s bank account information for the direct deposit of the rebate. If the target refuses, he is told that he cannot receive the rebate.

This phone call is a scam. No legislation has yet been enacted that would allow the IRS to provide advance payments to taxpayers or that determines the details of those payments. Moreover, the IRS does not force taxpayers to use direct deposit. Those who opt for direct deposit do so by completing the appropriate section of their tax return, with bank routing and account information, when they file; the IRS does not gather the information by telephone.



Refund e-Mail

The IRS has seen several variations of a refund-related bogus e-mail which falsely claims to come from the IRS, tells the recipient that he or she is eligible for a tax refund for a specific amount, and instructs the recipient to click on a link in the e-mail to access a refund claim form. The form asks the recipient to enter personal information that the scamsters can then use to access the e-mail recipient´s bank or credit card account.

In a new wrinkle, the current version of the refund scam includes two paragraphs that appear to be directed toward tax-exempt organizations that distribute funds to other organizations or individuals. The e-mail contains the name and supposed signature of the Director of the IRS´s Exempt Organizations business division.

This e-mail is a phony. The IRS does not send unsolicited e-mail about tax account matters to individual, business, tax-exempt or other taxpayers.

Filing a tax return is the only way to apply for a tax refund; there is no separate application form. Taxpayers who wish to find out if they are due a refund from their last annual tax return filing may use the "Where´s My Refund?" interactive application on this Web site, IRS.gov. The only official IRS Web site is located here at www.irs.gov.



Audit e-Mail

Another new scam brought to IRS attention contains features not seen before by the IRS. Using a technique calculated to get almost anyone´s attention, the e-mail notifies the recipient that his or her tax return will be audited. This is the first scam of which the IRS is aware that uses this to get the victim to respond.

Unusual for a scam e-mail, it may contain a salutation in the body addressed to the specific recipient by name. Most scam e-mails seen by the IRS are sent using the same technique used by spammers, in which hundreds of thousands of messages are sent to potential victims based on Internet address. Because of the volume, the typical scam e-mail is not personalized.

This e-mail instructs the recipient to click on links to complete forms with personal and account information, which the scammers will use to commit identity theft.

This e-mail is a phony. The IRS does not send unsolicited, tax-account related e-mails to taxpayers.




Changes to Tax Law e-Mail

This bogus e-mail is addressed to businesses, accountants and "Treasury" managers. It instructs them to download information on tax law changes by clicking on a series of links to publications on businesses, estate taxes, excise taxes, exempt organizations and IRAs and other retirement plans. The IRS believes that clicking on a link downloads malware onto the recipient´s computer. Malware is malicious code that can take over the victim´s computer hard drive, giving someone remote access to the computer, or it could look for passwords and other information and send them to the scamster. There are other types of malware, as well.

The urls contained in the link are not legitimate IRS Web addresses. All IRS.gov Web page addresses begin with http://www.irs.gov/.




Paper Check Phone Call

In a current telephone scam, a caller claims to be an IRS employee who is calling because the IRS sent a check to the individual being called. The caller states that because the check has not been cashed, the IRS wants to verify the individual´s bank account number. The caller may have a foreign accent.

In reality, the IRS leaves it entirely up to the individual to choose to cash or not cash a paper check. The IRS has no business need to know, and does not ask for, bank account or similar information, except when taxpayers indicate on their tax return that they are opting for the direct electronic deposit of their refund. In that case, however, it is the individual´s responsibility to provide the IRS with the correct bank routing and account numbers on the tax return; the IRS does not contact taxpayers to verify the information.




What to Do

Anyone wishing to access the IRS Web site should initiate contact by typing the IRS.gov address into their Internet address window, rather than clicking on a link in an e-mail or opening an attachment.

Those who have received a questionable e-mail claiming to come from the IRS may forward it to a mailbox the IRS has established to receive such e-mails, phishing@irs.gov, using instructions contained in an article titled "How to Protect Yourself from Suspicious E-Mails or Phishing Schemes." Following the instructions will help the IRS track the suspicious e-mail to its origins and shut down the scam. Find the article by visiting IRS.gov and entering the words "suspicious e-mails" into the search box in the upper right corner of the front page.

Those who have received a questionable telephone call that claims to come from the IRS may also use the phishing@irs.gov mailbox to notify the IRS of the scam.

Identity Theft “Prevention” Defined Accurately

Everybody that talks about prevention uses the word in a different way. It is about perspective. Here is an example:

Think about how you would feel if this scenario happened: Your bank called and said “someone infiltrated your savings account and they have been making withdrawals regularly for the last three months. Your account has been drained of $25,000 but due to our diligence we stopped it and you still have $15,000 left. We have effectively prevented the thief from draining your account. We thought you’d like to know we mitigated your loss.”

Was there any prevention here? Absolutely! Are you going to be happy about it? I doubt it. People are paying big money for a false sense of the word “prevention”. They are really paying for and getting “mitigation”.

Now let’s compare the words “prevention” and “mitigation”:

pre·ven·tion [ pri vénshən ] (plural pre·ven·tions)

action that stops something from happening: an action or actions taken to stop somebody from doing something or to stop something from happening

  • the prevention of crime

mit·i·gate [ mítti gàyt ] (past and past participle mit·i·gat·ed, present participle mit·i·gat·ing, 3rd person present singular mit·i·gates)

  • to mitigate a loss

lessen something: to make something less harsh, severe

When put in the context of identity theft: Everyone uses the word prevention when they are referring to credit freeze, fraud monitoring and credit reports, and credit monitoring, data scouring etc.

Now let’s look at it from the context of the consumer: Prevention would be keeping my information completely secure and preventing it from being stolen in the first place.

Real prevention is thwarting the theft of your personal information. Securing your name so nobody uses it for anything. That is what ID theft “prevention” truly is.

If I rely on a credit report, a fraud alert or a credit freeze to stop something from happening, that means that SOMEONE ALREADY HAS OBTAINED MY PERSONAL INFORMATION ! A CRIME HAS ALREADY OCURRED! Now that does not sound like identity theft prevention at all, it most definitely is mitigation. Sure it may have plugged a small hole but in the grand scheme of the information that thief still has, it is like putting a bandage on a bullet wound.

So how can credit freeze, fraud monitoring and credit reports, and credit monitoring qualify as prevention? Well, they stopped something from happening, and that has some limited value, but now who has this information and where are they going with it next? Keep in mind if they have gone to the effort to steal your info, they are going to use it. A car thief does not steal a car and drive around in it until it runs out of gas. They are going to use the stolen device until it no longer meets their needs. The same with your identity, it could be used next for medical services, prescriptions, getting arrested, forging a check, and so on.

An ID theft recovery company stated under the guise of “prevention” that they look for changes in your existing accounts and they look for new accounts and transactions in your name. By doing this, they can detect someone's attempt to steal your identity before it gets too far and before any damage has been done. Sorry people, but if any of this is detected, the damage has been done. SOMEONE HAS ALREADY STOLEN YOUR IDENTITY! THEY HAVE YOUR PERSONAL INFORMAION AND ARE PUTTING IT TO USE! This should not be sugar coated as identity theft “prevention”. The prevention ship has sailed, it is now time to mitigate.

You will still have to wonder when or where they may use it next. And you still may have work to do, to get everything closed down, changed, modified etc. and you may never be completely sure you’ve plugged the gaps because how do you know your personal information has not been passed around or sold on the black market?

So how much is “mitigation” really worth? It is up to you, but most will pay much more for “prevention”.

True identity theft “PREVENTION” is about stopping the crime from occurring, and that starts with preventing and keeping your information out of the hands of the thieves to start with. True prevention is up to you! True prevention starts with you doing the right things with your personal information.

Don’t confuse paying for mitigation services and expect prevention. You may not end up being happy with the results.

Monday, January 28, 2008

Attention grabbing survey sites could set the stage for ID theft

There are a number of sites that quiz you about yourself and then tell you something about yourself in return. Our site does that as well. We ask you information about your personal daily habits and use proprietary algorithms backed by research to gage your risk for ID theft with an output that is in an easy to understand ID Risk Level. No ads, no personal information requested, not even email.

Someone emailed me recently asking about other sites that have quizzes and pointed out a few in particular and asked me how safe they are even if just for fun.

Some sites, by piquing your interest in certain, even silly subjects, are looking for something. There are a number of sites that purport being able to tell you when you are going to die! Wonderful, that information will certainly come in handy. It makes my retirement investment planning so much easier.

Well, you’re not gullible, but you went there for fun, as a joke, just to see, etc. All in good fun as long as you are not giving them any personal information.

So what could a site like this really be after? Mainly ad revenue. By getting thousands of people to go through the site and take the “date of your death survey”, they land you in a seemingly never ending, page after page of offers for everything from free laptops to a cruise around the world to magazines and so on. The catch is you have to get past saying no to these or fill out a few with your personal information like name, address, phone number, email etc. and what seems to be fairly harmless information. Only, once you go past the myriad of ads asking you to fill in information will you get your “calculated” date with the grim reaper.

So I tried it at a site this person asked me about. I answered the few simple questions and then waited for my results, it had to be calculated, apparently they have a long connection to go through and the grim reaper’s WiFi was down. In the meantime, they graciously had me take review some of their fine offers and click “no” if not interested. I counted 97 (yes, I counted because I assumed it was going to be big) offers that I said “no” to and still was not given my much awaited date with death. I even filled in a few with some random misinformation thinking if they got me on one maybe they would cough up that date! Nothing. I literally gave up as it was appearing to be more and more of a perpetual scam. I guess I’ll need to keep my retirement plans in place for now.

Seriously though, what was really happening was a massive operation to get you to provide just the basics of personal information. Now the company that runs the site may only be a conduit and collecting ad dollars from the marketing agency who is the real culprit in this operation. Fill one out correctly with real information and you have just asked to receive a minimum of 100,000 emails with other exciting offers include. Hey, you asked!


That information may possibly be used by them directly for ID theft, Spamming, phishing, etc. They may sell it to others who will use it unscrupulously. Worse yet, you will be put on a sucker list. This is a list created about people who willingly provide information thinking they are going to win a prize. AKA in their business “a sucker”. ID thieves love suckers. They know they are the easiest of easy targets. The people who think they will really get something for nothing, the same people who ultimately will give the thieves the keys to their identity in much the same way. The thieves already know you are an optimists, and play that hand against you to the fullest.


So the next time you go to a site and think you are providing information that is harmless, looking for that humorous “date of your death” you may find out a new date, when your identity was stolen.

Monday, June 18, 2007

Think before filling out that Free Prize or Sweepstakes Card

When you are walking through the mall, or at a fair, or even online, chances are you’ll get asked to fill out a form for a chance to win some wonderful prize or receive something for free.

And why not, it costs you nothing and someone’s got to win that new laptop, or the car, or the trip to the moon. A pen in hand and 60 seconds later you feel like you may be getting a call or letter for some fantastic prize. And you were sure to put down your phone number, so when you win, they’ll call right away.

We all like to be optimistic. We all want to think we have got a shot at the big one! I don’t know what the big one is, but it’s big!

Now let’s take a walk to the other side of the isle called reality. In reality there is no real prize, or the person who won it lives in the Arctic circle and the company cannot deliver it. If there is a prize, the barriers to get it may be out of reach. You get the picture, they are trying to get your personal information for a much bigger catch.

But what you may ultimately end up with, is your identity stolen, and you’ll become the victim of identity theft.

When you filled out that form for a prize, you labeled yourself as an optimist. The company who requested the information, may be legitimate, and there may be the prize,, and but may sell that list of names collected to a marketing company. You may end up on a “sucker list”.

Identity thief rings buy “sucker lists” from direct marketing companies. You’ll then be a target for a phone scam or “vishing”. You’ve already given them a good reason to call because you are optimistic or in their terms a “sucker”. Now your wide open, and they will throw every trick in the book at you. This is what they do, this is what they are good at.

The odds of getting your identity stolen are much greater than winning anything, so don’t bother trying to win by giving up information. You will have taken a significant step in defending your identity.

Monday, May 7, 2007

What’s missing from your mailbox today?

A habit that we are all used to doing since we had our first apartment, or first went away to college, is get the mail before we walk in the door. Every day we expect to get something when we open that box. Mail is a way of life in our society. It is woven into the thread of our daily lives.

Will physical mail ever go away? No, but it will evolve into a different service than what we see today. Email, estatements, online billpay, are all eroding at a service that has been in existence for ages. But what online taketh away, online giveth back in another form. Ecommerce has opened up the marketplace for any item you want with a click of a mouse.

So who still uses this age old system of antiquated origins? All of us do! There must be something about still receiving items in that box that keeps us attached to this extremely vulnerable system. Ever think about how vulnerable it is? Most don’t.

According to the US Postal Service they arrested 6000 people last year for mail theft! If it doesn’t sound like many, just think of how many they have not arrested. Then add in the ones who will start doing it. The number of mail thieves is growing as identity theft continues to grow year after year.

There is also the occurrence of “volume thefts”, that is prevalent in a number of states. The postal service does not specify what a “volume theft” is, but I would guess it is in the range of a bulk airline cargo hold shipment (ever look out the airplane window and see bulk bags of US mail being loaded with your luggage) to an entire truckload. I doubt they are looking for Ebay packages either. The thefts are occurring everywhere that mail is readily available, from collection boxes, apartment mailbox panels, postal trucks, your curbside box etc.

So what is missing from your mailbox today? A quick off the cuff answer is nothing, because you picked up your mail and it was there….so you thought. But were you there when it was delivered? Did it sit all day waiting for you to get it after work? And are those 2 credit card offers the only ones you received today or did the mailperson leave 4? You just don’t know what is missing from your mail because you never see it to start with.

You need to defend yourself from mail theft by eliminating the use of mail for all critical and essential information. Only use the mail for catalogs and advertisements and coupons, the thieves can have that.

Saturday, April 14, 2007

National identity theft awareness week

While identity theft is a year round event, this coming week, could just qualify for National Identity Theft Awareness Week. The week could get this designation because it is becoming one of the more prevalent ones for identity theft due strictly to the time of year. No, there is no such week, but if there were any good time to raise awareness, this week is it.

We wouldn’t be human if we did not have some worry this time of year regarding filing our income taxes.

The forms, the documents, the receipts, the calculator, the room you barricade yourself in, and vow not to emerge until the deed is done. Those are all recurring items that we’ve been through before and will go through again, but we still feel anxiety regardless.

While getting your taxes done is paramount for this time of year, you need to be on alert for more than just an audit. The thieves and con artists go into overdrive this time of year. They feed on your sense of commitment and urgency to get that return done and in on time.

So what should you be concerned about? Here are my top 10 awareness items to think about this week for protecting yourself from an identity thief:

1) Shred all those printed copies that you found mistakes on, and had to reprint.

2) Keep your hard copy of your tax returns locked up.

3) If you use a tax preparer or a CPA, be sure they are securing your information, after you leave the office. Look around to see and verify that they use a shredder. Ask them how they secure your information when they are done for the night.

4) Give some consideration to where you are copying a tax return. It has recently come to light that copiers retain digital information of every copy they make, and some are not being properly erased.

5) If you used software at home on your own PC, save your tax returns to a disc and delete it from your hard drive. Keep in mind if you loose a laptop do you want your tax return available to anyone who acquires it?

6) Ignore and delete emails from the IRS. They don’t have your email address, do you remember providing it to them?

7) Only eFile through the links on the IRS website http://www.irs.gov/ . Recently thieves have been setting up fake eFile sites and collecting your information.

8) Don’t provide any information to any who calls claiming to be from the IRS.

9) Don’t leave your return in your mailbox. Take it to the post office directly.

10) Use a reputable tax preparer. Remember that you are handing them the keys to your identity, if you don’t know them, they may just drive off with it, or sell the information to a third party.

Tuesday, April 10, 2007

The IRS does not use email?

Around this time every year millions of emails arrive proclaiming the IRS needs you to verify your information, needs more information, has money to give back to you, and the list goes on and on. To conform, all you need to do is cough up some very valuable information.

They all invoke some type of high emotion, either fear or excitement. Both can cloud clear judgment, and reasoning. And it works, all too well.

Lets look at this from a logical and simple point of view. What is the main goal of the IRS? To collect tax revenue. What else do they do? Audit you to try and collect more tax revenue. Have you ever heard of them doing anything else?

Those two functions just about wrap it up.

So if we look at what they don’t do here is my simple list of 5 rules, and read rule #1 at least 50 times:

Rule 1)The IRS doesn’t ask for an email address on your 1040
Rule 2)The IRS doesn’t ask for missing information via email (See rule #1)
Rule 3)The IRS doesn’t ask for more information via email (See rule #1)
Rule 4)The IRS certainly doesn’t offer additional refund money via email (See rule #1)
Rule 5)The IRS absolutely doesn’t locate bonus or extra money just for you


Now go back and read rule #1 above again. If you can remember that, you can be assured that any message you get proclaiming anything from the IRS is a fake and a phishing scam.

So when you see the words IRS in an email for any reason instantly think of my IRS #1 rule and then hit the DELETE key.