Showing posts with label privacy rights clearinghouse. Show all posts
Showing posts with label privacy rights clearinghouse. Show all posts

Saturday, August 02, 2008

Countrywide Insider Steal's 2 Million People's Information

On Friday, the FBI arrested a former Countrywide employee and his accomplice for stealing and selling personal information (including social security numbers) obtained from people applying for mortgages. According to news sources, the number of people compromised was about 2 million.

The Countrywide inside man was identified as Rene L. Rebollo Jr., who worked at Countrywide's sub prime lending division, Full Spectrum Lending. Also arrested was Wahid Siddiqi, who was the alleged information reseller in the caper. Both arrests took place in Southern California.

The criminal complaint alleges that Rebollo downloaded 20,000 names a week for about two years. The batches of 20,000 were sold for about $500 to Siddiqi. This amounts to about 25 cents a person compromised.

According to a spokeswoman at Countrywide, the investigation shows that 19,000 peoples information has been actually used.

Beth Givens, of the Privacy Rights Clearing House was quoted in a story about this in the LA Times and aptly pointed out Rebollo sold the information at well below known black market prices. Although the prices for stolen information -- which is sometimes sold in underground Internet forums has dropped in recent years -- a name that has a matching social security number is worth well more than 25 cents a pop.

The official spin is that this information was used for leads to sell real estate, but my speculation is that how would anyone know for sure? According to the news reports, the information was being sold to companies. The FBI posing as a company was able to buy records for Siddiqi.

If it was sold to companies, who knows who they might have sold it to, or if they have any dishonest employees selling it, elsewhere?

This made me wonder if any of the companies buying the information will be publicly disclosed? In a similar case at Certegy -- where another dishonest employee was caught and convicted for selling stolen information to "companies" -- the companies involved were never made public or charged with any crime (to my knowledge). Court records indicated a co-conspirator in this case, but again (to my knowledge) no one has ever revealed exactly who this mysterious co-conspirator was?

Givens also pointed out that names, which include a social security number and perhaps financial data, can be used to commit what is known as new account fraud. New account fraud is where an identity thief poses as their victim and opens new lines of credit. Once this is done the first time, the thief (sometimes thieves) continue to open lines of credit until the victim's credit report makes them look like a deadbeat.

My guess is that the affected people will be offered some sort of credit monitoring/identity theft protection. While this prevents some forms of identity theft, it doesn't necessarily protect from all the ways a stolen identity can be used. Some examples of when it might not show up on a credit report are cases of medical benefit fraud, employment fraud, government benefit fraud, some forms of check fraud and last, but not least, when it is used to commit crimes of other than a financial nature.

Recently, the Privacy Rights Clearinghouse, issued a well written fact sheet pointing out that existing credit monitoring/identity theft protection services do not protect a person from all forms of identity theft. I highly recommend that anyone -- who thinks their identity has been compromised -- read this fact sheet before buying or relying on the free protection offered in the aftermath of a known data compromise.

If and when -- employers are required to react to workers using social security numbers that do not match -- the millions of illegal immigrants already over here are going to have to use real social security numbers and a matching name to remain employed, or obtain employment. While the federal law on this has been tied up in federal court, some States have already enacted similar legislation. This type of identity theft normally doesn't appear on a credit report and is often discovered when a person files their tax return, or gets their social security earning statement and notices employment listed they never had.

A statistic that might support this is the IRS revealing that identity theft used to file tax returns has grown 644 percent in recent years. The two main reasons cited for this were people using them to obtain employment or to file a fraudulent tax return to obtain a phony refund, normally using what is known as the earned income credit.

Stories of large scale data breaches seem to surface, frequently. Despite this, there are a lot more that no one ever finds out about. Recent evidence revealed by Finjan, a computer security outfit, supports the contention that we really don't know how much stolen information there is out there, or how it is being used. Finjan has been discovering what they term as crime servers on the Internet, which contain all kinds of stolen information. This information included compromised patient data, bank customer data and even sensitive e-mail communications. At least some of this information wasn't even password protected on the crime server.

This particular data breach at Countrywide will probably fade into the mist fairly quickly. It does show that any and all security measures can and will be defeated when a person who has access is the point of compromise. The sad fact is that despite a lot of efforts -- until the issues that fuel (enable) this problem are addressed -- we will continue to see personal and financial information stolen.

We have made personal and financial information worth a lot of money and there are a lot of people buying and selling it. Some of them even have legitimate or semi-legitimate status. The more this occurs means the information is going to be electronically transmitted (sold) and then stored in a lot of different places. As long as this keeps happening, it's probably impossible to protect all of it.

Thursday, November 15, 2007

Former Nevada State employee claims he was fired for revealing data breach


(Photo courtesy of wazzywooze at Flickr)

It never ceases to amaze me how a lack of information security translates into official statements that no one is aware of any identity theft that has occurred.

With as many people, we know have been compromised, and accounting for episodes like the one below where we probably aren't sure, who really knows?

The State of Nevada has a possible compromise, where no one seems to be certain, whether or not, a lot of people were compromised.

From the article written about this by RJG.com:

Hundreds of CDs containing payroll information about state employees, including Social Security numbers, have either been lost or stolen over the last three years.

That's the word from state Personnel Director Todd Rich, who says the system has been tightened to prevent unauthorized people from getting employee information.

Rich says his department sent a total of more than 13,000 CDs to 80 agencies for review every two-week pay period over the last three years. He says as many as 470 are still missing, but his agency has NOT been notified of any identity theft as a result.

The powers that be have since instituted putting a password on the CDs, along with a requirement that they be signed for.

The person, Jim Elste, who revealed the fact that the CDs were missing was fired. He claims it was for revealing this matter, but the State is claiming his employment was terminated for "poor management and lack of anger control."

There have been so many data breaches and so many people compromised, if they were to become an identity theft victim, it might be nearly impossible to figure out where the crook got their information.

No wonder, whenever a suspected breach occurs, no one is SURE if anyone has become a victim of identity theft. The only thing we can be sure of is that there are a lot of victims out there and the number is growing.

Reno Gazette-Journal story, here.

If you would like to see how many people have been compromised -- the list grows VERY frequently -- the Privacy Rights Clearinghouse tracks reported breaches, here.

As of this writing, this one isn't listed as a breach yet!

Tuesday, August 21, 2007

The sad state of affairs in the information (identity) theft crisis

It shouldn't surprise anyone that data breaches are becoming more prevalent than ever, or that identity theft is up fifty percent since 2003.

Robert L. Scheier (courtesy of InfoWorld) wrote an article about this that is getting a lot of play in the press:

Today's electronic world is a risky place for your personal data -- and it's not getting any safer. More than 158 million data records of U.S. residents have been exposed as a result of security breaches since January 2005, according to The Privacy Rights Clearing House, a nonprofit consumer rights organization.

As fast as banks, merchants and consumers add new layers of security to their storage systems and network, say security analysts, new technologies -- or simply careless users -- create new security holes that aggressive and sophisticated identity thieves eagerly exploit. The result, says Avivah Litan, a vice president and distinguished analyst at Gartner Inc., is that "things will get worse before they get better."

Whether information is being stolen by phishing, pharming, hacking, insider theft, or common dumpster diving - the problem seems to be growing by leaps and bounds.

An interesting aspect, which I've covered in previous posts is that criminals seem to be using technology as a marketing tool - just like their counterparts in more legitimate businesses:

Criminals are also getting smarter. Larry Ponemon, chairman and founder of Ponemon Institute, which conducts research on privacy and security issues, calls it "inverted customer relationship management," in which criminals target the wealthiest individuals for their attacks.

Some are even buying marketing lists to piece together profiles of "who's got the Platinum [American Express card] and who's got the account with Merrill Lynch and who doesn't," says Litan.
I found this particularly interesting because a reasonable person would have to question, who is selling them these lists?

In the most recent high profile data breach to hit the news at Certegy, a dishonest insider sold the information to a broker. Interestingly enough, as far as I know, this information broker has yet to be identified. The next question might be - who did the information broker sell the information to?

Recently, another data broker (InfoUSA) was pegged for selling marketing lists to sweepstakes scammers.

Perhaps PogoWasRight, who states "We have met the enemy and he is us" hits the reason for the problem right on the nose.

A lot of people are making billions, if not trillions of dollars making it easy to use information. So much information has been plastered in so many places, we seem to have lost track of it all.

This gives the criminals behind this phenomenon a lot of places to steal, or even buy everything they need to commit identity theft.

Another sad statistic is that these criminals seem to rarely get caught. Pretty sure the last statistic I saw was less than 1 percent. This makes it a pretty lucrative criminal enterprise to be involved in.

Despite this, we still don't have a law that addresses data breaches?

With the elections coming up, perhaps we should be asking our elected leaders, why this is the case?

The only way to turn this trend around is to make everyone involved in it, more accountable.

Interesting article by Robert L. Scheier, here.

The article mentions statistics gathered by the Privacy Rights Clearinghouse, which I quote frequently. Other places that gather information on this are PogoWasRight and Attrition.org.

And all of them will be the first to tell you - these are only the breaches we know about. The mysterious criminals stealing the information would rather not disclose, who they are stealing IT from. Of course, the people getting the information stolen from them would probably rather not make it public, either.

Thursday, April 19, 2007

Not answering a Privacy Notice gives the sender permission to sell your personal/financial information

Recently, I did a post on the difficulties a blogger had after receiving a privacy notice from one of his financial institutions (American Express) and trying to "opt-out" (let them know he didn't want his personal and financial information sold).

In reality, most of the privacy notices, we receive are saying "if you don't respond to me, you are giving us permission to sell your personal and financial information."

These privacy notices (hard to distinguish from junk mail) come about from a law passed in 2001 to protect consumers from having their information sold (just about anywhere). This personal information is often put at risk because it wasn't protected, properly.

The Privacy Rights Clearinghouse has a lot of information on this subject and why the version of the law that was passed isn't as consumer friendly as it sounds. Here is what they had to say:

When this law was debated in Congress, consumer advocates argued unsuccessfully for an "opt-in" provision. This stronger standard would have prevented the sharing or sale of your customer data unless you affirmatively consented. Unfortunately, the opt-in standard did not prevail. That is why we emphasize in Fact Sheet 24 that the burden is on you to protect your financial privacy.

They do have an EXTREMELY informative page on the site, which gives a lot of information on the law and how you can protect your information, here.

They also have another page with a lot of information on how to opt-out from having a lot of different companies sell your personal details.

If you are like me and have a "time challenged" life style, there is one place everyone should opt-out from having their information sold, or the credit bureaus. Credit bureaus, collect and gather all our personal and financial information, and make a LOT of money, selling it.

In a lot of instances, they were the ones, who sold it in the first place.

You can do this, by going, here.

The Federal Trade Commission also offers information to consumers on this subject.

Since most of these laws were passed by Congress prior to data breaches being tracked, perhaps the time is right to make a few changes to the law.

In case any of them are interested, the Privacy Rights Clearinghouse, has also been maintaining a very telling chronology of why something should be done, here.

As of this post, 153,558,451 voters and potential voters have been compromised, according to the chronology (which freely admits it isn't 100 percent accurate). The stated reason that it is impossible to be accurate is because in many instances, the total number of people compromised couldn't be determined.

It's normally pretty hard to get the data thieves to comment on how much information they got in any particular breach!

Tuesday, February 20, 2007

Another sad statistic, the Stop and Shop data breach

Last weekend, Stop and Shop (Quincy, MA) reported a data-breach at two of their stores in Rhode Island. After an initial investigation, they tracked the theft to two pin-pads.

Consumer Affairs has the most informative story (my opinion) on this current breach. They are reporting that with the assistance of the Secret Service, four more compromised pin-pads have been identified (all in the Rhode Island area).

Martin H. Bosworth makes an interesting point in his article that the United States hasn't been as proactive as our European friends in instituting new technology to stop debit/credit card fraud, such as chip and PIN.

Of course, implementing PCI data protection standards are not exactly 100 percent, either.

PCI data protection standards were implemented by the payment card industry, and even when they are violated, the only consequence seems to be that the merchant will be fined. The standards are designed to stop merchants from storing information they aren't supposed to.

Consumer Affairs story, here.

Of interest (in this case) is that (it appears) PIN pads were tampered with inside the stores, which makes me wonder if there is some sort of inside connection?

Tom Fragala (CEO, Truston Identity Theft Services) did a recent post on his blog, where he linked to a video on how easily a remote ATM machine can be compromised in a store, here.

Of note, Truston is the only service for victims (that I know of), where someone doesn't have to submit all their personal information to a database, which could be compromised, also.

This is a good video, but note the ATM was in a pretty concealed area, and I'm guessing that these pin-pads were in the check out lanes in stores?

Attrition.org and PogowasRight provide information on data breaches (frequently updated), here.

Someone should start a chronology of how many of the people stealing this information get caught. Unfortunately, the list wouldn't be very long.

*(Update): I must have missed that Attrition.org is recording arrests, but the results are not encouraging.

The most recent news about legislation to protect the people being victimized by this growing problem isn't good.

A recent article by Scott Bradner (Network World) about how special interests are preventing the passage of any meaningful legislation argues this point, eloquently:

The Leahey privacy bill: coddling the criminals?

Sunday, February 18, 2007

Just how many computer records have been compromised?

Just yesterday, I ranted about statistics and how (for the right amount of money) some of them are manipulated to lead people to a particular conclusion.

To counter some recent statistical analysis, I used the Privacy Rights Clearinghouse's, "chronology of data-breaches." Please note, they have a disclaimer on this page clearly saying that their figures are merely an estimate.

This morning, I was reading the "Chronicles of Dissent," which is a new site (off-shoot of PogowasRight.org) and I saw (what I consider) a very interesting post.

100 million records exposed? Nope, make that 1.76 billion and counting.

Apparently, this will be an upcoming topic at the Stanford Law School. I'm going to refrain from my usual "rolling commentary" because I truly feel people should read this post.

PogowasRight is now listed on the data-theft chronology put out by the Privacy Rights Clearinghouse as a resource.

For anyone interested in privacy, both these sites are an excellent place to educate yourself.

Wednesday, January 03, 2007

Medical Identity Theft Could Kill

Recently, I've seen a lot written about Medical Identity Theft. There seems to be a lot of people getting bills for medical procedures they never received and subsequently going through a lot of "pain and suffering" to clear their good names.

And (it seems) organized criminal are getting involved in the activity, probably because it's a "profitable" enterprise with little danger of getting caught.

BusinessWeek online did an interesting article about this, where they said:
Yet the thief isn't always an individual desperately needing medical care. In some instances, the perpetrator can be a doctor hoping to pad his or her income by filing fraudulent claims. Even worse, law enforcement authorities say that more and more frauds are being perpetrated by organized crime rings who steal dozens, and sometimes thousands, of medical records, as well as the billing codes for doctors. The rings then set up fake medical clinics—offering free health screenings as a ruse to draw in patients—that submit bogus bills to insurers, collect payments for a few months, and then disappear before the insurers realize they've been had. (Dixon notes that health records now fetch $50 to $60 each on the black market, vs. a mere 7 cents for stolen résumés.)

BusinessWeek online article, here.

The BusinessWeek article quotes Pam Dixon, executive director of the World Privacy Forum, and rightfully so. The World Privacy Forum (to the best of my knowledge) was the first to call out this growing problem and has done quite a bit of work to determine the extent of it.

They have an entire page devoted to it on their site, here. I highly recommend it for anyone, who is, or might become a victim of this growing trend.

Based on their research, they have presented some key recommendations:

  • Individuals’ rights to correct errors in their medical histories and files need to be expanded to allow them to remove false information from their files.
  • Victims of medical identity theft should have the right to receive one free copy of their medical file.
  • Individuals should have expanded rights to obtain an accounting of disclosures of health information.
  • Notification of medical data breaches to consumers has the potential to save lives, protect health, and prevent losses.
  • All working prototypes for the National Health Information Network need comprehensive risk assessments focused on preventing medical identity theft while protecting patient privacy.

The World Privacy Forum has also presented their finding to several government agencies, including the FTC.

This problem goes beyond the financial implications of identity fraud because it could cause great harm to victims, who have had erroneous medical information put in their medical histories. People could be improperly diagnosed, which might (in an extreme case) lead to their demise.

I did a previous post:

Tell it to the Identity Theft Task Force

Since the Federal Identity Theft Task Force is soliciting information from the public - this would be an appropriate place for someone to voice their thoughts (recommendations) about medical identity theft.

Saturday, December 16, 2006

Boeing Holds Employee Accountable in Laptop Theft

Laptops are stolen all the time - and far too often - they contain personal and financial information that can be used for identity theft purposes.

The Boeing Company announced Thursday that they fired the employee, who had their laptop stolen and compromised 400,000 people's personal information. This wasn't the first Boeing employee that lost a laptop containing sensitive information.

Boeing is saying that the computer was "password protected," and they believe the intent of the thief was to steal the laptop rather than breach the information on it. They are also saying that there is no evidence of identity theft, but are "assuming the worst case scenario."

I sometimes wonder if the same public relations firm prepares all these statements. They all say about the same thing - that there is no evidence the information has been used to commit "identity theft."

Of course, with all the attention brought upon this, even if the original motive was to steal a laptop, the thief probably is now aware the laptop contains a lot of information that can be sold for a price.

It's become pretty easy to find a place to sell stolen information with carder forums designed to do so operating on the Internet. Previous post, here.

The employee was terminated (fired) for not having the information "encrypted" per Boeing policy, which was implemented because of the earlier "laptop thefts."

Even if the information were encrypted - in theory at least - encrypted data can still be hacked by someone with the knowledge to do so. Another problem is that if information can be downloaded, it can be compromised by a dishonest insider, or with a "compromised password."

Just last week, the media was awash with stories of IT students being "courted" to work for organized criminal groups - which more and more - seem to be getting involved in technology based crimes, including "identity theft."

I did a post with my thoughts on this matter, here.

In all fairness, Boeing isn't the only organization losing laptops with personal information on them. The Privacy Rights Clearinghouse, which maintains a chronology of "known data-breaches," hit the 100 million mark this week (number of people compromised in the U.S., alone). Just this week, they documented eight "known" breaches.

Note, they can only document the "known breaches" and breaches that previously were "unknown" seem to be appearing, all too often.

Encryption and computer security measures are only one part of the solution. It's the information that the bad guys are after and we need to stop keeping it in places where it's too easily stolen.

Firing one employee is unlikely to have any impact on the overall problem.

James Wallace, Seattle PI has an extensive article about the Boeing story, here.

Tuesday, May 23, 2006

26.5 Million Veterans Compromised in Data Breach

Data breaches seem to be a weekly occurrence. Now we can add 26.5 million veteran's personal information to the list.

With as many times as this has happened, it never ceases to amaze me that much of this information isn't compromised by criminals with advanced "technical knowledge." In this case - as in many others - it appears the information was on a laptop and was stolen by a home burglar. In other words, 26.5 million people, who served their country have been compromised by a petty criminal.

The Privacy Rights Clearinghouse keeps track of these ongoing data breaches, which can be viewed, here. When you add them all up, it's pretty scary.

Here is the statement from the Department of Veterans Affairs:

The Department of Veterans Affairs (VA) has recently learned that an employee, a data analyst, took home electronic data from the VA, which he was not authorized to do. This behavior was in violation of our policies.

This data contained identifying information including names, social security numbers, and dates of birth for up to 26.5 million veterans and some spouses, as well as some disability ratings. Importantly, the affected data did not include any of VA's electronic health records nor any financial information. The employee's home was burglarized and this data was stolen. The employee has been placed on administrative leave pending the outcome of an investigation.

Appropriate law enforcement agencies, including the FBI and the VA Inspector General's office, have launched full-scale investigations into this matter. Authorities believe it is unlikely the perpetrators targeted the items because of any knowledge of the data contents. It is possible that they remain unaware of the information which they posses or of how to make use of it. However, out of an abundance of caution, the VA is taking all possible steps to protect and inform our veterans.

The VA is working with members of Congress, the news media, veterans service organizations, and other government agencies to help ensure that those veterans and their families are aware of the situation and of the steps they may take to protect themselves from misuse of their personal information. The VA will send out individual notification letters to veterans to every extent possible. Veterans can also go to http://www.firstgov.gov/ as well as http://www.va.gov/opa/ to get more information on this matter. The firstgov web site is being set to handle increased web traffic. Additionally, working with other government agencies, the VA has set up a manned call center that veterans may call to get information about this situation and learn more about consumer identity protections. That toll-free number is 1-800-FED INFO (333-4636). The call center will be open beginning today, and will operate from 8 am to 9 pm (EDT), Monday-Saturday as long as it is needed. The call center will be able to handle up to 20,000 calls per hour (260,000 calls per day).

Recently, I did a post, where another laptop (government) was compromised:

Laptop Loss Exposes U.S. Marines

It amazes me that in the "Age of Compliance," our information isn't better protected. Another thing that amazes me is that "experts" are assuring the public that there is a very small chance this information will be used for identity theft. I supposed that this is based on the premise that the "crook" merely wanted to steal the laptop.

My thoughts are that either the crook stole the laptop for the information, or has now likely discovered (via all the attention this has raised) exactly what they have.

Saturday, March 18, 2006

Information Breaches, the Human Factor

According to the Privacy Rights Clearinghouse, millions of identities have been compromised recently. In fact, it's impossible to quote an exact figure anymore because new reports of breaches are surfacing weekly. In their chronology, they list several occurrences as being caused by a dishonest insider, but in reality how much more of this could be happening?

One of the recent stories was about Ernst and Young getting some laptops stolen. Several other breaches are listed as a result of stolen computers. The question is how did the people, who stole them determine which ones to steal and what information would be on them?

Many other breaches are listed as a result of "hacking." Hacking is a big word and brings visions of teenagers breaking into systems from afar. BUT is it possible, that some of the hacking occurring today might be the result of insider information obtained by the hackers?

A recent study by Taleo research found that background screening at many companies is inadequate. The results of this study are pretty interesting:

27 percent of organizations experienced a major problem, workplace fraud (10%), employee theft (10%) or workplace violence, with an employee who was screened in, but ended up having a criminal record that was not found.

57 percent of survey respondents believe that their organization should be doing a better job of screening employees prior to being hired.

Only 19 percent consider their current background check process very effective at weeding out candidates that do not meet the criteria for employment at their company.

Two-thirds of organizations do not conduct ongoing background checks on employees.

Only 29 percent have ever run an audit of their current screening provider to determine the quality of their screenings.

Of course, in the real world of data breaches, it seems that those, who have been breached, are extremely reluctant to reveal very many details.

AND there is another problem, which is the number of illegal immigrants out there in the work force. Depending on who you quote, they number in the millions and the trafficking is done by organized criminal gangs. Many of these immigrants owe lots of money to these gang members and already use fake, or stolen identities to work. How many of them might be repaying their debts by stealing information?

Here is a document from CERT, which shows the implications of organized cyber crime:

Organized Crime and Cyber-Crime: Implications for Business

There is no doubt this is trend is growing and will continue to be a problem. Whether these organizations approach insiders for information, or plant them from within with fake identities; they can steal a lot of what is a very profitable commodity in the world marketplace, or information.

Another potential problem is outsourcing financial and computer services to other countries, where the security standards are not up to par. In fact, this might even make some of these firms more attractive targets for the criminal element. I wrote about this in a previous post:

What are the Security Implications of Outsourcing

Until some of the organizations, who have been breached are held more accountable, we will probably never know the true scope of "insider involvement."