Showing posts with label identity theft protection services. Show all posts
Showing posts with label identity theft protection services. Show all posts

Saturday, August 02, 2008

Countrywide Insider Steal's 2 Million People's Information

On Friday, the FBI arrested a former Countrywide employee and his accomplice for stealing and selling personal information (including social security numbers) obtained from people applying for mortgages. According to news sources, the number of people compromised was about 2 million.

The Countrywide inside man was identified as Rene L. Rebollo Jr., who worked at Countrywide's sub prime lending division, Full Spectrum Lending. Also arrested was Wahid Siddiqi, who was the alleged information reseller in the caper. Both arrests took place in Southern California.

The criminal complaint alleges that Rebollo downloaded 20,000 names a week for about two years. The batches of 20,000 were sold for about $500 to Siddiqi. This amounts to about 25 cents a person compromised.

According to a spokeswoman at Countrywide, the investigation shows that 19,000 peoples information has been actually used.

Beth Givens, of the Privacy Rights Clearing House was quoted in a story about this in the LA Times and aptly pointed out Rebollo sold the information at well below known black market prices. Although the prices for stolen information -- which is sometimes sold in underground Internet forums has dropped in recent years -- a name that has a matching social security number is worth well more than 25 cents a pop.

The official spin is that this information was used for leads to sell real estate, but my speculation is that how would anyone know for sure? According to the news reports, the information was being sold to companies. The FBI posing as a company was able to buy records for Siddiqi.

If it was sold to companies, who knows who they might have sold it to, or if they have any dishonest employees selling it, elsewhere?

This made me wonder if any of the companies buying the information will be publicly disclosed? In a similar case at Certegy -- where another dishonest employee was caught and convicted for selling stolen information to "companies" -- the companies involved were never made public or charged with any crime (to my knowledge). Court records indicated a co-conspirator in this case, but again (to my knowledge) no one has ever revealed exactly who this mysterious co-conspirator was?

Givens also pointed out that names, which include a social security number and perhaps financial data, can be used to commit what is known as new account fraud. New account fraud is where an identity thief poses as their victim and opens new lines of credit. Once this is done the first time, the thief (sometimes thieves) continue to open lines of credit until the victim's credit report makes them look like a deadbeat.

My guess is that the affected people will be offered some sort of credit monitoring/identity theft protection. While this prevents some forms of identity theft, it doesn't necessarily protect from all the ways a stolen identity can be used. Some examples of when it might not show up on a credit report are cases of medical benefit fraud, employment fraud, government benefit fraud, some forms of check fraud and last, but not least, when it is used to commit crimes of other than a financial nature.

Recently, the Privacy Rights Clearinghouse, issued a well written fact sheet pointing out that existing credit monitoring/identity theft protection services do not protect a person from all forms of identity theft. I highly recommend that anyone -- who thinks their identity has been compromised -- read this fact sheet before buying or relying on the free protection offered in the aftermath of a known data compromise.

If and when -- employers are required to react to workers using social security numbers that do not match -- the millions of illegal immigrants already over here are going to have to use real social security numbers and a matching name to remain employed, or obtain employment. While the federal law on this has been tied up in federal court, some States have already enacted similar legislation. This type of identity theft normally doesn't appear on a credit report and is often discovered when a person files their tax return, or gets their social security earning statement and notices employment listed they never had.

A statistic that might support this is the IRS revealing that identity theft used to file tax returns has grown 644 percent in recent years. The two main reasons cited for this were people using them to obtain employment or to file a fraudulent tax return to obtain a phony refund, normally using what is known as the earned income credit.

Stories of large scale data breaches seem to surface, frequently. Despite this, there are a lot more that no one ever finds out about. Recent evidence revealed by Finjan, a computer security outfit, supports the contention that we really don't know how much stolen information there is out there, or how it is being used. Finjan has been discovering what they term as crime servers on the Internet, which contain all kinds of stolen information. This information included compromised patient data, bank customer data and even sensitive e-mail communications. At least some of this information wasn't even password protected on the crime server.

This particular data breach at Countrywide will probably fade into the mist fairly quickly. It does show that any and all security measures can and will be defeated when a person who has access is the point of compromise. The sad fact is that despite a lot of efforts -- until the issues that fuel (enable) this problem are addressed -- we will continue to see personal and financial information stolen.

We have made personal and financial information worth a lot of money and there are a lot of people buying and selling it. Some of them even have legitimate or semi-legitimate status. The more this occurs means the information is going to be electronically transmitted (sold) and then stored in a lot of different places. As long as this keeps happening, it's probably impossible to protect all of it.

Sunday, June 22, 2008

Identity Theft Service wins Network Products Guide 2008 Product Innovation Award

Tom Fragala announced on his blog that "Truston received a 2008 Product Innovation Award from Network Products Guide for our myTruston Software-as-a-Service (SaaS) platform."

Tom is a well known blogger on the subject of identity theft, was really a victim himself and has spent a lot of time advocating for victims.

He quoted Networks Product Guide as saying:

“Truston's innovative SaaS platform offers an organized approach to getting a stolen identity back and keeping it safe.

myTruston is the only ID theft product that does not require sensitive data, is the only SaaS product in the space, supports virtually all fraud types, has unlimited content extensibility, is built on a patent-pending task management engine and allows for seamless integration with partner's web sites.”

Truston is a platform that allows the individual to protect themselves and recover from identity theft without handing over their personal and financial information. Many of their competitors maintain this information in databases, which seem to be compromised, frequently.
Some of them also require you sign a power of attorney to use their service.

In fact, there is so much compromised information out there, no one is really sure how much there is. Finjan, a noted computer security company, has recently been finding crime servers containing a lot of stolen information that no one knew had been compromised before. Ironically, the owners of these crime servers didn't even bother to password protect them in certain instances.

Despite this, we read about known data breaches all the time.

This isn't the first award Truston has received from the Technology industry and I suspect it won't be the last.

The neat thing is that if you are reading this post, Tom is still offering a free 45 day trial. Of course, the protection part always has been free.

If you would like to try the services for free, click here.

Recently MyTruston created a partnership with Identity Force and their platform is now being used by government agencies. These include the Department of Veterans Affairs, FEMA, US Coast Guard, Transportation Safety Administration, and Department of Energy.

While identity theft is a growing problem and no one can protect themselves 100 percent, MyTruston offers a platform to do so that is at least as good (if not better) than anything else in the industry. If you see advertising for an identity service that is 100 percent bulletproof, I recommend exercising the sage principle of caveat emptor (buyer beware) before shelling out your hard-earned money.

The reason I say better is that it was built on principles that protect privacy and by an individual that wanted people to "trust" his product.

If you would like to learn more about MyTruston, their site has a FAQ page that answers a lot of questions.

Press release on this latest award, here.

Sunday, May 25, 2008

Lifelock's identity theft protection saga racks up 339 articles in Google!

Todd Davis, Lifelock's flamboyant CEO, who flashes his social security in public to sell identity theft protection made Yahoo's top five stories of the week. When I checked Google News, there were no less than 339 articles covering the woes of Lifelock and it's CEO.

Lifelock has been mired in controversy since it was revealed in the New Phoenix Times that one of his co-founders (Robert Maynard) wasn't being truthful about being an identity theft victim and was suspected of being a identity thief, himself.

I covered this part of the Lifelock saga in a post called, "Is LifeLock an identity theft protection service people can trust?"

Maynard stepped down from his position as co-founder, but continued to maintain a 10 percent interest in the company.

A short while thereafter, it was revealed that Todd Davis was himself a victim of identity theft. Instead of letting the authorities do their job, Davis took it upon himself to send out a PI (and film crew) to get a pre-written confession from the scoundrel. The end result was that the authorities dropped the case.

Meanwhile, Lifelock seemed to flourish and obtained a lot of investment capital to drive their aggressive marketing campaign. Everyone from Radio icons to bloggers have been paid to endorse their services.

The bad publicity even led to speculation that an organized hit job was being undertaken against Lifelock.

So far as the organized hit job theory, it does have some merit. The reason for this is that Lifelock's service isn't much different than what a lot of other companies are offering. Additionally, the repetitive fraud alerts make it more expensive to issue credit, and there is a cost incurred by the credit bureaus for providing them.

Then there is the competitive edge, identity theft protection services are being hawked by a lot of different companies. They range from unknown start-ups to financial institutions and the credit bureaus, themselves. In not very good economic times, the industry is showing double-digit growth.

The Motley Fool gave a good explanation of the reason for this in their article (one of the recent 339 or so) about Lifelock:

There's clearly profit to be had in the privacy protection market -- much-needed profit for credit reporting-related services. The 2003 passage of the Fair and Accurate Credit Transactions Act (FACT Act) handicapped one of their revenue streams by mandating free credit reports for all. (Get yours at annualcreditreport.com.)

To help make up for the financial shortfall, the credit reporting companies created a new revenue stream: credit watch products. Seeing profit in consumer fear, other companies soon created their own credit watch muscle for hire.

Please note, the article in the Motley Fool gives some pretty sound advice about how to protect yourself for free from identity theft, also.

Then came the legal actions, first Experian filed a law suit and then came a series of class actions alleging the Lifelock is guilty of misleading advertising, doesn't warn it's customers that it only provides limited protection and doesn't warn them that repetitive fraud alerts might damage their credit rating.

I suspect the current flurry of stories were partially the result of information released from the law offices in the class action suits that Todd Davis has been the victim of identity theft numerous times.

It's now been revealed that Davis' identity has been compromised 87 times in the past two years. 20 of these attempts involved drivers licenses. Davis has responded by stating that this proves Lifelock protects it's consumers from identity theft since the only known successful attempt was with the PayDay loan in Texas.

While this might be partially true, there is a flaw in this thinking. The flaw is that partial information isn't always picked up by credit bureaus and credit bureaus don't detect all forms of identity theft.

A new buzz word in identity theft circles is "synthetic identity theft." Here is a description of it from a previous post:

This is where different parts of other people's identities are used to forge a synthetic one. Quite often, because a lot of the information doesn't match, the credit bureaus don't pick it up. Most frequently, this is discovered at tax time, when someone gets a bill for taxes that an identity thief never paid to the government.

So far as identity theft that isn't picked up on a credit bureau, here is what I wrote about that in the same post:

Another reason there is no way to guarantee protection is that not all identity theft shows up on credit bureaus. Some examples of this are in cases of medical benefit fraud, employment fraud, government benefit fraud, some forms of check fraud and last, but not least, when it is used to commit crimes of other than a financial nature.

Because of these reasons, I'm not certain if Mr. Davis can be sure that all 87 attempts were entirely unsuccessful?

Another marketing claim that many feel is misleading is Lifelock's $1 million dollar guarantee. If you read the fine print, they only guarantee they will hire people to look into it should you become a statistic while using their service. They also stipulate that they will choose who does this for you.

Trust me, it's highly unlikely anyone will collect much of anything if they become an identity theft statistic while paying for Lifelock. In most instances, after the work is done, the financial institutions end up responsible for the loss.

Of course, when this happens the cost is passed on to all of us. No business would be able to remain solvent, otherwise.

The sad truth is that there really is no guarantee that you will never become an identity theft victim and it's probably better to exercise common sense and perform your own due diligence.

Since I seem to be quoting myself a lot in this post, here is something I wrote about this:

Most of the experts (not selling services) agree most people can fix their identity for free, and in the long run, they might do a better job of it, themselves.

If someone were to do this, a good place would be the FTC's Identity Theft page. Other decent free resources are the Identity Theft Resource Center and the Privacy Rights Clearinghouse.

Last, but not least, the good folks at Attrition.org did a highly amusing parody of identity theft protection services after they got sick and tired of them using their free material:

Going forward, we would like to announce that we have a new partnership with Identity-Love-Sock, a trusted provider of identity theft prevention services. Not only can Identity-Love-Sock protect YOU from IDENTITY THEFT, it also provides several guarantees for your PROTECTION should YOU be affected by IDENTITY THEFT. With the services provided by Identity-Love-Sock , YOU will NEVER have to WORRY about your IDENTITY being STOLEN, MISUSED, or otherwise COMPROMISED. For more details on how YOU can be COVERED and PROTECTED, please visit Identity-Love-Sock . You'll be glad you did.

Along with covering various matters related to computer security and privacy, Attrition is recognized for maintaining a pretty telling database on where a lot of identity theft starts, or data breaches.