The US-based Financial Services Technology Consortium has launched a project to investigate the use of biometrics for verifying customer IDs. The FSTC says over 20 banks have expressed an interest in the project, including the American Bankers Association which has signed on as a sponsor.
Dan Schutzer, executive director FSTC says the programm will endeavour to develop a methodology for banks to better select, specify, evaluate and deploy biometric applications with greater customer acceptance.
"We also hope to identify and validate at least one or two of them that will make an immediate impact in the fight against identity theft and insider fraud," he adds.
The initiative grew out of a panel discussion at a joint FSTC/Bits summit in early March. A follow-up meeting is planned for later this month at Wells Fargo Bank in San Francisco.
A global survey conducted by Unisys last year found that 72% of US citizens would be willing to undergo fingerprint scans to verify their identities when dealing with banks and government organisations.
Sunday, April 5, 2009
US banks sign up for biometric project
Tuesday, March 31, 2009
March News & Views Published Below
CU SECURITY & TECHNOLOGY News - Providing a brief summary of news and information related to security and technology issues for credit unions - Plus some interesting and fun web sites. Join us for our annual security conference in June. Here's the location.
..

Stolen ID: 20 tips to protect yourself
You can take steps to protect yourself from identity fraud:
Keep your confidential information private. Your bank or credit card company won't call or e-mail to ask for your account information. They already have it.
Keep an inventory of everything in your wallet and your PDA, including account numbers. Don't keep your Social Security card or any card with your Social Security number, such as an insurance card, in your wallet.
Stop getting banking and credit card information in the mail. (See "Go paperless for safer banking.")
Monitor your bank and credit card transactions for unauthorized use. Crooks with your account numbers usually start small to see if you'll notice.
Keep your vehicle registration and insurance forms in a sealed envelope in your glove box and lock it and your car when at home or away.
If you conduct business online, use your own computer. A public computer is less secure, as is wireless Internet.
Look for suspicious devices and don't let anyone stand nearby when you use an ATM. Take your card and receipt with you. Keep your PIN in your head, not in your wallet.
Don't store credit card numbers and other financial information on your cell phone. (See "Is your cell phone spilling your secrets?")
If you're job hunting using resume Web sites, don't apply unless the employer has a verifiable address.
Protect your computer from vulnerability:
Keep system and browser software up to date and set to the highest security level you can tolerate. Install anti-virus, anti-spyware and firewall protection, and keep them up to date as well. When possible use hardware firewalls, often available through your broadband connection router.
If you use wireless Internet access, make sure that you get help from someone who understands wireless security when you set up your access point or router.
Back up your data and store it way from your computer.
Don't open e-mails from strangers. Malware can be hidden in embedded attachments and graphics files.
Don't open attachments unless you know who sent them and what they contain. Never open executable attachments. Configure Windows so that the file extensions of known file types are not hidden.
Don't click on pop-ups. Configure Windows or your Web browser to block them.
Don't provide your credit card number online unless you are making a purchase from a Web site you trust. Reputable sites will always direct you to a secure page with an URL starting with https:// whenever you actually make purchases or are asked to provide confidential information.
Use strong passwords: at least six characters, including at least one symbol and number, and no reference to your name or other personal information. Use a different password for every site that requires one, and change passwords regularly.
Never send a user name, password or other confidential information via e-mail.
Consider turning off your computer when you're not using it or at least putting it in standby mode.
Don't keep passwords, tax returns or other financial information on your hard drive.
Keep your confidential information private. Your bank or credit card company won't call or e-mail to ask for your account information. They already have it.
Keep an inventory of everything in your wallet and your PDA, including account numbers. Don't keep your Social Security card or any card with your Social Security number, such as an insurance card, in your wallet.
Stop getting banking and credit card information in the mail. (See "Go paperless for safer banking.")
Monitor your bank and credit card transactions for unauthorized use. Crooks with your account numbers usually start small to see if you'll notice.
Keep your vehicle registration and insurance forms in a sealed envelope in your glove box and lock it and your car when at home or away.
If you conduct business online, use your own computer. A public computer is less secure, as is wireless Internet.
Look for suspicious devices and don't let anyone stand nearby when you use an ATM. Take your card and receipt with you. Keep your PIN in your head, not in your wallet.
Don't store credit card numbers and other financial information on your cell phone. (See "Is your cell phone spilling your secrets?")
If you're job hunting using resume Web sites, don't apply unless the employer has a verifiable address.
Protect your computer from vulnerability:
Keep system and browser software up to date and set to the highest security level you can tolerate. Install anti-virus, anti-spyware and firewall protection, and keep them up to date as well. When possible use hardware firewalls, often available through your broadband connection router.
If you use wireless Internet access, make sure that you get help from someone who understands wireless security when you set up your access point or router.
Back up your data and store it way from your computer.
Don't open e-mails from strangers. Malware can be hidden in embedded attachments and graphics files.
Don't open attachments unless you know who sent them and what they contain. Never open executable attachments. Configure Windows so that the file extensions of known file types are not hidden.
Don't click on pop-ups. Configure Windows or your Web browser to block them.
Don't provide your credit card number online unless you are making a purchase from a Web site you trust. Reputable sites will always direct you to a secure page with an URL starting with https:// whenever you actually make purchases or are asked to provide confidential information.
Use strong passwords: at least six characters, including at least one symbol and number, and no reference to your name or other personal information. Use a different password for every site that requires one, and change passwords regularly.
Never send a user name, password or other confidential information via e-mail.
Consider turning off your computer when you're not using it or at least putting it in standby mode.
Don't keep passwords, tax returns or other financial information on your hard drive.
Wednesday, March 25, 2009
Welcome to 419BAITER.COM, the land of extreme B.S.
Scamming the Scammers . . . http://419baiter.com/
To jump right in and see what this site is all about, click "The Games". Aside from some obfuscation of personal info (e-mail addresses and telephone numbers) and some text reformatting to improve readability, the e-mails depicted in these games are real and unedited in any way. Any spelling mistakes, bad grammar and
adult language have been left intact.
adult language have been left intact. A CAUTIONARY NOTE: Within the pages on this site, you are bound to run across some nasty language, photos, and voice/sound recordings which may be considered vulgar or offensive by some. While you certainly won't find any pornography on this site, some material on this site may offend some people.
Most of you have, at one time or another, received "Urgent Business Transaction" e-mails from someone asking for assistance in retrieving huge amounts of money in return for a good-sized percentage of the take. Maybe it's an e-mail informing you that you've won a lottery that you've never bought a ticket for. Maybe it's a job offer cashing checks in return for a commission.
These are known as Nigerian 419 e-mails. 419 scam baiting involves responding to these e-mails posing as a potential victim of their scam and getting them to trust you to the extent that they waste a lot of their time and hopefully some money trying to bilk you out of your hard-earned cash. With luck, the scammers also provide for a few laughs along the way.
This site is dedicated to this little-known but growing Internet sport.
These scams are named after section 419 of the Nigerian penal code which deals with this type of scam. However, Nigeria is certainly not the only country from which these e-mails originate. I have had these e-mails come from virtually every part of the world - Europe, Asia, Africa, Australia, UK, Canada, etc. This site will consider dealing with any type of advance fee fraud proposal that arrives by e-mail, regardless of its origin.
And it's not only poor and/or uneducated street criminals that perpetrate these scams. Many of these scammers are very well educated. Often bureaucrats are involved, either acting on their own or with the blessing (and even the support) of their corrupt government bosses, as demonstrated by these scam e-mails sent from a Malaysian government computer or this one sent from a Brazilian government computer.
You can find plenty of examples of some of the most popular formats along with explanations on the 419 Scam Examples page.
Thursday, March 19, 2009
CUs warn of rash of automated phishing calls
Several credit unions nationwide are reporting an uptick in the number of automated phishing calls seeking to obtain personal information from members.
Some recent incidents:
1. Several Wisconsin credit unions report scam artists are using automated phone calls with recordings that ask members to divulge personal financial information, according to the Wisconsin Credit Union League. Phishing calls reported Tuesday claimed the member's credit and/or debit card had been locked and asked for the card number to unlock it. The Credit Union National Association also noted variations on scam tactics and said unsolicited requests for personal information have circulated under the subjects: "Account Deactivation," "Account Status Alert," "Changes to Terms and Conditions," and "Irregular Activity."
Click here to read about 9 other credit unions hit by phishers.
http://www.cuna.org/newsnow/09/system031809-6.html?ref=hed
Some recent incidents:
1. Several Wisconsin credit unions report scam artists are using automated phone calls with recordings that ask members to divulge personal financial information, according to the Wisconsin Credit Union League. Phishing calls reported Tuesday claimed the member's credit and/or debit card had been locked and asked for the card number to unlock it. The Credit Union National Association also noted variations on scam tactics and said unsolicited requests for personal information have circulated under the subjects: "Account Deactivation," "Account Status Alert," "Changes to Terms and Conditions," and "Irregular Activity."
Click here to read about 9 other credit unions hit by phishers.
http://www.cuna.org/newsnow/09/system031809-6.html?ref=hed
Wednesday, March 18, 2009
Weight-Revealing Billboard Shames Fatties into Joining Gym
Here we see the results of an ad campaign for the gym chain Fitness First. The bus stop seat has a scale inside, hooked up to a readout on the billboard. The idea is to shame overweight bus-goers into signing up, and we love it. The campaign was designed by Amsterdam based agency N=5, and ran in the Netherlands.
That last part is probably the most relevant. Can you imagine something like this running in the US? The company responsible would be sued out of existence in about five seconds, a class action lawsuit citing "psychological damage" or some such nonsense.
Worse, though, would be the result if this ad were to run in England. I can (quite seriously) imagine children (who should be in school) lying in wait with bags of cream cakes, ready to throw them at anyone over 200lbs who has the naivete to sit on the scale.
Fitness First "Bus Stop" [
That last part is probably the most relevant. Can you imagine something like this running in the US? The company responsible would be sued out of existence in about five seconds, a class action lawsuit citing "psychological damage" or some such nonsense.
Worse, though, would be the result if this ad were to run in England. I can (quite seriously) imagine children (who should be in school) lying in wait with bags of cream cakes, ready to throw them at anyone over 200lbs who has the naivete to sit on the scale.
Fitness First "Bus Stop" [
Navy Federal Tweaks Anti-Robbery Policy
The biggest credit union in the U.S. has modified its policy on head coverings in branches to move the emphasis away from whether a member's head is covered to whether the member's full face can be seen.
The $36 billion Navy Federal's previous policy which required credit union members to remove head coverings when they entered credit union branches had led to complaints from a muslim female member who had been asked to conduct her transaction in a another room at the branch because she wore a head covering for religious reasons.
“The policy is that head coverings for religious reasons, cultural reasons, economic reasons are all acceptable, as long as we can see the members full face,” explained Tom Lyons, senior vice president for security for the Vienna, Virginia based federal credit union. “Our emphasis is on safety of our members and on preventing robberies and identity theft,” he said.
Lyons said the credit union had begun to implement the policy of asking members to remove head coverings and sun glasses when entering the branch as the economic downturn had begun to make robberies more likely.
The $36 billion Navy Federal's previous policy which required credit union members to remove head coverings when they entered credit union branches had led to complaints from a muslim female member who had been asked to conduct her transaction in a another room at the branch because she wore a head covering for religious reasons.
“The policy is that head coverings for religious reasons, cultural reasons, economic reasons are all acceptable, as long as we can see the members full face,” explained Tom Lyons, senior vice president for security for the Vienna, Virginia based federal credit union. “Our emphasis is on safety of our members and on preventing robberies and identity theft,” he said.
Lyons said the credit union had begun to implement the policy of asking members to remove head coverings and sun glasses when entering the branch as the economic downturn had begun to make robberies more likely.
Monday, March 16, 2009
The Starbucks Economic Indicator
The economic indiacator I monitor is the Starbucks at 290 & Spring Cypress Rd.
I pass there every Sunday @ 1:00 pm.Last Spring there would be 8-10 cars in line, now I usually see no more than two and sometimes none.
Another indicator is the advancing age of the workers at Starbucks, Papa Johns or other retail stores. 2009 is going to be a TOUGH year.
I pass there every Sunday @ 1:00 pm.Last Spring there would be 8-10 cars in line, now I usually see no more than two and sometimes none.
Another indicator is the advancing age of the workers at Starbucks, Papa Johns or other retail stores. 2009 is going to be a TOUGH year.
Saturday, March 7, 2009
TOP TECHNOLOGY BREAKTHROUGHS
1) Wireless world
2) Defense technology
3) Alternative fuel vehicles
4) Biotechnology
5) Computers
6) Lasers
7) Genomics
8) Global finance
9) Processors
10) Digital storage
11) Space
12) Fiber optics
13) Satellite TV & radio
14) DNA testing
15) Video games
16) Biometrics
17) Energy and water savers
18) Scanning tunneling microscopes
19) Batteries
20) E-baggage
21) Remote controls
22) Animal cloning
23) Manufacturing technology
24) The big picture
25) Weather technology
2) Defense technology
3) Alternative fuel vehicles
4) Biotechnology
5) Computers
6) Lasers
7) Genomics
8) Global finance
9) Processors
10) Digital storage
11) Space
12) Fiber optics
13) Satellite TV & radio
14) DNA testing
15) Video games
16) Biometrics
17) Energy and water savers
18) Scanning tunneling microscopes
19) Batteries
20) E-baggage
21) Remote controls
22) Animal cloning
23) Manufacturing technology
24) The big picture
25) Weather technology
Friday, March 6, 2009
Hoax Busters - the BIG LIST of Internet Hoaxes
An alphabetical list of Internet hoaxes, scams and chain letters. If it's on the list, it's a hoax. Please, if any doubt, check it out. - http://www.hoaxbusters.org.
Thursday, March 5, 2009
Harland Announces UltraData, Cavion Signings
Harland Financial Solutions said several more credit unions are now using its UltraData Enterprise core processing solutions.
That includes $1.2 million Genisys CU of Auburn Hills, Mich., which is the result of a recent merger between T&C FCU and USA CU. T&C already was an UltraData user.
The Lake Mary, Fla., company also said $103 million Bull Dog FCU will go live with an in-house UltraData platform on March 1. The Hagerstown, Md., credit union now is an Open Solutions customer, according to its 5300 Call Report. Meanwhile, $14 million Syracuse Cooperative FCU in New York will convert to a service bureau core processing relationship with UltraData. It currently is a CompuSource Systems client, according to NCUA records.
Two Huron, S.D., credit unions–$13 million Huron Area FCU and $3 million HB Telco FCU–will be converting from HFS’ CuServ platform to UltraData enterprise in a service bureau environment, the company said.
More than 550 credit unions now run UltraData, including more than 200 through the company’s service center in West Des Moines, Iowa.
The company also said it has signed 119 new users of its Cavion Internet Banking service in 2008 and 42 users of its Cavion Mobile Banking Professional service since it was launched several months ago.
That includes $1.2 million Genisys CU of Auburn Hills, Mich., which is the result of a recent merger between T&C FCU and USA CU. T&C already was an UltraData user.
The Lake Mary, Fla., company also said $103 million Bull Dog FCU will go live with an in-house UltraData platform on March 1. The Hagerstown, Md., credit union now is an Open Solutions customer, according to its 5300 Call Report. Meanwhile, $14 million Syracuse Cooperative FCU in New York will convert to a service bureau core processing relationship with UltraData. It currently is a CompuSource Systems client, according to NCUA records.
Two Huron, S.D., credit unions–$13 million Huron Area FCU and $3 million HB Telco FCU–will be converting from HFS’ CuServ platform to UltraData enterprise in a service bureau environment, the company said.
More than 550 credit unions now run UltraData, including more than 200 through the company’s service center in West Des Moines, Iowa.
The company also said it has signed 119 new users of its Cavion Internet Banking service in 2008 and 42 users of its Cavion Mobile Banking Professional service since it was launched several months ago.
Tuesday, March 3, 2009
Register 1 and Send More At No Cost
St. Louis, January 30, 2009 – William Rogers & Associates, sponsor of the CU InfoSECURITY Conference, announced that they are reducing their previously announced conference fee from $895 to $795. The reduction was brought about in discussion with the conference host site, MonteLago Village Resort at Lake Las Vegas, and as way to help credit unions receive much needed security information during these difficult economic times.
We have also announced a special registration. Register 1 person at the regular rate of $795 and send others from your credit union at no extra cost. The extra persons will be responsible for their lodging. That's it. The dates are June 4-5, 2009.
..

Conference Manager Bill Rogers said, “We’re pleased to pass this savings on to our conference attendees. This makes the conference even more valuable and affordable.” Rogers adds that “the conference registration fee includes two free nights lodging at a beautiful 5 star resort – a unique feature that only we offer to further help credit unions afford this one of a kind conference.” The CU InfoSECURITY Conference is the only conference in the credit union movement offering two nights lodging as part of their low conference fee.
Rogers added, “This is our 8th annual conference focusing on security issues facing credit unions. Security continues to be a top of mind issue for credit unions of all sizes. With over a dozen security expert speakers, a security tour of a Las Vegas credit union for pre-conference attendees, vendor exhibits and two nights free lodging, this makes for an outstanding program. It’s the best value in the credit union movement.”
The conference agenda, registration and more information is available at: https://www.cunews.com/infosec.htm.
We have also announced a special registration. Register 1 person at the regular rate of $795 and send others from your credit union at no extra cost. The extra persons will be responsible for their lodging. That's it. The dates are June 4-5, 2009.
..

Conference Manager Bill Rogers said, “We’re pleased to pass this savings on to our conference attendees. This makes the conference even more valuable and affordable.” Rogers adds that “the conference registration fee includes two free nights lodging at a beautiful 5 star resort – a unique feature that only we offer to further help credit unions afford this one of a kind conference.” The CU InfoSECURITY Conference is the only conference in the credit union movement offering two nights lodging as part of their low conference fee.
Rogers added, “This is our 8th annual conference focusing on security issues facing credit unions. Security continues to be a top of mind issue for credit unions of all sizes. With over a dozen security expert speakers, a security tour of a Las Vegas credit union for pre-conference attendees, vendor exhibits and two nights free lodging, this makes for an outstanding program. It’s the best value in the credit union movement.”
The conference agenda, registration and more information is available at: https://www.cunews.com/infosec.htm.
February News & Views Shown Below
CU SECURITY & TECHNOLOGY News - Providing a brief summary of news and information related to security and technology issues for credit unions - Plus some interesting and fun web sites.(Click on all photos to enlarge)
Tuesday, February 24, 2009
ATM thieves drain $60,000 from machine, camera helps catch them
Arlington police are investigating a string of thefts in which a group of people apparently tricked a cash machine out of $60,000 over
several months.
The thefts occurred at one Boeing Employees Credit Union machine in the Smokey Point area of Snohomish County, said BECU spokesman Todd Pietzsch.
Pietzsch said the thieves were able to trick the machine's software program in a way that caused it not to recognize that it had dispensed money, and it would then dispense money again, "so they were actually getting twice as much as they should have."
The thefts occurred at one Boeing Employees Credit Union machine in the Smokey Point area of Snohomish County, said BECU spokesman Todd Pietzsch.
Pietzsch said the thieves were able to trick the machine's software program in a way that caused it not to recognize that it had dispensed money, and it would then dispense money again, "so they were actually getting twice as much as they should have."
Banks, Credit Card Firms Wait For The Other Shoe To Drop Amid Reports Of Another Payment Processor Breach
Hack of a second U.S.-based payment processing firm exposes accounts used in Internet, phone transactions, according to credit union alerts
Brace yourself for another payment-processor breach: A second U.S.-based payment acquirer/processor has been hit with a network hack that exposed consumers' credit card accounts.
As of this posting, the victim firm's identity had not been revealed. According to several credit unions, Visa recently alerted them that another payment processor had discovered a data breach. Among the credit unions issuing alerts about the breach on their Websites are The Tuscaloosa VA Federal Credit Union and the Pennsylvania Credit Union Association. The Open Security Foundation has a notice posted on its DataLossDB site.
The latest breach follows that of Heartland Payment Systems, which went public on Jan. 20 about discovering malware on its processing system; some security experts have called it the largest security breach ever. Heartland processes 100 million payment card transactions per month for 175,000 merchants.
While details on the latest hack are still emerging, there is one known difference between it and Heartland's: This latest breach exposed so-called card-not-present transactions -- online and call-based transactions -- and not magnetic-stripe track data. Primary account numbers and expiration dates were stolen from the firm's settlement system, according to the Tuscaloosa VA Federal Credit Union.
Brace yourself for another payment-processor breach: A second U.S.-based payment acquirer/processor has been hit with a network hack that exposed consumers' credit card accounts.

As of this posting, the victim firm's identity had not been revealed. According to several credit unions, Visa recently alerted them that another payment processor had discovered a data breach. Among the credit unions issuing alerts about the breach on their Websites are The Tuscaloosa VA Federal Credit Union and the Pennsylvania Credit Union Association. The Open Security Foundation has a notice posted on its DataLossDB site.
The latest breach follows that of Heartland Payment Systems, which went public on Jan. 20 about discovering malware on its processing system; some security experts have called it the largest security breach ever. Heartland processes 100 million payment card transactions per month for 175,000 merchants.
While details on the latest hack are still emerging, there is one known difference between it and Heartland's: This latest breach exposed so-called card-not-present transactions -- online and call-based transactions -- and not magnetic-stripe track data. Primary account numbers and expiration dates were stolen from the firm's settlement system, according to the Tuscaloosa VA Federal Credit Union.
Tuesday, February 17, 2009
Give Every Member a Branch of Your Credit Union
Branchless banking’ allows an individual to have a remote bank account
that is accessed and managed through their mobile phone or other technologies. This could mean those with no chance of using traditional banks – because they are either too poor or the nearest bank is miles away - will be given the opportunity to save money, gain access to credit and receive money sent from family members in other countries.
The potential market for technology and mobile phone companies is huge, and by piggy-backing on existing technologies and infrastructures, the transaction cost can be much cheaper than traditional banks. For example a study in India showed it costs $1 per transaction in a bank, 40-50 cents per transaction from a cash machine and only 10 cents when a smart card is used.
(For the rest of the story, visit: http://www.dfid.gov.uk/news/files/SoS-FAST.asp
The potential market for technology and mobile phone companies is huge, and by piggy-backing on existing technologies and infrastructures, the transaction cost can be much cheaper than traditional banks. For example a study in India showed it costs $1 per transaction in a bank, 40-50 cents per transaction from a cash machine and only 10 cents when a smart card is used.
(For the rest of the story, visit: http://www.dfid.gov.uk/news/files/SoS-FAST.asp
Tuesday, February 10, 2009
Cherry Valley woman sentenced for taking $1 million from credit union
A 40-year-old woman was sentenced to nearly four years in prison for embezzling more than $1 million from the Rock Valley Federal Credit Union.
Lisa Farel was given three years and seven months in prison, as well as five years of supervised release. In October of last year she pleaded guilty to taking more than $1 million from the credit union over a 15-year period starting in 1993. Farel was manager of the credit and debit card portfolio department during that time.
After being charged, she admitted to manipulating 73 credit card accounts after pretending to close them.
Lisa Farel was given three years and seven months in prison, as well as five years of supervised release. In October of last year she pleaded guilty to taking more than $1 million from the credit union over a 15-year period starting in 1993. Farel was manager of the credit and debit card portfolio department during that time.
After being charged, she admitted to manipulating 73 credit card accounts after pretending to close them.
Number of ID fraud victims up 22%
The number of identity fraud victims in 2008 increased 22% to 9.9 million adults in the U.S., according to the 2009 Identity Fraud Survey Report, issued Monday by Javelin Strategy & Research.
However, the total annual fraud amount rose only slightly--7%--to $8 billion during the past year, the survey said (Business Wire Feb. 9).
Javelin, based in Pleasanton, Calif., is an independent provider of quantitative and qualitative research focused on financial services topics.
Other key survey findings:
>> Overall identity fraud incidents increased in the U.S. The number of identity fraud incidents in 2008 rose by 22% over 2007, which brings the number back up to levels not seen since 2004. Javelin said the rise was due to economic misfortune. Historically, higher rates of fraud occur when the economy worsens. Identity fraud remains substantially lower overall when compared to the 2004 level of $60 billion.
>> Cost to consumers is down. The mean consumer cost of identity fraud decreased 31% to $496-- its lowest level since 2005--from $718 per incident. The lower cost per incident is attributable to faster detection of fraud, lower fraud amounts, and quicker resolution times thanks to industry efforts and consumer education, Javelin said.
>> Fraudsters are moving much more quickly. In cases where identity fraud was reported, 71% of the fraud incidents began occurring less than one week from when the data was stolen, up from 33% in 2005. The dramatic increase points to more sophisticated attacks by fraudsters and an increasing number of "attacks of opportunity" in which people or businesses leave data exposed.
>> Gender disparity. Women were 26% more likely to be victims of identity fraud than men in 2008. Women are making more purchases in stores, and more women than men experienced breaches last year.
>> Low-tech methods still most popular. Lost or stolen wallets, checkbooks and credit and debit cards were still the most likely avenues of fraudsters' attacks. These avenues totaled 43% of all incidents in which the method of access was known. By protecting their information, consumers can significantly lower their risks, Javelin said.
However, the total annual fraud amount rose only slightly--7%--to $8 billion during the past year, the survey said (Business Wire Feb. 9).Javelin, based in Pleasanton, Calif., is an independent provider of quantitative and qualitative research focused on financial services topics.
Other key survey findings:
>> Overall identity fraud incidents increased in the U.S. The number of identity fraud incidents in 2008 rose by 22% over 2007, which brings the number back up to levels not seen since 2004. Javelin said the rise was due to economic misfortune. Historically, higher rates of fraud occur when the economy worsens. Identity fraud remains substantially lower overall when compared to the 2004 level of $60 billion.
>> Cost to consumers is down. The mean consumer cost of identity fraud decreased 31% to $496-- its lowest level since 2005--from $718 per incident. The lower cost per incident is attributable to faster detection of fraud, lower fraud amounts, and quicker resolution times thanks to industry efforts and consumer education, Javelin said.
>> Fraudsters are moving much more quickly. In cases where identity fraud was reported, 71% of the fraud incidents began occurring less than one week from when the data was stolen, up from 33% in 2005. The dramatic increase points to more sophisticated attacks by fraudsters and an increasing number of "attacks of opportunity" in which people or businesses leave data exposed.
>> Gender disparity. Women were 26% more likely to be victims of identity fraud than men in 2008. Women are making more purchases in stores, and more women than men experienced breaches last year.
>> Low-tech methods still most popular. Lost or stolen wallets, checkbooks and credit and debit cards were still the most likely avenues of fraudsters' attacks. These avenues totaled 43% of all incidents in which the method of access was known. By protecting their information, consumers can significantly lower their risks, Javelin said.
Friday, February 6, 2009
CU Stages Robbery Drill
LOMPOC, Calif. — Credit unions staging mock robberies have fallen out of favor with some authorities in recent years, but the $660 million CoastHills Federal Credit Union still uses the practice and credits it with preventing a recent potential robbery.
In the mock “take over” style robberies, real time drills in two CoastHills branches, run by local police authorities, mimicked the circumstance where a robber brandishes a weapon and otherwise takes control of the branch for the duration of the robbery. In the case of the drills, the mock robberies were limited to 30 minutes.
Video tapes are made of the mock robberies and then examined later for use as teaching tools as credit union staff are trained in their responses to a robbery, the credit union said.
Even though the majority of robberies are not the “take over” type, the credit union pointed out the numbers of robberies in its immediate area has been rising, along with robbery numbers across the country.
Video tapes are made of the mock robberies and then examined later for use as teaching tools as credit union staff are trained in their responses to a robbery, the credit union said.
Even though the majority of robberies are not the “take over” type, the credit union pointed out the numbers of robberies in its immediate area has been rising, along with robbery numbers across the country.
Wednesday, February 4, 2009
Credit Union Says They Identified Passwords for 80% of Staff
People and passwords—in the long run, they just don't work very effectively together. At least that's what Phil Fowler, vice president of IT at Telesis Community Credit Union, a Chatsworth, Calif.-based financial services provider that manages $1.2 billion in assets, found out. His team ran a network password cracker as part of an enterprise security audit last year to see if employees were adhering to Telesis' password policies. They weren't.
"Within 30 seconds, we had identified probably 80% of people's passwords," says Fowler, whose group immediately asked employees to create strong passwords that adhered to the security requirements. A few days later, the team ran the password cracker again: This time, they cracked 70%. (Click on photos to enlarge)
"We couldn't get [employees] to maintain strong passwords, and those that did forgot them, so the help desk would have to reset them," says Fowler. Telesis decided to secure network and application access with a biometric system that eliminated the need for user IDs and passwords, opting for the DigitalPersona fingerprint system from DigitalPersona Inc. in Redwood City , Calif.
"We couldn't get [employees] to maintain strong passwords, and those that did forgot them, so the help desk would have to reset them," says Fowler. Telesis decided to secure network and application access with a biometric system that eliminated the need for user IDs and passwords, opting for the DigitalPersona fingerprint system from DigitalPersona Inc. in Redwood City , Calif.
Telesis rolled out fingerprint-based network and systems access technology in its headquarters and credit-union branches. Once Telesis has thoroughly tested the system, the company will deploy it in the offices of Business Partners LLC, its business loan services partner. Users no longer need to remember IDs and passwords because DigitalPersona authenticates enrolled personnel via fingerprint scanners, tying the fingerprints to 256-character passwords that it randomly generates every 45 days.
Labels:
biometrics,
DigitalPersona,
fingerprint,
passwords
Subscribe to:
Posts (Atom)
