On Monday, Federal authorities informed the public of a series of arrests where identity theft was used to steal the equity out of homes. I guess we've already lost so much money in the mortgage crisis, the identity thieves figured it wouldn't matter?
The four arrested on Monday were Derek Polk, Oluda Akinmola, Oluwajide Ogunbiyi, and Oladeji Craig. The four appeared in federal court in Los Angeles, Newark, Buffalo, and Springfield. Also arrested for home equity schemes between August and October were Daniel Yumi (Brooklyn), Yomu and Olokodana Jagunna (Queens), and Abayomi Lawal (Brooklyn).
Strangely enough — although no one in the mainstream media is saying — most of these names sound slightly foreign. Judging by the surnames my best guess is that they are originally from West Africa, probably Nigeria. Stories of Nigerian fraud are extremely popular in the media so I'm surprised no one took this opportunity to put that twist to this story.
In all fairness, in previous posts, I've lamented that fraudsters often pose as Nigerians or the media incorrectly pegs fraud as coming from Nigeria when it doesn't. There is no doubt Nigeria is known for a lot of fraud, but they didn't invent it and are not the only players in the game.
It should also be noted (out of fairness) that court documents reflect the federal authorities stating that this is the result of an investigation into a multi-national identity theft ring. There are a lot of fraud groups out there, both foreign and domestic, and many of the experts have concluded they are working together when it suits them.
The proceeds of these home equity scams were wired all over the world, including South Korea, Japan, China, Vietnam, Canada, and the United Kingdom. According to news accounts about $2.5 million was wired and the total take in the scheme was about $10 million.
Sadly — although this has been called out as a problem frequently — a lot of fodder (information) used in the scams was obtained by none other than public record searches. The public records used even contained credit applications, credit reports, and the victims' signatures, according to the FBI. BJ Ostegren — who was kind enough to give me a personal demonstration a while back — is the champion of exposing just how much of this information is out there for anyone to grab. If you want to see exactly how much information is available, her website is a good place to start.
Also mentioned in the criminal complaint was that fee-based Internet services were used to obtain some of the information. This is a huge business, which nets billions of dollars a year for the people selling it. I did notice that no one is saying which one of the services were used.
It should also be noted that information like this is bartered in forums on the Internet. Symantec just released a report showing how cheaply some of this information can be obtained. This type of activity is fairly well known and the FBI recently cracked one of the forums (Dark Market). This group allegedly racked up about $70 million in fraud, worldwide.
The individuals arrested in this scheme also used a lot of known technological fraud crutches, such as caller ID spoofing, prepaid cellular, and forwarding calls without the owner's knowledge. Tricking a phone company into forwarding calls is no problem for most fraudsters as little to no due diligence is performed before it is done. You can have your carrier block this feature, or password protect it (recommended) — however doing this is left entirely up to you. So far as caller ID spoofing — it's essentially legal — and anyone can purchase the means to do it right over the Internet.
There probably won't be any effort to change call forwarding, or caller ID spoofing as it is a lucrative income stream for telecom businesses.
You would think as long as we are in a world-class financial crisis, we might begin to wake up and smell the coffee? Although, we can't blame fraud as the cause of the entire crisis, I often wonder how much of a contributing factor it is. We've made identity theft too easy to do and hard to control. The people who committed this latest form of identity theft probably aren't the sharpest tools in the shed. They are just taking advantage of other people making a lot of money by making too much information available and not protecting it.
If you look in the mirror you might get an idea who suffers from this seeming inability to fix a growing problem. Even if you aren't victimized, we all pay for it in the end — either in an organization's expense line or in the form of a government bail-out.
I'll close with a with an interesting satire written by Phillip Maddocks, which came out in the Norwich Bulletin entitled, "Credit card fraud gangs say they can fix economy but need government loan." This satire is about the heads of several credit card gangs who are seeking a government handout to keep credit card fraud alive because it is beneficial to the economy.
Although this is a satire — it has a ring of truth to it!
Unfortunately, we allow a lot of dumb things to continue because someone thinks it's beneficial to the economy.
Showing posts with label data brokers. Show all posts
Showing posts with label data brokers. Show all posts
Friday, November 28, 2008
Sunday, June 08, 2008
Large scale data theft of U.S. information uncovered in India
Stealing personal and financial information in large quantities isn't just a problem in North America and the Europe Union. As more IT functions are outsourced to a variety of countries, this information might be getting compromised from just about anywhere.
Recently, it was disclosed in the Indian press that a large amount of data was stolen by an Indian BPO from a company in United States. It's amazing this story didn't get very much coverage in the West, despite the fact that the data was stolen from a company called Noble Ventures, which is based in Florida? As a slight disclaimer ComputerWorld (Norway) and CIO (Australia) did cover the story, but I was unable to find anything about it in the American press.
I suppose in this instance we will have to rely on the Indian media to provide some transparency to this event. Parth Shastri at TNN reports:
Apparently this occurred after Dave got his contract cancelled with Noble Ventures Inc., who "provides customer database of 1.25 crore (ten million) US citizens to various marketing companies in the US and also has a client-base in other international markets," according to the TNN article.
Of even greater concern to me was the deduction (my speculation) that Dave had insider access to their systems after his contract was cancelled? From the article, it is unclear if this was because the access was never removed, or if he got it from another Noble Ventures employee, Milan Dabhi, who is based in the U.S. and allegedly Dave's accomplice.
In another article published by the IT Examiner in India a person claiming to be a spokesman for Noble Ventures, Sunny Vaghela with credentials as a cyber crime expert, claimed that the information was stolen, but never sold. The rationale for this was that Noble Ventures reported the theft to Indian authorities and a sting (?) was conducted.
From the IT examiner article:
I went to the Noble Ventures site and they offer a lot of information for a price. Targeted data on executives, "heroes" (police and firemen), veterans and a slew of other marketing segments can be obtained. They even sell e-mail lists.
While I couldn't determine if this information was enough to open a line of credit, it could certainly be used to mount telemarketing scams, spam campaigns and even whaling (phishing) expeditions like the recent one we've seen targeting executives in the United States. Verisign just reported that 15,000 white collar types were speared in this expedition.
Please note that even though I am assuming no financial or SSN information was compromised -- if a dose of social engineering, phishing or malicious software is added to the equation -- getting the rest of the information to commit identity theft would probably be fairly easy.
Incidents, such as this, continue to point to the fact that there is too much information being stored in too many not very well protected places. In fact, this incident might point to the fact that the problem is getting worse.
We also need to remember that this information came from a U.S. company, and although I don't know where the server was physically located, it didn't have to be located in India for this to have occurred.
Information like this is protected by the FTC's Telemarketing Sales Rule.
Violations in the United States of this rule can be reported, here.
TNN story from India can be seen in full, here.
ComputerWorld, Norway story about this, here.
CIO Australia story, here.
Recently, it was disclosed in the Indian press that a large amount of data was stolen by an Indian BPO from a company in United States. It's amazing this story didn't get very much coverage in the West, despite the fact that the data was stolen from a company called Noble Ventures, which is based in Florida? As a slight disclaimer ComputerWorld (Norway) and CIO (Australia) did cover the story, but I was unable to find anything about it in the American press.
I suppose in this instance we will have to rely on the Indian media to provide some transparency to this event. Parth Shastri at TNN reports:
It could well be one of the biggest data thefts in the country. An Ahmedabad-based BPO owner, Maulik Dave, has been accused of data theft from a Florida-based company and selling them to its rival companies in the US.
Dave stole data worth Rs 1 crore (ten million) from the company. With the help of his accomplice based in the US, Milan Dabhi, he sold the data to competitors of the company in the US.
Apparently this occurred after Dave got his contract cancelled with Noble Ventures Inc., who "provides customer database of 1.25 crore (ten million) US citizens to various marketing companies in the US and also has a client-base in other international markets," according to the TNN article.
Of even greater concern to me was the deduction (my speculation) that Dave had insider access to their systems after his contract was cancelled? From the article, it is unclear if this was because the access was never removed, or if he got it from another Noble Ventures employee, Milan Dabhi, who is based in the U.S. and allegedly Dave's accomplice.
In another article published by the IT Examiner in India a person claiming to be a spokesman for Noble Ventures, Sunny Vaghela with credentials as a cyber crime expert, claimed that the information was stolen, but never sold. The rationale for this was that Noble Ventures reported the theft to Indian authorities and a sting (?) was conducted.
From the IT examiner article:
He further added claiming the theft report of 12.5 million Americans’ personal and professional records to be untrue as he assumed of some kind of miscommunication between the reporters and the Police.While I hope this is true, the logic in this is flawed (my opinion) because the information was stolen by someone, who had inside access prior to the discovery that the data was being compromised. How can it be determined that it was never sold to anyone else? Information is bought and sold in a lot of places, including underground Internet forums set up for illicit purposes. Additionally, no matter where it might have been sold, it is unlikely that anyone, who bought it illegally is going to stand up and be counted in this affair.
I went to the Noble Ventures site and they offer a lot of information for a price. Targeted data on executives, "heroes" (police and firemen), veterans and a slew of other marketing segments can be obtained. They even sell e-mail lists.
While I couldn't determine if this information was enough to open a line of credit, it could certainly be used to mount telemarketing scams, spam campaigns and even whaling (phishing) expeditions like the recent one we've seen targeting executives in the United States. Verisign just reported that 15,000 white collar types were speared in this expedition.
Please note that even though I am assuming no financial or SSN information was compromised -- if a dose of social engineering, phishing or malicious software is added to the equation -- getting the rest of the information to commit identity theft would probably be fairly easy.
Incidents, such as this, continue to point to the fact that there is too much information being stored in too many not very well protected places. In fact, this incident might point to the fact that the problem is getting worse.
We also need to remember that this information came from a U.S. company, and although I don't know where the server was physically located, it didn't have to be located in India for this to have occurred.
Information like this is protected by the FTC's Telemarketing Sales Rule.
Violations in the United States of this rule can be reported, here.
TNN story from India can be seen in full, here.
ComputerWorld, Norway story about this, here.
CIO Australia story, here.
Saturday, May 03, 2008
Does the proposed class action settlement in the Certegy data breach case lack teeth?
I happened to notice, I was getting a lot of hits on some posts about the Certegy data breach and discovered that there is a proposed settlement in the class action law suit against them.
Tim Wilson at Dark Reading pointed out that this settlement amounts to Certegy paying less than $1 per victim and wrote:
Of note, I would imagine the plantiff's lawyers made A LOT more than $1 each for orchestrating this event. In all fairness, given the precedent set by similar actions might mean there isn't a very "deep pocket" on this type of action.
At $1 million for monitoring divided by 8.4 million potential victims, if any of them want the free monitoring, they better move quickly.
So far as the $4 million being set aside to make victims whole, I wonder how hard it is going to be for them to prove (as required by this settlement) that Certegy was the point-of-compromise in their case? The general rule of thumb is that identity thieves, even if they are caught (rare), probably aren't 100 percent sure where the information came from themselves. There is so much stolen information out there, it's being traded over the Internet.
The sad truth is that with all the data breaches out there, it might be hard to prove exactly where an identity theft victim's information was compromised.
So far as the criminal prosecution of the employee, one William Sullivan, who sold off 8.5 million people's records, I did a post in November about how he was able to make a plea bargain and get a reduced sentence in this case. There was a mention of a data broker being a co-conspirator, but they never seemed to be named (at least in public).
Personally, I've always had mixed feelings about law suits that result when data breaches occur. There is an argument that at least some (my opinion) of the organizations being breached are victims in the overall equation, also.
Saying that, if this class action and the one for TJX have set the legal precedent on this type of action, they are unlikely to serve as much of a deterrent against data breaches, or all the identity theft that results from them. Furthermore, the criminal prosecution of William Sullivan in his case is unlikely to be much of a deterrent, either.
In fact these results are probably going to do little to inspire organizations to protect their information better and for some, will probably be viewed as a cost of doing business.
I guess it's time to go back to the drawing board to figure out a way to effectively address information/identity theft and data breaches?
Here are the original posts, I did on this matter, which contain some angry commentary from more than one victim:
Not to worry, check processing company (Certegy) believes the 2.3 million stolen records will not be used for fraud!
Certegy reveals their data breach is a lot larger than originally reported
Class action law suit filed against Certegy for data breach
Tim Wilson at Dark Reading pointed out that this settlement amounts to Certegy paying less than $1 per victim and wrote:
Certegy Check Services is proposing to settle a class action lawsuit of last year's security breach on behalf of 8.4 million victims for about $4 million.He also surmised in his article that:
According to a report in the St. Petersburg (Fla.) Times, Certegy will also offer free credit monitoring services to some victims and reimbursement of credit monitoring expenses totaling $1 million on a first-come-first-served basis.
While plaintiffs' lawyers hailed the offer as a victory, critics said the relatively small settlement will not help the cause of identity protection. The massive TJX breach also resulted in a relatively small settlement for the victims, netting about $6.5 million for customers.
Of note, I would imagine the plantiff's lawyers made A LOT more than $1 each for orchestrating this event. In all fairness, given the precedent set by similar actions might mean there isn't a very "deep pocket" on this type of action.
At $1 million for monitoring divided by 8.4 million potential victims, if any of them want the free monitoring, they better move quickly.
So far as the $4 million being set aside to make victims whole, I wonder how hard it is going to be for them to prove (as required by this settlement) that Certegy was the point-of-compromise in their case? The general rule of thumb is that identity thieves, even if they are caught (rare), probably aren't 100 percent sure where the information came from themselves. There is so much stolen information out there, it's being traded over the Internet.
The sad truth is that with all the data breaches out there, it might be hard to prove exactly where an identity theft victim's information was compromised.
So far as the criminal prosecution of the employee, one William Sullivan, who sold off 8.5 million people's records, I did a post in November about how he was able to make a plea bargain and get a reduced sentence in this case. There was a mention of a data broker being a co-conspirator, but they never seemed to be named (at least in public).
Personally, I've always had mixed feelings about law suits that result when data breaches occur. There is an argument that at least some (my opinion) of the organizations being breached are victims in the overall equation, also.
Saying that, if this class action and the one for TJX have set the legal precedent on this type of action, they are unlikely to serve as much of a deterrent against data breaches, or all the identity theft that results from them. Furthermore, the criminal prosecution of William Sullivan in his case is unlikely to be much of a deterrent, either.
In fact these results are probably going to do little to inspire organizations to protect their information better and for some, will probably be viewed as a cost of doing business.
I guess it's time to go back to the drawing board to figure out a way to effectively address information/identity theft and data breaches?
Here are the original posts, I did on this matter, which contain some angry commentary from more than one victim:
Not to worry, check processing company (Certegy) believes the 2.3 million stolen records will not be used for fraud!
Certegy reveals their data breach is a lot larger than originally reported
Class action law suit filed against Certegy for data breach
Saturday, July 28, 2007
Certegy reveals their data breach is a lot larger than originally reported
Earlier this month, I blogged about the Certegy data breach, where a not very HONEST employee got caught selling information to an unidentified data-broker. Certegy was quick to assure the public that none of this information would be used to commit fraud because it was being used by "legitimate marketing firms."
Now the number of records (people compromised) has risen significantly after Certegy filed a report with the Securities and Exchange Commission.
The Tampa Bay Business Journal Reports:
Florida Attorney General Bill McCollom listed some useful information for victims in a press release, which said:
I've received a lot of comments on my original post, including some (anonymous) claiming their information was used for fraud. Unfortunately, I cannot verify this information, but someone with the e-mail address LPLong@Yahoo.com claims to be collecting victims to file a class action law suit.
My original post with comments, here.
Press release from Florida Attorney General (Bill McCollom), here.
Note this is probably the right place to verify information, if you receive a letter. If you believe you are fraud victim based on the Certegy breach, I would let them know about it, also.
Tampa Bay Business Journal article, here.
Now the number of records (people compromised) has risen significantly after Certegy filed a report with the Securities and Exchange Commission.
The Tampa Bay Business Journal Reports:
An ongoing investigation has determined that about 8.5 million consumer records were stolen, according to a July 25 Securities and Exchange Commission filing by Fidelity National Information Services Inc. (NYSE: FIS), the Jacksonville-based parent company of St. Petersburg-based Certegy.According to Fidelity, Certegy's parent company the investigation is continuing and this number could grow.
Florida Attorney General Bill McCollom listed some useful information for victims in a press release, which said:
For more information, consumers may call Certegy at 866-498-9916 or may visit their website at http://www.certegy.com. Affected consumers are encouraged to take the precautionary steps outlined in the Certegy letter, including obtaining a free fraud alert from one of the credit reporting agencies. Furthermore, if consumers believe at any time they are victims of identity theft, they should report this to the police and request that the national credit bureaus place a fraud alert on their credit reports. Consumers should also notify banks and creditors involved of questionable charges or accounts, keep records of all telephone calls and follow up in writing with credit bureaus, banks and creditors.
If you received a letter from Certegy and you continue to receive marketing calls that you suspect result from this data breach, please report this activity to the Attorney General’s Citizens Services Hotline at 1-866-9-No SCAM (1-866-966-7226). Additional information about protecting yourself from identity theft is available online at http://www.myfloridalegal.com/identitytheft.
I've received a lot of comments on my original post, including some (anonymous) claiming their information was used for fraud. Unfortunately, I cannot verify this information, but someone with the e-mail address LPLong@Yahoo.com claims to be collecting victims to file a class action law suit.
My original post with comments, here.
Press release from Florida Attorney General (Bill McCollom), here.
Note this is probably the right place to verify information, if you receive a letter. If you believe you are fraud victim based on the Certegy breach, I would let them know about it, also.
Tampa Bay Business Journal article, here.
Wednesday, July 04, 2007
Not to worry, check processing company (Certegy) believes the 2.3 million stolen records will not be used for fraud!
Large data breaches are becoming a VERY frequent news event! This time only 2.3 million records were stolen, a mere fraction of the amount (45 million plus) TJX lost. In this instance, we are told we have nothing to fear because the information was sold to a data broker.
Ron Word of the AP (courtesy of the Washington Post) reports:
This occurred at one of their subsidiaries, Certegy Check Services.
According to the article:
Since Certegy verifies check transactions, this probably means a lot of checking account information in addition to some credit and personal information. From a financial crimes perspective, this information could be used to commit a lot of identity theft, check and credit card fraud.
The company claims the information was sold to data brokers, who sold it to direct marketers. Their president, Renz Nichols, "believes" this is the extent of the damage.
Not sure, if I can "believe" that no one is at risk. The last time I checked, identity thieves normally shy away from revealing exactly, who they intend to compromise next. It's bad for business. Besides that, is this based on the word of someone, who stole the information and sold it in the first place?
Interestingly enough, the data broker is unnamed at this point. The AP article does say they are claiming they didn't know the information was stolen. I wonder how this data broker verifies the information they get, and who they are getting it from?
Data brokers and credit bureaus sell information all the time. Recently, a data broker (InfoUSA) was caught selling direct marketing information to spammers, who commit lottery fraud schemes.
The sad thing is that once the information starts getting sold, it becomes available to more and more insiders, who might sell it to the wrong person, assuming it hasn't been already.
And there is so much information to be sold, no one is ever sure exactly where it came from. Criminals are even selling it via the Internet to other criminals.
AP Story (courtesy of the Washington Post), here.
Attrition.org is tracking data breaches, here. The amount of them that happen is pretty scary!
I've written a lot of about how data brokers make billions buying and selling our information, which can later used against us, here.
They don't believe they are enabling a worldwide problem, either.
At least that's what I keep hearing, whenever a new data breach is announced.
Ron Word of the AP (courtesy of the Washington Post) reports:
Fidelity National Information Services, a financial processing company, said yesterday that a worker at one of its subsidiaries stole 2.3 million consumer records containing credit card, bank account and other personal information.
This occurred at one of their subsidiaries, Certegy Check Services.
According to the article:
About 2.2 million records stolen from Certegy contained bank account information and 99,000 contained credit card information, company officials said.
Since Certegy verifies check transactions, this probably means a lot of checking account information in addition to some credit and personal information. From a financial crimes perspective, this information could be used to commit a lot of identity theft, check and credit card fraud.
The company claims the information was sold to data brokers, who sold it to direct marketers. Their president, Renz Nichols, "believes" this is the extent of the damage.
Not sure, if I can "believe" that no one is at risk. The last time I checked, identity thieves normally shy away from revealing exactly, who they intend to compromise next. It's bad for business. Besides that, is this based on the word of someone, who stole the information and sold it in the first place?
Interestingly enough, the data broker is unnamed at this point. The AP article does say they are claiming they didn't know the information was stolen. I wonder how this data broker verifies the information they get, and who they are getting it from?
Data brokers and credit bureaus sell information all the time. Recently, a data broker (InfoUSA) was caught selling direct marketing information to spammers, who commit lottery fraud schemes.
The sad thing is that once the information starts getting sold, it becomes available to more and more insiders, who might sell it to the wrong person, assuming it hasn't been already.
And there is so much information to be sold, no one is ever sure exactly where it came from. Criminals are even selling it via the Internet to other criminals.
AP Story (courtesy of the Washington Post), here.
Attrition.org is tracking data breaches, here. The amount of them that happen is pretty scary!
I've written a lot of about how data brokers make billions buying and selling our information, which can later used against us, here.
They don't believe they are enabling a worldwide problem, either.
At least that's what I keep hearing, whenever a new data breach is announced.
Wednesday, April 11, 2007
Warning if you don't open (and respond) to snail mail from American Express, they will sell your personal information!
I get snail (mostly junk) mail from credit issuers, daily. Being concerned about identity theft and my personal privacy, I try to shred all of them. But am I doing the right thing? As you will see, some of them probably hope I never do.
Here is what happened to someone, who is a lot more diligent than I am (he actually opens the mail). Christoper Null (ATT/Yahoo Tech blogger) got his most recent privacy notice from American Express, which informed him if he didn't want all of his personal and financial information sold, he needed to opt-out with them.
They gave him two methods to do so, snail mail and a 1-800 number. Chris selected the 1-800 number and here is what happened:
He later (being the saavy tech guy he is) tried to go to their webstite to opt-out and was only able to opt out from electronic, not snail communication.
Very REVEALING post from Chris, here.
It is pretty scary that credit card companies require us to opt-out, and if we don't, they sell our information to, anyone and everyone. After all, selling information, is highly profitable.
The Personal Finance Blog did a post about how much personal information is worth (retail-value), here.
The post is about a year old, and the prices might vary, depending on who is selling it.
I guess the finance industry has found a way to get around recent privacy concerns, and they do it under the guise of a privacy notice!
It's no wonder there is so much identity theft!
Here is what happened to someone, who is a lot more diligent than I am (he actually opens the mail). Christoper Null (ATT/Yahoo Tech blogger) got his most recent privacy notice from American Express, which informed him if he didn't want all of his personal and financial information sold, he needed to opt-out with them.
They gave him two methods to do so, snail mail and a 1-800 number. Chris selected the 1-800 number and here is what happened:
I call (800-297-8378 if you want to try it for yourself). I get a recording welcoming me American Express and notifying me that the call could be recorded... thenabruptly says: "The computer system needed to answer your questions is not available." And it hangs up.According to several comments on his post, the 1-800 was down for quite awhile.
Now I understand computers go down, but that was five days ago, and I'm still getting the recording. Will it ever come back online or is it all a scam? The paranoid side of me believes that there is no computer connected to this 800 number, and that it's designed to trick me into forgetting about the entire matter and being too lazy to fill out the paperwork so I'll remain opted in.
He later (being the saavy tech guy he is) tried to go to their webstite to opt-out and was only able to opt out from electronic, not snail communication.
Very REVEALING post from Chris, here.
It is pretty scary that credit card companies require us to opt-out, and if we don't, they sell our information to, anyone and everyone. After all, selling information, is highly profitable.
The Personal Finance Blog did a post about how much personal information is worth (retail-value), here.
The post is about a year old, and the prices might vary, depending on who is selling it.
I guess the finance industry has found a way to get around recent privacy concerns, and they do it under the guise of a privacy notice!
It's no wonder there is so much identity theft!
Subscribe to:
Posts (Atom)
