Friday, June 19, 2009

ATM fraud ring arrests made, stole from Florida CUs

Police in Jacksonsville, Fla., recently made three arrests in a complex ATM fraud ring involving more than 100 people. The ring defrauded a number of Florida credit unions.

Ophel Day, Tony Fudge and Jacob Dunn were arrested for depositing bad checks into ATMs and then making withdrawals or purchases before the checks bounced, according to federal investigators (WJXT Jacksonville June 17).

The fraud has cost local credit unions from $300,000 to $500,000, police said. Affected credit unions include Jacksonville-based Vystar CU and Mulberry, Fla.-based Community First CU.
More arrests will be made, Paul Elliot of the Secret Service said

The scam begins when account holders sell their ATM cards and personal identification numbers for up to $500 to a "recruiter" in the ring, authorities said. The recruiter then passes the information on to the scam's ringleader. Individuals giving up their card then report the card as stolen.

Recruiters deposit checks that are counterfeit, stolen or from closed accounts into ATMs. The active accounts allow a percentage of the money deposited to be immediately withdrawn, with subsequent withdrawals and purchases from businesses conducted before the check is returned, authorities said.

Account holders often report that their cards are stolen or lost after the thefts occur. Many are reimbursed for losses they claim--which results in a double whammy to the financial institutions involved, authorities added.

Newest report shows fraud trends

The recently released May 2009 Online Fraud report from RSA Security Inc.'s Anti-Fraud Command Center provides information for credit unions and others about the latest fraud trends and forecasts for the next 12 to 18 months.

These include:

> Muling--the evolution of recruitment scams directed towards unsuspecting individuals to aid in the monetization of stolen goods;

> Evolving supply chains, including fraud-as-a-service, which helps online criminals commit fraud;

> Significant increase in attacks against the enterprise;

Evolution in crimeware and attack vectors including: a rise in use of the latest crimeware delivery method; fast-flux botnets (a network of compromised computers); improvements in both Trojan functionality and infrastructure; and consolidation of "traditional" phishing and malware attacks.

The number of phishing attacks in April dropped 7% from March attacks, the report said.

In the next 12 to 18 months, RSA said it expects to see an increase in enterprise fraud in which online criminals can gain access to sensitive corporate data such as intellectual property and business plans.

To stay ahead of the fraudsters, RSA recommends that companies deploy a layered approach to security, which has three core elements:

> Understand the threat landscape--Organizations must understand the threats that are targeting their business and the relative risks they pose. By doing so, organizations can mitigate the risks of online fraud or even prevent it from occurring at all.

> Use multi-factor authentication to protect the login--Username and password authentication is not enough to protect access to sensitive data today. Multi-factor authentication--including two-factor and risk-based authentication--are critical to preventing unauthorized access to a user's sensitive and personal data.

Monitor transactions and activities that occur post-login--Going beyond authentication solutions that can challenge users to assure their identity login, organizations should consider implementing a transaction-monitoring solution that analyzes and challenges high-risk transactions after login has occurred. Transaction monitoring can help identify suspicious post-login activities and mark them for further review.

Friday, June 12, 2009

Reach a human when you call customer service

This is an amazing concept: A Web site called gethuman.com ("get human")gives instructions for avoiding the interminable voice menus used by companies and government agencies -- and reaching a real customer-service person. We're bookmarking this baby. If the company you need to contact isn't listed, a tips page tells you how to find the phone number and gives some suggestions for reaching a person, like punching the zero on your phone repeatedly, mumbling when the machine tells you to speak, or asking for "account collections," which generally is quick to answer the phone.

"When you do finally find a human, ask them how to connect directly the next time (in case your call gets disconnected, etc.), and be sure to tell us so we can then list their number here," the site says.

The site, founded by consumer advocate Paul English, provides a message board and also rates companies' customer-service phone system performance against the gethuman standards. We don't need to tell you that the F's vastly outnumber the A's.

There's also a translation guide for what the voice menu really means. "Your call is important to us" means this, according to gethuman.com: "You are not important enough for us to have a human answer your call, but we think you are stupid enough to feel good when we say you are important."

http://www.gethuman.com/

Funny Money: Why Banks Want to be Our Friend

Redneck Bank is still alive and kicking. They're offering checking accounts of various types and they're the buzz of the finance news world for their tongue-in-cheek approach to banking.

(Click on photo to enlarge)


You can see their website here, complete with braying donkey, outhouse for "personal bidness" and lots and lots of Flash animation tutorials and info. (Note: they're not a "bank", per se, they're an extension of Bank of the Wichitas).


Click here to visit: http://www.redneckbank.com/

Feds Hunting for $120 Million of CU Funds Missing From U.S. Mortgage

Michael McGrath, the founder and owner of U.S. Mortgage and its CU National Corp., is scheduled to plead guilty in federal court to bank fraud and conspiracy charges in what is growing into one of the biggest financial scandals ever to hit credit unions.

Customer Service Hall of Shame

MSN Money's 3rd annual survey finds which companies, despite tough times, still put customers first -- and which ones seem intent on walking all over them.

MSN Money released its third annual Customer Service Hall of Shame survey results. The results revealed that financial intuitions and telecommunication services keep slipping in the minds of consumers when it comes to customer service and nine out of the 10 companies that made it to this year’s shame list are repeat offenders!

Once again, the coveted number one worst customer service spot was reserved for AOL. The rest of the shame awards go to:

#2 Comcast
#3 Sprint
#4 Capital One
#5 Time Warner Cable
#6 HSBC
#7 Qwest
#8 Abercrombie and Fitch
#9 Bank of America
#10 Citigroup

On the bright side, some companies are satisfying consumers, especially low-cost entertainment and bulk food companies that provide great value in this economic climate. The number one Hall of Fame spot is awarded to USAA and the second to Trader Joe’s.

To check out the entire Hall of Shame list, visit:
http://articles.moneycentral.msn.com/SmartSpending/ConsumerActionGuide/HowCompaniesWereRanked.aspx

Thursday, June 11, 2009

95% of Blogs Abandoned

The NY Times reports that according to a 2008 survey only 7.4 million out of the 133 million blogs the company tracks had been updated in the past 120 days meaning that "95 percent of blogs being essentially abandoned, left to lie fallow on the Web, where they become public remnants of a dream -- or at least an ambition -- unfulfilled."

Richard Jalichandra, chief executive of Technorati, said that at any given time there are 7 million to 10 million active blogs on the Internet, but it's probably between 50,000 and 100,000 blogs that are generating most of the page views.

"There's a joke within the blogging community that most blogs have an audience of one." Many people who think blogging is a fast path to financial independence also find themselves discouraged.

Tuesday, June 9, 2009

Employed women to outnumber men

Did you know that men make up about 82% of job losses so far? Employed women will soon outnumber employed men for the first time in U.S. history, according to the U.S. Bureau of Labor Statistics.

Security video records ghostly vibes in CU

Anderson City Employees FCU, located in the South Carolina city's brand new Municipal Business Center, is experiencing some otherworldly vibes in the form of not-yet-explained moving blurs picked up by its security camera.

The moving blur is white and floats around the room to a chair, sits down and disappears. Sometimes there are two blurs. The local NBC affiliate, KFOR, has the sightings on a video. Use the resource link below to view it.

The sightings began last month after security guard Rob Colbert spotted movement out of the corner of his eye while working late. He checked the security tape. It had captured the movement.

The blurs always occur in the same office. The most recent visit was last Thursday morning.
The center's IT director, Mark Cunningham, checked the cameras and found nothing wrong. The credit union closed the blinds to avoid any reflections from outside. But the apparition showed up again--this time more clearly.

IT cleaned the camera lens and resealed the camera cover, but the image reappeared. It doesn't cause any trouble and the credit union has nicknamed it "Clair, for clairvoyant."

The new center was built on a former service station lot but no one know of any ghosts lurking about.

"If it is a ghost, maybe it's Casper the friendly ghost," Frances Parham, CEO of the $1.6 million asset credit union, told the television reporters.

Click here to view the ghost video:
http://www.kfor.com/news/local/kfor-news-south-carolina-ghost-story,0,4375330.story

ID thefts with victims' names on cards rise

The number of identity thefts where fraudsters obtained credit cards using victims' names rose during 2008, according to Javelin Strategy and Research.

Javelin attributed the increase to a credit card loan application process that requires less verified information and is easier than other types of loan applications. Also, credit cards provide the most financial gain for thieves, who often don't get caught (CardLine June 8).

The results, published by the Pleasanton, Calif.-based firm last week, are based on a survey conducted by the firm of 4,784 U.S. consumers last year.

Of those responding, 487 said they had been victims of identity theft. Of the identity theft victims, 146 indicated that a variety of fraudulent new accounts had been opened using their name.

Among the new-account fraud victims, one-third said criminals had opened new credit card accounts in their name, up from 26% from the previous year's survey.

Other findings:

> Twenty-six percent of the victims said fraudsters opened new store-branded credit cards in their names, down from 29% in 2007.

> Fifteen percent reported other types of fraudulent loans were in their names, down from 21%.

Saturday, May 30, 2009

May News & Views Published Below


CU SECURITY & TECHNOLOGY News - Providing a brief summary of news and information related to security and technology issues for credit unions - Plus some interesting and fun web sites . . . and no monkey business.

Thursday, May 28, 2009

The Web's most dangerous keywords to search for

Which is the most dangerous keyword to search for using public search engines these days? It’s “screensavers” with a maximum risk of 59.1 percent, according to McAfee’s recently released report “The Web’s Most Dangerous Search Terms“.

Upon searching for 2,658 unique popular keywords and phrases across 413,368 unique URLs, McAfee’s research concludes that lyrics and anything that includes ‘free” has the highest risk percentage of exposing users to malware and fraudulent web sites. The research further states that the category with the safest risk profile are health-related search terms. (Click on chart to enlarge)

Here are more findings:

> The categories with the worst maximum risk profile were lyrics keywords (26.3%) and phrases that include the word “free” (21.3%). If a consumer landed at the riskiest search page for a typical lyrics search, one of four results would be risky.

> The categories with the worst average risk profile were also lyrics sites (5.1%) and “free” sites (7.3%).

> The categories with the safest risk profile were health-related search terms and searches concerning the recent economic crisis. The maximum risk on a single page of queries on the economy was 3.5% and only 0.5% risky across all results. Similarly, even the worst page for health queries had just 4.0% risky sites and just 0.4% risk overall.

To view the entire article, visit: http://blogs.zdnet.com/security/?p=3457&tag=nl.e539

Another wave of scams hits several states

From CUNA . . .

MADISON, Wis. (5/28/09)--Phone scams are targeting credit unions in Wisconsin, Vermont and Maryland, and credit unions are reminding members that the credit union would never contact them for account or credit card information.

Forward Financial CU, Niagara, Wis., would never call members asking for personal information because the credit union already has it, said Tammy Young, vice president of operations (UpperMichiganSource.com May 26). Forward Financial was one of two institutions recently targeted by scammers who were calling consumers and asking for personal financial information.
Members who have provided their information to scammers should contact the credit union immediately. Forward Financial can block members' debit or credit card from being used, Young said.

Cumberland, Md., police have received hundreds of reports about a phone scam in which individuals identifying themselves as Chessie FCU employees asked for account information (WCBC Wire May 26). The scammers have called homes, businesses and cell phones in the area.
Williston, Vt., residents have received calls from individuals claiming to represent New England FCU and Heritage Family CU. The callers ask recipients to supply personal account information to reactivate a credit card.

Matt Levandowski, Heritage Family CU executive vice president, said some of his credit union's members had given scammers their account information but their accounts had not been compromised.

Wednesday, May 27, 2009

Augusta Metro FCU Ads Ingersoll Rand's Biometric HandKey Reader

Augusta Metro Fed. Credit Union has implemented Ingersoll Rand Security Technologies' standalone Schlage biometric HandKey reader to provide its members with self-service access to the safe deposit vault. The technology allows members to simply punch in a code on the hand reader, presents his or her hand to the unit and, once verified, the bullet-proof glass door opens.

At the same time, the individual's safe deposit box opens and nobody can enter the vault until that member puts away the deposit box.

Today's Best News Stories

>> According to Mexican officials, the swine flu outbreak has cost Mexico $2.2 Billion. Only $2.2 Billion? Maybe we can put them in charge of GM.

>> Police say a Michigan postal worker has admitted to stealing $20,000 worth of postage stamps and trying to sell them online. The worker will be fired for breaking the Postal Service's strict rules against turning a profit.

>> The Indy 500 approaches. A race driver is like an automobile executive. If anything bad happens to the car, he has to be bailed out.

>> Los Angeles Dodgers superstar Manny Ramirez admitted he took a banned substance Thursday but was careful to point out he didn't take steroids. That's illegal. If convicted of steroids use, he could get four to eight years as governor of California.

>> The price of a stamp is up to 44 cents. It's out of control. If only there was some other way to send written messages . . . If anyone can think of anything just e-mail me.

Survey: Better rates, more ATMs top members' wish list

From CUNA . . .

MADISON, Wis. (5/27/09)--While most members report they are satisfied with their credit unions, better rates and expanded access to automated teller machines (ATMs) top their list of suggested improvements, says a recently released survey report by the Credit Union National Association (CUNA).

Click for larger view
About 45% of members surveyed would like to see their credit union pay higher savings rates than they do now, according to CUNA's 2009-2010 National Member Survey. Lower loan rates (27%) and more ATM locations (22%) rounded out the top suggestions from members.

Higher savings rates are the leading request from members age 45 and older. More ATMs topped the list for 25- to 44-year-old members, and more convenient credit union locations ranked highest with 18- to 24-year-olds.

"The desire for more convenient brick-and-mortar locations among such a technology savvy young group was interesting, and it could indicate that some young adults are doing business with a credit union located near the workplace of one of their parents, but not necessarily near them," said Jon Haller, CUNA director of business-to-business publishing.

The National Member Survey reveals trends involving members' use of financial services and attitudes, and strategies to build loyalty and attract more business. It also provides information and analysis related to members' demographics, satisfaction, interest in new services and delivery channels.

Also, the 2009-2010 Survey of Potential Members--CUNA's companion report to this survey--uncovers new issues, opportunities, and strategies for reaching and attracting new members. It analyzes current trends relating to non-members' financial behaviors and loyalty to their banks, and suggests how to leverage competitive advantages to attract eligible non-members from their current provider.

Tuesday, May 26, 2009

Our Ears May be Our Password

YOU are the victim of identity theft and the fraudster calls your credit union to transfer money into their own account. But instead of asking them for your personal details, the credit union rep simply presses a button that causes the phone to produce a brief series of clicks in the fraudster's ear. A message immediately alerts the bank that the person is not who they are claiming to be, and the call is ended.

For more on this security technology, visit: http://www.newscientist.com/article/mg20227035.200-our-ears-may-have-builtin-passwords.html

An Expectation of Online Privacy

If your data is online, it is not private. Oh, maybe it seems private. Certainly, only you have access to your e-mail. Well, you and your ISP. And the sender's ISP. And any backbone provider who happens to route that mail from the sender to you. And, if you read your personal mail from work, your company. And, if they have taps at the correct points, the NSA and any other sufficiently well-funded government intelligence organization -- domestic and international.

You could encrypt your mail, of course, but few of us do that. Most of us now use webmail. The general problem is that, for the most part, your online data is not under your control. Cloud computing and software as a service exacerbate this problem even more.

Your webmail is less under your control than it would be if you downloaded your mail to your computer. If you use Salesforce.com, you're relying on that company to keep your data private. If you use Google Docs, you're relying on Google. This is why the Electronic Privacy Information Center recently filed a complaint with the Federal Trade Commission: many of us are relying on Google's security, but we don't know what it is.

This is new. Twenty years ago, if someone wanted to look through your correspondence, he had to break into your house. Now, he can just break into your ISP. Ten years ago, your voicemail was on an answering machine in your office; now it's on a computer owned by a telephone company. Your financial accounts are on remote websites protected only by passwords; your credit history is collected, stored, and sold by companies you don't even know exist.

And more data is being generated. Lists of books you buy, as well as the books you look at, are stored in the computers of online booksellers. Your affinity card tells your supermarket what foods you like. What were cash transactions are now credit card transactions. What used to be an anonymous coin tossed into a toll booth is now an EZ Pass record of which highway you were on, and when. What used to be a face-to-face chat is now an e-mail, IM, or SMS conversation -- or maybe a conversation inside Facebook.

Remember when Facebook recently changed its terms of service to take further control over your data? They can do that whenever they want, you know.

We have no choice but to trust these companies with our security and privacy, even though they have little incentive to protect them. Neither ChoicePoint, Lexis Nexis, Bank of America, nor T-Mobile bears the costs of privacy violations or any resultant identity theft.

This loss of control over our data has other effects, too. Our protections against police abuse have been severely watered down. The courts have ruled that the police can search your data without a warrant, as long as others hold that data. If the police want to read the e-mail on your computer, they need a warrant; but they don't need one to read it from the backup tapes at your ISP.

This isn't a technological problem; it's a legal problem. The courts need to recognize that in the information age, virtual privacy and physical privacy don't have the same boundaries. We should be able to control our own data, regardless of where it is stored. We should be able to make decisions about the security and privacy of that data, and have legal recourse should companies fail to honor those decisions. And just as the Supreme Court eventually ruled that tapping a telephone was a Fourth Amendment search, requiring a warrant -- even though it occurred at the phone company switching office and not in the target's home or office -- the Supreme Court must recognize that reading personal e-mail at an ISP is no different.

This essay was originally published on the SearchSecurity.com website, as the second half of a point/counterpoint with Marcus Ranum.

http://searchsecurity.techtarget.com/magazinePrintFriendly/0,296905,sid14_gci1354832,00.html or http://tinyurl.com/pnv8vq

Tuesday, May 19, 2009

City police urge 'no hat/hood/sunglasses' policies

COLUMBUS, Ohio (5/19/09)--City police are urging the credit unions in Westerville, Ohio, to strictly enforce policies that require members to remove their sunglasses, hats or hoods when entering to avoid potential robberies.

Suzanne McCann, vice president of sales and operations at CME FCU in Columbus, Ohio, told The Columbus Dispatch Friday that she witnessed a robbery at the credit union. The robber wore a hat and sunglasses, she said.

CME has a similar "no hats, sunglasses" policy that has been enforced at every branch, the newspaper said. Some credit union members weren't happy with the policy, but McCann said the policy helps keep everyone safe.

Although only a few cities nationwide have "no hats" policies, voluntary participation is increasing, Harry Trombitas, an FBI special agent based in Columbus. Most bank robbers want to avoid conflict, and complying with a request to take a hat or sunglasses off could attract more attention, he said.

There have been 22 Columbus-area robberies this year, five fewer than this time last year, the newspaper said.

Credit unions in several states have adopted "no hat, no hoods, no sunglasses" policies. In 2003, the Delaware Credit Union League provided posters and signs to credit unions that ask member to remove these articles of clothing when they enter the credit union. The same year, the Missouri Credit Union Association adopted a similar policy.

Other states with "no hats, hoods or sunglasses" rules include South Carolina, Massachusetts and Oklahoma (News Now June 3, 2005).

Though the policies have been implemented to increase safety, they have been criticized. Earlier this year, a Muslim woman who was a member of Navy FCU said she was denied service from the credit union for wearing a traditional head scarf as required by her religion. Navy Federal contacted the member and apologized to her.

Friday, May 15, 2009

Sixty gang members nabbed in $500,000 scam vs. Credit Union

SAN DIEGO (5/15/09)--More than 60 members and associates of the San Diego Lincoln Park Street Gang were arrested Tuesday and charged with stealing $500,000 from a credit union by recruiting young credit union members to give up their account information so the account could receive counterfeit check deposits.

The gang then withdrew thousands of dollars from an ATM at a casino and the accomplice account holders, who received a portion of the payout, would file a police report for an unauthorized withdrawal, said California Attorney General Edmund G. Brown Jr. and San Diego District Attorney Bonnie Dumanis in a press release.

In a multi-agency operation termed "Bank Gig," a Tuesday morning pre-dawn sweep by more than 100 law enforcement officers took the suspects into custody. They are being held on 347 felony charges related to conspiracy, grand theft, money laundering, recruiting to commit a felony for a gang, unlawful sale of access card information , burglary and gang enhancement.

After obtaining personal account information and personal identification numbers from members of Navy FCU, gang members would deposit counterfeit checks into the members' accounts, then withdraw thousands from an ATM machine at Barona Casino near San Diego.

"The size, scope and sophistication of this operation show us that criminal street gangs in San Diego are expanding their criminal enterprise into white collar crime," said Dumanis.

The investigation began when the credit union in 2005 reported to the U.S. Secret Service a significant increase in fraud reports from young members reporting their account information and PINs had been stolen.

Thursday, May 14, 2009

Dumb & Dumber: Credit union treats member like small change

Due to a lack of timely intervention at the Okemos Branch, the MSU Federal Credit Union (Lansing) experienced a casualty Saturday. Joyce Banish, the credit union's vice president of university and community public relations, acknowledged Monday that "better judgment" would have been the proper treatment.

Kimberly Schulz, a member of the credit union, waits tables. Some of her tips come in the form of change. It's her habit to take the change to the credit union once a week or so, drop it in the coin counter, get a receipt, then deposit the total in her account.

Schulz walked into the branch Saturday and discovered that the machine was out of service. So she informed a woman at the front desk that she wished to deposit the money - all $15 dollar's worth - directly into her savings account. The woman told her that wouldn't be possible. In an e-mail to me Schulz described the encounter this way:

"I asked why and she said she had no way of counting it ... I showed her the small amount of change I had, but she said (the credit union) wouldn't take it."

Let me reiterate some key facts here: Schulz is a MEMBER. She was trying to DEPOSIT the money. The credit union's change counter was NONFUNCTIONAL. Schulz's change TOTALLED $15 (and, by the way, was mainly in quarters).

Schulz approached a teller and offered to arrange the change into one-dollar stacks. And no one, she said, was waiting in line behind her. But the teller refused to accept the money.

In her e-mail Schulz wrote: "I was flabbergasted. I understand their policy to normally not take (uncounted) change, since they have a change-counting machine right in their office. But when the machine is not working, you would think Customer Service 101 would kick in ..."
Exactly.

Responding my inquiry, Banish said the branch takes in a lot of change and that, with the coin machine down, the "no change" policy was aimed primarily at people with large bags of uncounted change.

Stopping to count it, she pointed out, could cause service delays for other customers.
Banish also said Schulz could have used a change counter at another branch.

But she conceded, in the end that "better judgement would have been to count (Schulz's change)."

Don't let this happen in your credit union.

Interesting Credit Union Names

Many credit unions with common words in their name:

> 1-in-6 credit unions have the word ‘Employee’ in their name
> Over 600 credit unions have ‘School,’ ‘Teachers’ or ‘Educators’ in their name
> 183 have ‘Postal’ in their name
> 157 credit unions have ‘Municipal’ in their name
> 110 credit unions have ‘Health’ in their name
> 108 credit unions have ‘Fire’ in their name
> 73 credit unions have ‘Police’ in their name

For more on this subject, visit:
http://thefinancialbrand.com/2008/07/01/most-common-words-in-credit-union-names/

Thursday, May 7, 2009

Meetings Are Important

Meetings Mean Business Petitionhttp://www.keepamericameeting.com/

Please sign this important petition.

Here is my posting:"Meetings directly or indirectly support one in eight Americans with important impact globally. One third of all hotel rooms are booked as a result of meetings. 20% of all airline flights are for those flying to and from meetings. The multiplier effects of meeting attendees spending their money at events, trade shows and conventions is huge! Meetings are also major educators of adults in the industrialized world.

We need to notify our legislators that meetings are not junkets -- they are vital for our economy."

Monday, May 4, 2009

Another Massive Data Breach

CBS News has learned of another data breach potentially compromising the personal information of thousands of people. Companies Lexis Nexis and Investigative Professionals have sent up to 40,000 letters to customers whose “sensitive and personally identifiable” information may have been viewed by individuals who should not have had access.

The United States Postal Inspection Service is investigating a data breach at both companies that resulted in sensitive information being used in a crime. Those individuals have been notified. Sources tell CBS News that the data breach is linked to a Nigerian Scam artist who used the information to incur fraudulent charges on victims’ credit cards.

The letters caution customers to review their credit reports for any inaccuracies, to report any errors or suspicious activity to creditors as soon as possible, and to contact the United States Postal Service if they believe their personal information may have been compromised.

Thursday, April 30, 2009

April News & Views Published Below


CU SECURITY & TECHNOLOGY News - Providing a brief summary of news and information related to security and technology issues for credit unions - Plus some interesting and fun web sites.
Join us for our annual security conference in June.

Tuesday, April 28, 2009

Risk expert: E-fraud advances require new techniques

Credit unions, their members and third-party providers of electronic funds transfer services need to improve their online security because of advances in online fraud involving personal and financial institutions computer systems, a CUNA Mutual Group risk management expert said Friday.

Electronic fraud losses are caused primarily by consumer account compromises through online banking systems and system intrusions at third-party providers of electronic services, Ken Otsuka, risk manager, told attendees at the Hawaii Credit Union League 71st Annual Convention.

Ken Otsuka, risk manager with CUNA Mutual Group, discusses electronic fraud with attendees at the Hawaii Credit Union League 71st Annual Convention Friday. Phishing scams have become a mainstream activity for fraudsters," Otsuka said. "Consumers continue to be duped by this e-mail scam and provide their account numbers and online banking passwords." Account compromises occur when members respond to phishing e-mails by clicking on embedded links that take them to bogus Web sites imitating the credit union's site.

"The branding is remarkably good, and consumers are fooled" into providing information that would allow fraudsters to open accounts with the victim's information," he said.

Read More at: http://www.cuna.org/newsnow/09/system042709-5.html?ref=hed

Friday, April 24, 2009

When you fall, how will you get back up?

We all fall at some point in our lives. A new business or product that we thought would be the next winner, turns out to be a disaster. Failure happens.

If we don't fail, we're probably not trying hard enough.

But what separates the great business leaders from the "also-rans" is how they respond to the times when they fall flat on their face.

Nick Vujicic is someone who constantly falls. And it should be impossible for him to get back up. But he does. It's an incredible story that you've got to see for yourself, especially in this tough economy. You'll be glad you did.

An incredible story.
http://www.yourbusinessgps.com/main.asp?column=1115&page=1342

Survey of Experts Finds Increase in Fraud During Economic Crisis

Intense financial pressure during the economic crisis has led to an increase of fraud, according to a survey of fraud experts conducted by the Association of Certified Fraud Examiners (ACFE). Results of the survey, published in the new ACFE report "Occupational Fraud: A Study of the Impact of an Economic Recession," also found that layoffs are pervasive and are leaving holes in organizations' internal control systems.

The survey responses of more than 500 randomly selected Certified Fraud Examiners (CFEs) were compiled by the Austin, Texas–based ACFE, the world’s largest anti-fraud organization and premier provider of anti-fraud training and education. CFEs are experts in fraud detection, prevention and deterrence, and must pass a rigorous exam as well as meet high professional, educational and ethical standards.

Read more at: http://www.earthtimes.org/articles/show/acfe-survey-of-experts-finds-increase-in-fraud-during-economic-crisis,788078.shtml

Wednesday, April 22, 2009

Dash ATM Expands Product Line to Better Serve U.S. Credit Unions

Recognizing the need to provide credit unions and other financial institutions with a single source for safe secure and reliable ATM products and services, Dash ATM, the nation’s leading manufacturer of high security environmentally controlled drive-up and walk-up ATM enclosures and kiosks, announced that the company will begin marketing state-of-the-art ATMs manufactured by Triton and Hyosung, two of the world’s largest and most respected ATM manufacturers.

Dash ATM will be the only kiosk manufacturing company in the US that can provide financial institutions with a full turn-key operation for a new ATM, a safe/secure enclosure and even take care of installation and first and second line maintenance service.

Established nearly 10 years ago, DASH ATM manufactures environmentally controlled drive-up and walk-up ATM enclosures for machines which are not equipped with level 1 safes. To date, no criminal has ever gained entry into a DASH manufactured enclosure. For more information on Dash ATM visit http://www.dashatm.com/.

Tuesday, April 21, 2009

Vendor partnerships key to fighting fraud

Credit unions plan to increase their efforts to fight fraud, and vendors should work on creating strategic partnerships to present more complete solutions, according to a recent study.

Fraud is a serious concern for financial institutions, and credit unions spend millions of dollars each year on solutions to prevent attacks, Boston-based Aite said in its new report, "Fraud Management at Retail Banks and Credit Unions: The Vendor Landscape."

"The sheer number of fraud management vendors used by financial institutions speaks to a lack of ability for any one vendor to address the gamut of fraud management needs," said Nick Holland, senior analyst with Aite Group and author of the report.

"Vendors looking at the fraud management landscape for financial institutions should realize that institutions are likely to gravitate to vendors that can provide fewer touchpoints to the overall fraud picture. Vendors should explore strategic partnerships in order to present a more complete offering," he added.

The report is based on a November 2008 survey of executives at 23 of the top 150 U.S. financial institutions. It reveals financial institutions' perceptions of fraud management technology vendors and ranks vendors in four areas: new account opening fraud detection, ID verification, authentication and ID fraud monitoring; fraud database; enterprise fraud case management; and check fraud detection.

Friday, April 17, 2009

Warn members about skimmers, 'Grandma, it's me' scams

Credit unions may want to warn their members about two types of scams circulating recently: ATM skimmers and scammers preying on older consumers by posing as a grandchild in trouble.
ATM skimmers, which are attached to ATMs or terminals to read unsuspecting consumers' card data as they use the machines, have seen attention the past two weeks.

Skimmers at three JPMorgan Chase & Co. ATMs--two Chase-branded ones in New York and a Washington Mutual-banded one in West Hollywood, Calif.--were discovered and reported by consumers using the machines (American Banker April 15).

The Chase-branded skimmers mimicked the translucent green material used to make the card slot in the NCR Corp. machines. The one in the WaMu machine was made from opaque gray plastic.

Since the cardholder's data personal identification number (PIN) isn't stored in the card's magnetic stripe, the skimmer must be paired with a camera on or near the ATM to record the numbers the consumer types on the keypad. One consumer, who didn't spot the skimmer until his card snagged on it, found a camera behind a mirror stuck on the ATM (Bank Technology News April 13).

The latest scam circulating in Ohio is the "Grandma, it's me" scam, says the Ohio Credit Union League (eLumination Newsletter April 15.

Scammers call unsuspecting seniors and in a highly excited or anxious voice say, "Hi Grandma/Grandpa, it's me." The senior will reply with the name of their grandchild (for example, "Oh, Johnny, what's wrong?") The scammers pick up on whatever name the victim uses and pretend to be a grandson. The "grandson" claims to be in trouble and needs money wired immediately to bail him out of jail or for a hospital bill.

"This is a financially and emotionally devastating scam and has occurred throughout Ohio," said the league. "Routinely educate your staff and members about circulating scams to avoid others falling victim."

Thursday, April 16, 2009

Palm Scan May Replace Log-on Passwords

Be patient. Large file is loading.

Forget your password? Don't worry about it. A scan of your hand, palm, fingerprint or face will someday replace it. Hundreds of credit unions across the country are using biometric identifcation technology to identify employees. Here's an example of one of these technologies.

Monday, April 13, 2009

Fake CU also prompts alerts in Pennsylvania

HARRISBURG, Pa. (4/13/09)--The Pennsylvania Department of Banking has issued a consumer scam alert about an entity calling itself "First Star Lending Services" and "First Star Credit Union," believed to be the same entity that received a cease-and-desist order from a Michigan regulator last week.

The Pennsylvania department warned about an apparent advance fee loan scam using the names at www.firststarlendingservices.com.

Two consumers said they applied to the company for loans ranging from $7,000 to $10,000. When they were asked to pay several hundred dollars in upfront fees to receive their loans, they became suspicious and did not send any funds.

The companies claim to be located at 1800 Loucks Rd., Suite 850, York, Pa. However, no such address exists there. First Star Lending Services claims to offer first and second mortgages, consumer loans and other financial products, but it is not licensed by the Pennsylvania Department of Banking. There is no First Star CU chartered by state or federal regulators said the department.

News Now reported that the Michigan Office of Financial and Insurance Regulation issued a cease-and-desist order against a fake credit union, "Firststar CU," claiming to be a Pennsylvania-based credit union. OFIR said the institution is a fraudulent financial institution (News Now April 10).

Sunday, April 5, 2009

US banks sign up for biometric project

The US-based Financial Services Technology Consortium has launched a project to investigate the use of biometrics for verifying customer IDs. The FSTC says over 20 banks have expressed an interest in the project, including the American Bankers Association which has signed on as a sponsor.

Dan Schutzer, executive director FSTC says the programm will endeavour to develop a methodology for banks to better select, specify, evaluate and deploy biometric applications with greater customer acceptance.

"We also hope to identify and validate at least one or two of them that will make an immediate impact in the fight against identity theft and insider fraud," he adds.

The initiative grew out of a panel discussion at a joint FSTC/Bits summit in early March. A follow-up meeting is planned for later this month at Wells Fargo Bank in San Francisco.

A global survey conducted by Unisys last year found that 72% of US citizens would be willing to undergo fingerprint scans to verify their identities when dealing with banks and government organisations.

Tuesday, March 31, 2009

March News & Views Published Below

CU SECURITY & TECHNOLOGY News - Providing a brief summary of news and information related to security and technology issues for credit unions - Plus some interesting and fun web sites. Join us for our annual security conference in June. Here's the location.
..

Stolen ID: 20 tips to protect yourself

You can take steps to protect yourself from identity fraud:

Keep your confidential information private. Your bank or credit card company won't call or e-mail to ask for your account information. They already have it.

Keep an inventory of everything in your wallet and your PDA, including account numbers. Don't keep your Social Security card or any card with your Social Security number, such as an insurance card, in your wallet.

Stop getting banking and credit card information in the mail. (See "Go paperless for safer banking.")

Monitor your bank and credit card transactions for unauthorized use. Crooks with your account numbers usually start small to see if you'll notice.

Keep your vehicle registration and insurance forms in a sealed envelope in your glove box and lock it and your car when at home or away.

If you conduct business online, use your own computer. A public computer is less secure, as is wireless Internet.

Look for suspicious devices and don't let anyone stand nearby when you use an ATM. Take your card and receipt with you. Keep your PIN in your head, not in your wallet.

Don't store credit card numbers and other financial information on your cell phone. (See "Is your cell phone spilling your secrets?")

If you're job hunting using resume Web sites, don't apply unless the employer has a verifiable address.

Protect your computer from vulnerability:

Keep system and browser software up to date and set to the highest security level you can tolerate. Install anti-virus, anti-spyware and firewall protection, and keep them up to date as well. When possible use hardware firewalls, often available through your broadband connection router.

If you use wireless Internet access, make sure that you get help from someone who understands wireless security when you set up your access point or router.

Back up your data and store it way from your computer.

Don't open e-mails from strangers. Malware can be hidden in embedded attachments and graphics files.

Don't open attachments unless you know who sent them and what they contain. Never open executable attachments. Configure Windows so that the file extensions of known file types are not hidden.

Don't click on pop-ups. Configure Windows or your Web browser to block them.

Don't provide your credit card number online unless you are making a purchase from a Web site you trust. Reputable sites will always direct you to a secure page with an URL starting with https:// whenever you actually make purchases or are asked to provide confidential information.

Use strong passwords: at least six characters, including at least one symbol and number, and no reference to your name or other personal information. Use a different password for every site that requires one, and change passwords regularly.

Never send a user name, password or other confidential information via e-mail.

Consider turning off your computer when you're not using it or at least putting it in standby mode.

Don't keep passwords, tax returns or other financial information on your hard drive.

Wednesday, March 25, 2009

Welcome to 419BAITER.COM, the land of extreme B.S.

Scamming the Scammers . . . http://419baiter.com/

To jump right in and see what this site is all about, click "The Games". Aside from some obfuscation of personal info (e-mail addresses and telephone numbers) and some text reformatting to improve readability, the e-mails depicted in these games are real and unedited in any way. Any spelling mistakes, bad grammar and adult language have been left intact.

A CAUTIONARY NOTE: Within the pages on this site, you are bound to run across some nasty language, photos, and voice/sound recordings which may be considered vulgar or offensive by some. While you certainly won't find any pornography on this site, some material on this site may offend some people.

Most of you have, at one time or another, received "Urgent Business Transaction" e-mails from someone asking for assistance in retrieving huge amounts of money in return for a good-sized percentage of the take. Maybe it's an e-mail informing you that you've won a lottery that you've never bought a ticket for. Maybe it's a job offer cashing checks in return for a commission.

These are known as Nigerian 419 e-mails. 419 scam baiting involves responding to these e-mails posing as a potential victim of their scam and getting them to trust you to the extent that they waste a lot of their time and hopefully some money trying to bilk you out of your hard-earned cash. With luck, the scammers also provide for a few laughs along the way.

This site is dedicated to this little-known but growing Internet sport.

These scams are named after section 419 of the Nigerian penal code which deals with this type of scam. However, Nigeria is certainly not the only country from which these e-mails originate. I have had these e-mails come from virtually every part of the world - Europe, Asia, Africa, Australia, UK, Canada, etc. This site will consider dealing with any type of advance fee fraud proposal that arrives by e-mail, regardless of its origin.

And it's not only poor and/or uneducated street criminals that perpetrate these scams. Many of these scammers are very well educated. Often bureaucrats are involved, either acting on their own or with the blessing (and even the support) of their corrupt government bosses, as demonstrated by these scam e-mails sent from a Malaysian government computer or this one sent from a Brazilian government computer.

You can find plenty of examples of some of the most popular formats along with explanations on the 419 Scam Examples page.

Thursday, March 19, 2009

CUs warn of rash of automated phishing calls

Several credit unions nationwide are reporting an uptick in the number of automated phishing calls seeking to obtain personal information from members.

Some recent incidents:

1. Several Wisconsin credit unions report scam artists are using automated phone calls with recordings that ask members to divulge personal financial information, according to the Wisconsin Credit Union League. Phishing calls reported Tuesday claimed the member's credit and/or debit card had been locked and asked for the card number to unlock it. The Credit Union National Association also noted variations on scam tactics and said unsolicited requests for personal information have circulated under the subjects: "Account Deactivation," "Account Status Alert," "Changes to Terms and Conditions," and "Irregular Activity."

Click here to read about 9 other credit unions hit by phishers.
http://www.cuna.org/newsnow/09/system031809-6.html?ref=hed

Wednesday, March 18, 2009

Weight-Revealing Billboard Shames Fatties into Joining Gym

(Click on photo to see full picture)

Here we see the results of an ad campaign for the gym chain Fitness First. The bus stop seat has a scale inside, hooked up to a readout on the billboard. The idea is to shame overweight bus-goers into signing up, and we love it. The campaign was designed by Amsterdam based agency N=5, and ran in the Netherlands.

That last part is probably the most relevant. Can you imagine something like this running in the US? The company responsible would be sued out of existence in about five seconds, a class action lawsuit citing "psychological damage" or some such nonsense.

Worse, though, would be the result if this ad were to run in England. I can (quite seriously) imagine children (who should be in school) lying in wait with bags of cream cakes, ready to throw them at anyone over 200lbs who has the naivete to sit on the scale.
Fitness First "Bus Stop" [

Navy Federal Tweaks Anti-Robbery Policy

The biggest credit union in the U.S. has modified its policy on head coverings in branches to move the emphasis away from whether a member's head is covered to whether the member's full face can be seen.

The $36 billion Navy Federal's previous policy which required credit union members to remove head coverings when they entered credit union branches had led to complaints from a muslim female member who had been asked to conduct her transaction in a another room at the branch because she wore a head covering for religious reasons.

“The policy is that head coverings for religious reasons, cultural reasons, economic reasons are all acceptable, as long as we can see the members full face,” explained Tom Lyons, senior vice president for security for the Vienna, Virginia based federal credit union. “Our emphasis is on safety of our members and on preventing robberies and identity theft,” he said.

Lyons said the credit union had begun to implement the policy of asking members to remove head coverings and sun glasses when entering the branch as the economic downturn had begun to make robberies more likely.

Monday, March 16, 2009

The Starbucks Economic Indicator

The economic indiacator I monitor is the Starbucks at 290 & Spring Cypress Rd.

I pass there every Sunday @ 1:00 pm.Last Spring there would be 8-10 cars in line, now I usually see no more than two and sometimes none.

Another indicator is the advancing age of the workers at Starbucks, Papa Johns or other retail stores. 2009 is going to be a TOUGH year.

Saturday, March 7, 2009

TOP TECHNOLOGY BREAKTHROUGHS

1) Wireless world
2) Defense technology
3) Alternative fuel vehicles
4) Biotechnology
5) Computers
6) Lasers
7) Genomics
8) Global finance
9) Processors
10) Digital storage
11) Space
12) Fiber optics
13) Satellite TV & radio
14) DNA testing
15) Video games
16) Biometrics
17) Energy and water savers
18) Scanning tunneling microscopes
19) Batteries
20) E-baggage
21) Remote controls
22) Animal cloning
23) Manufacturing technology
24) The big picture
25) Weather technology

Friday, March 6, 2009

Hoax Busters - the BIG LIST of Internet Hoaxes

An alphabetical list of Internet hoaxes, scams and chain letters. If it's on the list, it's a hoax. Please, if any doubt, check it out. - http://www.hoaxbusters.org.

Thursday, March 5, 2009

Harland Announces UltraData, Cavion Signings

Harland Financial Solutions said several more credit unions are now using its UltraData Enterprise core processing solutions.

That includes $1.2 million Genisys CU of Auburn Hills, Mich., which is the result of a recent merger between T&C FCU and USA CU. T&C already was an UltraData user.

The Lake Mary, Fla., company also said $103 million Bull Dog FCU will go live with an in-house UltraData platform on March 1. The Hagerstown, Md., credit union now is an Open Solutions customer, according to its 5300 Call Report. Meanwhile, $14 million Syracuse Cooperative FCU in New York will convert to a service bureau core processing relationship with UltraData. It currently is a CompuSource Systems client, according to NCUA records.

Two Huron, S.D., credit unions–$13 million Huron Area FCU and $3 million HB Telco FCU–will be converting from HFS’ CuServ platform to UltraData enterprise in a service bureau environment, the company said.

More than 550 credit unions now run UltraData, including more than 200 through the company’s service center in West Des Moines, Iowa.

The company also said it has signed 119 new users of its Cavion Internet Banking service in 2008 and 42 users of its Cavion Mobile Banking Professional service since it was launched several months ago.

Tuesday, March 3, 2009

Register 1 and Send More At No Cost

St. Louis, January 30, 2009 – William Rogers & Associates, sponsor of the CU InfoSECURITY Conference, announced that they are reducing their previously announced conference fee from $895 to $795. The reduction was brought about in discussion with the conference host site, MonteLago Village Resort at Lake Las Vegas, and as way to help credit unions receive much needed security information during these difficult economic times.

We have also announced a special registration. Register 1 person at the regular rate of $795 and send others from your credit union at no extra cost. The extra persons will be responsible for their lodging. That's it. The dates are June 4-5, 2009.
..

Conference Manager Bill Rogers said, “We’re pleased to pass this savings on to our conference attendees. This makes the conference even more valuable and affordable.” Rogers adds that “the conference registration fee includes two free nights lodging at a beautiful 5 star resort – a unique feature that only we offer to further help credit unions afford this one of a kind conference.” The CU InfoSECURITY Conference is the only conference in the credit union movement offering two nights lodging as part of their low conference fee.

Rogers added, “This is our 8th annual conference focusing on security issues facing credit unions. Security continues to be a top of mind issue for credit unions of all sizes. With over a dozen security expert speakers, a security tour of a Las Vegas credit union for pre-conference attendees, vendor exhibits and two nights free lodging, this makes for an outstanding program. It’s the best value in the credit union movement.”

The conference agenda, registration and more information is available at: https://www.cunews.com/infosec.htm.

February News & Views Shown Below

CU SECURITY & TECHNOLOGY News - Providing a brief summary of news and information related to security and technology issues for credit unions - Plus some interesting and fun web sites.



(Click on all photos to enlarge)

Tuesday, February 24, 2009

ATM thieves drain $60,000 from machine, camera helps catch them

Arlington police are investigating a string of thefts in which a group of people apparently tricked a cash machine out of $60,000 over several months.

The thefts occurred at one Boeing Employees Credit Union machine in the Smokey Point area of Snohomish County, said BECU spokesman Todd Pietzsch.

Pietzsch said the thieves were able to trick the machine's software program in a way that caused it not to recognize that it had dispensed money, and it would then dispense money again, "so they were actually getting twice as much as they should have."

Banks, Credit Card Firms Wait For The Other Shoe To Drop Amid Reports Of Another Payment Processor Breach

Hack of a second U.S.-based payment processing firm exposes accounts used in Internet, phone transactions, according to credit union alerts

Brace yourself for another payment-processor breach: A second U.S.-based payment acquirer/processor has been hit with a network hack that exposed consumers' credit card accounts.
As of this posting, the victim firm's identity had not been revealed. According to several credit unions, Visa recently alerted them that another payment processor had discovered a data breach. Among the credit unions issuing alerts about the breach on their Websites are The Tuscaloosa VA Federal Credit Union and the Pennsylvania Credit Union Association. The Open Security Foundation has a notice posted on its DataLossDB site.

The latest breach follows that of Heartland Payment Systems, which went public on Jan. 20 about discovering malware on its processing system; some security experts have called it the largest security breach ever. Heartland processes 100 million payment card transactions per month for 175,000 merchants.

While details on the latest hack are still emerging, there is one known difference between it and Heartland's: This latest breach exposed so-called card-not-present transactions -- online and call-based transactions -- and not magnetic-stripe track data. Primary account numbers and expiration dates were stolen from the firm's settlement system, according to the Tuscaloosa VA Federal Credit Union.

Tuesday, February 17, 2009

Give Every Member a Branch of Your Credit Union

Branchless banking’ allows an individual to have a remote bank account that is accessed and managed through their mobile phone or other technologies. This could mean those with no chance of using traditional banks – because they are either too poor or the nearest bank is miles away - will be given the opportunity to save money, gain access to credit and receive money sent from family members in other countries.

The potential market for technology and mobile phone companies is huge, and by piggy-backing on existing technologies and infrastructures, the transaction cost can be much cheaper than traditional banks. For example a study in India showed it costs $1 per transaction in a bank, 40-50 cents per transaction from a cash machine and only 10 cents when a smart card is used.

(For the rest of the story, visit: http://www.dfid.gov.uk/news/files/SoS-FAST.asp

Tuesday, February 10, 2009

Cherry Valley woman sentenced for taking $1 million from credit union

A 40-year-old woman was sentenced to nearly four years in prison for embezzling more than $1 million from the Rock Valley Federal Credit Union.

Lisa Farel was given three years and seven months in prison, as well as five years of supervised release. In October of last year she pleaded guilty to taking more than $1 million from the credit union over a 15-year period starting in 1993. Farel was manager of the credit and debit card portfolio department during that time.

After being charged, she admitted to manipulating 73 credit card accounts after pretending to close them.

Number of ID fraud victims up 22%

The number of identity fraud victims in 2008 increased 22% to 9.9 million adults in the U.S., according to the 2009 Identity Fraud Survey Report, issued Monday by Javelin Strategy & Research.

However, the total annual fraud amount rose only slightly--7%--to $8 billion during the past year, the survey said (Business Wire Feb. 9).

Javelin, based in Pleasanton, Calif., is an independent provider of quantitative and qualitative research focused on financial services topics.

Other key survey findings:

>> Overall identity fraud incidents increased in the U.S. The number of identity fraud incidents in 2008 rose by 22% over 2007, which brings the number back up to levels not seen since 2004. Javelin said the rise was due to economic misfortune. Historically, higher rates of fraud occur when the economy worsens. Identity fraud remains substantially lower overall when compared to the 2004 level of $60 billion.

>> Cost to consumers is down. The mean consumer cost of identity fraud decreased 31% to $496-- its lowest level since 2005--from $718 per incident. The lower cost per incident is attributable to faster detection of fraud, lower fraud amounts, and quicker resolution times thanks to industry efforts and consumer education, Javelin said.

>> Fraudsters are moving much more quickly. In cases where identity fraud was reported, 71% of the fraud incidents began occurring less than one week from when the data was stolen, up from 33% in 2005. The dramatic increase points to more sophisticated attacks by fraudsters and an increasing number of "attacks of opportunity" in which people or businesses leave data exposed.

>> Gender disparity. Women were 26% more likely to be victims of identity fraud than men in 2008. Women are making more purchases in stores, and more women than men experienced breaches last year.

>> Low-tech methods still most popular. Lost or stolen wallets, checkbooks and credit and debit cards were still the most likely avenues of fraudsters' attacks. These avenues totaled 43% of all incidents in which the method of access was known. By protecting their information, consumers can significantly lower their risks, Javelin said.

Friday, February 6, 2009

CU Stages Robbery Drill

LOMPOC, Calif. — Credit unions staging mock robberies have fallen out of favor with some authorities in recent years, but the $660 million CoastHills Federal Credit Union still uses the practice and credits it with preventing a recent potential robbery.

In the mock “take over” style robberies, real time drills in two CoastHills branches, run by local police authorities, mimicked the circumstance where a robber brandishes a weapon and otherwise takes control of the branch for the duration of the robbery. In the case of the drills, the mock robberies were limited to 30 minutes.

Video tapes are made of the mock robberies and then examined later for use as teaching tools as credit union staff are trained in their responses to a robbery, the credit union said.

Even though the majority of robberies are not the “take over” type, the credit union pointed out the numbers of robberies in its immediate area has been rising, along with robbery numbers across the country.

Wednesday, February 4, 2009

Credit Union Says They Identified Passwords for 80% of Staff

People and passwords—in the long run, they just don't work very effectively together. At least that's what Phil Fowler, vice president of IT at Telesis Community Credit Union, a Chatsworth, Calif.-based financial services provider that manages $1.2 billion in assets, found out. His team ran a network password cracker as part of an enterprise security audit last year to see if employees were adhering to Telesis' password policies. They weren't.

"Within 30 seconds, we had identified probably 80% of people's passwords," says Fowler, whose group immediately asked employees to create strong passwords that adhered to the security requirements. A few days later, the team ran the password cracker again: This time, they cracked 70%. (Click on photos to enlarge)

"We couldn't get [employees] to maintain strong passwords, and those that did forgot them, so the help desk would have to reset them," says Fowler. Telesis decided to secure network and application access with a biometric system that eliminated the need for user IDs and passwords, opting for the DigitalPersona fingerprint system from DigitalPersona Inc. in Redwood City , Calif.

Telesis rolled out fingerprint-based network and systems access technology in its headquarters and credit-union branches. Once Telesis has thoroughly tested the system, the company will deploy it in the offices of Business Partners LLC, its business loan services partner. Users no longer need to remember IDs and passwords because DigitalPersona authenticates enrolled personnel via fingerprint scanners, tying the fingerprints to 256-character passwords that it randomly generates every 45 days.

Friday, January 30, 2009

January News & Views Below


CU SECURITY & TECHNOLOGY News - Providing a brief summary of news and information related to security and technology issues for credit unions - Plus some interesting and fun web sites.

(Click on photos to enlarge)

Women Are Better at Financial Planning Than Men


Dan was a single guy living at home with his father and working in the Family business.

When he found out he was going to inherit a fortune when his sickly Father died, he decided he needed a wife with which to share his Fortune.
One evening at an investment meeting he spotted the most beautiful woman he had ever seen. Her natural beauty took his breath away.

"I may look like just an ordinary man," he said to her, "but in just a few years, my father will pass, and I'll inherit $20 million." Impressed, the woman obtained his business card and three days later, she became his stepmother.

Women are so much better at financial planning
than men.

Monday, January 26, 2009

Beware the debit card swindlers

Five seconds.

"We've looked at the videotape, that's how long it took," said Detective Steve Cook of Hamilton Police Services major fraud unit.

Five seconds was all the fraudsters needed to install the equipment that would rig an automatic banking machine to capture the debit card information from unsuspecting users.

"One guy standing behind to block the view, the other guy takes the pieces out of a gym bag," said Cook. "Five seconds, he walks away, and it's ready to go."

But this is no amateurish duct-tape-and-chewing-gum job being pulled off.

To an untrained eye, it would be difficult to detect that the machine had been compromised.
The level of sophistication involved in today's typical debit card fraud is staggering -- tiny computer processors attached to bank machines, miniature cameras, Bluetooth wireless technology, magnetic stripe encoders, portable safes.

As technology evolves, there's a corresponding evolution in criminal techniques.

Read the rest of this interesting story at:

http://www.thespec.com/News/Discover/article/501278

Scam alerts flooding several states

MADISON, Wis. (1/26/09)--

Credit unions nationwide are reporting that their members have been targeted by scams--including scams that have origins overseas.

Achieve FCU, Berlin, Conn. said that two dozen of its members lost money after sending debit card passwords to scammers that requested personal financial information (The Hartford Courant Jan. 23). The scammers had contacted members saying their accounts had been frozen.
One member lost $2.76--all she had in her account--while others lost $400, which is the maximum amount a member can withdraw in one day, Mary Budnick, Achieve vice president of operations, told the newspaper.

The scammers that targeted Achieve members were located in Romania and in Spain (Journal Register News Service Jan. 22).

The Federal Deposit Insurance Corp. (FDIC) warned its consumers, businesses and financial institutions Jan. 15 about fraudulent e-mails purporting to be from the Federal Reserve Bank. The e-mails state that a phishing attack has hit the Fedwire system and recipients are asked to click on links for more information.

More info at: http://www.cuna.org/newsnow/09/system012309-7.html?ref=hed

Saturday, January 24, 2009

Get Your Credit Union to Stand Out in a Crowd

If you really want to be noticed, get yourself a mascot. He’ll stand out in a crowd anywhere. We guarantee it. More credit unions today are using mascots to represent their credit union in a variety of different ways. Here are just a couple.




For more, visit Kincaid Karacter Mascots at http://www.kincaidkaracter.com/karacters/index.html
http://www.kincaidkaracter.com/

First Capitol Business Centre
2277 First Capitol Drive
Saint Louis, Mo. 63301
Phone 636-947-8822
karacter@kincaidkaracter.com

Friday, January 23, 2009

Locating a Private Individual

The following was posted on US.Gov on December 5, 2008.

Question

Locating a Private Individual

Answer

There are several organizations that might be able to assist you in locating a private individual. Please review the policies and guidelines for each agency/organization below.

Internal Revenue Service (IRS)
The IRS may forward a letter to someone when humane reasons are involved. For example:

* To notify someone of a serious illness, imminent death, or death of a close relative
* To seek an individual for a medical study to detect and treat medical defects
* To notify an individual, who cannot otherwise be located, that he or she is entitled to certain assets
* The IRS will forward a letter from an attorney, estate administrator, or other person who directly controls the assets

If you would like the IRS to help you locate an individual, place a personal letter addressed to the individual in a blank envelope. Include first class U.S. postage, and do not seal the letter. Place the unsealed letter in another envelope and address it as follows:

Internal Revenue Service
Office of Disclosure Operations
1111 Constitution Avenue NW
Washington, D.C. 20224

Social Security Administration (SSA)
The SSA will attempt to forward a letter to a missing person for reasons similar to those mentioned in the IRS section above. There is a $25.00 charge for forwarding letters to inform people about money or property they may be owed. Humanitarian letters are forwarded free of charge.

Follow the same guidelines above for sending a letter, and address it as follows:

Social Security Administration
Letter Forwarding
PO Box 33022
Baltimore, MD 21290-3022

The Salvation Army
The Salvation Army has operated a Family Tracing Service since 1885. The service is designed to help people establish contact with close relatives they may have lost touch with a few years ago or many years ago. The service is available in many of the 100 countries where the Salvation Army is located.

The Salvation Army will not help to locate someone in the following instances:

*
Friends
*
Situations where adoptions have taken place
*
Alleged fathers of non-marital children
*
Young people under 17 years of age
*
Former husbands or wives
*
Spouses for divorce purposes
*
Estate or similar business matters
*
Genealogies

In the United States, you may contact a Salvation Army territory office for your state. Local Salvation Army office numbers are listed in your local telephone directory.

Department of State (DOS)
The Overseas Citizens Services section of DOS will help locate relatives or friends who are overseas when there is concern about their welfare or a need to notify them of emergencies at home.

The Privacy Act requires that U.S. citizens over the age of 18 provide a Privacy Act waiver before information about them is released to a third party.

People in the United States may inquire about the welfare or whereabouts of U.S. citizens abroad by calling Overseas Citizens Services at 1-888-407-4747 or 1-202-501-4444. You may also contact the American Citizens Service Section of the nearest U.S. embassy or consulate directly.

You will need to include the following information before you call or contact the DOS:

* Your full name, address, telephone number and relationship
* The name of the person abroad
* Their date and place of birth
* Their passport number (if known)
* Their last known address and phone number
* Their itinerary
* Reason for their travel/residence abroad (business, tourism, etc.)
* Date of last contact
* Other points of contact abroad (friends, relatives, business associates, etc.)

For emergency messages, also include:

* Nature of the emergency
* What message should be provided to the person
* Name, address, telephone number and relationship of person you wish to be contacted after the emergency family message is delivered by the U.S. embassy or consulate

The United States Military
The military may also be able to help you locate the address of a servicemember. For immediate family members and government officials, the search is free. Other family members, civilian friends, businesses and others must pay $3.50. The check or money order must be made out to the U.S. Treasury and is non refundable.

You will need to provide as much identifying information on the military member as possible, such as:

*
Name
*
Rank
*
Last duty assignment
*
Last known military address
*
Service number
*
Social Security number

Please note: Because privacy regulations may limit the government's ability to provide you specific contact information for the person you are trying to locate, many people find that private sector resources can be quite helpful. While there are a number of free or fee-based services available through commercial sites on the Internet that you may opt to use in your search, the government cannot recommend or endorse any such service.
..

How To Stop Receiving Spam from Your Friends & Family

The following is an e-mail which you can send to friends and family asking that they stop sending spam type e-mail . . . all done anonymously.

Hi,

One of your friends has sent you this message from StopForwarding.Us, the website that allows individuals to politely and anonymously email their friends and ask that they stop the habit of sending forwarded emails or FWDs.Please do not forward chain letters, urban legends, potentially offensive jokes, videos or photos without being asked or first receiving permission.

If you find something that you want to pass on and you genuinely think the recipient will enjoy it then forward it to that person only (not in an email blast to all your friends and family) and include a personal note about why you enjoyed it and why you think they will too. Avoid sending forwards to friends or relatives that you've grown distant with. It can be frustrating for the recipient when the only correspondence he or she has with someone is via impersonal, unwanted email.

For more tips on email etiquette, visit www.StopForwarding.Us

Thank you,

A Friend (via www.StopForwarding.Us )

Worm Infects Millions of Computers Worldwide

January 23, 2009

<http://www.nytimes.com/2009/01/23/technology/internet/23worm.html?ref=science>

A new digital plague has hit the Internet, infecting millions of personal and business computers in what seems to be the first step of a multistage attack. The world’s leading computer security experts do not yet know who programmed the infection, or what the next stage will be.

In recent weeks a worm, a malicious software program, has swept through corporate, educational and public computer networks around the world. Known as Conficker or Downadup, it is spread by a recently discovered Microsoft Windows vulnerability, by guessing network passwords and by hand-carried consumer gadgets like USB keys.

Experts say it is the worst infection since the Slammer worm exploded through the Internet in January 2003, and it may have infected as many as nine million personal computers around the world.

Worms like Conficker not only ricochet around the Internet at lightning speed, they harness infected computers into unified systems called botnets, which can then accept programming instructions from their clandestine masters. "If you’re looking for a digital Pearl Harbor, we now have the Japanese ships steaming toward us on the horizon," said Rick Wesson, chief executive of Support Intelligence, a computer security consulting firm based in San Francisco.

Many computer users may not notice that their machines have been infected, and computer security researchers said they were waiting for the instructions to materialize, to determine what impact the botnet will have on PC users. It might operate in the background, using the infected computer to send spam or infect other computers, or it might steal the PC user’s personal information.

More information at:

<http://www.nytimes.com/2009/01/23/technology/internet/23worm.html?ref=science>

Wednesday, January 21, 2009

Computer Worm Affected 10+ Million Computers

A complex computer worm has infected corporate networks and has affected more than 10 million computers this week, experts say. Infecting computers in the U.S., Europe and Asia, the Downadup worm - which focuses on Microsoft Windows - scans company networks trying to guess passwords in order to access corporate networks, experts found. If the password is guessed, the worm can then infect a computer and the entire network of servers it is connected to.

As a result, experts are calling for all computer users to install a patch from Microsoft and to use long, difficult passwords that cannot be deciphered.

Read the entire article at: http://blogs.techrepublic.com.com/security/?p=740&tag=nl.e550

Card Data Compromised in Breach, Insurer Says Millions of Card Numbers Might Be Compromised

Despite Heartland Payment Systems' attempt to play down the significance of a security breach in a recent announcement, it appears that hackers were able to compromise a significant number of card accounts, according to CUNA Mutual Group.

"Although the exact number of affected cards is not known, it is expected to be many millions. Card-issuing credit unions and their members will be impacted by this breach," said Chuck Cashman, an executive with CUNA Mutual's Plastic Card Insurance.

The insurer reported that Visa and MasterCard have confirmed a significant number of credit and debit card accounts were compromised in the 2008 breach, which the company announced on Jan. 20.

Cashman said the insurer had been looking into a spike in card fraud since October 2008.
"CUNA Mutual Risk Management detected that something big was happening," Cashman said. "We reported our findings to both card associations to help facilitate an investigation to determine if a breach had occurred and, if so, its origin. It seems our worst fears are coming true, but we are relieved that it's finally been solved."

Monday, January 19, 2009

Analyst: Obama may spend a billion on biometrics

The Obama administration is likely to spend $750 million to $1 billion on biometric applications this year, primarily in defense, intelligence and homeland security, according to a new report from Jeremy Grant, an analyst for the Stanford Group Co. research firm.

Key programs at the Defense Department could result in $500 million to $600 million in biometrics contracts, and intelligence programs could add another $250 million to $350 million, Grant said. Other major programs contributing to the growth include the Homeland Security Department’s U.S. Visitor and Immigrant Status Indicator Technology and Real ID Act of 2005, the FBI’s Next Generation Identification and Homeland Security Presidential Directive-12, he said.

“U.S. identity solutions projects should survive intact through the presidential transition and the industry should continue to do well in the Obama administration,” Grant wrote. “Still, the distractions of the transition -– magnified by the economic crisis -– will slow some projects and delay the creation of new ones.

We forecast flat government spending for 2009 outside of several key programs, as a new administration takes a year to review and reshape existing initiatives.”

Samsung camera recognizes faces, names, shoe sizes...

Facial recognition is fast becoming a standard feature on compact cameras. But Samsung’s latest camera purports to take the technology to new heights.

The nine-megapixel ST10 can recognize individual people by analyzing faces as the shutter button is pressed, Samsung says.

The feature requires a little setting up. For example, you may have to take several snaps of Adam from different angles before the ST10 can automatically recognize him in future shots.
The technology also prioritizes friends, family and the frequently photographed so that the camera's smile mode will only take photos of recognized faces when they’re grinning.

Radical new tire design by Michelin. The next generation of tires.

These tires are airless and are scheduled to be out on the market very soon. The bad news for law enforcement is that spike strips will not work on these tires.This is what great R&D will do, and just think of the impact on existing technology: a... no more air valvesa... no more air compressors at gas stations and no more repair kitsS

CLICK BELOW AND SEE.These are actual pictures taken in the South Carolina plant of Michelin. It will be awhile before they are available to the automotive industry.

Smoking Shortens Lives

Technology to block phones in cars isn't foolproof

Many parents would love to be able to give their teenagers a cell phone that couldn't be used while driving. Now some inventors say they have come up with ways to make that possible, but they appear to be relying on wishful thinking.

One product to hit the market, $10-a-month software by Dallas-based WQN Inc., can disable a cell phone while its owner is driving. It uses GPS technology, which can tell how fast a person is traveling. But it can't know whether the person is driving — and therefore it can needlessly lock a phone. WQN, which sells cell phone and Internet security software under the name WebSafety, says it signed up about 50 customers for its first month of service.

(Read the rest of this interesting story at: http://news.yahoo.com/s/ap/20090119/ap_on_bi_ge/tec_cell_phones_driving