Showing posts with label Identity theft. Show all posts
Showing posts with label Identity theft. Show all posts

Monday, November 13, 2017

The Crimes Americans Worry About Most

Even though 2017 is already the worst year for mass shootings in modern U.S. history, Americans are more worried about cybercrime than violent crime.


That"s according to a new Gallup poll which found that 67 percent of U.S. adults frequently or occasionally fret about having personal, credit card or financial information stolen by hackers. 66 percent also worry about the threat presented by identity theft.


In comparison with cybercrime, Statista"s Niall McCarthy notes that anxiety about conventional crime forms is less prevalent with a large gap to the third-biggest worry - having a car stolen or broken into. That"s a frequent concern for 38 percent of people while 36 percent tend to worry about burglary when they are away from home.


Infographic: The Crimes Americans Worry About Most | Statista


You will find more statistics at Statista


More serious crimes such as muggings, murders and sexual assault are much further down the list, but why?


The reason cybercrime comes first is more than likely due to far higher levels of victimization, along with substantial coverage in the media. Gallup also found that a quarter of households have experienced hackers stealing their personal information while a mere three percent have experienced a burglary.









Thursday, October 5, 2017

This Isn't A Joke: The IRS Just Hired Equifax To Safeguard Taxpayer Data

Just hours after Equifax CEO Rick Smith wrapped up his testimony before the House Energy and Commerce committee – the first in a series of Congressional “fact-finding missions” about the hack - Politico reported that the IRS last week awarded the disgraced credit monitoring bureau with a $7.25 no-bid contract even as the company struggled to address suspicions that it mislead investors and customers by withholding information about one of the most damaging data breaches in US history.


Equifax famously waited more than a month to disclose that hackers had infiltrated its servers and absconded with the sensitive financial information of more than 140 million customers, sparking widespread outrage that only intensified after reporters discovered that several of the company’s senior executives – including its CFO – cashed out of shares and options in the weeks before the company came clean about the hack.



According to the terms of the IRS contract, Equifax would be responsible for verifying taxpayer identities and help prevent fraud under a no-bid contract issued last week.


As if the IRS"s decision to entrust the disgraced credit bureau with sensitive taxpayer data wasn"t galling enough, the agency seemingly fast-tracked the contract by classifying it as a “sole source order” – a designation that allows the agency to circumvent the bidding process by claiming a given vendor is the only one capable of executing the contract. However, the agency"s justification for this designation is baffling, considering that there are two other credit bureaus in the US that offer a nearly identical suite of services.





The notice describes the contract as a "sole source order," meaning Equifax is the only company deemed capable of providing the service. It says the order was issued to prevent a lapse in identity checks while officials resolve a dispute over a separate contract.



Lawmakers from both parties demanded an explanation from the agency, which has endured several memorable data-security lapses – including a 2015 breach that exposed the sensitive financial information of more than 100,000 taxpayers.





Reps. Suzan DelBene (D-Wash.) and Earl Blumenauer (D-Ore.) separately penned letters to IRS Commissioner John Koskinen demanding he explain the agency"s rationale for awarding the contract to Equifax and provide information on any alternatives the agency considered. "I was initially under the impression that my staff was sharing a copy of the Onion, until I realized this story was, in fact, true," Blumenauer wrote.



Senate Finance Committee Chairman Orrin Hatch criticized the agency’s decision as “irresponsible.”





"In the wake of one of the most massive data breaches in a decade, it’s irresponsible for the IRS to turn over millions in taxpayer dollars to a company that has yet to offer a succinct answer on how at least 145 million Americans had personally identifiable information exposed," Senate Finance Chairman Orrin Hatch (R-Utah) told POLITICO in a statement.



Hatch raised concerns about the IRS’s cybersecurity practices in a letter sent to the agency’s head last month. To help the agency improve its data-security safeguards, Congress recently allocated $106.4 million to bolster the agency’s identity theft protections.





Hatch questioned the agency"s security systems in a letter to Koskinen last month. Hatch said he was concerned that the IRS lacked the technology necessary "to safeguard the integrity of our tax administration system."



Ron Wyden said the Finance Committee would seek to verify whether Equifax was really the only company capable of executing the contract, as the agency insisted.





The committee"s ranking member, Sen. Ron Wyden (D-Ore.), piled on: "The Finance Committee will be looking into why Equifax was the only company to apply for and be rewarded with this. I will continue to take every measure possible to prevent taxpayer data from being compromised as this arrangement moves forward.”



In defending its decision, the IRS claimed that Equifax said that none of its data was involved in the data breach.





The IRS defended its decision, saying Equifax has told the agency that none of its data was affected by the breach. The agency also noted that Equifax already provides “similar services” to the agency under a different contract.



"Following an internal review and an on-site visit with Equifax, the IRS believes the service Equifax provided does not pose a risk to IRS data or systems," the statement reads. "At this time, we have seen no indications of tax fraud related to the Equifax breach, but we will continue to closely monitor the situation."



Given that Equifax waited more than a month to disclose the hack to the public – and has bungled seemingly every step in its response to the hack - the fact that the IRS justified its decision by, in effect, saying "they told me everything is fine" is hardly reassuring. As Yahoo demonstrated just last night, the true scope of cyber-security intrusions sometimes takes years to uncover, which is precisely why sticking with Equifax is a risky. Yahoo, of course, revealed yesterday that a 2013 data breach impact all 3 billion of the company’s user accounts – three times the one billion accounts previously reported by the company.


As lawmakers have suggested, when determining which companies should be trusted to safeguard tax payers" most sensitive financial data, the agency should"ve erred on the side of caution.

Thursday, September 21, 2017

Equifax Accidentally Directs 200,000 Customers To Fake Phishing Website

And the hits just keep coming for Equifax, the once-trusted credit-monitoring firm that has been embroiled in one of the biggest corporate public-relations disasters in recent memory since disclosing that hackers had penetrated its cyber security defenses and absconded with sensitive personal and financial data belonging to 143 million Americans. Because of the types of data that were stolen, including drivers" license, social security and credit-card numbers, experts have described the hack as possibly the most damaging corporate hack yet.


As if this weren’t enough to permanently sully the firm’s reputation (amid cries of “you had one job!”) – the staggering irony of a credit monitoring firm inadvertently divulging the sensitive information that it was supposed to safeguard hasn’t been lost on consumers) a series of subsequent disclosures have portrayed the firm’s executives as bungling, at best, and nefarious, at worst.


In the nearly two weeks since the story broke…





  • It was revealed that three of the firm’s executives, including its CFO, cashed out of stocks and options worth some $2 million in the month between when the company first learned about the hack, and when it was disclosed to the public. A federal prosecutor in Atlanta has opened a criminal investigation into Equifax that will focus both on whether the firm was criminally negligent in failing to patch a hole in its cybersecurity systems, as well as whether the suspect stock sales constitute securities fraud.

  • The company’s head of cyber security was revealed to have no background in computer science or security – a fact the company tried to hastily cover up by scrubbing her social-media profiles. Susan Mauldin, Equifax’s chief information security officer, has a bachelor’s degree in music composition and a master’s in fine arts from the University of Georgia.

  • Several Congressional committees have asked the company to turn over information relating to the hack as multiple investigations appear to be getting under way. The attorneys general of a handful of states, including Massachusetts and Rhode Island, have joined a probe into the company’s handling of the breach.

  • The company has been hit with dozens of lawsuits from consumers alleging fraud, abuse and negligence.

  • Equifax CEO Rick Smith has been called to testify before a special House panel early next month.


When Equifax first set up a website to allow consumers to check whether their information was compromised, it carried a waiver stating that by using the service consumers would forfeit the right to sue Equifax. The internet quickly exploded in outrage, and the company quickly clarified that the waiver didn’t apply to this hacking incident, which…sure. Now, The Verge, The New York Times and a handful of other media outlets are reporting that Equifax accidentally tweeted the link to an imposter website set up by a white-hat hacker hoping to expose gllaring errors that the firm had made in setting up its verification website. This happened not once, but three times. And in at least one instance, the tweet with the phony link was left up for a whole day.



Here’s The Verge:





“Today, Equifax ended up creating that exact situation on Twitter. In a tweet to a potential victim, the credit bureau linked to securityequifax2017.com, instead of equifaxsecurity2017.com. It was an easy mistake to make, but the result sent the user to a site with no connection to Equifax itself. Equifax deleted the tweet shortly after this article was published, but it remained live for nearly 24 hours.”



Luckily for consumers, the fake site wasn’t malicious. Instead, it was set up by developer Nick Sweeting to try and expose the glaring security vulnerabilities that the company had embedded in its recovery website, which it set up as a separate domain, rather than making it a subdomain of Equifax’s main website.





“Luckily, the alternate URL Equifax sent the victim to isn’t malicious. Full-stack developer Nick Sweeting set up the misspelled phishing site in order to expose vulnerabilities that existed in Equifax"s response page. “I made the site because Equifax made a huge mistake by using a domain that doesn"t have any trust attached to it [as opposed to hosting it on equifax.com],” Sweeting tells The Verge. “It makes it ridiculously easy for scammers to come in and build clones — they can buy up dozens of domains, and typo-squat to get people to type in their info.”



Sweeting says no data will leave his page and that he "removed any risk of leaking data via network requests by redirecting them back to the user"s own computer," so hopefully data entered on his site is relatively safe. Still, Equifax"s team linked out to his page. That isn"t reassuring.”



Prior to Equifax customer service sharing the imposter site, Sweeting says he emailed the company’s support team and tweeted to Equifax that he spotted a potential vulnerability. By the time the site was taken down, Sweeting says it had received more than 200,000 hits. In the spirit of transparency, Sweeting included a disclaimer on his site warning consumers that it was a fake – and blasting Equifax for its sloppy security practices.


According to the NYT, phishers cannot create a page on the equifax.com domain, so if the website were hosted there instead, it would be easy for users to tell that the page was legitimate.





“Fortunately for the people who clicked, Mr. Sweeting’s website was upfront about what it was. The layout was the same as the real version, complete with an identical prompt at the top: “To enroll in complimentary identity theft protection and credit file monitoring, click here.” But a headline in large text differed: “Cybersecurity Incident & Important Consumer Information Which is Totally Fake, Why Did Equifax Use A Domain That’s So Easily Impersonated By Phishing Sites?”



The legitimate Equifax domain was securityequifax2017.com. Sweeting’s was equifaxsecurity2017.com. And as one cybersecurity expert told the NYT, even the legitimate website looks fake because it’s not a subdomain of the larger Equifax site.





“You would think that would be the obvious place to start,” said Rahul Telang, a professor of information systems at Carnegie Mellon University. “Create a subdomain so that if somebody tries to fake it, it becomes immediately obvious.”



The company’s actions, Telang told the NYT, suggest that it had never anticipated or planned for a breach.


This has become clear in the last few weeks. Now, the only thing left to be decided is whether the fact that the company was almost comically unprepared for a hack rises to the level of criminal negligence.

Sunday, September 17, 2017

Here's What Your Identity Sells For On The Dark Web

Millions of Americans who trusted Equifax with sensitive personal and financial data, including social security numbers and credit-card information, are now nervously wondering whether they will be among the unlucky minority of affected customers whose identities are successfully “repurposed” by online criminal groups.


One researcher from security firm SecureWorks shared some details about today’s burgeoning marketplace for stolen data with Bloomberg, and the conclusion is clear: It is now easier – and cheaper – for criminals to access and abuse illicit data than ever before. In fact, a high-limit American express card with a high chance of working can be purchased online for less than $20. Criminals can buy files with thousands of low-limit card numbers for pennies on the dollar.


According to Bloomberg, “verified” high-limit credit cards from developed countries like the US, Japan, and South Korea are selling on the dark web for the bitcoin equivalent of about $10 to $20.



“Verified” means the seller has tested out transactions on the card and found it hasn’t been canceled yet. For scammers on a budget, there’s unverified stolen credit card data, which comes out to pennies a card when bought in bulk.


Here’s a screengrab from one dark-web marketplace.



Luckily for criminals, cards generally aren’t selling any cheaper on the dark web these days, said Alex Tilley, a researcher at Secureworks. Today’s buyers are more likely to get higher-quality cards, ones with sizable limits that can be used fraudulently with ease. It isn’t as hit-or-miss as it used to be, a welcome change for criminals, chilling news for most of us.


Criminals have even set up sophisticated “rating systems” to help value the data. Business cards are preferred, Tilley said, because they don’t have a limit. Those and high-end personal cards—say, a Platinum American Express that has been verified and has an 85 percent rating (judged by the seller to have an 85 percent chance of being successfully used in a fraud)—will go for $15 to $20. A regular Mastercard that doesn’t have a high limit might go for $9.



One underground hacker market inexplicably called Trump’s Dumps is selling full identities of individuals just like you for as little as $10 apiece. They’re called fullz, “dossiers that provide enough financial, geographic and biographical information on a victim to facilitate identity theft or other impersonation-based fraud.” Fullz can help a criminal get past those irritating “secret questions” that sites ask to verify your identity.


Recently, Secureworks’ researchers have seen more offers of bulk pre-verified card details, along with more identifying information about the owners. In some cases, offers even include the cardholder’s mother’s maiden name. Still, they cost just $10 to $12. Below is a fullz offer with a lot of personal identification on a Korean consumer.


In a massive breach like Equifax, hackers can easily walk away with hundreds of millions of dollars in profits from selling the data. Meanwhile, the identity thieves who purchased it can reap their own fortune running their scams.


Congress, the FTC and Equifax customers – enraged by both the company’s reluctance to initially disclose the breach and its carelessness (some would say tight-fistedness) concerning its cybersecurity defenses – have buried the company in lawsuits and official inquiries.


As USA Today revealed yesterday, hackers took advantage of an Equifax security vulnerability two months after an industry group discovered the coding flaw and shared a fix for it, raising questions about why Equifax didn"t update its software successfully when the danger became known.


We’re looking forward to hearing the whole story from CEO Rick Smith when he testifies before Congress early next month. Whether Smith manages to hang on to his job remains to be seen - calls for his resignation after a 12-year-long scandal-free tenure are mounting. CNBC"s Jim Cramer said last night that Smith "should be fired today."


But perhaps more worrying for Smith and his C-Suite companions are calls from North Dakota Sen. Heidi Heitkamp, who has demanded a criminal investigation into whether the company"s executives - several of whom sold stock during the period between when the company first learned about the hack and when it disclosed it to the public - commited securities fraud.


"If that happened, then somebody needs to go to jail," she said.

Saturday, April 8, 2017

For Sale On The Dark Web: Your Tax Refund And Social Security Number

After death, and taxes, we can now add a third "certainty" to life - identity theft.


Amid the business of tax season, it"s not just accountants that are toiling hard to collect their fees. As Bloomberg reports, tax season is hog heaven for cybercriminals. The thought of all that personal data just sitting around, unmolested in tax documents, inspires a torrent of creepy scammer creativity.


The Krebs on Security blog provided a glimpse earlier this year of how our tax data is bought and sold, and what scammers charge other scammers for our data.


Founder Brian Krebs came across something he hadn’t seen before on the Dark Web: Bulk sales of W-2 forms.



A scammer had phished a tax preparation firm, Krebs discovered, and was offering for sale 3,600 Florida W-2s in this cyber netherworld which, while connected to the everyday web, requires special software or authorization to access.


Bloomberg notes that the fruits of all the successful phishing attempts wind up on the Dark Web.


These offers can look run of the mill, complete with star ratings for sellers. Here is a screenshot showing sellers and their illegal wares, such as W-2s, taken from IBM’s report:



The Dark Web has its own selling language. “Fullz” means complete information on an individual, including, according to the IBM report, “payment card information, address and contact details, and other additional pieces of personally identifiable information, such as Social Security number, a driver’s license number, and any other information sold along with the set.”




An individual’s tax data is far more valuable than their credit card data. Stolen credit card data might sell for $1 or be given away to establish credibility on the Dark Web, said Limor Kessem, executive security adviser of IBM Security. Credit card accounts can be closed or frozen, and thus have a short criminal-shelf life.





“Tax filing information is probably the most premium type of record criminals can buy on the underground,” said Kessem, who has been tracking this world for eight years.



“It goes for $40 or $50, and unlike credit cards, never expires. People can try and get loans in someone’s name, make fake IDs in people’s names, get credit.” And of course, the top target is filing a tax return in someone"s name and getting the refund.



With phishing attacks on the rise, Bloomberg suggests a consumer’s best defense is a good offense. One of the simplest, when it comes to tax refund fraud: File your taxes early to beat would-be scammers to the punch.

Friday, March 3, 2017

Is The Tyranny Of A Cashless Society Coming?

Via Capt. William E Simpson of WesternJournalism.com,


Like many people, I am a careful person when it comes to digital commerce, yet nonetheless I had two of my credit cards hacked (twice in the last four years) — one time by a supposedly reliable online retail company, another time when I rented a trailer. And both times, it required an incredible amount of time, police reports, phone calls, etc., just to get back to square one and get my money back.


But my experience was not unusual. Nearly 18 million Americans suffered from some form of identity theft in 2014 alone.


Digital commerce and credit cards are very problematic and are not the panacea that companies and the government want the public to believe.


Looking to a future in which governments abolish cash in useful denominations, it follows that they will then focus on eliminating personal and commercial commerce through the use of compact high-value commodities such as gold and silver, a natural progression if $100 bills are taken out of circulation in the United States.


People today who are living in the legacy of the Barack Obama economy already need a fistful of $20 bills just to buy a week’s supply of groceries. And it’s easy to spend $400 a week on fresh groceries for two people, especially if you buy premium products and organic.


If we consider the increasing trend where banks, institutions and big retailers are regularly hacked, combined with identity theft, digital commerce and credit cards aren’t all they’re cracked up to be, and in reality are posing an ever-increasing level of liability on all levels through their use.


The relatively few people who may ultimately control all of the digital wealth of Americans will virtually have control of all the people in a cashless society. This results in a definite loss of freedom and liberty.


There are many, many other ways for law enforcement to hammer criminals and curtail their enterprises, if that is truly the goal. But any method that inhibits or erodes the freedoms of Americans in any way, including limiting or infringing upon person-to-person commerce and personal privacy in any manner, is to be shunned and runs counter to the intents and spirit of our beloved U.S. Constitution.


Digital currency transactions in lieu of cash would allow virtually 100 percent tracking of all Americans, including law-abiding citizens and all that we do.


We have already learned over the past eight years of the Obama-led government that governments don’t necessarily work for or even represent the will of the people. So how can anyone justify giving the government this much power over Americans? There is no such justification.


The vast majority of Americans are not criminals, and therefore any action by government that affects or targets the vast majority of people in order to deal with a small factional percentage of criminals in the population is manifestly unfair. Politicians simply need to do the jobs they are being paid to do, and come up with anti-criminal tactics that strictly focus upon the bad actors, not the majority of law-abiding Americans.


If the minds behind a cashless society are allowed to have their way, America would become little more a monumental ant farm, where the elitist class studies Americans to a much greater extent than ever before — how we move around and what we do, use, eat, watch and listen to — and then uses this deeply insightful personal information, potentially to plot how to control everyone. Things like if we’re allowed to be born (abortions already control this to some extent), how long we get to live, and what we are allowed to do in between. Orwellian, yes, but possible nonetheless.


Brazil played around in past decades on many occasions with reissuing, devaluing and recalling currency to limit amounts in circulation. And the Marxists paid close attention to that exercise.


However, India’s currency games are more immediate and could have a sinister effect, since it is already a socialist state and we know how fond socialists and communists are of controlling all aspects of their populations.


Here’s a video that should be alarming.


Is India executing a plan similar to what may soon be in the works for Americans?


I have to say, it’s looking like living in the countryside on a piece of land that provides sustainable sustenance and a firewall from a population that may recoil and strike out in anger sometime soon is the only viable path to surviving past what may be an ugly and austere future. Anyone who cares to look at the news these days will see riots, murders and unrest all around inside the United States, a result of numerous factors.


Even as much as many Americans admire and respect President Donald Trump, the Marxist-socialist momentum that has already metastasized in America might be too much for him and his team to overcome. Our new president definitely needs our continued strong support more than ever.


Smile and pray for the best, but adequately prepare for the worst.