By Pam Greenberg
State Legislatures 12/15/08 4:00 AM PT
A Countrywide mortgage employee working Sunday nights copied customer records from an office computer, then sold the personal information of an estimated 2 million mortgage applicants.
A group of hackers "wardriving" -- searching for unsecured wireless networks in parking lots and outside retail stores such as TJ Maxx, Marshalls, Boston Market and others -- managed to capture credit card numbers, passwords and account information for more than 40 million customers.
A laptop stolen from a National Institutes of Health researcher contained the information of about 2,500 participants in a medical research study, including names, birth dates, health data and diagnoses.
Unreported Information
Before 2004, consumers rarely heard about these kinds of thefts. But a landmark California law, which went largely unnoticed outside the state when it passed in 2002, set off a chain of events felt nationwide. California's Security Breach Notice Law requires businesses or state agencies that have a security breach to notify state residents if their personal information is lost or stolen.
Since the law took effect in mid-2003, hundreds of data breaches have been reported in the press, and more than 245 million records containing personal information have been exposed. Thousands of people have received letters warning them to monitor their records, and businesses and organizations have beefed up data security. One study put the cost of data breaches to the companies involved at $197 per record breached in 2007.
National Reach
In February 2005, ChoicePoint, a company that collects and compiles information about millions of consumers, discovered that it had inadvertently sold the personal information of almost 145,000 people to a con artist who claimed to be an executive with a Los Angeles company. ChoicePoint initially notified only California residents, who were covered by the state's notification law, even though the stolen data included information about residents in other states. Only after widespread media coverage, and after 38 state attorneys general had called for notification to victims in other states and territories, did the company notify everyone whose personal information had been compromised.
After ChoicePoint's security failure became widely known, lawmakers in other states moved quickly to make sure their citizens had the same kind of notice as California residents.
Twenty-two states enacted security breach laws in 2005, and others quickly followed in subsequent years.
In the five years since the California law has been in force, 43 states, the District of Columbia, Puerto Rico and the Virgin Islands have passed similar laws. But the laws have their critics, and researchers are beginning to take a careful look at their effectiveness.
Laws Create Change
"The law has worked surprisingly well," says State Sen. Joe Simitian, a sponsor of the California bill. "Millions of American consumers have known when their personal information had been disclosed and they were at risk."
With notice, a consumer can protect against theft by closing accounts, freezing credit reports -- effectively blocking the issuance of new credit without permission -- or issuing a fraud alert requiring creditors to check before extending any new credit.
The law also creates a powerful incentive on the part of government and business to improve data security. "You have a responsibility to handle this data with care, and if you come up short," Simitian says, "you'll suffer the damage to your reputation."
Companies have increased security practices in response to data breach laws, according to Chris Hoofhagle, director of Information Privacy Programs at the Berkeley Center for Law & Technology, who supervised a survey of chief security officers by the Samuelson Clinic. "Businesses are changing practices and policies, getting security on the accounting books, and integrating security into legal and marketing teams," he says.
Joanne McNabb, chief of California's Office of Privacy Protection, also sees businesses changing their practices. "One of the striking lessons we've learned is how much sensitive information is not safe on a server but is traveling on a laptop or flash drive. It's now becoming a common practice to encrypt these and to have policies that restrict or limit what kind of information can be carried on these devices."
McNabb points to another change that's happening in government and the private sector. "There's a real scouring of systems to remove Social Security numbers. Organizations are saying, why do we still collect this or why are we keeping this information so long?"
A 2008 review of breach incidents compiled by the Privacy Rights Clearinghouse found that about 75 percent of the publicly known breaches involved Social Security numbers. A report by McNabb's office highlights how, after one university's breach had exposed Social Security numbers and other information from 15 years prior, it changed its policies to shorten the time it retained information on certain applicants. In another example, a blood bank stopped collecting Social Security numbers altogether.
Critics Point to Limitations
Some researchers, however, are questioning the benefits of the laws. A Progress and Freedom Foundation analysis of security breach laws questions whether the costs of notification outweigh the benefits. The report's authors, Thomas M. Lenard and Paul H. Rubin, maintain that businesses already have strong incentives to spend money on data security, because many of the costs related to identity theft and fraud are borne directly by business. They also argue that the benefits of the notice to consumers are negligible since only a very small percentage of those who receive breach notices actually become victims of a fraud.
Fred Cate, a law professor and director of the Center for Applied Cybersecurity Research at Indiana University, agrees. "Research shows pretty clearly that there's very little identity theft that follows breached accounts. Security threats are all around us, but security breaches are like a little sideshow. I don't mean to suggest that they aren't a concern, but if you asked security experts to name the top 15 security risks, I doubt breaches would be on anyone's list."
Also, a little less than half of consumers fail to take action after being notified that their information has been lost or stolen. A 2005 survey of identity theft victims by the Federal Trade Commission found that 44 percent did nothing after receiving a notice about a breach of their information.
"Notices have become a substitute for real action," Cate says.
But Simitian considers notices valuable, giving consumers the opportunity to take steps if they choose. "What you don't know can hurt you. You and I may get the same notice letter, and you may close all your accounts and do everything possible to protect yourself. Someone else may do nothing. I'll take a middle position and monitor my accounts more carefully."
Simitian also thinks notices can be improved by providing standard information about what data were breached.
McNabb agrees. "If the breach involves use of credit card numbers, you know the fraud is likely to happen fairly soon, and you can close your account. But with a Social Security number, there are numerous types of fraud that can occur, it can happen anytime, and you can't change your Social Security number."
Effect on Identity Theft Unclear
According to the most recent figures from the Federal Trade Commission, 8.3 million Americans were victims of identity theft in 2005, and identity theft is the No. 1 source of consumer fraud complaints the agency receives. And given the hardship that identity theft can create for individuals, it's not surprising that some have looked to security breach laws as a solution.
But data breaches are not the only ways in which identity theft occurs. A lost or stolen wallet or thefts from mail or garbage also can lead to identity theft. In addition, information about such thefts is often based on anecdotal accounts or surveys of victims, who sometimes have no idea how their information was compromised.
"It's a fundamental problem that security breach laws have been hung on the hook of identity theft," says Hoofhagle. "Investigating the source of identity theft is extremely tricky."
A team of researchers at the Heinz School of Public Policy and Management at Carnegie Mellon has attempted to do so, however. The researchers compared identity theft rates, over time, in states with and without security breach laws, and concluded that data breach disclosure laws have "no statistically significant effect" in reducing identity theft.
The study also noted that, if a small percentage of identity thefts is attributable to data breaches, the effectiveness of data breach laws on these thefts is limited. The researchers acknowledged, however, a need for better data and further study. They also say security breach laws may have other benefits, such as reducing a victim's average losses and improving security practices.
Lessons Learned
What have we learned after five years?
"We've learned that the law works well, but that there are some improvements that would make a good law even better," says Simitian.
In addition to requiring a core set of information in notice letters, Simitian favors requiring businesses to notify a central state entity. New York, for example, requires notification of breaches to the attorney general's office.
"It gives law enforcement the information they need to assess the particular kinds of data lost or the means by which they are being breached."
State lawmakers also need this information, he says. "If we're to legislate effectively, we need to know the nature and extent of the problem."
Cate is skeptical that including a standard set of information in letters will make a difference, but he supports the idea of a central reporting requirement. A central repository would have all the benefits of notice, he says, "without scaring people about dangers when no real harm is there or if there's little they can do about it."
With central reporting, businesses could start making more rational investments in security, says Hoofhagle. "I think we'll find these laws sparked investment and innovation in security -- maybe even over-investment -- but we were in a posture of under-investment before."
As states continue to work on improving data breach laws, Congress also has been considering legislation. Some bills have made it out of committee, but none have had a floor vote.
Federal legislation is a mixed blessing," says Simitian. "If we end up with a weaker set of provisions that also preempts the more rigorous state laws, that's not going to benefit consumers."
Cate thinks Congress will act, and he's surprised it hasn't already. "It's probably because they found it a lot more complicated than they thought."
The way data are collected, used and transferred across states, it's likely many companies will opt to comply with the most stringent provisions in state laws, Cate says.
"One way or another, we'll have national preemption -- either from the state that adopts the toughest law or from Congress. But it's a classic case of states leading the way."
Tuesday, December 16, 2008
Monday, December 15, 2008
State and Local Governments Tackle Security Projects
By Ellen Messmer , Network World , 12/15/2008
State and local governments around the country are worrying as much as any business enterprise about protecting the sensitive data they hold, based on a look at security projects in places such as Arizona, Indiana and Florida.
Arizona's government last year decided to create state-level positions for both CISO and chief privacy officer (CPO), after the Federal Trade Commission ranked Arizona first among all states in identity theft, though the exact reason wasn't cited by the FTC. After the state passed legislation for more oversight, David VanderNaalt, named CISO, began working with Mary Beth Joublanc, the state's CPO, in the newly created Statewide Information Security & Privacy Office at the Statewide Information Technology Agency.
"This is an oversight agency," says VanderNaalt, formerly CISO for the City of New York for eight years and a witness to the Sept. 11 attacks.
VanderNaalt and Joublanc report directly to Arizona's governor, among others, about whether dozens of state agencies are complying with state legislation requiring agencies to report security incidents.
"In my role I see we have 100 different business models," VanderNaalt says about Arizona's dozens of agencies and their departmental activities. While many agencies collect data about security incidents, there needs to be a centralized way to automate collection from technical sources in addition to manual reports, he says.
Just last month, for example, to comply with state law, Arizona's Department of Economic Security had to notify the families of about 40,000 children that their personal data may have been compromised following the theft of hard drives from a facility where they were stored.
VanderNaalt says one approach he's testing to report and track incidents statewide is a tool from Agiliance called RiskVision at the agencies, though he adds when it comes to identity theft, the private sector is likely to be at least as big a source of the problem.
But the purpose of the statewide office on security and privacy is to tackle wider concerns, too, including major online attacks, in order to respond with as complete a picture as Arizona's government can muster.
To do that, VanderNaalt knows he needs the trust from Arizona's employees.
"We're trying to position ourselves that reporting is a good thing, and you will get help," VanderNaalt says. The state oversight agency will also be conducting assessments of agency practices and technologies with an eye toward identifying statewide approaches to safeguarding security and privacy of data.
Securing Indiana
Indiana has already adopted a centralized approach in IT and security and it appears to be working well, according to Paul Baltzell, director of distributed services. His department is responsible for desktops used across the agencies.
Four years ago, Gov. Mitch Daniels, annoyed that even the state's e-mail systems weren't fully connected (although its state WAN was), made the decision that there should be a state-level CIO office defining infrastructure requirements, including security policies.
Indiana's IT centralization effort has had some pushback Baltzell acknowledges, noting that it resulted in about a 40% staff reduction in some IT function areas.
But by centralizing, the state government now benefits from volume discounts in IT acquisitions, including in security procurements, Baltzell says.
As part of a recent state-level acquisition of McAfee antivirus, intrusion-prevention and other security gear, Indiana also licensed McAfee's Endpoint Encryption software (based on McAfee's acquisition of SafeBoot) which it's deploying on about 10,000 laptops and other mobile devices.
"One bad security breach and you've lost all credibility," Baltzell says, adding that trying to achieve this wide a rollout of desktop encryption would have been much more difficult without a centralized statewide mandate.
Baltzell also says he's enjoying success with Intel's vPro, now used inside 6,000 of Indiana's state-agency desktops, for remote management of them "even if it's blue-screened," Baltzell says.
"We have offices all over the state, and my techs have to get in the car if they can't fix something remotely," Baltzell says. Intel's vPro has greatly simplified remote management for Indiana employees and Baltzell hopes security vendors will work with Intel to explore some of the potential it offers in malware defense.
Security at the local level
Local city governments also take on ambitious security projects and find it can be a substantial effort to put in place centrally mandated IT governance policies just for city agencies.
"A key one we had is software installation and computer-use policy spelling out the rules of engagement," says Nelson Martinez, systems support manager for the City of Miami Beach municipal government in Florida, which has about 2,000 employees using computers.
Establishing a citywide computer-use policy entailed meeting individually not only with city agencies themselves but also with five unions and their lawyers, including the police and fire unions, to discuss the policy and how violations would be handled."It all went faster than I thought it would," says Martinez says, noting each group voiced issues about how reprimands or punishments might be applied. In the end, it was made clear that while the IT department might be providing information about blatant violations of IT policy — for instance, "no chat, no instant messaging, no adding in unofficial software except with permission" — it's up to high-level city management to handle the repercussions, he says.
For endpoint enforcement on almost 2,000 employee computers, the city is using eEye Digital's Blink, which prevents malware from executing as well as blocks unauthorized applications. "I'm trying to keep them out of trouble," Martinez says. "People are always trying to test the boundaries."
Martinez says one of the most ambitious projects the city is undertaking now is single-sign on authentication using fingerprint biometrics for authentication in order to attain a higher security level than simple passwords.
The project makes use of Imprivata's single sign-on appliance, Microsoft Active Directory and UPEK scanners, and is starting with 150 city personnel, including the city's directors and those in law enforcement and emergency response.
Biometrics is important "because it all comes back to security," Martinez says. "You can use complex passwords, but you will have people writing sticky notes."
State and local governments around the country are worrying as much as any business enterprise about protecting the sensitive data they hold, based on a look at security projects in places such as Arizona, Indiana and Florida.
Arizona's government last year decided to create state-level positions for both CISO and chief privacy officer (CPO), after the Federal Trade Commission ranked Arizona first among all states in identity theft, though the exact reason wasn't cited by the FTC. After the state passed legislation for more oversight, David VanderNaalt, named CISO, began working with Mary Beth Joublanc, the state's CPO, in the newly created Statewide Information Security & Privacy Office at the Statewide Information Technology Agency.
"This is an oversight agency," says VanderNaalt, formerly CISO for the City of New York for eight years and a witness to the Sept. 11 attacks.
VanderNaalt and Joublanc report directly to Arizona's governor, among others, about whether dozens of state agencies are complying with state legislation requiring agencies to report security incidents.
"In my role I see we have 100 different business models," VanderNaalt says about Arizona's dozens of agencies and their departmental activities. While many agencies collect data about security incidents, there needs to be a centralized way to automate collection from technical sources in addition to manual reports, he says.
Just last month, for example, to comply with state law, Arizona's Department of Economic Security had to notify the families of about 40,000 children that their personal data may have been compromised following the theft of hard drives from a facility where they were stored.
VanderNaalt says one approach he's testing to report and track incidents statewide is a tool from Agiliance called RiskVision at the agencies, though he adds when it comes to identity theft, the private sector is likely to be at least as big a source of the problem.
But the purpose of the statewide office on security and privacy is to tackle wider concerns, too, including major online attacks, in order to respond with as complete a picture as Arizona's government can muster.
To do that, VanderNaalt knows he needs the trust from Arizona's employees.
"We're trying to position ourselves that reporting is a good thing, and you will get help," VanderNaalt says. The state oversight agency will also be conducting assessments of agency practices and technologies with an eye toward identifying statewide approaches to safeguarding security and privacy of data.
Securing Indiana
Indiana has already adopted a centralized approach in IT and security and it appears to be working well, according to Paul Baltzell, director of distributed services. His department is responsible for desktops used across the agencies.
Four years ago, Gov. Mitch Daniels, annoyed that even the state's e-mail systems weren't fully connected (although its state WAN was), made the decision that there should be a state-level CIO office defining infrastructure requirements, including security policies.
Indiana's IT centralization effort has had some pushback Baltzell acknowledges, noting that it resulted in about a 40% staff reduction in some IT function areas.
But by centralizing, the state government now benefits from volume discounts in IT acquisitions, including in security procurements, Baltzell says.
As part of a recent state-level acquisition of McAfee antivirus, intrusion-prevention and other security gear, Indiana also licensed McAfee's Endpoint Encryption software (based on McAfee's acquisition of SafeBoot) which it's deploying on about 10,000 laptops and other mobile devices.
"One bad security breach and you've lost all credibility," Baltzell says, adding that trying to achieve this wide a rollout of desktop encryption would have been much more difficult without a centralized statewide mandate.
Baltzell also says he's enjoying success with Intel's vPro, now used inside 6,000 of Indiana's state-agency desktops, for remote management of them "even if it's blue-screened," Baltzell says.
"We have offices all over the state, and my techs have to get in the car if they can't fix something remotely," Baltzell says. Intel's vPro has greatly simplified remote management for Indiana employees and Baltzell hopes security vendors will work with Intel to explore some of the potential it offers in malware defense.
Security at the local level
Local city governments also take on ambitious security projects and find it can be a substantial effort to put in place centrally mandated IT governance policies just for city agencies.
"A key one we had is software installation and computer-use policy spelling out the rules of engagement," says Nelson Martinez, systems support manager for the City of Miami Beach municipal government in Florida, which has about 2,000 employees using computers.
Establishing a citywide computer-use policy entailed meeting individually not only with city agencies themselves but also with five unions and their lawyers, including the police and fire unions, to discuss the policy and how violations would be handled."It all went faster than I thought it would," says Martinez says, noting each group voiced issues about how reprimands or punishments might be applied. In the end, it was made clear that while the IT department might be providing information about blatant violations of IT policy — for instance, "no chat, no instant messaging, no adding in unofficial software except with permission" — it's up to high-level city management to handle the repercussions, he says.
For endpoint enforcement on almost 2,000 employee computers, the city is using eEye Digital's Blink, which prevents malware from executing as well as blocks unauthorized applications. "I'm trying to keep them out of trouble," Martinez says. "People are always trying to test the boundaries."
Martinez says one of the most ambitious projects the city is undertaking now is single-sign on authentication using fingerprint biometrics for authentication in order to attain a higher security level than simple passwords.
The project makes use of Imprivata's single sign-on appliance, Microsoft Active Directory and UPEK scanners, and is starting with 150 city personnel, including the city's directors and those in law enforcement and emergency response.
Biometrics is important "because it all comes back to security," Martinez says. "You can use complex passwords, but you will have people writing sticky notes."
Saturday, December 13, 2008
Identity Theft Harder than Ever to Prevent
With so many companies leaking your personal information, it's more and more likely that you'll get your identity stolen at some point. But a new report from the US government reports that law enforcement is lagging way behind on convictions for identity theft.
In fact, say officials, convicting an identity thief is almost impossible.
Things aren't all gloom and doom. In 2007, 26 percent more identity thieves were convicted in the United States than in 2006. That's a huge jump, but it still means that only 1,943 people were convicted of identity theft last year — that's out of about 1.6 million reports of identity theft on file with the Federal Trade Commission. Partly this is because the techniques that ID thieves use are always changing with changing tech. But it's also because so many of these crimes happen across national lines.
According to Threat Level's David Kravets, though, the US has a few ideas about how to combat ID theft. Some are obvious, like using social security cards less often.
But others involve creating new mega-ID cards and a new law enforcement unit:
The 70-page document (.pdf) also includes 31 recommendations to combat identity theft. The report has a couple of interesting recommendations: the creation of a "National Identity Theft Law Enforcement Center" and providing victims of identity theft with a so-called passport "to prove they are who they say they are."
So basically if you're the victim of a ID thief, you'll have to carry around additional identity papers.
Welcome to more airport line-waiting nightmares, to say the very least.
In fact, say officials, convicting an identity thief is almost impossible.
Things aren't all gloom and doom. In 2007, 26 percent more identity thieves were convicted in the United States than in 2006. That's a huge jump, but it still means that only 1,943 people were convicted of identity theft last year — that's out of about 1.6 million reports of identity theft on file with the Federal Trade Commission. Partly this is because the techniques that ID thieves use are always changing with changing tech. But it's also because so many of these crimes happen across national lines.
According to Threat Level's David Kravets, though, the US has a few ideas about how to combat ID theft. Some are obvious, like using social security cards less often.
But others involve creating new mega-ID cards and a new law enforcement unit:
The 70-page document (.pdf) also includes 31 recommendations to combat identity theft. The report has a couple of interesting recommendations: the creation of a "National Identity Theft Law Enforcement Center" and providing victims of identity theft with a so-called passport "to prove they are who they say they are."
So basically if you're the victim of a ID thief, you'll have to carry around additional identity papers.
Welcome to more airport line-waiting nightmares, to say the very least.
Friday, December 12, 2008
Identity Theft Scam Targets Investors; E-Mail Claims To Be From The Internal Revenue Service
BY MONDEE TILLEY, MOUNT AIRY NEWS
POSTED: 9:23 am EST December 11, 2008
UPDATED: 10:46 am EST December 11, 2008
A new scam is targeting non-resident investors in the U.S. It is an e-mail message, reportedly from the IRS, that threatens to impose a 30-percent withholding tax on all income from the account if the recipient fails to disclose a great deal of confidential information.
Here is an excerpt from the e-mail message now hitting local and worldwide in-boxes:
“Our records indicate that you are a non-resident alien. As a result, you are exempted from the United States of America Tax reporting and with-holdings, on interest paid you on your account and other financial dealing to protect your exemption from tax on your account and other financial benefit in rectifying your exemption status.
“Therefore, you are to authenticate the following by completing the form W-4100B2, and return to us as soon as possible through the fax number: 1-646-731-6884.”
Sgt. Alan Freeman, a detective with the Mount Airy Police Department, said, “They seem to be targeting the Hispanic community. Whenever in doubt, seek professional advice. Call the IRS, or your local law enforcement agency. The IRS would not be sending this type of information via the Internet. They would not be asking questions about this type of information.”
Yvonne Nichols, executive assistant with the Greater Mount Airy Chamber of Commerce, said she received the e-mail in her inbox recently.
“I talked to the IRS, and they said they only correspond via mail, not e-mail.”
According to the Internal Revenue Service, the agency warns taxpayers about Internet scams in which fraudulent e-mails are sent that appear to be from the IRS.
The e-mails direct the consumer to a Web link that requests personal and financial information, such as Social Security, bank account or credit card numbers. The practice of tricking victims into revealing private personal and financial information over the Internet is known as “phishing” for information.
The IRS does not send out unsolicited e-mails or ask for detailed personal and financial information. Additionally, the IRS never asks people for the PIN numbers, passwords or similar secret access information for their credit card, bank or other financial accounts.
The information fraudulently obtained by scammers is used to steal the taxpayer’s identity and then his or her financial assets. Generally, identity thieves use someone’s personal data to steal his or her financial accounts, run up charges on the victim’s existing credit cards, apply for new loans, credit cards, services or benefits in the victim’s name and even file fraudulent tax returns to obtain refunds rightfully belonging to the victim.
“Don’t be fooled by these shameless scam artists. The IRS doesn’t send unsolicited e-mail,” said IRS Commissioner Mark W. Everson. “Always exercise caution when you receive unsolicited e-mails or e-mails from senders you don’t know, and always verify the source.”
Last year, the IRS established an electronic mail box, phishing@irs.gov, to receive copies of possibly fraudulent e-mails involving misuse of the IRS name, logo or Web site for investigation. Since the establishment of the mail box, the IRS has received more than 17,700 e-mails from taxpayers reporting more than 240 separate phishing incidents. To date, investigations by the Treasury Inspector General for Tax Administration (TIGTA) have identified host sites in at least 27 different countries, as well as in the United States.
The only genuine IRS Web site is www.IRS.gov.
More information on phishing schemes and others, including abusive tax avoidance transactions, frivolous arguments and more, may be found on the Compliance and Enforcement page on this Web site. For information on preventing or handling the aftermath of identity theft, visit the Federal Trade Commission’s (FTC) Web site.
POSTED: 9:23 am EST December 11, 2008
UPDATED: 10:46 am EST December 11, 2008
A new scam is targeting non-resident investors in the U.S. It is an e-mail message, reportedly from the IRS, that threatens to impose a 30-percent withholding tax on all income from the account if the recipient fails to disclose a great deal of confidential information.
Here is an excerpt from the e-mail message now hitting local and worldwide in-boxes:
“Our records indicate that you are a non-resident alien. As a result, you are exempted from the United States of America Tax reporting and with-holdings, on interest paid you on your account and other financial dealing to protect your exemption from tax on your account and other financial benefit in rectifying your exemption status.
“Therefore, you are to authenticate the following by completing the form W-4100B2, and return to us as soon as possible through the fax number: 1-646-731-6884.”
Sgt. Alan Freeman, a detective with the Mount Airy Police Department, said, “They seem to be targeting the Hispanic community. Whenever in doubt, seek professional advice. Call the IRS, or your local law enforcement agency. The IRS would not be sending this type of information via the Internet. They would not be asking questions about this type of information.”
Yvonne Nichols, executive assistant with the Greater Mount Airy Chamber of Commerce, said she received the e-mail in her inbox recently.
“I talked to the IRS, and they said they only correspond via mail, not e-mail.”
According to the Internal Revenue Service, the agency warns taxpayers about Internet scams in which fraudulent e-mails are sent that appear to be from the IRS.
The e-mails direct the consumer to a Web link that requests personal and financial information, such as Social Security, bank account or credit card numbers. The practice of tricking victims into revealing private personal and financial information over the Internet is known as “phishing” for information.
The IRS does not send out unsolicited e-mails or ask for detailed personal and financial information. Additionally, the IRS never asks people for the PIN numbers, passwords or similar secret access information for their credit card, bank or other financial accounts.
The information fraudulently obtained by scammers is used to steal the taxpayer’s identity and then his or her financial assets. Generally, identity thieves use someone’s personal data to steal his or her financial accounts, run up charges on the victim’s existing credit cards, apply for new loans, credit cards, services or benefits in the victim’s name and even file fraudulent tax returns to obtain refunds rightfully belonging to the victim.
“Don’t be fooled by these shameless scam artists. The IRS doesn’t send unsolicited e-mail,” said IRS Commissioner Mark W. Everson. “Always exercise caution when you receive unsolicited e-mails or e-mails from senders you don’t know, and always verify the source.”
Last year, the IRS established an electronic mail box, phishing@irs.gov, to receive copies of possibly fraudulent e-mails involving misuse of the IRS name, logo or Web site for investigation. Since the establishment of the mail box, the IRS has received more than 17,700 e-mails from taxpayers reporting more than 240 separate phishing incidents. To date, investigations by the Treasury Inspector General for Tax Administration (TIGTA) have identified host sites in at least 27 different countries, as well as in the United States.
The only genuine IRS Web site is www.IRS.gov.
More information on phishing schemes and others, including abusive tax avoidance transactions, frivolous arguments and more, may be found on the Compliance and Enforcement page on this Web site. For information on preventing or handling the aftermath of identity theft, visit the Federal Trade Commission’s (FTC) Web site.
Wednesday, December 10, 2008
MORE TIPS AND COMMENTS
Every one loves a "Top 10" this time of year, so here is a great one from our friends at Kroll Fraud Solutions. It was put together by Brian Lapidus - Kroll Fraud Solution chief operating officer and identity theft expert. Enjoy!
1. Beware the Word "Prevent"
No person and no product can prevent identity theft. As long as criminals can benefit from stealing, there will be theft. Sensitive personal information (SPI) is everywhere, housed and archived in a mind-boggling variety of ways. Individuals and companies can reduce access to SPI and improve safeguards around it by working to change how we share, collect, store and dispose of information.
2. There Are No Guarantees
This mantra holds true for a lot of things in life and dealing with identity theft is no exception. While a number of instances of fraud can be restored to pre-theft status, some identity dilemmas simply can’t be fixed. If you’re on the ‘no fly list’ thanks to an imposter or an error, you’ll stay there. A third-party solution cannot deliver a remedy.
3. Watch for "Shoulder Surfers" and "Skimmers"
Shield the entry of personal identification numbers (PINs), and be aware of people standing entirely too close by when using your credit or debit card in public. Especially with the advent of cell phone cameras, a sneaky, shoulder surfing thief can get your private information pretty easily, if you’re not careful. It’s also advisable to use teller machines that are familiar to you, so you are in a better position to identify when the equipment looks different or doesn’t “feel right.” Your increased awareness may reveal a skimmer’s attempt to steal PINs and banking details at that site.
4. Keep Your Social Security Card Safe at Home
Unless you’re on your way to fill out a job application, there are very few reasons to carry around the crown jewel of SPI. At lunch a few weeks ago, the woman beside me opened her wallet for a credit card and there was her Social Security card, too. Remember, ID theft and fraud are not exclusively credit-related – thieves can use a clean Social Security number to construct a whole new life.
Additional note from Dave: I regularly receive emails from Fight Identity Theft visitors explaining how they just had their purse or wallet stolen with their Social Security card inside. Remove that card today!
5. Destroy Before You Dump That Old Computer
Erasing data just enables the computer to write over that space again; it doesn’t actually eliminate the original bits and bytes. Physically remove the hard-drive to ensure you’re not tossing out or passing along your personal details. Our company is often called upon to recover data from an erased or damaged drive; we’re very good at it – and so are some professional thieves.
Additional note from Dave: You could also consider using a software tool like Eraser to do a complete wipe of your drive. If you physically remove your drive, smash the drive with a hammer (find someone strong) before throwing it in the trash.
6. Choose "Forget Me’ Instead of "Remember Me"
How many Web sites do you frequent that invite you to enable an automatic log on the next time you visit? Don’t check that box! When convenience trumps confidentiality, you’re asking for trouble. The harder you make it for hackers to follow your trail into an online store or bank account, the better.
Additional note from Dave: This is absolutely necessary when using public computers. In fact, you should avoid accessing any secure sites from a public computer (like a library, internet cafe) or when using a public wireless network or wifi hotspot.
7. Don’t Rely On Fraud Alerts Or Credit Freezes Alone
Fraud alerts are meant to stop an identity thief from opening new accounts in your name. Credit freezes let you restrict access to your credit report, which would also make it hard for someone else to open new accounts. But, neither one will stop a thief from trading your SPI for cash, or using it for tax fraud or in any of the countless other ways fraudsters exploit stolen identities.
8. Practice Prudent Posting
Social networking sites on the internet enable individuals around the world to chat, share photos, recruit employees, date, post resumes, auction property, and more. Because the Web makes it possible for any posted document to link with another, any data you put out online have the potential to stay there for what amounts to electronic eternity.
Additional note from Dave: I suggest creating usernames or an email address that don't contain your name or anything traceable to you, whenever possible. You also might consider using different usernames on different sites. This makes sense because if someone is able to determine that you use "CatLuvr55" on one site, it's an easy search to track down "CatLuvr55" on any other sites where you have a profile.
9. Keep That Key
When you check out of a hotel where you were issued a card-key to unlock the door to your room, don’t leave the card-key behind. Hold on to it until you’re safely home and can shred or otherwise discard it safely. Some say it’s an urban myth that the card-keys hold vital details like credit card numbers, while others report having tested and confirmed the presence of private data coded into the magnetic strip. Even if there’s no definitive answer, why risk it?
Additional note from Dave: Not sure I'm convinced on this one. I'd need to see more data showing that it is a problem. Snopes.com debunks this pretty thoroughly.
10. What’s In Your Wallet?
Make photocopies of the personal material in your wallet: Driver’s license, credit cards, insurance cards, all of it – front and back. Should your wallet be lost or stolen, you won’t be left wondering what was actually taken, and you’ll be able to quickly notify the appropriate agencies about what has taken place.
Source: -http://fightidentitytheft.com/blog/-2/top-10-identity-theft-tips-for-2008/
****************************************************
Mel Rapozo
Certified Identity Theft Risk Management Specialist
M&P Legal Support Services, LLC
www.mplss.com
1. Beware the Word "Prevent"
No person and no product can prevent identity theft. As long as criminals can benefit from stealing, there will be theft. Sensitive personal information (SPI) is everywhere, housed and archived in a mind-boggling variety of ways. Individuals and companies can reduce access to SPI and improve safeguards around it by working to change how we share, collect, store and dispose of information.
2. There Are No Guarantees
This mantra holds true for a lot of things in life and dealing with identity theft is no exception. While a number of instances of fraud can be restored to pre-theft status, some identity dilemmas simply can’t be fixed. If you’re on the ‘no fly list’ thanks to an imposter or an error, you’ll stay there. A third-party solution cannot deliver a remedy.
3. Watch for "Shoulder Surfers" and "Skimmers"
Shield the entry of personal identification numbers (PINs), and be aware of people standing entirely too close by when using your credit or debit card in public. Especially with the advent of cell phone cameras, a sneaky, shoulder surfing thief can get your private information pretty easily, if you’re not careful. It’s also advisable to use teller machines that are familiar to you, so you are in a better position to identify when the equipment looks different or doesn’t “feel right.” Your increased awareness may reveal a skimmer’s attempt to steal PINs and banking details at that site.
4. Keep Your Social Security Card Safe at Home
Unless you’re on your way to fill out a job application, there are very few reasons to carry around the crown jewel of SPI. At lunch a few weeks ago, the woman beside me opened her wallet for a credit card and there was her Social Security card, too. Remember, ID theft and fraud are not exclusively credit-related – thieves can use a clean Social Security number to construct a whole new life.
Additional note from Dave: I regularly receive emails from Fight Identity Theft visitors explaining how they just had their purse or wallet stolen with their Social Security card inside. Remove that card today!
5. Destroy Before You Dump That Old Computer
Erasing data just enables the computer to write over that space again; it doesn’t actually eliminate the original bits and bytes. Physically remove the hard-drive to ensure you’re not tossing out or passing along your personal details. Our company is often called upon to recover data from an erased or damaged drive; we’re very good at it – and so are some professional thieves.
Additional note from Dave: You could also consider using a software tool like Eraser to do a complete wipe of your drive. If you physically remove your drive, smash the drive with a hammer (find someone strong) before throwing it in the trash.
6. Choose "Forget Me’ Instead of "Remember Me"
How many Web sites do you frequent that invite you to enable an automatic log on the next time you visit? Don’t check that box! When convenience trumps confidentiality, you’re asking for trouble. The harder you make it for hackers to follow your trail into an online store or bank account, the better.
Additional note from Dave: This is absolutely necessary when using public computers. In fact, you should avoid accessing any secure sites from a public computer (like a library, internet cafe) or when using a public wireless network or wifi hotspot.
7. Don’t Rely On Fraud Alerts Or Credit Freezes Alone
Fraud alerts are meant to stop an identity thief from opening new accounts in your name. Credit freezes let you restrict access to your credit report, which would also make it hard for someone else to open new accounts. But, neither one will stop a thief from trading your SPI for cash, or using it for tax fraud or in any of the countless other ways fraudsters exploit stolen identities.
8. Practice Prudent Posting
Social networking sites on the internet enable individuals around the world to chat, share photos, recruit employees, date, post resumes, auction property, and more. Because the Web makes it possible for any posted document to link with another, any data you put out online have the potential to stay there for what amounts to electronic eternity.
Additional note from Dave: I suggest creating usernames or an email address that don't contain your name or anything traceable to you, whenever possible. You also might consider using different usernames on different sites. This makes sense because if someone is able to determine that you use "CatLuvr55" on one site, it's an easy search to track down "CatLuvr55" on any other sites where you have a profile.
9. Keep That Key
When you check out of a hotel where you were issued a card-key to unlock the door to your room, don’t leave the card-key behind. Hold on to it until you’re safely home and can shred or otherwise discard it safely. Some say it’s an urban myth that the card-keys hold vital details like credit card numbers, while others report having tested and confirmed the presence of private data coded into the magnetic strip. Even if there’s no definitive answer, why risk it?
Additional note from Dave: Not sure I'm convinced on this one. I'd need to see more data showing that it is a problem. Snopes.com debunks this pretty thoroughly.
10. What’s In Your Wallet?
Make photocopies of the personal material in your wallet: Driver’s license, credit cards, insurance cards, all of it – front and back. Should your wallet be lost or stolen, you won’t be left wondering what was actually taken, and you’ll be able to quickly notify the appropriate agencies about what has taken place.
Source: -http://fightidentitytheft.com/blog/-2/top-10-identity-theft-tips-for-2008/
****************************************************
Mel Rapozo
Certified Identity Theft Risk Management Specialist
M&P Legal Support Services, LLC
www.mplss.com
Tuesday, December 9, 2008
How can you prevent identity theft from happening to you?
- Promptly remove mail from your mailbox after delivery.
- Deposit outgoing mail in post office collection mailboxes or at your local post office. Do not leave in unsecured mail receptacles.
- Never give personal information over the telephone, such as your social security number, date of birth, mother's maiden name, credit card number, or bank PIN code, unless you initiated the phone call. Protect this information and release it only when absolutely necessary.
- Shred pre-approved credit applications, credit card receipts, bills, and other financial information you don't want before discarding them in the trash or recycling bin.
- Empty your wallet of extra credit cards and IDs, or better yet, cancel the ones you do not use and maintain a list of the ones you do.
- Order your credit report from the three credit bureaus once a year to check for fraudulent activity or other discrepancies.
- Never leave receipts at bank machines, bank counters, trash receptacles, or unattended gasoline pumps. Keep track of all your paperwork. When you no longer need it, destroy it.
- Memorize your social security number and all of your passwords. Do not record them on any cards or on anything in your wallet or purse. Sign all new credit cards upon receipt.
- Save all credit card receipts and match them against your monthly bills.
- Be conscious of normal receipt of routine financial statements. Contact the sender if they are not received in the mail.
- Notify your credit card companies and financial institutions in advance of any change of address or phone number.
- Never loan your credit cards to anyone else.
- Never put your credit card or any other financial account number on a postcard or on the outside of an envelope.
- If you applied for a new credit card and it hasn't arrived in a timely manner, call the bank or credit card company involved.
- Report all lost or stolen credit cards immediately.
- Closely monitor expiration dates on your credit cards. Contact the credit card issuer if replacement cards are not received prior to the expiration dates.
- Beware of mail or telephone solicitations disguised as promotions offering instant prizes or awards designed solely to obtain your personal information or credit card numbers.
- Use caution when disclosing checking account numbers, credit card numbers, or other personal financial data at any Web site or on-line service location unless you receive a secured authentication key from your provider.
- When you subscribe to an on-line service, you may be asked to give credit card information. When you enter any interactive service site, beware of con artists who may ask you to "confirm" your enrollment service by disclosing passwords or the credit card account number used to subscribe. Don't give them out!
Monday, December 8, 2008
Guard Yourself Against Identity Theft on Social Networks
08:14 AM CST on Monday, December 8, 2008
By PAMELA YIP / The Dallas Morning News pyip@dallasnews.com
The next source of identity theft may be social networking Web sites.
"There's a growing problem, and the risks are increasing," said Scott Mitic, chief executive of TrustedID, which has identity-theft protection products for consumers and businesses.
Officials of the Federal Trade Commission, which enforces identity theft laws, said they know of no ID theft cases that have arisen from social networking sites, but you can't be too careful.
Thieves are constantly searching for new ways to get you to divulge any sliver of personal information so they can tap into your wallet.
And social networking sites such as MySpace and Facebook are becoming a "growing pool of valuable information that at some point thieves may consider more valuable than a credit report," Mr. Mitic said.
For example, most of us use facts associated with our lives as user words or passwords, and thieves are learning they can mine these facts from social networking sites.
"I know most Americans who, if they have pets, that's usually their password," Mr. Mitic said. "The information that may seem innocuous to share may have real value to individuals with criminal minds."
Social networking sites enable people to freely express themselves in a way that may cause them to unwittingly drop morsels of information that criminals can extract to steal their identity.
Here's how it might work:
Your profile says that you live in Texas, you were born in Dallas, your beloved pet's name is Max and that you like to spend time with your parents, Dick and Jane.
It also says that today you're venting your anger at your bank – Bank XYZ – because it's been slow to resolve a problem with your account.
Now criminals know the name of your bank, the name of your pet and your mother's name. They will seek to learn your mother's maiden name, which is often used as a security question on bank Web sites.
Here are some tips to protect yourself online. You've heard them before, but they're particularly important for social networking sites because the information you post can be accessed by others:
•Never post sensitive personal data, such as your Social Security number, driver's license number and bank account numbers.
That includes your hometown, mother's maiden name, your date of birth, your high school, the hospital or city in which your were born and your favorite color.
"There are all of these secret-password answer questions," Mr. Mitic said.
•Avoid telling everyone your physical location and what you're doing at the very moment, especially if you're away from home. That's an invitation for someone to burglarize your home.
•Manage privacy controls on social networks. Set your profile to "Private" to prevent uninvited people from viewing your personal information.
•Don't make your password easy to guess.
•Only allow people you know to view your personal profile. Be careful about allowing strangers to view your profile because people aren't always who they say they are.
Officials of social networking site Facebook said they give users tools to protect themselves.
"Facebook users' profiles are by default accessible only to confirmed friends and others in a given network, and we've put in place additional protections for more sensitive information like phone number, e-mail, and home address," said spokesman Simon Axten. "Users can control access to information as they see fit using the extensive and particular settings we offer."
Users of MySpace also can control how visitors and other MySpace members communicate with them by controlling their account settings.
It reminds users that their personal profile and MySpace forums are public spaces and advises users to not post sensitive personal information.
Many of you will see this advice and say it's unrealistic because I'm practically muzzling you. But you have to decide how much information you want to share.
"How safe do you want to be?" Mr. Mitic said. "How risky a lifestyle do you want to live? We live in a world where it can be dangerous to publicly expose personal information about yourself. If you want to live a safer life, you need to be more protective of your information."
Bottom line: Have fun but be safe.
***********************************************
Let us help you with your identity theft protection needs. We provide monitoring and restoration benefits to all our members. For more information, visit www.mplss.com or call our office toll free at (800) 306-3063. Happy holidays to all of you!!
Mel Rapozo
Certified Identity Theft Risk Management Specialist
M&P Legal Support Services, LLC
By PAMELA YIP / The Dallas Morning News pyip@dallasnews.com
The next source of identity theft may be social networking Web sites.
"There's a growing problem, and the risks are increasing," said Scott Mitic, chief executive of TrustedID, which has identity-theft protection products for consumers and businesses.
Officials of the Federal Trade Commission, which enforces identity theft laws, said they know of no ID theft cases that have arisen from social networking sites, but you can't be too careful.
Thieves are constantly searching for new ways to get you to divulge any sliver of personal information so they can tap into your wallet.
And social networking sites such as MySpace and Facebook are becoming a "growing pool of valuable information that at some point thieves may consider more valuable than a credit report," Mr. Mitic said.
For example, most of us use facts associated with our lives as user words or passwords, and thieves are learning they can mine these facts from social networking sites.
"I know most Americans who, if they have pets, that's usually their password," Mr. Mitic said. "The information that may seem innocuous to share may have real value to individuals with criminal minds."
Social networking sites enable people to freely express themselves in a way that may cause them to unwittingly drop morsels of information that criminals can extract to steal their identity.
Here's how it might work:
Your profile says that you live in Texas, you were born in Dallas, your beloved pet's name is Max and that you like to spend time with your parents, Dick and Jane.
It also says that today you're venting your anger at your bank – Bank XYZ – because it's been slow to resolve a problem with your account.
Now criminals know the name of your bank, the name of your pet and your mother's name. They will seek to learn your mother's maiden name, which is often used as a security question on bank Web sites.
Here are some tips to protect yourself online. You've heard them before, but they're particularly important for social networking sites because the information you post can be accessed by others:
•Never post sensitive personal data, such as your Social Security number, driver's license number and bank account numbers.
That includes your hometown, mother's maiden name, your date of birth, your high school, the hospital or city in which your were born and your favorite color.
"There are all of these secret-password answer questions," Mr. Mitic said.
•Avoid telling everyone your physical location and what you're doing at the very moment, especially if you're away from home. That's an invitation for someone to burglarize your home.
•Manage privacy controls on social networks. Set your profile to "Private" to prevent uninvited people from viewing your personal information.
•Don't make your password easy to guess.
•Only allow people you know to view your personal profile. Be careful about allowing strangers to view your profile because people aren't always who they say they are.
Officials of social networking site Facebook said they give users tools to protect themselves.
"Facebook users' profiles are by default accessible only to confirmed friends and others in a given network, and we've put in place additional protections for more sensitive information like phone number, e-mail, and home address," said spokesman Simon Axten. "Users can control access to information as they see fit using the extensive and particular settings we offer."
Users of MySpace also can control how visitors and other MySpace members communicate with them by controlling their account settings.
It reminds users that their personal profile and MySpace forums are public spaces and advises users to not post sensitive personal information.
Many of you will see this advice and say it's unrealistic because I'm practically muzzling you. But you have to decide how much information you want to share.
"How safe do you want to be?" Mr. Mitic said. "How risky a lifestyle do you want to live? We live in a world where it can be dangerous to publicly expose personal information about yourself. If you want to live a safer life, you need to be more protective of your information."
Bottom line: Have fun but be safe.
***********************************************
Let us help you with your identity theft protection needs. We provide monitoring and restoration benefits to all our members. For more information, visit www.mplss.com or call our office toll free at (800) 306-3063. Happy holidays to all of you!!
Mel Rapozo
Certified Identity Theft Risk Management Specialist
M&P Legal Support Services, LLC
Subscribe to:
Posts (Atom)

