Tuesday, September 1, 2009

CU Tech Conference Highlights the Fall Season; Coming November 9-12, 2009

CU InfoTech '09 is an innovative, comprehensive conference on credit union IT issues, products and strategies. CU InfoTech is in its 15th year and is the only conference totally dedicated to technology issues. Communicating with other credit unions is more important today than never before. No webinar or written communication can replace face-to-face technology networking.

(Click on photo to enlarge)

You can learn how to enjoy operational efficiency and profitability in the pre-conference workshop on Monday, November 9. Then join in the conference program on Tuesday and Wednesday which includes:

> Future Technology and Your Credit Union

> Next Generation Risks

> Leveraging Technology and Attracting New Members

> Reinventing Information Technology

> An inside Look at Mobile Banking

> Identity Theft and Where We're At Today

> Web Application Firewalls

> The Art and Science of LoanAcquisition

The legendary Riveria Resort & Spa in Palm Springs, CA creates an inspiring atmosphere for CU InfoTech '09. Click on the above photo for a great look at the Riveria.

For a brochure on the entire program, click here: http://cuconferences.com/tech09/09%20InfoTech%20FINAL.pdf

Wednesday, August 26, 2009

NCUA Warns of Phony Fraud Alert

The NCUA is urging federally insured credit unions to be on the lookout for a bogus Letter to Credit Unions accompanied by two compact discs.

The letter, which purports to be a fraud alert, has so far been received by one federal credit union. It is numbered “09-FCU-09” and deals with phishing scams.

The agency urges people not to run the compact discs because it could corrupt security.

Credit unions receiving this package or a similar package should contact your NCUA Regional Office or the NCUA Fraud Hotline at 1-800-827-9650.

Monday, August 24, 2009

Credit Unions Receive Fraud Buster Awards

The Financial Services Centers Cooperative Inc. (FSCC) shared branching network announced last week 30 of its client credit unions will receive awards for stopping more than $930,000 in fraud activity during first and second quarters of 2009.

Recipients of the Fraud Buster Awards are recognized for protecting their credit unions, their members and members of other credit unions from fraud. Credit unions stopped fraud at every touch point in the system, said FSCC.

"The award recipients demonstrated their commitment and diligence in preventing fraud for members nationwide. It is not just their members who would be impacted, but also members of other credit unions," said Sarah Canepa Bang, FSCC president/CEO.

Financial institutions and businesses lose more than $48 billion annually from fraudulent activities, according to the Federal Trade Commission.

"Fraud is one of the most expensive security challenges facing credit unions today. And as a (credit union service organization), it is our duty to provide tools that support prevention and training for credit unions," added Bang.

FSCC's Operation Advisory Committee of stockholder credit unions reviews activity and looks at ways to prevent and detect fraud through rule changes, products and services. The committee organized the awards program in 2000.

In eight years, credit unions have stopped more than $7.4 million in attempted fraud, said FSCC.

Wednesday, August 19, 2009

It's OK to Write Passwords on Post-it Notes . . . Providing! The Perfect 4-Character Password

My kids love going to the Web, and they keep track of their passwords by writing them on Post-it notes.

I noticed their password was "MickeyMinnieGoofyPluto" and asked why it was so long."Because," my son explained, "they say it has to have at least four characters."

Tuesday, August 18, 2009

Stopwatch Measures How Long It Takes to Load a Web Page

Would you like to know how long it takes to load your credit union's webpage? This program will measure the time for you. Enter the URL to be measured and watch the top of the window.

The StopWatch can only measure websites that can be displayed in a frame. Some websites use javascript to break out of frames. This is not a StopWatch bug.

Click here to check your credit unions website: http://www.numion.com/Stopwatch/index.html

Monday, August 17, 2009

Man gives teller ID before robbing Credit Union

A 34-year-old man is in custody after authorities say he gave a teller his account number and showed her his picture ID before robbing an Anchorage credit union.

The FBI says Jarell Paul Arnold of Anchorage is being held on federal bank robbery charges.
The FBI alleges Arnold walked into an Alaska USA Federal Credit Union branch Friday and inquired about the balance on his account. The teller asked for his name, account number and ID.

Authorities say he complied, and then handed over a receipt with a note on the back that said he had a gun and demanded money. The FBI says he got away with about $600. Authorities arrested Arnold on Monday. Duh!

Court records say Arnold was sentenced to 57 months in prison for bank robbery in 2004.

ATM Problems: Mouse Rolls in the Dough

An ATM deployer in Oregon discovered recently that a mouse was responsible for some of the losses it had experienced at its machine.

According to press reports, an employee at the Gem Stop Chevron in La Grande was surprised to find a mouse inside the ATM, happily nesting on a bed of shredded $20 bills.

The ATM continued to function despite the mouse, employees said. The mouse had chewed up two bills and damaged another 14 to make his nest, but the deployer reinserted all the money that wasn't extensively damaged.

The deployer released the mouse and employees could not answer questions about how the mouse got inside the machine.

Sunday, August 16, 2009

Scammers try to horn in on 'clunkers' program

CUNA - http://www.cuna.org/newsnow/09/system081309-8.html?ref=hed

WASHINGTON (8/14/09)--The Credit Union National Association (CUNA) is warning credit unions to educate their members about scammers seeking to take advantage of the recently renewed Cash for Clunkers program. The Better Business Bureau (BBB) has reported that identity thieves are using the program to skim sensitive information from consumers.

The National Highway Traffic Safety Administration, prior to the passage of the Cash for Clunkers legislation earlier this year, reported websites that were soliciting for the names, addresses and Social Security numbers of potential customers, said BBB.

Consumers also reportedly have been solicited by companies that offer to help fill out the paperwork needed to receive vouchers to take part in the program.

The BBB has informed potential program participants that they do not need to register or receive a voucher to participate in the Cash for Clunkers program. Also, auto dealerships, not individuals, are responsible for filling out any paperwork associated with the program.

The program, which gives car buyers up to $4,500 for trading in older, gas-guzzling vehicles for more fuel-efficient cars, was responsible for an estimated 250,000 new car sales in July.
The BBB recommends that interested participants consult the official government site for the program, cars.gov, to answer any questions they may have.

Thursday, August 6, 2009

When it Comes to Business: Common Sense VS. Nonsense

“It’s unwise to pay too much, but it’s worse to pay too little. When you pay too much, you lose a little money – that is all. When you pay to little, you sometimes lose everything, because the thing you bought was incapable of doing the thing it was bought to do. The common law of business balance prohibits paying a little and getting a lot – it can’t be done. If you deal with the lowest bidder, it is well to add something for the risk you run, and if you do that you will have enough to pay for something better.”

… John Ruskin (1819-1900)

Wednesday, August 5, 2009

Fraud report: Call center fraud is evolving

CUNA: http://www.cuna.org/newsnow/09/system080409-7.html?ref=hed

Cybercriminals are infiltrating the call center, with scams evolving into a new criminal professional call service that can spoof any number in the U.S. and offer cash out in multiple languages.

According to RSA Anti-Fraud Command Center's monthly Online Fraud Report for June, the service enables phone numbers to be customized depending on the state where the account holder resides. It also enables fraudsters to accept incoming calls, posing as the genuine account holder.

"Service providers in the underground have evolved phone fraud services into a singular location to provide other fraudsters with the ability to conduct phone channel fraud to any destination and in any language," the report said.

The service helps the cybercriminals to increase their profits while significantly lowering the risk of exposure, said RSA.

Other findings for June:

> More than 13,000 phishing attacks were identified, a 10% increase from May and the highest in 11 months;

> Attacks against credit union brands remained constant--at 18%, the same as in May. After peaking at 38% of attacks in February, attacks against credit unions dropped to 22% in March and 14% in April.

> Attacks against regional bank brands increased 60% while national brand attacks dropped more than 50%; and

> Fast-flux attacks, the denial of service using sophisticated networks of computers called botnets, increased by 5% to make up 56% of the hosting methods of attacks. Hijacked websites accounted for 26% of the attack methods.

Sunday, August 2, 2009

July News & Views Published Below

CU SECURITY & TECHNOLOGY News - Providing a brief summary of news and information related to security and technology issues for credit unions - Plus some interesting and fun web sites . . .

Thursday, July 30, 2009

CUSO Preps XCalibur Testing for October Using Biometric ID

Employees and board members at three credit unions will be among the first to test the XCalibur card, a biometric card that can function as a single debit, gift and loyalty card.

The XCalibur card was created by CUSO XCard Systems LLC with assistance from IBM Global Engineering Solutions. One of the features that sets it apart from typical debit and credit cards is a biometric touch sensor that authenticates the user before activation. The card can then only be activated by the user or an authorized user, according to XCard. Certain key functions allow the user to pick which account they want to use for a particular transaction, according to the CUSO.

In October, 50 cards will tested, said Vic Pantea, president/CEO of Member Gateways LLC, a product development CUSO that has been involved in the card’s pilot. A simultaneous testing for Visa and MasterCard standards will also take place. From these tests, any final revisions will be made and the card device will enter final production.

CU*Answers is providing card processing and core system testing and Beyond Marketing LLC will market the card. Kent Displays Inc. created the screen display and Seidenfaden Design came up with the prototype sleeve. Prevas Engineering has also played a role in the overall development.
Employees and board members at three credit unions will be among the first to test the XCalibur card, a biometric card that can function as a single debit, gift and loyalty card.

The XCalibur card was created by CUSO XCard Systems LLC with assistance from IBM Global Engineering Solutions. One of the features that sets it apart from typical debit and credit cards is a biometric touch sensor that authenticates the user before activation. The card can then only be activated by the user or an authorized user, according to XCard. Certain key functions allow the user to pick which account they want to use for a particular transaction, according to the CUSO.

In October, 50 cards will tested, said Vic Pantea, president/CEO of Member Gateways LLC, a product development CUSO that has been involved in the card’s pilot. A simultaneous testing for Visa and MasterCard standards will also take place. From these tests, any final revisions will be made and the card device will enter final production.

CU*Answers is providing card processing and core system testing and Beyond Marketing LLC will market the card. Kent Displays Inc. created the screen display and Seidenfaden Design came up with the prototype sleeve. Prevas Engineering has also played a role in the overall development.

Wednesday, July 29, 2009

You Said What? 43 Things Actually Said in Job Interviews

"I'm not wanted in this state." "How many young women work here?" "I didn't steal it; I just borrowed it." "You touch somebody and they call it sexual harassment!" "I've never heard such a stupid question."

Believe it or not, the above statements weren't overheard in bars or random conversations -- they were said in job interviews.

Maybe you were nervous, you thought the employer would appreciate your honesty, or maybe you just have no boundaries. Whatever the reason, you can be certain that you shouldn't tell an interviewer that it's probably best if he doesn't do a background check on you. (And yes, the hiring manager remembered you said that.)

We asked hiring managers to share the craziest things they've heard from applicants in an interview. Some are laugh-out-loud hysterical, others are jaw-dropping -- the majority are both. They will relieve anyone who has ever said something unfortunate at a job interview -- and simply amuse the rest of you.

Hiring managers shared these 43 memorable interview responses:

Why did you leave your last job?"I have a problem with authority." - Carrie Rocha, chief operating officer, HousingLink

Tell us about a problem you had with a co-worker and how you resolved it"The resolution was we were both fired." - Jason Shindler, CEO, Curvine Web Solutions

What kind of computer software have you used?"Computers? Are those the black boxes that sit on the floor next to the desks? My boss has one of those. He uses it. I don't have one. He just gives me my schedule and I follow it." - Greg Szymanski, director of human resources, Geonerco Management Inc.

What are your hobbies and interests?"[He said] 'Well, as you can see, I'm a young, virile man and I'm single -- if you ladies know what I'm saying.' Then he looked at one of the fair-haired board members and said, 'I particularly like blondes.'" - Petri R.J. Darby, president, darbyDarnit Public Relations

Why should we hire you?"I would be a great asset to the events team because I party all the time." - Bill McGowan, founder, Clarity Media Group

Do you have any questions?"Cross-dressing isn't a problem is it?" - Barry Maher, Barry Maher & Associates

"If you were a fruit, what fruit would you be?" - Megan Garnett, Articulate Leadership Team, Articulate Communications Inc.

"What do you want me to do if I cannot walk to work if it's raining? Can you pick me up?" - Christine Pechstein, career coach

"I was a chamber of commerce executive once hiring a secretary. [The candidate asked] 'What does a chamber of commerce do?'" - Mary Kurek, Mary Kurek Inc. Visibility Consulting

Hey, there's a lot more of these at: http://tinyurl.com/lmhfdt or
http://bit.ly/1h7uhM

CU robber goes to confession, returns money

A man who robbed a branch of Patelco CU turned at least part of the money he stole over to a catholic priest after taking part in confession at a church last week.

Police do not know the name of the man who went to a Walnut Creek, Calif., church Sunday night and told the priest during confession that he had robbed the Walnut Creek branch of Patelco CU Thursday afternoon. He left the church after giving the priest $1,200 he said he had robbed from the credit union (Contra Costa Times July 28).

After the man left, the priest called the police.

"I don't know if that was the entire amount or a percentage of the amount," Shelly James, Walnut Creek police lieutenant, told the newspaper. "He said he felt remorse."

After handing the Patelco teller a note Thursday, the man claimed he had a gun. Police will arrest the robber when he is found.

Tuesday, July 28, 2009

Fraudulent checks circulating with CU's name

Fraudulent checks bearing the Meadville (Pa.) Area FCU name and a distorted logo are being mailed to various individuals nationwide.

The check is made payable to the individual in the amount of $2,950.00 with a date of July 9. The item is printed on burgundy check stock and at first glance may appear valid. However, a closer look reveals that MidAtlantic is misspelled and other items are placed in the wrong locations on the face of the check.

The checks are accompanied by a letter from Greenwater Mystery Shopping. The recipient is asked to complete certain tasks within 48 hours. A request to call its office is listed first. Then, the recipient is asked to go to a local Sears or Wal-Mart and send a money gram to someone in Canada.

Meadville Area FCU is gathering evidence to assist the U.S. Postal Investigators in their pursuit of the perpetrators. Anyone with relevant information should contact the credit union.

Saturday, July 25, 2009

Delta Begins In-Flight Wi-Fi Rollout (and It's Free Until Next Year)

Delta said it was coming before 2009, and it's looking like it's actually managed to pull it off. The struggling airline is indicating that most of its most commonly used shuttle craft between New York, Boston, and Washington D.C. are currently being upgraded to offer in-flight Wi-Fi -- and it'll even be free until the end of the year.

The service, provided by Aircell, will be $9.95 on flights less than three hours and $12.95 for anything longer. These short flights will all fit into the former category, just the beginning of the system-wide roll-out that Delta wants to put in place next year.

However, that expansion will be dealt an early blow next year as Delta replaces many of those shuttle flights with contract carriers that don't offer such fancy features. In other words, we're still not quite to the point where mid-air surfing is standard fare, but we're getting close.

Thursday, July 23, 2009

More Advertisers Turning to Internet, Relying Less On Printing

The majority (92%) of advertisers are using Internet advertising in their media campaigns followed by print advertising at 88 percent, according to a new LinkedIn Research Network/Harris Poll.

At the same time, less than half are using radio advertising (46%), television advertising (46%) and mobile advertising (39%). The Harris poll found there is a regional difference as advertisers in the South are more likely to use radio advertising (57%) and television advertising (56%) while those in the West are least likely to use both (39% each).

Among those advertisers who are using each of these types of media, there is a difference in the level of usage since last year. Three-quarters of those who use Internet advertising (74%) say they are incorporating it more often while 69 percent of those who use mobile advertising are using it more often compared to a year ago.

Unsurprisingly, the largest drop is with print advertising as half (49%) of those who use it are using it less often compared to a year ago while 41 percent are using it the same amount.

Of those who use Internet advertising just 14 percent say they use it in a standalone campaign, while 54 percent say the use it in an integrated campaign with other media and 33 percent use Internet advertising in both types of campaigns equally.

Sunday, July 19, 2009

The potential of biometrics to solve a multitude of problems has never been greater

Biometric solutions have secured borders, facilities, and inventory; they have increased operational safety and efficiency and have enhanced customer satisfaction. Importantly, biometrics has done so in many cases without adding complexity for the end user.

Successful biometrics applications have generated a great deal of well-deserved attention – and yet, many biometrics applications continue to disappoint. All too frequently, biometric applications perform poorly in the real world application environment.

Additionally, many biometric solutions have been ineffective, difficult to deploy, and simply too expensive to operate.

Read "Planning for success" at: http://www.global-identification.com/index.php?id=1290

Thursday, July 16, 2009

India to issue all 1.2 billion citizens with biometric ID cards

The Indian government has announced that it is to issue all of its 1.2 billion citizens with biometric identity cards.

The Government has said that the first cards will be issued within 18 months. The operation will be run by the Unique Identification Authority, a new government department created specifically for the task of assigning every living Indian an exclusive number and gathering and electronically storing their personal details.

It is hoped that the operation, which is expected to cost at least £3 billion, will fight corruption but it could also be used to identify illegal immigrants and tackle terrorism.

Is biometric identification coming to the U.S.? It already has. Have you applied for a passport lately? Hundreds of credit unions are using biometric identification. Learn more about biometric ID at the CU InfoTECH Conference set for November 9-11, 2009 in Palm Springs, CA.

Click here for a conference brochure:
http://cuconferences.com/tech09/09%20InfoTech%20FINAL.pdf

Fiserv Survey Cites Online Banking, Bill Pay Growth

About 80% of American households that have Internet access now use it for online banking, while nearly as many use bill pay.

That’s according to Fiserv Inc.’s ninth-annual consumer billing and payment trends survey, conducted by The Marketing Workshop and Harris Interactive.

The survey’s results were released this week and reflect the habits of the 88.2 million American households that have Internet access, the Brookfield, Wis., company said.

It found that 69.7 million households now use online banking–primarily for balances, histories and transfers–and that 64.4 million pay at least one bill online through their financial institution’s Web site or that of a biller. That’s more than 2 million more households than reported the same last year, Fiserv said.

A video detailing findings from the survey is at www.fiserv.com/trends.htm.

Wednesday, July 15, 2009

CUs Filing More Reports of Suspicious Activities

Credit unions filed 9% more Suspicious Activity Reports last year, according to data released by the Treasury Department.

Last year there were 57,179 such reports, compared with 52,432 in 2007. At all depository institutions, there were 732,563 reports last year, compared with 649,176 in 2007.

Since 1996, when the information began being gathered in its present form, there have been 227,865 suspicious activity reports filed by credit unions, 48% were filed in 2007 and 2008.The data is compiled by the Financial Crimes Enforcement Network, a division of the Treasury Department.

Credit unions filed 9% more Suspicious Activity Reports last year, according to data released by the Treasury Department.Last year there were 57,179 such reports, compared with 52,432 in 2007. At all depository institutions, there were 732,563 reports last year, compared with 649,176 in 2007.Since 1996, when the information began being gathered in its present form, there have been 227,865 suspicious activity reports filed by credit unions, 48% were filed in 2007 and 2008.

The data is compiled by the Financial Crimes Enforcement Network, a division of the Treasury Department.

Report: Text message scams increasing

Internet criminals are increasingly operating like successful businesses, borrowing the best strategies from legitimate companies and collaborating in partnerships with each other to make a profit off their illegal activities, says a new security report.

Cisco's 2009 Midyear Security Report covers a range of threats, including a significant increase in text message scams--the "new frontier for fraud irresistible to criminals," who hope that consumers savvy enough not to fall for e-mail phishing scams may still be gullible through their mobile phone.

The research notes that recently smaller financial institutions have been the focus of many text message scams "likely because customers tend to have higher levels of trust and familiarity with local banks." It cites three examples--all from credit unions (First Community CU, Jamestown, N.D.; Buffalo Metropolitan FCU, Buffalo, N.Y., and BCT FCU, Binghamton, N.Y.).

Among the threats the report cites:

Botnets--Networks of compromised computers used to launch an attack, botnets are being increasingly rented out as a service by their owners to fellow criminals to deliver spam and malicious software.

Spam--A major vehicle for spreading worms and malware and clogging Internet traffic, spam encompasses everything from legitimate sales pitches to malicious websites. More than 180 billion spam messages are sent each day-- about 90% of the world's e-mail traffic.

Worms--Credit unions interested in using social networking need to be aware that the rise of social networking has made it easier to launch worm attacks. People who social network are more likely to click links and download content they believe were sent by people they know.

Spamdexing--Packing a website with keywords or search terms so search engines will display the site more prominently, spamdexing also can send malware disguised as legitimate software. Consumers who trust the rankings on major search engines may download a fake package.

Text message scams--Since the beginning of the year at least two or three new campaigns have surfaced every week on handheld mobile devices such as cell phones. More than 4.1 billion mobile phone subscriptions worldwide mean a criminal can cast a wide net and walk away with a hefty profit, even if the attack yields only a small fraction of victims.

Insiders--With the global recession causing loss of jobs, insider threats are an increasing concern for businesses. Insiders who commit fraud can be contractors or other third parties as well as current or former employees.

The reported noted three trends to watch:

1. Spam will return to record high levels;
2. Legitimate websites will see more attacks; and
3. Social networking attacks will continue;

Tuesday, July 14, 2009

Quebec Police Warn Against Attractive People at ATMs

Police in the Canadian province of Quebec are warning Canadians and U.S. residents to be cautious about attractive people standing close to them at ATMs.

According to the police, fraudsters on both sides of the border are working in teams of two, one of whom is usually a very attractive person, to steal card data from unsuspecting ATM users. In the scam, the attractive partner in the criminal team distracts cardholders as they enter their personal identification numbers so they won't notice them being copied.

A device is also often attached to the ATM to collect the card number and other data when users swipe their ATM cards.Police urged ATM users on both sides of the Canada/US border to exercise caution about using an ATM while other people are close by.

Police in the Canadian province of Quebec are warning Canadians and U.S. residents to be cautious about attractive people standing close to them at ATMs.

According to the police, fraudsters on both sides of the border are working in teams of two, one of whom is usually a very attractive person, to steal card data from unsuspecting ATM users. In the scam, the attractive partner in the criminal team distracts cardholders as they enter their personal identification numbers so they won't notice them being copied.

A device is also often attached to the ATM to collect the card number and other data when users swipe their ATM cards.Police urged ATM users on both sides of the Canada/US border to exercise caution about using an ATM while other people are close by.

Wednesday, July 1, 2009

Pointless Credit Union Staff Photo


Hacker pleads guilty to stealing 2M card numbers

A hacker pleaded guilty in Pittsburgh to charges of hacking into computer systems belonging to other hackers and financial institutions--including a credit union. The hacker, Max Ray Vision, stole two million credit card numbers and ran up charges of more than $86 million.

The breach affected Visa, MasterCard, American Express and Discover cardholders, according to the Pittsburgh Tribune-Review (June 29). Vision also hacked Pentagon FCU, Alexandria, Va.

Thousands of financial institutions suffered losses due to the breach, Luke Dembosky, assistant U.S. attorney, told the newspaper.

Vision pleaded guilty to two counts of wire fraud. He faces up to 60 years in prison and will be sentenced Oct. 20, the newspaper said.

Vision and a partner, Christopher Aragon, created CardersMarket.com to sell and use stolen credit card information, the newspaper said. The website had 4,500 members worldwide at its peak. Aragon and Vision participated in hacking activities from 2005 until their arrests in 2007.

Tuesday, June 30, 2009

June News & Views Published Below


CU SECURITY & TECHNOLOGY News - Providing a brief summary of news and information related to security and technology issues for credit unions - Plus some interesting and fun web sites . . .

Need A Speaker For Your Next Conference?

Rory Rowland as Mr. Bean . . . .

Bringing your conference program to life. Call for information, references, smiles and education. Check out the video at: http://www.youtube.com/watch?v=InWRkiag4yg

Rory Rowland
14401 Covington Rd.
Independence, MO 64055
816-478-3249
roryrowland@yahoo.com


(No, that's Mr. Bean, above. Rory is below. Click on photos to enlarge.)

Monday, June 29, 2009

Several CUs report more scams

Credit unions in Maine and Texas reported that recent scams have targeted their members.

The scams have involved:

> Brewer (Maine) FCU, which is warning its members about attempts to fleece their accounts. Scam artists are sending checks to credit union members for items bought on Craigslist and other Internet sites that are "in excess of the purchase price with a request to return the excess," said a Brewer FCU press release. Or, scammers send checks to members and ask that the checks be cashed for the scammers. "Inevitably these checks are returned either for insufficient funds or because they are fraudulent altogether," the $39.1 million-asset credit union said (Bangor Daily News June 23).

> The $6.2 million-asset, Sugar Land (Texas) Employees FCU, whose members have been targeted by text messages sent by scammers posing as the credit union. The messages claim that members' debit cards had to be deactivated for security reasons, and that members should call an 800 number and give out personal information to reactivate their cards, according to the Texas attorney general's office (The Fort Worth Star-Telegram June 21).

> New Dimensions FCU, Waterville, Maine, which is advising members to ignore pre-recorded phone calls that tells members--for instance--that their Visa card has been restricted for supermarket use only, and that they must call a specific phone number to contact Visa security and a press "1" to speak to someone. The $5.8 million-asset credit union and local police are advising members that the calls are a scam and to ignore them.

Sunday, June 28, 2009

2009 CU Security Conference Photos

The 2009 Credit Union InfoSECURITY Conference brought together dozens of experts in the field of security for credit unions. Lake Las Vegas provided a unique setting for a unique conference. Attendees enjoyed free lodging in condominiums, Power Point handouts on USB drives and a program ending networking pool party.

Here are a few photos taken at the conference.

..



Below (and above) is what you saw when you walked out of the conference meeting room. (Click to enlarge photos)










Friday, June 26, 2009

Cell phone in the toilet bowl? Here’s how to fix it

Your cell phone, pager or iPod has fallen into the toilet bowl, swimming pool or kitchen sink full of water. You fish it out. After you've washed your hands -- depending on the circumstance -- what can you do?

Here's five techniques for restoring the gadget to life. Here's a short description (don't try this without reading his entire post):

1. Remove the battery -- immediately. Then take off the battery cover and other compartments, he says.

2. Submerge the device in a container filled with the alcohol for five minutes.

3. Let the device dry for an hour or so. "The alcohol will evaporate very quickly but be sure it's really dry," "FiscalGeek" says.

4. If that doesn't work after several tries, move on to the other options:

5. Store the phone overnight in a sealed bag of dry rice. The rice acts as a desiccant. (We'll save you the trouble of looking that up. It means "a drying agent.")

Use a Dri-Z-Air dehumidifier.

Finally, maybe a hair blower will work.

It's worth a try to salvage the phone or other gadget. Otherwise, you're left with his final suggestion:

Smash it with a hammer and buy a new device. This one works every time.

Tuesday, June 23, 2009

Top 10 Worst People in Anyone's Life

Top 10: Worst Names for the Special Service People in Your Life:

Of all the people you count on weekly to help you get through life, here are the top ten worst choices by area of relationship and/or service:

10. Your hotel innkeeper is Norman Bates.

9. Your limo driver is Evel Knievel.

8. Your primary care physician is Dr. Edward Scissorhands.

7. Your international travel agent is Mr. Phineas T. Fogg.

6. Your personal tailor is Bozo the Clown.

5. Your personal trainer is Ozzy Osbourne.

4. Your barber is Sweeney Todd.

3. Your spiritual advisor is Charles Manson.

2. Your investment manager is Charles Ponzi.

1. And finally .... or fatally .... and on a much more personal note, your "significant other" is either Ann Coulter, Nancy Pelosi, Nancy Grace, Rush Limbaugh, Larry King, Al Franken, Lizzie Borden, Bill O'Reilly, Hillary Clinton, Jerry Springer, Barney Frank, Madonna, or Rosie O'Donnell.

Friday, June 19, 2009

How good is Microsoft's free antivirus software?

Microsoft has officially unveiled its long-awaited consumer antivirus offering. Formerly code-named “Morro,” it’s now been christened Microsoft Security Essentials, and it will enter public beta testing next week. If you have a licensed copy of Windows XP (Service Pack 2 or above), Windows Vista, or Windows 7, you’ll be able to download and install the software at no additional charge. No subscription is required for ongoing definition updates, either. The final release is scheduled for this fall.

The public beta will be limited to 75,000 downloads, Microsoft says, and the targets are global. The initial beta release is limited to the United States, Israel (where a core development team is based), and Brazil. Next month, the beta will open up for users in China. It’s no coincidence that Microsoft is rolling out early in Brazil and China, which are large-scale vectors of malware infections because of the sheer number of Windows users running without antivirus protection. According to Microsoft, barriers to adoption of paid security software are especially high in developing markets, where internet access is slower and credit cards are unavailable to a large percentage of the population.

The MSE download is impressively lightweight. The x64 copy I installed on Windows 7 was 3.8 MB in size; x86 copies are 4.8 MB for Vista/Windows 7 and 7.7 MB for Windows XP. Installation (including the most recent definition updates) took less than four minutes and, as promised, the initial setup didn’t require any personal information or registration. After I accepted the license agreement, the software informed me that it needed to update its virus definitions and then proceeded to get the most recent updates on its own.

You can bet that the beta release will be seriously tested by independent labs and especially by Microsoft’s for-profit competitors in the coming weeks. If it has any weaknesses, expect to see them heavily publicized. Meanwhile, I’m sufficiently impressed by MSE in operation to give it a more in-depth workout on multiple systems here.

ATM fraud ring arrests made, stole from Florida CUs

Police in Jacksonsville, Fla., recently made three arrests in a complex ATM fraud ring involving more than 100 people. The ring defrauded a number of Florida credit unions.

Ophel Day, Tony Fudge and Jacob Dunn were arrested for depositing bad checks into ATMs and then making withdrawals or purchases before the checks bounced, according to federal investigators (WJXT Jacksonville June 17).

The fraud has cost local credit unions from $300,000 to $500,000, police said. Affected credit unions include Jacksonville-based Vystar CU and Mulberry, Fla.-based Community First CU.
More arrests will be made, Paul Elliot of the Secret Service said

The scam begins when account holders sell their ATM cards and personal identification numbers for up to $500 to a "recruiter" in the ring, authorities said. The recruiter then passes the information on to the scam's ringleader. Individuals giving up their card then report the card as stolen.

Recruiters deposit checks that are counterfeit, stolen or from closed accounts into ATMs. The active accounts allow a percentage of the money deposited to be immediately withdrawn, with subsequent withdrawals and purchases from businesses conducted before the check is returned, authorities said.

Account holders often report that their cards are stolen or lost after the thefts occur. Many are reimbursed for losses they claim--which results in a double whammy to the financial institutions involved, authorities added.

Newest report shows fraud trends

The recently released May 2009 Online Fraud report from RSA Security Inc.'s Anti-Fraud Command Center provides information for credit unions and others about the latest fraud trends and forecasts for the next 12 to 18 months.

These include:

> Muling--the evolution of recruitment scams directed towards unsuspecting individuals to aid in the monetization of stolen goods;

> Evolving supply chains, including fraud-as-a-service, which helps online criminals commit fraud;

> Significant increase in attacks against the enterprise;

Evolution in crimeware and attack vectors including: a rise in use of the latest crimeware delivery method; fast-flux botnets (a network of compromised computers); improvements in both Trojan functionality and infrastructure; and consolidation of "traditional" phishing and malware attacks.

The number of phishing attacks in April dropped 7% from March attacks, the report said.

In the next 12 to 18 months, RSA said it expects to see an increase in enterprise fraud in which online criminals can gain access to sensitive corporate data such as intellectual property and business plans.

To stay ahead of the fraudsters, RSA recommends that companies deploy a layered approach to security, which has three core elements:

> Understand the threat landscape--Organizations must understand the threats that are targeting their business and the relative risks they pose. By doing so, organizations can mitigate the risks of online fraud or even prevent it from occurring at all.

> Use multi-factor authentication to protect the login--Username and password authentication is not enough to protect access to sensitive data today. Multi-factor authentication--including two-factor and risk-based authentication--are critical to preventing unauthorized access to a user's sensitive and personal data.

Monitor transactions and activities that occur post-login--Going beyond authentication solutions that can challenge users to assure their identity login, organizations should consider implementing a transaction-monitoring solution that analyzes and challenges high-risk transactions after login has occurred. Transaction monitoring can help identify suspicious post-login activities and mark them for further review.

Friday, June 12, 2009

Reach a human when you call customer service

This is an amazing concept: A Web site called gethuman.com ("get human")gives instructions for avoiding the interminable voice menus used by companies and government agencies -- and reaching a real customer-service person. We're bookmarking this baby. If the company you need to contact isn't listed, a tips page tells you how to find the phone number and gives some suggestions for reaching a person, like punching the zero on your phone repeatedly, mumbling when the machine tells you to speak, or asking for "account collections," which generally is quick to answer the phone.

"When you do finally find a human, ask them how to connect directly the next time (in case your call gets disconnected, etc.), and be sure to tell us so we can then list their number here," the site says.

The site, founded by consumer advocate Paul English, provides a message board and also rates companies' customer-service phone system performance against the gethuman standards. We don't need to tell you that the F's vastly outnumber the A's.

There's also a translation guide for what the voice menu really means. "Your call is important to us" means this, according to gethuman.com: "You are not important enough for us to have a human answer your call, but we think you are stupid enough to feel good when we say you are important."

http://www.gethuman.com/

Funny Money: Why Banks Want to be Our Friend

Redneck Bank is still alive and kicking. They're offering checking accounts of various types and they're the buzz of the finance news world for their tongue-in-cheek approach to banking.

(Click on photo to enlarge)


You can see their website here, complete with braying donkey, outhouse for "personal bidness" and lots and lots of Flash animation tutorials and info. (Note: they're not a "bank", per se, they're an extension of Bank of the Wichitas).


Click here to visit: http://www.redneckbank.com/

Feds Hunting for $120 Million of CU Funds Missing From U.S. Mortgage

Michael McGrath, the founder and owner of U.S. Mortgage and its CU National Corp., is scheduled to plead guilty in federal court to bank fraud and conspiracy charges in what is growing into one of the biggest financial scandals ever to hit credit unions.

Customer Service Hall of Shame

MSN Money's 3rd annual survey finds which companies, despite tough times, still put customers first -- and which ones seem intent on walking all over them.

MSN Money released its third annual Customer Service Hall of Shame survey results. The results revealed that financial intuitions and telecommunication services keep slipping in the minds of consumers when it comes to customer service and nine out of the 10 companies that made it to this year’s shame list are repeat offenders!

Once again, the coveted number one worst customer service spot was reserved for AOL. The rest of the shame awards go to:

#2 Comcast
#3 Sprint
#4 Capital One
#5 Time Warner Cable
#6 HSBC
#7 Qwest
#8 Abercrombie and Fitch
#9 Bank of America
#10 Citigroup

On the bright side, some companies are satisfying consumers, especially low-cost entertainment and bulk food companies that provide great value in this economic climate. The number one Hall of Fame spot is awarded to USAA and the second to Trader Joe’s.

To check out the entire Hall of Shame list, visit:
http://articles.moneycentral.msn.com/SmartSpending/ConsumerActionGuide/HowCompaniesWereRanked.aspx

Thursday, June 11, 2009

95% of Blogs Abandoned

The NY Times reports that according to a 2008 survey only 7.4 million out of the 133 million blogs the company tracks had been updated in the past 120 days meaning that "95 percent of blogs being essentially abandoned, left to lie fallow on the Web, where they become public remnants of a dream -- or at least an ambition -- unfulfilled."

Richard Jalichandra, chief executive of Technorati, said that at any given time there are 7 million to 10 million active blogs on the Internet, but it's probably between 50,000 and 100,000 blogs that are generating most of the page views.

"There's a joke within the blogging community that most blogs have an audience of one." Many people who think blogging is a fast path to financial independence also find themselves discouraged.

Tuesday, June 9, 2009

Employed women to outnumber men

Did you know that men make up about 82% of job losses so far? Employed women will soon outnumber employed men for the first time in U.S. history, according to the U.S. Bureau of Labor Statistics.

Security video records ghostly vibes in CU

Anderson City Employees FCU, located in the South Carolina city's brand new Municipal Business Center, is experiencing some otherworldly vibes in the form of not-yet-explained moving blurs picked up by its security camera.

The moving blur is white and floats around the room to a chair, sits down and disappears. Sometimes there are two blurs. The local NBC affiliate, KFOR, has the sightings on a video. Use the resource link below to view it.

The sightings began last month after security guard Rob Colbert spotted movement out of the corner of his eye while working late. He checked the security tape. It had captured the movement.

The blurs always occur in the same office. The most recent visit was last Thursday morning.
The center's IT director, Mark Cunningham, checked the cameras and found nothing wrong. The credit union closed the blinds to avoid any reflections from outside. But the apparition showed up again--this time more clearly.

IT cleaned the camera lens and resealed the camera cover, but the image reappeared. It doesn't cause any trouble and the credit union has nicknamed it "Clair, for clairvoyant."

The new center was built on a former service station lot but no one know of any ghosts lurking about.

"If it is a ghost, maybe it's Casper the friendly ghost," Frances Parham, CEO of the $1.6 million asset credit union, told the television reporters.

Click here to view the ghost video:
http://www.kfor.com/news/local/kfor-news-south-carolina-ghost-story,0,4375330.story

ID thefts with victims' names on cards rise

The number of identity thefts where fraudsters obtained credit cards using victims' names rose during 2008, according to Javelin Strategy and Research.

Javelin attributed the increase to a credit card loan application process that requires less verified information and is easier than other types of loan applications. Also, credit cards provide the most financial gain for thieves, who often don't get caught (CardLine June 8).

The results, published by the Pleasanton, Calif.-based firm last week, are based on a survey conducted by the firm of 4,784 U.S. consumers last year.

Of those responding, 487 said they had been victims of identity theft. Of the identity theft victims, 146 indicated that a variety of fraudulent new accounts had been opened using their name.

Among the new-account fraud victims, one-third said criminals had opened new credit card accounts in their name, up from 26% from the previous year's survey.

Other findings:

> Twenty-six percent of the victims said fraudsters opened new store-branded credit cards in their names, down from 29% in 2007.

> Fifteen percent reported other types of fraudulent loans were in their names, down from 21%.

Saturday, May 30, 2009

May News & Views Published Below


CU SECURITY & TECHNOLOGY News - Providing a brief summary of news and information related to security and technology issues for credit unions - Plus some interesting and fun web sites . . . and no monkey business.

Thursday, May 28, 2009

The Web's most dangerous keywords to search for

Which is the most dangerous keyword to search for using public search engines these days? It’s “screensavers” with a maximum risk of 59.1 percent, according to McAfee’s recently released report “The Web’s Most Dangerous Search Terms“.

Upon searching for 2,658 unique popular keywords and phrases across 413,368 unique URLs, McAfee’s research concludes that lyrics and anything that includes ‘free” has the highest risk percentage of exposing users to malware and fraudulent web sites. The research further states that the category with the safest risk profile are health-related search terms. (Click on chart to enlarge)

Here are more findings:

> The categories with the worst maximum risk profile were lyrics keywords (26.3%) and phrases that include the word “free” (21.3%). If a consumer landed at the riskiest search page for a typical lyrics search, one of four results would be risky.

> The categories with the worst average risk profile were also lyrics sites (5.1%) and “free” sites (7.3%).

> The categories with the safest risk profile were health-related search terms and searches concerning the recent economic crisis. The maximum risk on a single page of queries on the economy was 3.5% and only 0.5% risky across all results. Similarly, even the worst page for health queries had just 4.0% risky sites and just 0.4% risk overall.

To view the entire article, visit: http://blogs.zdnet.com/security/?p=3457&tag=nl.e539

Another wave of scams hits several states

From CUNA . . .

MADISON, Wis. (5/28/09)--Phone scams are targeting credit unions in Wisconsin, Vermont and Maryland, and credit unions are reminding members that the credit union would never contact them for account or credit card information.

Forward Financial CU, Niagara, Wis., would never call members asking for personal information because the credit union already has it, said Tammy Young, vice president of operations (UpperMichiganSource.com May 26). Forward Financial was one of two institutions recently targeted by scammers who were calling consumers and asking for personal financial information.
Members who have provided their information to scammers should contact the credit union immediately. Forward Financial can block members' debit or credit card from being used, Young said.

Cumberland, Md., police have received hundreds of reports about a phone scam in which individuals identifying themselves as Chessie FCU employees asked for account information (WCBC Wire May 26). The scammers have called homes, businesses and cell phones in the area.
Williston, Vt., residents have received calls from individuals claiming to represent New England FCU and Heritage Family CU. The callers ask recipients to supply personal account information to reactivate a credit card.

Matt Levandowski, Heritage Family CU executive vice president, said some of his credit union's members had given scammers their account information but their accounts had not been compromised.

Wednesday, May 27, 2009

Augusta Metro FCU Ads Ingersoll Rand's Biometric HandKey Reader

Augusta Metro Fed. Credit Union has implemented Ingersoll Rand Security Technologies' standalone Schlage biometric HandKey reader to provide its members with self-service access to the safe deposit vault. The technology allows members to simply punch in a code on the hand reader, presents his or her hand to the unit and, once verified, the bullet-proof glass door opens.

At the same time, the individual's safe deposit box opens and nobody can enter the vault until that member puts away the deposit box.

Today's Best News Stories

>> According to Mexican officials, the swine flu outbreak has cost Mexico $2.2 Billion. Only $2.2 Billion? Maybe we can put them in charge of GM.

>> Police say a Michigan postal worker has admitted to stealing $20,000 worth of postage stamps and trying to sell them online. The worker will be fired for breaking the Postal Service's strict rules against turning a profit.

>> The Indy 500 approaches. A race driver is like an automobile executive. If anything bad happens to the car, he has to be bailed out.

>> Los Angeles Dodgers superstar Manny Ramirez admitted he took a banned substance Thursday but was careful to point out he didn't take steroids. That's illegal. If convicted of steroids use, he could get four to eight years as governor of California.

>> The price of a stamp is up to 44 cents. It's out of control. If only there was some other way to send written messages . . . If anyone can think of anything just e-mail me.

Survey: Better rates, more ATMs top members' wish list

From CUNA . . .

MADISON, Wis. (5/27/09)--While most members report they are satisfied with their credit unions, better rates and expanded access to automated teller machines (ATMs) top their list of suggested improvements, says a recently released survey report by the Credit Union National Association (CUNA).

Click for larger view
About 45% of members surveyed would like to see their credit union pay higher savings rates than they do now, according to CUNA's 2009-2010 National Member Survey. Lower loan rates (27%) and more ATM locations (22%) rounded out the top suggestions from members.

Higher savings rates are the leading request from members age 45 and older. More ATMs topped the list for 25- to 44-year-old members, and more convenient credit union locations ranked highest with 18- to 24-year-olds.

"The desire for more convenient brick-and-mortar locations among such a technology savvy young group was interesting, and it could indicate that some young adults are doing business with a credit union located near the workplace of one of their parents, but not necessarily near them," said Jon Haller, CUNA director of business-to-business publishing.

The National Member Survey reveals trends involving members' use of financial services and attitudes, and strategies to build loyalty and attract more business. It also provides information and analysis related to members' demographics, satisfaction, interest in new services and delivery channels.

Also, the 2009-2010 Survey of Potential Members--CUNA's companion report to this survey--uncovers new issues, opportunities, and strategies for reaching and attracting new members. It analyzes current trends relating to non-members' financial behaviors and loyalty to their banks, and suggests how to leverage competitive advantages to attract eligible non-members from their current provider.

Tuesday, May 26, 2009

Our Ears May be Our Password

YOU are the victim of identity theft and the fraudster calls your credit union to transfer money into their own account. But instead of asking them for your personal details, the credit union rep simply presses a button that causes the phone to produce a brief series of clicks in the fraudster's ear. A message immediately alerts the bank that the person is not who they are claiming to be, and the call is ended.

For more on this security technology, visit: http://www.newscientist.com/article/mg20227035.200-our-ears-may-have-builtin-passwords.html

An Expectation of Online Privacy

If your data is online, it is not private. Oh, maybe it seems private. Certainly, only you have access to your e-mail. Well, you and your ISP. And the sender's ISP. And any backbone provider who happens to route that mail from the sender to you. And, if you read your personal mail from work, your company. And, if they have taps at the correct points, the NSA and any other sufficiently well-funded government intelligence organization -- domestic and international.

You could encrypt your mail, of course, but few of us do that. Most of us now use webmail. The general problem is that, for the most part, your online data is not under your control. Cloud computing and software as a service exacerbate this problem even more.

Your webmail is less under your control than it would be if you downloaded your mail to your computer. If you use Salesforce.com, you're relying on that company to keep your data private. If you use Google Docs, you're relying on Google. This is why the Electronic Privacy Information Center recently filed a complaint with the Federal Trade Commission: many of us are relying on Google's security, but we don't know what it is.

This is new. Twenty years ago, if someone wanted to look through your correspondence, he had to break into your house. Now, he can just break into your ISP. Ten years ago, your voicemail was on an answering machine in your office; now it's on a computer owned by a telephone company. Your financial accounts are on remote websites protected only by passwords; your credit history is collected, stored, and sold by companies you don't even know exist.

And more data is being generated. Lists of books you buy, as well as the books you look at, are stored in the computers of online booksellers. Your affinity card tells your supermarket what foods you like. What were cash transactions are now credit card transactions. What used to be an anonymous coin tossed into a toll booth is now an EZ Pass record of which highway you were on, and when. What used to be a face-to-face chat is now an e-mail, IM, or SMS conversation -- or maybe a conversation inside Facebook.

Remember when Facebook recently changed its terms of service to take further control over your data? They can do that whenever they want, you know.

We have no choice but to trust these companies with our security and privacy, even though they have little incentive to protect them. Neither ChoicePoint, Lexis Nexis, Bank of America, nor T-Mobile bears the costs of privacy violations or any resultant identity theft.

This loss of control over our data has other effects, too. Our protections against police abuse have been severely watered down. The courts have ruled that the police can search your data without a warrant, as long as others hold that data. If the police want to read the e-mail on your computer, they need a warrant; but they don't need one to read it from the backup tapes at your ISP.

This isn't a technological problem; it's a legal problem. The courts need to recognize that in the information age, virtual privacy and physical privacy don't have the same boundaries. We should be able to control our own data, regardless of where it is stored. We should be able to make decisions about the security and privacy of that data, and have legal recourse should companies fail to honor those decisions. And just as the Supreme Court eventually ruled that tapping a telephone was a Fourth Amendment search, requiring a warrant -- even though it occurred at the phone company switching office and not in the target's home or office -- the Supreme Court must recognize that reading personal e-mail at an ISP is no different.

This essay was originally published on the SearchSecurity.com website, as the second half of a point/counterpoint with Marcus Ranum.

http://searchsecurity.techtarget.com/magazinePrintFriendly/0,296905,sid14_gci1354832,00.html or http://tinyurl.com/pnv8vq

Tuesday, May 19, 2009

City police urge 'no hat/hood/sunglasses' policies

COLUMBUS, Ohio (5/19/09)--City police are urging the credit unions in Westerville, Ohio, to strictly enforce policies that require members to remove their sunglasses, hats or hoods when entering to avoid potential robberies.

Suzanne McCann, vice president of sales and operations at CME FCU in Columbus, Ohio, told The Columbus Dispatch Friday that she witnessed a robbery at the credit union. The robber wore a hat and sunglasses, she said.

CME has a similar "no hats, sunglasses" policy that has been enforced at every branch, the newspaper said. Some credit union members weren't happy with the policy, but McCann said the policy helps keep everyone safe.

Although only a few cities nationwide have "no hats" policies, voluntary participation is increasing, Harry Trombitas, an FBI special agent based in Columbus. Most bank robbers want to avoid conflict, and complying with a request to take a hat or sunglasses off could attract more attention, he said.

There have been 22 Columbus-area robberies this year, five fewer than this time last year, the newspaper said.

Credit unions in several states have adopted "no hat, no hoods, no sunglasses" policies. In 2003, the Delaware Credit Union League provided posters and signs to credit unions that ask member to remove these articles of clothing when they enter the credit union. The same year, the Missouri Credit Union Association adopted a similar policy.

Other states with "no hats, hoods or sunglasses" rules include South Carolina, Massachusetts and Oklahoma (News Now June 3, 2005).

Though the policies have been implemented to increase safety, they have been criticized. Earlier this year, a Muslim woman who was a member of Navy FCU said she was denied service from the credit union for wearing a traditional head scarf as required by her religion. Navy Federal contacted the member and apologized to her.

Friday, May 15, 2009

Sixty gang members nabbed in $500,000 scam vs. Credit Union

SAN DIEGO (5/15/09)--More than 60 members and associates of the San Diego Lincoln Park Street Gang were arrested Tuesday and charged with stealing $500,000 from a credit union by recruiting young credit union members to give up their account information so the account could receive counterfeit check deposits.

The gang then withdrew thousands of dollars from an ATM at a casino and the accomplice account holders, who received a portion of the payout, would file a police report for an unauthorized withdrawal, said California Attorney General Edmund G. Brown Jr. and San Diego District Attorney Bonnie Dumanis in a press release.

In a multi-agency operation termed "Bank Gig," a Tuesday morning pre-dawn sweep by more than 100 law enforcement officers took the suspects into custody. They are being held on 347 felony charges related to conspiracy, grand theft, money laundering, recruiting to commit a felony for a gang, unlawful sale of access card information , burglary and gang enhancement.

After obtaining personal account information and personal identification numbers from members of Navy FCU, gang members would deposit counterfeit checks into the members' accounts, then withdraw thousands from an ATM machine at Barona Casino near San Diego.

"The size, scope and sophistication of this operation show us that criminal street gangs in San Diego are expanding their criminal enterprise into white collar crime," said Dumanis.

The investigation began when the credit union in 2005 reported to the U.S. Secret Service a significant increase in fraud reports from young members reporting their account information and PINs had been stolen.

Thursday, May 14, 2009

Dumb & Dumber: Credit union treats member like small change

Due to a lack of timely intervention at the Okemos Branch, the MSU Federal Credit Union (Lansing) experienced a casualty Saturday. Joyce Banish, the credit union's vice president of university and community public relations, acknowledged Monday that "better judgment" would have been the proper treatment.

Kimberly Schulz, a member of the credit union, waits tables. Some of her tips come in the form of change. It's her habit to take the change to the credit union once a week or so, drop it in the coin counter, get a receipt, then deposit the total in her account.

Schulz walked into the branch Saturday and discovered that the machine was out of service. So she informed a woman at the front desk that she wished to deposit the money - all $15 dollar's worth - directly into her savings account. The woman told her that wouldn't be possible. In an e-mail to me Schulz described the encounter this way:

"I asked why and she said she had no way of counting it ... I showed her the small amount of change I had, but she said (the credit union) wouldn't take it."

Let me reiterate some key facts here: Schulz is a MEMBER. She was trying to DEPOSIT the money. The credit union's change counter was NONFUNCTIONAL. Schulz's change TOTALLED $15 (and, by the way, was mainly in quarters).

Schulz approached a teller and offered to arrange the change into one-dollar stacks. And no one, she said, was waiting in line behind her. But the teller refused to accept the money.

In her e-mail Schulz wrote: "I was flabbergasted. I understand their policy to normally not take (uncounted) change, since they have a change-counting machine right in their office. But when the machine is not working, you would think Customer Service 101 would kick in ..."
Exactly.

Responding my inquiry, Banish said the branch takes in a lot of change and that, with the coin machine down, the "no change" policy was aimed primarily at people with large bags of uncounted change.

Stopping to count it, she pointed out, could cause service delays for other customers.
Banish also said Schulz could have used a change counter at another branch.

But she conceded, in the end that "better judgement would have been to count (Schulz's change)."

Don't let this happen in your credit union.

Interesting Credit Union Names

Many credit unions with common words in their name:

> 1-in-6 credit unions have the word ‘Employee’ in their name
> Over 600 credit unions have ‘School,’ ‘Teachers’ or ‘Educators’ in their name
> 183 have ‘Postal’ in their name
> 157 credit unions have ‘Municipal’ in their name
> 110 credit unions have ‘Health’ in their name
> 108 credit unions have ‘Fire’ in their name
> 73 credit unions have ‘Police’ in their name

For more on this subject, visit:
http://thefinancialbrand.com/2008/07/01/most-common-words-in-credit-union-names/

Thursday, May 7, 2009

Meetings Are Important

Meetings Mean Business Petitionhttp://www.keepamericameeting.com/

Please sign this important petition.

Here is my posting:"Meetings directly or indirectly support one in eight Americans with important impact globally. One third of all hotel rooms are booked as a result of meetings. 20% of all airline flights are for those flying to and from meetings. The multiplier effects of meeting attendees spending their money at events, trade shows and conventions is huge! Meetings are also major educators of adults in the industrialized world.

We need to notify our legislators that meetings are not junkets -- they are vital for our economy."

Monday, May 4, 2009

Another Massive Data Breach

CBS News has learned of another data breach potentially compromising the personal information of thousands of people. Companies Lexis Nexis and Investigative Professionals have sent up to 40,000 letters to customers whose “sensitive and personally identifiable” information may have been viewed by individuals who should not have had access.

The United States Postal Inspection Service is investigating a data breach at both companies that resulted in sensitive information being used in a crime. Those individuals have been notified. Sources tell CBS News that the data breach is linked to a Nigerian Scam artist who used the information to incur fraudulent charges on victims’ credit cards.

The letters caution customers to review their credit reports for any inaccuracies, to report any errors or suspicious activity to creditors as soon as possible, and to contact the United States Postal Service if they believe their personal information may have been compromised.

Thursday, April 30, 2009

April News & Views Published Below


CU SECURITY & TECHNOLOGY News - Providing a brief summary of news and information related to security and technology issues for credit unions - Plus some interesting and fun web sites.
Join us for our annual security conference in June.

Tuesday, April 28, 2009

Risk expert: E-fraud advances require new techniques

Credit unions, their members and third-party providers of electronic funds transfer services need to improve their online security because of advances in online fraud involving personal and financial institutions computer systems, a CUNA Mutual Group risk management expert said Friday.

Electronic fraud losses are caused primarily by consumer account compromises through online banking systems and system intrusions at third-party providers of electronic services, Ken Otsuka, risk manager, told attendees at the Hawaii Credit Union League 71st Annual Convention.

Ken Otsuka, risk manager with CUNA Mutual Group, discusses electronic fraud with attendees at the Hawaii Credit Union League 71st Annual Convention Friday. Phishing scams have become a mainstream activity for fraudsters," Otsuka said. "Consumers continue to be duped by this e-mail scam and provide their account numbers and online banking passwords." Account compromises occur when members respond to phishing e-mails by clicking on embedded links that take them to bogus Web sites imitating the credit union's site.

"The branding is remarkably good, and consumers are fooled" into providing information that would allow fraudsters to open accounts with the victim's information," he said.

Read More at: http://www.cuna.org/newsnow/09/system042709-5.html?ref=hed

Friday, April 24, 2009

When you fall, how will you get back up?

We all fall at some point in our lives. A new business or product that we thought would be the next winner, turns out to be a disaster. Failure happens.

If we don't fail, we're probably not trying hard enough.

But what separates the great business leaders from the "also-rans" is how they respond to the times when they fall flat on their face.

Nick Vujicic is someone who constantly falls. And it should be impossible for him to get back up. But he does. It's an incredible story that you've got to see for yourself, especially in this tough economy. You'll be glad you did.

An incredible story.
http://www.yourbusinessgps.com/main.asp?column=1115&page=1342

Survey of Experts Finds Increase in Fraud During Economic Crisis

Intense financial pressure during the economic crisis has led to an increase of fraud, according to a survey of fraud experts conducted by the Association of Certified Fraud Examiners (ACFE). Results of the survey, published in the new ACFE report "Occupational Fraud: A Study of the Impact of an Economic Recession," also found that layoffs are pervasive and are leaving holes in organizations' internal control systems.

The survey responses of more than 500 randomly selected Certified Fraud Examiners (CFEs) were compiled by the Austin, Texas–based ACFE, the world’s largest anti-fraud organization and premier provider of anti-fraud training and education. CFEs are experts in fraud detection, prevention and deterrence, and must pass a rigorous exam as well as meet high professional, educational and ethical standards.

Read more at: http://www.earthtimes.org/articles/show/acfe-survey-of-experts-finds-increase-in-fraud-during-economic-crisis,788078.shtml

Wednesday, April 22, 2009

Dash ATM Expands Product Line to Better Serve U.S. Credit Unions

Recognizing the need to provide credit unions and other financial institutions with a single source for safe secure and reliable ATM products and services, Dash ATM, the nation’s leading manufacturer of high security environmentally controlled drive-up and walk-up ATM enclosures and kiosks, announced that the company will begin marketing state-of-the-art ATMs manufactured by Triton and Hyosung, two of the world’s largest and most respected ATM manufacturers.

Dash ATM will be the only kiosk manufacturing company in the US that can provide financial institutions with a full turn-key operation for a new ATM, a safe/secure enclosure and even take care of installation and first and second line maintenance service.

Established nearly 10 years ago, DASH ATM manufactures environmentally controlled drive-up and walk-up ATM enclosures for machines which are not equipped with level 1 safes. To date, no criminal has ever gained entry into a DASH manufactured enclosure. For more information on Dash ATM visit http://www.dashatm.com/.

Tuesday, April 21, 2009

Vendor partnerships key to fighting fraud

Credit unions plan to increase their efforts to fight fraud, and vendors should work on creating strategic partnerships to present more complete solutions, according to a recent study.

Fraud is a serious concern for financial institutions, and credit unions spend millions of dollars each year on solutions to prevent attacks, Boston-based Aite said in its new report, "Fraud Management at Retail Banks and Credit Unions: The Vendor Landscape."

"The sheer number of fraud management vendors used by financial institutions speaks to a lack of ability for any one vendor to address the gamut of fraud management needs," said Nick Holland, senior analyst with Aite Group and author of the report.

"Vendors looking at the fraud management landscape for financial institutions should realize that institutions are likely to gravitate to vendors that can provide fewer touchpoints to the overall fraud picture. Vendors should explore strategic partnerships in order to present a more complete offering," he added.

The report is based on a November 2008 survey of executives at 23 of the top 150 U.S. financial institutions. It reveals financial institutions' perceptions of fraud management technology vendors and ranks vendors in four areas: new account opening fraud detection, ID verification, authentication and ID fraud monitoring; fraud database; enterprise fraud case management; and check fraud detection.

Friday, April 17, 2009

Warn members about skimmers, 'Grandma, it's me' scams

Credit unions may want to warn their members about two types of scams circulating recently: ATM skimmers and scammers preying on older consumers by posing as a grandchild in trouble.
ATM skimmers, which are attached to ATMs or terminals to read unsuspecting consumers' card data as they use the machines, have seen attention the past two weeks.

Skimmers at three JPMorgan Chase & Co. ATMs--two Chase-branded ones in New York and a Washington Mutual-banded one in West Hollywood, Calif.--were discovered and reported by consumers using the machines (American Banker April 15).

The Chase-branded skimmers mimicked the translucent green material used to make the card slot in the NCR Corp. machines. The one in the WaMu machine was made from opaque gray plastic.

Since the cardholder's data personal identification number (PIN) isn't stored in the card's magnetic stripe, the skimmer must be paired with a camera on or near the ATM to record the numbers the consumer types on the keypad. One consumer, who didn't spot the skimmer until his card snagged on it, found a camera behind a mirror stuck on the ATM (Bank Technology News April 13).

The latest scam circulating in Ohio is the "Grandma, it's me" scam, says the Ohio Credit Union League (eLumination Newsletter April 15.

Scammers call unsuspecting seniors and in a highly excited or anxious voice say, "Hi Grandma/Grandpa, it's me." The senior will reply with the name of their grandchild (for example, "Oh, Johnny, what's wrong?") The scammers pick up on whatever name the victim uses and pretend to be a grandson. The "grandson" claims to be in trouble and needs money wired immediately to bail him out of jail or for a hospital bill.

"This is a financially and emotionally devastating scam and has occurred throughout Ohio," said the league. "Routinely educate your staff and members about circulating scams to avoid others falling victim."

Thursday, April 16, 2009

Palm Scan May Replace Log-on Passwords

Be patient. Large file is loading.

Forget your password? Don't worry about it. A scan of your hand, palm, fingerprint or face will someday replace it. Hundreds of credit unions across the country are using biometric identifcation technology to identify employees. Here's an example of one of these technologies.

Monday, April 13, 2009

Fake CU also prompts alerts in Pennsylvania

HARRISBURG, Pa. (4/13/09)--The Pennsylvania Department of Banking has issued a consumer scam alert about an entity calling itself "First Star Lending Services" and "First Star Credit Union," believed to be the same entity that received a cease-and-desist order from a Michigan regulator last week.

The Pennsylvania department warned about an apparent advance fee loan scam using the names at www.firststarlendingservices.com.

Two consumers said they applied to the company for loans ranging from $7,000 to $10,000. When they were asked to pay several hundred dollars in upfront fees to receive their loans, they became suspicious and did not send any funds.

The companies claim to be located at 1800 Loucks Rd., Suite 850, York, Pa. However, no such address exists there. First Star Lending Services claims to offer first and second mortgages, consumer loans and other financial products, but it is not licensed by the Pennsylvania Department of Banking. There is no First Star CU chartered by state or federal regulators said the department.

News Now reported that the Michigan Office of Financial and Insurance Regulation issued a cease-and-desist order against a fake credit union, "Firststar CU," claiming to be a Pennsylvania-based credit union. OFIR said the institution is a fraudulent financial institution (News Now April 10).

Sunday, April 5, 2009

US banks sign up for biometric project

The US-based Financial Services Technology Consortium has launched a project to investigate the use of biometrics for verifying customer IDs. The FSTC says over 20 banks have expressed an interest in the project, including the American Bankers Association which has signed on as a sponsor.

Dan Schutzer, executive director FSTC says the programm will endeavour to develop a methodology for banks to better select, specify, evaluate and deploy biometric applications with greater customer acceptance.

"We also hope to identify and validate at least one or two of them that will make an immediate impact in the fight against identity theft and insider fraud," he adds.

The initiative grew out of a panel discussion at a joint FSTC/Bits summit in early March. A follow-up meeting is planned for later this month at Wells Fargo Bank in San Francisco.

A global survey conducted by Unisys last year found that 72% of US citizens would be willing to undergo fingerprint scans to verify their identities when dealing with banks and government organisations.