Thursday, June 3, 2010

Wi-Fi key-cracking kits sold in China mean free Internet

Dodgy salesmen in China are making money from long-known weaknesses in a Wi-Fi encryption standard, by selling network key-cracking kits for the average user.

Wi-Fi USB adapters bundled with a Linux operating system, key-breaking software and a detailed instruction book are being sold online and at China's bustling electronics bazaars. The kits, pitched as a way for users to surf the Web for free, have drawn enough buyers and attention that one Chinese auction site, Taobao.com, had to ban their sale last year.

With one of the "network-scrounging cards," or "ceng wang ka" in Chinese, a user with little technical knowledge can easily steal passwords to get online via Wi-Fi networks owned by other people.

Chinese Internet censorship: An inside lookLenovo looks for strong finish at Beijing OlympicsSpammers leverage interest in OlympicsU.S. Congressmen accuse China of hacking their computers

View more related contentGet Daily News by EmailThe kits are also cheap. A merchant in a Beijing bazaar sold one for 165 yuan ($24), a price that included setup help from a man at the other end of the sprawling, multistory building.

The main piece of the kits, an adapter with a six-inch antenna that plugs into a USB port, comes with a CD-ROM to install its driver and a separate live CD-ROM that boots up an operating system called BackTrack. In BackTrack, the user can run applications that try to obtain keys for two protocols used to secure Wi-Fi networks, WEP (Wired Equivalent Privacy) and WPA (Wi-Fi Protected Access). After a successful attack by the applications, called Spoonwep and Spoonwpa, a user can restart Windows and use the revealed key to access its Wi-Fi network.

(Read the entire article at: http://www.networkworld.com/news/2010/050510-wi-fi-key-cracking-kits-sold-in.html)

Daddy , how was I born?

A little boy goes to his father and asks 'Daddy, how was I born?'

The father answers, 'Well, son, I guess one day you will need to find out anyway! Your Mom and I first got together in a chat room on Yahoo. Then I set up a date via e-mail with your Mom and we met at a cyber-cafe. We sneaked into a secluded room, and googled each other.

There your mother agreed to a download from my hard drive. As soon as I was ready to upload, we discovered that neither one of us had used a firewall, and since it was too late to hit the delete button, nine months later a little Pop-Up appeared that said:

Scroll down...You'll love this ...
















'You got Male!

Wednesday, June 2, 2010

BIGGER IS NOT BETTER: Kinecta and NuVision Head to $5 Billion Mega Merger

The boards of the $3.5 billion Kinecta FCU and $1.2 billion NuVision FCU have announced their intent to merge into an institution that will serve 300,000 members in two Southern California counties. What will this produce?  Easy, a $5 billion institution. I'm certain many old time CU leaders are rolling over in their graves. Do these CUs feel they cannot survive unless they merge? There's a bunch of "quitters" here somewhere and it's a shame to see one (or both) throw in the towel.

The Manhattan Beach-based Kinecta will be the surviving institution. Although the two are just now beginning due diligence and have yet to file formal merger documents with NCUA, Huntington Beach-based NuVision now shares CEO Roger Ballard with Kinecta; he took executive control of both institutions yesterday.

Interim CEO Steve Lumm, who retired as Addison Avenue FCU’s CEO in 2007, said he was under contract with Kinecta’s board as a consultant, and wasn’t interested in the permanent position.

A general strategy discussion between Ballard and Lumm evolved into “what if” brainstorming which revealed two credit unions and boards open to merger discussions. They share aerospace legacies and SEG Boeing, which has large employment facilities in both Los Angeles and Orange Counties.

Does this send a signal that all CUs under $1 billion are be in trouble? Will the day come where trillion dollar credit unions cannot survive and will need to merge? Is bigger really better?



Monday, May 31, 2010

May News and Views Published Below

CU SECURITY & TECHNOLOGY News - Providing a brief summary of news and information related to security and technology issues for credit unions - Plus some interesting and fun web sites . . .

Saturday, May 29, 2010

Why a CU should or should not use MySpace, Facebook, or other social media outlets?

If you are a credit union, why should you use or not use MySpace, Facebook, or other social media outlets as methods to attract young adults and teens?

Readers comments as to Why a Credit Union should or should not use Myspace, Facebook, or other social media outlets?

“I believe that if used properly, social media is the most effective method of consumer influence in today’s market.

I can’t source the following numbers, but I know that I’ve seen them somewhere credible before:

- 30% of online consumers find a manufacturer website to be credible.

- 70% of online consumers find media and/or journalists credible.

- 68% of online consumers find other consumers (people whom they have never met) to be credible.

Pretty powerful stuff, no?”

Another reader comments:

“This sounds kind of like an essay question for school.

“Should” reasons/rationale:

* Social media is a way to reach a target market, much like advertising on specific tv shows or cable channels

* social media is influential

* social media is new marketing avenue

* other companies are doing it successfully

* stay competitive

* keep in touch with current trends

* young people have lots of questions about money management & credit unions can provide answers


“Should not” reasons/rationale:

* potential for credit union to lose credibility (if they’re not upfront about who they are & what they do — like when a company’s marketing person “disguises” him/herself as average citizen who says good things about products, services but who is really just pitching for the company)

* social media is unknown territory with lots of potential pitfalls

* young people may resent adults entering their “turf”

* adults aren’t as savvy when entering the cyberspace world of young people

Hope this helps.”

Good luck!

Wednesday, May 26, 2010

North American Biometrics Market Witnesses Growth Spurt, Finds Frost & Sullivan

The North American biometrics market is likely to experience a steady growth rate, with national ID projects, e-Passports, and other security projects spearheading market growth. Trends indicate that the industry has evolved a great deal over the past 5 years due to the increased accuracy rates and performance levels of the technology. Biometric standards, cost versus performance benchmarks, and interoperability issues have enabled high uptake in civil and commercial applications even as fraudulent activities and identity thefts continue to cost institutions significant revenue losses.

New analysis from Frost & Sullivan (http://www.autoid.frost.com), North American Biometrics Market, finds that the market earned revenues of $364.4 million in 2009 and estimates this to reach $1,588.6 million in 2016.
http://www.autoid.frost.com/

NCUA Warns against Phony E-Mails

E-mails purporting to offer $40 to participate in a survey that say they come from the NCUA are false, the agency warned.

The e-mails, which solicit credit union member participation in an Online Survey or Member Survey are “fraudulent, and may be an attempt to obtain confidential member information. NCUA does not solicit such information from credit union members. This is a phishing activity with no NCUA activity or approval,” the agency said in a statement.

Tuesday, May 25, 2010

Fraud forced Cardtronics to shut down 1,000+ ATMs

ATM provider Cardtronics Inc. was forced to temporarily shut down more than 1,000 ATMs owned by companies and merchants earlier this year when owners of its armored-car service were charged with fraud.

Cardtronics, which owns and operates more than 28,000 ATMs in the U.S., shut down nearly 4% of its ATMs after the owners of Mount Vernon (N.Y.) Money Center Corp. were arrested Feb. 8, according to Cardtronics' filing with the Securities and Exchange Commission (ATM & Debit News May 19).

Arrested were Money Center Corp. President Robert Egan, 64, and Chief Operating Officer Bernard McGarry, 50. Their company supplied cash to more than 5,300 ATMs, including those of Cardtronics.

The two men were indicted for allegedly defrauding banks, other financial institutions, retailers, hospitals and universities out of $50 million. Instead of segregating cash for each of their clients, they allegedly commingled funds by taking whatever cash that arrived in the vault, regardless of its source, to fill the next day's ATMs, according to the indictment.

The company had to convert the ATMs to another third-party armored-service provider, which resulted in downtime at the machines. Cardtronics estimates it lost $16.2 million from the vault. Money Center has been put into receivership.

Targeting and Measuring Social Media Objectives

(Click above for more information)

Saturday, May 15, 2010

Ways to Extend the Life of Your Printer Ink Cartridges

Since ink cartridges can be quite expensive, making them last for as long as possible makes sense. Here are a few simple ways to get the most out of your ink cartridges.

1)  Print in draft mode. Most of the items we print out do not need to printed at the highest quality. Simply printing in draft mode can give you 3 to 5 times more prints from your cartridges.

2)  Store your cartridges properly. If you get a deal on cartridges online and want to purchase a large quantity to save money you should make sure you store them properly. If stored under the right conditions, cartridges can stay in good condition for up to two years. Make sure they are in a place that is not too hot or too cold, keep the cartridges in an upright position, and do not open the packages until you are ready to use them. The vacuum seal helps keep air from the cartridges extending the life of the ink cartridges.

3)  Use the printer frequently. Yes, I said use your printer. If you use your printer on a regular basis you can help keep your cartridges in good working order and prevent the nozzles from getting clogged by dried ink. It is recommended that you print at least a page or so every couple of weeks at a minimum.

Friday, May 14, 2010

CUNA Tech Council Offers Social Media Report

The CUNA Technology Council is offering a new report on the benefits and pitfalls of social media.

The 30-page paper discusses how credit unions should assess how social media tools fit into their overall marketing objectives and what values such specific tools as Facebook and Twitter provide the credit union and members. Protection from malware and other threats also is examined.

The paper was authored by Elizabeth Thompson, a Madison, Wis., writer who has produced more than a dozen white papers for the CUNA Councils and drew on input from credit unions and industry experts and providers.

“Social Media from a Technology Point of View” is free to CUNA Council members and $50 to non-members and is one of more than 200 white papers offered through http://www.cunacouncils.org/.

Wednesday, May 12, 2010

Poland Installs Europe's First Biometric Fingerprint-Scanning ATM Machine

 Given the financial situations in Greece, Spain, and Portugal in recent weeks, the Euro Zone has plenty of reason to be down on itself. But Poland is showing a bit of financial-sector flash this week, becoming the first nation in Europe to install biometric ATM machines that read fingerprints rather than magnetic cards.

Poland's BPS SA bank set a European -- and if we're not mistaken, a Western -- milestone by installing the biometric cash machine in Warsaw.

Senior Prank at High School Brings Smiles and Donations

Kudos to the Seckman Senior High School girls (St. Louis, MO area)


Sunday night they pulled their senior prank, and a very funny one, and it wasn't destructive. They hung over 1,000 bras from the trees and the fences in front of their high school and they placed signs around, such as "Thank you for the uplifting experience," "Thanks for all your support" and "We're busting out of here."

The students and staff and teachers had lots of laughs for a few days this week. Teachers were known to share the incident on Facebook and comment that this was the best senior prank ever. No harm was done, but fun and enjoyment to be remembered for a long time. By the way, most of these bras were donated to charity, because most of them were very gently used and some of them weren't even used.

Monday, May 10, 2010

How Much Government?

Seventy-five years ago, President Franklin D. Roosevelt was eager to weave a safety net under millions of impoverished Americans who were retired and had no savings.

On his left, supporters called for a massive new government program. On his right, Republicans argued that it wouldbankrupt the country and undermine people's habits of thrift and self-reliance.

Sound familiar?

Sunday, May 9, 2010

Internet Flaws Could Bring Down Service in 30 Minutes

In 1998, a hacker told Congress that he could bring down the Internet in 30 minutes by exploiting a certain flaw that sometimes caused online outages by misdirecting data. In 2003, the administration of President George W. Bush concluded that fixing this flaw was in the nation's "vital interest."

Fast forward to 2010, and very little has happened to improve the situation. The flaw still causes outages every year. Although most of the outages are innocent and fixed quickly, the problem still could be exploited by a hacker to spy on data traffic or take down websites. Meanwhile, our reliance on the Internet has only increased. The next outage, accidental or malicious, could disrupt businesses, the government or anyone who needs the Internet to run normally.

The outages are caused by the somewhat haphazard way that traffic is passed between companies that carry Internet data. The outages are called "hijackings," even though most of them are not caused by criminals bent on destruction. Instead the outages are a problem borne out of the open nature of the Internet, a quality that also has stimulated the Net's dazzling growth.

"It's ugly when you look under the cover," says Earl Zmijewski, a general manager at Renesys Corp., which tracks the performance of data routes. "It amazes me every day when I get into work and find it's working."

When you send an e-mail, view a Web page or do anything else online, the information you read and transmit is handed from one carrier of Internet data to another, sometimes in a long chain. When you log into Facebook, your data might be handed from your Internet service provider to a company such as Level 3 Communications Inc., which operates a global network of fiber-optic lines that carry Internet data across long distances. It, in turn, might pass the data to a carrier that's connected to Facebook's servers.

The crux of the problem is that each carrier along the way figures out how to route the data based only on what the surrounding carriers in the chain say, rather than by looking at the whole path. It's as if a driver had to get from Philadelphia to Pittsburgh without a map, navigating solely by traffic signs he encountered along the way — but the signs weren't put up by a central authority. If a sign pointed in the wrong direction, that driver would get lost.

(Read more at: http://www.stltoday.com/stltoday/business/stories.nsf/story/EEB5A07B82E2B45E8625771D0011FA3D?OpenDocument
or:  http://bit.ly/bYqCrR

Thursday, May 6, 2010

Why Debit Cards Are a Nightmare

Not all plastics cards are created equal. The major differences in credit vs. debit is in the protections (or lack of protections) that come along with the fine print. A debit card is connected directly to a person’s bank account and when compromised can devastate your bank balance.

I know too many people who’ve fallen victim to some type of debit card fraud whether through skimming or unauthorized purchases and never recouped their losses. Sometimes the banks just won’t budge. They tend not to believe a person who’s PIN and card number was leaked.

Creditcards.com reports The Federal Reserve’s Regulation E (commonly dubbed Reg E), covers debit card transfers. It sets a consumer’s liability for fraudulent purchases at $50, provided they notify the bank within two days of discovering that their card or card number has been stolen. TWO DAYS. That’s it! After that, the maximum liability jumps to $500. Some banks will extend the grace period up to a year, but good luck getting your money back.

Federal laws limit cardholder liability to $50 in the case of credit card fraud, as long as the cardholder disputes the charge within 60 days. And if a victim doesn’t discover or report the fraud until after 60 days have passed, the liability could be the entire card balance, for a debit or credit card. Once your debit card is compromised, you might not find out until a check bounces or the card is declined. And once you do recover the funds, the thief can just start all over again, unless you cancel the account altogether.

Don’t use a debit card. Use credit cards and pay attention to your statements every month and refute unauthorized charges immediately. I check my charges online once every two weeks. If I’m traveling extensively, especially out of the country, I let the credit card company know ahead of time, so they won’t shut down my card while I’m on the road.

National Motor Vehicle Title Registration System

The National Motor Vehicle Title Information System is designed to protect consumers from fraud and unsafe vehicles and to keep stolen vehicles from being resold. NMVTIS is also a tool that assists states and law enforcement in deterring and preventing title fraud and other crimes.

Use NMVTIS to access important vehicle history information. Data available to consumers include:

Title data
Brand history
Odometer reading
Total loss history
Salvage history

More at: http://www.nmvtis.gov/

Tuesday, May 4, 2010

Debit card scammers target credit union customers

West Virginia-based Star USA Credit Union is warning members about a scam in which customers have received an automated telephone message requesting debit card account information.

Credit union members received the call from scammers. The automated message alleges that customers' ATM/debit cards have been deactivated, and they must reveal account information and a three-digit security code (located on the back of the debit card) to reactivate it.

"They're asking for account information and personal information," said Steve Hewitt, Star USA vice president and spokesman. "They're identifying that the card has been compromised and needs to be reissued."

Star USA is urging members -- and anyone else with a debit or credit card -- not to release banking account and PIN numbers, or other personal information when receiving an unsolicited phone call.

Hewitt said more than a dozen credit union members, including a Star USA board member, have complained about the scam. No customers reported that they fell for the scam, he said.

Hewitt said the scam might be widespread and affect other area credit unions and banks. After speaking with the credit union's insurance carrier, Hewitt learned that a similar scam has been going on in Huntington and other parts of the country. It's often difficult for law enforcement to track down the scammers, many of whom call from outside the U.S., Hewitt said.

Monday, May 3, 2010

April News & Views Published Below



CU SECURITY & TECHNOLOGY News - Providing a brief summary of news and information related to security and technology issues for credit unions - Plus some interesting and fun web sites . . .

Friday, April 23, 2010

Passwords Are Passe', Financial Institutions Looking Toward Biometric ID

Biometric logins that use fingerprints, voice recognition, or identify you based on how you type look set to replace conventional passwords for accessing online banking and credit card services, online payment companies and even internet stockbrokers.

James Pope of the College of Business Administration, at the University of Toledo, Ohio working with Dieter Bartmann of the University of Regensburg, Germany, explain that the security of online financial transactions is becoming an increasing problem, especially as security loopholes in login systems and web browsers emerge repeatedly. Simply logging in with a password looks set to become technically passé.

"Passwords have been widely used because of their simplicity of implementation and use," the researchers say, "but are now regarded as providing minimal security." Moreover, as repeated scare stories about hacking and identity theft pervade the media, consumers are becoming increasingly concerned about online security. Further development of e-commerce and banking will be stifled if the issues of fraud and identity theft are not addressed.

Tuesday, April 20, 2010

Credit Union Cost Reducing Efficiencies; Here Is What One CU Did

If it comes to laying off employees, cutting salaries, no raises, etc., it's time to REALLY tighten the belt.  Here is what one credit union did to safeguard their existence.

• Eliminated NSF/Overdraft notices - we no longer mail them and encourage members to use on-line alerts instead

• Implemented an employee suggestion program to encourage cost savings ideas from staff

• Eliminate Life Savings/Loan Protection programs to members that were paid for by the credit union

• Evaluated our fee structure and adjusted according to pricing within our local market

• Evaluated Reg D accounts for possible changes

• Eliminated loan payment books

• Stopped offering "overnight" delivery through UPS and now if it is requested, it is paid for by the member

• Switched as many of our vendors over to ACH payments instead of mailing a check for payment

• Introduced electronic paystubs to staff

• Made changes to life insurance and disability coverages

• Changed sick time accrual (we have ours seperate from the PTO)

• Closed some of our ATM's and placed them in storage (it was cheaper to put them in storage than it was to leave them operational and due to the age of them, selling wasn't really an option)

• Evaluated branch hours and adjusted

• Eliminated after-hours (or overflow) third party call center

• Conducted a marketing campaign for e-statements (we offered $5 just for signing up)

• Made changes to our new member packet to reduce size and cost of material

• Evaluated the reports staff printed on a daily basis and set some to spool instead of printing on paper

• Eliminated holiday pay for July 4th (it fell on a Saturday and we normally would have given staff an extra 8 hours of pay)

• Reduced the quantity of coffee supplies and bottled water deliveries for staff. Staff can buy their own water.

• Encouraged members to use our Investment/Financial Planning Representative. He is quite conservative in nature and seems to work nicely with the Baby Boomers. This has helped reduce Cost of Funds while generating revenue for us.

We have done most of the things, plus:

1. We're doing our own office cleaning - vacuum, dust, empty trash, etc.

2. We fired our lawn care guy and now mow our own grass.

3. We were able to renegotiate several contracts with vendors - after threatening to drop totally if they didn't (CUNA bond, VISA servicer, web host, on-line application dude).

4. We dropped the annual cpa audit and have the Supr Comm do one every other year.

5. Made it clear to staff that expenses needed to come down - turn lights off, raise/lower thermostats, order/use fewer supplies, etc.

6. We also looked on the income side with fees and rates but didn't really want to put the burden directly on the members - yet.

Not all of these are permanent changes, but they could be indefinite.

What has your credit union done to increase efficiencies?  Anything?  How about sharing them with us. Make up a list like the above and send to billrogers@swbell.net.

Friday, April 16, 2010

Credit Unions Remain Target of Phishing Attacks

Credit unions accounted for 12% of the phishing attacks on American financial institutions in February, down slightly from January and sharply from February 2009, according to RSA.

The security division of EMC said in its just-issued March report that regional banks continued to account for the majority of attacks, 60% in February, while 28% of the attacks were attempts to gain access to accounts at nationwide banks.

Credit unions were the focus of 14% of the attacks on financial institutions in January and 38% of the attacks in February 2009, according to the RSA Anti-Fraud Command Center, which provides detection and shutdown services against malware attacks on more than 300 organizations in 140 countries.

Wednesday, April 14, 2010

Fraudsters Take Aim At Mobile Banking

Symptomatic of a new fraud trend targeting mobile banking, at least two banking institutions have posted messages on their websites, alerting members to be wary of a bogus application distributed on mobile phone platforms.

Bayport Credit Union of Newport News, VA, and First Technology Credit Union of Portland, OR, warned members about a mobile banking application that had appeared on the Android Marketplace, part of the Android mobile phone platform. Android is a subsidiary of Google. More than 50 fraudulent banking apps began appearing in the Android Marketplace in mid-December, industry experts say. The apps didn't contain malware, but instead attempted to get users to enter their passwords, account numbers or other personal information.

Google says it has removed the malicious applications, which targeted customers of Barclays Bank, Chase, Wells Fargo, Bank of America, Wachovia and Deutsche Bank, among others.

Read more at: http://www.cuinfosecurity.com/articles.php?art_id=2085

22 Banking Breaches So Far in 2010

There have been 173 reported data breaches so far in 2010, and 22 of these involve financial services companies.

This means that in less than one quarter of the year, we already have seen more than one-third of the 62 banking-related breaches reported in all of 2009.

The numbers are slightly skewed, says Linda Foley of the Identity Theft Resource Center (ITRC), the organization that tracks data breaches, because some of the 22 incidents actually occurred in 2009 but are just now being brought to light - particularly in Maryland, where the state's attorney general's office reported a slew of 2009 incidents on March 1 of this year. "I suspect there will be more [reports] coming," Foley says, "so the trend thus far is we're finally finding out about breaches that are just coming out."

But the new year's breaches are enough to convince observers that last year's trends are continuing. "2010 could be a tough year for everyone," Foley says.


>>  2010 Trends

If the breach trends do continue as they did in 2009, then financial service companies will continue to experience malicious hacking and insider theft. The challenge for organizations such as the ITRC is that many organizations fail to report their breaches. "The problem is: We're not trying to embarrass a company, but inform everyone of what is happening out there."

Based on what Foley says she's seen so far in 2010, much information has been lost, "so there's a real need for businesses to adopt policies to protect data."

Despite the Federal Trade Commission's work in promoting the ID Theft Red Flags Rule, Foley says many businesses still don't want to comply with the requirements. "If you don't want to protect it, then don't collect the data," she advises these organizations.

For those organizations that do buy into data protection, they must deputize their employees to take the responsibility seriously. "You should be telling your employees why it is important, so they buy into the wanting to actively protect data, and so they don't see it as another chore," Foley says.

Biometrics: Getting Back to Business

People and passwords—in the long run, they just don't work very effectively together. At least that's what Phil Fowler, vice president of IT at Telesis Community Credit Union, a Chatsworth, Calif.-based financial services provider that manages $1.2 billion in assets, found out. His team ran a network password cracker as part of an enterprise security audit last year to see if employees were adhering to Telesis' password policies. They weren't.

"Within 30 seconds, we had identified probably 80% of people's passwords," says Fowler, whose group immediately asked employees to create strong passwords that adhered to the security requirements. A few days later, the team ran the password cracker again: This time, they cracked 70%.

"We couldn't get [employees] to maintain strong passwords, and those that did forgot them, so the help desk would have to reset them," says Fowler. Telesis decided to secure network and application access with a biometric system that eliminated the need for user IDs and passwords, opting for the DigitalPersona fingerprint system from DigitalPersona Inc. in Redwood City, Calif.

Monday, April 12, 2010

Identity Fraud Reaches New High in 2009

The bad news is that identity fraud reached a new high in 2009. The good news is that consumers are fighting back.

The number of ID fraud victims jumped 12 percent in 2009, but consumers are becoming more educated and are filing more reports with law enforcement, according to Javelin Strategy & Research.

Javelin analysts said the increase may be due to the economic downturn, when fraud rises historically.

And there are many ways a thief can swipe your personal information, even without your credit card or Social Security card.

For the rest of the story, go to:
http://www.chicagotribune.com/business/yourmoney/sc-ym-0307-identity-theft-20100304,0,5146332.story?obref=obinsite

ATM attacks more sophisticated, says Javelin

ATM attacks have become more sophisticated--shifting from traditional skimming to use of malware inside ATMs or ATM networks, fraudulent mobile alerts and account takeover from stolen information, according to a new report.

Attacks have been reported in which maintenance crews opened up ATMs and installed malware, according to a Javelin Strategy and Research study.

ATM manufacturer Diebold issued a security update last year for its ATMs after they were attacked by criminals who installed malware to steal sensitive customer information (Financial Services Information Security News April 6).

Individuals can gain access to sensitive information in ATMs via administrative privileges to encrypted personal identification number (PIN) data, then use a computer to reverse the PIN encryption, said Robert Vamosi, analyst at Javelin Strategy and Research. Other attacks have involved sending customers fake message alerts asking for account information. Criminals then use the information to create a cloned card, the publication said.

The financial services industry is moving toward Triple Data Encryption Standard for all ATMs that will help prevent such attacks. Other steps financial institutions can take to protect their ATMs include using security software that guards against malware and using encrypted PIN pads in ATMs that are Payment Card Industry Data Security Standard-compliant, Vamosi added.

About 10% of fraud victims experienced fraudulent ATM withdrawals, Javelin said. About 23% of those with the fraudulent withdrawals left their primary financial institution.

Thursday, April 1, 2010

March News & Views Published Below



CU SECURITY & TECHNOLOGY News - Providing a brief summary of news and information related to security and technology issues for credit unions - Plus some interesting and fun web sites . . .

Monday, March 29, 2010

Metvante Bill Paying Fuels Credit Union Fee Income; Members Paying Through the Nose

We recently came across a situation where an individual received a check from Metavante, a credit union’s bill paying service, on which payment had been stopped. The individual receiving the check routinely deposited it in his credit union. A few days later he received a notice that payment had been stopped and he was being assessed a $10 fee as a result. The problem is there was insufficient funds in the members account at the issuing credit union on the date the check was issued.
Now, the big question is “Why did the credit union or Metavante even issue a check knowing there was insufficient funds in the account?” This puts the CU and Metavante in a very negative light especially with the person receiving the check. Should this person “trust” future checks from Metavante?

Every person we put this question to has expressed surprise . . . and shock in some cases.

A chat with the Credit Union official says that’s how the Metavante program works and that it worked well. Metavante says “no comment.”

We think we have a finger pointing situation here on a poorly designed service whether it’s the Credit Union’s fault or Metavante. When the check bounced the first time, a fee of $25 was assessed. Metavante processed the bad check a second time resulting in a second fee of $25. It’s interesting to note that when the Metavante check was presented for payment, there were sufficient funds in the member’s account to clear the check.

So here we are. Metavante says it’s the credit union’s policy. The Credit Union says “that’s the way the program works.” The member is out $50 bucks. The bill paying recipient is out $10.

Industry consultants say 10% to 20% of households generate the bulk of overdraft income. The households hit hardest by overdrafts pay an average of $1,374 a year in fees, estimates G. Michael Flores, founder of Bretton Woods, a management advisory firm that works with financial institutions.

If consumers overdraw on a $20 debit card or bill paying transaction, are charged the median fee of $27 and repay the credit in two weeks, they're effectively paying a 3,520% APR, according to the Federal Deposit Insurance Corp.

Robin Rutan, of Glenwood Springs, Colo., says her local credit union pays transactions that overdraw her account by a few cents, without her permission, and charges her $27.

Here is what some firefighter credit unions do.

Charlotte Fire Department Credit Union uses IPay. They receive a file from IPay for posting. If an account does not have sufficient funds, the credit union has an option to post or not post the transaction and determines if a fee should be assessed . . . but no check is issued if funds are not available.

Houston Firefighters Fed. Credit Union says if a member does not have the funds to cover the check, they do not pay it. They also do not charge a fee. If the member signs up for e-mail notification, we will e-mail them that we did not pay the bill. We will try again for the next two of days and then stop.

San Francisco Fire Credit Union says,”If a member has scheduled a payment and there are no funds in the account we do one of two things: 1) We offer courtesy pay up to $750 so if the bill does not take them over that limit, we will issue the payment (97% of all online bill payments are process electronically so no checks are cut) and charge the member a fee.

2) If they either opted out of courtesy pay or are over the limit for courtesy pay we will retry for 3 days and post a message in home banking letting the member know we can’t process the payment – no fee.”

San Diego Firefighters Fed. Credit Union uses IPay. The Credit Union will pay the bill so long as the member has direct deposit and charge them a courtesy pay fee of $22. This is only good for bills up to $1,500. If the bills total over $1,500, they will not pay but return to IPAY. They will then notify the member via e-mail that the bill was not paid due to insufficient funds.

What does your Credit Union do? Share with us who your bill payment processor is. Do they issue checks and then stop payment on them? What is your policy regarding fees and insufficient funds? Send to billrogers@swbell.net. Also, note that Metavante is now part of FIS.

Airport Deals for You And Your Car

Hate having to get up at an ungodly hour for an early-morning flight, drive to the airport in the dark, park your car, then dash to the terminal? Here's one way to cut the hassle and get a good night's sleep. Consider a package deal that includes an airport hotel for the night before your flight, seven to 14 days of parking, and a shuttle to and from your gate-all costing not much more than parking alone.

ParkSleepFly.com is a one-stop shopping site where you can compare the rates and amenities of hotel brands, giving you a choice of more than 1,500 airport hotels in 129 cities in the United States and Canada, and even a few in Europe. Similar sites are Stayl23.com and ParkingAccess .com.

Sunday, March 28, 2010

New rules for fee-depleting gift cards

Gift cards have become so popular, given to or by 95 percent of Americans, angering so many of them with unexpected fees and timing-out deadlines, that the Federal Reserve has stepped in with some new rules.

Have you ever found a gift card tucked away only to pull it out and use it and find that all but $3.25 cents of it has been eaten up in fees? I'm not exaggerating. My kids get lots of gift cards as gifts, and because they are not the best at keeping track of such things, this kind of thing has happened around here. So it's good to hear about these changes, though don't expect them to put an end to all fees on gift cards.

Here's what the Fed says will happen as of August 22:

>  Consumers must have at least five years to use gift cards before they expire.

>  However, service or inactivity fees can still be applied, under certain conditions --

>  if the consumer hasn't used the card for at least a year

>  if the consumer is given clear disclosures about them, and

>  no more than one fee is charged a month

Some better. But it's still buyer beware you may be giving a gift that won't be fully used, and recipient remember to use your gift cards! Right away!

Friday, March 26, 2010

Airports to get whole body imagers

Reported by a brokerage firm, 3/25/10

Whole Body Imagers Order Expected: The TSA has a goal of deploying approximately 1,000 whole body imagers in airports by the end of 2011, and another order is expected to come down in the next 30 – 60 days. We believe this order will be for around $50 million, and will be split between the two companies currently certified to provide systems to the TSA, OSI and L-3.

Thursday, March 25, 2010

LifeLock to pay $12M in false-claims settlement

LifeLock Inc. has agreed to pay $11 million to the Federal Trade Commission (FTC) and $1 million to a group of 35 state attorneys general to settle charges that the company used false claims to promote its identity theft protection services.

It is one of the largest FTC-state coordinated settlements on record, said FTC. LifeLock and its principals will be barred from making deceptive claims and required to take more stringent measures to safeguard the personal data they collect from customers, FTC said.

The company and its co-founders, Richard Todd Davis and Robert J. Maynard Jr., are barred from misrepresenting the "means, methods, procedures, effects, effectiveness, coverage, or scope of any identity theft protection service." The settlements also bar misrepresentations about the risk of identity theft and the manner and extent to which LifeLock protects consumers' personal information.

The settlements also require LifeLock to establish a comprehensive data security program and obtain biennial independent third-party assessments of that program for 20 years.

Since 2006, LifeLock's ads claimed it could prevent identity theft for consumers willing to sign up for its $10-a-month service, said the FTC.

The agency noted that LifeLock's fraud alerts on customers' credit files protected against only certain forms of identity theft and gave no protection against the misuse of existing accounts; that they did not protect against medical identity theft or employment identity theft; and that they could not provide absolute protection against new account fraud, where fraud alerts are most common.

Other claims made--that LifeLock could prevent unauthorized changes to customers' address information, that it constantly monitored activity on customer credit reports, and that it would ensure the customer always received a telephone call from a potential creditor before opening a new account--were also false, said FTC.

The FTC said it will use the $11 million it receives from the settlements to provide refunds to consumers. It will send letters to current and former LifeLock customers who may be eligible for the refunds, and instructions for applying.

Wednesday, March 24, 2010

Fingerprint The Same As Credit Card Theft?

By Ravi Das

You know what, today, I was going to start the same process for my daily writings as I always do. That is, look at the latest Press Releases, and decide what is important enough to report to my blog subscribers.

Once I pick a Press Release for the day, I then read it very thoroughly, and analyze the information from it.

As you have noticed, usually the first section is a summary of the Press Release, which is just usually the highlights. The second section usually contains my analysis of the Press Release.

Well, today I thought I would try something just a little different. I attend a lot of networking events here in the Chicago and surrounding areas to promote my newsletter, and other services.

A question I keep getting asked all the time: “What if my fingerprint is stolen”??? And in fact, I was just asked this question a number of times this morning.

Well, my usual answer is that yes, it is a form of ID Theft. But, put things in perspective. It’s not quite the same as Credit Card Theft. With a fingerprint, it’s not the actual fingerprint which is stored, just the mathematical representation of it.

So for instance, look at your fingerprint, and imagine a bunch of one’s and zeroes. That is what your fingerprint is to a Fingerprint Scanner, and what is stored. So, yes there is some possibility something bad could happen, but the chances are sort of remote.

Now look at your Credit Card. You will see the number, and if your card is stolen, yes, there is a lot of damage which can happen. At this point, after you discover your card is missing, hopefully you will contact your credit card company immediately.

So, the two are not exactly the same.

Well, in an attempt to further explore this topic, here is an editorial I wrote, specifically on this. It appears in one of the sample newsletters on my website, which is http://www.biometricnews.net/ .

Tuesday, March 23, 2010

Man could face felony for not giving bank back money

A man could face felony charges for refusing to give back money to a Cape Girardeau (MO) bank that claims a teller inadvertently gave the customer too much money. Police tell the Southeast Missourian they are still investigating the incident that happened Friday at the Bank of Missouri, but charges of stealing more than $500 are being considered. So far, no charges have been filed.

Police spokesman Adam Glueck says the man came to the bank to exchange a large stack of mixed bills for a stack of $20 bills, but the teller accidentally gave him substantially more than he was owed. The error was discovered after the customer left.

When the bank and police contacted the man, he refused to turn over the excess amount, saying he was given the correct amount. (What do you think his reaction would be if he was short-changed?

Monday, March 22, 2010

Do these people work for your credit union?

Do these people work for your credit union?

A woman at work was seen putting a credit card into her floppy drive and pulling it out very quickly.

When I inquired as to what she was doing, she said she was shopping on the Internet and they kept asking for a credit card number, so she was using the ATM 'thingy.'

---------------

Several years ago, we had an Intern who was none too swift. One day she was typing and turned to a secretary and said, 'I'm almost out of typing paper. What do I do?' 'Just use paper from the photocopier', the secretary told her.

With that, the intern took her last remaining blank piece of paper, put it on the photocopier and proceeded to make five 'blank' copies.

Thursday, March 18, 2010

CUNA advises on 10 places not to use a debit card

There are 10 situations where consumers should keep their debit card in their wallet, according to CreditCards.com. periodicals, provides some of the advice.

Don't use a debit card online. Not using debit cards online was No. 1 on the list. Since the debit card links directly to a checking account, .

Most lists warn against letting a credit or debit card out of sight at a restaurant, but restaurants are one of the few places where the consumer must let the card out of sight to use it. Avoiding such situations isn't workable.

Some gas stations and hotels will place holds to cover customers who may leave without settling the entire bill.

That means that even though the consumer bought only $10 in gas, the hotel can have a temporary banking hold for $50 to $100/ The practice isn't as noticeable if paying with a credit card but can be problematic for debit card users with just enough funds in the account to cover the purchase.

Don't use debit cards for:

1. Online;
2. For big-ticket items;
3. When a deposit is required;
4. At restaurants;
5. If you're a new customer;
6. When you buy now and take delivery later;
7. For recurring payments;
8. For future travel;
9. At gas stations and hotels; and
10.When the ATM looks "off."

Wednesday, March 17, 2010

Technology Made Me Do This

Data Breach Incidents Cost U.S. Companies

The Ponemon Institute released a study last month which examined 43 organizations across 17 different industry sectors, showing that data breach incidents cost U.S. companies $202 per compromised customer record in 2008, compared to $197 in 2007.

Since the study's inception in 2005, this cost component has grown by more than $64 on a per victim basis, nearly a 40% increase.

Tuesday, March 16, 2010

Convictions for Major Hackers

Albert Gonzalez, the convicted ringleader of a major hacking and thieving operation that cost credit unions millions of dollars, awaits sentencing by a federal court. But as he awaits his fate, the cases of his co-conspirators are being resolved, according to court documents.

The latest is Humza Zaman, 33, former network programmer for Barclay's Bank. Zaman pled guilty to being part of the back-end, money laundering part of the Gonzalez operation rather than the hacking part.

Prosecutors charged Zaman with helping Gonzalex repatriate American currency that purchasers of the stolen card data paid for the information.

“In late 2005 and early 2006, Zaman traveled to California at Gonzalez’s direction on approximately three occasions,” the prosecutors said in a memo, which supported their recommendation that Zaman serve 46 months in federal prison with other penalties.

“There, he met with an unknown man of apparent Eastern European descent. On each occasion, Zaman picked up between $50,000 and $370,000 in currency. Zaman then put the currency, minus his cut, in Federal Express boxes and shipped the money using a fictitious name to Gonzalez in Miami,” the prosecutors added.

In the end the court agreed with the prosecutors, sentencing Zaman to 46 months in prison and a fine of $75,000.

Online crime losses more than doubled in 2009

Online crime losses more than doubled during 2009, reaching $559.7 million, according to the Internet Crime Complaint Center (IC3). That compares with $265 million lost during 2008.

IC3 is a partnership between the Federal Bureau of Investigation (FBI) and the National White Collar Crime Center (NW3C).

The number of complaints also rose--to 336,655 complaints, or 22.3% more than the 275,284 complaints filed in 2008.

Complaints involved fraud and nonfraud categories including auction fraud, nondelivery of merchandise fraud, credit card fraud, computer intrusions, spam/unsolicited e-mail, and child pornography, said IC3.

In 2009, IC3 implemented a new complaint classification system, separating complaints into 79 categories. This resulted in a number of changes to the way the system gathers the data and classifies complaint data.

Among the significant findings for 2009:

> E-mail scams that used the FBI's name to gain information represented 16.6% of all complaints submitted. Nondelivered merchandise and/or payment accounted for 11.9% of complaints, advance fee fraud made up 9.8%. Rounding out the top five categories were identity theft and overpayment fraud.

> Of the top five categories of offenses reported, nondelivered merchandise and/or payment ranked 19.9%, identity theft, 14.1%, credit card fraud, 10.4%, auction fraud, 10.3%, and computer fraud (destruction/damage/vandalism), 7.9%.

> Of the complaints involving financial harm and referred to law enforcement, the highest median dollar losses were found among investment fraud ($3,200), overpayment fraud ($2,500), and advance fee fraud ($1,500).

>Among complainants, 54% were male, nearly two-thirds were between the ages of 30 and 50, and more than one-third resided in either California, Florida, Texas or New York. Ninety-two percent of the complaints were from the U.S.

>Males lost more money than females. Men lost $1.51 to every $1 that women lost. Individuals who were between 40 and 49 years old on average lost more than other age groups.

Monday, March 15, 2010

Adjusting currency for blind would impact ATMs, CUs

Credit unions could be impacted by proposed changes to U.S. currency that would make denominations easier to read for the visually impaired.

The U.S. Bureau of Engraving and Printing is working to redesign banknotes after the U.S. Court of Appeals in the District of Columbia in 2008 upheld a 2006 lower court ruling that the federal government violated the U.S. Rehabilitation Act by not providing meaningful access to banknotes for the blind and visually impaired.

The Treasury is proceeding to redesign currency and will soon seek comment on the proposed designs. The comment period is expected to last about 90 days, said James Hanisch, executive vice president of CO-OP Financial Services in Rancho Cucamonga, Calif., a credit union service organization.

Depending on which design the Treasury proposes and what denominations will be affected, the changes could be a "fairly expensive proposition" for credit unions. The $20 bill is the most commonly dispensed at ATMs, and its change would have the largest impact. The $1 bill will be exempt, and the $100 bill will be grandfathered in the next redesign, Hanisch said.

Changes in currency sizes could mean adjustments to cash drawers, vaults, and ATM canisters and dispensers. ATM manufacturers already have the capabilities to change the machines, since many countries have already adjusted their currency sizes for the visually impaired, he added.

Currency changes could cost $3,000 to $5,000 per ATM, depending on the denomination. CO-OP offers about 28,000 ATMs, Hanisch said.

At minimum, the changes are a year a way. "It's just starting to sink in how significant this could possibly be," Hanisch said.

Sunday, March 14, 2010

Fiber optic speed coming to computers

High-speed data communication isn’t so speedy by the time it reaches your video player or smartphone.

Lasers may send information flying in tiny bursts of light through optical fibers across oceans and cities. But you’re still in the electronic slow lane when you’re transferring high-definition videos or other large files between devices. Then the content travels only at the rate permitted by the USB or other cord.

But soon, some data exchanges between consumer gadgets may travel at the higher rate of fiber optics, letting people transfer a Blu-ray version of “Gone With the Wind,” for example, or the complete family photo archive in less than a minute.

Later this year, Intel will introduce its Light Peak fiber optic link, in a bid to replace USB and other electrical cables that connect computers with digital cameras, music players, smartphones and dozens of other devices, said Jason Ziller, Intel’s director for the optical input-output program office. Light Peak optical cable technology, which includes computer chips and miniature lasers, will be available to manufacturers later this year, he said, for installation in products next year. Prices are not yet available from Intel.

(Read the entire article at: http://www.stltoday.com/stltoday/news/stories.nsf/nation/story/D05D94426042D100862576E600103DBC?OpenDocument
or
http://bit.ly/b8yRj1

Thursday, March 4, 2010

Continental to let coach customers buy more space

Continental Airlines will begin charging coach customers extra if they want a seat with more legroom.

Prices will vary depending on the length of a flight and popularity of the route. A spokeswoman said extra room on a Houston-New York flight might cost $59. International fliers would pay more than that.

Starting March 17, coach customers will be able to pay the charge at check-in to get an exit-row seat with at least 7 inches more legroom than the other rows, Continental said Wednesday.

Top-level members of Continental's frequent-flier program - those who rack up at least 25,000 miles a year - and their traveling companions will still be able to claim the exit row without extra charge.

To see what other airlines are doing, visit:  http://bit.ly/8YCZKV  

Google 411 Info Service - FREE

Google's new 411 information service is free, fast and easy to use. Give it a try now and see how simple it is to find and connect with local businesses for free.

Dial from any phone  -  (1-800-466-4411)   1-800-GOOG-411

See demo at:  http://www.google.com/goog411/index.html

Monday, March 1, 2010

Stalker Fear Over Phone App

A CAMERAPHONE application that finds names and addresses of total STRANGERS was blasted as a "stalker's dream". The facial recognition "app" instantly identifies snaps by matching them to photos on websites like Facebook and Twitter, where personal info is accessed.

Horrified security experts claim BURGLARS taking secret snaps of revellers could find out their addresses. Unsuspecting strangers fooling around on nights out could also fall prey to BLACKMAIL.

And women could be stalked by PERVERTS.

Simon Davies, of Privacy International, slammed the "Recognizr" gizmo as an "atrocious invasion". He warned: "It takes the dangers that already exist and increases them infinitely."

Dr Ian Brown, of the Oxford Internet Institute, said: "A guy could take a picture of a girl in a bar and find out all sorts of information."

The "app" is being developed by Swedish software firm The Astonishing Tribe. They were unavailable for comment.

Tom Gaffney, of software security experts F-Secure, said: "This app looks like it could be a stalker's dream."

Read more: http://www.thesun.co.uk/sol/homepage/news/2872019/Stalker-fear-over-facial-recognition-phone-app.html#ixzz0gxUDL8Of

Or

http://bit.ly/ajAhHr

February News & Views Published Below

CU SECURITY & TECHNOLOGY News - Providing a brief summary of news and information related to security and technology issues for credit unions - Plus some interesting and fun web sites . . .
(Click on photo to enlarge)

Sunday, February 28, 2010

Please Rob Me

Please Rob Me . . . lists all those empty homes out there. Is yours one of them?

http://www.pleaserobme.com/

Actual message on School Answering Machine in Australia

A must view for anyone with kids of any age.

This is the message that the Maroochydore High School, Queensland ,Australia, staff voted unanimously to record on their school telephone answering machine. This is the actual answering machine message for the school.

This came about because they implemented a policy requiring students and parents to be responsible for their children's absences and missing homework. The school and teachers are being sued by parents who want their children's failing grades changed to passing grades - even though those children were absent 15-30 times during the semester and did not complete enough school work to pass their classes.

Way to go, Aussies!

http://www.youtube.com/watch?v=Pwghabw4N80

Note: after this post was made, we learned the above event was a hoax. Even so, it's pretty funny. Don't you just wish that all of our schools operated like this?

Friday, February 19, 2010

Perfect Solution to Airport Scanning

Here's a solution to all the controversy over full-body scanners.

I think the Transportation Security Adminstration is making things way too complicated.

Have a booth that you can step into that will NOT x-ray you, but will detonate any explosive device you may have on you.

It would be a win-win for everyone. So simple.
Click on photo to enlarge

Friday, February 12, 2010

The Top Ten Gross Things People Do On Airplanes

We all know about the rare instances of airline passenger misconduct that make it to the headlines, like the case of the naked, angry flyer or the fighting Lohan, but every day little instances of pure gross occur unnoticed or just unreported.

Perhaps you've spotted someone getting a little too frisky beneath their $5 on-board purchase blanket or going about some hygienic business, but chances are you haven't seen all Top Ten Gross Things People Do On Airplanes:

10. Browse dating websites over the in-flight WiFi

We know that having in-flight WiFi is new and great and magical, but it's best to keep your private profile and your preferences for "18/F/Asian" private.

9. Sleep on you/sleep on the floor

It's a long flight back from Hawaii and your seatmate had two too many Mai Tais. Before you can say "Mauna Loa," he's conked out on your shoulder and speedily producing a lava flow of glistening drool.

8. Use the main aisle as a space to do sit-ups, push-ups or change your child's diaper

The aisle is not your gym, nor is it a changing table. No one wants to see your lunging butt centimeters away from them as you attempt calisthenics.

7. Read Hustler, or other "adult" magazines

We realize that airport bookstores and newspaper kiosks sell adult magazines, but that doesn't mean you should immediately "read" them on the plane; those are for after the flight.

6. Attempt to join the Mile High Club

Although it seems flirty and adventurous to get in a mood with your partner and try to see things through while in-flight, keep in mind that you're in a public space.

5. Attempt to join the Mile High Club solo

The provided (or purchsed) airline blanket does not mean you have complete privacy and carte blanche to do what you will underneath it.

4. Eat fried chicken

Don't bring it on a bus, don't bring it on a train, and definitely don't bring it on a plane: smelly, greasy, messy food.

3. Tend to foot hygiene

There are foot fetishists and then there's everyone else. Feet just aren't the sort of thing that you want spending 8 hours a few inches away from the side of your face, especially if they're not your own feet (doing some yoga there?).

2. Vomit into something that is not the supplied barf bag

Thanks. We have a gross image of this in our head: "Saw someone use the plastic wrap from an airline blanket as a barf bag...didn't really work."

1. Sneeze open-mouthed/neglect to wash hands after using lavatory

This in-flight offense takes the number one spot because it happens most frequently and can affect the most passengers.

See more details at: http://bit.ly/ccXhQ7

I just verified the above address and got a warning - probably because the regular address is very long. Don't worrk, it works.

Feds push for tracking cell phones

Two years ago, when the FBI was stymied by a band of armed robbers known as the "Scarecrow Bandits" that had robbed more than 20 Texas banks, it came up with a novel method of locating the thieves.

FBI agents obtained logs from mobile phone companies corresponding to what their cellular towers had recorded at the time of a dozen different bank robberies in the Dallas area. The voluminous records showed that two phones had made calls around the time of all 12 heists, and that those phones belonged to men named Tony Hewitt and Corey Duffey. A jury eventually convicted the duo of multiple bank robbery and weapons charges.

Even though police are tapping into the locations of mobile phones thousands of times a year, the legal ground rules remain unclear, and federal privacy laws written a generation ago are ambiguous at best. On Friday, the first federal appeals court to consider the topic will hear oral arguments (PDF) in a case that could establish new standards for locating wireless devices.

In that case, the Obama administration has argued that warrantless tracking is permitted because Americans enjoy no "reasonable expectation of privacy" in their--or at least their cell phones'--whereabouts. U.S. Department of Justice lawyers say that "a customer's Fourth Amendment rights are not violated when the phone company reveals to the government its own records" that show where a mobile device placed and received calls.

Read more of this interesting story at: http://news.cnet.com/8301-13578_3-10451518-38.html

New Malware Threat for Sale

The global black market for financial services malware now includes a new player, for sale to hackers who want to target the financial credentials of customers of large and mid-sized U.S. banks, according to SecureWorks.

The Atlanta-based online security specialists have given the Trojan the name “Bugat.”

Jason Milletary, a SecureWorks security researcher, said his firm believes the new malware was developed to compete with more costly or hard to buy Trojans such as Zeus and Clampi.

“The emergence of Bugat reinforces that there is a strong demand for new malware to commit financial credential theft and that ACH and wire fraud remains a profitable venture for criminals,” Milletary said.

SecureWorks has posted a research blog note on the find. It’s at www.secureworks.com/research/blog.

FSCC awards CUs for stopping over $1.1M in fraud

Financial Service Centers Cooperative (FSCC) announced that it gave awards to 12 credit unions for stopping more than $1.1 million in fraud activity during 2009. The credit unions garnered about 50 Fraud Buster Awards. The awards were presented to credit unions on a quarterly basis during 2009.

Award recipients included credit unions that participate in the FSCC Shared Branching Network. The recipients of the Fraud Buster Awards were recognized for protecting their credit unions, their members, and members of other credit unions from fraud.

FSCC maintains an Operations Advisory Committee comprising of stockholder credit unions. The committee reviews activity and looks at ways to prevent and detect fraud through rule changes, training, products and services. In the nine years the awards have been presented, credit unions have stopped more than $7.5 million from fraudulent activities. FSCC has presented more than 280 awards.

Financial institutions in the U.S. lose about $12 billion a year in check fraud, and the retail industry loses a similar amount resulting in losses of $24 billion as a result of check fraud. The Federal Trade Commission also reports that financial institutions and businesses lose more than $48 billion annually from fraudulent activities, according to statistics FSCC cited from U.S. News and World Report.

Thursday, February 11, 2010

ID Theft at All-Time High

The number of identity fraud victims in the U.S. increased 12% to 11.1 million adults in 2009--the highest increase since 2003, according to a new ID theft study. The total annual fraud amount increased by 12.5% to $54 billion.

The high is probably due to the economic downturn, Javelin Strategy and Research said in its study, "The 2010 Identity Fraud Survey Report," which was co-sponsored by Intersections, a CUNA Strategic Service, that specializes in I.D. theft prevention services.

Average fraud resolution time dropped 30% to 21 hours. Nearly half of new victims file police reports, resulting in double the reported arrests, triple the prosecutions and double the percentage of convictions in 2009.

Thirty-nine percent of identity fraud victims reported fraudulent new credit card accounts, up from 33% in 2008. New online accounts opened fraudulently more than doubled over 2008, and the number of new e-mail payment accounts increased 12%.

Financial services companies continue to excel in detecting fraud and alerting their customers. More than one-third of victims first learned about the fraud from their financial institution, the report said.

Other findings:

>  Identification most likely to be compromised in a data breach continues to be full name (63%) and physical address (37%). Compromised health insurance information increased 4% over the last year.

>  About 75% of existing card fraud incidents came from credit cards, an increase of 12% over 2008. Existing debit cards fraud incidents represented 33% of total existing card fraud in 2009 and decreased by 2%.

>  Eighteen to 24-year-olds are the slowest to detect fraud--they take nearly twice as many days to detect it as other age groups. They were found to be less likely to monitor accounts regularly and the least likely group to take advantage of monitoring programs offered by financial institutions. However, they are the most likely group to take action such as switching primary institutions or switching forms of payment if fraud occurs.

> Identity fraud victims in the U.S. grew to 4.8% of  the population, with a projected total of $54 billion in crime.

>  Small business owners suffer fraud at one-and-a-half times the rate of other adults, because small office and home office business owners use personal accounts when making business transactions and make more transactions than typical adults.

"Identity fraud continues on the upswing, and we believe it will continue to rise if consumers fail to take proactive steps to prevent fraudsters from taking advantage of their offline and online transactions and their increasingly exposed personal information on social networks," said Michael Stanfield, Intersections chairman/CEO. "In addition, consumers need to protect themselves and their computers from sophisticated malware, and well-conceived and executed spam and phishing attacks."

Intersections offered several tips to reduce identity fraud, including the use of direct deposit, installing software to protect against viruses and spyware, turning off Bluetooth or Wi-Fi when not in use, monitoring accounts weekly, and acting quickly when fraud is suspected.

Tuesday, February 9, 2010

CURE 1-Year Old

Credit Union Retired Executives (CURE), at http://www.curetiredexecs.com/  is pleased to announce the celebration of the 1st anniversary of its unique new online service, which offers free and confidential advice that is tailored to questions from credit union professionals.

During this inaugural year, the 26 Advisors have answered more than 250 questions from credit union professionals nationwide.

Friday, February 5, 2010

What can private corporations do to employees? Just about everything

Toni Bowers with Tech Republic writes an interesting. Details are at: http://blogs.techrepublic.com.com/career/?p=1706&tag=nl.e101


In his new book Can they do that?, Lewis Maltby says that employees are often surprised at the reasons over which they can be fired.

With all that you hear today in the news about employees suing former employers, you’d think that it would be very difficult for an employer to actually fire someone. But the reality is different in the private sector.

In a recent interview on NPR, Maltby said, “Freedom of speech is protected by the First Amendment - but only where the government is concerned. What most Americans generally don’t know is that the Constitution doesn’t apply to private corporations at all.”

Private corporations can fire someone for almost anything. Maltby related an incident when a worker was fired for having a bumper sticker that expressed a political view that did not jibe with the CEO’s.

The only thing that a corporation cannot do is eavesdrop on a personal oral conversation. Anything else, Maltby said, “is open season.”

I’ve written before about how employers-potential and existing-are within legal limits to peruse individuals’ personal blogs or Facebook pages, and to watch what you put there. Maltby says employers do this regularly and can fire someone over what they see.

And it doesn’t stop there. In his book, Maltby relates stories of employer abuses that include tracking employees through cell phone GPS locators to placing hidden cameras in restrooms. He says that 20% of employers now require employees to agree before being hired not to go to court if the corporation violates their legal rights.

While most people would agree that a private company has the right to run itself any way it sees fit, you can see how this right could be abused. Maltby is pushing for the Bill of Rights to apply to the private sector. In the book appendixes, he provides sample letters to elected representatives and human rights organizations as well as an Employee Bill of Rights.

You're Invited



Technology Brings Double-Digit CU Member Growth to Mexico

Technology Does Pay.  Believe me.

Thanks to the installation of high-powered computer servers and the use of handheld transaction devices like PDAs, Mexican credit union Caja Yanga is experiencing a 15% monthly growth rate.

In anticipation of the launch of Caja Yanga's first ATMs last month, the credit union installed a new information technology infrastructure and moved its principal data center. In addition to bringing the credit union into compliance with federal regulations, the move drastically improved data transfer efficiency, providing the capacity to support projected growth.

The credit union also implemented a WOCCU outreach model in which field officers bring savings-focused financial services to members on foot or motorcycle and use PDAs to conduct transactions and transmit data. Last year, field officers performed 80,960 PDA-based financial transactions for remote members.

Monday, February 1, 2010

CU Information Security Conference Set for May 19-21

One of the biggest needs in credit unions today is security. The 10th annual credit union security conference is set for May 19-21, 2010 at the Red Rock Resort in Las Vegas. This popular conference offers one of the highest dollar values of any other conference serving credit unions. Your registration fee includes the first two nights lodging FREE - No Extra Cost.  Check out the program agenda, schedule, a site visit to an area credit union, speakers and more at:  http://bit.ly/cusecurity2010.