Custom Search
Showing posts with label identity theft. Show all posts
Showing posts with label identity theft. Show all posts

August 14, 2017

Equifax Continues to Profit from Identity Theft

Equifax has purchased identity theft protection company ID Watchdog for approximately $63 million.  ID Watchdog is a company similar to LifeLock that consumers and/or businesses pay to monitor their credit and "protect" them from identity theft.

Once again, Equifax is turning identity theft into a profit center for its bottom line.

Equifax is charged by the Fair Credit Reporting Act to perform reasonable investigations of disputes made to it by consumers regarding inaccuracies on their Equifax credit reports.  Many times these errors are actually credit cards, car loans or mortgages opened fraudulently as a result of the theft of the consumer's identity.  Sometimes they are collection accounts placed on the consumer's credit report for the purpose of collecting a debt that was fraudulently incurred by the identity thief in the consumer's name.

Unfortunately for the victims of identity theft, Equifax often does not properly investigate the disputes it receives, particularly those resulting from identity theft.  Instead of investing in its investigation department to make it better and thereby possibly comply with the Fair Credit Reporting Act and eliminate a lot of the problems caused by identity theft, Equifax instead turns identity theft into a means to profit by investing in a company that sells identity theft protection.

If Equifax consistently did the job that it is required by the Fair Credit Reporting Act to do and actually investigate the disputes it receives, consumers would not need to pay for additional identity theft protection or pay for multiple credit reports per year or monitoring services to monitor their credit.  But instead of doing what it is required to do, Equifax instead chooses to profit from the misery of identity theft victims.

Equifax makes millions each year from the sale of credit monitoring services and the sale of extra credit reports to consumers worried about the contents of their credit report because their identities have been stolen.  A quick glance at Equifax's website makes it clear that Equifax's emphasis is on profiting from credit monitoring rather than properly investigating consumer disputes.  Equifax sells no less than 5 different plans to "monitor" and "protect" the contents of your credit report.  They give these plans catchy names like Premier Plans, Advantage Plans, Family Plans, Patrol and even Patrol Premier, but they all have the same goal, to play on consumers' fear of identity theft to line Equifax's pockets.

The purchase of ID Watchdog provides Equifax with another mechanism to use to prey on consumers' fears.  Instead of fixing the problem by deleting fraudulent accounts when disputed, Equifax wants consumers scared so they will buy more credit reports and purchase more monitoring plans.  Not that Equifax is likely to delete any fraud accounts found by the consumers using Equifax's monitoring products.

Equifax needs to be held accountable for its decision to put its profits over the well being of consumers.  The government has put in place the mechanism to hold Equifax accountable when it passed the Fair Credit Reporting Act.  Now it is up to juries and judges to show Equifax and the other credit bureaus that putting profits over people will not be tolerated.

August 07, 2017

Nigerian Citizen Living in North Carolina Arrested for Phishing Scheme Targeting Connecticut and Minnesota School Districts


Nigerian citizen Daniel Adekunle Ojo was arrested last week at his residence in Durham, North Carolina.  He is being charged with fraud and identity theft charges filed by Connecticut U.S. Attorney Deirdre Daly.  

According to prosecutors, an employee of the school district in Glastonbury, Connecticut was duped by a phishing scam which Ojo was allegedly behind.  A phishing scam is one where an e-mail that appears to be legitimate asks for private information or asks the recipient to log into an account via a link in the e-mail that leads to a fake site.  Any information obtained via a phishing e-mail can then be used to commit financial crimes.

In the scam in this case, Ojo allegedly spoofed the e-mail address of one school employee to make it appear that that school employee had e-mailed the duped school employee requesting tax information for approximately 1600 school district employees.  Not realizing that the e-mail was not legitimate, the school employee provided the requested information, which was then allegedly used to file 122 bogus tax returns for nearly $600,000.00 in tax refunds.

At least six of the fake tax returns were successful, resulting in $37,000 in refunds being electronically deposited into various bank accounts.

It is also believed by authorities that Ojo is not a first time phisher.  Ojo's e-mail address is allegedly linked to a phishing scam in Bloomington, Minnesota earlier this year and that he may have been involved in a similar phishing scheme that targeted the school district in Groton, Connecticut.

A federal magistrate judge has ordered that Ojo be transferred to Connecticut for prosecution.

My advice on phishing:  Never, ever, ever click a link in an unsolicited e-mail even if it looks like it legitimately came from a company with which you do business.  Phishers used to be easy to spot due to their poor grammar and odd phrasing used in their e-mails.  But they have gotten better and thus less easy to spot.  So think hard before you click.

August 06, 2017

Former Member of U.S. Air Force Sentenced for Identity Theft

A Chicago federal judge has sentenced former U.S. Air Force member Ronnie Allen II to four years in prison for identity theft.  Allen, a 28 year old from Greensboro, North Carolina, used his position in the Air Force to illegally steal an Air Force personnel roster.  The roster contained the private identifying information of approximately 1400 Air Force members stationed in Idaho at Mountain Home Air Force Base.  The personal identifiers contained on the illegally obtained roster included the names, Social Security numbers and dates of birth of the Air Force personnel.

According to prosecutors, Allen distributed the private information contained on the stolen personnel roster with the hopes of profiting financially from the information's dissemination.  The information was then used to file tax returns and fraudulently open financial accounts using the names and other personal identifiers of the Air Force personnel on the list.  It is unclear how many Air Force members were affected by the dissemination of their personal identifiers.

Identity thieves often open credit cards and obtain loans using the names and other personal identifiers of their victims.  The criminals then make purchases using the credit cards and loans.  The charges are never paid, thereby ruining the victims' credit history while the criminals profit without any consequence unless caught.

Forged tax returns are a slightly different version of identity theft and has become more prevalent in recent years.  Instead of opening new financial accounts, the identity thief completes a fake tax return in the name of his or her victim.  This is usually done as early in the year as possible before the victim files his or her real return.  The taxes on the forged tax return are calculated in such a way as to result in a refund, which is then received by the identity thief instead of the victim.  The IRS has been cracking down on this type of identity theft over the past few years, including issuing pin numbers to persons who have been victims in the past to prevent the crime from reoccurring.

While four years seems like a light sentence to me (the damage to the victims' credit histories will last longer than that), it is good to see an identity thief like Allen being forced to spend at least some time behind bars.

February 26, 2013

Identities stolen at a pace of one every three seconds in 2012!


One Mississippi ... Two Mississippi ... Three  Mississippi.  Uh oh, someone's identity was just stolen.

The crime rate for identity theft rose to a three year high in 2012 with more than 5% of the adult population in the United States having their identities stolen last year. That's 12.6 million consumers.  That also means that an identity was stolen every three seconds last year.

Yes, every three seconds someone in the U.S. fell victim to the life changing, financial ruining, most under prosecuted crime in the nation. Not to mention a crime that is nearly impossible to recover from absent a lawsuit due not to the complexity of the crime but the utter disdain for consumers held by the consumer reporting agencies and the furnishers of credit information, i.e. those charged by the Fair Credit Reporting Act with investigating credit errors but instead refer those investigations to out sourced, less than minimum wage, third world citizens who are not even given the authority or tools to investigate or correct any error.

The percentage of identity theft rose to more than 5% in 2012 , up from 4.9% in 2011 and 4.35% in 2010. Identity thieves made off with over $21 billion in fraudulently obtained goods and cash, the most since 2009. Also, not surprising, the same study revealed that the most important information to keep private is your social security number. According to the study, consumers whose social security number were compromised were five times more likely to have their identity stolen than an average consumer. So keep your social security number private as much as you can. And, if you are one of the unlucky 5%, be sure to hire the Kittell Law Firm and regain your correct financial reputation.

February 04, 2013

Identity Theft News

Interesting Identity Theft news found on the Kittell-law.com blog.  Click here to read - http://www.kittell-law.com/blog/2013/02/04/bullet-points-identity-theft-news-121708

January 22, 2013

Identity theft insurance? Is it really worth it?


Is Identity Theft Insurance worth the money?  Not really.

In fact, is it even insurance?  Insurance is supposed to pay for things to be replaced or repaired in the event something bad happens.  Home insurance pays for repairs to your house after its damaged by a fire or a storm.  Flood insurance will pay to replace something damaged in a flood.  Car insurance will pay to repair your car after a wreck.  Life insurance replaces the income of a deceased family member.

Identity theft "insurance," on the other hand, does little to repair the damage caused by identity theft.  Sure, it will reimburse a victim for some out of pocket costs, such as certified mail costs and notary charges.  At a cost of $15.00 to $20.00 a month, identity theft insurance seems like its a good deal.  But its not.  It covers little.  

Identity theft insurance does nothing to fix the main thing damaged by identity theft - the victim's good name.  Identity theft insurance does nothing to correct the errors on the victim's credit reports caused by the appearance of the numerous fraud accounts opened in the victim's name.  It does not eliminate from the victim's criminal record any charges for crimes committed in the victim's name.  It does not reimburse the victim for the mental anguish and stress caused by dealing with uncaring credit bureaus, fraud credit grantors and relentless collection agencies.  Nor does identity theft insurance reimburse victims for the embarrassment they suffer when denied credit due to the unpaid fraud accounts appearing on their credit reports.

Instead of wasting money on identity theft insurance, consumers should save that money and instead be proactive about protecting their Social Security Number and disputing the fraudulent accounts if and when their identities are stolen.  Then, if the credit bureaus and the fraud credit grantors fail to fix the errors caused by the identity theft, the consumer should hire an experienced Fair Credit Reporting Act attorney (like me!) and sue the credit bureaus and credit grantors using the Fair Credit Reporting Act.  Not only does filing such a lawsuit not cost the consumer his or her hard earned money (like identity theft insurance does), if the consumer prevails at trial or settles with the credit bureau, the consumer receives compensation for all he or she has gone through.  

Do yourself a favor.  Don't pay for identity theft insurance and, if you feel like you must, simply add it as a rider to your existing homeowner's insurance.  That's a much cheaper option (usually $20 or $30 a year, rather than a month) and provides the same level of coverage.  And, if you end up being a victim of identity theft, don't just look to your identity theft insurance for reimbursement.  Hire an experienced consumer attorney who can get your credit report corrected and get you fair compensation for your damages.

January 15, 2013

What the Smurf?! Dr. Smurf guilty of identity theft!

A Lithuanian hacker who used the screen name "Dr. Smurf" has been convicted of identity theft and sentenced to five years in prison.  Tadas Petrauskus, 23, of Brick, New Jersey, sold passwords to an unidentified western Pennsylvania person that could have potentially given the buyer access to the financial accounts of approximately 10,000 people.  

Petrauskus was caught at John F. Kennedy International Airport after flying in from Belgium in the possession of a laptop containing many credit card numbers in its memory.  Dr. Smurf was sentenced by U.S. District Judge Nora Barry Fischer.  Hopefully his five year sentence will seem like a Smurfing long time!

January 13, 2013

Tax Refunds for Identity Theft Victims Likely to be Delayed


Are you an identity theft victim?  Well, you are likely to be more victimized this tax season.

Last year, identity theft victims were told to expect to wait 180 days (or approximately 6 months) for their tax returns to be processed.  According to Taxpayer Advocate Service, an IRS watchdog group, the delay this year could be similar or even longer than last year's wait.

The IRS waits to give tax refunds until it completes a load of internal paperwork, even if the IRS has already determined that the identity theft victim is entitled to a refund.

When the Taxpayer Advocate Service reported to Congress recently, it recommended faster refund access and setting up a single point of contact for victims.  However, the IRS contends that its current system is effective and that it has improved procedures for stopping identity theft.  Let's hope so, because tax return identity theft has been rampant the last few years.

January 09, 2013

10,000 Active Identity Theft Rings in the U.S.?!


According to an article written by Bob Sullivan for nbcnews.com, there are 10,000 identity theft rings active in the United States, primarily in the Southeast, including a hot spot right down the road from me in Greenville, Mississippi.  Very interesting read.  I have reposted Mr. Sullivan's article below and here is a link to his article - http://redtape.nbcnews.com/_news/2012/11/14/15144350-10000-id-fraud-gangs-active-in-us-especially-the-southeast-study-finds?lite

"There are 10,000 active identity theft crime rings across the United States, with the greatest concentration in a "ring of fraud" that stretches across the Southeast from Virginia to Mississippi, according to a new report by fraud-fighting firm ID Analytics.

A majority of these rings are what the firm calls "Friends & Family" groups, not professional criminal organizations, the report concludes. The rings are most highly concentrated in Washington D.C.; Detroit; Tampa, Fla.; Greenville, Miss., Macon, Georgia; and Montgomery, Ala., the report found.

ID Analytics compiled the results by examining its massive database of credit applications and other identity “risk events,” which now includes 1.7 billion entries.  The firm cross references credit applications from major banks, auto dealers, wireless firms and other credit grantors looking for evidence of systematic identity fraud. Previously, ID Analytics has used its data to help identify tens of thousands of registered sex offenders who are living digital double lives, and millions of U.S. residents who are"sharing" their Social Security number with someone else.

The crime ring project is a first, says head researcher Stephen Coggeshall.

"This is first time we raised it up a level and looked at how these people are connected," he said. "I am surprised at how many rings there are."
A "crime ring" was defined by ID Analytics as two or more individuals working in concert, repeatedly submitting fraudulent applications in an attempt to commit fraud. Collusion was determined by noting when multiple members of the rings used similar personal identifying information, such as Social Security numbers, in fraud attempts.
Not every fraudulent credit application is successful; many are detected and denied by lenders' fraud-fighting tools.  Still, the attempts indicate an active fraudster at work.
Examples of fraud rings published in the report read like short mystery novels.
One four-person group in the Indianapolis-area --  made up of two members in their 70s and two 48-year-old women -- has submitted 345 fraudulent credit card applications.  The individuals’ names were not provided by ID Analytics because they have not been charged with any crime.
Another six-member ring is run by a 52-year-old woman and her sister and operates out of an apartment complex in Washington, D.C., the report said.  
"Together this team has used 10 SSNs and multiple first names, last names and  birthdates to commit fraud," the report says. "In addition to identity manipulation, this group is also applying for accounts using stolen identities (identity theft). They have completed more than 69 credit card applications and defrauded four victims, including two deceased persons."
Near McCallum, Texas, two families appear to have teamed up and specialized, with one member targeting wireless providers and two others focusing on retail and bank credit cards, the report said.  Together they have submitted 142 fraudulent applications.
"It appears that the children in the group are stealing their own parents’ identities," it added.
While traditional organized crime and drug crime rings also form ID fraud rings, Coggeshall said the most surprising result of his research was the prevalence of what he called "Friends and Family" fraud rings.  More than half of the rings include multiple family members.
"This is a strong indication that more than half are not what we’d think of as professional groups," he said. "(It’s) a family or an innocuous neighbor committing fraud.”  
"The family dynamics is a big surprise," he said. "Rather than seeing a lot of what I would say are unrelated people collaborating, we see a lot of families doing this, sharing information. Siblings and parents toggling SSNs systematically, sharing dates of birth and committing identity theft."
Coggeshall said he excluded those family groups who might be sharing identities to simply avoid bad credit histories -- a brother and sister living together, and the brother allowing the sister to use his Social Security number to obtain cell service, for example.
"Every one of the (10,000) is committing fraud with the intent to not pay," he said, and doing it at least 10 times or more.
Another surprise in the report: Numerous studies have shown that the rate of identity theft is higher in urban areas, but the number of crime rings is much higher in rural areas, Coggeshall said.
"The map is a surprise, the systematic collusion in the South," he said.
One potential explanation:  Identity theft and methamphetamine crime rings often go hand in hand, with meth addicts trading stolen mail and credit card applications for drugs.  Meth addiction rates are also higher in rural areas. 
But that doesn't completely explain the ID fraud rings to Coggeshall.
"These rural areas must make it easier for people to collude, for some reason," he said.
ID Analytics, which was acquired last year by identity theft monitoring service LifeLock Inc., has indicated a willingness to share the crime ring data with law enforcement, but Coggeshall said he was unaware of any arrests that have resulted from the research.
That level of information sharing is in its early stages, he said.
"It's not our business to (encourage law enforcement to act). I would say law enforcement is very busy and has to pick priorities. ... We do this for our commercial clients. We are having conversations with law enforcement agencies, but they are not too far along. I would say law enforcement is cautiously interested."

May 09, 2012

Inmates - the latest type of identity theft VICTIM?!

This is a new one on me.  Just read an article about a new identity theft ring in Arizona that targeted some of their own kind - i.e. convicted criminals.  Four female prisoners became victim to identity theft when the criminals outside the prison used their identity to apply for federal student loans.  The scheme worked for a while, allowing the identity thieves to receive over $150,000 in student loans as well as grants.  They attended classes but reaped the benefits by pocketing the amount exceeding the cost of tuition and books, etc.

Wild.  Wonder if the credit bureaus will believe the victims were actually not at those classes if the warden provides documentation that they were incarcerated at the time?!

April 10, 2012

Number of Identity Theft Cases in Mississippi Skyrockets

The Clarion Ledger in Jackson, Mississippi, included an article today by Jimmie E. Gates regarding the sharp increase of the number of identity theft cases in Mississippi.  The Magnolia State jumped from 32nd in the nation in the pro rata number of identity theft cases five years ago to 17th in the nation last year.  Read the full article here --> http://www.clarionledger.com/article/20120409/NEWS/204090317/Identity-theft-soars-Miss-?odyssey=tab%7Ctopnews%7Ctext%7CHome

February 19, 2012

Identity theft ranked No. 1 of the dirty dozen tax frauds

The IRS annually lists the "dirty dozen" tax scams in an effort to protect the public and itself. This year, identity theft is ranked as the top of the dirty dozen scams.

Identity thieves use a taxpayer's identity to file a tax return and fraudulently obtain a tax refund. The IRS reported that it blocked $1.4 Billion from going to the wrong person last year. Small wonder identity theft is ranked no. 1.

Other scams include "phishing" (i.e. tricking people into revealing personal identifiers), hiding funds offshore, reporting false income and abuse of charitable organizations.

If you suspect you are the victim of tax return identity theft, you should contact the IRS immediately.

February 15, 2012

Tax Refund Identity Theft

Its that time of year again.  Millions will file their tax returns between now and April 15.   An increasing number of those tax return filers will find to their dismay that their refunds have already been swiped by an identity thief.

The scam is pretty simple.  Identity thieves forge tax returns using your identifying information.  All that has to happen is that the Social Security number must match the name on file with the IRS.  The address does not have to match, since the person could have moved since the last tax return was filed.  The identity thieves use this loophole to provide an address that they can use to pick up the tax refund.

By filing these forged tax returns early and using bogus income totals that result in a refund, the identity thieves receive the refunds before the unsuspecting victim ever files his or her return.

If this happens to you, immediately contact the IRS.  They will provide you with the appropriate forms to dispute the fraudulent tax returns and obtain your rightful refund (assuming you are eligible for a refund).  Also, only use reputable tax return preparers, as a lot of this type of identity theft seems to occur when less than professional tax return companies are used the year before.

The IRS has allegedly stepped up its efforts to prevent this type of identity theft.  They have allegedly added some "filters" to the screening process that will supposedly catch this fraud at the outset.  I hope this is true as I have seen a marked increase in calls to my office about this type of identity theft.  And, unfortunately, there is usually no legal recourse that I can use to help these victims (unlike victims of traditional identity theft) so its up to the IRS to take measures to protect the public from this type of fraud.

October 13, 2011

Known Victims of Georgia Identity Theft Ring Total Nearly 9,000!

A Georgia identity theft ring has nearly 9,000 victims!  The current number of victims of the alleged identity theft ring centered in Suwanee, Georgia stands at 8,965 and includes people from Georgia to California.

Apparently, the identity theft ring ran a bogus tax preparation service that was submitting false tax returns for unknowing victims.  The scheme caused one victim, Jeanette Adams of Georgia, to get stuck with a $2400 tax bill.  A retired nurse, Adams struggled to keep a roof over her head and pay for her medicines while paying back the IRS for taxes she did not owe.  Unfortunately, no one would help her.  Only later did she find out she was a victim of identity theft.

Authorities discovered the identity theft ring when they served a search warrant on the home of Annette Ford of Suwanee, Georgia.  During their search, which was triggered by an investigation of some stolen checks, police found stacks of fraudulent tax returns, stolen checks and a legal pad containing handwritten notes of names, birth dates and Social Security numbers.

Ford has plead guilty in federal court.  Three others have also been charged.

I have seen more and more tax return identity theft over the last few years.  Unfortunately, there is usually no one to sue, since the debt rarely show up on the victim's credit reports.  The FCRA therefore is no help to those victims.  And the actual criminals usually are either never located or are judgment proof, making a civil suit against the criminals a waste of time.

October 11, 2011

Operation Swiper busts largest identity theft scheme in U.S. history

Who says the economy is struggling?  One identity theft ring that involved more than 100 criminals spent more than $13 million on iPads, iPhones, computers, watches and even swanky handbags from Gucci and Louis Vuitton.  The only problem - they used their victims' credit to make the purchases.

A sixteen month investigation, dubbed "Operation Swiper", led to charges against 111 suspects, 86 of whom have been arrested thus far.  The identity theft ring was run out of Queens, New York but stretched all over the globe, including China, Europe, Africa and the Middle East.

Employees at banks, restaurants and retail stores would start the identity theft by "skimming" the credit card data of customers (i.e. steal the information when they swiped the card, often by using a special machine to do so).  Members of the ring would also steal credit card information online. 

The information was then used to forge credit cards, which were placed in the hands of criminal shoppers, who would make the high end purchases identified above.  The items bought (but never paid for) would then be sold overseas for pure profit.

The credit card companies in the U.S. could have prevented a lot of this by installing anti-skimming micro chips in their cards.  Credit card companies overseas already install these chips so it must be feasible.  The untold number of identity theft victims I am sure would have appreciated this extra protection, had the credit card companies been wise enough to have implemented it.  Maybe losing out on over $13 million just from one ring will get their attention.

As always, any victims of this identity theft ring that need help can contact me through this blog or via e-mail to ckittell@merkel-cocke.com.  I have represented identity theft victims in NY before and thus know some good FCRA attorneys in NY that may be willing to help.

September 28, 2011

Identity thieves go high tech

Do you think you are safe because you shred your credit card bills (after paying them of course), change your password often and don't respond to e-mails from banks where you've never been a customer?  Think again.  Identity thieves are now using a new high tech device to take advantage of new features on credit cards.  This new device, which costs less than $100, allows identity thieves to electronically pick your pocket without ever touching you.

Newer credit and debit cards, as well as some driver's licenses and passports, are being made with radio frequency identity chips that transmit information.  This relatively new feature has opened up an opportunity for identity thieves to use a small device to intercept the signals being transmitted by getting close to you, within 7 feet, from what I am told.  Thus, sporting events (like the Cubs/Cardinals game I went to over the weekend) are treasure troves, since at any time you are within 7 feet of multiple people. 

Many of the banks/credit card companies whose cards use these new identity chips offer protective sleeves for the credit cards.  But for those of us who already have a "George Costanza wallet" issue - see http://www.youtube.com/watch?v=yoPf98i8A0g if you don't understand the reference - this is not a good option.  Another option is a whole new type of billfold - a new type that is made of lighweight steel.  Never tried a wallet like that myself, but it is said to hamper the success of this type of identity theft.

As I have said before, there is no fool proof way to prevent identity theft.  Do your best, but be prepared to take action if and when it happens to you.  Dispute the fraudulently opened accounts early and often, with as much detail and supporting proof as you can.  And, when that doesn't work, hire someone like me to sue the credit bureaus and/or fraudulent credit grantors using the protections of the Fair Credit Reporting Act.  Only in a courtroom are your rights equal to the power of these corporations.

July 19, 2011

Is your child a victim of ID theft?

Identity thieves are not ones to discriminate based on age.   In fact, some of their favorite targets are children.  This is so for various reasons, not the least of which is that their crime is likely to go undiscovered longer if the ID theft victim is a child.

A recent study performed by Debix, an identity theft monitoring company, found that 4000 children's identities had been stolen or otherwise compromised out of only 40,000 children surveyed.

So what do you do to protect your children's identity?  First, when your child turns 16, check his credit report.  This should leave enough time to correct any errors caused by any identity theft before the child starts college and starts needing credit in his own name.

Second, watch out for any early signs of identity theft.  If your minor son or daughter starts getting collection calls or preapproved credit offers, then you should request his credit reports from the Big Three to see what's up.

When you request the report, the credit bureaus should respond that there is no report regarding your child.  If they have a report, then your child is either the victim of identity theft or a mixed file.  How do you tell the difference?  Two ways - first, if all three bureaus have a file on your child, its probably identity theft.  If only one has a file, its likely a mixed file.  But, the only way to know for sure is to contact the creditors who appear on the report and find out what Social Security number was used to open the accounts.  If its your child's SSN, then he or she is a victim of identity theft.  If its a different but similar SSN, its a mixed file and all the blame lies with the credit bureau's faulty matching logic.

In either scenario, the first step after learning of the problem is to dispute the errors to the credit bureaus in writing.  If that doesn't work, after multiple tries, then you need to hire someone like me to sue the bureaus' for your child.  Remember, I'm only an e-mail away.

July 17, 2011

Starbucks' new iPhone app a risk for identity theft?

According to 9News.com (Colorado's News Leader), Starbucks' new iPhone app, that allows iPhone users to pay for purchases, check gift card balances and purchase gift cards for others, is causing identity theft concerns.

Actually, the identity theft concerns are not really related to Starbucks' app as the concerns would apply to many apps.  Any app that encourages the storage of personal financial information (i.e. credit card info, passwords, etc.) on a mobile device increases the chances of identity theft, just because mobile phones are easier to lose than a desktop computer.  Just ask my niece, who loses her cell phone at what seems like a rate of one a month.  But that's a subject for another blog.

One of the next waves of technology will no doubt be some way to pay for purchases using your cell phone rather than a credit card.  But the trade off for something so convenient is the increased risk of identity theft.  Just like the trade off of being able to receive instant credit decisions while you wait to buy a toaster at Sears is that the decision must be based on information that can be transmitted to Sears while you wait.

True story - I once had a client who was unable to purchase a toaster on credit at a Sears because of an error on his credit report.  The defendant in the case was Experian, one of the three national credit bureaus.  Their argument regarding the credit denial was that he was not denied credit due to the error but due to the statement added to his credit report regarding the error, indicating that he was an identity theft victim and that he should be called at his home number to verify his identity before being granted credit.  In the case of instant credit, he would never be home to receive the verification call, since he would be out shopping, waiting for the credit decision.  Kind of a catch 22, huh?  Client should have used his cell phone number but, then again, this was back before everyone had cell phones.

Anyway, the trade off for "instant" stuff is almost always going to be an increased risk of something such as identity theft.  The trick is first recognizing the increased risk and then building safeguards into the app to handle the increased risk.  Hopefully, the apps of Starbucks and others take this into account when designing their apps.

April 01, 2011

March 31, 2011

Interesting experiment regarding what personal data is left on discarded or sold cell phones

An interesting experiment conducted by a company called CPP regarding second hand cell phones to determine what treasure troves of personal identifiers an identity thief would find.  The results of the experiment were disheartening (well, except maybe for me - I call the results "job security".  :)

"Life assistance company CPP purchased second hand mobile phones and SIM cards through Ebay and used electronic shops. The experiment examined what personal data was available on the mobile handsets purchased and whether this information could be used to commit identity fraud.

Alarmingly the experiment revealed 247 pieces of personal data were left on a range of mobile phones and SIM cards, leaving previous owners open to the risk of identity theft. Information found included:

• Credit and debit card PIN numbers

• Bank account details

• Passwords

• Phone numbers

• Company information

• Log in details to social networking sites, such as Facebook and LinkedIn.

The experiment also revealed 81% of those questioned claim to have wiped their mobile phone before selling on and that six out of ten people were confident that all their personal details have been removed. However 54% of mobiles and SIM cards were found to contain sensitive information, unknowingly putting people at risk of identity theft.

The life assistance company's findings were supported by data that found 50% of second hand mobile phone owners said they had found personal data when they had purchased second hand mobile phones or SIM cards.

Most people claim to have wiped their mobile handsets manually, which security experts acknowledge leaves information intact and retrievable and therefore at risk of id fraud.

Mobile data expert from CPP, Danny Harrison said: "This report is a shocking wake up call and shows how mobile phones can inadvertently cause people to be careless with their personal data and put them as risk of identity fraud.

"With the rapid technology advancements in the smartphone market and new models released by manufactures multiple times a year, consumers are upgrading their mobiles more than ever and it is imperative people take personal responsibility to properly manage their own data."

Danny continues, "If they do sell or recycle them online or even give them to friends and family, they need to ensure they remove all their personal information thoroughly and consider the serious consequences of not doing so, such as being a victim of id theft."

Jason Hart, Senior Vice President of CRYPTOCard who was commissioned by CPP to carry out the experiment said, "The safest way to remove all of your data from a mobile phone or SIM card is to totally destroy the SIM and double check to ensure that all content has been removed from your phone before disposal. With new technology does come new risks and our experiment found that newer smartphones have more capabilities to store information and that information is much easier to recover than on traditional mobiles due to the increase of applications."

CPP's top tips on wiping your mobile phone of personal information to prevent identity theft:

1. Restore all factory settings - this is the first step that you should take as it is the easiest precaution before disposing of the unit, but factory resets are far from permanent so follow steps 2 - 4 to protect your data

2. Remove your SIM card and destroy it

3. Delete back-ups - even if your smartphone, PDA or laptop data is securely removed from the mobile device, it can continue to exist on a back up somewhere else

4. Log out and delete- make sure you have logged out of all social networking sites, emails, wireless connections, company networks and applications. Once you are logged out make sure you delete the password and connection

5. Various passwords - avoid using the same ID/password on multiple systems and storing them on your mobile phone, if you are going to store them on your phone use a picture that reminds you of the password

6. If you are selling on your phone ensure you ask for it to be wiped to be on the safe side

7. Don't store vast amounts of personal information on your mobile phone / SIM

8. Make sure you check your bank statements regularly to monitor for suspicious transactions

9. Remember the Golden Rule: Identity thieves are experts at spotting an opportunity to steal your identity and only need a few personal details

10. If you want more information on how to protect yourself from id fraud or see how these experiments worked, please visit CPP's blog"
Cell phones are the only electronic items that you need to wipe clean before discarding.  You should do the same with any electronic device - PDAs, computers, even copying machines these days store information.  Today's copiers, for instance, don't copy, they scan and print.  The documents they scan stay on their memory, whether its a hard drive or some other type of storage device.  People who buy used copiers potentially have access to thousands of pages of previously copied documents.  Scary, huh?

The whole article can be found at http://pr-usa.net/index.php?option=com_content&task=view&id=669843&Itemid=29.