Tuesday, February 24, 2009

ATM thieves drain $60,000 from machine, camera helps catch them

Arlington police are investigating a string of thefts in which a group of people apparently tricked a cash machine out of $60,000 over several months.

The thefts occurred at one Boeing Employees Credit Union machine in the Smokey Point area of Snohomish County, said BECU spokesman Todd Pietzsch.

Pietzsch said the thieves were able to trick the machine's software program in a way that caused it not to recognize that it had dispensed money, and it would then dispense money again, "so they were actually getting twice as much as they should have."

Banks, Credit Card Firms Wait For The Other Shoe To Drop Amid Reports Of Another Payment Processor Breach

Hack of a second U.S.-based payment processing firm exposes accounts used in Internet, phone transactions, according to credit union alerts

Brace yourself for another payment-processor breach: A second U.S.-based payment acquirer/processor has been hit with a network hack that exposed consumers' credit card accounts.
As of this posting, the victim firm's identity had not been revealed. According to several credit unions, Visa recently alerted them that another payment processor had discovered a data breach. Among the credit unions issuing alerts about the breach on their Websites are The Tuscaloosa VA Federal Credit Union and the Pennsylvania Credit Union Association. The Open Security Foundation has a notice posted on its DataLossDB site.

The latest breach follows that of Heartland Payment Systems, which went public on Jan. 20 about discovering malware on its processing system; some security experts have called it the largest security breach ever. Heartland processes 100 million payment card transactions per month for 175,000 merchants.

While details on the latest hack are still emerging, there is one known difference between it and Heartland's: This latest breach exposed so-called card-not-present transactions -- online and call-based transactions -- and not magnetic-stripe track data. Primary account numbers and expiration dates were stolen from the firm's settlement system, according to the Tuscaloosa VA Federal Credit Union.

Tuesday, February 17, 2009

Give Every Member a Branch of Your Credit Union

Branchless banking’ allows an individual to have a remote bank account that is accessed and managed through their mobile phone or other technologies. This could mean those with no chance of using traditional banks – because they are either too poor or the nearest bank is miles away - will be given the opportunity to save money, gain access to credit and receive money sent from family members in other countries.

The potential market for technology and mobile phone companies is huge, and by piggy-backing on existing technologies and infrastructures, the transaction cost can be much cheaper than traditional banks. For example a study in India showed it costs $1 per transaction in a bank, 40-50 cents per transaction from a cash machine and only 10 cents when a smart card is used.

(For the rest of the story, visit: http://www.dfid.gov.uk/news/files/SoS-FAST.asp

Tuesday, February 10, 2009

Cherry Valley woman sentenced for taking $1 million from credit union

A 40-year-old woman was sentenced to nearly four years in prison for embezzling more than $1 million from the Rock Valley Federal Credit Union.

Lisa Farel was given three years and seven months in prison, as well as five years of supervised release. In October of last year she pleaded guilty to taking more than $1 million from the credit union over a 15-year period starting in 1993. Farel was manager of the credit and debit card portfolio department during that time.

After being charged, she admitted to manipulating 73 credit card accounts after pretending to close them.

Number of ID fraud victims up 22%

The number of identity fraud victims in 2008 increased 22% to 9.9 million adults in the U.S., according to the 2009 Identity Fraud Survey Report, issued Monday by Javelin Strategy & Research.

However, the total annual fraud amount rose only slightly--7%--to $8 billion during the past year, the survey said (Business Wire Feb. 9).

Javelin, based in Pleasanton, Calif., is an independent provider of quantitative and qualitative research focused on financial services topics.

Other key survey findings:

>> Overall identity fraud incidents increased in the U.S. The number of identity fraud incidents in 2008 rose by 22% over 2007, which brings the number back up to levels not seen since 2004. Javelin said the rise was due to economic misfortune. Historically, higher rates of fraud occur when the economy worsens. Identity fraud remains substantially lower overall when compared to the 2004 level of $60 billion.

>> Cost to consumers is down. The mean consumer cost of identity fraud decreased 31% to $496-- its lowest level since 2005--from $718 per incident. The lower cost per incident is attributable to faster detection of fraud, lower fraud amounts, and quicker resolution times thanks to industry efforts and consumer education, Javelin said.

>> Fraudsters are moving much more quickly. In cases where identity fraud was reported, 71% of the fraud incidents began occurring less than one week from when the data was stolen, up from 33% in 2005. The dramatic increase points to more sophisticated attacks by fraudsters and an increasing number of "attacks of opportunity" in which people or businesses leave data exposed.

>> Gender disparity. Women were 26% more likely to be victims of identity fraud than men in 2008. Women are making more purchases in stores, and more women than men experienced breaches last year.

>> Low-tech methods still most popular. Lost or stolen wallets, checkbooks and credit and debit cards were still the most likely avenues of fraudsters' attacks. These avenues totaled 43% of all incidents in which the method of access was known. By protecting their information, consumers can significantly lower their risks, Javelin said.

Friday, February 6, 2009

CU Stages Robbery Drill

LOMPOC, Calif. — Credit unions staging mock robberies have fallen out of favor with some authorities in recent years, but the $660 million CoastHills Federal Credit Union still uses the practice and credits it with preventing a recent potential robbery.

In the mock “take over” style robberies, real time drills in two CoastHills branches, run by local police authorities, mimicked the circumstance where a robber brandishes a weapon and otherwise takes control of the branch for the duration of the robbery. In the case of the drills, the mock robberies were limited to 30 minutes.

Video tapes are made of the mock robberies and then examined later for use as teaching tools as credit union staff are trained in their responses to a robbery, the credit union said.

Even though the majority of robberies are not the “take over” type, the credit union pointed out the numbers of robberies in its immediate area has been rising, along with robbery numbers across the country.

Wednesday, February 4, 2009

Credit Union Says They Identified Passwords for 80% of Staff

People and passwords—in the long run, they just don't work very effectively together. At least that's what Phil Fowler, vice president of IT at Telesis Community Credit Union, a Chatsworth, Calif.-based financial services provider that manages $1.2 billion in assets, found out. His team ran a network password cracker as part of an enterprise security audit last year to see if employees were adhering to Telesis' password policies. They weren't.

"Within 30 seconds, we had identified probably 80% of people's passwords," says Fowler, whose group immediately asked employees to create strong passwords that adhered to the security requirements. A few days later, the team ran the password cracker again: This time, they cracked 70%. (Click on photos to enlarge)

"We couldn't get [employees] to maintain strong passwords, and those that did forgot them, so the help desk would have to reset them," says Fowler. Telesis decided to secure network and application access with a biometric system that eliminated the need for user IDs and passwords, opting for the DigitalPersona fingerprint system from DigitalPersona Inc. in Redwood City , Calif.

Telesis rolled out fingerprint-based network and systems access technology in its headquarters and credit-union branches. Once Telesis has thoroughly tested the system, the company will deploy it in the offices of Business Partners LLC, its business loan services partner. Users no longer need to remember IDs and passwords because DigitalPersona authenticates enrolled personnel via fingerprint scanners, tying the fingerprints to 256-character passwords that it randomly generates every 45 days.

Friday, January 30, 2009

January News & Views Below


CU SECURITY & TECHNOLOGY News - Providing a brief summary of news and information related to security and technology issues for credit unions - Plus some interesting and fun web sites.

(Click on photos to enlarge)

Women Are Better at Financial Planning Than Men


Dan was a single guy living at home with his father and working in the Family business.

When he found out he was going to inherit a fortune when his sickly Father died, he decided he needed a wife with which to share his Fortune.
One evening at an investment meeting he spotted the most beautiful woman he had ever seen. Her natural beauty took his breath away.

"I may look like just an ordinary man," he said to her, "but in just a few years, my father will pass, and I'll inherit $20 million." Impressed, the woman obtained his business card and three days later, she became his stepmother.

Women are so much better at financial planning
than men.

Monday, January 26, 2009

Beware the debit card swindlers

Five seconds.

"We've looked at the videotape, that's how long it took," said Detective Steve Cook of Hamilton Police Services major fraud unit.

Five seconds was all the fraudsters needed to install the equipment that would rig an automatic banking machine to capture the debit card information from unsuspecting users.

"One guy standing behind to block the view, the other guy takes the pieces out of a gym bag," said Cook. "Five seconds, he walks away, and it's ready to go."

But this is no amateurish duct-tape-and-chewing-gum job being pulled off.

To an untrained eye, it would be difficult to detect that the machine had been compromised.
The level of sophistication involved in today's typical debit card fraud is staggering -- tiny computer processors attached to bank machines, miniature cameras, Bluetooth wireless technology, magnetic stripe encoders, portable safes.

As technology evolves, there's a corresponding evolution in criminal techniques.

Read the rest of this interesting story at:

http://www.thespec.com/News/Discover/article/501278

Scam alerts flooding several states

MADISON, Wis. (1/26/09)--

Credit unions nationwide are reporting that their members have been targeted by scams--including scams that have origins overseas.

Achieve FCU, Berlin, Conn. said that two dozen of its members lost money after sending debit card passwords to scammers that requested personal financial information (The Hartford Courant Jan. 23). The scammers had contacted members saying their accounts had been frozen.
One member lost $2.76--all she had in her account--while others lost $400, which is the maximum amount a member can withdraw in one day, Mary Budnick, Achieve vice president of operations, told the newspaper.

The scammers that targeted Achieve members were located in Romania and in Spain (Journal Register News Service Jan. 22).

The Federal Deposit Insurance Corp. (FDIC) warned its consumers, businesses and financial institutions Jan. 15 about fraudulent e-mails purporting to be from the Federal Reserve Bank. The e-mails state that a phishing attack has hit the Fedwire system and recipients are asked to click on links for more information.

More info at: http://www.cuna.org/newsnow/09/system012309-7.html?ref=hed

Saturday, January 24, 2009

Get Your Credit Union to Stand Out in a Crowd

If you really want to be noticed, get yourself a mascot. He’ll stand out in a crowd anywhere. We guarantee it. More credit unions today are using mascots to represent their credit union in a variety of different ways. Here are just a couple.




For more, visit Kincaid Karacter Mascots at http://www.kincaidkaracter.com/karacters/index.html
http://www.kincaidkaracter.com/

First Capitol Business Centre
2277 First Capitol Drive
Saint Louis, Mo. 63301
Phone 636-947-8822
karacter@kincaidkaracter.com

Friday, January 23, 2009

Locating a Private Individual

The following was posted on US.Gov on December 5, 2008.

Question

Locating a Private Individual

Answer

There are several organizations that might be able to assist you in locating a private individual. Please review the policies and guidelines for each agency/organization below.

Internal Revenue Service (IRS)
The IRS may forward a letter to someone when humane reasons are involved. For example:

* To notify someone of a serious illness, imminent death, or death of a close relative
* To seek an individual for a medical study to detect and treat medical defects
* To notify an individual, who cannot otherwise be located, that he or she is entitled to certain assets
* The IRS will forward a letter from an attorney, estate administrator, or other person who directly controls the assets

If you would like the IRS to help you locate an individual, place a personal letter addressed to the individual in a blank envelope. Include first class U.S. postage, and do not seal the letter. Place the unsealed letter in another envelope and address it as follows:

Internal Revenue Service
Office of Disclosure Operations
1111 Constitution Avenue NW
Washington, D.C. 20224

Social Security Administration (SSA)
The SSA will attempt to forward a letter to a missing person for reasons similar to those mentioned in the IRS section above. There is a $25.00 charge for forwarding letters to inform people about money or property they may be owed. Humanitarian letters are forwarded free of charge.

Follow the same guidelines above for sending a letter, and address it as follows:

Social Security Administration
Letter Forwarding
PO Box 33022
Baltimore, MD 21290-3022

The Salvation Army
The Salvation Army has operated a Family Tracing Service since 1885. The service is designed to help people establish contact with close relatives they may have lost touch with a few years ago or many years ago. The service is available in many of the 100 countries where the Salvation Army is located.

The Salvation Army will not help to locate someone in the following instances:

*
Friends
*
Situations where adoptions have taken place
*
Alleged fathers of non-marital children
*
Young people under 17 years of age
*
Former husbands or wives
*
Spouses for divorce purposes
*
Estate or similar business matters
*
Genealogies

In the United States, you may contact a Salvation Army territory office for your state. Local Salvation Army office numbers are listed in your local telephone directory.

Department of State (DOS)
The Overseas Citizens Services section of DOS will help locate relatives or friends who are overseas when there is concern about their welfare or a need to notify them of emergencies at home.

The Privacy Act requires that U.S. citizens over the age of 18 provide a Privacy Act waiver before information about them is released to a third party.

People in the United States may inquire about the welfare or whereabouts of U.S. citizens abroad by calling Overseas Citizens Services at 1-888-407-4747 or 1-202-501-4444. You may also contact the American Citizens Service Section of the nearest U.S. embassy or consulate directly.

You will need to include the following information before you call or contact the DOS:

* Your full name, address, telephone number and relationship
* The name of the person abroad
* Their date and place of birth
* Their passport number (if known)
* Their last known address and phone number
* Their itinerary
* Reason for their travel/residence abroad (business, tourism, etc.)
* Date of last contact
* Other points of contact abroad (friends, relatives, business associates, etc.)

For emergency messages, also include:

* Nature of the emergency
* What message should be provided to the person
* Name, address, telephone number and relationship of person you wish to be contacted after the emergency family message is delivered by the U.S. embassy or consulate

The United States Military
The military may also be able to help you locate the address of a servicemember. For immediate family members and government officials, the search is free. Other family members, civilian friends, businesses and others must pay $3.50. The check or money order must be made out to the U.S. Treasury and is non refundable.

You will need to provide as much identifying information on the military member as possible, such as:

*
Name
*
Rank
*
Last duty assignment
*
Last known military address
*
Service number
*
Social Security number

Please note: Because privacy regulations may limit the government's ability to provide you specific contact information for the person you are trying to locate, many people find that private sector resources can be quite helpful. While there are a number of free or fee-based services available through commercial sites on the Internet that you may opt to use in your search, the government cannot recommend or endorse any such service.
..

How To Stop Receiving Spam from Your Friends & Family

The following is an e-mail which you can send to friends and family asking that they stop sending spam type e-mail . . . all done anonymously.

Hi,

One of your friends has sent you this message from StopForwarding.Us, the website that allows individuals to politely and anonymously email their friends and ask that they stop the habit of sending forwarded emails or FWDs.Please do not forward chain letters, urban legends, potentially offensive jokes, videos or photos without being asked or first receiving permission.

If you find something that you want to pass on and you genuinely think the recipient will enjoy it then forward it to that person only (not in an email blast to all your friends and family) and include a personal note about why you enjoyed it and why you think they will too. Avoid sending forwards to friends or relatives that you've grown distant with. It can be frustrating for the recipient when the only correspondence he or she has with someone is via impersonal, unwanted email.

For more tips on email etiquette, visit www.StopForwarding.Us

Thank you,

A Friend (via www.StopForwarding.Us )

Worm Infects Millions of Computers Worldwide

January 23, 2009

<http://www.nytimes.com/2009/01/23/technology/internet/23worm.html?ref=science>

A new digital plague has hit the Internet, infecting millions of personal and business computers in what seems to be the first step of a multistage attack. The world’s leading computer security experts do not yet know who programmed the infection, or what the next stage will be.

In recent weeks a worm, a malicious software program, has swept through corporate, educational and public computer networks around the world. Known as Conficker or Downadup, it is spread by a recently discovered Microsoft Windows vulnerability, by guessing network passwords and by hand-carried consumer gadgets like USB keys.

Experts say it is the worst infection since the Slammer worm exploded through the Internet in January 2003, and it may have infected as many as nine million personal computers around the world.

Worms like Conficker not only ricochet around the Internet at lightning speed, they harness infected computers into unified systems called botnets, which can then accept programming instructions from their clandestine masters. "If you’re looking for a digital Pearl Harbor, we now have the Japanese ships steaming toward us on the horizon," said Rick Wesson, chief executive of Support Intelligence, a computer security consulting firm based in San Francisco.

Many computer users may not notice that their machines have been infected, and computer security researchers said they were waiting for the instructions to materialize, to determine what impact the botnet will have on PC users. It might operate in the background, using the infected computer to send spam or infect other computers, or it might steal the PC user’s personal information.

More information at:

<http://www.nytimes.com/2009/01/23/technology/internet/23worm.html?ref=science>

Wednesday, January 21, 2009

Computer Worm Affected 10+ Million Computers

A complex computer worm has infected corporate networks and has affected more than 10 million computers this week, experts say. Infecting computers in the U.S., Europe and Asia, the Downadup worm - which focuses on Microsoft Windows - scans company networks trying to guess passwords in order to access corporate networks, experts found. If the password is guessed, the worm can then infect a computer and the entire network of servers it is connected to.

As a result, experts are calling for all computer users to install a patch from Microsoft and to use long, difficult passwords that cannot be deciphered.

Read the entire article at: http://blogs.techrepublic.com.com/security/?p=740&tag=nl.e550

Card Data Compromised in Breach, Insurer Says Millions of Card Numbers Might Be Compromised

Despite Heartland Payment Systems' attempt to play down the significance of a security breach in a recent announcement, it appears that hackers were able to compromise a significant number of card accounts, according to CUNA Mutual Group.

"Although the exact number of affected cards is not known, it is expected to be many millions. Card-issuing credit unions and their members will be impacted by this breach," said Chuck Cashman, an executive with CUNA Mutual's Plastic Card Insurance.

The insurer reported that Visa and MasterCard have confirmed a significant number of credit and debit card accounts were compromised in the 2008 breach, which the company announced on Jan. 20.

Cashman said the insurer had been looking into a spike in card fraud since October 2008.
"CUNA Mutual Risk Management detected that something big was happening," Cashman said. "We reported our findings to both card associations to help facilitate an investigation to determine if a breach had occurred and, if so, its origin. It seems our worst fears are coming true, but we are relieved that it's finally been solved."

Monday, January 19, 2009

Analyst: Obama may spend a billion on biometrics

The Obama administration is likely to spend $750 million to $1 billion on biometric applications this year, primarily in defense, intelligence and homeland security, according to a new report from Jeremy Grant, an analyst for the Stanford Group Co. research firm.

Key programs at the Defense Department could result in $500 million to $600 million in biometrics contracts, and intelligence programs could add another $250 million to $350 million, Grant said. Other major programs contributing to the growth include the Homeland Security Department’s U.S. Visitor and Immigrant Status Indicator Technology and Real ID Act of 2005, the FBI’s Next Generation Identification and Homeland Security Presidential Directive-12, he said.

“U.S. identity solutions projects should survive intact through the presidential transition and the industry should continue to do well in the Obama administration,” Grant wrote. “Still, the distractions of the transition -– magnified by the economic crisis -– will slow some projects and delay the creation of new ones.

We forecast flat government spending for 2009 outside of several key programs, as a new administration takes a year to review and reshape existing initiatives.”

Samsung camera recognizes faces, names, shoe sizes...

Facial recognition is fast becoming a standard feature on compact cameras. But Samsung’s latest camera purports to take the technology to new heights.

The nine-megapixel ST10 can recognize individual people by analyzing faces as the shutter button is pressed, Samsung says.

The feature requires a little setting up. For example, you may have to take several snaps of Adam from different angles before the ST10 can automatically recognize him in future shots.
The technology also prioritizes friends, family and the frequently photographed so that the camera's smile mode will only take photos of recognized faces when they’re grinning.

Radical new tire design by Michelin. The next generation of tires.

These tires are airless and are scheduled to be out on the market very soon. The bad news for law enforcement is that spike strips will not work on these tires.This is what great R&D will do, and just think of the impact on existing technology: a... no more air valvesa... no more air compressors at gas stations and no more repair kitsS

CLICK BELOW AND SEE.These are actual pictures taken in the South Carolina plant of Michelin. It will be awhile before they are available to the automotive industry.