Has anyone besides me noticed that when data breaches are reported, we see an official statement that the information hasn't been used by identity thieves?
After thinking on that one for awhile, it makes sense that criminals would stop using the information from a data breach after it has been reported.
So far as information used before the breach is discovered, it's pretty hard to prove where the information came from in an identity theft case. With so much compromised information out there, it's nearly impossible to figure out where the point-of-compromise is in any individual case.
When a data breach occurs, a lot of accounts are closed down and everyone who has been compromised runs out and checks their credit reports. Most of the time, free identity theft monitoring is made available to those who have been breached, also.
My guess is that once the stolen information is made public, it's probably dangerous to use. At the very least, it probably doesn't hold the same profit value that it had when no one knew it had been stolen.
For the past week, the news has been awash with the year end statistics on data breaches. By all the recent news accounts, 2007 was a record year.
While reporting data breaches is painful and costly, reporting them probably makes the information a lot harder to exploit for criminal purposes.
Although 2007 was a record number for reported data breaches, very few of criminals stealing the information got caught. Organizations losing the information are starting to be held accountable, but it would be nice to see more of criminals stealing the information brought to justice.
Another thing to consider is that data breaches aren't putting organizations out of business. True, they are costly, but in the end the cost is normally passed on to everyone using their services.
In the end, we are all paying for the cost of fixing data breaches.
And while a record number of data breaches were reported, there would have to be some that no one (except the criminals) know about.
My guess is that there is a lot information theft that is never detected. I would also surmise that this is considered the most valuable information being sold and used by criminals.
Compromised information is normally most effective when the person who it belongs to doesn't know it's being used.
Until we impact both sides of the equation -- the people losing information and punishing the people stealing it -- we are probably going to see news reports reflecting record statistics on the amount of data breaches occurring.
To do this, we need to focus more resources on catching the people stealing the information and enact laws that make it hurt when they get caught.
The last statistic I saw was that less than 1 percent of them get caught, and if they do, they normally get a slap on the wrist. A lot of the reasons for this are insufficient resources to investigate fraud and a lot of cases that are never reported by both organizations and individuals.
AP article (courtesy of the Washington Post) on 2007 data breach trends, here.
Update: Dissent from the Chronicles of Dissent and PogoWasRight left a good comment on this post pointing out that a lot of people did get caught this year. He is right and I did posts on a number of them.
The people out there catching the crooks stealing the data would be able to do a lot more if they were given more resources!
The Chronicles of Dissent has an excellent article on this subject that I highly recommend to anyone interested in the phenomenon of data breaches, here.
Tuesday, January 01, 2008
Saturday, December 29, 2007
Will you be the next person arrested after a criminal borrows your identity?
With new Social Security verification laws on the horizon, up to 20 million illegal aliens are probably will have to come up with a legitimate identity in order to remain employed.
Up until now, anyone has been able to make up a number and pass it off with false identification. DHS (Department of Homeland Security) was supposed to begin going after businesses that employed people with "no match social security numbers" in September, but a law suit has temporarily blocked them from implementing the process.
Interestingly enough, one of the arguments is that Social Security records aren't accurate enough to ensure mistakes won't be made. This is probably a "no brainer" defense with all the fraud that exists with social security numbers.
Given that a lot of illegal immigrants look Hispanic, a lot of them will probably seek out legitimate identities of U.S. citizens with Hispanic surnames.
Hidden within the camoflauge that illegal immigration creates is a lot of criminal activity. When another person's identity is used to commit a crime, there is a potential that they are going to face more than financial problems after becoming a victim.
Here is a scary story -- possibly a premonition of things to come -- of a senior U.S. citizen, who obviously had his identity stolen by a criminal. The story also reveal why relying on social security numbers to identify people might lead to mistakes being made.
Eloisa Ruano Gonzalez of the Yakima Herald-Republic wrote:
Of course, Hispanic identities aren't the only ones used by criminals. In fact, there are more and more reports of innocent people being charged with crimes after a criminal assumes their identity, commits crimes and disappears into the mist after making bail or being released because the jail is full.
The issue of people wrongfully getting arrested because they are suspected of illegal immigration is probably only one small part of the overall problem.
Stealing personal and financial information and putting it on counterfeit documents has become an organized activity. I was recently in the Mission District of the sanctuary city of San Francisco and full sets were being offered, along with a variety of drugs for as little as $200.00. A full set is normally a drivers license, Social Security and green card.
Please note, I've personally seen this activity in other cities besides San Francisco. It's pretty much out in the open and little to nothing seems to be done about it.
Suad Leija -- the stepdaughter of the "Jefe" of an organized counterfeiting cartel --recently provided evidence to the government that counterfeiting documents is an extremely organized enterprise, which operates across the entire United States.
One of the more ironic things Suad was able to show the government was proof of her Uncle serving a prison sentence in Texas under an assumed name.
There is also considerable evidence that hackers have already stolen millions (billions?) of people's information and sell it pretty openly in anonymous Internet venues.
Put these two organized activities together and they will likely easily defeat any legislation requiring Social Security numbers to match.
I started this post with an observation about Hispanic identities being targeted, but the truth of the matter is that the 20 million or so illegal immigrants seeking legitimate identities is only one small part of a bigger problem. Even if the problem were simply related to illegal immigration -- people of Hispanic origin aren't the only ones crossing our borders illegally.
Figuring out exactly what country an illegal immigrant came from is difficult. Most of them aren't likely to reveal very many personal details. I was able to find a rather outdated study from DHS.gov that reveal some old statistics on the matter:
Even with NATO having boots on the ground in Afghanistan, opium production is at an all time high. Most of this is allegedly being bought by the Taliban, who now seem to operate pretty freely from the tribal areas in Pakistan.
Criminals trafficking narcotics aren't the only ones using false identities. In fact, more and more, the use of false (other people's) identities is being used to facilitate all kinds of criminal activity.
Identity theft may very become the great facilitator (enabler) of more and more crime. If criminals are able to get away with using someone else's identity, we are going to see a lot of more people victimized.
As long as we continue to consider identity theft a "low priority issue," it will continue to grow and multiply like a cancer.
The bottom line is that until we start addressing the factors that make enable stealing and using information too easy, we aren't going to fix the problem.
Doing this is going to take the cooperation of everyone from the average citizen to executive types in major corporations and our leaders in government.
Yakima Herald-Republic story, here.
Up until now, anyone has been able to make up a number and pass it off with false identification. DHS (Department of Homeland Security) was supposed to begin going after businesses that employed people with "no match social security numbers" in September, but a law suit has temporarily blocked them from implementing the process.
Interestingly enough, one of the arguments is that Social Security records aren't accurate enough to ensure mistakes won't be made. This is probably a "no brainer" defense with all the fraud that exists with social security numbers.
Given that a lot of illegal immigrants look Hispanic, a lot of them will probably seek out legitimate identities of U.S. citizens with Hispanic surnames.
Hidden within the camoflauge that illegal immigration creates is a lot of criminal activity. When another person's identity is used to commit a crime, there is a potential that they are going to face more than financial problems after becoming a victim.
Here is a scary story -- possibly a premonition of things to come -- of a senior U.S. citizen, who obviously had his identity stolen by a criminal. The story also reveal why relying on social security numbers to identify people might lead to mistakes being made.
Eloisa Ruano Gonzalez of the Yakima Herald-Republic wrote:
It seemed like a bad dream when 72-year-old retiree Rafael "Ralph" Franco woke up to a loud pounding on his front door, opened it, and found four federal agents waiting to seize him.
The longtime Yakima resident was arrested about 6 a.m. on Nov. 28 at his South Second Street apartment. Immigration officers believed that Franco, a U.S. citizen, was an undocumented immigrant convicted of several alcohol- and weapon-related crimes.
Of course, Hispanic identities aren't the only ones used by criminals. In fact, there are more and more reports of innocent people being charged with crimes after a criminal assumes their identity, commits crimes and disappears into the mist after making bail or being released because the jail is full.
The issue of people wrongfully getting arrested because they are suspected of illegal immigration is probably only one small part of the overall problem.
Stealing personal and financial information and putting it on counterfeit documents has become an organized activity. I was recently in the Mission District of the sanctuary city of San Francisco and full sets were being offered, along with a variety of drugs for as little as $200.00. A full set is normally a drivers license, Social Security and green card.
Please note, I've personally seen this activity in other cities besides San Francisco. It's pretty much out in the open and little to nothing seems to be done about it.
Suad Leija -- the stepdaughter of the "Jefe" of an organized counterfeiting cartel --recently provided evidence to the government that counterfeiting documents is an extremely organized enterprise, which operates across the entire United States.
One of the more ironic things Suad was able to show the government was proof of her Uncle serving a prison sentence in Texas under an assumed name.
There is also considerable evidence that hackers have already stolen millions (billions?) of people's information and sell it pretty openly in anonymous Internet venues.
Put these two organized activities together and they will likely easily defeat any legislation requiring Social Security numbers to match.
I started this post with an observation about Hispanic identities being targeted, but the truth of the matter is that the 20 million or so illegal immigrants seeking legitimate identities is only one small part of a bigger problem. Even if the problem were simply related to illegal immigration -- people of Hispanic origin aren't the only ones crossing our borders illegally.
Figuring out exactly what country an illegal immigrant came from is difficult. Most of them aren't likely to reveal very many personal details. I was able to find a rather outdated study from DHS.gov that reveal some old statistics on the matter:
In October 1996, 15 countries were each the source of 40,000 or more undocumented immigrants (See Table 1). The top five countries are geographically close to the United States--Mexico, El Salvador, Guatemala, Canada, and Haiti. Of the top 15 countries, only the Philippines, Poland, and Pakistan are outside the Western Hemisphere. The estimated undocumented population from Poland has declined by more than 25 percent, from 95,000 to 70,000, since 1988, possibly reflecting changed conditions in that country over the last several years.Sara Carter of the Washington Times did an article in August about a report she saw from the DEA (Drug Enforcement Administration) that people of Middle Eastern/South Asian descent were posing as Hispanics. The article alleged that a partnership was being formed by something they have in common, or trafficking narcotics.
Even with NATO having boots on the ground in Afghanistan, opium production is at an all time high. Most of this is allegedly being bought by the Taliban, who now seem to operate pretty freely from the tribal areas in Pakistan.
Criminals trafficking narcotics aren't the only ones using false identities. In fact, more and more, the use of false (other people's) identities is being used to facilitate all kinds of criminal activity.
Identity theft may very become the great facilitator (enabler) of more and more crime. If criminals are able to get away with using someone else's identity, we are going to see a lot of more people victimized.
As long as we continue to consider identity theft a "low priority issue," it will continue to grow and multiply like a cancer.
The bottom line is that until we start addressing the factors that make enable stealing and using information too easy, we aren't going to fix the problem.
Doing this is going to take the cooperation of everyone from the average citizen to executive types in major corporations and our leaders in government.
Yakima Herald-Republic story, here.
Thursday, December 27, 2007
Symantec awarded $21 million award against Chinese Software Pirates
On Christmas Eve, Symantec announced a legal victory against Chinese pirates selling their cloned software at super cheap prices.
Please note, I stole the super cheap description from Symantec's video called, The 12 days of Christmas Spam." The super cheap tag can either refer to price, or the quality of counterfeit software (personal thought).
From the press release:
It appears that this particular case involved pirated software being made to appear as if it was the real deal. According to industry experts, the counterfeiting problem has increased 10,000 percent in recent history.
The software industry alone estimates it loses $40 billion a year because of pirated software. I wonder how many jobs this equates to?
Pirated (super cheap software) is also hawked via the millions (billions?) of spam e-mails attacking our in boxes in record amounts. Recently, Symantec issued a report based on the spam data they monitor revealing that over the current holiday season 71percent of all e-mail sent is spam.
Counterfeit software also can contain malware (malicious software), which can lead to your system becoming a zombie (part of a botnet to facilitate more spam) and even steal your personal and financial details. These details are then used to steal money either from you directly, or to steal money from financial institutions.
I'm sometimes amazed how a lot of current criminal activity ties in together via the digital world. All the average person needs to do is to watch all the spam messages they get and consider all the different schemes that are behind them. The schemes are nothing new, but the digital age has enabled criminals to reach out to more people than ever before.
Either this is occurring naturally, or someone pretty organized people are running operations along the lines of major corporations?
Besides the more personal dangers of buying pirated software, there is a lot of evidence the activity is making a lot of money for organized crime, rogue governments and terrorist groups, alike.
Press release from Symantec, here.
Please note, I stole the super cheap description from Symantec's video called, The 12 days of Christmas Spam." The super cheap tag can either refer to price, or the quality of counterfeit software (personal thought).
From the press release:
Symantec Corp. (NASDAQ: SYMC) today announced that it was awarded $21 million in damages against a large network of distributors selling counterfeit Symantec software.The investigation conducted by Symantec in collusion with the FBI and Chinese authorities also led to some criminal charges being filed in China.
The judgments were handed down by the United States District Court for the Central District of California in Los Angeles, CA in favor of Symantec against ANYI, SILI Inc., Mark Ma, Mike Lee, John Zhang, Yee Sha, and related defendants.
"Our customers are the real winners as a result of this case," said Scott Minden, director, Symantec Legal department. "A judgment like this is a crippling blow against these particular syndicates and will drive them even further underground, making it more difficult for them to sell directly to unsuspecting users. It complicates their ability to operate behind the guise as legitimate businesses."
It appears that this particular case involved pirated software being made to appear as if it was the real deal. According to industry experts, the counterfeiting problem has increased 10,000 percent in recent history.
The software industry alone estimates it loses $40 billion a year because of pirated software. I wonder how many jobs this equates to?
Pirated (super cheap software) is also hawked via the millions (billions?) of spam e-mails attacking our in boxes in record amounts. Recently, Symantec issued a report based on the spam data they monitor revealing that over the current holiday season 71percent of all e-mail sent is spam.
Counterfeit software also can contain malware (malicious software), which can lead to your system becoming a zombie (part of a botnet to facilitate more spam) and even steal your personal and financial details. These details are then used to steal money either from you directly, or to steal money from financial institutions.
I'm sometimes amazed how a lot of current criminal activity ties in together via the digital world. All the average person needs to do is to watch all the spam messages they get and consider all the different schemes that are behind them. The schemes are nothing new, but the digital age has enabled criminals to reach out to more people than ever before.
Either this is occurring naturally, or someone pretty organized people are running operations along the lines of major corporations?
Besides the more personal dangers of buying pirated software, there is a lot of evidence the activity is making a lot of money for organized crime, rogue governments and terrorist groups, alike.
Press release from Symantec, here.
Tuesday, December 25, 2007
Storm Worm bot-herders use scantily clad women in Santa attire to recruit zombies!
Here is a warning from Dancho Danchev about a site that might leave your computer with a worm.
The site invites a person to watch a bunch of scantily clad women in Santa attire for "free."
From the Mindstreams of Information blog:
In case you are less than technically astute (a lot of us are) the storm worm has been around for awhile. Wikipedia offers a good explanation of how it will trash a Windows system, here.
Downloading it normally leads to your computer becoming a spam spewing zombie controlled by a bot-herder. Of course, becoming infected also poses certain information theft risks, also.
Full post from Dancho, here.

(Screen shot courtesy of the Mindstreams of Information blog)
Update:
Found some more information on this on the SANS Internet Storm Center, which can be seen, here.
And apparently some splogs have been set up on blogspot to support this current storm on the Internet:
Also reported SANS Internet Report Center, here.
The site invites a person to watch a bunch of scantily clad women in Santa attire for "free."
From the Mindstreams of Information blog:
Stormy Wormy is back in the game on the top of Xmas eve, enticing the end users with a special Xmas strip show for those who dare to download the binary. The domain merrychristmasdude.com is logically in a fast-flux, here are some more details :
Administrative, Technical Contact
Contact Name: John A Cortas
Contact Organization: John A Cortas
Contact Street1: Green st 322, fl.10
Contact City: Toronto
Contact Postal Code: 12345
Contact Country: CA
Contact Phone: +1 435 2312633
Contact E-mail: cortas2008 @ yahoo.com
In case you are less than technically astute (a lot of us are) the storm worm has been around for awhile. Wikipedia offers a good explanation of how it will trash a Windows system, here.
Downloading it normally leads to your computer becoming a spam spewing zombie controlled by a bot-herder. Of course, becoming infected also poses certain information theft risks, also.
Full post from Dancho, here.

(Screen shot courtesy of the Mindstreams of Information blog)
Update:
Found some more information on this on the SANS Internet Storm Center, which can be seen, here.
And apparently some splogs have been set up on blogspot to support this current storm on the Internet:
If you google for merrychristmasdude.com you'll see a number of spam blogs set up with that domain in their body and directing traffic to siski.cn (take a look for that in your proxy logs while you're at it.)IT also appears that the hackers behind this are moving on to New Years lures and a new domain.
Visiting skiski.cn will redirect you over to shockbabetv.com and attempt to install a fake video codec, which itself appears to be a downloader to deliver more coal to your stocking.
Shortly before 1600 GMT 25-DEC-2007 we got a report indicating that the Storm Botnet was sending out another wave of attempts to enlist new members. This version is a New Years-themed e-card directing victims to "uhave post card.com." (spaces inserted to break the URL) NOTE: Please do not blindly go to this URL -- there is malware behind it.
Also reported SANS Internet Report Center, here.
Labels:
bot-herders,
botnets,
crimeware,
hacking,
identity theft,
malware,
storm worm
Subscribe to:
Posts (Atom)
