Friday, November 13, 2009

arstechnica tips on protecting ones identity

arstechnica has posted 5 reminder tips on how to protect yourself from identity theft:
1. protect against spyware/malware
2. fraud alerts
3. Google the kids
4. medical identity
5. social networking
http://arstechnica.com/security/news/2009/09/five-steps-to-protect-yourself-from-identity-theft.ars

Remember, most identity theft is actually done through physical means but that doesn't mean you should leave your electronic door wide open for them. Make sure to always have up to date virus protection & run periodic scans on your computer for bad software that might unknowingly be on your computer. All of the necessary software can be found on the net for free so there is no excuse.

Police arrest victim after DNA database linked ID thief to victim

An Oregon woman was recently held overnight after warrants had been issued for her arrest. It seems that various law enforcement agencies across the country had incorrect data entered into them due to a Florida woman using the Oregon womans identity to commit various crimes including prostitution & theft. In some cases, the victims DNA & photo had been linked with the thiefs causing greater confusion. Click the link below to read the whole story.
http://www.katu.com/news/local/69946642.html

This problem began when the Oregon womans purse became lost 5 years ago. She had taken the precautionary measure (at the time) of cancelling her credit cards & getting new identification cards but that did little good.

Tuesday, November 3, 2009

FTC Extends Enforcement Deadline for Identity Theft Red Flags Rule

The FACTA Red Flags compliance deadline has been delayed again, this time for 7 months until June 1, 2010.

At the request of Members of Congress, the Federal Trade Commission is delaying enforcement of the “Red Flags” Rule until June 1, 2010, for financial institutions and creditors subject to enforcement by the FTC.
http://www2.ftc.gov/opa/2009/10/redflags.shtm

Bank Employee Charged with Identity Theft, Fraud

Employee with access to PII comits ID Theft. This is why the FTC wants all businesses to tighten up their policies and procedures. I find it interesting that this has been going "over an eight-year period."

Just another article about ID Theft being an inside job.

http://www.itbusinessedge.com/cm/community/news/sec/blog/bank-employee-charged-with-identity-theft-fraud/?cs=37196

Thursday, October 8, 2009

Check Washing

We've discussed this in some of my classes.

Thieves can remove ink from your check and re-write it without compromising any safeguards, including your legitimate signature. Takes forgery to a new level.

Here is a great illustration if YouTube lets the video stay up.
http://www.youtube.com/watch?v=iwUTvIyRvdk

Watch this if you write checks, or accept them for that matter.

Wednesday, October 7, 2009

Norton Risk Assessment Tool and Videos

Norton has a very interesting and entertaining Online Risk Calculator and several videos posted here http://www.everyclickmatters.com/victim/assessment.html to help illustrate the issue of Identity Theft and the "cybercriminal black market."

They remind us that Identity Theft has surpassed the criminal drug trade according to the US Department of Justice.

The assessment will even tell you what they estimate your value to be on the black market.

And then they offer some illuminating videos to illustrate the point. I found it entertaining. You may find it more disturbing. We have discussed these issues in class.

I enjoyed taking the test and particularly the videos at the end which are also available in the top navigation via the link "Explore Digital Dangers."

Consider visiting the site and taking the quiz and watching the videos. I've provided links directly to three of the videos, Bank of Nikolai, S.O.L. and Cyber Hunting in my list of Identity Theft videos at the right.

I do want to comment on the low value they may estimate your Identity to be worth. I have seen other studies with low values for credit card, social security number and other information. Remember, in a supply and demand economy, a low demand (price) indicates a high supply (availability). This may be because there is so much stolen data available. PrivacyRights.org estimates at least 339,674,601 records have been compromised in the US since 2005 as of October 2, 2009. The US Census Bureau estimates today's US population to be 307,645,025. More data has been compromised than there are people living in the country.

Also, I like to point out that if a thief steals your car, he can sell it or part of it only one time before he is out of inventory, but if a thief steals your Social Security Number or Driver's License Number he can sell that information until he gets tired of repeating it because he can't run out of inventory, he can only decide when and if the information is too risky or unprofitable to resell again. So the low value of Identity Theft information supports the fact that there is a lot of information out there that thieves want and it is easy for them to obtain, not vice-versa.

Monday, September 28, 2009

ID Theft Resources and TX AG Abbott Enforcement Actions

As the current November 1, 2009 Federal deadline to comply with the Red Flags Rules approaches, I thought I would recap some of the currently available resources and some of the enforcement actions already taken by Texas Attorney General Greg Abbott related to Identity Theft and its impact on you and your business.

The FTC currently mandates all Businesses to adopt an IDTheft Program bu November 1, 2009 here http://www.ftc.gov/opa/2009/07/redflag.shtm.

They have published this website tp help you figure out what to do http://www.ftc.gov/redflagsrule

The Texas Workforce Commission interpreted the FTC mandate, years ago, in the first four pages of their Winter 2007 newsletter http://www.twc.state.tx.us/news/tbt/tbt0107.pdf

Our Texas Attorney General has filed enforcement actions against companies such as CVS Pharmacy, Lifetime Fitness, Radio Shack, GAB Robins, B&F Finance McAllen, L.L.C, Nino Tax of Brownsville, Cornerstone Fitness and others for violating the Texas "Identity Theft Enforcement and Protection Act" and fined them over $1.8 million collectively.

I recommend that any business, especially in Texas, pay close attention to these issues when crafting their policy to comply with these State and Federal laws.

To help reduce your risks and mitigate your damages should you have a customer, client, news reporter, disgruntled employee, law enforcement officer or even the AGs office discover that you have violated one or more of these laws either knowingly or unknowingly, you should take action immediately to ensure that you have taken reasonable steps and complied with these laws before it is too late.

Do not wait until you experience a break-in, theft or data breach at your company. By then it may already be too late. Attorney General Abbott has stated

"The Office of the Attorney
General will continue aggressively
enforcing identity theft laws and
protecting Texas consumers."

http://www.oag.state.tx.us/agency/weeklyag/2007/0607data.pdf

Welcome

Welcome to my blog. The primary purpose of this Blog is to provide links to source material that I may have quoted in a presentation or training or researched in answer to a question I have been asked.

I hope this site helps you share this information with others and/or conduct your own research. Please contact me with any questions. Thank you for visiting.