Thursday, February 26, 2009
Crimes Against Businesses Contribute to Job Losses
When retailers lose money to theft, the end result can be (assuming they don't go bankrupt) that jobs are cut. Payroll is normally the largest and most controllable expense in any business. When businesses start to show negative earnings — like a lot of them are right now — payroll is normally the first place they look to cut when trying to avoid shutting their doors.
In an effort to fight what experts say is a $30 billion a year organized retail crime issue, the National Retail Federation is welcoming legislation being introduced to give them more tools to fight this problem. Yesterday, three bills were introduced in Congress to assist retailers and law enforcement in this effort.
The three bills introduced are "the Combating Organized Retail Crime Act of 2009, sponsored by Senate Majority Whip Richard J. Durbin, D-Ill.; the Organized Retail Crime Act of 2009, sponsored by Representative Brad Ellsworth, D-Ind.; and the E-Fencing Enforcement Act of 2009, sponsored by House Judiciary Committee Crime, Terrorism and Homeland Security Subcommittee Chairman Bobby Scott, D-Va. The measures are similar to legislation first introduced last summer" according to the press release and podcast on this matter by the National Retail Federation.
In case you are unfamiliar with "Organized Retail Crime," it involves organized retail theft activity for profit. Once the merchandise is stolen, it is fenced (sold) to get a cash value out of it. Traditionally, this merchandise was sold at flea markets/dishonest retailers, but more and more often nowadays, retail crime rings are turning to auction sites to unload their stolen goods.
The reason for this is if they sell it on an auction site, they make a lot more money than in the more traditional fencing venues. Experts believe they net 70 percent of the retail value by selling their stolen wares on an auction site versus the 30 percent of retail value they receive in more traditional fencing venues.
Another possible factor contributing the problem is that consumers — who are operating with ever-decreasing personal budgets — are flocking to these sites to stretch their buying dollars. Without knowing it, they might be adding fuel to the fire and unknowingly buying this stolen merchandise.
Even if the retailer can prove that merchandise on an auction site is stolen, it can be extremely difficult for them to get the site to cooperate in going after the criminals selling it. Due to a lot of red-tape imposed by these sites to release information, it requires a lot of time/effort to get the site to cooperate in an investigation. Because of this, the crooks are normally long gone before any effective investigative action is taken.
Another phenomenon called phishing makes the activity even more anonymous/hard to track on auction sites. Phishing is where a person (user) is tricked into giving up their credentials to an account. For years, eBay and PayPal have ranked as some of the most phished brands out there. Criminals use this information to take over an account and commit fraud using someone else's selling account. When investigating auction fraud, time is of the essence, otherwise the trail is often too cold to track. The crooks use one of these accounts for a short period of time and then move on to another phished account to avoid detection.
Organized retail crime is also taking advantage of the identity theft/financial crimes phenomenon and working with the hacking element that has been attacking the financial industry. Counterfeit payment cards (credit/debit), checks and identification are all being used to electronically boost merchandise and walk right out the store with it. In the TJX data breach — which was the largest hack of financial data to date — a group was caught using cloned payment cards to buy $8 million worth gift cards from Walmart. In the more recent data breach at Heartland Payment Systems — which looks like it might surpass TJX in the amount of data stolen — the only arrests made thus far were a group using the stolen data to clone gift cards. Since gift cards are redeemed at retailers, this is yet another example of how the financial hackers and organized retail crime types are working together. To me, this is evidence that organized retail crime is becoming more sophisticated in their theft techniques, which will likely make this problem get even worse than it already is.
The three bills being introduced will force auction sites to cooperate with retailers and law enforcement, define organized criminal activity as a federal offense and establish stricter sentencing guidelines for criminals convicted of organized retail crime. Too frequently, under current laws, criminals involved in this activity are treated like petty thieves and get a slap on this wrist when they are caught. Last, but not least, it will hold auction sites more accountable for the sale of stolen merchandise if it could have been prevented.
Besides fencing, there is a lot of other fraud on auction sites that isn't necessarily tied in to fencing and victimizes auction customers/sellers, more personally. Legitimate e-commerce sellers are frequently ripped off with bogus financial instruments. Buyers are also defrauded in a wide variety of scams on these sites. Like the major retail types, who are behind this legislation, the more ordinary victims are often hung out to dry when they try to get any assistance from the auction sites. There is little doubt (my opinion) that auction sites need to clean up all the fraud that occurs on them. While they do provide value and a fun way to buy things, there have been too many innocent people victimized on them.
While this legislation primarily focuses on fencing, it's a start in the right direction. Perhaps other groups should join in and support this legislation, which if passed, will likely set some needed legal precedents. It will also make it a little harder for the criminally inclined to operate on auction sites.
Supporting this legislation makes a lot of sense for a lot of different reasons. These are not victimless crimes and the consequences are being felt by innocent consumers and businesses.
Wednesday, January 21, 2009
Will Heartland Become the Largest Data Breach in History?
Heartland was initially notified by Visa/Mastercard of suspicious activity, which led to malicious software being discovered in their system. The malware in question was harvesting and (obviously) transmitting data. In the press release, they state they believe the breach has been contained. Heartland claims no merchant data, social security numbers or unencrypted PINs were compromised. They were also quick to add that their check management systems, Canadian payroll, campus solutions, micropayments operations and recently acquired Network Services and Chockstone processing platforms had not been compromised, either.
It should be noted that in previous breaches, additional items were later discovered to have been compromised as the investigation progressed.
Brian Krebs at the Washington Post interviewed Robert Baldwin, Heartland's president and chief financial officer, who stated they don't know how many transactions were compromised. In the interview, Baldwin pointed out that since the card numbers compromised didn't have address information; it would be hard for fraudsters to use them in card-not-present (e-commmerce) transactions. Most e-commerce platforms validate the address tied to the card as a security measure. I thought about this for a second and remembered that Visa/Mastercard had warned Heartland about suspicious transactions. If there were suspicious transactions, I would deduct someone is using this data to commit fraud. Besides that, I doubt anyone sophisticated enough to pull this off would go to all this trouble (and potential legal exposure) if they couldn't use the information to make money. This is another thing that might suggest additional information will be discovered as the investigation progresses.
In the interview, Baldwin declined to name any of their customers, who were compromised. Heartland processes payments for about 250,000 customers and processes about 100 million transactions per month. He also said they will not be offering identity theft protection since not enough information was stolen to commit identity theft.
On the Truston blog, Tom Fragala, aptly pointed out that this equates to four billion transactions a year. Many are speculating that this will turn out to be the largest known data breach in history. Tom's company, which offers a privacy-friendly identity theft prevention and recovery service, offers a 45 day free-trial of their services. Even after the 45 days, the prevention part of the service is free.
Tom blogs on matters like this and wrote an interesting article pointing out the consumer protection features of debit and credit cards. Please note, debit cards offer less protection. The point is that if a card owner doesn't discover the fraud in a specified time period, they can be held liable for the financial loss. It's probably a good time for everyone to pay attention to their statements, carefully.
Given the mandatory notification laws, which have been passed in almost all 50 states, this is going to equate a lot of people that have to be notified. Simply stated, it's going to be a "notification nightmare." It should be noted that shutting down all the compromised cards and notifying victims is a substantial cost in any data breach.
SC Magazine also covered the story and got a quote from Rich Mogull, founder of IT security consultancy Securosis, who pointed out there is a trend of malicious software being planted somewhere in the processing system in all the high-profile data breaches seen in recent history. TJX (94 million cards compromised), Hannaford and CardSystems (40 million cards compromised) are all being cited as examples.
According to Visa, Heartland was validated as Payment Card Industry Data Security Standard (PCI DSS) compliant on April 30, 2008. They then stated this status was being reviewed. Trustwave is Heartland's PCI assessor. Hannaford was PCI compliant at the time they were compromised, also. According to the article in SC magazine, TrustWave wouldn't return calls to comment on this.
On the Heartland site, it mentions they are a founding supporter of the Merchant Bill of Rights, which advocates for and educates merchants on fair practices when they accept payment cards. Two of the biggest heartaches for merchants accepting payment cards are the interchange fees and becoming PCI compliant, which is considered an expensive process. Interchange fees are a tariff charged by the credit card companies on every transaction and according to the critics are not very equitable. Estimates have been made in the past that they equate to $30 billion in extra fees added to the cost-of-goods sold with payment cards, yearly. Ultimately, these are costs are often passed on to the consumer.
So far as PCI compliance — which now seems to have been proven ineffective in at least two instances — the National Retail Federation has responded by going on record to challenge the card issuers on their requirements to store data. Because of the cost, a lot of merchants have been slow to adopt PCI data-security standards and the merchants who are not in compliance face fines by the payment card industry.
Storing this data is required to prevent the third headache merchants face when accepting payment cards, or what is known as chargebacks. Chargebacks are when transactions are charged back to a merchant account because of alleged fraud. The NRF contends that being forced to maintain the data to protect themselves makes it easier to compromise.
Heartland is being challenged for releasing this information during the inauguration, when it was less likely to be a hot story. Although this seems to be the case, we need to realize the stakes in data-breaches are high. In the last breach involving a card processor (CardSystems), the card-issuers stopped doing business with the company and the end-result was the company is no longer in existence. Also, it should be pointed out that Heartland wouldn't be the only company that seemed to be very cautious when disclosing the fact that their data was compromised. Once disclosed, there is little doubt that the company in question faces some extremely unfavorable public exposure.
On a closing note, data breaches continue to occur at alarming rates. All sides of the equation need to come together and figure out solutions that work. One of them might be to upgrade the plastic to chip and PIN technology, which has become the standard in other countries. Nigeria was the most recent country to mandate this technology. While this might not directly stop data breaches, it would make it a lot harder to counterfeit the plastic, which is what the criminals use to cash-out the proceeds of data breaches with.
The other problem is that credit card fraud has been made too easy to commit. Card data and the tools to produce counterfeit cards are easy to obtain and even sold in chat rooms. A lot of this technology can also be bought on (what I consider) questionable sites, including eBay. Very few of these fraudsters get caught and because of this; it appears that the activity is getting more and more organized. Historically, the cost of all this seems to have been written off as a cost of doing business. In reality, a lot of these "costs" are passed on to the consumer in the form of higher interest rates and fees.
My prediction is that with the state credit is currently in with the sour economy, coupled with the increase in criminal activity, we are getting to the point where it is going to be hard to simply write-off all the financial costs. Until we start punishing the criminals effectively for this type of activity, it is going to continue to grow and probably prosper.
Update 2/13/09: It appears that the first arrests in the Heartland Data Breach have been made in Leon County, Florida. Three men (Tony Acreus, Jeremy Frazier and Timothy Johns) were encoding numbers stolen in the breach on gift cards and using them at Walmart.
The official press release from the authorities credits Walmart for supporting the investigation.
While it's great a few people got caught -- this probably only accounts for a small amount of the stolen data. My guess is that our three fraudsters bought the numbers via anonymous sources (probably on the Internet).
Wednesday, December 03, 2008
How to Legally Buy Hot Merchandise

(Courtesy of PropertyRoom.com)
Auction sites like eBay and Craigslist are frequently criticized for the amount of stolen and counterfeit items being sold on their sites. Even worse, stories about their customers being scammed have become Internet folklore.
Now there is a site that openly advertises that it is selling stolen merchandise. Even better, when you buy hot merchandise off this site, you need not worry about the authorities showing up at your door in the wee hours of the morning with a search warrant. The reason for this is that the site is stocked by over 1500 Police Departments and is run by former law enforcement types.
The site, PropertyRoom.com is an e-version of the more traditional auctions held by Police departments to get rid of unclaimed stolen property. "With distribution and service centers nationwide, PropertyRoom.com specializes in the auction of stolen, seized, found and surplus goods and vehicles. Serving over 1,100 law enforcement agencies nationwide, we offer a fraud-free marketplace with superior customer support." according to the "about us" page on the site.
I decided to surf the site and it contains a wide array of goodies at cheaper prices than what I've seen being fenced (speculative) on other Internet auction sites. For instance, desktop computers being auctioned were being bid at well under $100, laptops were showing bids of $100 to $400 and iPods were being bid anywhere from about $16 to $150. Of course computers aren't the only items available on the site, which hawks all kinds of electronics, watches, jewelry, tools, cameras, cars and a host of other high theft items.
It is well known that criminals like to steal high value items that are easy to transport. They also tend to go after items that are popular and easy to sell (fence). If you are looking for popular items, this site is a good place to buy them at an almost too good to be true price, legally.
PropertyRoom.com also is in the fund raising business and will help charitable organizations raise money. All the costs of putting on the event are covered by PropertyRoom.com. I should also mention that some of the proceeds of the sales on the site help fund law enforcement agencies, who like the rest of us, are dealing with ever-dwindling financial resources.
They also maintain the only nationwide registry available to the general public for recovering lost or stolen goods. This service is completely free. You can register items that were stolen already, or your high value items that might be stolen at a later date. If they receive an item that matches what you have registered — your property will be returned to you. Try doing this at any of the other auction sites!
The Internet has opened new avenues for criminals to fence stolen merchandise. This has made it easier to sell stolen merchandise and there are many who believe that it contributes to the problem. The most recent survey by the National Retail Federation estimates that Organized
Retail Crime is a $30 billion a year issue. Their most most recent Organized Crime Survey showed that e-fencing on traditional auction sites has grown by six percent. In response to this, they are even pushing bills in Congress to force the auction sites to allow more access to law enforcement and retailers, who are attempting to shut down this activity.
Even the government has found some of their stolen merchandise available for sale on eBay and Craigslist.
Please remember this doesn't even take into account the billions of dollars of property stolen from ordinary people. It also doesn't take into account the ordinary people who are scammed on auction sites, either. I wouldn't worry about getting scammed on PropertyRoom.com — I'm pretty sure they cooperate with law enforcement to the fullest extent.
We all know money is tight this Christmas season and there are a lot of people trying to stretch their limited resources. PropertyRoom.com is a place where you can do it and be certain that you are not contributing to a growing problem.
Sunday, August 03, 2008
Bills Introduced to Combat Organized Crime on Auction Sites
In response to this, two bills are being introduced to combat this problem in the halls of Congress.
The reason this has become a growing issue is that criminals can net 70 percent of the value of stolen merchandise on an auction site versus the going 30 percent received on street corners, flea markets and pawn shops. So far as all the knock-off (counterfeit) goods being sold on auction sites, it's hard to put a dollar loss to it, but many believe it's substantial.
According to the International Anticounterfeting Coalition, counterfeiting costs U.S. businesses $200 to $250 billion a year. Counterfeiting and e-fencing pose safety risks to the public-at-large, also. Outdated or merchandise that isn't what it is advertised to be could potentially poison people, or cause bodily harm when it doesn't work like it's supposed to.
Simply stated auction sites, provide an anonymous marketing environment to sell both stolen and counterfeit goods.
“By hiding behind the anonymity of the Internet, they can make more money with less risk of getting caught than selling to a stranger on a street corner who might turn out to be a police officer. This bill would lift that cloak and help law enforcement put on-line criminals where they belong – behind bars,” according to Joe LaRocca, the National Retail Federations Vice President of Loss Prevention.
To address this problem, a federal bill (H.R. 6713, the E-Fencing Enforcement Act of 2008) is being introduced by Representative Bobby Scott, chairman of the House Judiciary Committee’s Subcommittee on Crime, Terrorism and Homeland Security.
The bill will require on-line auction operators to maintain information about high-volume sellers and provide the information to a person with "standing" once a police report is filed. The definition of a person of standing would be a law enforcement officer or a representative from a company, who has an interest in the merchandise being illegally sold on an auction site.
This is the second bill introduced recently to combat organized retail crime, which costs retailers anywhere from $15 to 30 billion a year. On July 15th, H.R. 6491, the Organized Retail Crime Act of 2008, was introduced by Representative Brad Ellsworth, a former county sheriff, along Representative Jim Jordan, as the lead co-sponsor. The bill establishes that unless auction site owners can show specific steps to prove goods being sold were not being obtained by theft or fraud, they could be viewed as "facilitating" the activity. This bill will also require site operators to cooperate with the police and organizations with a stake in stopping the activity. In certain instances, it will also allow merchants to initiate civil actions over stolen merchandise being sold on an auction site.
In the past, auction operators have been criticized for not effectively cooperating with companies and law enforcement when they made an inquiry into suspected criminal activity on their sites. It has also been established that smaller (individual) victims and merchants often receive little to no assistance after being victimized in an Internet auction deal.
E-fencing, phishing, counterfeit goods and the use of fraudulent financial instruments to buy merchandise from unsuspecting customers have all victimized countless people and organizations on auction sites.
Criminals often lure people to do their dirty work, also. Recruits are normally harvested off the Internet, sometimes from job sites, and offered work to reship stolen merchandise and or launder money from fraudulent transactions. Much of this activity involves sending money, or hot merchandise across an International border --making it extremely difficult to track.
A lot of criminal activity is facilitated on auction sites by what is known as phishing. Phishing is where an account owner is tricked into giving up their account details, either via social engineering, or more and more often, after downloading some malicious sofware. The stolen account details are then used to take-over the account and use it for illicit purposes.
In fact, eBay and PayPal accounts are frequently the most phished brands out there.
Phishing, normally facilitated by spam e-mails, is another ever-growing criminal activity on the Internet. Recent studies by the Anti Phishing Working Group show that it is becoming more automated and malicious software (crimeware) used to automatically steal information is becoming more prevalent.
There is little doubt that a lot of the criminal activity on auction sites is sophisticated and reeks of organized crime.
For anyone investigating fraud on an auction site, the only way to effectively do so, is to have access to information quickly and with as little red tape as possible. A lot of these crimes cross over borders quickly and by the time and investigator gets what they need, the trail is often pretty cold.
When auction site owners -- who suffer no financial liability and collect a lot of revenue in fees from this activity -- don't cooperate or move too slowly, it only ensures that criminals will be laughing all the way to the bank.
Even the government has had their stolen inventory sold on eBay and Craigslist. In April, the GAO issued a report that military items, including F-14 components, were being sold on auction sites. In August of last year, a U.S. Attorney was quoted as saying that stamps being stolen from self service vending machines with cloned payment cards were being sold on auction sites. At the time, I ran a simple search query and found some pretty good deals on stamps. As of today, these great deals still exist. Many of them are being sold below cost and the last I checked the Postal Service still offers credit. Why would someone sell stamps below cost?
In my opinion, both of the bills don't only serve the large merchants out there, but have the potential to protect everybody from fraud on auction sites. While both of these bills are being driven by the National Retail Federation, I see a lot of benefits to passing them for everyone concerned with fraud on auction sites.
I highly recommend that these other people, join in with the NRF and the Congressmen involved, and support getting these bills passed.
Wednesday, June 25, 2008
Retailers Honor Sleuths Who Smashed $100 Million Organized Retail Crime Ring
The National Retail Federation is recognizing a couple of individuals, both from law enforcement and within their own ranks, for their contributions in smashing a $100 million organized retail crime ring. These crime fighters are being honored at the NRF Loss Prevention Conference & EXPO in Orlando, Florida.
The two being honored are Detective Ostojic, of the Polk Country Sheriff's Department, and Ron Averette from the loss prevention department at Publix Supermarkets. In June 2007, the two began comparing notes on a group that was stealing large amounts of merchandise. Subsequently, Detective Ostojic was able to tie in cases at other retailers and Averette (along with Ostojic) presented the pattern of activity to the Florida Department of Law Enforcement and Florida State Attorney's Office. This led to a task force being formed under the leadership of Special Agent Telly Sands from the Florida Department of Law Enforcement.The result of the task force's efforts were that 18 people were identified as being involved in the ring and subsequently arrested.
The FBI estimates that organized retail crime costs retailers an estimated $30 billion dollars a year. To date, this is the largest documented case where organized retail crime was identified as being the cause.
These rings use flea markets, Internet auction sites like eBay and Craigslist, rogue e-commerce sites, and even seedy merchants to sell their goods. Some retail loss prevention departments have dedicated personnel to investigate stolen merchandise on auction sites.
In this case, a lot of the stolen merchandise were health and beauty aids. Some of these products have expiration dates, which might lead to health and safety concerns for the end user.
Mark Albright wrote an article about this case in the Saint Petersburg Times, where he mentioned specific brands the group deemed desirable for resale. By doing a search on eBay, I found a wide selection of Gillette razor blades, Prilosec, Crest WhiteStrips, and Oil of Olay available on the site. Please note that I have no way of telling if these items were the result of organized retail crime or obtained legitimately. I do know that large companies generally frown on having their products sold on auction sites and I saw some extremely good prices listed for these products.
According to the article in the Saint Petersburg Times some of the shoplifters (boosters) involved have rap sheets (criminal records) ranging from sex crimes to armed robbery and attempted murder.
A recent survey indicated that retailers are seeing an increase in organized retail crime activity. The cost of this type of crime is eventually added into the cost of the product being stolen, which means we all end up paying for it.
This activity has been known to run smaller businesses bankrupt. Even at larger retail organizations, out of control losses often dictate that operating budgets need to be trimmed. Since payroll is often the largest operating cost in an organization, this leads to reductions in hours and positions to keep a company afloat. Simply stated, activity like this can cost people their jobs.
Legislation has been passed in many states and more is forthcoming to make organized retail crime penalties stiffer.
Sunday, June 08, 2008
NRF Survey shows Organized Retail Crime activity is growing!
Also mentioned in the survey are shady e-commerce sites being put up on the Internet to fence the proceeeds of ORC.
In case you've never heard the term, Organized Retail Crime, here is a good description of the activity:
Organized retail crime (ORC) refers to groups, gangs and sometimes individuals who are engaged in illegally obtaining retail merchandise through both theft and fraud in substantial quantities as part of a commercial enterprise. These crime rings generally consist of “boosters” who methodically steal merchandise from retail stores and fence operators who convert the product to cash or drugs, as part of the criminal enterprise. Some of the more sophisticated criminals engage in changing the UPC bar codes on merchandise so they ring up differently at checkout, this is commonly called “ticket switching.” Others use stolen or cloned credit cards to obtain merchandise or produce fictitious receipts to return products back to retail outlets.
The report acknowledges that these groups are using cloned credit cards to steal merchandise and or get the necessary receipts to refund the merchandise for cash.
In the wake of the TJX data breach, where up to 94 million personal and financial records were hacked, a group was caught in Florida using data from the breach (cloned cards) to buy a reported $8 million worth of gift cards.
Please note that TJX is hardly the only retailer, or financial services institution that has had personal and financial records hacked from their systems in recent history. Attrition.org does a good job of recording the known breaches on their Data Loss Database - Open Source .
Although not addressed in the current report, I suspect the use of fraudulent checks are used to obtain merchandise and receipts, also.
This could be fueled by another organized crime activity. Portable technology has made the counterfeiting of identification documents another growing trend. Over the past two years or so, I've had the pleasure of being able to speak with Suad Leija and her husband about this organized criminal activity on a semi-regular basis. Suad, the step-daughter of one of the top players in this game was recruited in an intelligence operation and eventually exposed a cartel operating throughout North America to the government. Prosecution of members of the cartel is ongoing in this case and Suad is currently working on a book.
These documents, which are available throughout the United States, can be easily used to support both check and refund fraud by using names that get past the data bases designed to protect retailers from these types of fraudulent activity.
Portable technology is also being used to clone payment cards and some of it is easily found on auction, or shady e-commerce sites set up to sell these devices. As of this writing, I was easily able to find credit card encoders for sale on eBay. A site called HackersHomePage.com provides an array of devices that could be used to steal and produce payment (credit/debit) cards. They also provide tools to make counterfeit checks and even, paper for fake prescriptions. They do have a "disclaimer" stating that none of their products are to be used for illegal purposes, but it is pretty obvious someone could.
There is no doubt that there is a lot of technology that is enabling a lot of criminal activity out there!
NRF's Vice President of Loss Prevention, Joe LaRocca, made what I consider a sage comment on this activity:
“Law enforcement and retailers alike are fed up with organized retail crime rings and are stepping up efforts to stop them in their tracks,” said NRF Vice President of Loss Prevention Joseph LaRocca. “The brazen and unethical behavior of organized retail crime suspects results in possible health risks for consumers, adds unnecessary fees to consumers’ purchases and funds criminal enterprises, including the mob and terrorist organizations around the world.”
When I stated that this activity hurts all of us, the reason is that retailers have to make up the $30 billion they are losing to this activity somewhere. This normally equates to higher prices, or in extreme circumstances (especially in tight economic times) cutting payroll. Simply stated, people might be losing their jobs because of this activity.
So far as health risks, the report sums up the obvious risks rather well:
For example, criminals may not keep stolen merchandise in a temperature-controlled environment, so merchandise like baby formula and over-the-counter medicines can easily spoil. When criminals sell these items online through third party auction sites consumers are left with no way to guarantee they are getting safe and reliable healthy and beauty products.
I decided to see if I could find baby formula on eBay. As you can see - there seems to be a lot of it for sale on the site at discounted prices. At the time I checked 26 pages of it were for sale on the site.
Actual cases in the report that support how organized this activity has become are a $60-$100 million dollar case in Florida involving health, beauty, cosmetic products and over-the-counter medicines. Another case mentioned involved a high ranking member Gambino Crime Family and a sophisticated ticket/UPC switching case and extortion. In this case, a planted employee was making up the labels and providing temporary credit cards to move the merchandise through point-of-sale systems.
Recent initiatives to combat Organized Retail Crime include launching LerpNET, which is a crime database available to both retailers and law enforcement. Also highlighted was legislation against ORC throughout the country to "reduce the rewards and increase the risk" to the groups involved in it. Several States have already passed this legislation and more are considering it.
Full 2008 ORC Survey, here.
Friday, October 05, 2007
Retailers call for a level playing field on data security
Thus far, we've seen legislation introduced to hold retailers responsible and calls for PCI data security standards. Legislation has been passed in Minnesota and is awaiting Governor Schwarzenegger's signature in California.
In any disagreement, there are two sides to a story -- and now the National Retail Federation (NRF) is bringing up what I consider is a valid point -- which is if they weren't required to store all this information, it would be harder to steal.
Under current rules, they are required to maintain too much information for 18 months, or face what are known as chargebacks.
Chargebacks are when a customer requests a refund from their card issuer, normally because of fraud. Please note that some dishonest customers claim fraud, when it never occurred. Additionally, the payment card industry sets the due diligence standards when accepting their cards and actively promotes their use.
The bottom line is -- merchants can accept payments, follow all the rules, and if they can't provide the required information -- they get charged for it, anyway.
With all the fraud that results from payment cards, this could get pretty expensive for a retailer, if they fail to control it.
Saying all this, we need to consider the bigger picture, which is the best way to protect data is to limit how many places it is being stored. This principle should be considered in a lot of other places besides retailers, also.
Mark Jewell of the AP is reporting:
The National Retail Federation on Thursday urged a card industry organization to stop requiring retailers to keep customers' card numbers for up to 18 months.In the article, Mr. Hogan brings up the very reason that retailers have been holding on to what some consider, too much information:
The stored data helps track product returns and disputed or suspicious transactions. But retailers say the data would be more secure if only credit card companies and banks that issue the cards stored it.
"It makes more sense for credit card companies to protect their data from thieves by keeping it in a relatively few secure locations than to expect millions of merchants scattered across the nation to lock up their data for them," David Hogan, the retail federation's chief information officer, said in a strongly worded letter.
Hogan said in an interview that retailers routinely hold onto information because credit card companies ask them to produce data from transactions as old as 18 months to verify product returns and protect against fraud. If retailers can't produce data showing the product was legitimately purchased, they can end up reimbursing banks and card companies, Hogan said.Only 44 percent of large retailers are now PCI compliant. This month, the larger retailer's banks will start facing fines for failing to become compliant. Banks that service medium size retailers will start facing fines in January.
This doesn't even take into account smaller merchants, who often are victimized the most by fraud, and chargebacks.
In case you don't understand how chargebacks can be a burden to a merchant, I've included a YouTube video at the bottom of this post, where a small merchant rants about chargebacks from PayPal.
The frustration expressed in this video is the same one felt by a lot of merchants (retailers).
The basic issue in all this is who will end up paying for it. Since no business remains solvent if they are losing money, the costs are going to end up being passed on to the consumer.
So far as the NRF's point, I think it is entirely valid. If retailers didn't have to store all this data, it would be one less place, where criminals could access it.
After all, while data breaches at retailers have gotten a lot of attention recently, they are not the only place they are occurring.
If you are interested in seeing what I mean by this the Privacy Rights Clearinghouse, PogoWasRight and Attrition.org all try to keep track of as many of them as they can.
All of them will tell you that their efforts only document the known breaches. There are probably many more that no one knows about -- and the last I heard -- the criminals behind them keep this a closely guarded secret.
After all, disclosure of a data breach impacts their bottom lines, also.
My personal solution is for everyone to get together and go after the real people behind this problem, or the criminals. Everyone would benefit from this!
My guess is they (the criminals) could care less, who ends up paying for all the damage they are causing.
AP story, here.
National Retail Federation (NRF) press release, here.
Here is the YouTube video (mentioned above), which reflects a small merchant's frustrations with the chargeback process. Please note that smaller merchants are bound to have a stake in what becomes of this controversy, also.
(YouTube video courtesy of Terry)
Tuesday, June 05, 2007
Merchants demand their rights from the payment (credit/debit) card industry!
Additionally, merchants aren't only becoming more alarmed by fraud, but also by a perception that current fee structures are unfair, and deceptive. Interestingly enough, a lot of consumers feel the same way, also.
- Only 26 percent of participants believe they are being treated fairly by the debit/ credit/prepaid card processing industry.
- Only 32 percent understand unfair card processing practices and how they impact their business.
- Only 21 percent understand the rates, fees and surcharges they pay.
- Only 15 percent believe they are charged the same as larger businesses.
The survey was sponsored by Heartland Payment Systems, who processes payment card transactions and payroll.
Heartland's CEO and Chairman, Bob Carr stated:
It’s clear that many owners of small and mid-sized businesses don’t understand the complexities of card acceptance. Yet, card acceptance is often one of the three largest expenses they incur. Business owners need to educate themselves so they can manage these costs. What they don’t know may be hurting their bottom line.
According to the press release, the bill of rights promotes fairness and transparency in card processing by identifying 10 fundamental rights:
The right to know the fee for every card transaction – and who’s charging it.
The right to know the markup of Visa and MasterCard fee increases.
The right to know all Visa and MasterCard fee reductions.
The right to know all transaction middlemen.
The right to know all surcharges and bill-backs.
The right to a dedicated local service representative.
The right to encrypted card numbers and secure transactions.
The right to real-time fraud and transaction monitoring.
The right to reasonable equipment costs.
The effort has a home page, which can be viewed, here.
The page has a video for merchants to see if their rights are being violated, here.
The Association of Certified Fraud Examiners recognizes that small businesses suffer greater losses than larger ones do. I did a post on this subject, with the some tips on how to avoid becoming a victim, here.
In January, I did a post about how both consumers and merchants are calling for some reforms:
Congress needs to take a hard look at credit practices
In this post, I mentioned the Merchant's Payment Coalition, which is calling for greater oversight on some of this. Their page on unfair credit card fees can be viewed, here.
Even if you aren't a merchant, the truth is that these costs have to be passed off somewhere; otherwise merchants would go out of business. Who do you think ultimately pays for all this?
Friday, April 06, 2007
Retailers and the FBI band together to fight organized crime
The retail industry realizes this and in partnership with the FBI is launching a secure tool that businesses and law enforcement can use to communicate criminal activity with each other. A simple, but powerful principle.
Here is the information on this new tool from the NRF site:
In response to an alarming rise in organized retail crime, the National Retail Federation and the Retail Industry Leaders Association, in collaboration with the Federal Bureau of Investigation, have teamed up to launch the Law Enforcement Retail Partnership Network (LERPnet), a secure national database that will allow retailers to share information through its unique web-based design. With LERPnet, retailers and law enforcement will be able to fight back against illegal activity including organized retail crime, burglaries, robberies, counterfeiting, and online auction fraud. The database will launch on April 9, 2007.
Full NRF press release, here.
More information on this tool can be seen by linking, here.
The Washington Post also did a good story covering this.
A lot of other industries and law enforcement agencies should follow this example. Developing better tools to communicate could help resolve the current epidemic, currently being seen in all types of financial crimes.
There is some evidence that the bad guys communicate with each other, regularly (carder forums). The good guys should do no less!
To close, Joe LaRocca, NRF vice president of loss prevention is saying:
“With this system, retailers are banding together with law enforcement to send a clear message to criminals: We will not tolerate your behavior and we will stop you.”
Sunday, March 04, 2007
Organized retail criminals sell their ill-gotten proceeds in many places
Some estimates (RILA) reflect that this could be a $34 billion a year problem.
I've seen a lot of recent stories about merchandise being fenced on auction sites. Although, this is a big problem, stolen goods are fenced in other places, also.
WKYC news (Ohio) is reporting that 19 homes and business were recently raided, illustrating how organized some of this activity can be.
Very interesting video, here.
The Washington Post, did an interesting article about organized retail crime in 2005, here.
It noted that federal law enforcement is getting involved in the prosecution of these cases, because of their impact, and (probably) the fact that they cross state lines, frequently.
RILA (The Retail Industry Leaders Association) proposed changes to Congress to deal with the problem, here.
Of note, they quote the FBI as saying that organized retail crime is funding terrorist organizations.
Another problem (the FBI calls out) is when outdated medicine and items, such as baby formula are repackaged and sold as new.
This could pose significant health risks to those, who purchase these stolen items.
Besides the fact that we all pay for this with our hard earned money (higher prices), our safety is being compromised by these criminals, also.
Saturday, January 27, 2007
Congress needs to take a hard look at credit practices
And Consumers Union isn't alone - a lot of other consumer groups are pretty much calling for the same kind of corrective action for the industry, here.
But it's not only consumer groups that are up in arms. Merchants seem to be, also.
The Merchants Payment Coalition is also applauding this development and is calling for a "deeper look" into interchange fees, which they say cost consumers $30 billion a year. Notably, they state that this amount represents twice the amount the industry charges for late fees, which have also been under attack by the consumer groups mentioned above.
The describe these fees as:
Americans pay a hidden fee on virtually every transaction they make, whether they use a credit card or not, costing consumers tens of billions of dollars a year. This fee, called interchange, is a percentage of each transaction that Visa and MasterCard banks collect from merchants every time a consumer uses a credit or debit card to pay for a purchase. The fee varies with type of card, size of merchant and other factors, but averages close to 2 percent for credit card and signature debit transactions. These hidden fees drive up the cost of goods and services for all consumers whether they pay with plastic, cash or check.Merchants Payment Coalition page about this, here.
The National Retail Federation is also very "passionate" about interchange fees.
In July, they issued a press release, stating:
The National Retail Federation welcomed a hearing on soaring credit card interchanges rates scheduled to be held today by the Senate Judiciary Committee. The hearing is expected to focus on the $26.3 billion in credit card interchange fees collected each year, the impact of the fees on American retailers and consumers and whether the price-fixing practices involved in setting interchange fees violate federal antitrust laws.National Retail Federation press release, here.
Since this release was issued in July stating that interchange fees brought in 26.3 billion, I guess the current estimates of $30 billion means that these fees were more profitable than anticipated for the credit card issuers?
We seem to be living in a world, where the amount of debt carried by consumers is at an all time high and fraud is running rampant. Critics claim that credit is issued too easily and not very responsibly.
Please note, this doesn't only apply to the credit card industry, we are (also) beginning to see the impact in the mortgage industry - where defaults are at a record high. Probably the result of too many people "flipping properties," and what appears to have been a record amount of "mortgage fraud."
We are also seeing a growing amount - especially with all the data breaches - of payment card (credit/debit) card fraud.
It makes one wonder how much longer it will be before we hit "bottom," and an economic disaster is the result. If this happens - who will pay the cost?
Our leaders need to examine this problem carefully - and take appropriate action to fix it. Passing the costs of it between businesses (and ultimately consumers) will only work for so long.
Wednesday, November 15, 2006
Why Buying Gift Cards on Auction Sites isn't a Good Idea
The main reason eBay limited the sales on their site was pressure from the retail industry, or so I've read.
Fraud committed against retailers costs billions, and it's added into the "cost of goods sold," which means we are all paying higher prices because of it. There is a limit to being able to add the price of fraud into the cost of an item (competition) and when this happens, businesses fail.
A lot of people have lost their jobs when retail fraud couldn't be controlled.
In response to my original post, Joe LaRocca, Vice President of Loss Prevention for the National Retail Federation was kind enough to send me some links illustrating how big a problem this has become.
In November, the NRF released information that estimates retailers will lose $3.5 billion during the holiday (Christmas) season - link here.
Many retailers issue gift cards versus cash for refunds (especially when no receipt is present) and fraudsters sell them for cash. Joe provided me with an interesting link on this (story and video clip) from NBC4.com, here.
Refund fraud normally is a result of shoplifting, but when dealing with gift card fraud, we also need to include credit/debit card and check fraud. Retail fraudsters buy gift cards with their "bogus financial instruments" and then sell the cards for cash. Of course - they could be refunding merchandise bought with their bogus instruments - but it's easier (less work) for them to simply buy the "gift cards" and resell (fence) them.
Credit/debit card and check fraud are two activities that directly tie into "identity theft," which victimizes 9 million people a year in the United States, alone.
Besides the "indirect costs" we all pay - a lot of ordinary people become fraud victims after an encounter with a fraudster on an auction site. The Internet Crime Complaint Center cites auction fraud as their number one complaint and it keeps growing every year.
Besides placing yourself at risk - buying gift cards over the Internet - might be supporting the victimization of ordinary people and businesses alike!
Thursday, November 09, 2006
Will Gift Card Sites Become a Fraud Problem?
The story quoted Joseph LaRocca, of the National Retail Federation:
"Goods stolen by organized or professional thieves are sometimes sold cheaply at flea markets, on street corners or in impromptu home boutiques, say retail security experts. They can end up as fraudulent returns to stores. And in a high-tech age, they can be "e-fenced'' on online auction sites."Also mentioned was how gift cards are being bought and stolen with fraudulent checks and credit cards.
Not mentioned in the article is the fact that gift cards are also issued as refunds when someone doesn't have a receipt and that "hackers" have been able to load "blank cards" in the past.
And new "gift-card auction sites" seem to be popping up all over the Internet.
Marshall Loeb of MARKETWATCH recently did a story on these sites, which attributed this new trend to consumers not using up their old cards. While this might be true -- gift card fraud is nothing new -- and I have to wonder how many cards sold on these sites were the result of one fraudulent transaction, or another?
And even the article states that consumers should be wary:
Consumer advocates warn that you should be careful when doing business on these sites. There is virtually no way to avoid fraud completely; a seller could post and sell cards that have no value. Some sites have built in safeguards to prevent this from happening. CardAvenue.com, for example, validates cards listed at more than $100 and will cover up to $100 of a card's value if it proves to be a dud (you have to pay a $10 deductible, though).
After reading this, I had another thought, which was that eBay warns people all the time not to do off-eBay transactions, but they do anyway - and there are many of them who become fraud victims.
It's amazing what a few "too good to be true deals" will harvest in the way of victims.
Will we see the same thing on these "gift card sites?"
A couple of years ago - eBay limited the number of cards that could be sold by any one seller - as a result of all the fraud and some pressure by corporate victims (retailers).
Now - it seems - that these gift card sites are stepping into to fill the "void" left by eBay's change in policy.
A lot of these sites are too new to have developed a history, but given the history of gift cards being tied into fraud - it's probably a matter of time before we see problems.
I would strongly recommend that buyer's be careful (caveat emptor) and that the "retail industry and law enforcement" keep a "watchful eye" on these sites.
Of course - my guess - is that they already are!
A closing thought is that even if the cards work - if they were a result of a fraud transaction - we all end up paying for it in the end.
Businesses wouldn't stay in business otherwise.
If you are interested in how much gift card fraud there is out there, click on the title of this post.
Saturday, May 06, 2006
Retailers Find their Stolen Merchandise for Sale on eBay
A common misconception is that the majority of losses stem from individuals stealing items for their own use. In fact, the majority of stolen goods are converted into cash.
With the increased focus on the traditional means of converting stolen merchandise into cash, such as refunding, common and professional "boosters" are flocking to eBay to accomplish their primary goal.
This was a matter of concern raised at the Retail Fraud Conference held in London recently. Penelope Ody of the Retail Bulletin reports:
Retailers at this week's Retail Fraud conference in London (May 4) had a new preoccupation adding to the usual concerns over dishonest cashiers, sweethearting and back door delivery thefts-eBay. According to Boots head of loss prevention and security, Robert Jennings, this is now in the top five areas of concern as retailers increasingly see their merchandise offered in bulk on the web auction site.
Link, here.
Note that the Jennings is saying for "offered in bulk," which would lead one to speculate that this isn't being done by the "opportunists" and is more likely the work of organized gangs.
Interestingly enough, there has been a lot of buzz recently on organized gangs involved in shoplift activity. Margaret Pressler of the Washington Post recently wrote:
Retailers and theft experts say criminals have discovered that large profits can be made relatively easily, and without much risk, by stealing merchandise from crowded, understaffed stores. They say the most stolen items tend to be high-priced, widely used products that are routinely sold in chain stores: over-the-counter medicines, razors, film, CDs and DVDs, baby formula, diapers, batteries, hair-growth and smoking-cessation products, hardware, tools, designer clothes and electronics.
Link, here.
AND another recent viewpoint from SecurityInfoWatch.com might lead one to believe that organized retail crime has ties to illegal immigration and terrorisim.
Liz Mart'nez wrote:
According to CIS Robert W. Nolen, a lead trainer in a course developed with Bureau of Justice Assistance grant money called "Understanding, Combating, and Surviving Terrorism," many criminals from terrorist countries specialize in the re-sale of stolen consumer goods. The profits from these enterprises are used to fund terrorist activities.
In many cases, men and women from El Salvador, Honduras and Mexico travel together, doing the actual stealing. Each person in the crew has a particular area of expertise, whether it be distracting store employees, doing the actual boosting, or driving the get-away vehicle. These professional thieves often earn $3,000 a week.
Link, here.
Although not stated in the article, if illegal immigrants are doing the stealing and criminals from terrorist countries are selling the goods, it makes me wonder how close their relationships could be?
Another issue, retailers have had with eBay is the sale of gift cards on the site. Whether purchased with bogus financial instruments, or issued as refunds (which could be a direct result of shoplifting), gift cards are another means of converting stolen proceeds into cash.
In another interesting article, again from the Washington Post, Ariana Cha wrote:
The shoplifters discovered some stores would allow them to return the goods without receipts for store credit or gift cards. They then sold those vouchers on the giant online marketplace. It was easy, instant and anonymous. The money flowed in -- they got 76 cents per dollar of stolen merchandise, a huge takeaway considering that shoplifters traditionally net 10 percent or less of the retail value of the items. The group made more than $200,000 in 10 months.
This is yet another example of many, where crimes of all sorts are occurring in the Internet auction world (particularly eBay). We can't hold auction sites accountable for being in collusion with criminals, but we can hold them accountable for not providing a safe shopping environment.
After all, how long would one of these retailers survive if they allowed the amount of crime to occur within their four walls with people walking around? My guess is that they would be out of business pretty quickly.
The same standard needs to be applied to the Internet and if this "business model" is to survive, the auctioneers needs to wake up and smell the coffee. Thus far, eBay has been able to blame everyone, but themselves; however as corporations become victims, the stakes are likely to grow.
Corporations have money and can afford a lot of lawyers.
Tiffanys might have already started this trend with it's pending litigation regarding the sale of counterfeit merchandise on eBay.
