Saturday, January 28, 2006

Government Warns Corporate America to Protect Customer Data

There have been a record amount of data breaches in the past couple of years. Millions of people have had their personal information compromised. It only makes sense that the government (who are supposed to protect the people) are looking into the reasons why it occurred.

The FTC has determined that Consumer data broker (Choice Point) failed to protect the information of 163,000 people.

In the FTC press release it states:

"At Least 800 Cases of Identity Theft Arose From Company’s Data Breach.

Consumer data broker ChoicePoint, Inc., which last year acknowledged that the personal financial records of more than 163,000 consumers in its database had been compromised, will pay $10 million in civil penalties and $5 million in consumer redress to settle Federal Trade Commission charges that its security and record-handling procedures violated consumers’ privacy rights and federal laws. The settlement requires ChoicePoint to implement new procedures to ensure that it provides consumer reports only to legitimate businesses for lawful purposes, to establish and maintain a comprehensive information security program, and to obtain audits by an independent third-party security professional every other year until 2026."

“The message to ChoicePoint and others should be clear: Consumers’ private data must be protected from thieves,” said Deborah Platt Majoras, Chairman of the FTC. “Data security is critical to consumers, and protecting it is a priority for the FTC, as it should be to every business in America.”

Here is the full press release, Choicepoint Settles Data Security Breach Charges; to Pay $10 Million in Civil Penalties, $5 ....

For years, corporations (notably the credit bureaus) have made billions off of selling our information. Here is a message that failing to take security seriously in their quest for profit may cost them dearly at a later date.

For all of us little people, you can now stop (slow down) information brokers from getting your personal information at OptOutPrescreen.com. By "opting out" the credit bureaus can no longer sell your personal data.

Chase Customers Being Phished?

This e-mail was discovered floating around yesterday. When I reported it to Chase, a person in their security department admitted to me that they already knew about it.

If you read below the mail directs you to a site, which asks for your login information and password. This is something no bank will do.

This appears to be a phishing attack directed towards Chase customers to steal their personal and financial information. Phishing is becoming one of the main ways personal and financial information is stolen, which makes people victims of identity theft.

Here is a copy of the e-mail, note I have disabled the link and I wouldn't recommend trying to look at it. There is no telling what malicious software (malware), also know as scumware someone could get if they weren't properly protected.

Subject: CHASE MANHATTAN BANK
From: "Chase Team"

Date: Fri, 27 Jan 2006 10:13:10 -0600 (CST)

Dear Chase Member,

Your account has been randomly flagged in our system as a part of our routine security measures. This is a must to ensure that only you have access and use of your Chase account and to ensure a safe Chase experience. We require all flagged accounts to v erify their information on file with us. To verify your Information at this time, please visit our secure server webform by clicking the hyperlink below:

xxxx//www.chase.com/cgi-bin/webscr?cmd= login

(https disabled for safety reasons)

Thank you for using Chase Manhattan Bank!The Chase Manhattan Bank Team
--------------------------------------------------------------------------------
Please do not reply to this e-mail. Mail sent to this address cannot be answered. For assistance, log in to your Chase account and choose the "Help" link in the footer of any page.

To receive email notifications in plain text instead of HTML, update your preferences here.

Chase Email ID PP478

This e-mail also made it past the Spam Filter of the person, who received it.

I've sent this into a couple of the security labs for analysis. Since Chase confirmed to me they knew about it and no one will ever solicit anyone for their log in information and password via a e-mail, I decided to send this out.

My question is if Chase knows about it, what are they doing to warn their customers?

Here is an excellent resource from the Anti Phishing Working Group (APWG) on how to avoid being phished: How to Avoid Phishing Scams.

Thursday, January 26, 2006

Borderless is the Future of Fighting Cyber Crime

Robert S. Mueller, III Director, Federal Bureau of Investigation gave a speech at the U.S. Chamber of Commerce in Washington, D.C. on January 19, 2006.

He made some interesting comments, which make a lot of sense to me.

"Turning from the transformation of the FBI in the wake of September 11 to threats to our national security and partnerships. When the FBI was established 97 years ago, it was because crime had begun to cross state lines. Today, criminal activity not only crosses state lines, it traverses international boundaries with the click of a mouse.

"Like your businesses, law enforcement has also been affected by globalization. While technology and travel have made the world smaller, crime is more diverse than ever before—from terrorism to telemarketing fraud to the trafficking of human beings."

Here is the entire speech: Director Mueller’s speech.

Here are some great resources found on the Federal Bureau of Investigation (FBI)'s site for corporations and good citizens to share information in the fight against borderless criminal activity.

Submit tips about crimes that may impact your company and report cyber attacks and scams through the Internet Crime Complaint Center;

Learn how to join
InfraGard, a joint FBI and private sector initiative that battles cyber crimes and other threats through information sharing;

Get details on how to protect your business from
economic espionage and receive unclassified national security threat information through our Awareness of National Security Issues and Response program;

Browse our
Be Crime Smart website, which has a full range of tips and suggestions for protecting your business from fraud, workplace violence, and other threats;

Read about how our
Anti-Piracy Warning Seal can help prevent copyright theft on music recordings, movies, software, and more;

Learn about our
criminal history checks for employment and licensing; and

Find out
how to do business with the FBI.

There is no doubt that with borderless crime, the solution is teamwork and breaking down barriers. This is a good example of how this is happening AND the result will be a better society for us all.

Hatch Fails to Survive Court

This just came out from the Associated Press (Ray Henry):

"Richard Hatch, who won $1 million in the debut season of the reality show "Survivor," was found guilty Wednesday of failing to pay taxes on his winnings and taken straight to jail.
Hatch remained calm as the court clerk read the verdict. He waved goodbye to family members, then was handcuffed and taken into custody after U.S. District Judge Ernest Torres said he was a potential flight risk.

The charges carry up to 13 years in prison. Torres said he expected a sentence of between 33 months and 41 months, but it could be longer because prosecutors accuse Hatch of committing perjury during his testimony. Sentencing was scheduled for April 28.

Hatch, 44, was also convicted of evading taxes on $327,000 he earned as co-host of a Boston radio show and $28,000 in rent on property he owned."

It never ceases to amaze me when someone, who comes into, or already has a lot of money is caught cheating. Perhaps, Money is the "root of all evil."

What a shame for someone, who seemed to have a good thing going.

For another version of the story on E Online, go to:

Jurors Extinguish Richard Hatch's Torch

You can also view the story from the AP by clicking on the title of this post.