Monday, February 12, 2007

Trooper discovers a lot of counterfeit instruments used to commit identity theft/financial fraud

I recently did two posts:

Is tracking fraudulent refund information effective and could it be putting people at risk of becoming an identity theft victim?

Paper weapons (counterfeit documents) enable more serious crimes than illegal immigration and identity theft

I wrote both of these to show how easy criminals seem to be getting around existing systems designed to stop them.

Here is a rather obscure story that illustrates how widespread counterfeit identification and the use of other people's identities to commit crime might be.

Santiago Esparza of the Detroit News reports:

Troopers with the Michigan State Police Richmond Post stopped a man and a woman on eastbound Interstate 94 near Joy Road and discovered much more than two people not wearing seat belts.

The troopers found dozens of driver's licenses, social security cards, credit cards, debit cards and check cards. The troopers also found checks, check registers and other items that could be used to purchase items with fake identification, according to a Michigan State Police press release issued today.

Santiago's story, here.

I doubt if the two people were using their own identities to purchase, or return merchandise. IT also doesn't look like they had a problem getting a lot of other people's information to use for illicit purposes.

Sunday, February 11, 2007

Information Week exposes the Internet Underworld

With the TJX data breach fresh in the news, Larry Greenemeier and J. Nicholas Hoover (Information Week) have written one of the most informative articles to date on the hacker underworld.

They are warning us that:

Hacking isn't a kid's game anymore. It's big business. Online black markets are flush with stolen credit card data, driver's license numbers, and malware, the programs that let hackers exploit the security weaknesses of commercial software. Cybercriminals have become an organized bunch; they use peer-to-peer payment systems just like they're buying and selling on eBay, and they're not afraid to work together.

The article covers the mysterious carder forums - where other people's financial information is bought and sold and how the information is paid for (wire transfer, PayPal, e-gold). It also shows how they avoid detection by anti-money laundering laws by what is know as "layering" (splitting up large sums into smaller ones).

There is also interesting information about the shady world where malware (crimeware) is being produced to steal the data.

Information Week article, here.

In case you were interested, here is how much (roughly) this information is being sold for:

The Black Market

$980-$4,900
Trojan program to steal online account information

$490
Credit card number with PIN

$78-$294
Billing data, including account number, address, Social Security number, home address, and birth date

$147
Driver's license

$147
Birth certificate

$98
Social Security card

$6-$24
Credit card number with security code and expiration date

$6PayPal
account logon and password

Data: Trend Micro

The conclusion of the article isn't new, which is that the business world needs to protect it's data better and law enforcement faces obstacles in going after borderless crimes. Until laws are enacted, which allow the problem to be solved, it will likely flourish and grow.

Blaming FEMA for the fraud in Katrina isn't going to solve the problem

There is no doubt about it - the Katrina and Rita debacle - was NOT a shining moment in our nation's history. Fifteen months later as New Orleans prepares to celebrate "Fat Tuesday" (Mardi Gras), more allegations of fraud and mismanagement are coming to light.

Two reporters (Michelle Roberts and Frank Bass) of the AP wrote an interesting article about how FEMA now wants $300 million back in claims paid for households that didn't exist, according to official pre-hurricane census figures.

Even more interesting is that they did their own analysis using the federal Freedom of Information Act, which deducts that a lot more than $300 million might come out in the wash before all is said and done.

Here is what they said in their article:
But an Associated Press analysis of government data obtained under the federal Freedom of Information Act suggests the government might not have been careful enough with its checkbook as it gave out nearly $5.3 billion in aid to storm victims. The analysis found the government regularly gave money to more homes in some neighborhoods than the number of homes that actually existed.

The pattern was repeated in nearly 100 neighborhoods damaged by the hurricanes. At least 162,750 homes that didn't exist before the storms may have received a total of more than $1 billion in improper or illegal payments, the AP found.

Full story (ABC news version), here.

While there is no doubt a big problem exists, we need to put the overall issues in perspective and I'm not sure FEMA is entirely to blame.

David Garratt, FEMA's deputy director is saying that officials were in a "no win" situation. And while, I'm not here to defend FEMA, he probably has a valid point.

When the federal government got involved, fraud artists from all over the world were setting their sights on what they saw as a "lucrative opportunity."

A lot of the fraud that occurred didn't necessarily come from the areas affected by the hurricane.

Couple this, with a lot of pressure to right all the initial blunders in the disaster, which most of us were watching "live," and mistakes were made.

Sadly enough, fraud prevention systems in place, were deemed to cumbersome and disabled. Again, there was a lot of pressure (rightfully so) to take swift action to help a lot of people, who were in harm's way.

We can blame FEMA all we want, but the fact is that fraud is growing at a rapid rate, and the federal government isn't the only one with inadequate fraud prevention systems.

For example, in Southern California (pretty far from Louisiana), there was another interesting article about the taxpayers footing a $1.5 billion a year bill for fraud, here.

And while there seems to be a lot of government fraud, fraud in the private sector is growing by leaps and bounds, also. There is no doubt that identity theft (another growing problem) helped fuel the fraud in the hurricane disasters.

There is a lot of evidence to suggest that much of this fraud is enabled by information that has been data-mined on all of us, which isn't protected very well. Some suggest that technology and the information sector, which make a lot of money selling their wares are the root cause of all of this.

Unfortunately, those committing fraud are too keenly aware of this.

Blaming FEMA is unlikely to correct the overall problem. And if their fraud prevention systems were inadequate, perhaps we should be looking at who sold them the faulty systems?

Perhaps, when history is written, the Katrina disaster is a warning of the looming disaster we all face if we don't stop viewing fraud as a "victimless crime."

Fifteen months later (as Mari Gras approaches), there are still a lot of people suffering from the hurricane disasters.

If you would like to learn more about this, Margaret Saizan's site (Beyond Katrina) is a great resource.

I wonder how much good the money would have done for the true victims if it hadn't been stolen from underneath them?

Wednesday, February 07, 2007

Is tracking fraudulent refund information effective and could it be putting people at risk of becoming an identity theft victim?

The retail industry loses billions of dollars a year to fraudulent refunds.

Fraudulent refunds occur when retail crooks (shoplifters, bad check writers and credit card fraudsters) bring in stolen merchandise to convert into cash. To protect themselves, merchants have developed refund policies, which require that personal information be maintained in a database to identify retail crooks.

I believe the merchants, who came up with this idea, did so with honorable intentions. But is it possible that these systems are easily defeated and themselves might be attacked (hacked) for information they are storing?

The retail security industry has a new buzz word (organized retail crime). If these crooks are organized, my guess is that they are already using fake identification and other people's identities to return merchandise.

Refund data-bases might be full of information from some of the other data-breaches. Other people's information is used to commit a lot of credit/debit card and check fraud. In the case of fraudulent transactions at retailers - the criminals often refund the merchandise they purchase (with bogus financial instruments) to get what they really want, or cash.

And it wouldn't be very hard for them to get bogus information - personal and financial information is for sale in carder forums and fake identification is getting better and easier to obtain all the time.

Another thing to consider is that besides organized retail criminals, another huge loss factor for retailers happens when insiders (dishonest employees) steal from them. Like the external element, a lot of dishonest employees seek to steal cash, and one of the easiest means to do so is to do fraudulent refunds, themselves.

Given the new refund systems, they will have to come up with an identity to accomplish this. The easiest way to do this is to use a customer already in one of their data-bases, or even make up a name.

TJX (a merchant operating under many different names) recently enabled what a lot of experts believe will be the largest data breach to date. One of the databases compromised was their information on all the people, who had refunded merchandise at their stores.

Unfortunately for TJX and the retail industry - it now appears they were storing financial information that they shouldn't have been.

According to reports, TJX was storing payment card (credit/debit card) information they weren't supposed to be in violation of already established PCI data-protection standards. These standards are established by the payment card industry, themselves.

It seems odd to me that in light of all the data breaches, the industry is being allowed to police themselves. I wonder if an unbiased third-party (with no financial incentive) should be taking a look at the problem?

And even if the merchants bring their data protection standards up-to-par for payment cards - will the data being mined in the refund systems receive similar protection?

Guard My Credit File.org recently published a story about Federated requiring SSNs for refunds (courtesy of a blog post and later conversation with George at Fat Pitch Financials).

Apparently George's wife bought some merchandise off one of their websites with a gift card. She decided to return the jeans (for credit back to her gift-card) and when she went into a Federated store (Macys), she was asked for her driver's license and SSN to complete the transaction.

Please note, she had her gift-card and the receipt for her purchase. George eventually complained loudly enough that a manager relented and allowed the return without a SSN.

My guess is that criminals are furnishing fake SSNs (which are hard to verify) and only the honest customers are providing real ones.

Story, here.

As I stated earlier, tracking refund data was probably a good idea when it was first conceived, but I wonder how effective it is today? The data itself could be posing risks to anyone honest enough to give their real information, and criminals are likely using other people's information.

Sadly enough, recent data- breaches indicate that this (personal information) probably isn't very well protected. It's also sad that after spending millions of dollars to protect themselves with refund databases, the retailers have a product that might not be very effective and could become a customer trust issue.

There needs to be a better way to protect merchants and their customers from theft. Customers and retailers are both being victimized by what seems to be a growing problem.

Here is another post, I wrote on this same issue:

Are Retail Refunds Violating Customer Privacy