Showing posts with label employee dishonesty. Show all posts
Showing posts with label employee dishonesty. Show all posts

Monday, December 10, 2007

SIRAS offers guarantee that it will reduce retail crime

The reason SIRAS' product registration and smart return service perked my interest is because it protects people's privacy and is an effective means of reducing losses.

SIRAS tracks an inanimate object (merchandise) instead of a customer's personal information.

Now they are now offering a "guarantee" the technology will add dollars to a organization's bottom line by reducing fraudulent returns.

In their own words from the press release regarding this matter:

Electronic Product Registration, is putting its money where its mouth is with a unique Return On Investment (ROI) Guarantee for any company using SIRAS’s product registration and Smart Return service to manage their product returns and warrantees. The program, designed to eliminate any risk for companies interested in implementing SIRAS’s technology, guarantees that over the course of a year companies will save more money through deflected product returns than it spends in transaction fees.

In case you haven't had to refund any merchandise in a long time, most retailers require you to give them your personal statistics before they approve your return.

This information is all maintained in a database, where it might be exposed to a hacker, or probably more frequently, dishonest employee. Information is worth a lot of money to anyone, who knows where to sell it.

A dishonest Certegy employee recently got caught selling 8.5 million people's information to an undisclosed data-broker. Since the mysterious data-broker still hasn't been identified -- despite being listed as a co-conspirator in court filings -- we really aren't sure where these records went?

Certegy provides check verification services for a lot of merchants.

Personal and financial information is marketed in carder forums (chat rooms) on the Internet. Anonymous payment methods, such as wire transfers, PayPal and eGold add to the problem. They make it relatively easy to buy and sell stolen information.

It also isn't unknown for criminal organizations to plant, or recruit employees to steal information from within an organization.

The press release quotes Peter Junger (SIRAS CEO) as saying, "And in all cases, regardless of ROI, clients retain all of the valuable POS data collected."

This POS data also serves another important purpose. If the merchandise is found in a fencing operation, or on an auction site, it can still be tracked to the point-of-compromise.

This opens up opportunities to recover stolen merchandise and makes it more dangerous for the criminals fencing it.

Mesa Police Department tested these capabilities with SIRAS and FOX News did a story on it, which can be seen, here.

The technology, when deployed properly with a point-of-sale system can also identity fraudulent means of tender used to purchase merchandise.

SIRAS technology can be deployed by a merchant, or at the factory, itself.

They already makes their database available to law enforcement free-of-charge.

With all the identity theft and counterfeit ID available, using SIRAS reduces the possibility that an innocent customer will be wrongfully identified as an "undesirable" in a refund database.

Saying that, who knows how much of the information in these databases is one-hundred percent accurate anymore? With retail crime becoming more and more organized, the possibility exists that it is NOT.

One of the systems targeted in the TJX data-breach was their refund database. The information in this database is probably worth more than simple financial information because it contains the elements necessary to assume a person's identity.

It's relatively easy to shut down a bank account, or credit card number. Once a person's statistics are compromised, they can be at risk of identity theft for a long time.

Data breaches are becoming more expensive. TJX claimed a loss of $118 million in their second quarter earnings. Estimates vary widely on exactly how expensive data-breaches will become, but everyone agrees the cost of them is going up.

SIRAS seems more effective in resolving property crimes because it tracks the property, itself. It also protects customer privacy and protects a merchant from becoming the victim of a data-breach.

I doubt that SIRAS would make this guarantee if they weren't absolutely certain of the results. If they were wrong, I doubt they would be in business very long.

Press release from SIRAS, here.

Tuesday, July 31, 2007

Correctional Officers steal credit cards from prisoners

Ran into a pretty sad story, where it was reported that two Baltimore correctional officers were caught stealing credit cards from inmates they were processing into jail.

John-John Williams IV of the Baltimore Sun reports:

Two corrections officers from the Central Booking and Intake Center were arrested yesterday and charged with stealing credit cards of people under arrest.

Lontona Maria Webb, 38, of the 3600 block of Clarinth Road and Latoya Renee James, 24, of the 1300 block of Dalton Road each face multiple counts of credit card fraud, identity theft and misconduct in office, according to charging documents.
The authorities investigating the case aren't commenting because the investigation is still underway.

It also appears that the Baltimore Sun and an attorney, who was arrested (charges later dropped) are responsible for alerting the authorities that their jail needs a little cleaning up:

Nicholas Panteleakis, 34, a city public defender, said that his credit card was used to make nearly $1,000 in fraudulent purchases at McDonald's, Target and a gas station.

Panteleakis said that his credit card company took care of all of the fraudulent charges.

The Sun detailed Panteleakis' claims of fraud at Central Booking in February. At that time, Panteleakis said he discovered that someone had used his credit card within six hours of his release from Central Booking. He said he believes the card was stolen after his wallet was checked as property at the facility when he was arrested on one count of loitering, a charged later dropped. He immediately canceled his credit card.

"If it wasn't for my access to the media and other avenues, I don't think anything would have become of it," he said. "People would still be having their stuff stolen from them."

As a result of this, officials at the jail have had video surveillance cameras installed to watch the area, where personal property is inventoried.

It's sad when we discover those, who have taken a sacred oath to uphold the law, violate it. They damage the reputation of their profession, and all the fine people, who take this oath seriously!

Unfortunately, this isn't the first time, I've done a post, where a correctional officer (and some Jet Blue employees) were stealing credit cards:

Airline employees and correctional officer arrested for credit card fraud

Baltimore Sun story, here.

Wednesday, May 02, 2007

Airline employees and correctional officer arrested for credit card fraud

A lot of payment (credit/debit) card fraud is caused by dishonest employees, who skim the information from cards; or might even simply forget to return them to you. And when they "forget" to return them, it might be intentional!

The New York City District Attorney's Office announced:

Manhattan District Attorney Robert M. Morgenthau announced today the arrest of four JetBlue employees and a New York City Department of Corrections Officer for the unauthorized use of credit cards from Jet Blue customers.

Press release, here.

Pretty scary, that Jet Blue (airline) personnel and a correctional officer, who should be people that can be trusted, seem to have given a black eye to their professions.

I saw this story the day after I had to go back to a Del Taco, who failed to return my card to me. After going to considerable trouble to get my card back (which I should probably cancel), I was amazed that no one apologized to me for what had occurred.

They even charged me for the ice tea, I ordered when returning to get the card.

On a more serious note, businesses should always make sure lost payment devices and identification are properly secured. They should only be maintained for a short period of time, then destroyed to prevent someone compromising (using) them.

Many people would be shocked at how often these lost and found items are maintained (sometimes for years) in not very secure places, such as an unlocked drawer.

At least, the Del Taco manager did make me show ID to get my card back, but she didn't do very much to make me rave about their customer service. A kind, or sympathetic word can do a lot of smooth out an unfortunate situation, like this one!

So far as restaurant employees involved in credit card fraud, a lot has been written about this, recently.

Here is my version of what a lot of people have been writing about:

Why it's become TOO easy for restaurant workers to skim payment cards

Please note, it's probably not fair to single out restaurant workers, this can occur at any business that accepts plastic, or even checks.

Wednesday, November 15, 2006

Why Buying Gift Cards on Auction Sites isn't a Good Idea

I recently did a post wondering if sites reselling gift cards would create an additional avenue for dishonest people to commit fraud. After all - gift card fraud - isn't new and eBay limits the sales of them on their sites because of the criminal activity associated with them.

The main reason eBay limited the sales on their site was pressure from the retail industry, or so I've read.

Fraud committed against retailers costs billions, and it's added into the "cost of goods sold," which means we are all paying higher prices because of it. There is a limit to being able to add the price of fraud into the cost of an item (competition) and when this happens, businesses fail.

A lot of people have lost their jobs when retail fraud couldn't be controlled.

In response to my original post, Joe LaRocca, Vice President of Loss Prevention for the National Retail Federation was kind enough to send me some links illustrating how big a problem this has become.

In November, the NRF released information that estimates retailers will lose $3.5 billion during the holiday (Christmas) season - link here.

Many retailers issue gift cards versus cash for refunds (especially when no receipt is present) and fraudsters sell them for cash. Joe provided me with an interesting link on this (story and video clip) from NBC4.com, here.

Refund fraud normally is a result of shoplifting, but when dealing with gift card fraud, we also need to include credit/debit card and check fraud. Retail fraudsters buy gift cards with their "bogus financial instruments" and then sell the cards for cash. Of course - they could be refunding merchandise bought with their bogus instruments - but it's easier (less work) for them to simply buy the "gift cards" and resell (fence) them.

Credit/debit card and check fraud are two activities that directly tie into "identity theft," which victimizes 9 million people a year in the United States, alone.

Besides the "indirect costs" we all pay - a lot of ordinary people become fraud victims after an encounter with a fraudster on an auction site. The Internet Crime Complaint Center cites auction fraud as their number one complaint and it keeps growing every year.

Besides placing yourself at risk - buying gift cards over the Internet - might be supporting the victimization of ordinary people and businesses alike!

Saturday, August 26, 2006

Secret Service is Studying the Problem from Within

The USSS (Secret Service) is studying how dishonest "insiders" can pose a large problem to organizations.

Here's what they say about it in their press release:


The report released today focuses on the people who have had access to and have perpetrated harm using information systems in the banking and finance sector, which includes credit unions and financial institutions. The findings underscore the importance of organizations’ technology, policies and procedures in securing their networks against insider threats, as most of the cases showcased in the report were perpetrated by insiders with minimal technical skills. Various proactive practices are among the suggestions offered by the report.

“With the potential for cyber crime and network intrusion expanding rapidly around the globe, the importance of cooperation with our partners in the private sector is greater than ever,” said Secret Service Director W. Ralph Basham. “The Insider Threat Study is a solid example of the role the Secret Service and its partners can play in understanding threats and helping to prevent serious crimes such as network intrusions, identity theft and financial fraud.”
Link to press release, here.

Link to full study, here.

I have no doubt that individuals and even people planted as "insiders" pose a serious threat to the safety/security of any organization. Information is worth a lot of money and getting an asset on the inside makes stealing it, pretty easy.

There is a report by the Privacy Rights Clearinghouse, I quote often, which shows that the reason for a lot of data breaches is never discovered, here.

I wonder if any of them were inside jobs?