So what do you use your office copy machine for? Obviously, you would say, it’s used for work documents such as company brochures or internal memos. But what else? Occasionally, you and/or your office mates may use it for personal documents, such as income tax returns, photo identification or Social Security documents. Surely, the boss wouldn’t mind that too much. In most offices, this is true, but that’s not the point. Here is some information that may make you change your mind or at least think twice before doing so.
If your office copy machine was manufactured in the past five years, a hard drive is included with the copier that stores a digital copy of every document copied. That way if the original is lost, you can call up the digital version to make another copy. This is a great idea for your office documents, but what about any documents with personal tax or identifying information? Ouch! Let’s hope everyone in the office is trustworthy. Worse yet, what if the company decides to sell the photocopier and get a new one. Ouch again! You don’t know who will have access to this information.
However, Sharp is promoting its new copy machines with options to encrypt these stored copies or virtually shred them so they can’t be recovered. Find out if your company copier offers these features, and if they do, be sure to use them. If not, you may want to think twice about what you copy.
Friday, March 16, 2007
Thursday, February 15, 2007
Where in the U.S. are Identity Thieves Most Active?
Does where you live make you at higher or lower risk of identity theft? If so, which U.S. Cities and states are at highest risk of identity theft? A recent study provides the answers to those questions. According to ID Analytics Inc., New Yorkers, especially those living in New York City, are major targets for identity theft. Californians were the runners up, especially those living in Los Angeles.
So who else made the list? The states with the highest rates of identity theft include: New York, California, Nevada, Arizona, Illinois, Hawaii, Oregon, Michigan, Washington and Texas. The study goes on to say that the cities at the highest risk include: New York, NY; Detroit, MI; Los Angeles, CA; Little Rock, AR; Greenville, MS; Atlanta, GA; Phoenix, AR; Portland, OR; Dallas, TX, and Springfield, IL.
The lowest rates of identity theft are in the following states: Wyoming, Vermont, Montana, North Dakota, New Hampshire, Ohio, Maine, Iowa, West Virginia and South Dakota. Keep in mind that lower risk doesn't mean no risk. I live in one of these “low risk” states, but I was still hit.
So who else made the list? The states with the highest rates of identity theft include: New York, California, Nevada, Arizona, Illinois, Hawaii, Oregon, Michigan, Washington and Texas. The study goes on to say that the cities at the highest risk include: New York, NY; Detroit, MI; Los Angeles, CA; Little Rock, AR; Greenville, MS; Atlanta, GA; Phoenix, AR; Portland, OR; Dallas, TX, and Springfield, IL.
The lowest rates of identity theft are in the following states: Wyoming, Vermont, Montana, North Dakota, New Hampshire, Ohio, Maine, Iowa, West Virginia and South Dakota. Keep in mind that lower risk doesn't mean no risk. I live in one of these “low risk” states, but I was still hit.
Labels:
city,
identity theft,
risk,
state
Friday, February 09, 2007
Is ID Theft Still a Problem? Yes!!!
The financial services industry has been promoting that identity theft is on the decline and that it is no longer the serious problem it once was. They'd like to think so, wouldn't they? According to the Federal Trade Commission, that's not necessarily the case. For the seventh year in a row, the crime identity theft has topped the FTC's complaint list.
So what does the statistics from the 2006 FTC complaint list tell us? First of all, identity theft accounts for 36% of the 674,354, or 246,035 consumers reported being victims of ID theft. That doesn't even account for all the cases. There will always be a percentage that don't report the crime because either it was a close friend or relative and they don't want to press charges or they are embarrassed about being a victim and getting scammed. On the decline they say?
While there were no close runners-up, some distant ones include shop-at-home/catalog sales (7%); prizes, sweepstakes and lotteries (7%); Internet services and computer complaints (6%); Internet auction fraud (5%), and the list goes on from there.
I hope that this report is enough to convince you that identity theft is still very much with us. Keep that information safe.
So what does the statistics from the 2006 FTC complaint list tell us? First of all, identity theft accounts for 36% of the 674,354, or 246,035 consumers reported being victims of ID theft. That doesn't even account for all the cases. There will always be a percentage that don't report the crime because either it was a close friend or relative and they don't want to press charges or they are embarrassed about being a victim and getting scammed. On the decline they say?
While there were no close runners-up, some distant ones include shop-at-home/catalog sales (7%); prizes, sweepstakes and lotteries (7%); Internet services and computer complaints (6%); Internet auction fraud (5%), and the list goes on from there.
I hope that this report is enough to convince you that identity theft is still very much with us. Keep that information safe.
Monday, February 05, 2007
Increased Penalties for Some Identity Thieves
Most people would agree that more needs to be done to not only catch identity thieves, but also that they should be punished to robbing people of their identity and financial stability. It looks like the punishments for at least some identity thieves may become stiffer. Friday the U.S. House of Representatives approved a bill that will increase penalties for those convicted of committing financial identity theft against a disabled or elderly person. The proposal will now be decided by the Senate.
The penalty is now between three and 10 years of prison time and a fine of up to $10,000, but if this bill passes, it would increase to between five and twenty years in prison and a fine of up to $15,000. The bill would also allow the court to order anyone convicted of identity to pay restitution to his/her victims.
While this is a step in the right direction, I don't really think its enough. For one thing, some identity thieves operate from offshore. These thieves are rarely investigated or caught, let alone punished. Besides, what's to stop a local identity thief to leave the country before he is caught? More needs to be done to train local law enforcement to investigate and catch identity thieves and educate the public regarding prevention methods.
The penalty is now between three and 10 years of prison time and a fine of up to $10,000, but if this bill passes, it would increase to between five and twenty years in prison and a fine of up to $15,000. The bill would also allow the court to order anyone convicted of identity to pay restitution to his/her victims.
While this is a step in the right direction, I don't really think its enough. For one thing, some identity thieves operate from offshore. These thieves are rarely investigated or caught, let alone punished. Besides, what's to stop a local identity thief to leave the country before he is caught? More needs to be done to train local law enforcement to investigate and catch identity thieves and educate the public regarding prevention methods.
Tuesday, January 30, 2007
ID Theft Victims Often Know Their Thief
It's one of those lessons in life we all learn at some point. You can't trust everyone. When and how you learn it isn't necessarily the issue as long as you learn it. Many are reminded of this when a trusted friend or relative steals their identities, and according to a recent survey by the Identity Theft Assistance Center (ITAC). According to this survey, 42% of participants knew the source of the crime, and out of those, the largest percentage, 22.61% are victimized by someone they know.
Being victimized by friends or relatives is tough, especially since they are usually the people you wouldn't expect to do such a thing. Like other forms of identity theft, you may never be completely immune, but there are precautions you can take to avoid make yourself less vulnerable. For instance, it's good to keep the data in your home safe so as not to tempt a friend or relative who may be in desperate need of some cash. Bills and credit card statements should not be left out for all to see, and personal financial records and documents should be filed away in a locked box or safe. Do not lend a check book or credit card to a friend or relative no matter how much you care for them or trust them.
Identity theft is hard to deal with as it is, but even harder if you know the thief. Make the theft a little harder by keeping important information out of the reach of wandering eyes.
Being victimized by friends or relatives is tough, especially since they are usually the people you wouldn't expect to do such a thing. Like other forms of identity theft, you may never be completely immune, but there are precautions you can take to avoid make yourself less vulnerable. For instance, it's good to keep the data in your home safe so as not to tempt a friend or relative who may be in desperate need of some cash. Bills and credit card statements should not be left out for all to see, and personal financial records and documents should be filed away in a locked box or safe. Do not lend a check book or credit card to a friend or relative no matter how much you care for them or trust them.
Identity theft is hard to deal with as it is, but even harder if you know the thief. Make the theft a little harder by keeping important information out of the reach of wandering eyes.
Thursday, January 18, 2007
T.J. Maxx Security Breach
We're all aware of the possible dangers of shopping online. If a website doesn't have a secure log in and order for (https), we shouldn't be shopping with them. But what about a local retail outlet? Is a credit card purchase there secure? While there's always the possibility of dishonest employees, we'd like to assume “yes.” However, this story proves that retail stores are also likely to get hacked along with online vendors. Retail company T.J. Maxx had its credit card computer system hacked just before Christmas.
The computer network in question handles credit cards, debit cards and checks. This network was broken into, and some of the customer data was stolen. T.J. Maxx is investigating to find out exactly what information was compromised so they can contact victims.
The store has issued a customer alert on their website as well as providing a customer helpline to handle customer questions and concerns. If you've made any credit or debit card purchases at T.J. Maxx in the past, you may want to check your credit card or bank statements for charges you didn't make.
The computer network in question handles credit cards, debit cards and checks. This network was broken into, and some of the customer data was stolen. T.J. Maxx is investigating to find out exactly what information was compromised so they can contact victims.
The store has issued a customer alert on their website as well as providing a customer helpline to handle customer questions and concerns. If you've made any credit or debit card purchases at T.J. Maxx in the past, you may want to check your credit card or bank statements for charges you didn't make.
Sunday, January 14, 2007
More Laws to Prevent ID Theft?
When it comes to laws protecting consumers from identity theft, much of the legislation is at the state level, and some states have better privacy laws than others. However, the federal government has been making moves over the past few years to pass laws attempting to prevent identity theft, including the forming of the Identity Theft Task Force. Now there are a few more laws have been reintroduced to the Senate that will hopefully help protect consumer privacy.
The first one, the Notification of Risk to Personal Data Act would require, as the name implies, would require businesses and government agencies to notify a consumer of a security breach involving the individual's personal data among other things. It would also require a description of the type of data compromised as well as a number for consumers to call for more information. The media should also be notified as well as individual consumers. These and other requirements in this bill hope to give people the information they need if their data is compromised so they can take the necessary precautions to prevent or at least limit identity theft.
The second one, the Social Security Number Misuse Prevention Act, could be highly effective if properly enforced. This bill would prohibit the sale or display of someone's Social Security number without consent. It would also prohibit government agencies from displaying Social Security number on public records in print or electronically. This is a great idea. Too long have companies been sharing this data with affiliates or selling it for profit, and removing Social Security numbers would make an identity thief work a lot harder to obtain this valuable information.
We'll see if these bills pass. You can read more about both of them here.
The first one, the Notification of Risk to Personal Data Act would require, as the name implies, would require businesses and government agencies to notify a consumer of a security breach involving the individual's personal data among other things. It would also require a description of the type of data compromised as well as a number for consumers to call for more information. The media should also be notified as well as individual consumers. These and other requirements in this bill hope to give people the information they need if their data is compromised so they can take the necessary precautions to prevent or at least limit identity theft.
The second one, the Social Security Number Misuse Prevention Act, could be highly effective if properly enforced. This bill would prohibit the sale or display of someone's Social Security number without consent. It would also prohibit government agencies from displaying Social Security number on public records in print or electronically. This is a great idea. Too long have companies been sharing this data with affiliates or selling it for profit, and removing Social Security numbers would make an identity thief work a lot harder to obtain this valuable information.
We'll see if these bills pass. You can read more about both of them here.
Monday, January 08, 2007
Identity Theft and the Things We Carry: Employee or Student ID Cards
This is the final segment of my “things we carry” blogs. I know I've mentioned ID cards before, or at least student ID cards, but some things deserve repeating.
Employee and student identification cards are not a problem in and of themselves. Many schools and probably all universities require student IDs in order to register for classes or to use student only facilities, and many companies require employs to carry identification for the company's security. However, the problem is when employers and schools print the owner's Social Security number on the card which becomes a security risk for the employee or student. Many schools and companies that did this have already switched over to provide new ID numbers for the identification cards, instead of the Social Security number. If your school or company has a your Social Security number printed on your ID card, you may want to suggest that they give you a different identification number and may even suggest switching over to a system that does not use Social Security numbers on ID cards at all. It may be an expensive effort, but it will be safer for everyone.
Your Social Security number is the main component needed to open credit cards in your name or take out loans and other services. You can make this all the more difficult by removing any document with your Social Security number from your wallet completely.
Employee and student identification cards are not a problem in and of themselves. Many schools and probably all universities require student IDs in order to register for classes or to use student only facilities, and many companies require employs to carry identification for the company's security. However, the problem is when employers and schools print the owner's Social Security number on the card which becomes a security risk for the employee or student. Many schools and companies that did this have already switched over to provide new ID numbers for the identification cards, instead of the Social Security number. If your school or company has a your Social Security number printed on your ID card, you may want to suggest that they give you a different identification number and may even suggest switching over to a system that does not use Social Security numbers on ID cards at all. It may be an expensive effort, but it will be safer for everyone.
Your Social Security number is the main component needed to open credit cards in your name or take out loans and other services. You can make this all the more difficult by removing any document with your Social Security number from your wallet completely.
Saturday, January 06, 2007
Identity Theft and the Things We Carry: Health Care Card
This is another item that, while important, and even useful to carry with you in case something happens, but your health care or insurance card can also put you in potential danger of identity theft.
Obviously, this is one thing many of us would consider to be important to carry in case of emergency illness or injury and understandably so. However, is your Social Security number displayed on the card? Many insurance companies are switching over to the use of different account and identification numbers for their customers. If your insurance company has not made this change, you may want to contact them and ask them to issue a different number. If they are unwilling to do so, you may want to photocopy your card and black out all but the last four digits of your Social Security number and carry that instead. If you need emergency care, your name and the last four digits of your Social Security number are all they should need to look up your insurance information.
You want to be prepared in case of a medical emergency, but you don't want hand over such valuable information as your Social Security number to the wrong person in the process.
Obviously, this is one thing many of us would consider to be important to carry in case of emergency illness or injury and understandably so. However, is your Social Security number displayed on the card? Many insurance companies are switching over to the use of different account and identification numbers for their customers. If your insurance company has not made this change, you may want to contact them and ask them to issue a different number. If they are unwilling to do so, you may want to photocopy your card and black out all but the last four digits of your Social Security number and carry that instead. If you need emergency care, your name and the last four digits of your Social Security number are all they should need to look up your insurance information.
You want to be prepared in case of a medical emergency, but you don't want hand over such valuable information as your Social Security number to the wrong person in the process.
Friday, January 05, 2007
Identity Theft and the Things We Carry: Credit Cards
In my previous post, I started the first of a few posts on what we carry with us everyday can make us more appealing as potential victims of identity theft. While your Social Security card is something you shouldn't carry in your wallet unless you know you will need it, credit cards are a little more complicated because you are more likely to need them on a daily basis.
Of course, most of us carry credit cards for daily purchases when we are short on cash, but how many do you need to carry everyday? You will be less likely to notice if one you don't use often goes missing from your wallet or if the bill is re-routed to a different address. Pull out credit cards you are least likely to use and put them in a safe place at home only to be used when you know you'll need them. If you have any you never use or rarely use, you may even want to consider canceling it. An unused account, once discovered, is a gold mine for an identity thief.
Something else to consider would be to keep a list of all your credit card account numbers and the phone numbers necessary to cancel them. Don't carry this in your wallet, but keep it in a safe place. Then if your wallet is stolen, you can call the credit card companies to report the theft and cancel the card before too much damage is done.
Of course, most of us carry credit cards for daily purchases when we are short on cash, but how many do you need to carry everyday? You will be less likely to notice if one you don't use often goes missing from your wallet or if the bill is re-routed to a different address. Pull out credit cards you are least likely to use and put them in a safe place at home only to be used when you know you'll need them. If you have any you never use or rarely use, you may even want to consider canceling it. An unused account, once discovered, is a gold mine for an identity thief.
Something else to consider would be to keep a list of all your credit card account numbers and the phone numbers necessary to cancel them. Don't carry this in your wallet, but keep it in a safe place. Then if your wallet is stolen, you can call the credit card companies to report the theft and cancel the card before too much damage is done.
Wednesday, January 03, 2007
Identity Theft and the Things We Carry: Social Security Card
As I've mentioned before, identity theft can be committed in a variety of different ways. While some identity thieves prefer a phishing scam, others may prefer dumpster diving or stealing someone's mail or wallet. Since there are so many ways to get one's identity stolen, consumers need to protect their information on all fronts, and perhaps the place many of us are most vulnerable is follows us around everywhere we go, our wallets. In fact, the items we carry in our wallets daily may provide an identity thief with everything he needs. These next few blog posts will cover some things we may be carrying with us daily that will make us more vulnerable to identity theft.
Do you carry your Social Security card with you in your wallet? After all, you are occasionally asked for it as a form of identification? This is last thing you want to carry in your wallet because if it is stolen, you may very well be handing your identity over on a plate. Only carry it with you if you know for a fact you are going to need it. You know your Social Security number if you need to provide it, and if you don't, memorize it. Keep your Social Security card in a safe place, like a locked box or a safe.
One's Social Security card is the most valuable document to an identity thief. Do your best to keep it out of his/her hands.
Do you carry your Social Security card with you in your wallet? After all, you are occasionally asked for it as a form of identification? This is last thing you want to carry in your wallet because if it is stolen, you may very well be handing your identity over on a plate. Only carry it with you if you know for a fact you are going to need it. You know your Social Security number if you need to provide it, and if you don't, memorize it. Keep your Social Security card in a safe place, like a locked box or a safe.
One's Social Security card is the most valuable document to an identity thief. Do your best to keep it out of his/her hands.
Wednesday, December 27, 2006
MySpace Plagued With Identity Thieves
I've posted before on social networking sites and how people can become victims of identity theft by revealing too much online. It seems now the site hit most with identity theft is the most popular site, MySpace. MySpace users are now being hit by a band of identity thieves who are stealing user names, passwords and personal information and using them dishonestly. Many users are being spammed with junk emails and links to certain sites or being impersonated online.
While being impersonated online can be a serious pain to remedy, this isn't the most damaging problem. Personal information is being stolen, and identity thieves are accessing data on users' personal computers. According to this article, thieves are using different methods of to commit their crimes. One popular one is providing a link to download a media player or another kind of file, and when the user does this, a worm is installed on his/her computer.
NewsCorp, parent company of MySpace, is reportedly taking steps to slow down the identity theft, but MySpace users continue to be attacked. I can't emphasize this enough. Take extra precautions when using MySpace. It can be fun and safe if you are careful. Have a look at my former post and take the suggested precautions. Not everyone on the web is willing to play nice. Be safe.
While being impersonated online can be a serious pain to remedy, this isn't the most damaging problem. Personal information is being stolen, and identity thieves are accessing data on users' personal computers. According to this article, thieves are using different methods of to commit their crimes. One popular one is providing a link to download a media player or another kind of file, and when the user does this, a worm is installed on his/her computer.
NewsCorp, parent company of MySpace, is reportedly taking steps to slow down the identity theft, but MySpace users continue to be attacked. I can't emphasize this enough. Take extra precautions when using MySpace. It can be fun and safe if you are careful. Have a look at my former post and take the suggested precautions. Not everyone on the web is willing to play nice. Be safe.
Thursday, December 21, 2006
Dumpster Diver Charged With Identity Theft of Almost 90 MLB players
Some identity thieves go for the average consumer, preferably someone with good enough credit to make it worth their while. Others may go for those with deeper pockets. This one seems to have set the bar a bit higher. Police in Lake County outside Chicago found the personal information of almost 90 current and retired Major League Baseball players in the home of David Dright.
The information is believed to have come from trash bins of SFX Baseball Inc., a sports agency that represents major and minor league baseball players headed by Pat Rooney and Fern Cuza. The information he recovered includes dates of birth, Social Security numbers, canceled paychecks, and infant death records. The evidence was found in Dright's apartment after someone reported that Dright stole his identity. Whether any of the players have been affected is being investigated, but potential victims are being contacted.
Remember: Anyone can be a victim of identity theft. I hope this will be a lesson to SFX to be more careful when handling client data. These players trust this company, so their information should be treated with more care. I suppose I shouldn't be surprised by the careless practices of such companies. Reminder number two: Shred those documents before throwing them away.
The information is believed to have come from trash bins of SFX Baseball Inc., a sports agency that represents major and minor league baseball players headed by Pat Rooney and Fern Cuza. The information he recovered includes dates of birth, Social Security numbers, canceled paychecks, and infant death records. The evidence was found in Dright's apartment after someone reported that Dright stole his identity. Whether any of the players have been affected is being investigated, but potential victims are being contacted.
Remember: Anyone can be a victim of identity theft. I hope this will be a lesson to SFX to be more careful when handling client data. These players trust this company, so their information should be treated with more care. I suppose I shouldn't be surprised by the careless practices of such companies. Reminder number two: Shred those documents before throwing them away.
Sunday, December 17, 2006
Secret Chat Rooms for Identity Thieves
Have you ever wondered how so many identity thieves obtain the information necessary to take over someone's finances. Sure, many will do the foot work using the methods I've discussed earlier such as mail theft, phishing scams, card skimmers, dumpster diving, etc. However, it isn't always necessary to go to that kind of trouble when you can use the information someone else has obtained and sold. There are online communities that do just that. Sell identities.
There are online message boards and chat rooms where social security numbers, birth dates, credit card numbers, and bank account details are exchanged. These websites are nearly impossible for the even the most savvy of web users to find, but they exist with hackers selling identifying information amongst one another. A skilled identity thief can cost a victim thousands of dollars while only being charged a few dollars for a credit card number.
While this is obviously disturbing, it doesn't surprise me. Identity theft becomes easier with our current technology. So those collecting more information than they can use will gladly pass it along for a few extra dollars, and entire underground communities are doing this. It makes me hope my information is being sold on these sites.
There are online message boards and chat rooms where social security numbers, birth dates, credit card numbers, and bank account details are exchanged. These websites are nearly impossible for the even the most savvy of web users to find, but they exist with hackers selling identifying information amongst one another. A skilled identity thief can cost a victim thousands of dollars while only being charged a few dollars for a credit card number.
While this is obviously disturbing, it doesn't surprise me. Identity theft becomes easier with our current technology. So those collecting more information than they can use will gladly pass it along for a few extra dollars, and entire underground communities are doing this. It makes me hope my information is being sold on these sites.
Thursday, December 14, 2006
Boeing Laptop Theft Puts Thousands at Risk
Company laptop thefts are usually the result of carelessness on the part of the employee. This was the case with the latest Boeing laptop theft. The laptop was stolen earlier this month when an employee left it unattended. The stolen laptop contained the names, addresses, and Social Security numbers of 382,000 current and former Boeing employees, leaving these people at risk of identity theft.
A Boeing spokesman insisted that the laptop was turned off at the time of the theft, and required a password to access files so the information could not be accessed easily. How comforting is that for current and former Boeing employees? It wouldn't be enough for me, and the company is taking the necessary steps for those who feel the same way. Boeing has not only contacted those whose information may be compromised but also offered them credit monitoring for the next three years. Boeing has not said whether or not disciplinary action has been taken against the employee in question (I'd hope they are).
However, the most disturbing thing about it is that this is not the first such occurrence from Boeing in recent years, but the third. This is obvious carelessness. Employees handling sensitive information need to be trained in proper security procedures and punished when these procedures are not followed.
A Boeing spokesman insisted that the laptop was turned off at the time of the theft, and required a password to access files so the information could not be accessed easily. How comforting is that for current and former Boeing employees? It wouldn't be enough for me, and the company is taking the necessary steps for those who feel the same way. Boeing has not only contacted those whose information may be compromised but also offered them credit monitoring for the next three years. Boeing has not said whether or not disciplinary action has been taken against the employee in question (I'd hope they are).
However, the most disturbing thing about it is that this is not the first such occurrence from Boeing in recent years, but the third. This is obvious carelessness. Employees handling sensitive information need to be trained in proper security procedures and punished when these procedures are not followed.
Tuesday, December 12, 2006
Security Breach at UCLA
Your information is only as safe as the databases it's kept in. You can take every precaution to secure your private information, but if there is a security breach at your job, bank, school, etc., you are still at risk. As I've said in the past, everyone is a potential identity theft victim. The best we can do is secure things at our end and try to minimize the damage if we are hit by identity thieves.
Most companies and institutions are aware of the sensitivity of customer and employee data and take precautions to keep this information out of the wrong hands. Unfortunately, they are not always successful (as we know from my insider identity theft post). The most recent breach was detected at UCLA. A hacker has gained access to a restricted UCLA database containing names and personal information of current and former students, faculty and staff, applicants for financial aid, and more. UCLA is notifying those who have information in that database and are investigating how much information the hacker gained and whether or not it has been fraudulently used. They have set up a website for those who were in the database as well as anyone else who feels they have been affected by this breach, and they recommend certain precautions be taken to protect one's credit.
While this is definitely not a positive thing, UCLA seems to be handling it properly. Notifying potential victims and recommending security precautions, such as placing a fraud alert on one's credit report to prevent or at least minimize fraudulent accounts being opened, is a good way to keep consumers' trust despite security issues. Now, let's see if they can take the precautions to prevent this from happening again.
If you are a current or former student of UCLA or think your name may have been in this database, check out this site.
Most companies and institutions are aware of the sensitivity of customer and employee data and take precautions to keep this information out of the wrong hands. Unfortunately, they are not always successful (as we know from my insider identity theft post). The most recent breach was detected at UCLA. A hacker has gained access to a restricted UCLA database containing names and personal information of current and former students, faculty and staff, applicants for financial aid, and more. UCLA is notifying those who have information in that database and are investigating how much information the hacker gained and whether or not it has been fraudulently used. They have set up a website for those who were in the database as well as anyone else who feels they have been affected by this breach, and they recommend certain precautions be taken to protect one's credit.
While this is definitely not a positive thing, UCLA seems to be handling it properly. Notifying potential victims and recommending security precautions, such as placing a fraud alert on one's credit report to prevent or at least minimize fraudulent accounts being opened, is a good way to keep consumers' trust despite security issues. Now, let's see if they can take the precautions to prevent this from happening again.
If you are a current or former student of UCLA or think your name may have been in this database, check out this site.
Tuesday, December 05, 2006
Password Habits and Identity Theft
For many products and services we buy or use on the web, registration is required, and we create a user name and password for each account. This is done for security purposes, so others can't purchase goods and services with your account or access your email. How secure are your passwords? Is it a word that could easily be guessed or associated with you? We tend create passwords that will be easy for to remember, which makes perfect sense, but it shouldn't be easy for someone else to guess or figure out. For instance, don't use your login name as your password, or easy to guess number sequences like "12345." Also avoid using any part of your name or your birthday. The digits of your passwords should include both letters and numbers, and they should be changed regularly. If your password can be easily guessed, you are at greater risk of becoming an identity theft victim.
Another common password habit we often develop is using the same password for multiple purposes. Once again, it seems convenient since it would be a royal pain to have to remember dozens of different passwords for all of the purposes we need them for. But how does this help your online security? Once your password is cracked, an identity thief can log into any or all of your accounts. According to a report published by the International Telecommunications Union, more and more people continue to use the same passwords for different accounts, and in doing so, putting themselves at greater risk of identity theft.
Sure, varying our passwords might seem inconvenient, but it is definitely worth the extra effort. Also, it might be a good idea for companies to do their part to prevent identity theft by coming up with another way to verify a user's identification.
Another common password habit we often develop is using the same password for multiple purposes. Once again, it seems convenient since it would be a royal pain to have to remember dozens of different passwords for all of the purposes we need them for. But how does this help your online security? Once your password is cracked, an identity thief can log into any or all of your accounts. According to a report published by the International Telecommunications Union, more and more people continue to use the same passwords for different accounts, and in doing so, putting themselves at greater risk of identity theft.
Sure, varying our passwords might seem inconvenient, but it is definitely worth the extra effort. Also, it might be a good idea for companies to do their part to prevent identity theft by coming up with another way to verify a user's identification.
Monday, December 04, 2006
LimeWire and Identity Theft
There's been a great deal of talk lately about peer-to-peer file sharing and identity theft. The reason, as you may have heard, is popular file sharing network LimeWire having recently been used to access files on users computers and open fraudulent accounts with this information. On Friday, eight people were indicted fo using LimeWire to help with their identity theft ring. The three key players, Michael Sarrasin, Shawn Adams and Tamara Stesneyr, were indicted on November 30 on 115 charges. They allegedly accessed personal account information of LimeWire users and used the information to open fraudulent accounts at Denver banks. The victims' losses are estimated at about $70,000.
Now, I'm not going into my thoughts on peer-to-peer file sharing (that's not what this blog is for), but we all know our computers and the data on them become more vulnerable when we go online, which is why we have all our anti-virus software and firewall. However, when you participate in peer-to-peer networks such as LimeWire, you give other users access to certain data on your computer (supposedly the folders designated for it), and you may want to take extra precautions to protect sensitive data. Encryption programs like PGP and TrueCrypt are recommended.
I'm not going to tell people what to do online, but I will tell you to protect your private information.
Now, I'm not going into my thoughts on peer-to-peer file sharing (that's not what this blog is for), but we all know our computers and the data on them become more vulnerable when we go online, which is why we have all our anti-virus software and firewall. However, when you participate in peer-to-peer networks such as LimeWire, you give other users access to certain data on your computer (supposedly the folders designated for it), and you may want to take extra precautions to protect sensitive data. Encryption programs like PGP and TrueCrypt are recommended.
I'm not going to tell people what to do online, but I will tell you to protect your private information.
Thursday, November 30, 2006
Identity Theft Through Email
As I've discussed in earlier posts, there are many ways you can become an identity theft victim. By now we know that your identity can be stolen if someone is able to access your credit card numbers, bank account numbers, and Social Security number. It may be simpler than that. What if someone else gains access to your personal email?
This can be more dangerous than it sounds. We send and receive sensitive information in our email more and more often. What is at risk here? When you sign up for an online vendor, don't you often receive an email confirming your user name and password? If you have a Paypal account, you log into it with your email address. What's to stop an identity thief from clicking on, "forgot password" and entering your email address. You might also be reminded that your Paypal account can only be confirmed with your bank account. What about Amazon? Once you order, they keep your credit card number on file. Your thief won't even need the credit card number to start spending. He'd just need to re-route the order as a gift delivery to have it sent elsewhere. I could go on, but you probably get the point by now. And if you're not convinced, check out this woman's experience after leaving her Hotmail account open on a public computer.
So what's to be done? That actually depends. Do you use free web-based email accounts? Do you use them for signing up for membership on the web and making online purchases? If so, you may not want to access them from a public computer. Sure, it's convenient, but at what cost? You may also consider changing your password often, and being careful to log out every time you use it. What about your personal email on your home computer? Do you have it set to automatically open when you start up your computer? That's something else you may want to consider. Anyone who enters your home (with or without permission) and sits down in front of your computer can view your email without even the benefit of a password.
Keeping your identity secure is not always convenient, but it pays off in the long run.
This can be more dangerous than it sounds. We send and receive sensitive information in our email more and more often. What is at risk here? When you sign up for an online vendor, don't you often receive an email confirming your user name and password? If you have a Paypal account, you log into it with your email address. What's to stop an identity thief from clicking on, "forgot password" and entering your email address. You might also be reminded that your Paypal account can only be confirmed with your bank account. What about Amazon? Once you order, they keep your credit card number on file. Your thief won't even need the credit card number to start spending. He'd just need to re-route the order as a gift delivery to have it sent elsewhere. I could go on, but you probably get the point by now. And if you're not convinced, check out this woman's experience after leaving her Hotmail account open on a public computer.
So what's to be done? That actually depends. Do you use free web-based email accounts? Do you use them for signing up for membership on the web and making online purchases? If so, you may not want to access them from a public computer. Sure, it's convenient, but at what cost? You may also consider changing your password often, and being careful to log out every time you use it. What about your personal email on your home computer? Do you have it set to automatically open when you start up your computer? That's something else you may want to consider. Anyone who enters your home (with or without permission) and sits down in front of your computer can view your email without even the benefit of a password.
Keeping your identity secure is not always convenient, but it pays off in the long run.
Monday, November 27, 2006
Identity Theft Methods: Shoulder Surfing
You never know who is watching. Most people who appear to be minding their own business while you are conducting your own business probably mean you no harm. But that's not the case for everyone. Some are watching, waiting for you to reveal important information. This identity theft method can be an effective way to gather information. Shoulder surfing involves the identity thief observing and/or eavesdropping on a potential victim to gather information such as PINs, account numbers, credit card numbers, passwords, etc.
The shoulder surfer will stand behind you at the grocery store or ATM, watching carefully as pull out your credit card or type in your PIN, maybe even taking pictures with a camera phone. Or he could be watching from farther off with binoculars. The shoulder surfer may also be sitting nearby at your favorite coffee shop, stealing glances at your fingers as you type in passwords on your laptop and eavesdroping on cell phone conversations for useful information. While most people around you are not trying to steal your identity, it is always best to act with some degree of caution.
If your identity thief has some hi-tech surveillance gear, it may be hard to hide from him, but here are a few tips to make it harder for the average shoulder surfer to steal your information:
* Do not write down passwords and PINs. As soon as you pull out that slip of paper, you make the shoulder surfing so much easier.
* Be aware of your surroundings and make note of those around you.
* If you are using a laptop in public, try to point the screen away from public view.
* Computer users should make user names and passwords as long and difficult as possible. Changing passwords frequently is also wise.
* While many ATMs are now modified to combat shoulder surfing, it is best to use the ATM as quickly as possible, and do not leave receipts behind.
It's always best to be cautious when it comes to your personal information. After all, you never know who is watching your back.
The shoulder surfer will stand behind you at the grocery store or ATM, watching carefully as pull out your credit card or type in your PIN, maybe even taking pictures with a camera phone. Or he could be watching from farther off with binoculars. The shoulder surfer may also be sitting nearby at your favorite coffee shop, stealing glances at your fingers as you type in passwords on your laptop and eavesdroping on cell phone conversations for useful information. While most people around you are not trying to steal your identity, it is always best to act with some degree of caution.
If your identity thief has some hi-tech surveillance gear, it may be hard to hide from him, but here are a few tips to make it harder for the average shoulder surfer to steal your information:
* Do not write down passwords and PINs. As soon as you pull out that slip of paper, you make the shoulder surfing so much easier.
* Be aware of your surroundings and make note of those around you.
* If you are using a laptop in public, try to point the screen away from public view.
* Computer users should make user names and passwords as long and difficult as possible. Changing passwords frequently is also wise.
* While many ATMs are now modified to combat shoulder surfing, it is best to use the ATM as quickly as possible, and do not leave receipts behind.
It's always best to be cautious when it comes to your personal information. After all, you never know who is watching your back.
Subscribe to:
Posts (Atom)
