Posts

 According to the Identity Theft Resource Center (ITRC) today, there has been 519 data breaches -- a record number -- reported thus far in 2015.  Businesses and the healthcare industry account for nearly 75% of the reported breaches, with banking accounting for another 9%, and education and government breaches accounting for the balance of 16%.    Of course, these are just the reported breaches.  Some entities choose not to report them, or they haven't been discovered yet.  Historically, many months go by before breaches are discovered.   Without trying to sound like a salesman, it is no longer a valid option to ignore identity theft, hoping it won't happen.  All of us have had our information compromised.  It is just a matter of whether our information will be used in a fraud.  If you do not have a strong identity theft protection service, get one. I recommend IDShield from LegalShield.  Take a look at it at my website http://IDSol...

American Airlines, United Airlines, and Sabre Reservations Hit by China-Tied Hackers

It was just announced that United Airlines, Sabre Corp, and likely American Airlines, may have been hacked some time ago, probably at or near the same time that Anthem HealthCare and the OPM were hacked, according to folks knowledgeable of the cybersecurity probes.  Quite possibly, the hackers moved through the Sabre system into the American Airlines system, since they share some infrastructure.  The digital "fingerprints" of the hackers, while not identical in each of the systems, are close enough to say they were from the same group.  For example, hacker IP addresses in the American Airlines breach were the same as those in the government's Office of Personnel Management (OPM) hack. Information stolen from Sabre included the reservation records on more than a billion travelers per year across the globe and may be combined with the United and American Airlines flight manifests and passenger info and the OPM breach data to blackmail executives and government officials o...

The OPM Breach Is A Major Security Exposure & Risk

In April, 2015, it was discovered -- almost by accident -- that 4.2 million current and former government employees had been stolen.  Bad as that was, in June, it was revealed that the real number was over 21 million, which included people who had applied for government jobs or had background checks and their families.  Stolen information included Social Security numbers, birthdays, home addresses, user names and passwords, background information, and even fingerprints. Although the original 4.2 million victims have been notified if they were affected, so far, no one has been notified from the larger group. The forensics suggest that the Chinese were behind the breach, but no one is officially pursuing the Chinese for this. Along with the risk of financial misuse, victims whose background information was stolen could potentially be blackmailed, since looking for compromising situations were why they were having the background checks in the first place. So if you wer...

The Current State Of Things

Well, I haven't died.  Just lost track of time, I suppose.  Got focused on other outlets for my thoughts. But now I need to dust off the blog and start communicating again on this topic. Identity theft is much worse than when I last took keyboard in hand and made a posting here in 2012. Much worse. Just in 2014, one of the largest breaches in history occurred when Anthem Blue Cross was hacked.  Over 80 million records were stolen -- that is 1 in every 4 Americans -- with critical pieces of personal information compromised, such as Social Security Number, birthday, and medical card, to mention a few. Late last year also was the announcement that the IRS was compromised, with  tax information stolen from over 200,000 individuals. Most recently, the government's Office of Personnel Management was hacked, exposing the personal information of over 14 million people. (I'll say more about this breach an another blog post.) The severity of the breaches is staggering. ...

One Million Social Security Numbers Stolen in Utah

   Utah -- and therefore all of us -- has a problem.  In early April, it was announced that the Health Services department had been hacked, probably by someone in Eastern Europe, and nearly one million Social Security numbers and corresponding data were stolen -- that's one in six Utah residents. An article: http://tinyurl.com/7k7v8wh    As bad as that sounds, the worse thing (to me) is that many of these are children -- Children's Health Insurance Plan (CHIP) recipients .  A child's Social Security number can be used for many years before it is discovered.    Why might this be bad for the rest of us?  The weakness in security that led to Utah's hack may be in other states' systems.  Certainly, the ease with which the thieves broke into Utah's computers will encourage them or other thieves to try to break into other systems.    I'm just glad I've got LegalShield's Identity Theft Shield.  No plan protects 100%, but wit...

Do you have a good password?

Password maintenance is a pain.  Anyone active on the network knows how difficult it is to keep track of passwords.  The temptation is to keep the same password for everything and keep it simple.  I've found that a service called Lastpass.com is a way to manage passwords with one login.  It helps, but isn't perfect. Did you know that the most common password is "Password1"?  (Oops -- did I just guess your password?)  Read this very interesting article on the topic of password complexity. The Lastpass.com site I mentioned above allows you to generate very complex passwords for your various sites, then it keeps track of those complex passwords for you.  Pretty handy, really, unless you need to manually enter those passwords.  An alternative I've used is to create a password that has something static and something that varies, but both are easy to remember yet hard to guess.  Let me explain. Take a phrase that describes something about yo...

Identity theft sweep brings attention to tax season security concerns

Image
JSOnline, a Wisconsin "paper" included this article March 5, 2012.  I'm including the full article. =============== Tax time has a reputation for being almost universally stressful. As the looming April deadline closes in, Americans are concerned with getting their taxes done correctly and on time. As financial information starts to fly between individuals, tax preparers and the IRS, concerns about personal security are rising. In late January, the federal government conducted a nationwide sweep to crack down on identity theft and tax fraud before the 2012 tax season. The timing of the effort was meant to stem the rising tide of fraudulent tax activity, which involves using stolen identities to file for tax refunds. In 2011, the IRS found as many as 260,000 identity theft fraud attempts, up from 49,000 in 2010. While the IRS is taking action to help taxpa...

Lexington Police Arrest Man for ID Theft

Police arrested a man at a Lexington motel and charged him with 19 counts of identity theft Monday night. According to a police report, detectives located Jabari N. Cowart, 22, at the La Quinta Inn on Stanton Way during an identity theft investigation. Police say Cowart had 19 separate names, Social Security numbers and dates of birth in his possession. The police report also indicates detectives located a second person on his way to meet Cowart who was in possession of 40 more names. Investigators say Cowart planned to use the information to file fraudulent tax returns. Police charged Cowart with identity theft, trafficking stolen identities and possession of marijuana. Link to article

Watching Your Credit

Image
Did you know that you can get a free credit report every 12 months from each of the credit bureaus? (Equifax, Experian, and Trans Union.)  You can request the report by going to annualcreditreport.com.  Just be careful, because the bureaus will try to steer you into monthly monitoring or other costly services you may or may not want to have. I'd recommend that you stagger these reports every four months so that in a year you have one from every bureau (ex: get Equifax in Jan, Experian in April or May, Trans Union in Aug or Sept). Why is this important, you might ask?  Things happen to our credit in the course of a year that might not be accurate, or may indicated a potential identity theft in progress.  Even if you have monitoring enabled, a monitor may not be able to pick out what is legitimate and what is bogus.  And it is possible, even likely, that things reported to Experian may not show up on Trans Union's report, depending upon the reporting agency...

Teenager Sentenced for Card Skimming

Image
Tracy Kitten of www.bankinfosecurity.com writes 1/11/12 about a teenager working at McDonald's used a card skimmer to commit identity theft.  Link to article HERE . ========================== A 17-year-old was slapped with a 60-day jail sentence after he was busted for skimming credit and debit details while working the drive-thru window at a McDonald's restaurant in Olympia, Wash. This insider scam highlights a card fraud trend the industry needs to watch, experts say Card-skimming expert and fraud consultant Jerry Silva says the case highlights just how easy it is for insiders to perpetrate card fraud, especially in a retail environment. "It truly is remarkable," Silva says. "Even if we protect the ATMs and POS devices, insider fraud like this will take place due to the ease with which criminals can get their hands on the appropriate devices. This is an industry that clearly needs an elegant and innovative solution (not EMV) that can at least make it a...