Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts

Wednesday, February 06, 2019

Huddle House Reports Point of Sale Hacked Since August 2017

If you had a meal at Huddle House and used a payment card -- you might want to give the issuing financial institution a call (or review your account online) and make sure your financial health wasn't compromised! Huddle House announced that the compromise occurred from the beginning of August 2017 until "present."

It always amazes me how long compromises go on without being detected. In this case, it was well in excess of a year!


Huddle House is a casual dining and fast food chain that operates in the southeastern United States. On 02/01/2019, they announced that their point of sale system had been hacked on the main page of their website. 


Huddle House reported that the following personal details were compromised:


"Based on the facts known to Huddle House at this time, the malware was designed to collect certain payment card information from the magnetic stripe, including cardholder name, credit/debit card number, expiration date, cardholder verification value, and service code."


The page also details all the resources available to protect yourself. 


Please note that some people opt for "paid services" to protect their financial resources, but you can also do it yourself for free. 


Free credit reports are available at AnnualCreditReport.Com and the Federal Trade Commission has great information on how to deal with any issue that arises from using your card at Huddle House.


In the United States, billions of dollars of payment card fraud are incurred by customers, banks, and merchants a year. The biggest losers are the merchants, but we can assume that we are all paying for it when these losses are passed down to the consumer via higher prices and fees.


Please note that there are varying estimates of the true cost of fraud. Based on years of personal experience, I have always found that large amounts of fraud loss are buried as "bad debt" because no one (normally a Collections Department or Fraud Department) spent the time to investigate the true cause of the loss. 


The sad thing is that when this happens, fraud losses tend to go up because no one is effectively mitigating the root cause of how the money is being stolen. 


Sunday, March 22, 2009

Symantec Indian Call Center Employee Selling Credit Card Details (Shocking)!

A story of an undercover investigation by the BBC shows how dishonest employees at call centers — who collect plastic payment card details on clients — might be making a little extra pocket change by selling them.

The focus of the BBC story is centered on an Indian call center employee for Symantec Security Corporation stealing payment card information. It is also centered on UK customers, which is understandable given it is the BBC, but the reality is that information is stolen then sold from countries all over the world.

Payment card details are handled by telephone at call centers in a lot of places and the calls come from all over, too. A lot of companies have different tiers (levels of personnel) handling calls, depending on the difficulty or nature of the call. At a lot of major companies, these tiers are located in different centers, which are in different countries. Any call might start in one country and, given the nature of the call, it could be transferred to another center located in another country. Given this, payment card information can be sent and then illicitly recorded over a fairly wide geographical area.

Besides that, dishonest employees are caught on a regular basis in a lot of different places. They don't all necessarily reside in India and call centers there are not the only place payment card information can be compromised. In fact, payment card information can be compromised anywhere (not just call centers) where they are used at a point of sale.

Information crooks are recruited and some think even planted anywhere financial information can be stolen. Even if they are not, payment card details are being bartered in forums on the Internet. It probably wouldn't be very hard to find a place to sell credit/debit card information when all it takes to do it is a click of a mouse.

The BBC story, which aired on video, chronicles an investigative effort by their reporters on the streets of Delhi. In the segment, it shows reporters making contact with the underground broker, who offers them payment card details from "all over the world" for $10-$12, each. It then shows a buy being made and money changing hands.

When the information was checked, it revealed that only one in seven card numbers were actually usable. They were able to trace some of the good numbers to a call center handling Symantec (Norton) products. The story stated that there has only been one successful prosecution in India for this type of crime and that it netted a non-custodial sentence. It also stated that the laws regarding the protection of data are not as stringent as they are in some places. The story mentions that Symantec's official comment was that it was an isolated incident and that the employee was removed.

Since one to seven card details turned out to be real, I guess we can assume the underground broker wasn't being completely honest. I've also seen reports of credit card details being sold for a lot less and you don't have to travel to India to find them.

In November, Symantec — the point of compromise in the story — issued a report on the underground economy, which focused on this very subject. "Credit cards are also typically sold in bulk, with lot sizes from as few as 50 credit cards to as many as 2,000. Common bulk amounts and rates observed by Symantec during this reporting period were 50 credit cards for $40 ($0.80 each), 200 credit cards for $150 ($0.75 each), and 2,000 credit cards for $200 ($0.10 each)," according to the report.

If this report is anywhere near accurate and the BBC was buying card details at $10-$12 each — if only one to seven was good in the Delhi exchange — the BBC was getting ripped off!

According to the 68-page report by Symantec, these details can be bought anywhere that has an Internet connection. Counterfeit instruments (ready to use) are often sent through the mail, too. The information is sold via IRC (Internet relay chat) channels in forums designed to market stolen financial information. Although credit/debit card details seem to dominate the scene, a lot of other information is sold that can be used to commit financial crimes and identity theft in these forums, too.

If you don't want to believe the Symantec report, the FBI took down one of these forums not very long ago. This forum known as Dark Market was responsible for about $70 million in fraud, worldwide. My best guess is that the information in the report is pretty accurate.

Although dishonest insiders are the cause of a portion of it, we should remember that hackers breaking into business systems, phishing, malicious software and even the trash can be sources of stolen information. The places targeted for information can be merchants, restaurants, goverment organizations, charity organizations, universities, medical facilities or anywhere payment card information is used at a point of sale.

Keeping up with all the points of compromise is difficult, but one place that attempts to is the DataLossDB site. Please note that the unknown data breaches are the most lucrative for the criminals behind this activity. Once a breach is discovered, measures are enacted to disable the stolen data.

It can be extremely difficult, if not impossible, to identify the point of compromise in most individual cases. The reason for this is there are too many different places where information might have been stolen from.

Maybe that's the problem, or we are storing and transmitting too much information all over the place? Since everyone is making money by transmitting information, I doubt this practice is going to stop anytime soon. So far as outsourcing, I doubt this is going to stop in the near term, either. Companies save a lot of payroll by outsourcing jobs. Payroll is a big expense for corporations and cutting payroll seems to be in vogue these days.

Nothing is going to change until laws are passed that force everyone making money from this information start doing the right things. This includes laws that prohibit people from being irresponsible (my opinion) to laws that punch the criminals stealing the information where it hurts.

Until then, the rest of us will have to batten down the hatches and weather the storm. I highly recommend making sure your information is protected as well as it can be (there are no guarantees) by protecting your own electronic transmissions. Monitoring financial activity — from your financial statements to information on your credit report and the Internet — is a good idea, too. Of course, while doing this, you need to ensure your electronic transmissions are protected by a reliable vendor and that you aren't paying for protection that you could get for free. Sadly enough, everyone claiming they can protect you isn't necessarily being completely honest, either.

Sunday, December 14, 2008

Keeping an ID Theft Victim's Information Private is Catching On



Tom Fragala, CEO of Truston Identity Theft Services, started his MyTruston identity theft and recovery product based on the principle that he didn't believe an identity theft victim should have to give up their information to a third-party to protect themselves. After all, most of this information gets stored in a database, which is one of main places (besides trash cans) identity thieves go to steal information.

Information stored on databases is legitimately bought and sold by information brokers all the time. Criminals sometimes pose as having a legitimate interest to access the information. Of course, there have also been cases of dishonest employees selling it without a so-called legitimate purpose. This makes it extremely difficult to determine exactly where any stolen information originally came from. At this point in time, so much information has been stolen, we routinely hear about it being sold in chat rooms right over the Internet.

It didn't make sense to Tom to put all this information in another place, where it could potentially be compromised again. Databases have created an ability to store more information than ever before and transfer it with a click of a mouse.

Having been an identity theft victim himself, Tom had some rather personal feelings on the subject. It should also be mentioned that Tom has spent thousands of hours being a personal advocate for victims of this crime.

Since launching the do-it-yourself tool — where you don't have to be an expert to protect yourself or recover from identity theft — it has received numerous awards and become a hot topic within the technology industry itself. Besides not having to be an ID theft expert — you don't have to expose any of your personal information to a third party and the protection aspect is and always has been free. There is a charge for using the recovery tool, which can be cancelled anytime. I'll tell you a secret about that last statement, further down.

I discovered the latest news that the Truston concept is catching on when reading Tom's blog, which is well worth a read if you are interested in identity theft or privacy issues. "Today we announced that our MyTruston product has been included in the portfolio of the Affinion Security Center, the largest provider of identity protection and privacy services. Affinion has nearly 35 years of industry experience and over 65 million members of their many products. Clients of their identity protection and privacy products include Wells Fargo, Bank of America and The Hartford Insurance. Truston's Software-as-a-Service technology is deeply integrated within the Affinion Security Center’s core solution platform, IdentitySecure," according to Tom himself.

Just the day before, Truston also announced a partnership with CreditFYI, which is a one-stop shop for the best credit card rates, best loan rates, as well as, to learn how to protect your good name and credit rating.

Besides Affinion Group and CreditFYI, Truston is a private label partner with Identity Force, which provides identity theft protection services to the U.S. Government. Truston has been given a Four-Star rating by PC Magazine and has received several awards. "Truston's awards include a 2008 Product Innovation Award, a Hot Company 2008 Award, being selected for 10 Companies to Watch in 2008 by the Pacific Coast Business Times, the 2008 Tomorrow's Technology Today award, and it was identified as a leader by Javelin Strategy & Research in their December 2007 identity theft market report," according to the press releases.

If you are interested in just how user-friendly the tool is, the Truston site has a tour you can take.

I've also had the pleasure of speaking with Tom on several occasions and beta tested the tool myself before it rolled out. I've covered this in several blog posts on Tom and the MyTruston identity theft tool.

Now for the secret I promised earlier in the post. I mentioned that using the tool always has been and always will be free, but there is a nominal charge for using he recovery services. The secret is that if you go directly to the Truston site - you can use everything free for 45 days. Last, but not least, this free trial doesn't require you give them a credit card (which will get charged if you forget to cancel) until after the trial expires.

Sunday, October 26, 2008

Microsoft is NOT the Biggest Hacker in China!

Chinese surfers are crying foul at Microsoft's launch of the "Windows Genuine Advantage Program," which turns a screen black when it detects pirated software. It is believed up to 200 million computer users in China have counterfeit software on their machines.

China is well-known for being involved in the knock-off trade, as well as, selling dangerous and defective products in the global economy. The news has had a lot of stories about them censoring the Internet, violating user privacy and being involved in hacking on an industrial scale.

Ironically, Dhong Zengwhi, a Bejing lawyer, accused Microsoft of being the "biggest hacker in China with its intrusion into users' computer systems without their agreement or any judicial authority," according to the China Daily. His argument is that this will cause serious functional damage to users' computers and according to China's criminal law, Microsoft could be accused of breaching and hacking into computer systems. Zengwhi has filed a complaint with the Chinese government about this.

Does this mean Microsoft won't be able to out-source work to China?

I wonder if Mr. Zengwhi's opinion was when it was revealed that the Chinese were data-mining the communications of Tom-Skype users? Tom-Skype is the Chinese version of the popular Skype software, which allows people to communicate worldwide using the Internet.

Privacy violations in China aren't limited to Tom-Skype communications, either. During the recent Olympic games, the government openly monitored Internet communications, using the excuse of security to justify what many believe was censorship.

The allegation that Microsoft is the biggest hacker in China is questionable. Governments from all over the world have accused the Chinese of hacking into their systems and it isn't considered safe to carry a laptop, or even a smart-phone when visiting China. Recently, there was speculation that Commerce Secretary Carlos Gutierrez had his laptop hacked during a visit to China.

In fact, if you follow the news, the theft of intellectual property is often traced to the Chinese. The FBI has caught numerous Chinese agents stealing a lot of private and government information in the recent past.

Pirated software is a huge problem in the global economy. It is estimated that one third of all software being sold is counterfeit. A large percentage of the software sold on auction and even e-commerce sites is counterfeit, also. It isn't unknown for a consumer to think they are getting legitimate software when they are not.

Besides costing jobs and revenue to legitimate firms -- knock-off software can damage a machine, or even lead to information theft when malicious software is added to the mix.

I'm sorry that that certain people in China are outraged by Microsoft's solution to the theft of their property, but let's face it, they are hardly the biggest hacker in China.

Sunday, October 05, 2008

TOM-Skype Communications - A Privacy Nightmare Come True

I've blogged frequently about the dangers of engaging in free trade with a not so free China. In the past couple of years -- we've seen an alarming amount of stories about dangerous and defective products, espionage, human rights violations, counterfeiting and privacy violations associated with the People's Republic.

The latest privacy violation was discovered by Nart Villeneuve from the University of Toronto's Citizen's Lab, who discovered that the Chinese were data-mining the communications of TOM-Skype users.

"Skype is software that allows users to make telephone calls over the Internet. Calls to other users of the service and to free-of-charge numbers are free, while calls to other landlines and mobile phones can be made for a fee. Additional features include instant messaging, file transfer and video conferencing," according to Wikipedia.

When Nart Villenueve forgot the password to his Chinese MySpace page and began looking at the Chinese version of Skype (TOM-Skype), he uncovered the massive privacy breach with TOM-Skype. His findings were that full chat messages (including those of Skype users communicating with TOM-Skype users) were being stored on servers in China. He also discovered that the data was being stored on insecure publicly-accessible webservers along with the encryption key needed to decrypt the information. The messages are tracked by keywords relating to what the Chinese would consider "sensitive political subjects." Analysis also revealed that information might be maintained by specific user names.

Also discovered was evidence of security problems at TOM Online, the Chinese company that owns TOM-Skype. Evidence was found that the servers have been compromised in the past and used to store pirated movies.It probably wouldn't be hard for a malicious attacker to access these stored communications, which include detailed user profiles.

Josh Silverman, the president of Skype, did a blog post discussing this subject. He was quick to point out that the only people being monitored were the parties using the TOM version of the software. Of course, this also includes anyone communicating with someone using the TOM version. He also claimed that Skype was unaware of this privacy breach until it was surfaced by the Citizen Lab.

Since September, Chinese Skype users have been directed to the TOM-Skype site to download the software. There has raised concerns that a trojan could be dropped on a user when downloading the Chinese version. A trojan is a form of malicious software, which can be used to steal all the information from a computer.

The full report from the Citizen Lab at the University of Toronto is an interesting read. While there is little doubt from this report that TOM-Skype is being used to track politically sensitive subjects, there are probably a lot of foreigners using TOM-Skype to communicate with loved ones while they work in China. This opens the door for personal information to be stolen and corporate espionage to take place.

Anyone using Skype to communicate with someone in China should be aware that they are being monitored and avoid revealing any personal or sensitive information.

Thursday, July 31, 2008

In China, Censorship is Called Security

Senator Sam Brownback (Kansas) is warning that China is planning to mount a massive espionage operation on guests staying at major hotels during the upcoming Olympic Games next month.

This shouldn't surprise anyone. Although they consistently deny it, China has a history of spying on both business and government visitors. They also consistently get accused by governments around the world of hacking into sensitive systems.

Recently, there was a lot of speculation that Commerce Secretary Carlos Gutierrez's laptop was hacked during a visit to China and the information was used to hack into government computers. Saavy business types have been quoted as saying that they do not carry laptops or smartphones with them while travelling in China. Of course -- if you needed some more substantial proof China is behind a lot of espionage -- you could read about all the people getting caught by the FBI stealing sensitive information for the People's Republic.

Senator Brownback made a statement on Tuesday that he was warned that the Chinese Public Security Bureau has made it mandatory for hotels chains to install spyware and special hardware by the end of July. Failure to install the required items (or disabling them afterwards) will lead to "punishment," according to a document in the Senator's possession.

Of course, all this is being done in the name of security, according to People's Republic officials. Oddly enough -- possibly to address privacy concerns -- they plan to employ pop up windows warning people the Internet is not private in China. I'm sure this is assuring to privacy advocates, worldwide (pun intended).

The Senator's staff handed out English language translations of two separate documents he said were received by hotels, outlining the government's instructions on how to implement Internet spying software and hardware by the end of July to members of the press on Tuesday.

In many people's opinion -- the intention of this security system is monitor people -- who might want to expose China's dismal human rights record during the games. In fact, Senator Brownback was initially warned about these so-called security measures by human rights advocates.

Further evidence of this is that on Tuesday access to sites like Amnesty International or any with a Tibet address were being blocked at the main Olympic press center in Bejing, according to the article in the Los Angeles Times on this story.

Senator Brownback announced during the conference that he and Senator Bunning of Kentucky were introducing a resolution calling on China to suspends it's plan to censor free speech and spy on people. It should be noted that years ago -- when bidding for the games -- China promised to not to do this.

While many speculate the intent of this so-called "security system" is to supress free speech (censor people), I'd highly recommend anyone with sensitive information be extremely careful if they are in China during the Olympic games. The real espionage and hacking will not be as apparent as this has been. A good place to learn about Chinese hacking and espionage is the Dark Visitor site, which should give anyone a good idea what information risks they might face during a visit to China.

Tuesday, July 01, 2008

Data Theft Grows 68 Percent in 2008

Linda Foley at the Identity Theft Resource Center made an ominous announcement that data breaches were at an all time high. According to research conducted by the group, the number of data breaches has grown 68 percent in 2008 versus the same time period in 2007.

The current study acknowledges that some breaches are under reported and multiple breaches are sometimes reported as a single event. The breach at BNY Mellon and SunGard data were cited as an example of a single event affecting multiple businesses.

The report shows an increase in data breaches at businesses, financial institutions and health/medical institutions. Interestingly enough, breaches that involved the government/military and educational institutions showed a decrease.

Breaches are becoming more technology based, also. Electronic data breaches accounted for 80.7 percent of the total versus 19.3 percent, which were considered paper breaches.

I suspect that the increased activity at businesses and financial institutions is because the goal is to steal financial instruments that already have a cash value associated with them. As the general public has become more aware of the issues surrounding identity theft, opening fraudulent accounts with other people's information is becoming more difficult. More people are reviewing their credit and placing alerts/freezes on their individual reports, either by doing it themselves or paying a service to do it for them. When accounts are stolen that already have disposable spending power or (cash) on them, identity theft protection is unlikely to stop them from being compromised.

Because of the increased awareness, more fraudsters take over accounts instead of trying to open new ones. Most of the current identity theft protection methods being used will not stop this from happening.

So far as the statistic that electronic theft is becoming more prevalent than paper theft, perhaps shredding documents is making stealing paper harder? Of course, it might also mean that the methods to steal information electronically have become more advanced, also. Crimeware kits of the DIY (do-it-yourself) variety have spread this ability to people, who lack the technical skills to do it by themselves. There is a lot of evidence that these kits aren't too hard to purchase over the Internet and that sometimes they even come with technical support.

ID Analytics partnered with the study and added statistical information showing that 39 percent of data exposures were caused by missing or stolen devices in 2007. Their statistics also show that malicious intent in data breaches is a growing trend. Malicious intent categories include insider theft and access into account information by external methods (hacking).

A new trend, not specifically mentioned in the report, is large caches of stolen information being discovered that no one knew about before. Yesterday, Dark Reading announced that SecureWorks found one of these caches. Finjan has recently reported finding pretty much the same thing located on what they refer to as "crimeservers" on the Internet. The announcement by SecureWorks reported that hackers are using a trojan, called "Coreflood" also known as "AFCore."

SecureWorks reported that this trojan has gone undetected for a number of years and has compromised corporations, government agencies, healthcare agencies and "others." In this attack, one work station would be compromised and the hacker would wait for an administrator to log on. Once the administrator logged on to the infected work station, the hacker would then use the administrator's privileges to infect entire systems. This "hack" is being used to grab user names, passwords and even entire pages of information. Please note (my speculation) that this type of exploit is probably being used to steal more than financial information, also.

Given the fact that SecureWorks mentions government sites being hacked in this manner, there is no telling what the intent might be or who the information is being sold to (my speculation).

To the best of my knowledge, neither SecureWorks or Finjan have disclosed exactly who has been compromised or the exact details of the information to the general public.

This should lead the average person to believe that the problem of data breaches is far greater than anyone knows. The ITRC study explains why this is a problem when compiling any study on this subject.

Besides the ITRC, there are a lot of dedicated people gathering statistical information on data breaches. While they can only track information on the known occurrences, these people do a lot to educate the rest of us and raise the awareness level of what is becoming a growing problem.

The report gives credit to PogoWasRight, Attrition.org, breachblog.com, the Maryland and New Hampshire Attorney General breach notification lists and other sources that were used to compile this report.

The ITRC is a non profit organization designed to help businesses and people protect themselves from this clear and present danger to all of us. If you are interested in this problem, their site is a good place to educate yourself.

Sunday, June 29, 2008

Wards will now start notifying customers their information was stolen in December

The Associated Press announced on Friday that old time retailer Montgomery Ward is the latest victim of a data breach, where at least 51,000 records were compromised. The unfortunate problem now is they failed to notify the victims, which is the law in 44 States.

Since Montgomery Ward declared bankruptcy in 2001 this announcement might sound confusing, but the company was resurrected in 2004 under the name, Direct Marketing Services Incorporated. Direct Market Services sells merchandise under the names Wards.com, SearsHomeCenter.com, SearsShowplace.com, SearsRoomforKids.com (and two more) online.

Allegedly, hackers gained access by going through another Direct Marketing Services site, HomeVisions.com.

When they discovered the hack in December, they did notify their payment processor, Visa and Mastercard, but failed to notify any individual customers. Of course, they now plan to do so after being asked about it by the Associated Press.

The hat tip in this instance goes to CardCops, which a group of cyber sleuths who track stolen payment card data in underground carder forums for financial institutions. CardsCops spotted a group of 200,000 card numbers for sale (including CVC data) on one of the forums (chatrooms) they were monitoring. After tracing some of these cards to their owners, they discovered that they were had one thing in common (Wards).

At this point, it is unclear on whether the official estimate of 51,000 missing records is correct, or the hackers misrepresented the number of cards available in their underground forum.

When asked for some commentary, Visa declined to comment, MasterCard stated they warned the issuing banks to watch for suspicious activity and Discover stated they issued new cards.

Wards is not alone in not notifying their customers, or the public promptly when a data breach occurs. Recently lamented about this in a post suggesting we are a long way from full disclosure in data breaches.

Even without all the known data breaches, there are many that are never discovered. Besides that, information is stolen all the time on a smaller scale by dishonest employees, phishing and (despite all the shredders) from the trash.

The sad truth is from the criminal perspective, stolen information that hasn't been detected is worth more than information that is known to be "hot."

If you would like to see more information on the known data breaches, the DLDOS database at Attrition.org is a good resource. PogoWasRight is also another place that covers the privacy concerns arising from this problem, which faces us all.

Tuesday, June 24, 2008

Inside CRM publishes 50 ways to protect your privacy!

I got a tip from Fiona King at InsideCRM magazine about an article they published that lists fifty tips to protect your privacy, personal and financial information. InsideCRM represents the customer relationship management industry.

The article intended to provide useful tips to protect the average person from fraud, phishing, and all the assorted financial misdeeds facing the average person in today's world. The tips provide information on how these scams originate and emphasize how a person can take back control of their personal and financial information.

The article covers how to protect yourself both on and offline and how you can track your personal information on the Internet. Although I've seen many of these tips before, putting them all in a one-page format makes this article a useful tool. Along with the fifty tips are useful links, which direct the reader to the source material about the particular tip.

The CRM industry has a stake in fighting the battle against scams that are being made easier by technology. Consumer trust is a key factor in any type of business involving customers.
One growing concern that can give the industry a bad rap (even though the legitimate CRM center had nothing to do with it) is a phenomenon called vishing where personal information is stolen by calling people up on the telephone. This type of activity is a growing phenomenon. In most cases, the crooks impersonate a legitimate organization when doing this.

My personal tip on how not to get caught in a vishing expedition is to remember that no reputable organization will ever call (unsolicited by you) and ask for personal or financial information. If this occurs, a red flag should go up in your head and I recommend verifying the number via a known third party source and calling them back. Do not rely on caller ID; spoofing services (which fake caller ID) numbers are available to anyone with the capital to purchase them on the Internet.

The article lists some useful tips when dealing with VoIP (Voice over Internet Protocol) technology, which many believe is the cause in the recent surge of vishing activity. The reason for this is that it has made calling long distance cheap and vishing scams now come from all over the world, making them hard to investigate or trace.

Additionally, CRM centers often deal in personal and financial information. One of the biggest consumer trust issues that faces the industry is when information is breached from within a CRM center. Recent reports of information being stolen at CRM centers have made internal security at CRM centers a priority.

Please note that CRM centers are not the only places personal and financial information are compromised. This is becoming a sad reality and any business that deals in "information" needs to be aware of the potential risks of having this valuable commodity stolen from under their noses.

Most technology scams involve healthy does of social engineering (human trickery) to make them work. Education is the best defense against social engineering and InsideCRM has provided all of us with a valuable tool to do this with!

Sunday, June 22, 2008

Identity Theft Service wins Network Products Guide 2008 Product Innovation Award

Tom Fragala announced on his blog that "Truston received a 2008 Product Innovation Award from Network Products Guide for our myTruston Software-as-a-Service (SaaS) platform."

Tom is a well known blogger on the subject of identity theft, was really a victim himself and has spent a lot of time advocating for victims.

He quoted Networks Product Guide as saying:

“Truston's innovative SaaS platform offers an organized approach to getting a stolen identity back and keeping it safe.

myTruston is the only ID theft product that does not require sensitive data, is the only SaaS product in the space, supports virtually all fraud types, has unlimited content extensibility, is built on a patent-pending task management engine and allows for seamless integration with partner's web sites.”

Truston is a platform that allows the individual to protect themselves and recover from identity theft without handing over their personal and financial information. Many of their competitors maintain this information in databases, which seem to be compromised, frequently.
Some of them also require you sign a power of attorney to use their service.

In fact, there is so much compromised information out there, no one is really sure how much there is. Finjan, a noted computer security company, has recently been finding crime servers containing a lot of stolen information that no one knew had been compromised before. Ironically, the owners of these crime servers didn't even bother to password protect them in certain instances.

Despite this, we read about known data breaches all the time.

This isn't the first award Truston has received from the Technology industry and I suspect it won't be the last.

The neat thing is that if you are reading this post, Tom is still offering a free 45 day trial. Of course, the protection part always has been free.

If you would like to try the services for free, click here.

Recently MyTruston created a partnership with Identity Force and their platform is now being used by government agencies. These include the Department of Veterans Affairs, FEMA, US Coast Guard, Transportation Safety Administration, and Department of Energy.

While identity theft is a growing problem and no one can protect themselves 100 percent, MyTruston offers a platform to do so that is at least as good (if not better) than anything else in the industry. If you see advertising for an identity service that is 100 percent bulletproof, I recommend exercising the sage principle of caveat emptor (buyer beware) before shelling out your hard-earned money.

The reason I say better is that it was built on principles that protect privacy and by an individual that wanted people to "trust" his product.

If you would like to learn more about MyTruston, their site has a FAQ page that answers a lot of questions.

Press release on this latest award, here.

Sunday, June 01, 2008

Bank of Mellon reports a second data breach

Last week, the Bank of Mellon disclosed they had lost unencrypted tapes containing the personal and financial information of several million people about three months ago.

Now it is being revealed that about a month ago, another incident involving a missing (unecrypted) tape occurred. This time, scanned images of checks, along with other assorted sensitive information disappeared. The Check 21 Act, passed in 2004 allows financial institutions to electronically deposit images of checks instead of using the actual paper check, itself.

According to press release on the matter, they are now going to start using encryption. I wonder how many other institutions out there are still not encrypting all of their confidential information?

Ironically, if you read the privacy and security pages on Bank of Mellon's site, they seem to be very pretty savvy about both identity theft and privacy issues.

The first incident occurred on February 27th and the now revealed second incident occurred April 29th. If they knew it happened on April 29th, why wasn't this one reported with the other one? The February 27th incident was reported last week, which was well after April 29th.

Of course, I'm sure that the "official explanation" will be that they didn't know if it was really missing and no one is really sure if the information is being used to commit identity theft.

Here is the low down as reported in Pittsburgh Tribune Review on the April 29th occurrence.:

The most recent incident occurred on April 29 when a backup data-storage tape containing images of scanned checks and other payment documents was lost while being moved from Philadelphia to Pittsburgh, spokesmen for the bank said Friday. It involved data of 47 institutional clients and a yet to be determined number of individual customers.

A ComputerWorld article by Brian Fonseca highlighted concerns that are being investigated by Connecticut Attorney General Richard Blumenthal, who is working with his peers in other States to determine why it took so long to report the matter. AG Blumenthal is also asking some hard questions as to why some tapes disappeared and other ones arrived at the storage facility.

The obvious reason, he might ask this question is that it probably points to an insider being involved (my speculation). If this is the case, it is very likely they had somewhere to get rid of the information, or more specifically, sell it.

His press release on the matter listed a lot of institutions, who may have had customers compromised in these incidents.

One thing I wanted to add is that in the most recent occurrence, they are stating scanned checks were contained on the tape. This would make it pretty easy for criminals to use the information to produce counterfeit checks. In recent years, we've seen checks counterfeited on a massive scale, and sent all over the world via snail mail, or even Federal Express and UPS. A recent joint investigation conducted in several nations revealed that these items were being produced on an industrial scale in certain countries.

Many of these counterfeit checks are passed via "too good to be true scams" on the Internet. There are also organized criminal gangs that pass counterfeit checks, also.

Interestingly enough, the way laws governing counterfeit checks are written, the banks have almost zero liability and pass off the loss to the entity who accepted them.

Since counterfeit checks are normally exact copies of actual checks, this made me wonder if sometimes the source of the information to produce them is coming from all the scanned checks being electronically transferred between businesses and financial institutions? Payment (credit/debit) card is transmitted and stored pretty much the same way, and there is certainly a history of these transactions being targeted for criminal purposes, frequently.

According to their most recent press release, the Bank of Mellon is offering free credit monitoring and identity theft insurance through Experian. This has become standard in the wake of most data breaches, but it doesn't necessarily protect a person from all forms of identity theft.

Some examples of where free credit monitoring doesn't catch identity theft right away are medical benefit fraud, employment fraud, government benefit fraud, some forms of check fraud and last, but not least, when it is used to commit crimes of other than a financial nature.

Additionally, the ComputerWorld article mentions that at least one class action law suit has been filed as a result of this:

This week, a lawyer representing 40 affected individuals filed a class-action lawsuit against the New York bank in Connecticut Superior Court. Attorney Michael Stratton, who represents the plaintiffs, said he is seeking up to seven years of free credit monitoring and credit insurance for customers, along with unspecified damages.
I found a list of companies that might have had their customers compromised in these data breaches on the Connecticut AG site:

People's United Financial Inc., John Hancock Financial Services, Inc. (acquired by Manulife Financial Corporation), The Walt Disney Company, TD Bank Financial Group, The Bank of New York Mellon Corporation, Hudson United Bancorp (acquired by TD Bank Financial Group), United Parcel Service, Inc., Wachovia Corporation, MetLife, Hudson City Bancorp, Eastman Kodak Company, Burlington Resources (acquired by ConocoPhillips Inc.), Providian Financial (acquired by Washington Mutual, Inc.), Penn Fed Financial (acquired by New York Community Bancorp), ADESA, Inc., Alcatel-Lucent, Odyssey America Reinsurance Corporation, Seacoast Financials Services Corp. (acquired by Sovereign Bancorp), Viewpoint Bank, Diamond Shamrock (acquired by ConocoPhillips Inc.), Sound Federal Bancorp (acquired by Hudson City Bancorp), Big Lots, Inc., Guidant Corporation (acquired by Boston Scientific Corp), New York Community Bancorp and ACE Limited.

Bank of Mellon press release on this matter, which contains information for potential victims, here.

Saturday, March 22, 2008

Barack, Hillary John - Does anyone know where our (your) privacy has gone?

About a week ago, I wrote a post about Britney having her privacy "jacked" by a bunch of "naughty" hospital employees. This occurred at one of the most respected medical and institutions of higher learning in the world, the University of California, Los Angeles.

Ironically, it's now been revealed that another highly respected institution, the State Department had some "naughty" employees "jack" the privacy of the three major presidential candidates, Barack, Hillary and John.

While a lot of us take Britney's exploits with a grain of salt, it's another example where too many people are being given access to too much sensitive information. Even if we take most of Britney's adventures in a not very serious light -- she is a human being and therefore worthy of a little respect and privacy in her personal affairs.

This should be especially true when someone is seeking medical attention of a sensitive nature.

The official spin in both instances is that these events were caused by naughty employees, who were snooping where they shouldn't have been. While it appears there was no sinister intent in all of this, it points to the fact that none of us can count on a little respect or privacy, anymore.

Maybe we have too many databases containing highly personal information that the wrong people have been given access to? You can spend millions on security, but no amount of it will prevent something from being compromised if the wrong person has been given access to it.

Of course, the there is a financial motive to not wanting to fix the problem anytime in the near future. It's no secret that selling personal information is a multi-billion dollar business. Implementing technology is a multi-billion dollar venture, also. It shouldn't surprise us that there is a lobby (with a lot of money), who wants to keep things the way they are.

Because of this, it shouldn't surprise us that we see criminals exploiting the loopholes in protecting information, either. After all, they're making a lot of money off it, also.

If naughty employees with a penchant for snooping could obtain the personal information of three political candidates, it isn't a far stretch that someone with more sinister intentions could have accomplished the same thing. I wonder, who failed to notice that we are now granting "contract employees" access to information of this nature?

After all, this isn't the first time a contract employee, government or otherwise, has compromised sensitive information.

I guess private businesses aren't the only entities outsourcing jobs (and a lot of people's personal information) in the process. We seem to live in a world, where in order to save a little on the bottom line, we seem to ignore basic principles (like need to know) when protecting information.

Perhaps, if we stopped storing sensitive information in too many places with little regard to who can look at it, we would stop being "shocked" when it's compromised?

All a reasonably intelligent person would have to do is look at the number of reported compromises involving sensitive information that occur and then wonder how many more there are that no one knows about? I threw that in because most people, who do something wrong normally don't disclose what they did to third parties.

After a compromise occurs, we all seem content that security enhancements will prevent the next one. Sadly, most of the enhancements introduced so far haven't put a dent in the problem and the saga goes on. In fact, it normally doesn't take very long before we hear about the latest security enhancement being defeated.

Maybe the problem needs to be taken to a more simple level? Perhaps if we weren't storing information in places -- where too many people have access to it -- we would see less of it being compromised?

We live in a world, where technology has made things easier and more productive. The problem is that "easy and productive" is taking a toll on what should be a basic human right, privacy.

The bottom line is that it has become too easy to compromise information and technology makes both good and bad people, more productive.

Saying all that, the three candidates are on record, when it comes to privacy. In July of 2006, Hillary Clinton spoke to a lot of same issues in a speech, where she said:

Privacy is at the crossroads of all these issues, and modern life makes many things easier… and many things easier to know. And yet, privacy is somehow caught in the crosshairs of these changes.

Our economy is increasingly data driven. We have dramatically ramped up surveillance in our efforts to fight terrorists who hide among innocent civilians.

But every day the news contains a story of how the records of millions of consumers, veterans, patients have been compromised.

At all levels, the privacy protections for ordinary citizens are broken, inadequate and out of date.

Likewise, Barack Obama has the following statement about this issue on his site:

Dramatic increases in computing power, decreases in storage costs and huge flows of information that characterize the digital age bring enormous benefits, but also create risk of abuse. We need sensible safeguards that protect privacy in this dynamic new world. As president, Barack Obama will strengthen privacy protections for the digital age and will harness the power of technology to hold government and business accountable for violations of personal privacy.
John McCain (as part of a bipartisan committee) has expressed frustration on the privacy issue, also. Here is what he was quoted as saying in a CNet story after a FTC report was released on the state of the state on privacy:

A bipartisan group of senators led by Sen. John McCain, R-Ariz., said it is determined to pass new laws restricting the ability of Web sites to collect and use information from a visitor without that person's consent.

For the last several years, Web sites have operated under a form of self-regulation, and industry groups have touted the ever-increasing number of sites posting privacy policies. However, members of the Senate Commerce Committee today decried those steps as inadequate and cited polls showing that the vast majority of consumers opposed industry self-regulation.
There is no doubt that by this point in the game, most of our politicians have made a statement on the privacy issue. Despite these statements, most of the legislation presented in Washington hasn't been passed yet?

In fact if memory serves me correctly, the last time we tried to pass some federal legislation, the end result was that it would have watered down more proactive laws already passed into law at the State level.

I know everyone is busy with the campaign underway so I'm going to include a reference to an article (with an interactive map) showing what State laws on this issue have already been enacted. Included on the map is a interactive flag over the District of Columbia showing which federal laws have not.

Well put together article by csoonline.com, here.

In case anyone reading this can't keep up with the record number of data breaches, Attrition.org had a chronology, here.

PogoWasRight is another place that helps me keep up with the record number of compromises, also.

Sunday, February 24, 2008

Will the Experian versus Lifelock law suit help identity theft victims?

Lifelock -- one of the companies that offers identity theft protection at a cost -- is being taken on by one of the big three credit bureaus. Last week, Experian filed a law suit seeking damages for their costs associated with placing and replacing credit alerts.

Before continuing on, it needs to be noted, as it has been by Lifelock CEO Todd Davis that Experian and the other members of the big three are involved in the identity theft protection business, also.

There is an interesting article by Terry Bibo at the PJStar.com about a Catepillar retiree, who was offered free credit monitoring after a data compromise. According to the article, the retiree tried to use the company provided protection service (ConsumerInfo.com), which is owned by Experian. The end result is seven months later all he has received is someone else's credit report and nothing has been done to protect him from becoming a victim.

It should also be noted that Lifelock isn't the only identity theft protection service that operates along the business model of charging people to place credit alerts or freezes on their reports.

Other companies, such as Debix and Trusted ID offer pretty much the same service.

Unfortunately, I'm not certain that any of this is necessarily going give any additional recourse to the millions of identity theft victims, who should be what this is all about. This law suit seems to be more about who is going to cash in on the identity theft protection industry, which by most estimates is showing double digit growth.

Lifelock has been under fire since it was disclosed by Ray Stern at the New Phoenix Times that one of the founders, Robert Maynard had been banned by the FTC to work in the credit repair industry and had been accused of identity theft by his father, who bears the same name he does.

At the time, Lifelock marketed their product by claiming it was inspired by Maynard being wrongfully arrested after his identity was stolen. The article revealed evidence that this wasn't true, and revealed that Maynard had been arrested for not paying his bill at a casino. The story was backed up with a booking photo of Maynard and a statement from an official source at the Clark County DA's office that Maynard had never claimed identity theft at the time of his arrest. In fact, according to the source at the DA, he made full restitution, which prevented the case from being prosecuted.

Shortly thereafter, CEO Todd Davis made headlines when he organized a "posee," complete with film crew to go after the person, who stole his identity to get a loan. The identity thief in question was described as mentally disabled by the authorities and the charges were dropped because of the questionable tactics used, referred to as coercion.

There are a lot of forms of identity theft and not all of them show up on a credit report. The fact that Todd Davis' social security number (which he plasters all over the universe as a marketing tool) is a pretty good indicator of this.

Stephen Lemons, who writes Feathered Bastard column for the New Phoenix Times wrote about the pending law suit. He pointed out that despite the negative publicity that Lifelock has received, it's business continues to grow.

The advertising campaign referred to consists of everything from television advertising to blogs. In fact, some of these blogs could probably be classified as splogs (my opinion). Recently, I've even seen e-mails touting the service that were caught in my spam filter. These e-mails have the following verbiage, "BBB: "LifeLock is the best Identity Theft Protection We Have Found."

When looking into this it was pointed out to me that the BBB (at least the Better Business Bureau?) doesn't provide endorsements.

Another thing, I noted in the several unsolicited e-mails I've received was that I was getting them because I had "opted in" at either Lifelock, or an affiliate. Strange, I don't remember ever opting in to receive e-mail campaigns from Lifelock? I do remember tracing a mysterious link from a Lifelock affiliate to this blog. When you tried to click on this link, which was set up on a Chinese domain, it redirected right to the main Lifelock website.

There are a lot of players in pay per credit alert business. Will this litigation eventually be the precedent for further litigation? I suspect Lifelock is the initial target because of some of the aggressive marketing tactics they use.

In November, the New York Times published an article by Brad Stone about Gideon Yu and his investment in Debix. In the article, he wrote:

Gideon Yu, the former chief financial officer of YouTube and current chief financial officer of Facebook, is one of the most notable new executives in Silicon Valley. But while Mr. Yu operated in high-tech’s highest circles over the last two years, an impersonator was quietly using his name and credit card number to make fraudulent purchases.

This is another testament that just about anyone can become an identity theft victim and it noted the frustration Mr. Yu went through trying to resolve his personal issue.

Another item mentioned in the article was that the credit bureaus make it difficult for the average person to protect themselves:

Other individual investors and venture capital firms also see opportunity in the business of combating identity theft. The big three credit agencies — Equifax, Experian and TransUnion — offer several tools for preventing ID theft, but generally make putting such measures in place difficult for consumers — requiring them to send requests by certified mail, for example, and making them renew fraud alerts every 90 days.

What's interesting about this is that most identity theft has been enabled by the buying and selling of too much personal information without protecting it very well (my opinion). It makes sense that those profiting from selling information and protecting us from the fall out wouldn't want to make identity theft protection easy. If they did, it probably would cut into some profit margins by making it harder to issue credit. Of course with the record amount of bad debt out there, this might not be such as bad idea (my opinion again)?

I'm not sure where this lawsuit will go, or if this action will spawn others in the future. The only thing I do know is that it would be nice to see the victim get a fair shake for once. There has to be a better way for the average consumer to protect themselves.

The article quotes Gail Hillebrand at the Consumers Union:

Many consumer advocates say that no one should have to pay anything to defend against identity theft. “Having to renew a fraud alert every 90 days is a pain, and I can see why there’s demand for these services,” said Gail Hillebrand, a senior lawyer at Consumers Union. “But the ultimate solution is not for consumers to pay someone extra. It’s for the credit agencies to make this an easier process and to extend fraud alerts for a year.”

NY Times article about Gideon Yu and Debix, here.

Feathered Bastard article, which contains a link with the actual Experian complaint, here.

In case you can't afford the extra money to protect yourself, or simply are frugal, here are two links on how to "do it yourself," I recommend taking a look at:

FTC site on how to deal with identity theft, here.

Information by the Privacy Rights Clearinghouse, here.

Consumers Union (quoted above) does a lot of work to advocate for better laws that will be more consumer friendly, also.


Click here to Guard your Identity

Saturday, February 16, 2008

The $54 million lost laptop law suit

Found this story on SANS Newsbites. Apparently, a former Best Buy customer is suing Best Buy after they lost her laptop and allegedly tried to cover up the matter.

After going to a link on Information Week, I discovered that the plaintiff in question, Raelyn Campbell started a blog to chronicle her battle with the retailer.

The blog states Raelyn's intention in her own words:

I have filed a lawsuit against Best Buy and launched this blog in an effort to bring attention to the reprehensible state of consumer property and privacy protection practices at America's largest consumer electronics retailer, with the hope that it might motivate Best Buy to effect changes and spare future consumers the experience I have been subjected to -- or worse.

Whether due to what seems to be a plague of bad customer service, inept employees or a combination of both, Raelyn charges that:

Her laptop went missing and the Geek Squad initially couldn't find it in their computer.

That later on, a computer entry mysteriously appeared which leads to speculation that the Geeks were covering their tracks.

She tried to settle for $5,000.00, but was continuously low-balled by Best Buy.

After she filed a law suit, Best Buy tried to offer $2500.00.

Raelyn declined this offer because (in her own words):
I advised Best Buy's lawyer that I would drop the suit if Best Buy would provide compensation for my expenses and time and address the shortcomings in its property and privacy protection practices.
Additionally Raelyn is charging that Best Buy broke D.C. law by not notifying her immediately that she could become an identity theft victim.

Her blog has a lot of links to other allegations of employee abuse at Best Buy, which can be seen, here.

Of note, this episode -- no matter whether you think a $54 million law suit is called for or not --brings up the very real problem of all the portable data we carry being exposed when we drop it off somewhere for repairs.

It's a far shot that a responsible business would knowingly employ personnel that steal, but dishonest employees are a reality in today's world. Since information isn't inventoried and can be copied, protecting it is a little more difficult than other assets such as money or merchandise. In fact, most of the time when information is stolen, no one ever probably notices it is missing (my opinion).

Since information is worth a lot of money, this poses a problem.

This leaves a lot of things to consider and my guess is that protecting information is going to be a hot subject for a long time to come.

There are a slew of comments on the blog, both bashing and praising Raelyn for this action. Please note on blogspot, Raelyn can control the comments and therefore is being transparent by publishing them all.

To end this post, I will refer to (what I consider) some sage advice and commentary from three SANS newsbite editors:

[Editor's Note (Pescatore): I was thinking of suing my employer for about that much for forcing to me to carry a laptop all the time. This does point out an issue where some companies have allowed employees to do business on personal laptops that get repaired at places that don't protect them very well, and then the business information ends up on eBay and thousands of customers have to get notified, etc. etc.

(Cole): This will continue to happen; so two key take aways. One, use folder level encryption with a strong passphrase so repair people will not have access to your data. Full disk encryption will not work, since the techs need to log into the system. Second, backup of all of your critical data on a removable drive.

(Schultz): It is easy to predict that lawsuits of this kind are going to proliferate in the future. Many organizations have been downright irresponsible in handling personal and financial information, let alone others' computers. The threat of a lawsuit is likely to force such organizations to radically tighten their procedures for handling such information and computing equipment.

If you are interested in reading more from the SANS people, I've provided a link to their SANS Newsbites page, here.

Tuesday, January 08, 2008

Sears faces class action for violating customer privacy on their site

A few days ago, I wrote about a post on the Truston blog concerning Sears being taken to task by a Harvard professor and the Washington Post (Brian Krebs) for violating customer privacy on their site.

Not only was information being data mined for marketing purposes, but the site allowed third parties (anyone) access to it.

Now it appears lawyers have gotten together a class action against Sears.

In an update, Brian Krebs is reporting:

In a complaint filed Friday in Cook County, Illinois -- where Sears is headquartered -- the plaintiffs allege that the lack of privacy protections at Sears's managemyhome.com site violated its own privacy promises to consumers, and in so doing ran afoul of the Illinois Consumer Fraud Act, which prohibits "unfair and deceptive practices."

The complaint seeks class-action status, and more than $5 million in damages, including attorneys' fees. A copy of the complaint is linked here (PDF).

The suit was filed by KamberEdelson, the same New York City based law firm that successfully pursued Sony BMG Music Entertainment after the media giant shipped millions of music CDs that included spyware.

The same law firm is also seeking plantiffs for a second class action against Sears for installing tracking software on customer's computers after they made a purchase on their site. This might set an interesting legal precedent given all the tracking sofware being used out there.

After all, there is a lot of customer espionage going on out there (my opinion).

So far as me personally, this story has made me extremely wary of shopping at Sears, whether in a mall or on the Internet.

Full story from Brian Krebs on the Security Fix blog, here.

Sunday, January 06, 2008

New IRS rules dictate stricter controls on how personal information is marketed by preparers!

Last year, a large amount of fraud cases were reported when people claimed refund anticipation loans using fraudulent information.

In many instances, these fraudulent returns were filed using the earned income tax credit. The earned income tax credit returns a portion, or all of the taxes people pay, who are below a certain income level when they file their yearly tax return.

While an honorable practice in principle, the credit is targeted by fraudsters, who submit fake W-2 information and claim large refunds that they were not entitled to.

W-2's can be purchased in just about any office supply store, or even over the Internet.

Another growing trend noted -- with all the stolen identities and counterfeit identification out there -- are fraudulent tax returns being filed using other people's information. RAL refunds can net several thousand dollars each, which make them prime targets for financial fraud.

Low income people are also often recruited to go in and get these loans using "made up" information.

Guess who ends up getting caught if the IRS discovers the fraud in most instances? I'll give you a hint, it probably won't be the person who talked them into doing it.

I'm not sure if all the tax refund fraud and reported identity theft last year inspired the recently announced IRS rules, but it's probably a good guess that it had something to do with it.

The IRS is now giving taxpayers more control over their personal and financial information. They are also examining whether certain restrictions should be placed on refund anticipation loans.

The IRS press release states:

Federal law already strictly prohibits the IRS from making disclosures of taxpayer return information within its control to third parties except with taxpayer consent or in circumstances set by Congress. The final rules have no effect on the strict protection of return information in the IRS’s hands and apply only to tax return information held by income tax return preparers.

Among the new rules:

Generally, preparers must obtain taxpayer consent, either by paper or electronically depending on how the return is being filed, before tax return information can be disclosed to any third party or used for any purpose other than filing the return.

If the taxpayer consents to the disclosure and use of his information, the consent must identify the intended purpose of the disclosure, identify the recipients and describe the particular authorized disclosure or use of the information.

Mandatory language informs individual taxpayers that they are not required to sign the consent; that if they sign the consent, federal law may not protect their information from further disclosure; and that if they sign the consent, they can set a time period for the duration of that consent. If taxpayers fail to set a time period, the consent is valid for a maximum of one year.

To prevent consent requests from individual taxpayers from bring buried in fine print, the rules require the paper consent documents to be in 12-point type on 81/2 by 11 inch paper and require electronic consent requests to be in the same type as the Web site’s standard text, all to prevent consent requests from being too difficult to read for individual taxpayers.

If a taxpayer declines to provide consent for an unrelated tax preparation disclosure or use request, the preparer cannot make a similar consent request. The intent is to protect taxpayers from being pressured with repeated consent requests regarding the same issue.

Mandatory consent from taxpayers also is required if the tax information is going to be disclosed to a tax preparer located outside the United States. This provision is intended to ensure taxpayers are informed if their tax information is being sent off-shore for return preparation. The individual taxpayer’s Social Security Number also must be redacted.
The press release also states:

One issue that was raised during the comment period was the use by tax return preparers of tax return information to market Refund Anticipation Loans (RALs) to taxpayers. The issue of marketing RALs and similar products, such as Refund Anticipation Checks and Audit Insurance, was not specifically addressed in the proposed regulations.

The Treasury Department and the IRS are concerned that RALs and similar products may provide preparers with a financial incentive to take improper tax return positions in order to inflate refund claims inappropriately. In order to give the public an opportunity to comment on this issue, the Treasury Department and the IRS are issuing an Advance Notice of Proposed Rulemaking (ANPRM) that announces they are considering a proposal that tax return preparers be prohibited from disclosing or using taxpayer return information for the purpose of selling products such as RALs and similar products.
Last year it came to light that a Jackson Hewitt franchise owner with a lot of branches was being charged by the federal government for enabling this type of fraud. The dollar amount of the fraud was calculated by the government at about $70 million.

Here is the post, I wrote about this particular incident:

Is tax fraud being enabled by too many dishonest preparers?

While the Jackson Hewitt allegations were major news, it probably only accounts for a small portion of the overall fraud committed with tax returns. In previous years, we've even seen prisoners file phony tax returns from behind bars.

Dishonest preparers also sometimes try to get their customers to claim questionable exemptions. This can lead to the customer ending up in a lot of trouble at a later date.

The IRS has a educational document to educate taxpayers about this problem, here.

If you happen to know of anyone committing any of these tax frauds, the IRS has a place where it can be reported, here.

Press release on the new rules and possible restrictions on RAL products, here.

There are articles circulating in the mainstream media with more information on how this might hurt the profitability of the tax preparation industry. I'll include the one from Reuters written by Jonathan Stempel, here.

Saturday, January 05, 2008

Sears site violates people's privacy!

Ran into this story on the Truston blog. Tom Fragala, CEO of Truston writes:

The internet retailer you choose just might, without disclosure, install software on your computer to snoop on your web browsing. Brian Krebs at the Security Fix blog has this story. Would you believe it could be one of the country's oldest retailers though?

"Sears is having a bit of a rough day with the privacy community. The company got off to a rocky start with revelations that many customers who gave Sears their personal details after shopping at the company's Web site also were giving away their online Web browsing habits to marketers, thanks to snooping software silently installed (and ill-documented) by a Sears marketing partner."
Even worse, as revealed in Brian Krebs interesting blog post is that:

The discovery comes from Ben Edelman, an assistant professor at the Harvard Business School and a privacy expert whose research has done much to raise public awareness about the intersection of big business and shady advertising practices.

Sears offers no security whatsoever to prevent any user from retrieving a third party's purchase history, Edelman said, which violates its own privacy policy with such disclosures, no part of which "grants Sears the right to share users' purchases with the general public."

I guess this means that anyone can violate a Sears customer's privacy by using their website as a tool?

Please note that Professor Edelman has shown some pretty good evidence that regular and not just e-commerce customers can be compromised, also.

Going back to Professor Edelman's contention that snooping software was spying on customers -- spyware and adware are used on a lot of sites. In fact, I highly recommend scanning your system on a regular basis using reputable software. I'm always amazed at how much of it I find when I do.

My opinion is that that when information is data mined, there needs to be a transparent way a customer opts-in (authorizes) an entity to use their information.

Current opt-out options are often deceptive and laden with a lot of small print.

So far as Sears, until they disclose what they are doing to fix this (at least answer Mr. Krebs), I'm going to make sure I avoid using their shopping facilities!

Friday, January 04, 2008

CALPIRG does consumer study revealing that privacy laws are being ignored in California

Many believe that the reason behind the identity theft crisis is the irresponsible data mining and selling of people's personal and financial information. This information then gets stored in places, where it is obtained (bought or stolen) by people, who have more than a "marketing" interest in it.

The buying and selling of people's personal information is a multi-billion dollar business.

Given this, a lot of people and consumer groups now are questioning how this done and how the information is protected.

CALPIRG, the California Public Interest Research Group has just released an "interesting" report on this subject and is making some recommendations to the California legislature to make the practice of buying and selling people's personal information more transparent.

From the press release on the CALPIRG site:

California’s consumers are “Still in the Dark” when it comes to who has access to their personal information according to a privacy report released today by the California Public Interest Research Group (CALPIRG).

“This holiday shopping season millions of consumers surrendered their personal information to retailers across the country with no idea how or with whom that information is shared” said Pedro Morillas, CALPIRG Consumer Advocate. “Fortunately there is light at the end of the tunnel. California already has some good policies regarding this issue. A few additions to the existing policies will give consumers the tools they need to safeguard their personal information.”
Currently, California law requires that if a consumer requests to find out where their information went a company must reveal where the information went for the past calendar year, or provide a no cost "opt-out" opportunity.

The report -- which includes a survey of customers trying to to discover where their information went -- revealed that over one-third of the requests were ignored.

Even worse, in addition to not getting a response, many of the customers were given the run around by being sent to other places within an organization or getting responses that had nothing to do with their original request.

CALPIRG is now calling that the California Legislature make the laws stronger with additional measures. They are calling out that the following additions should be made to existing laws:

Companies that do business with California consumers to respond to privacy requests, regardless of whether they share information with third parties.

Companies to both disclose the personal informa¬tion shared, and the third parties with which it is shared, and provide consumers with an opportunity to opt out of future sharing.

Companies to place a box on their Web sites’ privacy pages allowing consumers to opt out of information sharing.

Companies to get an affirmative “opt-in” from consumers before sharing their information with third parties, as opposed to the current practice of requiring consumers to opt out in order to protect their privacy.

The full report from CALPIRG can be read, here.

Opting out and privacy notices with an abundance of fine print have been criticized as not being effective, or consumer friendly for awhile now. Here are two other posts, I've written on this subject:

How does a telemarketer get your unlisted number?

Not answering a Privacy Notice gives the sender permission to sell your personal/financial information

Friday, December 14, 2007

Symantec reveals how the spammers are trying to steal Christmas

Kelly Conley announced the Christmas edition of Symantec's spam report on the company blog:

Here we are the end of another year. As 2007 rolls to a close the December State of Spam Report reviews this past month’s key trends and reflects on some of the year’s most notable spam events and trends.
The report notes that Bill Gates' prediction in 2004 that spam would be eradicated has proven not only to be wrong, but that the amount of spam circulating on the Internet has exceeded everyone's expectations (nightmares?).

This month, three out of every four e-mails sent is spam!

Spammers are even using MP3s, videos, and Google's alerts/searches to spread their seedy marketing ventures to Internet users.

Here are some of the highlights of the end-of-year report:

• Penny stocks use Thanksgiving holiday captions in subject line – spammers using common personal Thanksgiving-related words in the subject of emails

• Replica products a favorite for spammers this holiday season – replica gear has always been a spammer favorite. Spammers are marketing their wares using seasonal words in the subject lines of their mailings

• Spam begins to snowball – spammers collecting email addresses by using a funny .gif that shows a snowball hurtling at you through your computer

• Christmas freebie anyone? – spammers taking advantage of the season to market "free" gift cards for well known companies

• Seasonal lotto scams - in a scam targeted at UK end users, spammers have updated a lottery spam email for a Christmas Bonanza special

The current interest in celebrities like Britney Spears, Lindsay Lohan and the Osmonds were used as lures to get people to open spam e-mails hawking "questionably safe" drugs.

Spammers use whatever is trendy, popular or in the news to trick people into clicking on them. Here is one of the sicker examples of this seen recently:

An attack this month preyed on the public interest in the story of the missing British child, Madeleine McCann. The email contained a link to http://madeleine2007.notlong.com/, which redirected to http://internetwonderful.com/madeleine. The second site is designed to look similar to the official McCann family site, www.findmadeleine.com, however, it actually is set up to distribute a virus. The site also contains an unauthorized use of the Symantec logo and a number of Google ads for anti-virus products.

It should be noted that although the spam email also contains a link to the legitimate findmadeliene.com site, there is no connection between the spammers and the genuine site.

The report concludes it's findings with recognition of anti-spam efforts during the year, such as the FBI's Operation Bot Roast, the SEC's Operation Spamalot, ISP's sharing more information and security vendors employing new spam filter technologies.

We need to remember that spam is the vehicle used to spread 99.9 percent of the questionable marketing and scams on the Internet. Clicking on a spam e-mail can cause a person to become victim of anything from a financial scam to using a unsafe product that is a threat to their personal safety.

These reports serve a purpose, which is to educate the average person on what to watch out for and not click on a spam e-mail in the first place. Since it's Christmas and a lot of us are thinking about the young people in our lives, perhaps this is a good time to educate them on the growing problem of spam on the Internet!

I meet a few older people from time to time that might benefit from the education process, also.

Kelley Conley's blog post announcing the December report, here.

Symantec's December (year end) report on the state of spam, here.

On a lighter note, here is the YouTube video on the 12 days of Christmas Spam:

Saturday, December 08, 2007

Private Eyes charged with aggravated identity theft

This isn't the first time private investigators have been caught using social engineering techniques to steal personal information. The Hewlett Packard case raised caused quite a bit of uproar about this last September.

Here is another case involving private investigators using illegal techniques to data mine information for their clients:

Ten people were indicted by a federal grand jury in Seattle in connection with a scheme to illegally obtain confidential information on more than 12,000 citizens across the country. To obtain confidential tax, medical and employment information, workers at BNT Investigations in Belfair, Washington, would pose as another individual to get government agencies including the IRS, the Social Security Administration, and various state employment security offices to provide confidential information. The year-long investigation dubbed, “Operation Dialing for Dollars,” also revealed that some workers posed as representatives of doctors’ offices to get medical or pharmacy records.
The private investigators used "pretexting," which is a social engineering technique designed to trick people into giving up personal and financial information. Criminals use the same technique to steal people's identities.

In fact, phishing, where an e-mail is sent impersonating a trusted or authority figure with the intent of stealing personal information is a form of "pretexting."

In this case, we might term what these private eyes did as "vishing," which is phishing using the telephone.

It appears that the U.S. Attorney's office agrees that this is little difference in the techniques used by these private eyes and is charging them all with aggravated identity theft.

The ten defendants are charged with Conspiracy and Wire Fraud. Seven of the defendants are charged with Fraudulent Elicitation of Social Security Administration Information. Six of the defendants are charged with Solicitation of Federal Tax Information. All ten defendants are charged with Aggravated Identity Theft. The three Washington defendants are scheduled to appear in U.S. District Court in Tacoma at 2:30 today.

These are the defendants indicted by the grand jury:

EMILIO TORRELLA, 36, Belfair, Washington
BRANDY N. TORRELLA, 27, Belfair, Washington
STEVEN W. BERWICK, 22, Belfair, Washington
VICTORIA J. TADE, 52, San Diego, California
MEGAN OSOSKE, 40, Beaverton, Oregon
DARCI P. TEMPLETON, 55, Houston, Texas
ESAUN G. PINTO, Sr., 33, Brooklyn, New York
PATRICK A. BOMBINO, 58, Brooklyn, New York
ROBERT GRIEVE, 67, Houston, Texas
ZIAD N. SAKHLEH, 26, Houston, Texas

The Torellas, who own BNT investigations, allegedly are the "phishy-investigators" who were selling this illegally obtained information to their peers nationwide.

The private investigators had been hired by attorneys, insurance companies and collection agencies to investigate the backgrounds of opposing parties, witnesses and benefit claimants, and to uncover assets or income. The TORRELLAs promoted their services to the private investigators.

BNT investigations targeted financial institutions and government agencies to get the information they were selling.

This makes me wonder how much the people paying for these services knew and to what extent they might be held liable?

Although, it doesn't appear that more sophisticated spying (identity theft?) techniques were used in this case, in the Hewlett Packard case investigators dropped software (malicious?) on computer systems to monitor the people they were "investigating."

Press release from the Western Washington U.S. Attorney's Office, here.