Showing posts with label refund fraud. Show all posts
Showing posts with label refund fraud. Show all posts

Sunday, September 23, 2007

TJX class action settlement only addresses about one percent of the total people compromised

Friday evening, MarketWatch announced that TJX -- who suffered a data breach compromising over 45 million of their customers --has agreed to settle the class action lawsuits that were filed against them after the data breach was disclosed.

The class action lawsuits referred to were filed in both the United States and Canada.

Since most of the financial losses have been incurred by financial institutions -- who had to reissue the compromised cards and settle the fraud claims -- this settlement appears to primarily address the customers compromised by the breach of TJX's refund database.

This would amount to about 455,000 people, or one percent of the total number of people compromised.

Another issue that is still pending is how information is stored, and who will be responsible for paying for the administrative costs arising from data breaches in the future. Consumers Union is pushing that one of these bills, already passed in California, be signed into law. Minnesota has already passed legislation that addresses this.

MarketWatch reports:
Under the settlement, which is subject to court approval, TJX will offer three years of credit monitoring and identity theft insurance to customers who returned merchandise without a receipt and to whom the company sent letters reporting that their driver's licenses or other identifying information may have been compromised.

TJX will also reimburse the customers for documented costs of certain license replacements and certain losses from identity theft if identification numbers compromised were the same as their Social Security numbers.

The company will hold a one-time three-day customer appreciation event, in 2008 or later, at which prices will be reduced by 15%.
One thing that concerns me is that the settlement offer states that one of the requirements to receive compensation will be that the identification number compromised has to match their Social Security number.

I guess that TJX and their affiliates don't want to address the rising phenomenon of synthetic identity theft? When synthetic identity theft is committed different parts of a persons identity are crafted to create a new one.

Stephen Coggeshell of ID Analytics was recently quoted as saying:
Five years ago, this crime was hardly seen. Eighty-five to 90 percent of identity fraud is really this synthetic ID fraud, as opposed to the true name identity theft.
Just because the identity and the Social Security number were not compromised together doesn't assure that that the person involved will not become a victim.

This led me to wonder how many Social Security numbers could have been compromised? The answer was right on a FAQ sheet on the TJX site:
We do not receive or store customer social security numbers per se. However, the drivers' license or military ID numbers customers provide us in unreceipted merchandise return transactions are, in some cases and in some states, the same numbers as their social security numbers. We are writing directly to customers we were able to specifically identify whose drivers' license, military or state ID numbers, together with their names and addresses, were found in the information believed compromised and identifying where we believe those numbers may be social security numbers.

Laws have been passed that prohibit the practice of placing Social Security numbers on identification documents.

In the identity theft world -- which is what the concern about this data breach is all about, when a SSN or SIN (in Canada) is compromised -- the criminal compromising the information has all the information necessary to complete a full identity assumption.

In the dark world of Internet forums that sell this information, a complete identity (SSN, or SIN included) is often referred to as a "full." The complete information on a person is simply worth a little more money to the criminals purchasing it.

Retail criminals, who causes billions in losses a year, often refund the merchandise to launder the proceeds of their efforts into cash. This was the very reason -- most retailers implemented databases to track the information of people, who show up at refund desks -- a little too frequently.

With the increasing availability of fake identification and bogus financial instruments -- already being used at retailers to steal merchandise, with a focus on high-value items that are locked up -- it's likely that a lot of the information in these databases isn't completely accurate.

I would guess that the same people, using the bogus financial instruments, purchase the merchandise with them and then head to the refund counter.

So far as the TJX offer to settle this portion of their liability, it still has to be accepted by the court. Of even greater importance is that retailers need to take a hard look at how these refund databases are protected -- and -- whether or not, they are as effective in stopping refund fraud as they used to be.

For more information on the issue of using Social Security numbers on identification documents, the Privacy Rights Clearinghouse has a document, here.

The University of California submitted an interesting document to the Federal Trade Commission on the subject of synthetic identity theft, which can be seen, here.

Last, but not least, Tom Fragala at Truston put together a pretty neat blog post with a lot of references about synthetic identity theft, here.

Saturday, September 08, 2007

SIRAS PI - tracking theft to the source


Graphic demonstration of anti-theft technology courtesy of SIRAS.com.

Criminals, who steal goods, whether with bogus financial instruments, or by more physical means might be in for a little surprise if the merchandise is protected by SIRAS PI.

Last week, SIRAS made this announcement in a press release:

SIRAS.com, the pioneer in Point-Of-Sale Electronic Product Registration used by leading manufacturers and retailers, has announced the nationwide launch of SIRAS P.I., a groundbreaking initiative to aid law enforcement officials in determining whether products they recover are, in fact, stolen, and if so, from where. Piloted by the Mesa, Arizona Police Department, SIRAS’s P.I. (Product Information) Database has already proven to be effective in helping law enforcement officials identify stolen items, report suspicious items, and apprehend and convict thieves. The database will be available, free of charge, to police and law enforcement agencies nationwide.

The way SIRAS works is simple, but effective. It tracks a product by recording the UPC (Universal Product Code) and the product serial number. SIRAS has the capability to determine where merchandise was stolen, whether from a merchant, manufacturer, or individual.

Earlier this year, SIRAS did some testing that revealed a substantial reduction in TV and MP3 player losses on products, where their technology was being used.

If deployed properly at the merchant level -- it could also determine how an item was purchased, and whether or not -- the method of payment used was legitimate. In theory, a merchant could also use the technology to impact credit card chargeback and fraud check losses.

I say "deployed properly" and "in theory" because the information to accomplish this (sales data) belongs to the company using SIRAS technology. Because of this, the capability to track sales information would have to be implemented inside the company. At most larger companies, this information is already tracked and analyzed to prevent and detect dishonest activity.

For years, most high-theft (shrink) merchandise has been secured so a thief can't merely pick it up from a shelf. When high-theft merchandise that was secured is stolen, it's normally because of one of two reasons. It was purchased with a bogus financial instrument, or an insider was involved in the theft.

Other reasons for secured merchandise being stolen might be a theft, directly from the manufacturer, or a theft during the shipping (transport) process. In these instances, if the merchandise was registered at the manufacturer, SIRAS can identify the point of compromise, also.

Technology has made it a lot easier for criminals to obtain and use fraudulent forms of payment. Information being compromised (data breaches) and anonymous places to communicate like Internet chat rooms, have given a lot of common criminals access to bogus financial instruments.

Along with the increased availability of fraudulent forms of payment, obtaining counterfeit identification documents has become fairly easy, and the identity used on them normally belongs to someone else. This has made it easy for a lot of retail criminals to operate as someone else.

Because of these new trends, current systems that record personal information to prevent fraud are becoming less effective than they use to be. I often wonder (no one probably really knows) how much of the information contained in them is incorrect.

In the recent data breach at TJX, one of the systems compromised was their refund database. Stories have circulated recently about the wrong people being pegged as frequent refunders, or bad check writers after their identities were stolen.

Neither one of these situations fosters good will, or trust with customers. Besides that, data breaches are becoming costly. The last I heard TJX has spent approximately $256 million dealing with the breach. With pending litigation, the cost is liable to keep going up.

With SIRAS, using personal information isn't necessary to determine, whether or not, a return is legitimate. SIRAS already has proven to be highly effective in reducing refund fraud without asking for one item of personal information.

An example of how some of the TJX data was used in a retail theft scenario can be seen, here.

Given that criminals that steal merchandise want to turn it into money, two methods are normally used. They either refund it somewhere, or fence it. Auction sites provide an easy and when combined with account-takeover activity (anonymous) venue for criminals to fence merchandise.

In the auction world, seller accounts are taken over all the time. This normally occurs when seller accounts are compromised by a phenomenon known as phishing. Phishing occurs when a person is tricked into giving up their access information after receiving a spam e-mail.

Compromised seller accounts are sold on the Internet the same way financial information is, and there is a trend in DIY (do-it-yourself) phishing kits being sold that enable non-technical criminals to get into the game.

eBay and PayPal are two of the most heavily phished brands. Once these accounts are compromised (taken over), they are used by criminals to fence merchandise and launder the monetary proceeds of their illicit sales.

Another growing trend related to phishing is when malware, also sometimes known as crimeware is used to steal information. The difference here is information is stolen from systems automatically (normally by keylogging software) and social engineering (trickery) is no longer necessary to get people to give up information.

Malware is often picked up by a computer system by clicking on a spam e-mail link, or by visiting a website designed to inject the software on a system. PC World recently did one of the many stories floating around about malware being sold on the Internet in the form of DIY kits.

In the story they wrote:

The global market for criminal malware now operates like a supermarket, complete with special offers and volume discounts, a security company has discovered.

Here again, this capability enables not very technically inclined criminals to get into the game. This has become a growing problem and I expect it to get worse before it gets better.

With the availability of all this personal and financial information, being sold on an economy of scale, current fraud protection systems are routinely being compromised by a lot of criminals.

There is an old saying in the investigations world, which is if you want to solve a crime, the easiest way is to follow the money.

SIRAS takes this one step further by tracking both the merchandise and can track the money ( if programmed to do so by the user). When you do this, the odds are far greater that the true culprit will be identified. They are normally associated with either the money, and or the merchandise.

Since the technology records both physical and UPC information, the database can determine exactly where the merchandise was compromised (stolen). Given that many merchants use digital video systems -- which are capable of storing video footage for a long time, it's also possible to obtain video evidence of the original transaction -- when sales information has been programmed to tie into the technology.

SIRAS has been used by select manufacturers and merchants for several years now -- however a new initiative, SIRAS PI, which was tested with Mesa PD -- makes the database available to law enforcement agencies free of charge.

Law enforcement can access the database either via the Internet, or by telephone. They can also add items to the database when they are reported stolen. If someone later tries to refund the merchandise at a participating retailer, the transaction can be automatically flagged.

Although a lot of fencing now occurs on the Internet, the technology is equally as effective in investigating more traditional property crimes, also. The bottom line is once merchandise is discovered, it can be tracked by SIRAS, if the item has been registered.

Recently, Chris Hansen (MSNBC), did a story about iPod theft. When Apple was approached about tracking the merchandise using Apple's registration database, they decided not to cooperate with MSNBC.

Undaunted by this, MSNBC purchased a bunch of iPods and engineered the registration disc to send them the information when the iPod was registered. They then left the iPods (new in the box) unattended, let them get stolen and tracked them to the crooks once the iPod was registered.

Chris Hansen made an excellent point on how databases can track stolen merchandise -- but in this instance, brand new iPods had to be left in public places to be stolen -- then registered to make the point.

If Apple used SIRAS technology to protect their merchandise -- it would have already been traceable, even if it was stolen from an individual -- who didn't provide the thief with the registration disc. It also would eliminate privacy concerns, which might be why Apple didn't want to cooperate with the MSNBC investigation?

When registering any product, a lot of personal information is normally asked for.

In any event, most criminals of the smarter variety aren't going to provide their personal information in the registration process. Most of them shy away from doing things, which might get them caught.

It would be interesting to have MSNBC, or another investigative news source do the same story with merchandise protected by SIRAS. The story might expose more than people, who stole because of an almost "too good to be true" opportunity was provided to them.

MSNBC iJacking story, here.

This brings up another potential benefit to this technology. Expensive portable electronics and other expensive toys like mountain bikes are stolen from the people who buy them (customers) all the time. Using SIRAS technology might even be a selling point that instills customer trust in the product they are purchasing.

This technology has prevention/investigation applications for corporations, law enforcement agencies and individuals, alike. It also doesn't require using people's personal information, which isn't as effective as it used to be, and is becoming more unpopular all the time.

In my opinion, this technology has the ability to make it a lot harder to get away with stealing merchandise and converting it into money.

Of course, the more it is used, the more effective it will become. Databases have a tendency to do this, or become more useful as they contain more information.

There are a lot of anti-theft/fraud technologies that claim to prevent theft/fraud. Very few of them also claim to be able to go after and hold the criminals committing the fraud/theft personally accountable.

The last I heard, most criminals still fear getting caught!

If you would like more information on the organized trade in counterfeit identification documents, the story of Suad Leija can be seen, here.

Suad's story has been covered extensively in the media, including by Lou Dobbs. Currently, she is writing a book and I keep in touch with her occasionally.

More information about bogus financial instruments can be seen, here and here.

A chronology of data breaches is compiled by the Privacy Rights Clearinghouse, here.

The best source on phishing is the Anti-Phishing Working Group and if you are interested in learning even more about phishing and want to see some totally fake banking sites, Artists Against 419 is another good place to visit.

Last, but not least, if you are interested in learning more about SIRAS PI, you can do so by visiting their site, here.

Monday, May 07, 2007

Is Target's payment card and new refund procedure stopping retail criminal activity?

Will stricter return policies drive Target's customers, elsewhere? Some are saying their new return policy (which will require a receipt for cash returns of $20 or more) -- isn't very customer friendly --and might do just that. Some are also questioning, whether another policy (how they verify plastic transactions) is enabling fraud to occur within their four walls.

So far as the new refund policy, Target's response is that this will affect a very small amount of its customers. Chris Serres, Star Tribune, Minneapolis - St. Paul gives Target's rationale for this:

Target officials said the new limits affect fewer than 5 percent of its customers. Shoppers who have bought products with credit cards, debit cards or checks can still return them without receipts, without having to worry about the new limits.

"While we expect the changes to ... impact a very small number of guests, our goal is to minimize losses regardless of amount," said Amy von Walter, a Target spokeswoman.

Law enforcement officials have a different take on this:

Target's practice of not checking the IDs of credit card holders has made it a target for more sophisticated fraudsters, said Brandon Deshler, an officer with the Edina Police Department and a detective with the Minnesota Financial Crimes Task Force, a state law enforcement agency. "There is a real inconsistency here," he said.

Sophisticated fraudsters are becoming the norm with data breaches, carder forums, and do it yourself (DIY) crime kits being marketed via the Internet.

I keep reading about how identity theft is tied into methamphetamine use, but in reality, it might also be tied into heroin use, or any other narcotic that people get addicted to. Addicts often turn to retail crime to support their habits, also.

Before the Internet made sophisticated fraud pretty easy to accomplish, addicts did a lot of shoplifting (boosting) to support their habits.

As time went on, retailers got smarter. They started locking up high value (shrink) merchandise and tightened up their return policies. To get past this, many retail criminals use fraudulent payment devices, which are pretty easy to obtain.

Organized criminals now make their "cut" selling the information and devices to less sophisticated crooks, who do all the dirty work for them. Deals are made on the Internet with a click of a mouse, and these devices are (normally) shipped from foreign sources, where it is hard to identify the criminals behind it.


Fraudulent devices are ordered in chat rooms, paid for by wire transfer or PayPal, and shipped to these (questionably) sophisticated criminals UPS, or Fedex, worldwide. Sometimes, they are shipped in bulk to one location and then redistributed. This is another method used to make tracking these devices to their original source, difficult.

Because of the growing availability, retail criminals are using
fraudulent payment devices to obtain and then refund merchandise.

If customers using credit cards, debit cards and checks are still allowed to return them without receipts, I'm guessing a lot of refund fraud will still occur.

I wondered how customers, using payment devices (checks, credit cards, debit cards) could get a refund without a receipt? Just to make sure, I called my local Target and told them I lost my receipt from a credit card purchase. I was told to bring my credit card in and they could look up the information.

In light of the many recent data breaches, such as TJX -- where at least 45 million customers were compromised -- this thought scared me. Even if their systems are completely safe (not sure if any really are), does this mean that a dishonest employee could access my information? Employee dishonesty has long been (and still is) a major problem at most businesses.

The best thought out security can be beat by one person with access to it!

One of the systems compromised at TJX was their refund authorization system. Not allowing easy access, or even maintaining personal and financial information is the recommended way to prevent data theft.


Besides that, I often wonder how accurate the data is in some of these refund systems. These days, crooks use a lot of other people's information.

Since Target relies on electronic authorization systems (they don't even require their staff to check ID) on credit/debit card transactions, the law enforcement official quoted above might have a very valid concern.

But this isn't the only time, I read about this concern in the past week.

An article came out from Washington about an enraged identity theft victim, who after realizing no one was doing anything with her case, decided to beat the pavement (investigate), herself. Working with a reporter, she did her own check of retailers and here is what happened at Target (as reported on KOMOTV.com):


We did the same thing at Target. This time, we included wine in our purchase thinking some stores require an ID check when buying alcohol. At no point during our checkout did the Target clerk even ask to see the credit card. The clerk never asked for an identification check.

In a statement, Target says it does not require its clerks to handle or inspected credit cards.
Instead the store relies on an electronic authorization system where the customer swipes their own credit card through a reader."Electronic authorization is faster and more accurate than relying on visual inspection of verification of written signatures," says Brie Heath of Target.

Even with these systems, where a customer swipes their own card, a lot of retailers require that the clerk check identification AND inspect the card on signature transactions. In fact, a lot of pos (point-of-sale) systems prompt the customer and the clerk to do so.

Counterfeiting payment cards has become so easy to do that it's now
done in garages with hardware that can (unfortunately) be bought over the Internet. Granted, identification can also being counterfeited, but at least visual inspection is going to making it a little harder to commit payment (debit/credit) card fraud.

The truth is that electronic verification systems read data, and in the case of debit and credit card data, it's being transferred (counterfeited) all the time.

Many might ask why Target would rely on an electronic system with so much fraud going on out there? One reason might be that when a card is "swiped" (electronically authorized), it is pretty hard for the bank to charge it back to Target.

When this happens, I'm guessing that Target isn't the one taking the loss, the bank does.


Chargebacks are becoming a huge issue, and many merchants (especially e-commerce merchants) are saying they are unfair to them, also. These merchants claim the rules favor the banks, who are passing off the costs of fraud to them. With the recent TJX data breach, and the realization of how expensive information theft has become, we can expect to see more controversy on this issue.

It's sad that businesses seem to be spending more time going after each other than the criminals behind the activity (my emphasis).

We also need to consider the considerable grief, victims go through in this process. Victims can be held liable for losses, have their credit ruined, and are even charged with crimes they didn't commit. Some of these victims are undoubtedly past, present, or future customers.

It's pretty easy for me to understand law enforcement officials and identity theft victims might be a little frustrated with Target's policies.

There is no doubt that the amount of refund and payment device fraud is growing. Businesses do have the right to protect themselves, but passing the financial loss to another business, and ultimately (all of us) does little to stop the problem. In fact, it might be one of the reasons this type of fraud is growing.


It would be unfair to single out Target on these issues. Other retailers need to be looking at them, also. Retailers are sold expensive security technology and too often (my emphasis) find that someone has figured out a way to exploit it.

Systems get defeated by human beings all the time. The best defense against this are other human beings. Removing human interface from the equation makes it easier to commit fraud (my emphasis).

Star Tribune article, here.

KOMOTV.com article about the identity theft victim doing her own investigation,
here.

Thursday, March 22, 2007

SIRAS – Smart technology that protects profit and privacy


Organized retail crime, according to RILA (Retail Industry Leaders Association), is a $34 billion a year problem. A study at the University of Florida conducted by Dr. Richard Hollinger suggests that 9 percent of all refund activity or $16 billion is fraudulent.

At most merchants today, refunds are tracked with personal information. While this was effective 10 years ago, the information in the current databases might not be as accurate as it once was.

Personal and financial information is stolen and sold in a lot of places, most notably over the Internet. A perfect example is the recent compromise of consumer data at TJX stores. This information is turned into fraudulent identification and financial instruments and sold to criminals.

It is likely that criminals can assume multiple identities, using other people’s information to refund merchandise. In fact, payment (credit/debit) card and bad check fraudsters already demonstrate this ability on a daily basis.

With the negative publicity surrounding data breaches and identity theft, honest customers are nervous when asked to surrender their personal details. Recently, privacy groups and Senator Chuck Schumer have been openly critical of current systems, which gather personal information.
A company named SIRAS provides a means to protect an organization’s bottom line and their customer information, also. The way they do it is so simple, it’s brilliant. Instead of tracking personal information, SIRAS tracks the merchandise, itself.

The SIRAS system captures the UPC and serial number of a product at the point-of-sale and creates an electronic receipt. This enables a merchant to determine exactly when and where it was sold AND how it was paid for.

SIRAS can tell when the merchandise was never purchased (stolen), or if it was purchased at another retailer. It also can identify counterfeit merchandise, price switching and altered/counterfeit receipts. Because it ties into a sales transaction, the system could also identify fraudulent forms of payment used to purchase the merchandise, or if the item has been a chargeback issue.

SIRAS makes it pretty hard do a fraudulent refund. Getting series of numbers to match can be extremely difficult, if not almost, impossible.

The data is compiled into customized reporting tools, which can be leveraged to determine risk factors when merchandising products. These tools also have extremely useful applications from an intelligence (analysis) and investigation perspective.

Besides organized retail crime, the largest losses suffered by merchants are caused by internal theft. Fraudulent refunds, “sweetheart returns,” enable dishonest employees to steal cash, or issue credit to payment cards. Like their external counterpart, internal criminals now have to use personal information to prompt a point-of-sale system to issue a refund. Again, this information (which might not be accurate) corrupts a lot of the current databases.

Dishonest employees are going to have a hard time being able to match UPC/serial number to a legitimate sale. This will prevent employees from attempting to commit refund fraud, and should they decide to do so, the custom reporting tools (when used properly) would identify the culprits, with ease.

SIRAS can track and identify retail theft a long way past the refund counter. With its unique ability to track merchandise to a sale, SIRAS can be used to identify merchandise sold in fencing operations (and more likely) via Internet auctions.

In fact, SIRAS has been used to help prove criminal cases, or to obtain search warrants by law enforcement.

The system can also be used to identify counterfeit goods, wherever they might be appear for sale.

Other benefits include being able to better manager warranty programs and in the case of call centers (crucial in e-commerce), it provides their employees with direct access to the original purchase information.

An effective merchandising application, I noted was the ability (via analysis) to identify products that have a high rate of being defect rate, or that aren’t as easy to use, as advertised.

SIRAS has applications that go far beyond fraud at the refund counter.

The system is easily incorporated with patented technology into current point of sale systems and employee training is minimal. Being that it replaces many labor intensive tasks, payroll can be better spent in other areas.

SIRAS applications are beneficial not only to manufacturers and traditional retailers, but the system is equally effective in e-commerce applications.

This technology is already being used by several major retailers and manufacturers. You can view a list of them on their website (listed below).

With privacy becoming a bigger issue all the time, SIRAS provides a smart way to protect assets and not expose customer information. SIRAS makes it harder to commit fraud in a retail environment, while making it easier (customer friendly) to return an item without a paper receipt.

More information about SIRAS and who uses their services can be viewed at:
CNET's story about the TJX data breach can be viewed, here.

Wednesday, March 21, 2007

(Update: TJX data confirmed as used in Florida Case) Is the information being sold in carder forums being used in organized retail crime?

Underground carder forums (selling personal and financial information) are making it too easy to commit financial crimes. Symantec released a report showing that a credit-card number (with verification number) is sold for as little as $1 to $6. Complete information to take over an identity (government ID, social security number, bank account number, date of birth, etc.) costs about $14 to $18.

Here is an example of how this stolen information might be used by criminals. I happened to run across a good example of this in the News-Press (Southwest Florida):
Six people suspected of using stolen credit cards to purchase an estimated $8 million in WAL-MART and Sam’s Club gift cards were arrested in by Gainesville Police in a four-month ongoing investigation, according to a report released Monday by the Florida Department of Law Enforcement.
The bogus credit-cards were being used to purchase high-end electronic merchandise and gift cards.

News-Press story, here.

*Update (3/23/07): An article from InfoWorld is stating that the data used in this scheme is part of the TJX data breach. InfoWorld story, here. It still isn't clear how the culprits obtained the information, or how they, had the information made into counterfeit instruments.

Symantec's report covers all the different methods information is being stolen. One of the more common methods is referred to as phishing. This normally happens when a person clicks on a link from a spam e-mail sending them to a fake site (requesting personal information).

Note that sometimes the fake sites only ask for your personal and financial details (referred to as social-engineering), but more and more, computers are infected with malware when someone is tricked into clicking on a link they shouldn't have.

Malware records people's personal details (automatically) and sends them back to the scammers.

Symantec's press release on their report, here.

If you are wondering why the retail crooks were buying gift cards. Here is a previous post, I did on that subject:

Why Buying Gift Cards on Auction Sites isn't a Good Idea

Wednesday, February 07, 2007

Is tracking fraudulent refund information effective and could it be putting people at risk of becoming an identity theft victim?

The retail industry loses billions of dollars a year to fraudulent refunds.

Fraudulent refunds occur when retail crooks (shoplifters, bad check writers and credit card fraudsters) bring in stolen merchandise to convert into cash. To protect themselves, merchants have developed refund policies, which require that personal information be maintained in a database to identify retail crooks.

I believe the merchants, who came up with this idea, did so with honorable intentions. But is it possible that these systems are easily defeated and themselves might be attacked (hacked) for information they are storing?

The retail security industry has a new buzz word (organized retail crime). If these crooks are organized, my guess is that they are already using fake identification and other people's identities to return merchandise.

Refund data-bases might be full of information from some of the other data-breaches. Other people's information is used to commit a lot of credit/debit card and check fraud. In the case of fraudulent transactions at retailers - the criminals often refund the merchandise they purchase (with bogus financial instruments) to get what they really want, or cash.

And it wouldn't be very hard for them to get bogus information - personal and financial information is for sale in carder forums and fake identification is getting better and easier to obtain all the time.

Another thing to consider is that besides organized retail criminals, another huge loss factor for retailers happens when insiders (dishonest employees) steal from them. Like the external element, a lot of dishonest employees seek to steal cash, and one of the easiest means to do so is to do fraudulent refunds, themselves.

Given the new refund systems, they will have to come up with an identity to accomplish this. The easiest way to do this is to use a customer already in one of their data-bases, or even make up a name.

TJX (a merchant operating under many different names) recently enabled what a lot of experts believe will be the largest data breach to date. One of the databases compromised was their information on all the people, who had refunded merchandise at their stores.

Unfortunately for TJX and the retail industry - it now appears they were storing financial information that they shouldn't have been.

According to reports, TJX was storing payment card (credit/debit card) information they weren't supposed to be in violation of already established PCI data-protection standards. These standards are established by the payment card industry, themselves.

It seems odd to me that in light of all the data breaches, the industry is being allowed to police themselves. I wonder if an unbiased third-party (with no financial incentive) should be taking a look at the problem?

And even if the merchants bring their data protection standards up-to-par for payment cards - will the data being mined in the refund systems receive similar protection?

Guard My Credit File.org recently published a story about Federated requiring SSNs for refunds (courtesy of a blog post and later conversation with George at Fat Pitch Financials).

Apparently George's wife bought some merchandise off one of their websites with a gift card. She decided to return the jeans (for credit back to her gift-card) and when she went into a Federated store (Macys), she was asked for her driver's license and SSN to complete the transaction.

Please note, she had her gift-card and the receipt for her purchase. George eventually complained loudly enough that a manager relented and allowed the return without a SSN.

My guess is that criminals are furnishing fake SSNs (which are hard to verify) and only the honest customers are providing real ones.

Story, here.

As I stated earlier, tracking refund data was probably a good idea when it was first conceived, but I wonder how effective it is today? The data itself could be posing risks to anyone honest enough to give their real information, and criminals are likely using other people's information.

Sadly enough, recent data- breaches indicate that this (personal information) probably isn't very well protected. It's also sad that after spending millions of dollars to protect themselves with refund databases, the retailers have a product that might not be very effective and could become a customer trust issue.

There needs to be a better way to protect merchants and their customers from theft. Customers and retailers are both being victimized by what seems to be a growing problem.

Here is another post, I wrote on this same issue:

Are Retail Refunds Violating Customer Privacy