Showing posts with label social security number. Show all posts
Showing posts with label social security number. Show all posts

Wednesday, November 28, 2012

You’ll Shoot Your Eye Out…

…is probably one of the most memorable lines of any Holiday Classic.  Of course I’m referring to A Christmas Story, where a young Ralphie tries to convince his parents, teachers and Santa that the Red Ryder BB Gun is the perfect present.  I don’t know of there was a warning label on the 1940’s edition box but it is a good reminder from a security perspective that often we, meaning humans, are our own worst enemy when it comes to protecting ourselves.  Every year about 100 or so homes  burn down due to fried turkeys.  A frozen one with ice crystals straight in or the ever famous too much oil that overflows and toasts everything it touches.  Even with the warnings and precautions, humans still take the risk.  Warning: You can get burned badly.

As if the RSA breach wasn’t warning enough about the perils of falling for a phishing scam, we now learn that the South Carolina Department of Revenue breach was also due to an employee, and it only takes one, clicking a malicious email link.  That curiosity lead to over 3.8 million Social Security numbers, 3.3 million bank accounts, thousands of credit cards along with 1.9 million dependant’s information being exposed.  While the single click started it all, 2-factor authentication was not required and the stored info was not encrypted, so there is a lot of human error to go around.  Plus a lot of blame being tossed back and forth – another well used human trait – deflection.  Warning: Someone else may not protect your information.

While working the SharePoint Conference 2012 in Vegas a couple weeks ago, I came across a interesting kiosk where it allows you to take a picture and post online for free to any number of social media sites.  It says ‘Post a picture online for free.’ but there didn’t seem to be a Warning: ‘You are also about to potentially share your sensitive social media credentials or email, which might also be tied to your bank account, into this freestanding machine that you know nothing about.’  I’m sure if that was printed somewhere, betters would think twice about that risk.  If you prefer not to enter social media info, you can always have the image emailed to you (to then share) but that also (obviously) requires you to enter that information.  While logon info might not be stored, email is.  Yet another reason to get a throw away email address.  I’m always amazed at all the ways various companies try to make it so easy for us to offer up our information…and many of us do without considering the risks.  In 2010, there were a number of photo kiosks that were spreading malware.  Warning: They are computers after all and connected to the internet.

Insider threats are also getting a lot of attention these days with some statistics indicating that 33% of malicious or criminal attacks are from insiders.  In August, an insider at Saudi Aramco released a virus that infected about 75% of the employee desktops.  It is considered one of the most destructive computer sabotages inflicted upon a private company.  And within the last 2 days, we’ve learned that the White House issued an Executive Order to all government agencies informing them of new standards and best practices around gathering, analyzing and responding to insider threats.  This could be actual malicious, disgruntled employees, those influenced by a get rich quick scheme from an outsider or just ‘compromised’ employees, like getting a USB from a friend and inserting it into your work computer.  It could even be simple misuse by accident.  In any event, intellectual property or personally identifiable information is typically the target.  Warning: Not everyone is a saint.

The Holidays are still Happy but wear your safety glasses, don’t click questionable links even from friends, don’t enter your logon credentials into a stray kiosk and a third of your staff is a potential threat.  And if you are in NYC for the holidays, a limited run of "Ralphie to the Rescue!" A Christmas Story, The Musical is playing at the Lunt-Fontanne Theatre until Dec 30th.

ps

References

Technorati Tags: F5, smartphone, insiders, byod, Pete Silva, security, business, education, technology, a christmas story, threat,mobile device, kiosk, malware, iPhone, web, internet, phishing

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Tuesday, February 8, 2011

Identity Theft: Good News-Bad News Edition

So which would you like first? 

Javelin Strategy & Research said identity theft incidents were down 28% in 2010 (vs. 2009) according to their latest consumer survey.  This is the lowest level since 2007 and about 3 million less victims than in 2009.  They partially attribute this to a decline in industry reported data breaches going from 604 (221 million exposed records) to 404 (26 million exposed records) in 2010 along with economic conditions, better security measures and busts by law enforcement playing a major role.  If you have an existing credit card account, there’s good news on that front also – fraud from existing credit cards was down 38% ($14 billion) compared to 2009 ($23 billion).  New account fraud, where the victim might not have any idea than an account was opened in their name, took top honors in types of fraud with $17 billion siphoned.  ‘Change in physical address’ was the No. 1 method of account takeover reported by victims.

Don’t drop the confetti yet, however.  While the overall numbers look encouraging, the devil is in the details as the cliché goes.  Even thought the overall numbers are down, the consumer out-of-pocket expense to resolve ID fraud went from $387 per incident to $631 in 2010 – a 63% increase.  Because criminals are using more clever ways to steal you data, you have to spend more time fixing the issue and the costs can grew.  Your friends and family are also sticking it to ya. ‘Friendly Fraud,’ when someone you know steals your info, increased 7% with 41% of this batch saying their SSN was stolen.

They also found a correlation between retail sales and identity fraud.  When sales are up, fraud is down and when sales are down, fraud goes up, says James Van Dyke, founder of Javelin Strategy & Research.  He feels that when the economy is doing well and people can make purchases with their own money, they are less likely to steal.  Add to that, better security measures are in place and people are more aware of identify fraud, thus they keep a better eye on questionable transactions.  Another bad sign is that while credit card fraud has dropped, debit card fraud went from 26% to 36% in a year.  This could be due to more people using debit cards rather than credit for purchases but also due to debit’s lower level of protection when it comes to fraud. Some would question the validity of the survey since it is a ‘self-report’ telephone survey and bank data would argue that fraud is actually up in many areas.  There are many more intriguing tidbits in the report and you can check out Javelin’s report with a couple interesting charts here.

ps

Related:

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Technorati Tags: F5, infrastructure 2.0, integration, cloud connect, Pete Silva, security, business, education, technology, application delivery, intercloud, cloud, context-aware, infrastructure 2.0, automation, web, internet, cybercrime, security, holiday shopping, identity theft, scam, email, data breach

Thursday, December 9, 2010

Identity Theft Roundup

I’m on a ID fraud kick lately and there are quite a few stories of late about identity theft.  Here are just a few:

House Approves Red Flags Exemptions – In January 2008, the Red Flag Rule went into existence which said that organizations (mainly banks and financial institutions) that extend credit to have a written Identity Theft Prevention Program designed to detect identity fraud on a day to day basis.  This new bill would except certain businesses like physicians and hospitals from having to abide by the rule.  Sen. Dodd (D-Conn) said that the bill, ‘makes clear that lawyers, doctors, dentists, orthodontists, pharmacists, veterinarians, accountants, nurse practitioners, social workers, other types of healthcare providers and other service providers will no longer be classified as 'creditors' for the purposes of the Red Flags Rule just because they do not receive payment in full from their clients at the time they provide their services, when they don't offer or maintain accounts that pose a reasonably foreseeable risk of identity theft.’  So if you don’t have a foreseeable risk of ID theft, I guess you don’t have to pay attention.

Minn. man pleads guilty in ND identity-theft case – 20 felonies, 19 counts of ID theft, 1 theft charge and a 28 year old only gets a year in jail and 5 years probation.  He stole the SSN and names of 49 people.
Military at high risk for identity theft – Did you know that military personnel are required to use their SSN for silly things like checking out a basketball at a gym or to identify their laundry bag?  I didn’t and it is becoming a problem since most locations do not take ‘care’ of that personal info.

Fla woman stole identity, paid for breast implants – You might remember this one where a woman in Miami stole someone’s identity and used fake credit cards to get her fake, well, you know.  She also racked up $20,000 in new furniture.  She got 30 months in a federal pen for that one.  If you were wondering, she said she needed them since her old ones were giving her breathing problems.

Kent couple arrested for identity theft, prescription forgeries – While investigating a prescription forgery ring, Kent Police uncovered a nice little counterfeiting operation run out of an apartment building.  Since the suspect was a convicted felon with a firearm, SWAT arrived and took the couple without incident.  Wait, fake prescriptions here and a new law that says medical facilities can pass on Red Flag?  Hum.

Man arrested in financial identity theft – It’s not just strangers getting hit – here a 20 year old opened a credit card account in his grandparent’s names and just added himself as an authorized user.  $4000 worth of cigs, alcohol and electronic equipment later, he was in jail.

Queens D.A. Warns: Beware New ID Theft – At least in New York, thieves are using what’s called a ‘spoof card’ to get personal information.  Spoof cards are like calling cards but allows the caller to enter whatever number they want on the receiver’s caller ID.  Oh, a call from the bank.  They act/sound all authoritative on the phone and people spill the info.  This is a great opportunity to turn the tables – ask the caller to validate a piece of information.  To validate the caller, ask a couple questions that the bank usually asks you like, last transaction or first dog’s name.  Or, just say, ‘I’ll call you back at the number on your web site.’

ID theft alleged at Libertyville driver's license facility – A 22 year employee at an Illinois driver’s license facility gets caught giving other’s personal information to thieves.  Those thieves then opened credit card accounts with the info.  He’s facing 3 years in prison but shows just how slippery your personal info is in the hands of others.

More to come…

ps

Related:
twitter: @psilvas

Technorati Tags: F5, infrastructure 2.0, integration, cloud connect, Pete Silva, security, business, education, technology, application delivery, intercloud, cloud, context-aware, infrastructure 2.0, automation, web, internet, cybercrime, security, holiday shopping, identity theft, scam, email, data breach

Friday, December 3, 2010

Synthetic Identity Theft: The Silent Swindler

As a brief follow up to yesterday’s Got a SSN I Can Borrow, I came across this story from The Red Tape Chronicles saying the odds that someone else has used your Social Security Number is One in 7.  ID Analytics, a data collection and customer behavior analytics firm, works with organizations, including the US Social Security Administration, to detect Identity-Based fraud; separating the true customers from the impostors.  They’ve analyzed 290 million Social Security numbers and found that 40 million of those numbers have been connected to more than one name; basically, 40 million of us are sharing identities with someone else.  They also indicated that 6% of the total population, or 20 million Americans, have multiple SSNs associated with their name.  Often, it might just be an incorrect entry or typo into a system, but it can also be when criminals apply for credit at multiple banks changing 1 digit with each application – around 20% are deliberate misrepresentations.  When the system propagates either the error or intentional entry, that second SSN is forever associated with the individual and thus Synthetic.  Synthetic Identities are created when an unassigned number gets attached to someone and a new entity is created within the credit system.  Some people have 4-5 SSNs connected to their name and 5 million SSNs are connected to three or more people. 

Synthetic Identity Theft is typically when a criminal uses either totally fake or a mixture of fake and real information to create a new identity.  Usually, a fraudster will use a real SSN with a fake or different name that is associated with that number.  Synthetic Identity Theft is difficult to track, detect and report since individuals are usually not aware it is occurring since it doesn’t appear on a credit report and because a combination of names, addresses, SSNs and so forth are used, it is usually does not match up with a single, individual consumer to claim fraud.  Most go unreported and become ‘charge-offs’ within the financial institution well before anyone is aware of the problem.

Protect yourself by shredding mail and sensitive documents since thieves will dig through trash to find pieces of information they can use; review your Social Security benefits booklet every year to check if the income reported is actually what you made; and stay on top of your credit, reporting any discrepancies.  The free AnnualCreditReport.com is the official site to help consumers to obtain their free credit report each year.  I tend to grab all three at once since I subscribe to a credit monitoring service, but if you don’t – stagger each of three reporting agencies reports throughout the year to see any changes since the last credit file disclosure.  If necessary, you can also put a Security Freeze on your credit report.  Finally, don’t give out your Social Security number if you don’t have to – if someone asks, like a doctor’s office, just respectfully decline.  I have never had a problem telling someone that I prefer not to give out that sensitive information.  Heck, you could probably even say you’ve been a victim of Synthetic Identity Theft.

ps

Related:
twitter: @psilvas

Technorati Tags: F5, infrastructure 2.0, integration, cloud connect, Pete Silva, security, business, education, technology, application delivery, intercloud, cloud, context-aware, infrastructure 2.0, automation, web, internet, cybercrime, security, holiday shopping, identity theft, scam, email, data breach

Thursday, December 2, 2010

Got a SSN I can Borrow?

Apparently, I can use my own name and your Social Security Number to get a job or buy a car and it is not an identity theft crime.  Really.  This is according to a recent Colorado Supreme Court ruling.  They ruled that, ‘that using someone else’s Social Security number is not identity theft as long as you use your own name with it.’  Seriously.  The case in question involved a man who used his real name but someone else’s Social Security number to obtain a car loan.  The court said that since he used his real name, along with other identifiable pieces of information, he wasn’t trying to impersonate someone else.  The SSN info was just the ‘lender’s’ requirement and not a ‘legal’ requirement.  The defendant said that he fully intended to pay the loan back and wasn’t trying to avoid the bills.  There was another case where a man used a fake SSN to get a job at a steel plant in Illinois.  He presented a Social Security card with his name but a fake SSN.  Since he didn’t know that the number was fake and belonged to another person, the US Supreme Court ruled that he also didn’t break any federal ID theft laws since he did not ‘knowingly’ use another person’s number.  He just ‘borrowed’ it.  He could have just written 9 random numbers that may or may not have been tied to someone’s identity or he could have bought it from a broker, not knowing it was either fake or stolen.

These decisions contradicted previous rulings in Missouri, California, the Midwest, the Southeast and many other regions.  It also left folks scratching their heads wondering just what were the courts thinking.  Their logic is that, ‘(The suspect) claimed that the government could not prove that he knew that the numbers on the counterfeit documents were numbers assigned to other people….The question is whether the statute requires the government to show that the defendant knew that the ‘means of identification’ he or she unlawfully transferred, possessed, or used, in fact, belonged to ‘another person.’ We conclude that it does.’  I understand that there is a fine legal line between malicious intent and an uninformed accident but if you make up a number or obtain it by improper means, it’s still fake, false and fraudulent.  I also understand that there are criminal organizations that prey on immigrants who might not fully understand the ramifications and are told that it is legitimate.  We’ve all, at some point, been lured, duped or convinced that something we were obtaining was the real thing.  We’re told with great conviction that it is authentic and because we want to believe, we do.  When the truth is exposed, the ‘I didn’t know’ defense is obviously the most common and very well might be the honest answer.  Maybe because I focus on Information Security and a bit skeptical myself, I also gotta believe that there’s that little nudge, intuition or feeling in your belly telling you that something isn’t right.  I know because I’ve ignored that gut-check and got burned.  Just because something is ‘not-illegal’ does not make it the right thing to do. 

I’m not claiming to be a Mr. Goody-Two-Shoes and have certainly made my fair share of mistakes along with doing things I know to be wrong, legal or not.  I also know that always acting in the ‘proper’ way or doing the ‘right’ thing is difficult sometimes.  That’s what makes us human.  We might seek the easiest, least complicated and sometimes slightly unethical way of accomplishing something.  Sometimes we have to break the law to ensure the safety of others – like speeding to the Emergency Room if your wife is giving birth or a person is bleeding to death – but those are extenuating circumstances and doesn’t necessarily cause harm to others; unless, of course, you run somebody over on the way to the hospital.  There are victims with this SSN borrowing since the real person may not ever know that their information was used since it won’t show up on a credit report.  The trouble starts when a loan or tax payment is missed and by then, it’s too late.  The courts have had difficulty over the years trying to interpret certain laws as technology whizzes by but, at least in the States, our Social Security Number is one of our unique, primary identifiers and should be protected.  Incidentally, BIG-IP ASM does have a cool feature called Data Guard that can mask sensitive data from being leaked from the web application.  Data Guard helps protect against information leakage like the leakage of credit card or Social Security numbers.  Instead of sending the actual data to the client, ASM can respond by replacing the sensitive data with asterisks, or block the response and sending out an alert.  You can also decide what ASM should consider as sensitive: credit card numbers, Social Security numbers, or responses that contain a specific pattern.

ps

Related:

twitter: @psilvas

Technorati Tags: F5, infrastructure 2.0, integration, cloud connect, Pete Silva, security, business, education, technology, application delivery, intercloud, cloud, context-aware, infrastructure 2.0, automation, web, internet, cybercrime, security, holiday shopping, identity theft, scam, email, data breach