Showing posts with label fraud. Show all posts
Showing posts with label fraud. Show all posts

Tuesday, July 14, 2009

Employee ID Theft at AT&T, an Inside Job

If you've ever thought that your personal information was safe at work, this might make you change your mind.

This week a federal grand jury has indicted a Chicago area temporary employee for identity theft of over 2,100 employees. The employee, who was working for AT&T, had two accomplices. The trio of women apparently used the stolen information to fill out "payday" loan applications, then used random photos of individuals and faxed in the account information. After that, they would wire the money into their accounts. Before being apprehended, the trio stole more than $70,000.

It's pretty despicable when an employee steals trusted customer data. But stealing employee data is even worse, because if you can't trust your own employees or co-workers, who can you trust? They're supposed to be on your side.

On the brighter side of things, at least the number of affected people is lower than your typical data breach. If they had stolen customer data, the number of people affected could have easily been in the millions and that would have been a tremendous blow to AT&T.

These criminals will face 20 years in prison and $250,000 each for the fraud charges and 2 years for each count of identity theft, to be served consecutively, after the other 20 years for the fraud. These girls aren't going anywhere, anytime soon. Score one for the Feds.

Read the article from the SC Magazine here.

Thursday, June 18, 2009

Socializing Yourself Into Trouble

Nearly everyone has heard the term "social engineering" before. The term refers to a clever technique that can be used to get information from individuals without having to steal it or hack into a system. The technique is very effective. People like to talk, and if you ask enough questions, people will tell you quite a bit through the course of a normal conversation. Some people talk so freely in fact, that one senior citizen in Louisville, Kentucky apparently gave enough information for a nursing home employee to open up an American Express card with the patient as the co-signer and rack up $100,000 before the patient realized it. In fact, had the patient not received a call from American Express thanking her for opening the account, it may have taken much longer to figure out what was going on.

According to an article on WLKY.com, the suspect, Danielle McClain, actually had a criminal record for criminal possession of a forged instrument and spent 6 years in prison. Apparently, that's not enough of a red flag for some people. She was hired at the nursing home in Louisville anyway. Rest assured, a new policy is in place that will screen all employees and vendors' employees in the future.

It seems natural that someone recovering form surgery in a nursing home would make friends with the staff and get into lengthy conversations. That's part of our frail human nature. It's okay to be friendly, but as the phrase goes, "don't give away the farm" while you talk. As this example points out, we should be careful with the information we disclose. Without realizing it, you may be giving away valuable information, like your mother's maiden name, spouse's birth date, etc. This is information sometimes used to open new accounts.

The lesson here: be careful what you say. You never know how it can be used against you.

Sunday, June 14, 2009

Paper Trails: Crumbs for the Identity Thief



When I think of someone stealing my identity, I often imagine a pick pocket or a burglar lurking in the shadows, waiting to grab my personal information along with my money. But often that’s not how it works. Sometimes our identity is stolen when we have a new baby, get a home loan or apply for a credit card -- sometimes our identity is stolen by employees of such institutions who steal our personal information. An identity theft is a crime where someone gains crucial pieces of identifiable information -- your driver's license number or social security number -- all in the hopes of then getting a credit card in your name, or renting an apartment in your name, getting a phone account etc., all for their own personal gain.

Take the example of Shenequa Brown, a child support collector charged with ID theft. Just this last month, this child support collector obtained the check number, routing number and bank number of her victim/client and used that money to pay for her utilities and cable.

Sometimes, however, it's not so blatant, but instead we leave a paper trail for not-so-honest employees to steal our information. We leave a paper trail in the form of birth certificates, church files, school records, diplomas, marriage and divorce certificates, voting registrations, doctor files, credit cards, land deeds and the list goes on. Certain milestones in our lives such as becoming financially independent and applying for a credit card, or having a baby, or even purchasing our own home puts our personal information on paper.

One way to prevent identity theft is not to leave a paper trail. Of course in some instances, we're putting our trust in certain institutions to keep our information confidential and we have no choice but to leave a paper trail. Sometimes the only recourse here is to closely monitor bank and credit card statements to catch the criminal quickly and also to have an identity theft service set up to help us monitor and regain our identity back quickly. But let's go over some things we can do to prevent identity theft via a paper trail.

  • Don't have financial documents sent via snailmail and don't send paper checks out through the mail. Why? A thief can steal your personal information right out of your own mailbox or home. Rather, view them online. They're typically safer when stored online. Even pay your bills online through your bank's website. However that doesn't mean that we send people our personal info via email either.
  • Invest in a shredder. Some crooks are attracted to the sport of dumpster diving.
  • Where possible, don't use your social security number as a form of identification.

There's a lot to be improved upon here such as credit card companies not so loosely giving out our information to third party companies. But maybe we should even follow the example of our European neighbors and only use our social security number as a means of gaining our retirement benefits rather than a form of identification that is needed for loans and credit card applications that can then cause problems for many years if that information gets into the wrong hands. We can't control everything but we can be aware and cautious when we give out our personal information.

Friday, May 29, 2009

Phishing: An Online Identity Theft Scam









When I hear the word phishing, I imagine early dawn, a still morning and a smooth lake with not a single ripple. But outside the nature world -- and inside the world of computer security -- phishing is online identity theft. This process was described in 1987 and defined and recorded as 'phishing' in 1996 with one sole purpose: to bait innocent victims and catch their passwords, usernames, credit card information and any other financial details.

Con artists have been around since the beginning of time. We've all heard the stories of strangers stepping into the shoes of long lost relatives and making claim for crowns or large sums of money, but now we're in the internet age and the story -- with a similar theme -- has unsuspecting online consumers as its main characters. One of the more recent phishing scams involves the social networking sites. Facebook users beware because if you're one of those users that re-use passwords, then Facebook may be your downfall. Many of us use the same password for every website, meaning if were lured to phishing sites from our facebook account, hackers can also potentially gain access to our Amazon, PayPal and eBay accounts. Read the full story here: Facebook Attacks Threaten All Web Sites

According to the APWG (Anti-Phishing Working Group), these types of crimes are on the rise with crimeware-spreading sites infecting PC's with password-stealing crimeware increasing 827% from January 2008 to December. Phishing schemes are gaining sophistication and sometimes for the everyday online consumer it can be overwhelming. The Anti-Phishing Working Group web site gives up-to-date reports on the latest phishing schemes authorities have uncovered.

There are some steps we can take to protect ourselves from these types of scams.

  • Never give out personal information, including financial, via an email request. Remember the purpose of this is to gain your name, username, address, phone number, password, bank account number, credit card number, CVC code or social security number. Regular e-mail messages aren't encrypted so it's similar to sending a postcard. Be suspicious of email messages requesting this kind of information or even those messages asking to update or confirm such details. And don't call numbers listed on email messages, but rather get the phone numbers from statements. Never click links on suspicious emails or copy and paste links from messages into your browser, but instead you type the URL into your browser or use your Favorite Links.
  • Use secure websites. Ones that you know and trust to submit personal information -- established companies with good reputations and privacy statements where they state that they won't pass on your personal information to others. And make sure these web sites use encryption.
  • Continually monitor online transactions. Review bank and credit card statements and report anything suspicious by calling the number on your account statements. Use credit cards for online purchases, even those with a small credit limit. Debit cards are connected to your bank account and credit cards with high limits only give the thief more money.
  • Use strong passwords, changing them often. Don't use real words, but rather combinations of numbers, uppercase and lowercase letters, and symbols so it's difficult for hackers to guess.
  • Protect your PC. Make sure all your security patches are installed and your browser is up to date. Use a firewall, antivirus software, anti-spyware, and even anti-phishing software.

So if this information does get into the wrong hands, what will the thieves do with it? Identity theft is common and the hacker can now apply for credit in your name, empty out your accounts, max out cards, transfer money from your investments into your checking account and then use a copy of your debit card to take it all.

These identity theft scams are continually growing in sophistication on the internet, so be aware, protect yourself as best as you can, and be prepared with identity theft services for recovery and even prevention.

Friday, May 15, 2009

Identity Theft & Traveling: What You Need To Know

The summer is fast approaching and it may be time to start thinking travel plans. Whether we go near or far, we must be aware of identity theft. In 2007, over eight million people in the United States were victims of identity theft which resulted in almost fifty billion dollars of fraudulent financial charges as quoted by the Javelin Strategy and Research Survey. That number has most likely increased over the last year. Of those victims, a significant portion was business and holiday travelers.


When I travel it's a time to relax, get away from my routine and responsibilities, and enjoy some fun with my family. So, like most people, I let my guard down. Travelers are walking targets to the thief. So perhaps we're not donning the binoculars, loud hats and colorful shirts, but we are travelers nonetheless and to crooks we're quite obvious. These pickpockets lurk in crowded airports, hotel lobbies, bus and train stations, special events -- anywhere a victim is relaxed and seemingly unaware. Our wallet in a back pocket is an invite to these kinds. Besides the obvious stolen wallet, there are other ways our identity can be stolen when traveling. Crooks are becoming smarter -- more technically savvy -- so it's critical we stay one step ahead. We need to be cautious with our laptops and our usage of internet cafes. Rather than finding ourselves in such a situation, prevention is really the key and then leisure or business can follow. So what are some things we can do?

  • Before you even travel, hold mail and newspaper delivery. A pile of newspapers is an open invitation and bills and credit card offers contain all of your information.
  • Go through you wallet. What do you really need? Take out all personal information items that aren't crucial, such as social security cards, memberships, receipts, check books, bills etc. Lock these up in your home -- identity theft can occur at home also by a house sitter or burglar.
  • Carry a fanny pack. Traveling through a crowded airport, trying to get from one point to another can be an arduous task. Carry your credit cards and other personal information with you in your fanny pack. It's much harder to nab someone's fanny pack strapped firmly to their body than a wallet peeking from a pocket. Don't leave these items in checked luggage either. Lost luggage seems more common than in the past, even if it's just for a day.
  • Pay your bills before you leave. Bills lying around in hotel rooms are easy targets for identity crooks.
  • Even open a separate account before traveling and only put in it as much money as you'll need for your holiday. Bring that one debit card with you -- not one linking to all your savings back home.
  • Bring a couple of credit cards with you. These are protected by Federal law and so fraudulent charges are generally covered. Make sure they haven't expired and you can even purchase prepaid cash cards from Visa, American Express or Mastercard. Have a list of the credit cards you brought with you easily available so that you can report the information stolen and set up fraud alerts with the credit bureaus. You can even sign up for identity theft services which can provide continual credit monitoring among other preventative measures and recovery programs.
  • Use the ATM machines available in banks. There is a threat of fake ATM machines in popular tourist areas so be safe and go to the bank.
  • Leave passports, major cards, and any other personal information that's not necessary on a day to day basis in your hotel room safe.
  • Bring a copy of important documents and also store these in a secure and separate place. You'll definitely want a copy of your passport.
  • Keep an eye on your laptop at airports, hotel lobbies and restaurants. Thieves can access personal information when laptops are unattended -- they don't even have to steal it and then the traveler is clueless. Back up your laptop before you leave and put this disc in a safe place at home or in a safety deposit box. Write your name, destination address and any other relevant contact information on a piece of paper that’s taped to your laptop in case it's inadvertently left behind. Use caution here though and use your work address and phone number.
  • Be on guard when using public computers. Key stroke loggers could be installed but generally business centers located on cruise ships and hotels are safer than other public computers.

Stealing someone's identity is not just about having your credit card stolen while the thief enjoys a shopping spree. No, this criminal can then open new credit cards, new accounts, get new loans and then not pay them, leaving 'guess who's name' on the credit report? The worse case scenario is getting arrested for crimes you've never committed. Rather than becoming paranoid, apply the steps listed and be prepared. Preparation and prevention are the two crucial keys in protecting your identity. If a worse case scenario does occur, identity theft services can help with the recovery process along with preventative steps. Travel with confidence this summer season, knowing you've done all that you can do.

Tuesday, February 24, 2009

Thieves Take More Than Towels

Wyndham Hotels in Florida notified the state Attorney General about a data breach in which the credit and debit card information as well as personal data of 21,000 hotel guests was compromised in December 2008. Wyndham notified the affected guests by letter.

So far there has been no evidence that foul play has occurred, but Wyndham is urging those affected to be vigilant and obtain fraud alerts from the major credit bureaus.

Another solid piece of advice would be to watch for suspicious credit card activity. Any suspicious charge can be challenged and taken care of fairly easily with your credit card company. This is yet another reason to use credit cards rather than debit cards. If your debit card information is compromised, thieves can easily drain your bank account before you even notice a problem.

Read the original story by clicking here.

Thursday, December 11, 2008

Former FEMA Worker Sentenced for Aggravated Identity Theft

Robert G. Davis, 44, of the District of Columbia, received a sentence of 64 months in prison from U.S. District Judge Reggie Walton. The sentence also included payment of $48,765.80 in restitution to the victims. The sentence was in response to a guilty plea he entered earlier this year to charges of wire fraud (1 count) and aggravated identity theft (1 count).

Davis was employeed by a number of mortgage companies and subsequently by FEMA, from December 2003 to November 2007. During this time, Davis fraudulently used the personal information of 200 people to finance multiple shopping sprees. The items purchased were not just the everyday household products but luxury items instead. They included: gold and diamond jewelry, designer watches, gourmet food, and expensive clothing. Davis grew weary of wearing the same old jewelry, so he pawned some of it and bought more.

The victims of his fraud did nothing that would have put them at unusual risk. They were simply living normal lives trying to get by. In fact, 30 of the 200 were simply disaster victims applying to FEMA for relief.

This is just another excellent illustration that you have to exercise bad judgement or take unusual risks to be a victim of identity theft. All it takes is for one bad actor to have motive and opportunity.

That's why Merchants believes it is so important to protect yourself by enrolling in Merchants SmartIdentity program. We'll watch your credit file for you and send you email alerts when suspicious activity occurs. If you do become a victim, our Recovery Advocates can do the legwork for you to contact all of the creditors to straighten things out.