Showing posts with label fraud blog. Show all posts
Showing posts with label fraud blog. Show all posts

Saturday, August 18, 2007

Russian identity thieves target the rich and famous


Photo courtesy of CarbonNYC at Flickr

An interesting story hit the news this week about some Russian identity thieves targeting the rich and famous.

The ringleader was talked into meeting Federal Agents in the Dominican Republic, then entered the country (he believed illegally) and was arrested. Not very bright, especially given the clout of his intended victims.

Tom Fragala at the Truston Blog had some interesting and well thought out commentary about how the less rich and not so influential might be targeted in a caper like this.

In Tom's own words:

ID thieves going after the ultra-rich or celebrities is nothing new. That is not what makes this story interesting to me. It’s that the “ring” of thieves showed a bit of ingenuity in how it targeted the victims. The ring leader allegedly did public records searches such as home purchases. That’s right, if you purchase a home, then tremendous amounts of information about you is made available to anyone for a small fee. The law requires the information is made public via a UCC filing (uniform commercial code). Then using that information, such as the bank listed on the mortgage documents, and piecing together parts of your identity from other places, your financial accounts might be able to be compromised. In other words, if the thief knows your brokerage account is with Wells Fargo, the thief can then pose as you to authorize a withdrawal. Perhaps a wire transfer to Russia, Vanuatu or Nigeria.

And your bank is not necessarily going to come riding to the rescue and return your funds because, well, “they have to, right?” Not exactly. Can you name the US federal statute that provides consumer fraud protections for your brokerage or home equity account like FCRA does for your credit card? Don’t waste your time, it doesn’t exist. What about the Federal Trade Commission, don’t they help you? Nope, they have no jurisdiction. Banking oversight is handled by a hodge podge of agencies depending on where and how your bank/credit union is chartered.
According to the story, the information to do this was data mined online (probably from a County or State website).

Too much personal information being stored on government sites is a huge problem. Recently, I did a post about Betty Ostegren a.k.a. (also known as) the Virginia Watchdog. Betty actively goes after State and County governments, who leave information on their sites that could be used to commit identity theft, or worse. Although, a lot of sites have pulled some of the information off their sites, it's still a major problem.

When I was working on the post, Betty was able to show me how she has been able to view the personal information of a lot of prominent people from the comfort of her home.

In this instance, the crooks were caught, but the amount of money they almost got away with is scary.

Truston blog post, here.

Tom is the CEO of Truston, which is the only identity theft detection/recovery service (that I know of) that doesn't require you provide all your personal information to them. They are also unique in the fact that their detection (prevention) services are free.

A lot of identity theft services out there require you to surrender all your information and even give them your power of attorney.

As evidenced in the recent Certegy data breach, a dishonest employee, who has been given access to the information can compromise the best computer security. Besides internal compromises, external hackers seem to still be able to get into databases. TJX was recently compromised by hackers, who stole about 45 million personal and financial records.

A lot of their critics were quick to point out that they shouldn't have been storing some of this information in their proprietary databases.

Interestingly enough, one of main principles of PCI (Payment Card Industry) data security standards is to not store information in too many different places. These standards were set by the payment card industry to protect information, but as of this writing, not everyone has adopted them.

This is a Catch 22 (no-win) situation because (I suspect) many merchants store information to avoid chargebacks for fraudulent transactions.

I've often wondered how quickly this would all get fixed if compliance was mandatory to accept debit/credit card transactions?

Storing our personal and financial information in too many places is probably one of the root causes of the problem with data breaches.

Friday, August 17, 2007

Are fraudulent practices partially to blame in the current mortgage crisis?

We seem to be facing a looming financial crisis because of irresponsible lending practices that enabled a lot of people to buy property that was beyond their means.

Many will blame the people, who took out the mortgages, but are there other factors bear consideration when looking into the cause?

Although fraud hasn't been cited as a reason, government investigators might be pretty busy in a effort to discover why this problem occurred.

The Herald Tribune is reporting:

Within the next six months, it should be clear how regulators will proceed against those companies, said Michael Malloy, a former enforcement official of the U.S. Securities and Exchange Commission.

"Odds being what they are, somebody's going to get hooked," said Malloy, who now teaches at the McGeorge School of Law, part of the University of the Pacific. "From an investigative point of view, they'll be looking at how much of this was the result of stupidity and misfortune and how much is broader manipulation."

The broader manipulation could include failing to appropriately disclose the value or the risk of securities backed by subprime loans, which could constitute fraud, experts say.
Mortgage fraud is a bigger problem than most people think.

A good place to learn about all the various schemes and who is getting caught committing mortgage fraud is the Mortgage Fraud Blog, which can be viewed, here.

Herald Tribune story, here.

Wednesday, February 28, 2007

Could the arrests in the Stop and Shop data breach indicate a tie to Armenian Mobsters?

( Photo courtesy of Stop & Shop and the Rhode Island Police)

Stop & Shop has recently been in the news because of a data breach, involving compromised debit and credit card information. The data breach was traced to PIN pads that had been mysteriously replaced.

To read my original post on the Stop & Shop data-breach, link here.

Monday night, Stop & Shop employees spotted four individuals attempting to remove PIN pads at one of their stores. Police were notified, store video was shared with them, and four arrests were eventually made.

After the disclosure, Stop & Shop bolted down the PIN pads at all their stores. Some believe this helped slow the crooks down long enough to be noticed.

Despite this, some alert employees certainly deserve some recognition.

The Rhode Island police published some of the video stills of the suspects in action, here.

Ray Henry of the AP is reporting:

The men were arrested Monday night while attempting to switch keypads at a store in Coventry, police said. A store security officer called police after employees noticed one suspect trying to remove a keypad while two others were seeking to distract workers.

Arutyun Shatarevyan, 20, Mikael Stepanian, 28, Gevork Baltadjian, 20, and Arman Ter-Esayan, 22, were arrested and charged with conspiracy, computer theft and fraud. They were scheduled to be arraigned Tuesday afternoon in Kent County District Court.
Data breaches have become a huge issue, with new reports surfacing (it seems) every week. Over 100 million Americans have had their information compromised since 2005, according to the Privacy Rights Clearinghouse, which has maintained a chronology of these occurrences.

AP story, here.

Interestingly enough, the arrested individuals are from California. Judging by their surnames, they are of Armenian descent. This brings to mind a previous breach, where two fraudsters were charged after a data breach at Dollar Tree - they were also from California and have Armenian surnames.

Parkev Krmoian was arrested in the Dollar Tree episode and (at the time), a picture of his friend was being circulated (who was still at large), here.

Armenian organized crime is a big problem in Glendale (where Krimoian was from), and they are known to be involved in "lucrative white collar crimes," such as credit-card fraud. Glendale and Hollywood in Southern California has the largest Armenian population outside of Armenia.

If you are interested in learning more about Armenian organized crime, ARMENIANDIASPORA.com has a nice little write-up, here.

Placing skimming devices in public places is a growing phenomenon, Tom Fragala (MyTruston) did a great post on this (with video), here.

The video is pretty amazing!

Thursday, February 22, 2007

Tax Refund Loans attract fraudsters

There are a lot of people trying to scam tax preparers and the government.

Part of the problem is that W-2 forms are easily purchased at just about any Office Supply store and forged.

KGO, San Francisco (Alan Wong) reports:

The latest trend in tax fraud has made its way to the Bay Area and it could be costing the federal government millions.

People are being enticed to cheat Uncle Sam and then split the take.
The goal is to get these tax preparers to give them a loan (refund anticipation type) and walk out with about $6,000 - $8,000 in cash.

Fraudsters recruit low income/unemployed people to go in with the forged W-2s and get these loans.

KGO story, here.

Of course, those who get recruited will end up holding the bag if the IRS discovers this happening and takes the matter for prosecution. My guess is the people recruited will bear the brunt of any punishment because their information is being used, and the fraudsters (recruiters) will disappear in the mist.

These recruiters can be reported to the IRS, here. Of note, they mention that anyone reporting criminal activity might be entitled to a reward.

Here is a previous post, which covers all the scams the IRS looks for this time of year:

Don't be lured with promises of something too good to be true when filing your taxes

Identity theft is also becoming an issue when people try to file their taxes. A lot more than W-2s are being counterfeited these days.

News 25 (Peoria) is reporting how people are going to file their taxes and discovering someone else has already filed using their social security number.

News 25 story, here.

I wonder who will be liable for all the problems a taxpayers faces if their identity is stolen, and someone issues one of these handy dandy refund anticipation loans to a fraudster?

Unfortunately, my guess is that the identity theft victim will suffer the most.

Clearing up problems with the IRS can be a painful experience.

Tuesday, February 20, 2007

Counterfeit Check (Cheque) Scams are all over the Internet

The amount of counterfeit checks (cheques) being circulated via various Internet scams, and even the classifieds (paper media) is on the rise.

A new trend is also being seen, where people are getting these counterfeits items in the mail (unsolicited). Some of us, who watch this closely, suspect they are data mining information off job sites, like Monster.com and Craigs List.

Last April, I did a post about a Better Business Bureau (BBB) employee, who got a lot of negative attention after she accepted a job to cash bogus intruments and send the money overseas.

Common scams in which these checks are sent for someone to cash and wire the money back to fraudsters are the check cashing (job), lottery, auction, secret shopper, romance and Nigerian letter varieties.

According to the National Consumers League, counterfeit checks schemes rank near the top of the scams reported to them by victims.

High quality counterfeit money orders and travelers/gift cheques are making the Internet fraud scene, also. In the recent past, these have included Postal Money Orders, Travelers Express (MoneyGram) Money Orders and most recently, American Express Gift Cheques.

The NCL has an interesting page on their site about the most prevalent scams reported to them in 2007, here.

And don't expect the bank to tell you (whether or not) a check is good. Since they have no liability in the matter, they will often say the item is good, give you provisional (temporary) credit, then take the money away from you when it is determined to be a fraud.

Here is a previous post about how this occurs:

Don't Trust a Bank to Tell You Whether a Check is Good, or Not

Some of these scams direct you to places like Walmart to cash the item, and wire the money back to them, also. I've had readers leave comments and send me e-mails about getting arrested after attempting to pass one of these items at Walmart.

Before we smear Walmart, consider that with the amount of these items in circulation, its getting harder and harder to determine, who is and who is not, really a victim.

Check fraudsters are now posing as victims, and are scamming the scammers by cashing the items. If they are caught, they claim to be innocent victims.

I've personally spoken to a few of these alleged victims, and for some reason; they never seem to have wired (or sent) any of the money back?

Interestingly enough, the scammers love to direct people to Walmart (probably because they cash checks and wire money), but they could care less if you get arrested.

The bottom line is that even if the check is initially considered good, it can easily return, and the person passing it is held responsible.

Deb Radcliff (cybercrime author) did an interesting blog post about how law enforcement, and the companies having their brands used on these checks aren't going after the cuplrits, here.

Unfortunately, they normally don't have much to go on, and the crime is normally initiated from a foreign country.

Saturday, February 17, 2007

Why don't all the identity theft statistics say the same thing?

Consumer Affairs wrote an interesting article about all the recently released identity theft surveys.

Martin H. Bosworth reports:

The financial services industry, hoping to befuddle the new Congress, has been busily laying down a smokescreen claiming that identity theft is on the wane.

But the Federal Trade Commission's latest compilation of consumer complaints and a survey by the National Crime Prevention Council should do much to clear the air.

Martin's article, here.

Who should we believe, the government, or the financial services industry?

The civil servants behind the government surveys have no financial interest in all of this. On the other hand, the financial services industry have a huge financial interest. At least as long as they can still profit by writing all the losses off.

It's going to cost them some of their (hefty) profit margins to properly protect all the information they've been data-mining on all of us for decades. It also might force them to be more responsible when selling their products.

Interestingly enough, privacy and consumer advocates all seem to agree with the government.

Of course in any statistical analysis, there are a lot of unknowns. The Privacy Rights Clearinghouse regularly updates their statistics about how many people's personal information has been compromised in February, 2005.

They admit that their analysis might not be 100 percent accurate when they state:

The running total we maintain at the end of the Chronology represents the approximate number of *records* that have been compromised due to security breaches, not necessarily the number of *individuals* affected. Some individuals may be the victims of more than one breach, which would affect the totals. In reality, the number given below is much larger. For many of the breaches listed, the number of records is unknown.
It's also come to light recently that there is a flourishing market on the Internet, selling personal and financial information (wholesale), in underground chat-rooms.

This might support some of the data the Privacy Rights Clearinghouse has been compiling.

Of course, the people involved in this activity are unlikely to comment, or provide statistics of their own. I don't think it would be in their best interest to do so.

Doing so, might hurt their money flow, or cause them to lose their freedom.

The problem is that too many people have financial interests in what some of these surveys are selling to the public.

I think the Latin phrase, caveat lector (reader beware) certainly applies in this instance. I have a hard time believing what I read in some of this statistical analysis.

Tuesday, February 13, 2007

Don't be lured with promises of something too good to be true when filing your taxes

Tax season brings with it all kinds of fraud. A lot of immoral sorts try to get someone to fall for something that's too good to be true. They get away with it because people are afraid of what they might owe, or they take advantage of what I call the "greed factor."

One thing is certain, if you fall for their promises, you're going to be left holding the bag. This means financial hardship (at a minimum) and could mean incarceration (jail).

I firmly believe that education is the best weapon against fraud. And the best places to educate yourself about tax fraud is none other than the IRS website, itself.

They keep a close eye on trends involving tax fraud and publish the information for free.

On February 7th, they published the 2007 "Dirty Dozen Tax Scams."

Here are the 12 most prevalent scams, according to the IRS:

1. Zero Wages. In this scam, new to the Dirty Dozen, a taxpayer attaches to his or her return either a Form 4852 (Substitute Form W-2) or a “corrected” Form 1099 that shows zero or little wages or other income. The taxpayer may include a statement indicating the taxpayer is rebutting information submitted to the IRS by the payer. An explanation on the Form 4852 may cite "statutory language behind IRC 3401 and 3121" or may include some reference to the paying company refusing to issue a corrected Form W-2 for fear of IRS retaliation. The Form 4852 or 1099 is usually attached to a “Zero Return.” (See number four below.)

2. Form 843 Tax Abatement. This scam, also new to the Dirty Dozen, rests on faulty interpretation of the Internal Revenue Code. It involves the filer requesting abatement of previously assessed tax using Form 843. Many using this scam have not previously filed tax returns and the tax they are trying to have abated has been assessed by the IRS through the Substitute for Return Program. The filer uses the Form 843 to list reasons for the request. Often, one of the reasons is: "Failed to properly compute and/or calculate IRC Sec 83––Property Transferred in Connection with Performance of Service."

3. Phishing. Phishing is a technique used by identity thieves to acquire personal financial data in order to gain access to the financial accounts of unsuspecting consumers, run up charges on their credit cards or apply for new loans in their names. These Internet-based criminals pose as representatives of a financial institution and send out fictitious e-mail correspondence in an attempt to trick consumers into disclosing private information. Sometimes scammers pose as the IRS itself. In recent months, some taxpayers have received e-mails that appear to come from the IRS. A typical e-mail notifies a taxpayer of an outstanding refund and urges the taxpayer to click on a hyperlink and visit an official-looking Web site. The Web site then solicits a social security and credit card number. In a variation of this scheme, criminals have used e-mail to announce to unsuspecting taxpayers they are “under audit” and could make things right by divulging selected private financial information. Taxpayers should take note: The IRS does not use e-mail to initiate contact with taxpayers about issues related to their accounts. If a taxpayer has any doubt whether a contact from the IRS is authentic, the taxpayer should call 1-800-829-1040 to confirm it.

4. Zero Return. Promoters instruct taxpayers to enter all zeros on their federal income tax filings. In a twist on this scheme, filers enter zero income, report their withholding and then write “nunc pro tunc”–– Latin for “now for then”––on the return. They often also do this with amended returns in the hope the IRS will disregard the original return in which they reported wages and other income.

5. Trust Misuse. For years unscrupulous promoters have urged taxpayers to transfer assets into trusts. They promise reduction of income subject to tax, deductions for personal expenses and reduced estate or gift taxes. However, some trusts do not deliver the promised tax benefits, and the IRS is actively examining these arrangements. There are currently more than 200 active investigations underway and three dozen injunctions have been obtained against promoters since 2001. As with other arrangements, taxpayers should seek the advice of a trusted professional before entering into a trust.

6. Frivolous Arguments. Promoters have been known to make the following outlandish claims: the Sixteenth Amendment concerning congressional power to lay and collect income taxes was never ratified; wages are not income; filing a return and paying taxes are merely voluntary; and being required to file Form 1040 violates the Fifth Amendment right against self-incrimination or the Fourth Amendment right to privacy. Don’t believe these or other similar claims. These arguments are false and have been thrown out of court. While taxpayers have the right to contest their tax liabilities in court, no one has the right to disobey the law.

7. Return Preparer Fraud. Dishonest return preparers can cause many headaches for taxpayers who fall victim to their schemes. Such preparers derive financial gain by skimming a portion of their clients’ refunds and charging inflated fees for return preparation services. They attract new clients by promising large refunds. Taxpayers should choose carefully when hiring a tax preparer. As the old saying goes, “If it sounds too good to be true, it probably is.” And remember, no matter who prepares the return, the taxpayer is ultimately responsible for its accuracy. Since 2002, the courts have issued injunctions ordering dozens of individuals to cease preparing returns, and the Department of Justice has filed complaints against dozens of others. During fiscal year 2005, more than 110 tax return preparers were convicted of tax crimes.

8. Credit Counseling Agencies. Taxpayers should be careful with credit counseling organizations that claim they can fix credit ratings, push debt payment plans or impose high set-up fees or monthly service charges that may add to existing debt. The IRS Tax Exempt and Government Entities Division is in the process of revoking the tax-exempt status of numerous credit counseling organizations that operated under the guise of educating financially distressed consumers with debt problems while charging debtors large fees and providing little or no counseling.

9. Abuse of Charitable Organizations and Deductions. The IRS has observed increased use of tax-exempt organizations to improperly shield income or assets from taxation. This can occur, for example, when a taxpayer moves assets or income to a tax-exempt supporting organization or donor-advised fund but maintains control over the assets or income, thereby obtaining a tax deduction without transferring a commensurate benefit to charity. A “contribution” of a historic facade easement to a tax-exempt conservation organization is another example. In many cases, local historic preservation laws already prohibit alteration of the home’s facade, making the contributed easement superfluous. Even if the facade could be altered, the deduction claimed for the easement contribution may far exceed the easement’s impact on the value of the property.

10. Offshore Transactions. Despite a crackdown by the IRS and state tax agencies, individuals continue to try to avoid U.S. taxes by illegally hiding income in offshore bank and brokerage accounts or using offshore credit cards, wire transfers, foreign trusts, employee leasing schemes, private annuities or life insurance to do so. The IRS and the tax agencies of U.S. states and possessions continue to aggressively pursue taxpayers and promoters involved in such abusive transactions. During fiscal 2005, 68 individuals were convicted on charges of promotion and use of abusive tax schemes designed to evade taxes.

11. Employment Tax Evasion. The IRS has seen a number of illegal schemes that instruct employers not to withhold federal income tax or other employment taxes from wages paid to their employees. Such advice is based on an incorrect interpretation of Section 861 and other parts of the tax law and has been refuted in court. Lately, the IRS has seen an increase in activity in the area of “double-dip” parking and medical reimbursement issues. In recent years, the courts have issued injunctions against more than a dozen persons ordering them to stop promoting the scheme. During fiscal 2005, more than 50 individuals were sentenced to an average of 30 months in prison for employment tax evasion. Employer participants can also be held responsible for back payments of employment taxes, plus penalties and interest. It is worth noting that employees who have nothing withheld from their wages are still responsible for payment of their personal taxes.

12. “No Gain” Deduction. Filers attempt to eliminate their entire adjusted gross income (AGI) by deducting it on Schedule A. The filer lists his or her AGI under the Schedule A section labeled “Other Miscellaneous Deductions” and attaches a statement to the return that refers to court documents and includes the words “No Gain Realized.”

Two items fell off the list this year:
Two noteworthy scams have dropped off the “Dirty Dozen” this year: “claim of right” and “corporation sole.” IRS personnel have noticed less activity in these scams over the past year following court cases against a number of
promoters.

Dirty Dozen press release, here.

If you are a victim of one of these scams, you can report it, here.

Notably, they mention that reporting a scam might qualify you for a reward, but reporting one of these scams might (also) prevent someone else from becoming victimized.

There is also a lot of other free information and tools to do your taxes on the main IRS website, here.

Sunday, February 11, 2007

Information Week exposes the Internet Underworld

With the TJX data breach fresh in the news, Larry Greenemeier and J. Nicholas Hoover (Information Week) have written one of the most informative articles to date on the hacker underworld.

They are warning us that:

Hacking isn't a kid's game anymore. It's big business. Online black markets are flush with stolen credit card data, driver's license numbers, and malware, the programs that let hackers exploit the security weaknesses of commercial software. Cybercriminals have become an organized bunch; they use peer-to-peer payment systems just like they're buying and selling on eBay, and they're not afraid to work together.

The article covers the mysterious carder forums - where other people's financial information is bought and sold and how the information is paid for (wire transfer, PayPal, e-gold). It also shows how they avoid detection by anti-money laundering laws by what is know as "layering" (splitting up large sums into smaller ones).

There is also interesting information about the shady world where malware (crimeware) is being produced to steal the data.

Information Week article, here.

In case you were interested, here is how much (roughly) this information is being sold for:

The Black Market

$980-$4,900
Trojan program to steal online account information

$490
Credit card number with PIN

$78-$294
Billing data, including account number, address, Social Security number, home address, and birth date

$147
Driver's license

$147
Birth certificate

$98
Social Security card

$6-$24
Credit card number with security code and expiration date

$6PayPal
account logon and password

Data: Trend Micro

The conclusion of the article isn't new, which is that the business world needs to protect it's data better and law enforcement faces obstacles in going after borderless crimes. Until laws are enacted, which allow the problem to be solved, it will likely flourish and grow.

Thursday, January 04, 2007

Should cats be issued credit cards?

In order to protect her privacy, my daughter used to use the dog's name to register on websites fond of data mining personal information (smart kid). Shortly thereafter, our dog (Oliver) started receiving a lot of junk mail. Included were pre-approved offers for credit-cards.

All of this correspondence went directly into a shredder and we had a good laugh about it. I had to "coach" my daughter not to use our "actual address" and the problem stopped.

Now Reuters is reporting that a woman in Australia used her cat's name to apply for a secondary credit-card, and was able to get a new account for the feline. The stated reason she did this was to prove that it's too easy to commit credit-card fraud.

Reuters quoted the woman (Katherine) as saying:
You don't need to hack into the internet when you can just steal someone's credit card number and create a card for yourself."

In fact, had Messiah been a fraudster - and not a feline - Katherine wouldn't even have known the card existed.

I wasn't notified that a second card had been issued. Messiah could have put a different address and the card would have been sent there and I wouldn't have known. If it's that easy for a cat to get credit, imagine what a dog could get.
Reuters story (courtesy of IBN), here.

There was another story, I blogged about, where journalists tested how much security there is when a credit card is issued:

Ever Wonder How Well the Credit Card Companies Protect Your Personal Information?

But my favorite story about credit being issued "too easily" (along with pictures) comes from Rob at Cockeyed.com, which can be seen - here.

Credit card fraud is a serious problem, which causes a lot of "pain and suffering" to anyone unfortunate enough to be impersonated.

Wednesday, January 03, 2007

Medical Identity Theft Could Kill

Recently, I've seen a lot written about Medical Identity Theft. There seems to be a lot of people getting bills for medical procedures they never received and subsequently going through a lot of "pain and suffering" to clear their good names.

And (it seems) organized criminal are getting involved in the activity, probably because it's a "profitable" enterprise with little danger of getting caught.

BusinessWeek online did an interesting article about this, where they said:
Yet the thief isn't always an individual desperately needing medical care. In some instances, the perpetrator can be a doctor hoping to pad his or her income by filing fraudulent claims. Even worse, law enforcement authorities say that more and more frauds are being perpetrated by organized crime rings who steal dozens, and sometimes thousands, of medical records, as well as the billing codes for doctors. The rings then set up fake medical clinics—offering free health screenings as a ruse to draw in patients—that submit bogus bills to insurers, collect payments for a few months, and then disappear before the insurers realize they've been had. (Dixon notes that health records now fetch $50 to $60 each on the black market, vs. a mere 7 cents for stolen résumés.)

BusinessWeek online article, here.

The BusinessWeek article quotes Pam Dixon, executive director of the World Privacy Forum, and rightfully so. The World Privacy Forum (to the best of my knowledge) was the first to call out this growing problem and has done quite a bit of work to determine the extent of it.

They have an entire page devoted to it on their site, here. I highly recommend it for anyone, who is, or might become a victim of this growing trend.

Based on their research, they have presented some key recommendations:

  • Individuals’ rights to correct errors in their medical histories and files need to be expanded to allow them to remove false information from their files.
  • Victims of medical identity theft should have the right to receive one free copy of their medical file.
  • Individuals should have expanded rights to obtain an accounting of disclosures of health information.
  • Notification of medical data breaches to consumers has the potential to save lives, protect health, and prevent losses.
  • All working prototypes for the National Health Information Network need comprehensive risk assessments focused on preventing medical identity theft while protecting patient privacy.

The World Privacy Forum has also presented their finding to several government agencies, including the FTC.

This problem goes beyond the financial implications of identity fraud because it could cause great harm to victims, who have had erroneous medical information put in their medical histories. People could be improperly diagnosed, which might (in an extreme case) lead to their demise.

I did a previous post:

Tell it to the Identity Theft Task Force

Since the Federal Identity Theft Task Force is soliciting information from the public - this would be an appropriate place for someone to voice their thoughts (recommendations) about medical identity theft.

Friday, December 29, 2006

Government uses "phishing" techniques to test information security

Internet abuse in the workplace has been a concern for a long time.

Now the federal government is going to phish their own employees to determine if they will "click" on malicious links.

Wade-Hahn Chan of FCW.com reports:

Phishing is a technique of tricking or coercing users into giving up personal information, revealing log-in names and passwords or visiting malware or virus-infected Web sites. The government-sanctioned attacks will be designed to test how well federal workers adhere to organization's e-mail security policies.


FCW.com article, here.

Most stories about phishing concentrate on attacks for personal information, which is later used in financial crimes. While this type of phishing is bad enough, spear phishing targets an organization's information.

With the amount of data breaches - both in the private and public sector - the concerns that employees might be compromising large amounts of information is very real. If anyone wants to see a long list of these breaches (courtesy of the Privacy Rights Clearinghouse) compiled in the past couple of years, you can do so, by clicking here.

No matter how much security you use to protect a system, most of it proves worthless, if a person with access compromises it.

And although most stories about phishing emphasize the impact this has on identity theft and financial crimes, espionage is a valid concern, also.

This might be a very effective tool to raise "employee awareness" on "information security."

Wednesday, December 27, 2006

Tell it to the Identity Theft Task Force

Fighting Back Against Identity Theft - Federal Trade Commission

On May 10, 2006, the Federal Identity Theft Task Force was formed and has been working on what some believe is a national crisis. And it very well could be, identities are a very personal matter and should be considered, "sacred."

Now they soliciting advice from the public on how they can improve upon the recommendations they've already come up with.

I got this from the press release on the Federal Trade Commission's website:

The Federal Identity Theft Task Force, chaired by Attorney General Alberto R. Gonzales and co-chaired by Federal Trade Commission Chairman Deborah Platt Majoras, is seeking public comment on ways to improve the effectiveness and efficiency of federal government efforts to reduce identity theft. The public comments on these issues will supplement the research and analysis being conducted, provide further information about the proposals being considered, and identify areas where additional recommendations may be warranted.

You can visit the Federal Identity Theft Task Force's site, here.

For all of us who have been "ranting" about this problem, here is our chance to voice our opinions and make a "difference" in what has become a significant problem.

The site has a lot of resources for victims and those who might become one.

They also have two "interesting" ten-minute videos about identity theft:

English, here.

Espanol, here.

Saturday, December 23, 2006

It's illegal to ask someone to send in "fees" for a loan!

Fake websites offering loans, or credit cards at "too good to be true" terms are taking advantage of the post-Christmas blues. If an unwary person responds to them, they will ask for "up-front" fees before issuing the loan, or credit card.

Bottom line is that it is ILLEGAL to ask for up-front fees in order to secure a credit-card, or a loan. If someone asks you to do this, it's a scam!

The person sending these fees never receives the loan, or credit card and becomes an advance fee loan fraud victim.

Annys Shin of the Washington Post writes:
The scam has been around for decades. Many consumers are not aware that it is illegal to charge lending fees in advance. People with poor or no credit are enticed by ads, direct mail solicitations or telemarketing calls promising fast money at favorable terms.

The Internet has made it easier for scam artists to find victims. Consumers are drawn in by legitimate-looking Web sites, complete with privacy policies, customer service numbers and online loan applications. Soon after filling out applications, the victims typically receive phone calls saying their loans were approved, but because of their credit ratings, they must first wire deposits or collateral.

Washington Post article, here.

Fake websites are nothing new - they are used in a lot of Internet criminal activities. The Artists Against 419 go after some of these websites, which may be viewed, here.

I just did a post the other day citing a FTC action against a payment processor, who was aiding some of these advance fee criminals, here.

And if you spot one of these scams, or have been a victim of one - I highly recommend you report it to the FTC, here.

2006 was the Year of Internet Crime - 2007 is predicted to be even worse

Have you noticed spam getting past your e-mail filters lately? You're not alone, experts are saying 2006 was the worst year ever in Internet crime - and it appears - security fixes are being defeated.

Brian Krebbs (Washington Post) is warning:

Few Internet security watchers believe 2007 will be any brighter for the millions of fraud-weary consumers already struggling to stay abreast of new computer security threats and avoiding clever scams when banking, shopping or just surfing online.

Washington Post story, here.

Brian cites that in October 90 percent of all e-mail received was spam. And most spam is a come-on for one fraud scheme, or another.

Since "security fixes" are being defeated pretty quickly by organized criminals - who allegedly hire their own computer security experts - the only viable recourse is to go after the source(s) with the intent to put the people behind it out of business.

Resources allocated to fund the investigation of financial crimes are (normally) not funded very well and the people investigating them are "overwhelmed." Maybe we should take some of the money being spent on developing "fixes" and use it to solve the real problem, which is a social one. Prevention seems to only work temporarily.

Security fixes are needed, but if we don't aggressively go after the sources, the criminals develop countermeasures and we have to start all over again.

After all - it seems that organized criminals and some say, terrorists are flocking to this activity because it's financially lucrative and a lot less dangerous than other criminal activities. Until we make it more dangerous for them, the problem is likely to keep growing.

John Bambenek (Assistant Politics Editor for Blogcritics and academic professional for University of Illinois) recently wrote a compelling essay about this subject, here.

Here is a previous post, I wrote about why we are approaching this problem the wrong way:

Are We Addressing Cyber Crime from the Wrong End

Friday, September 15, 2006

Counterfeit American Express Gift Cheques

Counterfeit American Express Gift Cheques might be the latest form of fraudulent financial instrument circulating via the Internet. The items seen thus far are for $500.00 - note the largest denomination issued legitimately is $100.00.

If you receive one of these items - it is recommended you verify it before negotiating it. For the information to do so - link here.

Counterfeit financial instruments being used in Internet scams are nothing new. Here are some previous posts, I've done on this sort of activity:

Counterfeit Cashier's Checks Fuel Internet Crime

Counterfeit Postal Money Orders Showing Up in IScams Again

Postal Money Order Romance Scam

Counterfeit Travelers Express (MoneyGram) Money Orders Showing Up ...

In most Internet scams involving counterfeited financial instruments - a person is duped into negotiating the item and wiring the money back to the sender (scammer). If someone asks you to cash an item and wire them money - take a deep breath - and just say "no thanks."

Sunday, May 14, 2006

Chip and PIN, Another Chapter in the Attack on Debit Cards

The Daily Mail is reporting that Lloyds is admitting that there is a flaw in chip and PIN technology. The flaw is that the cards can still be remotely encoded and used in ATM's that accept older versions of debit cards.

The article states that the reason criminals are using the cards in other countries is because it takes longer for transactions to post and therefore escapes the "fraud detection" systems already in place.

Also contained in the article are a lot of reader comments, which are very enlightening.

The bottom line is that chip and PIN works, but only in machines that are set up to deal with the technology. This means that until we can create a "global" effort to curtail debit card fraud, newer technologies are going to have a limited effect.

Link to the article by the Daily Mail, here.

As a "Yank," I'm impressed with the fact that Lloyds is being up front with the problem. It's also refreshing to see the mainstream media working with the banks to get the word out.

Financial institutions in the United States haven't been as forthcoming with information. Even to this day, they still aren't admitting to the root causes of recent debit card breaches over here.

They might claim "zero liability" and offer free "identity theft monitoring," but they are in the business of making money. The cost of all of this is ultimately passed on to the customer.

Even though, there were many in the press and from blogs like Boing Boing that were getting the word out, the sources seemed to have either been victims, or confidential. I keep hoping to discover that the reason for this was an "investigation" that put a lot of the culprits -- where they belong -- or behind bars.

The bottom line is that the criminals seem to be very aware of the flaws that allow this to happen. Being up front about the flaws they are exploiting only serves to protect the public, who through their awareness, might spot the activity and report it.

Awareness might also help people from becoming victims, which is the best argument out there for laws forcing this activity to be "disclosed" to the public.

Saturday, April 22, 2006

Ever wonder how well you are protected from credit card fraud?

I was reading Cary Cartter's (I'm Thinking of the "O" Word...) and came upon a link he had on his blog on why we should all buy "shredders."

By the way "O" stands for obvious.

After clicking on the link, I found to my amusement a pictorial of Rob from Cockeyed.com ripping up one of those credit card offers in the mail we all receive, tearing it up, taping it back together and then sending it in to Chase.

AND Rob didn't stop here, he changed the address on the application and used his cell phone as his contact number. Note that these are both WARNING signals of fraud.

After researching the Chase site, Rob figured he had wasted his time. They clearly mention tearing up the application as a preventative measure.


Going even further, he researched the Federal Trade Commission's site, which also recommended tearing up the documents.

BUT he didn't waste his time, after a short wait his Dad called to let him know he had mail from Chase. Inside it was a shiny new credit card, which of course, he activated with his cell phone.

Link with lot's of pictures, here. One of the pictures shows a close up of the credit card indicating this is no hoax.

Although hilarious, this little experiment shows that despite the press from financial service companies about their top notch security procedures, fraud is too EASY to commit. It seems that they are more interested in marketing their products than protecting your personal information.

They expect fraud and figure it into their profitability margin, or add into the cost of using their service. That way they can sell even more services and you end up paying for it.

Of course, they are now "marketing" identity theft products and will try to sell that to you, also.

Here is an interesting commentary from the Motley Fool on why most identity theft products are another form of "dialing for your dollars" and why many of them offer little value.

Thursday, April 20, 2006

Package Deals to Commit eBay Fraud

Gone are the days where committing fraud took knowledge, or technical expertise. Personal, financial and "how to scam" kits are all easily purchased in IRC (Internet Relay Chat) chatrooms.

AuctionBytes (Ina Steiner) is reporting:

"According to an "eBay scam kit" obtained by AuctionBytes, women are easy marks on eBay. The kit, marketed as "eBay: Women Dough v1.8," contained everything a scammer needs to set up auctions on eBay to sell items they don't own and don't intend to fulfill to "customers."

"The eBay Women Dough scam kit contained three prepackaged high-end auctions targeting U.S. female buyers. The kit included descriptions and photos to include in the eBay auctions with detailed advice on how to list, handle customer service and accept payments."

These kits even contain detailed instructions on how to bypass eBay controls and dupe the potential victim into using unprotected wire transfer services, such as Western Union and MoneyGram.

Full story, here.

Please note that AuctionByte's article also quoted a Washington Post Article on IRC chatrooms written by Brian Krebbs. This article covers the full spectrum of information that is bought and sold in these chatrooms and paints a pretty realistic picture of the activity.

Here is something, I thought was interesting from the article:

"Marcus Sachs, a former cyber-security adviser to the White House who now directs the Bethesda, Md.-based SANS Internet Storm Center, said that if the information posted by the IRC channel operators is legitimate, then they are likely working with people on the inside at the major credit card issuers. But Sachs said he suspects that by "verifying" credit card information posted by other chat room members, those running the IRC channels are more interested in scamming the phishers."

Full story, here.

I guess we now know where all the stolen information from the record amount of data breaches is going. It's being sold on the Internet.

Here is a previous post, I wrote on that subject (data breaches):

Information Breaches, the Human Factor

Tuesday, April 18, 2006

Profiting at the Expense of the Poor, Electronically

Recently, I was in San Francisco and made a small purchase for about $5.00. While waiting in line, I watched the customer before me use one of the new EBT cards. EBT (Electronic Benefit Transfer) cards have replaced checks and food stamps for that segment of the population receiving government assistance.

The clerk behind the counter asked me whether I wanted to use credit, or debit and I said credit (I hate those pesky ATM fees). Much to my surprise, he put it through as a debit and handed me the PIN pad. I noticed that the amount (taking into consideration sales tax) had increased by $2.00.

When I confronted him, he claimed his command of English wasn't very good. Of course, I demanded a refund (out of principle) and left the store. Interestingly enough, he refunded my money in cash and declined to give me a receipt (which didn't exist).

The reason there was no receipt is that he used a calculator to figure the amount of the purchase. Please note, there was a cash register right in front of him. The only receipt available was from his handy debit card processor, which only accounts for the total dollar amount taken and doesn't break down the transaction.

Pretty handy and makes me suspect he was also skimming sales tax proceeds, which pay for needed government services.

The gentleman with the EBT card was standing near my car so I asked him about the fees. He told me that he gets charged wherever he goes. I mentioned that larger retailers don't charge to use the cards and he informed me that they were too far away and he didn't have a way to get there.

I started to think about it and what amazed me is that someone had just tried to charge me a 40 percent surcharge for using my debit card. Then I reflected on the plight of that poor individual using his EBT card. What was a minor inconvenience to me (I got in my car and drove to a reputable retailer) is something that he is forced to deal on a daily basis.

EBT cards were heralded as a means to reduce fraud and ensure that our tax dollars reached the poor. If they are being charged outrageous fees every time they use the card, it seems to me that this new system isn't helping the poor. Besides paying higher prices at inner city markets, they are getting dinged for a fee every time they use their card.

Alameda County (near San Francisco) has an interesting web page on how people on assistance can avoid surcharges. Please note that it is illegal to add a surcharge on the "food stamp" portion of the card.

A lot of this information is good stuff, but it is unlikely that poor people in inner cities are going to find the places that don't charge the extra fees easy to get to.

Small retailers aren't the only ones profiting from all of this. In fact, most states allow a legal surcharge to administer the cards. This means that certain financial institutions are profiting from processing the transactions. One example of this is Citibank, who contracts nationally to administer EBT. I wonder how profitable this is to their bottom line? At the .53 cents a transaction quoted on the Missouri Poverty at Issue site, it must make a lot of money for them.

Granted, most of this is based on a personal observation, but to me it doesn't seem fair. In fact, it reeks of "welfare reform" gone bad. I wonder how much of our tax money was spent thinking up this program and how many pockets it's lining?

The sad thing is that it probably takes money away from those, who need it the most.

Of course, this happened in California, where welfare reform has been criticized for other abuses. Here is a post, I wrote on that:

Back to Work Programs a Fraud Heaven for Scammers

Sunday, April 16, 2006

Postal Money Order Romance Scam


Altered Money Orders have been around for a long time. Before new technology made counterfeiting money orders pretty easy, it was a common method of committing fraud.

Criminals buy a large number of them for a small amount, normally $1.00. The $1.00 money orders are then altered, using chemicals, and a much higher dollar amount is put on them.

Because financial institutions are fairly aware of this activity AND the "getting caught" factor is a risk, they find creative ways to get a less knowledgeable person to take the risks and send them the rewards.

These "less knowledgeable" people frequently suffer the consequences, or take the RAP for them, also.

While altered money orders (not just the Postal variety) have been around for quite some time, convicts seem to have a new way of getting them cashed.

They place ads in the personal section seeking pen pals. Once they have gained the confidence of the person, they trick them into cashing the altered instruments and sending the money back to them.

The Postal Inspection Service warns:

Be aware of the telltale signs of this unusual scheme. If you begin to write letters to a prisoner who is attempting to cultivate you for his mail fraud scheme, he will slowly attempt to gain your trust and confidence. If you are a single woman, he may even send you love letters and handsome photos, and promise to marry you upon his release. Male prisoners posing as women try to lure men into the scheme as well.

While confessing their love for you, he will also admit that he is serving a prison term for a tax violation or other non-violent offense. But he will say his prison term is almost up, and he's looking forward to starting a new life together with you when he is freed.

Eventually, he will ask you to cash one or more postal or other money orders for him, claiming that he needs the money to pay attorney fees or court fines. Where does he get each high-value money order (often as much as $700)? He will obtain them from an accomplice outside the prison who buys them in small denominations (often only $1) and then smuggles them inside the prison, where inmates alter them to reflect higher values.

When you assist your pen pal by cashing any such money order--and sometimes there are many of them totaling thousands of dollars--you are told to send the money to a "friend" of the prisoner, whom you're told is helping with his legal defense. Of course, this friend is the outside accomplice. You will be told first to deposit the money orders in your personal bank account for temporary "safe-keeping" and then to pay out the funds to the outside accomplice.

Shortly after sending the money, you will receive a cruel "Dear Jane or John" letter asking you to understand that your pen pal only did what he or she "had to do" to survive, and now that he's out, the relationship is over. But he's not out. He's still in prison. And what's even worse, he now has your money, because the bank will charge your account for the phony money orders you deposited. Since the U.S. Postal Service routinely compares all of its cashed postal money orders with the original money order receipts, all altered postal money orders will ultimately be discovered.

Under current law, the person who cashes, or deposits and then withdraws, an altered money order is responsible for its total value--in this case, the altered value. Therefore, shortly after you pay out the temporarily held funds from your bank account, your bank will notify you that you must pay the difference between the issued amount and the raised amount. For example, if you cash a $1 money order that has been altered to $700, you will end up being charged $699 of your own money.

Link to bulletin, here.

Although convicted criminals committing crime from behind bars makes a good news story, they might not be the only group involved in this type of activity.

Nigerian fraudsters are also known to be involved in Romance scams. Of course, there are other places the scam originates besides Nigeria, also.

Altered Money Orders don't only come from the prison system, either.

The U.S. Department of Justice reported:
At trial, the national money order fraud coordinator for the U.S. Postal Service testified that document fraud rings operating in West Africa, are known to be involved in altering U.S. Postal Money Orders and shipping them back into the U.S. to be cashed.
Link, here.

Counterfeit money orders might be more common in a lot of Internet scams, but altered money orders are still being produced and successfully used.

If you happen to receive any of these altered money orders, they can be reported to the Postal Inspectors, here.