This set-up screen asks the member to call in and make the initital recording of the voice to be verified later. The $2.8 billion Desert Schools FCU in Phoenix is the first financial institution to use a new voice biometrics solution from Finivation Software of New York City.
The VoiceVerify solution can be used to verify a caller’s identity either through an IVR or when working with a live agent, and will be used for high-risk transactions such as wire and ACH transfers and password re-sets, the company and credit union said.
“We plan to use VoiceVerify in several ways – initially for 24/7 password resets for online banking followed by out-of-band authentication for transfers. We also hope to leverage the technology to make it faster for members to authenticate in the contact center while simultaneously reducing the chance for social engineering,” said Gary Laieski, CIO for the 342,000-member Desert Schools FCU.
“Voice biometrics’ advantage over other biometric and security solutions is the fact that a person can be verified remotely, so it is perfect for the contact center as well as online and mobile banking,” said Finivation CEO Brian Bodell. “Users don’t need any special hardware or software, and they don’t need any training to use their voice.”
Desert Schools said it plans to begin using the service this fall. The added security also will help it meet new FFIEC guidance for expanded authentication, the company and credit union said.
Showing posts with label identification. Show all posts
Showing posts with label identification. Show all posts
Wednesday, August 3, 2011
Wednesday, February 9, 2011
Identity fraud dropped 28% during 2010
Credit unions that have applied more stringent criteria to authenticate users and determine credit risk will be happy to learn their efforts work. The number of identity fraud victims in 2010 dropped by 28% to 8.1 million U.S. adults--the largest single-year decrease since 2003. And the total amount decreased to $37 billion--the smallest amount in eight years. However, consumers out-of-pocket expenses rose significantly--63%, said a new study.
The 8.1 million fraud victims were three million fewer than in 2009, and the total amount decreased from 2009's $56 billion to $37 billion. Javelin said consumers' costs rose significantly due to the types of fraud that were successfully perpetrated and an increase in "friendly fraud."
The study defined identity fraud as unauthorized use of another person's personal information to achieve illicit financial gain.
"Identity fraud underwent a marked decline and shift over the past year. This great news is a testament to the significant efforts businesses, the financial services industry and government agencies are making to educate consumers, protect data, and prevent and resolve identity fraud," said James Van Dyke, Javelin's president and founder. "Economic conditions also appear to have contributed to this year-over-year decline, as well as increased security measures and some significant law enforcement successes."
He noted the increase in out-of-pocket costs "carries a warning: Consumers cannot put their finances on autopilot or ignore important safeguards. Simple safeguards may dramatically reduce fraud risk, such as frequently monitoring banking, credit and other financial activities, securing computers and paper records, and activating electronic alerts to help prevent fraud and address the situation quickly when it occurs."
More on this subject at: http://www.cuna.org/newsnow/11/system020811-10.html
Wednesday, August 18, 2010
13 Things and Identity Thief Won't Tell You
1. My least-favorite credit card? American Express, because it likes to ask me for your zip code.
2. Your unlocked mailbox is a gold mine. I can steal your account numbers, use the convenience checks that come with your credit card statement, and send in pre-approved credit offers to get a card in your name. Stealing mail is easy. Sometimes, I act like I’m delivering flyers. Other times, I just stand there and riffle through it. If I don’t look suspicious, your neighbors just think I’m a friend picking up your mail.
3. Even with all the new technology, most of us still steal your information the old-fashioned way: by swiping your wallet or purse, going through your mail, or Dumpster diving.
4. I dig through Dumpsters in broad daylight. If anyone asks (and no one does), I just say my girlfriend lost her ring, or that I may have thrown my keys away by mistake.
5. One time I was on the run and needed a new identity so I went through a hospital Dumpster and found a statement with a Puerto Rican Social Security number for a Manuel Rivera. For a good two years after that, I was Manuel Rivera. I had his name on my apartment, on my paychecks and, of course, on my credit cards.
6. Is your Social Security number on your driver’s license or your checks, or is it your account number for your health insurance? Dumb move.
7. When I send out e-mails “phishing” for personal information by posing as a bank or online merchant, I often target AOL customers. They just seem less computer literate—and more likely (I hope) to fall for my schemes.
8. I never use my home computer to buy something with a credit card that’s not mine. That’s why you can often find me at the public library.
9. If you use the same ATM every time, you’re a lot more likely to notice if something changes on the machine, like the skimmer I installed.
10. Sometimes I pose as a salesman and go into a small office. After I make my pitch, I ask the secretary to make me a copy. Since most women leave their purses on the floor by their chairs, as soon as they leave the room, I grab their wallet. I also check the top and bottom right-hand drawers of their desks, where I often find company checks.
11. How much is your information worth? I can buy stolen account information—your name, address, credit card number, and more—for $10 to $50 per account from hackers who advertise on more than a dozen black market web sites.
12. Hey, thanks for writing your PIN number on that little slip of paper in your wallet. I feel like I just won the lottery.
13. Sure, it may be nice not to have to put in your password when you use an unsecured Wi-Fi connection. But know this: We have software that can scoop up all the data your computer transmits, including your passwords and other sensitive information.
(Readers Digest http://www.readersdigest.com/identity
2. Your unlocked mailbox is a gold mine. I can steal your account numbers, use the convenience checks that come with your credit card statement, and send in pre-approved credit offers to get a card in your name. Stealing mail is easy. Sometimes, I act like I’m delivering flyers. Other times, I just stand there and riffle through it. If I don’t look suspicious, your neighbors just think I’m a friend picking up your mail.
3. Even with all the new technology, most of us still steal your information the old-fashioned way: by swiping your wallet or purse, going through your mail, or Dumpster diving.
4. I dig through Dumpsters in broad daylight. If anyone asks (and no one does), I just say my girlfriend lost her ring, or that I may have thrown my keys away by mistake.
5. One time I was on the run and needed a new identity so I went through a hospital Dumpster and found a statement with a Puerto Rican Social Security number for a Manuel Rivera. For a good two years after that, I was Manuel Rivera. I had his name on my apartment, on my paychecks and, of course, on my credit cards.
6. Is your Social Security number on your driver’s license or your checks, or is it your account number for your health insurance? Dumb move.
7. When I send out e-mails “phishing” for personal information by posing as a bank or online merchant, I often target AOL customers. They just seem less computer literate—and more likely (I hope) to fall for my schemes.
8. I never use my home computer to buy something with a credit card that’s not mine. That’s why you can often find me at the public library.
9. If you use the same ATM every time, you’re a lot more likely to notice if something changes on the machine, like the skimmer I installed.
10. Sometimes I pose as a salesman and go into a small office. After I make my pitch, I ask the secretary to make me a copy. Since most women leave their purses on the floor by their chairs, as soon as they leave the room, I grab their wallet. I also check the top and bottom right-hand drawers of their desks, where I often find company checks.
11. How much is your information worth? I can buy stolen account information—your name, address, credit card number, and more—for $10 to $50 per account from hackers who advertise on more than a dozen black market web sites.
12. Hey, thanks for writing your PIN number on that little slip of paper in your wallet. I feel like I just won the lottery.
13. Sure, it may be nice not to have to put in your password when you use an unsecured Wi-Fi connection. But know this: We have software that can scoop up all the data your computer transmits, including your passwords and other sensitive information.
(Readers Digest http://www.readersdigest.com/identity
Friday, August 13, 2010
ID Insight Touts Patent Win
http://www.cutimes.com/news/2010/8/Pages/ID-Insight-Touts-Patent-Win.aspx?utm_source=cutimes&utm_medium=email&utm_campaign=traffic&cmpid=cutimes
ID Insight said it has been awarded a patent for its method of identifying differences in addresses that helps credit unions and banks identify potential identity theft.
The Northfield, Minn., company said its process can quickly spot the difference between a legitimate vs. fraudulent address change, thus thwarting a common way identity thieves obtain replacement cards and open fraudulent accounts.
The focus on address manipulation is stronger, the company added, now that the Fair and Accurate Transaction Act (FACT Act) requires financial institutions to monitor address changes for potential identity theft.
ID Insight said it now provides its market research, verification, authentication and other anti-fraud solutions to more than 600 credit unions, banks and other customers.
ID Insight said it has been awarded a patent for its method of identifying differences in addresses that helps credit unions and banks identify potential identity theft.
The Northfield, Minn., company said its process can quickly spot the difference between a legitimate vs. fraudulent address change, thus thwarting a common way identity thieves obtain replacement cards and open fraudulent accounts.
The focus on address manipulation is stronger, the company added, now that the Fair and Accurate Transaction Act (FACT Act) requires financial institutions to monitor address changes for potential identity theft.
ID Insight said it now provides its market research, verification, authentication and other anti-fraud solutions to more than 600 credit unions, banks and other customers.
Wednesday, August 4, 2010
Next Wave of ID Thefts Targeting Kids' SSNs
Identity thieves are beginning to steal Social Security numbers of children, long before they're ready for a savings or checking account or a credit score--and that could threaten the nation's credit system, said an Associated Press report.
The thefts could be a problem for credit unions and other financial institutions because they rely on credit scores from FICO, Experian, TransUnion and Equifax. But those scores could contain false information, planted by people who use stolen Social Security numbers to piggyback on the credit of someone else, according to Kansas City law enforcement agents.
Kansas City Assistant U.S. Attorney Linda Marshall and Julie Jensen, a special agent with the Federal Bureau of Investigation's office in Kansas City, said that in the fraud, online businesses use computers to locate dormant Social Security numbers, usually of children or long-term prison inmates who don't use them. The companies sell the numbers under another name to people who establish phony credit and run up huge debts without intending to pay.
The sellers skirt the law by referring to the Social Security numbers as "credit privacy numbers" or CPNs. They are also called "credit profile numbers" and "credit protection numbers."
Jensen discovered the scheme and says it is easy to create a false credit score using the CPNs, said the article.
The crooks have years to use the numbers before the child is old enough to apply for credit. That makes the fraud difficult to detect, and authorities can't estimate how prevalent the practice is.
The fraud is emerging because 25.5% of consumers have credit scores of 599 or below, which means they're poor credit risks. Many credit decisions are based on the credit scores provided by FICO and the three major credit reporting bureaus. But Jensen says those credit scores could contain false information.
FICO said it has tools for businesses to protect themselves, but the tools are expensive, the article said.
http://www.cuna.org/newsnow/10/system080310-11.html?ref=hed
The thefts could be a problem for credit unions and other financial institutions because they rely on credit scores from FICO, Experian, TransUnion and Equifax. But those scores could contain false information, planted by people who use stolen Social Security numbers to piggyback on the credit of someone else, according to Kansas City law enforcement agents.
Kansas City Assistant U.S. Attorney Linda Marshall and Julie Jensen, a special agent with the Federal Bureau of Investigation's office in Kansas City, said that in the fraud, online businesses use computers to locate dormant Social Security numbers, usually of children or long-term prison inmates who don't use them. The companies sell the numbers under another name to people who establish phony credit and run up huge debts without intending to pay.
The sellers skirt the law by referring to the Social Security numbers as "credit privacy numbers" or CPNs. They are also called "credit profile numbers" and "credit protection numbers."
Jensen discovered the scheme and says it is easy to create a false credit score using the CPNs, said the article.
The crooks have years to use the numbers before the child is old enough to apply for credit. That makes the fraud difficult to detect, and authorities can't estimate how prevalent the practice is.
The fraud is emerging because 25.5% of consumers have credit scores of 599 or below, which means they're poor credit risks. Many credit decisions are based on the credit scores provided by FICO and the three major credit reporting bureaus. But Jensen says those credit scores could contain false information.
FICO said it has tools for businesses to protect themselves, but the tools are expensive, the article said.
http://www.cuna.org/newsnow/10/system080310-11.html?ref=hed
Tuesday, December 15, 2009
Six cyber trends outlined by I.D. theft center
Identity crime, especially Internet-based crime, continues to plague consumers and the economy, according to the Identity Theft Assistance Center (ITAC) Identity Theft Outlook for 2010.
The report is based on developments during the past year and notes what's ahead in 2010, including trends in criminal activity and law enforcement.
The report also outlined six trends ITAC anticipates for 2010:
1) More criminals will use malware to steal usernames and passwords, and recruit accomplices as "money mules" to open phony accounts and transfer funds. "It is the responsibility of consumers and businesses alike to demand the best security protection and to implement it into their everyday experiences," said Michael Stanfield, CEO, Intersections Inc., a CUNA Strategic Service.
2) More collaboration on cyber security. The Obama administration will continue to break down silos within the government and collaborate more with the industry as it develops and implement cyber security policy, ITAC said.
3) Expanded use of identity management solutions to address identity theft, data breaches and cybercrime.
4) Changes resulting from "Red Flag" rules. Red flags are any activity or practice that indicates possible identity theft. Consumers will face questions about address changes and other behavior, including missed payments or changes in spending patterns. Consumers may be annoyed until they adjust to the new levels of scrutiny.
5) Stiffer sentences for those convicted of identity theft. The law requires a mandatory two-year sentence for aggravated identity theft. Prosecutors also are pursuing added jail time for related felonies, including wire fraud and use of unauthorized access devices.
6) Possible federal regulation of breaches of consumer data. The Senate is slated to consider two measures that would regulate how public and private organizations protect personal information.
The report is based on developments during the past year and notes what's ahead in 2010, including trends in criminal activity and law enforcement.
The report also outlined six trends ITAC anticipates for 2010:
1) More criminals will use malware to steal usernames and passwords, and recruit accomplices as "money mules" to open phony accounts and transfer funds. "It is the responsibility of consumers and businesses alike to demand the best security protection and to implement it into their everyday experiences," said Michael Stanfield, CEO, Intersections Inc., a CUNA Strategic Service.
2) More collaboration on cyber security. The Obama administration will continue to break down silos within the government and collaborate more with the industry as it develops and implement cyber security policy, ITAC said.
3) Expanded use of identity management solutions to address identity theft, data breaches and cybercrime.
4) Changes resulting from "Red Flag" rules. Red flags are any activity or practice that indicates possible identity theft. Consumers will face questions about address changes and other behavior, including missed payments or changes in spending patterns. Consumers may be annoyed until they adjust to the new levels of scrutiny.
5) Stiffer sentences for those convicted of identity theft. The law requires a mandatory two-year sentence for aggravated identity theft. Prosecutors also are pursuing added jail time for related felonies, including wire fraud and use of unauthorized access devices.
6) Possible federal regulation of breaches of consumer data. The Senate is slated to consider two measures that would regulate how public and private organizations protect personal information.
Tuesday, June 9, 2009
ID thefts with victims' names on cards rise
The number of identity thefts where fraudsters obtained credit cards using victims' names rose during 2008, according to Javelin Strategy and Research.
Javelin attributed the increase to a credit card loan application process that requires less verified information and is easier than other types of loan applications. Also, credit cards provide the most financial gain for thieves, who often don't get caught (CardLine June 8).
The results, published by the Pleasanton, Calif.-based firm last week, are based on a survey conducted by the firm of 4,784 U.S. consumers last year.
Of those responding, 487 said they had been victims of identity theft. Of the identity theft victims, 146 indicated that a variety of fraudulent new accounts had been opened using their name.
Among the new-account fraud victims, one-third said criminals had opened new credit card accounts in their name, up from 26% from the previous year's survey.
Other findings:
> Twenty-six percent of the victims said fraudsters opened new store-branded credit cards in their names, down from 29% in 2007.
> Fifteen percent reported other types of fraudulent loans were in their names, down from 21%.
Javelin attributed the increase to a credit card loan application process that requires less verified information and is easier than other types of loan applications. Also, credit cards provide the most financial gain for thieves, who often don't get caught (CardLine June 8).
The results, published by the Pleasanton, Calif.-based firm last week, are based on a survey conducted by the firm of 4,784 U.S. consumers last year.
Of those responding, 487 said they had been victims of identity theft. Of the identity theft victims, 146 indicated that a variety of fraudulent new accounts had been opened using their name.
Among the new-account fraud victims, one-third said criminals had opened new credit card accounts in their name, up from 26% from the previous year's survey.
Other findings:
> Twenty-six percent of the victims said fraudsters opened new store-branded credit cards in their names, down from 29% in 2007.
> Fifteen percent reported other types of fraudulent loans were in their names, down from 21%.
Tuesday, May 26, 2009
Our Ears May be Our Password
YOU are the victim of identity theft and the fraudster calls your credit union to transfer money into their own account. But instead of asking them for your personal details, the credit union rep simply presses a button that causes the phone to produce a brief series of clicks in the fraudster's ear. A message immediately alerts the bank that the person is not who they are claiming to be, and the call is ended.
For more on this security technology, visit: http://www.newscientist.com/article/mg20227035.200-our-ears-may-have-builtin-passwords.html
For more on this security technology, visit: http://www.newscientist.com/article/mg20227035.200-our-ears-may-have-builtin-passwords.html
Thursday, April 16, 2009
Palm Scan May Replace Log-on Passwords
Be patient. Large file is loading.
Forget your password? Don't worry about it. A scan of your hand, palm, fingerprint or face will someday replace it. Hundreds of credit unions across the country are using biometric identifcation technology to identify employees. Here's an example of one of these technologies.
Sunday, April 5, 2009
US banks sign up for biometric project
The US-based Financial Services Technology Consortium has launched a project to investigate the use of biometrics for verifying customer IDs. The FSTC says over 20 banks have expressed an interest in the project, including the American Bankers Association which has signed on as a sponsor.
Dan Schutzer, executive director FSTC says the programm will endeavour to develop a methodology for banks to better select, specify, evaluate and deploy biometric applications with greater customer acceptance.
"We also hope to identify and validate at least one or two of them that will make an immediate impact in the fight against identity theft and insider fraud," he adds.
The initiative grew out of a panel discussion at a joint FSTC/Bits summit in early March. A follow-up meeting is planned for later this month at Wells Fargo Bank in San Francisco.
A global survey conducted by Unisys last year found that 72% of US citizens would be willing to undergo fingerprint scans to verify their identities when dealing with banks and government organisations.
Dan Schutzer, executive director FSTC says the programm will endeavour to develop a methodology for banks to better select, specify, evaluate and deploy biometric applications with greater customer acceptance.
"We also hope to identify and validate at least one or two of them that will make an immediate impact in the fight against identity theft and insider fraud," he adds.
The initiative grew out of a panel discussion at a joint FSTC/Bits summit in early March. A follow-up meeting is planned for later this month at Wells Fargo Bank in San Francisco.
A global survey conducted by Unisys last year found that 72% of US citizens would be willing to undergo fingerprint scans to verify their identities when dealing with banks and government organisations.
Tuesday, February 10, 2009
Number of ID fraud victims up 22%
The number of identity fraud victims in 2008 increased 22% to 9.9 million adults in the U.S., according to the 2009 Identity Fraud Survey Report, issued Monday by Javelin Strategy & Research.
However, the total annual fraud amount rose only slightly--7%--to $8 billion during the past year, the survey said (Business Wire Feb. 9).
Javelin, based in Pleasanton, Calif., is an independent provider of quantitative and qualitative research focused on financial services topics.
Other key survey findings:
>> Overall identity fraud incidents increased in the U.S. The number of identity fraud incidents in 2008 rose by 22% over 2007, which brings the number back up to levels not seen since 2004. Javelin said the rise was due to economic misfortune. Historically, higher rates of fraud occur when the economy worsens. Identity fraud remains substantially lower overall when compared to the 2004 level of $60 billion.
>> Cost to consumers is down. The mean consumer cost of identity fraud decreased 31% to $496-- its lowest level since 2005--from $718 per incident. The lower cost per incident is attributable to faster detection of fraud, lower fraud amounts, and quicker resolution times thanks to industry efforts and consumer education, Javelin said.
>> Fraudsters are moving much more quickly. In cases where identity fraud was reported, 71% of the fraud incidents began occurring less than one week from when the data was stolen, up from 33% in 2005. The dramatic increase points to more sophisticated attacks by fraudsters and an increasing number of "attacks of opportunity" in which people or businesses leave data exposed.
>> Gender disparity. Women were 26% more likely to be victims of identity fraud than men in 2008. Women are making more purchases in stores, and more women than men experienced breaches last year.
>> Low-tech methods still most popular. Lost or stolen wallets, checkbooks and credit and debit cards were still the most likely avenues of fraudsters' attacks. These avenues totaled 43% of all incidents in which the method of access was known. By protecting their information, consumers can significantly lower their risks, Javelin said.
However, the total annual fraud amount rose only slightly--7%--to $8 billion during the past year, the survey said (Business Wire Feb. 9).Javelin, based in Pleasanton, Calif., is an independent provider of quantitative and qualitative research focused on financial services topics.
Other key survey findings:
>> Overall identity fraud incidents increased in the U.S. The number of identity fraud incidents in 2008 rose by 22% over 2007, which brings the number back up to levels not seen since 2004. Javelin said the rise was due to economic misfortune. Historically, higher rates of fraud occur when the economy worsens. Identity fraud remains substantially lower overall when compared to the 2004 level of $60 billion.
>> Cost to consumers is down. The mean consumer cost of identity fraud decreased 31% to $496-- its lowest level since 2005--from $718 per incident. The lower cost per incident is attributable to faster detection of fraud, lower fraud amounts, and quicker resolution times thanks to industry efforts and consumer education, Javelin said.
>> Fraudsters are moving much more quickly. In cases where identity fraud was reported, 71% of the fraud incidents began occurring less than one week from when the data was stolen, up from 33% in 2005. The dramatic increase points to more sophisticated attacks by fraudsters and an increasing number of "attacks of opportunity" in which people or businesses leave data exposed.
>> Gender disparity. Women were 26% more likely to be victims of identity fraud than men in 2008. Women are making more purchases in stores, and more women than men experienced breaches last year.
>> Low-tech methods still most popular. Lost or stolen wallets, checkbooks and credit and debit cards were still the most likely avenues of fraudsters' attacks. These avenues totaled 43% of all incidents in which the method of access was known. By protecting their information, consumers can significantly lower their risks, Javelin said.
Friday, December 5, 2008
Between Google and LinkedIn, identity management becomes a farce
What I find amazing is the number of people who are involved in various aspects of security and supposedly aware of basic security policy, continue to provide endless information about themselves and all the people they are connected with on LinkedIn. Every day, LinkedIn sends a daily bulletin to members with a list of new members who have joined the list of a members you are connected with including who they know and to which organizations they and their associates belong.
Members are more interested in having as many contacts as possible than they are about their own privacy or security. Between Google and LinkedIn, identity management becomes a farce.
One becomes a member simply by sending their true or alias name to LinkedIn. If I were to submit a well known and semi-famous alias that is known to several members of the group, I am sure that they would be flattered to have me on their list of LinkedIn associates and would be openly invited to join their list. I would slowly move up the ladder with their LinkedIn associates. Then by simple social engineering I would move about freely obtaining information and recommendation without any problem. I could then send to any of these trusting persons emails outside of LinkedIn with an innocent attachment containing a simple Trojan program that would allow me to obtain any data I needed from their computer.
Many years ago, I was invited by a friend to join LinkedIn. Flattered, I replied and filled out the application form. The very next day, I received an email bulletin containing the name of the member who invited me to join with his full biography. Soon, I began receiving requests from people I knew and had never heard. The potential dangers became all to apparent and I just stopped.
Identity management is not only academic, it is an everyday policy that people in the digital world need not only preach but practice.
Members are more interested in having as many contacts as possible than they are about their own privacy or security. Between Google and LinkedIn, identity management becomes a farce.One becomes a member simply by sending their true or alias name to LinkedIn. If I were to submit a well known and semi-famous alias that is known to several members of the group, I am sure that they would be flattered to have me on their list of LinkedIn associates and would be openly invited to join their list. I would slowly move up the ladder with their LinkedIn associates. Then by simple social engineering I would move about freely obtaining information and recommendation without any problem. I could then send to any of these trusting persons emails outside of LinkedIn with an innocent attachment containing a simple Trojan program that would allow me to obtain any data I needed from their computer.
Many years ago, I was invited by a friend to join LinkedIn. Flattered, I replied and filled out the application form. The very next day, I received an email bulletin containing the name of the member who invited me to join with his full biography. Soon, I began receiving requests from people I knew and had never heard. The potential dangers became all to apparent and I just stopped.
Identity management is not only academic, it is an everyday policy that people in the digital world need not only preach but practice.
Wednesday, August 6, 2008
11 charged in TJX, BJ's Wholesale Club breaches
Eleven people have been charged with stealing more than 40 million credit and debit card numbers obtained from TJX Cos., BJ's Wholesale Club Inc., and seven other retailers.
They were indicted Tuesday, in what the Justice Department calls the largest, most complex identity-theft case ever prosecuted (ComputerWorld.com, CNNMoney.com and Bloomberg.com Aug. 5).
Thousands of credit unions and their members were among those impacted in the thefts. Credit unions and other financial institutions were forced to reissue compromised cards and endure costs related to fraud. Some of the breaches sparked lawsuits by credit unions and by their insurance companies.
The identity theft ring targeted nine U.S. retailers, including TJX, BJ's, DSW Shoe Warehouse, Office Max Inc., Boston Market, Barnes & Noble Inc., Sports Authority, Forever 21, and Dave & Buster's restaurants.
More information at: http://www.cuna.org/newsnow/08/system080508-9.html?ref=hed
They were indicted Tuesday, in what the Justice Department calls the largest, most complex identity-theft case ever prosecuted (ComputerWorld.com, CNNMoney.com and Bloomberg.com Aug. 5).
Thousands of credit unions and their members were among those impacted in the thefts. Credit unions and other financial institutions were forced to reissue compromised cards and endure costs related to fraud. Some of the breaches sparked lawsuits by credit unions and by their insurance companies.
The identity theft ring targeted nine U.S. retailers, including TJX, BJ's, DSW Shoe Warehouse, Office Max Inc., Boston Market, Barnes & Noble Inc., Sports Authority, Forever 21, and Dave & Buster's restaurants.
More information at: http://www.cuna.org/newsnow/08/system080508-9.html?ref=hed
Friday, May 23, 2008
ID-protection ads come back to bite ID Company
Todd Davis has dared criminals for two years to try stealing his identity: Ads for his fraud-prevention company, LifeLock, even offer his Social Security number next to his smiling mug.
Now, Lifelock customers in Maryland, New Jersey and West Virginia are suing Davis, claiming his service didn't work as promised and he knew it wouldn't, because the service had failed even him.
Attorney David Paris said he found records of other people applying for or receiving driver's licenses at least 20 times using Davis' Social Security number, though some of the applications may have been rejected because data in them didn't match what the Social Security Administration had on file. Davis acknowledged in an interview with The Associated Press that his stunt has led to at least 87 instances in which people have tried to steal his identity, and one succeeded: a guy in Texas who duped an online payday loan operation last year into giving him $500 using Davis' Social Security number.
Paris said the fact Davis' records were compromised at all supports the claim that Tempe, Ariz.-based LifeLock doesn't provide the comprehensive protection its advertisements say it does.
Attorney David Paris said he found records of other people applying for or receiving driver's licenses at least 20 times using Davis' Social Security number, though some of the applications may have been rejected because data in them didn't match what the Social Security Administration had on file. Davis acknowledged in an interview with The Associated Press that his stunt has led to at least 87 instances in which people have tried to steal his identity, and one succeeded: a guy in Texas who duped an online payday loan operation last year into giving him $500 using Davis' Social Security number.
Paris said the fact Davis' records were compromised at all supports the claim that Tempe, Ariz.-based LifeLock doesn't provide the comprehensive protection its advertisements say it does.
Monday, April 14, 2008
Stolen bank account data was most advertised item on the internet black market in 2007
In the second half of 2007, stolen bank account details were the most frequently advertised items on the internet black market, states a report. The advertised price for bank account data varied between USD 10 and USD 1000, depending on the location and funds available in the account. According to the report, bank accounts that included higher balances were advertised for much higher prices.
Credit cards were the second most advertised by online fraudsters on underground websites. Criminals were selling 50 credit card numbers for USD 40 (EUR 0.8 each) and 500 numbers for USD 200 (EUR 0.4 each). The report says the bulk rates advertised in the second half of 2007 were lower than those advertised in the first half of 2007, when the lowest purchase price was USD 100 for a package of 100 credit card numbers.
The report shows that full identities were the third most common item advertised for sale on the black market. Identities of EU citizens were more expensive than American ones.Other report findings show a rise in the number of computers hosting phishing websites in the second half of 2007.
There are mentioned 87,963 phishing hosts during the period, up 167 percent on the first six months of 2007. Banks were most targeted by phishers, with 80 percent of brands targeted by attacks during the study period. During the last six months of 2007, 66 percent of phishing websites targeted the financial services sector, down from 72 percent registered in the first half of 2007.
Even though six of the top ten brands targeted by phishers were in the financial sector, the report mentions that the second most frequently attacked brand was a social networking website.
Credit cards were the second most advertised by online fraudsters on underground websites. Criminals were selling 50 credit card numbers for USD 40 (EUR 0.8 each) and 500 numbers for USD 200 (EUR 0.4 each). The report says the bulk rates advertised in the second half of 2007 were lower than those advertised in the first half of 2007, when the lowest purchase price was USD 100 for a package of 100 credit card numbers.
The report shows that full identities were the third most common item advertised for sale on the black market. Identities of EU citizens were more expensive than American ones.Other report findings show a rise in the number of computers hosting phishing websites in the second half of 2007.
There are mentioned 87,963 phishing hosts during the period, up 167 percent on the first six months of 2007. Banks were most targeted by phishers, with 80 percent of brands targeted by attacks during the study period. During the last six months of 2007, 66 percent of phishing websites targeted the financial services sector, down from 72 percent registered in the first half of 2007.
Even though six of the top ten brands targeted by phishers were in the financial sector, the report mentions that the second most frequently attacked brand was a social networking website.
Wednesday, March 12, 2008
Voice biometrics: coming to a bank near you
At a recent bankers' conference in the US, Australian speech application company VeCommerce presented delegates with a challenge: fool our voice biometric technology and win $US1000. No one did, vindicating the company's claim that the technology is robust enough to be deployed in multifactor authentication for applications such as online banking.
According to Steve Lewis, general manager business consulting for VeCommerce in Australia, while deployments of voice biometric technology have to date been fairly limited, that is set to change.
"We are a the cusp of seeing some major deployments. We are in the process of developing a system for a top tier financial services organisation in Australia which will roll out at the end of this year. That will be a very large scale deployment...Two of the others are looking at similar solutions: once one goes the others will follow."
Lewis said the banks were interested particularly in applying the technology to Internet banking.
"There is so much phishing going on that people are getting nervous about the security of their passwords. A number of banks secure now their transactions through SMS tokens - they send a one time password to your mobile phone. Our product allows the bank to generate a phone call to your mobile phone then it compares your voice to a stored profile."VeCommerce suggests that a voice profile eliminates the need for remembering identifiers such as PINs, passwords, mother's maiden name, or for having special equipment such as PIN pads or fobs.
Also, in situations where callers are required to identify themselves to a call centre operator, it avoids the caller having to provide information such as account number, date of birth, etc which could easily be stolen and used in subsequent identity fraud.
According to Steve Lewis, general manager business consulting for VeCommerce in Australia, while deployments of voice biometric technology have to date been fairly limited, that is set to change.
"We are a the cusp of seeing some major deployments. We are in the process of developing a system for a top tier financial services organisation in Australia which will roll out at the end of this year. That will be a very large scale deployment...Two of the others are looking at similar solutions: once one goes the others will follow."
Lewis said the banks were interested particularly in applying the technology to Internet banking.
"There is so much phishing going on that people are getting nervous about the security of their passwords. A number of banks secure now their transactions through SMS tokens - they send a one time password to your mobile phone. Our product allows the bank to generate a phone call to your mobile phone then it compares your voice to a stored profile."VeCommerce suggests that a voice profile eliminates the need for remembering identifiers such as PINs, passwords, mother's maiden name, or for having special equipment such as PIN pads or fobs.
Also, in situations where callers are required to identify themselves to a call centre operator, it avoids the caller having to provide information such as account number, date of birth, etc which could easily be stolen and used in subsequent identity fraud.
Labels:
biometrics,
fraud,
identification,
Internet,
on-line banking,
voice
Sunday, November 25, 2007
Customer Identification Programs for Banks, Savings Associations and Credit Unions
The National Consumer Law Center ("NCLC") submits the following comments on behalf of its low income clients regarding the proposed rules on Customer Identification Programs for financial institutions. NCLC makes this comment for two reasons. First, we present comments regarding the potential effect of the proposed regulations on addressing the serious problem to consumers of identity theft. Second, we want to ensure that Customer Identification Programs contain a reasonable method for new immigrants to this country to have access to basic financial services. We believe that these distinct issues do not require contradictory results.
http://www.nclc.org/initiatives/test_and_comm/id_program.shtml
or http://tinyurl.com/2mfg6c
http://www.nclc.org/initiatives/test_and_comm/id_program.shtml
or http://tinyurl.com/2mfg6c
Labels:
Customer identification,
identification,
identity theft,
NCLC
Subscribe to:
Posts (Atom)
