Showing posts with label data breach. Show all posts
Showing posts with label data breach. Show all posts

Wednesday, December 21, 2011

If it can happen to the U.S. Government...

Ever wonder what could possibly happen if you click on a link within an email you receive from an unknown and untrusted source? The U.S. Chamber of Commerce found out the hard way, many years after the fact. Read details about the spearphishing attack here.

It seems that an employee of this government branch was the victim of a "spearphishing" email back in 2009. "Spearphishing" is when an email is sent to a specific individual, rather than a general "phishing" email which casts a wide net to any user. The desired result of opening the email is that the user can be duped into clicking links or downloading spyware which is then used to gather personal information, such as passwords or bank account numbers. This employee either clicked a link within the email, or opened a document which did contain spyware and gave the hackers access to the servers.

Over the course of the next year, Chinese hackers were able to collect passwords which granted administrative rights. This then allowed the hackers to place additional software code, known as a "backdoor", onto the U.S. Chamber of Commerce's servers. This code would then allow the hackers to steal data.

The lesson here? If it's this easy to dupe a government employee into opening a document or clicking a link within an email, you, as a private citizen can be just as easily deceived into putting your own organization or your own personal information at risk. Anti-virus protection remains a must, even more so now than ever before. These types of attacks are becoming increasingly popular. ID thieves will stop at nothing to get any type of information they can use to commit fraud at any level.

The next time you receive an email from an untrusted source that wants you to click a link or open a document, "just say no." You have plenty of other junk mail to read.

Thursday, November 12, 2009

Identity Thief at Work

Identity theft is a societal problem and can occur in many places and by many means, including in the workplace. At work, it can happen by stealing vital information from employer's records. These records can be payroll and employment information and even customer lists. And those employees that can obtain these records can sometimes be at the very bottom of the totem pole.
Whether we're an individual working for a company or we are the company owner, we need to be aware of this growing trend and what we can do about it.On a large scale, if a big company is affected, it can result in negative publicity which would in turn affect sales, hiring and retention.

What can we, as an individual, do about this growing trend? We probably already know the obvious: shed documents with personal information, don't carry our social security card in our wallets, have locked mailboxes, and even monitor our credit reports. But the problem -- which seems to be beyond our control -- lies in crooks who obtain this information from businesses that have collected personal information for legitimate reasons and then they sell this information to more crooks that use it and steal our identity. And then with this new identity, thieves can open new credit card accounts, apply for loans, write bad checks, rent apartments and the list goes on. Individuals who have been educated on identity theft or who have had this occur in their life will scrutinize those companies that have their personal information. Because of the bad seeds, companies need to raise the bar both for their employees and clients.

So if we're looking at identity fraud from a business owner perspective, what can we do about it? Informed employees and clients know that their personal information is only as safe as the association protecting it. A solution would be to offer identity theft protection as a benefit, much like health insurance. This offer would be unique to the company, whether the company pays for part of it, all of it, or merely provides the information of how to obtain this protection. The key is in the offering so employees/clients are aware of their choices and can then make an educated decision whether to accept or decline. Too much cost, we may think. But actually, it can lower our costs whether the employee has coverage or not. With coverage, there will be less time spent in restoring their identity. Without coverage, our liability has changed. We've done all in our power to protect our employees by informing and offering. Well almost . . . There are still numerous ways where we must be proactive in protecting our employees and clients.



  1. Perform background checks on employees who have access to personal information on other employees/clients, even temporary workers. And limit this access where we can.



  2. Use employee identification numbers that are different to social security numbers to recognize employees on paychecks etc.



  3. Shred confidential documents and have specific guidelines for all employees to adhere to.



  4. Use passwords and encrypted codes when confidential files are stored on the computer.



  5. Be vigilant in educating staff on identity theft.



The Bank of New York and its employees are a perfect example of a workplace where large scale identity fraud has occurred. Adeniyi Adeyemi, a computer technician employed by a contractor who worked for the Bank of New York, has been charged with allegedly stealing the identities of over 150 employees and then with these identities, stealing over a million dollars from non-profit groups and charities and the employees themselves. Adeyemi now faces up to 25 years in prison. He obtained his information from the Technology department, opening additional bank accounts with this information to receive the stolen money. This all occurred over a seven and a half year period. The Bank of New York spokesman says that they are fully cooperating, but I wonder what the long-term ramifications of this will be (Read the Wall Street Journal article here).

It's always best to be insightful. But having insight is useless unless we take action by protecting ourselves, our employees and our company with our eyes wide open.

Tuesday, February 24, 2009

Thieves Take More Than Towels

Wyndham Hotels in Florida notified the state Attorney General about a data breach in which the credit and debit card information as well as personal data of 21,000 hotel guests was compromised in December 2008. Wyndham notified the affected guests by letter.

So far there has been no evidence that foul play has occurred, but Wyndham is urging those affected to be vigilant and obtain fraud alerts from the major credit bureaus.

Another solid piece of advice would be to watch for suspicious credit card activity. Any suspicious charge can be challenged and taken care of fairly easily with your credit card company. This is yet another reason to use credit cards rather than debit cards. If your debit card information is compromised, thieves can easily drain your bank account before you even notice a problem.

Read the original story by clicking here.

Non-fat, Low-foam Laptop Please!

Starbucks has once again lost a laptop containing employee data. In October 2008 the company lost a laptop that contained 97,000 employee's personal data, including Social Security numbers and addresses. I guess that fits in the extra-extra-large cup. Notice I said "once again?" In November of 2006 a laptop containing personal data of over 60,000 current and previous employees was also stolen. The difference is, this time the employees decided to file a lawsuit.

Some employees are saying that Starbucks took too long to notify them about the breach and provide them adequate time protect themselves against identity fraud. Starbucks has offered the employees one year of identity theft protection and credit monitoring, but some employees are asking for up to five years. Some of the plaintiff's have seen evidence of fraud due to the data breach, and are therefore seeking monetary damages.

This is bad news for you coffee drinkers. If this lawsuit is successful, I would expect to see the price of a Starbucks coffee increase. It's going to take a lot of beans to pay for the double blunder.

You can read the full story here.

Thursday, August 28, 2008

Teacher Fails Students

An article I read today on FOX 4 TV in Kansas City shows that at least one educational system is failing their students, but not in the way you would expect. You pay good money to get an education and you would think the school you attend should take every precaution to keep your personal information safe. Not so with one college teacher at least.

In Manhattan, Kansas, one teacher had his backpack stolen from his vehicle parked outside a home. No biggie, right? Well, it just so happens that he had the papers of 86 students and their Social Security numbers in that backpack. These were his students from Fall of 2007 to Summer of 2008. I can understand why a teacher would have papers with him if he were taking them home to grade. But papers from students a year ago? And if he was taking them home to grade, why didn't he take them in the house? And why did he have the students SSN's? Is that required to turn in a paper? Something is wrong with that.

This teacher deserves a failing grade for failing his students. Now they are all exposed to the possibility of identity theft and have to monitor their credit (which they should anyway) and identities for the next few years. Hopefully, the burden of expense will fall on the university and not the students.

Click here to read the full article.

This is similar to an incident that happened to me a few years ago. The financial institution handling my student loan had a server stolen from their facility. Just my luck, my personal information was on that server, and at least the bank knew that. In an effort to apologize, the bank was at least nice enough to foot the bill for credit and identity monitoring for the next year for myself and all the other thousands of students that had their information on that server.

Consider these two incidents for a moment. One occurred as theft from a car (a random smash and grab from the sounds of it), and the other occurred at a well-known financial institution. How exactly someone walks off with a server from a data center is beyond me. Where's the security? But to the point, both incidents bring to light the fact that your identity is at risk in many different ways, and unfortunately most often beyond your control. You can be as cautious as humanly possible about your personal information and do everything within your means to prevent someone from stealing your identity, yet some moron is allowed to walk off campus or out of a bank with your personal information in tow and you're put at risk.

Now, with an identity theft protection and recovery solution in place from Merchants Information Solutions, I feel a little more assured that at least if something like this should happen to me again and resulted in some devastating financial activities, I'd be able to clean it up. But I wonder what many other people are doing about this type of crisis? What kind of plan do you have in place for such incidents? Leave a comment and let me know.