Showing posts with label credit card. Show all posts
Showing posts with label credit card. Show all posts

Tuesday, February 20, 2018

ID Fraud and Your Taxes - Take Action!

   It's that time of year again.  Brian Krebs just put out two articles on the ongoing issue of tax fraud.  As is so often the case, the advice to protect yourself hasn't changed - and be assured, you must protect yourself because no one else will, certainly not the IRS!

   As noted below and in the Krebs' article, what you need to do now and always is:
  1. file your taxes early
  2. monitor your credit (I covered that topic here... in 2013!)
  3. freeze your credit (two articles from Krebs, also from 2015)
  4. become you before someone else becomes you (I wrote about that subject here and here)
   Here's a re-run of my article on this subject from three years ago.  It's all still true!  As I wrote nearly 5 years ago, the more things change the more they stay the same.

   I did a series of posts last year (2014) on the problem of ID Fraud.  This is an ongoing issue, certainly because organizations struggle to protect information, there are cyber attackers out there, and also individuals don't often take steps to protect their own information.

   The bottom line is that your personal information, primarily your financial information, has tangible dollar value to a cyber attacker.

   We usually think about credit card fraud or maybe bank account fraud as the results of these kinds of data breaches.  But in this post and the next I'd like to talk about two other scenarios that have happened, are happening... and you need to be aware.

   It's that wonderful time of year again in the US.  Crisp weather, snow (most places), the days are starting to get a bit longer... and it's the beginning of tax filing season.

   Imagine you are doing your civic duty, filling out and filing your tax return.  You send it in to the IRS, only to find out that "you" already filed your return and "you' have already received your rather sizable refund - surprise!

   Unfortunately, this has happened.  And, as we've discussed in the past, these attackers are smart.  This is a business.  They need to be able to maximize profits because there is a limited timeframe in which to commit the crime.  So they need to attack a sub-population who:
  1. makes good money;
  2. might have many deductions;
  3. might have complex returns, and;
  4. for whom a large refund might not raise red flags.
   How about... Doctors!

   And, just as I finishing writing this article, we have new news out about tax fraud this year!  Reports say this is connected with Turbo Tax software, but it is more likely that scammers got people's info through other means and filed the fraudulent returns.  Maybe Turbo Tax is just the scammers software of choice! :-)

   As always, we want to talk about what you can do.

   In addition to the steps outlined in these previous blog posts, here is the IRS Guide on Identity Theft.  The IRS guide and my previous tips talk about not only what you should do if you are a victim, but tips to avoid the problem in the first place including:
  • protecting your personal information, primarily your social security number
  • don't click on links sent to you via email or in social media - type the link in yourself or do a search
  • use link rating applications like Web Of Trust (WOT)
  • don't give our your personal information via web, email, phone unless you can positively identify the person on the other end
  • review your bills, credit record and other information that might provide early warning of a problem.
   Have you been the victim of tax-related ID Fraud?  Do you have any additional tips to share?

   Of course, this issue is not just about doctors!  Next time we'll talk about something perhaps even closer to your wallet... payroll fraud and misuse.

Tuesday, February 14, 2017

ID Fraud, Taxes and Doctors Again (Still?)

   It's that time of year again.  Brian Krebs just put out an article on "darkweb" sales of W-2 information.  You can read that article here.  As is so often the case, the advice to protect yourself hasn't changed - and be assured, you must protect yourself because no one else will, certainly not the IRS!

   As noted below and in the Krebs' article, what you need to do now and always is:

  1. file your taxes early
  2. monitor your credit (I covered that topic here... in 2013!)
  3. freeze your credit (two articles from Krebs, also from 2015)
  4. become you before someone else becomes you (I wrote about that subject here)

   Here's a re-run of my article on this subject from two years ago.  It's all still true...

   I did a series of posts last year (2014) on the problem of ID Fraud.  This is an ongoing issue, certainly because organizations struggle to protect information, there are cyber attackers out there, and also individuals don't often take steps to protect their own information.

   The bottom line is that your personal information, primarily your financial information, has tangible dollar value to a cyber attacker.

   We usually think about credit card fraud or maybe bank account fraud as the results of these kinds of data breaches.  But in this post and the next I'd like to talk about two other scenarios that have happened, are happening... and you need to be aware.

   It's that wonderful time of year again in the US.  Crisp weather, snow (most places), the days are starting to get a bit longer... and it's the beginning of tax filing season.

   Imagine you are doing your civic duty, filling out and filing your tax return.  You send it in to the IRS, only to find out that "you" already filed your return and "you' have already received your rather sizable refund - surprise!

   Unfortunately, this has happened.  And, as we've discussed in the past, these attackers are smart.  This is a business.  They need to be able to maximize profits because there is a limited timeframe in which to commit the crime.  So they need to attack a sub-population who:
  1. makes good money;
  2. might have many deductions;
  3. might have complex returns, and;
  4. for whom a large refund might not raise red flags.
   How about... Doctors!

   And, just as I finishing writing this article, we have new news out about tax fraud this year!  Reports say this is connected with Turbo Tax software, but it is more likely that scammers got people's info through other means and filed the fraudulent returns.  Maybe Turbo Tax is just the scammers software of choice! :-)

   As always, we want to talk about what you can do.

   In addition to the steps outlined in these previous blog posts, here is the IRS Guide on Identity Theft.  The IRS guide and my previous tips talk about not only what you should do if you are a victim, but tips to avoid the problem in the first place including:
  • protecting your personal information, primarily your social security number
  • don't click on links sent to you via email or in social media - type the link in yourself or do a search
  • use link rating applications like Web Of Trust (WOT)
  • don't give our your personal information via web, email, phone unless you can positively identify the person on the other end
  • review your bills, credit record and other information that might provide early warning of a problem.
   Have you been the victim of tax-related ID Fraud?  Do you have any additional tips to share?

   Of course, this issue is not just about doctors!  Next time we'll talk about something perhaps even closer to your wallet... payroll fraud and misuse.

Tuesday, March 22, 2016

Credit Cards Calling

   So I'm driving down the road, out of state but heading toward home, when I received a text message.  The message said it was from a credit card company asking me whether a charge was legit.  I did not recognize this charge!

   Receiving this kind of message may concern some of you, but for me this is awesome!  The credit card companies have, by necessity, become really good at detecting fraud.  That could be because of the huge amount of credit card fraud out there!  Fraud is big money and it's both in our, and the credit card companies', best interests to try to get a handle on it.

   Detecting this kind of fraud is basically about big data analytics and anomaly detection.  That's just a fancy way of saying it's kind of like finding a needle in a stack of needles!  It's complex and expensive.  Luckily(?) credit card companies have lots of money!  They have to figure out what might be fraud so they can appropriately allow or block transactions.  If they allow too much then there can be a lot of fraud.  If they block too much then there can be unhappy customers.

   Back to our story... the charge was not legit and I responded "2".  As you can see in the image, the credit card company said they would call me.  I did receive a call and was immediately put into a hold loop!  Wait...

   If I did speak to someone they would first have asked me to identify myself.  However, they called me.  I don't actually know who they are!  This whole event could have been a scam to collect personal information from me.  Had someone connected with me that way, I would not have given them any identifying information.  They called me... at my registered (with them) phone number.  They already know who I am.  They need to positively identify themselves to me!

Tuesday, July 7, 2015

ID Fraud... What to do Now

   I've written about Identity Fraud in the past.  Today I'd like to review what you need to do now if you are a victim.  I have written about this before, but a picture is worth a thousand words... and a video?...


Tuesday, March 10, 2015

Chip & Pin & a Tin Foil Wallet

   I've been talking a lot about ID Fraud lately and was recently asked this question:
"A question came up at home – and that is about use of credit card wallets that protect from rogue scanners. Are they necessary? Will they be more or less necessary when newer cards with embedded microchips are more prevalent?

I thought this might be an interesting topic for your blog."
   Thanks for the great question and idea to put this in a blog post!

   So, by credit card wallet I’m assuming that you mean some kind faraday cage or lead lined case that blocks electronic signals, as opposed to a credit card wallet like Google Wallet, Apple Pay or SoftCard.

   When it comes to old-school mag stripe cards… have you noticed how you sometimes have to reinsert or re-swipe the card in the reader, and even then it doesn’t always read?  Mag stripe is definitely a direct-physical-contact medium.  Other than vendor breaches or stolen (physical) wallets, the typical way someone can steal your mag-stripe card data is via some kind of skimmer.  There are very low profile skimmers that can be inserted into ATMs or gas pumps to grab your card data while you’re trying to do a legit transaction.  There are also hand-held or desktop units that an “evil waiter” can use to grab your card data when they take your card at a restaurant.  There are no reliable remote ways to read magnetic data off a card.  So, a lead wallet won’t help here at all.  It’s the same way you can’t read the contents of a hard drive just by being near it.

   Next is RFIDs.  That stands for Radio Frequency IDentification and, as the name implies, they do transmit data.  These are the chips in the tap & pay cards.  There are transmission-blocking wallets for RFID passports and things like that which transmit data.  So anything with RFID or a transmitter can be remotely read (at various distances).

   The new cards coming out will be chip & "something".  Currently in Europe they use chip & pin.  This is expensive to implement and requires replacing all the mag stripe readers with much costlier readers.  The chip is a microchip that computes a value and provides a 1-time-use code for a transaction.  Note that it does not use your credit card number.  In addition to that single use code, the person also needs to put in their numerical PIN.  So, even if the card was stolen, or the code could be remotely read, it couldn’t be used for a transaction without the PIN, and the code couldn't be reused.

   The US is actually considering chip & signature.  Among the reasons is that the cost will be lower even though the readers still need to be replaced.  (though, because of the marketing power of Apple and Apple Pay, many merchants have already upgraded readers).  The chip works the same way, but the 2nd part of the verification is the physical signature.  Not particularly strong but better than nothing.

   Now… neither of these new card types solves a particularly important case… Card Not Present.  This is when you buy something over the phone or internet.  So there’s no card reader nor person to look at your signature, and you don’t want to give some random merchant your PIN.

   There are a number of potential solutions in the works.  Verified-By-VISA or MasterCard SecureCode are examples of tools available now, even for mag stripe cards.  Basically, you choose one of these at online checkout; then you’re transferred to the VISA or MasterCard site; you authenticate there; the VISA or MasterCard site generates an acceptance code that get sent back to the merchant and you’re all set.

   So, chip & signature cards and readers will help deal with some of the credit card fraud we have, but we still need a standardized solution for Card Not Present (CNP).

   Now with that background, back to your initial question… remote reading of a magnetic stripe, chip & PIN or chip & signature card is not a major threat.  However, cards that use RFID, or any tap and pay technology, could be read remotely.

   You'd be far better off taking the precautions I listed in my previous ID Fraud articles including:

  • regularly viewing your credit report
  • watching your bills
  • shredding unneeded documents that have personal info
  • carrying only the minimum cards you need
  • using care online

   Thanks again for the great question!  If anyone has questions or ideas for things I should write about in the future, please let me know.

Tuesday, February 10, 2015

ID Fraud, Taxes and Doctors, Oh My!

   I did a series of posts last year on the problem of ID Fraud.  This is an ongoing issue, certainly because organizations struggle to protect information, there are cyber attackers out there, and also individuals don't often take steps to protect their own information.

   The bottom line is that your personal information, primarily your financial information, has tangible dollar value to a cyber attacker.

   We usually think about credit card fraud or maybe bank account fraud as the results of these kinds of data breaches.  But in this post and the next I'd like to talk about two other scenarios that have happened, are happening... and you need to be aware.

   It's that wonderful time of year again in the US.  Crisp weather, snow (most places), the days are starting to get a bit longer... and it's the beginning of tax filing season.

   Imagine you are doing your civic duty, filling out and filing your tax return.  You send it in to the IRS, only to find out that "you" already filed your return and "you' have already received your rather sizable refund - surprise!

   Unfortunately, this has happened.  And, as we've discussed in the past, these attackers are smart.  This is a business.  They need to be able to maximize profits because there is a limited timeframe in which to commit the crime.  So they need to attack a sub-population who:
  1. makes good money;
  2. might have many deductions;
  3. might have complex returns, and;
  4. for whom a large refund might not raise red flags.
   How about... Doctors!


   And, just as I finishing writing this article, we have new news out about tax fraud this year!  Reports say this is connected with Turbo Tax software, but it is more likely that scammers got people's info through other means and filed the fraudulent returns.  Maybe Turbo Tax is just the scammers software of choice! :-)

   As always, we want to talk about what you can do.

   In addition to the steps outlined in these previous blog posts, here is the IRS Guide on Identity Theft.  The IRS guide and my previous tips talk about not only what you should do if you are a victim, but tips to avoid the problem in the first place including:
  • protecting your personal information, primarily your social security number
  • don't click on links sent to you via email or in social media - type the link in yourself or do a search
  • use link rating applications like Web Of Trust (WOT)
  • don't give our your personal information via web, email, phone unless you can positively identify the person on the other end
  • review your bills, credit record and other information that might provide early warning of a problem.
   Have you been the victim of tax-related ID Fraud?  Do you have any additional tips to share?

   Of course, this issue is not just about doctors!  Next time we'll talk about something perhaps even closer to your wallet... payroll fraud and misuse.

Tuesday, December 2, 2014

The 4 R's of ID Fraud (part 2)

   As promised, in this post we'll wrap up the series about ID Fraud.  Check here if you'd like to see the first 3 parts of this series, and the first half of this post.

   So far we've focused on what ID Fraud is, and in the third installment, the steps you should take now if you are a victim.  As we've discussed, having the information for one of your credit cards grabbed in an attack such as we saw on Target or Home Depot doesn't automatically mean you will have other ID Fraud related problems.

   But we should all take steps to reduce our exposure and the odds that our ID and financial information will be fraudulently used... or at least increase the odds that we'll notice any problems quickly.

   We'll continue with the 4 R's: Review, Reduce, Record, Report. (unlike the 5 D's of dodge ball! :-)

Reduce - the amount of information you give out online.
  • Use care when emailing personal information.  Don't unless you need to.  Provide a minimum amount of information. Use encrypted email if it's available.
  • Choose passwords and hints that are not based on personal information.
  • Don't "click here to unsubscribe" from a spam or unwanted message - it just let's them know you exist.
  • Shop online with reputable or known vendors.
  • Delete doesn't really delete.
  • Use malware protection on your home computers and devices.
  • And a bonus tip for online - watch out for Phishing messages.  That's a big topic that I've covered in the past, and probably will revisit as scammer techniques evolve.

Tuesday, November 18, 2014

The 4 R's of ID Fraud (part 1)

   As part of our celebration of US Cyber Security Awareness Month, we've been talking about ID Fraud.  Check here if you'd like to see the first 3 parts of this series.

   So far we've focused on what ID Fraud is, and in the third installment, the steps you should take now if you are a victim.  As we've discussed, having the information for one of your credit cards grabbed in an attack such as we saw on Target or Home Depot doesn't automatically mean you will have other ID Fraud related problems.

   But we should all take steps to reduce our exposure and the odds that our ID and financial information will be fraudulently used... or at least increase the odds that we'll notice any problems quickly.

   Our theme for today is the 4 R's: Review, Reduce, Record, Report (just like you learned when you were a kid! :-)

[as I was writing this, the post became really long so I've broken it up into 2 parts]

Review - your credit report.  You are entitled to 1 free report from each of the big 3 credit reporting agencies each year.  So, spread it out and get 1 every 4 months.  The US FTC endorsed site to get these reports is www.annualcreditreport.com.  You can also put a fraud alert on your account as we discussed last time.
   You're also entitled to a free copy of your credit report if you:

Tuesday, November 4, 2014

Got ID Fraud? - Stop, Drop and Roll

   OK, maybe not stop, drop and roll (I'll always remember that fire safety phrase from my childhood), but take action!

   Cyber Security Awareness Month is now over, and I haven't finished covering the ID Fraud topic I started at the beginning of Oct.  I did get distracted on some other issues.  Besides, we can't confine our celebrating to only one month!

   I covered the basics of ID Fraud in these posts.  But if you have been a victim, and particularly if you recently discovered you are victim, you need to take action... and time matters.

   Here are the four key things you need to do, right now, if you have recently been the victim of ID Fraud in the US:
  1. Contact one of the three major Credit Bureaus (we'll leave a discussion of the "4th credit bureau" for another time).
  2. Close the suspect accounts.
  3. File a police report.
  4. File a report with the FTC by phone and in writing.
   I'll provide more detail and add a few more steps below.

   One additional thing you must do throughout this process is to keep a record of everything you do.  This includes: noting date/time of phone calls; copies of letters; printout any web forms, and; keep a chronological log of your overall progress.

   The FTC website has the specifics here.

Contact one of the Credit Bureaus and put a fraud alert on your account.
   This is the first thing to do.  You can put what is called an initial fraud alert on your credit record.  This initial alert will last 90 days.  It should not cost anything to place this alert.  The bureau you call should contact the other two credit bureaus, but it doesn't hurt to verify this with them.
   The fraud alert basically requires extra effort to authenticate any requests for new credit.  This typically means that the credit issuer needs to contact you before issuing credit.  This should make it tougher for a fraudster to open credit in your name.  That's good!  The downside is that it also might make it more difficult for you to open new credit.
   After the initial 90 day period, you can renew the alert each 90 days.  This may cost a nominal fee depending upon what state you live in (US).
   (we'll talk about other measures like credit monitoring services in a future post)

Close the affected accounts.
   Contact the credit issuer and close any accounts you know were affected.  If your purse or wallet was stolen, then close all the accounts for the cards you were carrying.
   If you're not sure if a particular account was affected, you're probably best off closing it as well.

File a police report.
   Contact your local police and file a report.  Except in rare cases where there was additional theft (for example, if your identifying documents and credit cards were stolen as part of a home break-in), the police will not actually take any action.  You're not contacting the police so they will investigate the problem.  You are establishing documentation and proof of the event.  In the future, you may need to prove that you took action and when you took action.  The police report accomplishes this.  Get a copy of that report.

File a complaint with the FTC (US Federal Trade Commission).
   Again, this is part of establishing your documentation trail.  The FTC has a great website for information that I'll link below.  The specific instructions for filing the FTC complaint is here.  Note that they suggest filing with the FTC before filing the police report.  That is not critical, and you need to do both.  You can complete the FTC form online so that might be easier and it's available 24x7.

   Those are the first steps to take.  But there are more.  Here are a few more steps to take:

Who else to notify?
   You may want to notify your other banks and creditors both to find out if there has been any unusual activity (banks and card issuers are usually pretty good at finding anomalous activity before you do) and so they can flag your accounts.  Consider notifying anyone who bills you monthly for services including utilities and insurance providers.

   If you think your US social security number has been compromised, you should contact the Social Security Administration.

   You can notify your state driver and vehicle services department in case someone tries to get a driver's license in your name.

Online defense.
   If this problem started online, perhaps through an information breach, you should change your passwords and consider using multi-factor authentication as I've covered in the past.

   There are more complete details on these steps on the FTC website here.

   Even under the best of circumstances, the process of reporting, documenting and repairing ID Fraud is a major pain.  In our next installment I'll talk about things you can do to help prevent you from becoming a victim, or in those circumstances where this is out of your control, how to increase the odds of early detection and minimize the impact.

   Have you had experience with any of the steps I list above?  Do you have any advice on additional steps to take?

Tuesday, September 23, 2014

"Who Am I?" (or, Who Was I?)

   I like the story of Les Mis.  I definitely like the musical.  I was not wild about the movies.  The book is definitely a good, and very long, read (or listen!).

   At it's core, Les Mis is a story about Identity Fraud!  It's the story of a man, seemingly wrongly convicted, who operates under a false identity in order to be able to live his life.  It's a common literary theme, used in stories like Martin Guirre, The Count of Monte Cristo and Matchstick Men.  In "olden times", Identity Fraud penalties were very serious. Today... not as much.  Last time we started a discussion of Identity Fraud - we'll continue our discussion of this topic.


   Breaches of online merchant websites and databases get a lot of media attention.  But there are many ways ID fraud is committed including:
  • Shoulder Surfing - this means someone looking over your shoulder, for example when you enter your PIN at an ATM
  • Dumpster Diving - it's amazing what people throw away
  • Mailbox theft - checks, financial statements and other sensitive documents get stolen from mailboxes
  • Stolen purse, wallet, laptop, tablet, phone - these all contain plenty of personal information
  • Social Engineering - be careful about what information you give out about yourself
  • Phishing - email or phone - con artists will call or email pretending to be your bank, law enforcement or other authority and ask you for information.
  • Social media - do you really know who your "friends" are?... there are all kinds of requests and information gathering schemes
  • Copy-cat websites - it's pretty easy for scam artists to create a fake site that looks just like your bank's website, perhaps with a misspelled URL like nationa1bank.com (that's a one instead of an L), and then collect the info you enter.
  • By known or unknown thieves! - some ID thieves know their victims.

   So many choices!