Wednesday, May 18, 2011

Here we go again! More Data Theft!

We have warned here that the personal information of Americans is no longer safe.

"The personal financial information of up to 210,000 unemployed Massachusetts residents may have been stolen in a data breach caused by a virus discovered in state labor department computers four weeks ago, officials said yesterday."

"Names, addresses, and Social Security numbers, among other data, may have been taken, said John Glennon, chief information officer for the Massachusetts Executive Office of Labor and Workforce Development. The number of affected recipients is probably a small fraction of the total number of potential victims, according to Glennon. The virus attempted to transmit confidential information to digital thieves, he added, but it was not clear how much, or even whether, any data was successfully stolen."

I will predict here that every American will have their confidential information stolen over the next two years. this will pose a huge threat to national security, economic stability, and individual tranquility. We will soon be a country of frightened, sleepless paranoids who spend all day and nights trying to recover their credit and personal information.

Labels: ,

Saturday, April 30, 2011

The Internet is our enemy




Today I was reading some news about flooding in Missouri.

Suddenly in Firefox a news browser window popped up that said - "You have Won and iPad 2"

I NEVER click on anything like this so I tried to close that pop up window.

It would not close. I tried quitting Firefox and it would not close. I tried rebooting and it would not let me because Firefox had an open pop up that took priority over my comment to close and restart.

I hard rebooted by pushing the power button. When my Mac rebooted the same pop up with the iPAd prize popped up again like some devilish spawn of Satan!

I waited and waited and would not click on the link but all of a sudden it opened up a browser page where I could enter some information to get my free iPad even though I repeatedly refused to click on the link.

I quickly quit Firefox and rebooted my computer.

I have no idea what price I will pay or what they did to my computer during that whole episode but I felt completely and utterly helpless. There was nothing I could do. The browser and the Internet had taken control of my computer!

I suddenly realized that with computers and the Internet you cannot call 911. You are on your own (unless you are at work and have some fantastic tech support)

You can't even be self sufficient and but a 357 Magnum so that you can defend yourself.

I believe that we are now right at the edge of some terrible, TERRIBLE things that will happen with the Internet. It has become a wild west and there is no sheriff in town.

If these gangsters program a pop up that cannot be closed and you are hostage to it I think most people will simply give up in desperation and click on the link button. I almost did. Then they will have violated the ONLY advice we have for people "don't click on links you don't know."

My question is "what is the industry doing to fight against the hordes of commercial and criminal gangsters (including Internet ad agencies and ad tools) that are rapidly seizing control of the Net?"

The answer is nothing. They don't care. Security is expensive. We have no way of tracing internet attacks to be able to retaliate because attacks and maleware is delivered by proxies.

We are truly now all alone as the Net aliens attack us, our financial and identity security.

.
.

Labels: , , ,

Tuesday, April 19, 2011

Your Kids Targets of Identity Theft?

We have been writing and teaching about the threats of identity theft in financial matters (credit card, checking accounts, your credit history), medical identity (your medical records are breached and people can get medication and medical services in your name), and true identity theft (your total "persona" is taken by someone who gets passports, drivers licenses and other identities with your name but their picture and biometrics).

Now we have more evidence of the risks to your kids. Read on.

A report by Carnegie Mellon's CyLab has found that identity theft is a growing concern for children. In a scan of 42,000 US child IDs, CyLab found that more than 10 per cent of kids had someone else using their Social Security number.

Why are kids such a good target? Parents aren't paying attention. However, parents should pay attention, since CyLab found that children had a 51 per cent higher attack rate than adults. The problem is likely to get worse as more kids go online at a younger age.

CyLab scanned more than 42,000 child IDs by identify protection company Debix and found that:

  • 4311, or 10 per cent of children, had someone else use their Social Security numbers;
  • these IDs were used to buy homes, cars and open credit lines;
  • the largest fraud was US$725,000 against a 16-year-old girl;
  • the youngest victim was five-months-old and 303 victims were under five; and
  • there were 1767 cases where a child's Social Security Numbers were found in utility records.
http://www.zdnet.com.au/identity-theft-s-next-frontier-your-kids-339313517.htm

Labels: , , ,

Wednesday, April 06, 2011

Biggest Crime in History – In terms of Potential Victims!

The world’s largest “permissions-based” e-mail marketing company, Epsilon, reported late last week that someone hacked into its computer system and stole an unknown number of e-mail addresses and names.

According to Professor Steffen Schmidt, Iowa State University, “This is probably the single largest criminal act in history since this company potentially has compromised the recipients on the 40 BILLION or so e-mails they send out each year.” Schmidt is professor of public policy and has co-written with Michael McCoy two books on identity theft. He is also co-founder of the blog http://stolendata.blogspot.com/ and a developer of the Engineering On Line certification workshop Information Security and Identity Theft Policy http://www.eol.iastate.edu/Professional-Development/Courses/idtheft.html

“This is a stunning example of the huge risk anyone using email now faces of being the victim of highly targeted “Spear Phishing” which is a sophisticated form of sending real-looking links to companies the recipient is familiar with (such as a bank or a retailer) and then soliciting “updates” or other information. The unsuspecting person clicks on the link and is routed to a criminal web site where their accounts and even potential their full identity will be stolen,” said Schmidt.

“It will be many, many years of painful and costly trouble for millions of people,” Schmidt said, adding, “someone needs to be sued, convicted, and do serious jail time for such negligence of a huge and sensitive data base.”

Steffen Schmidt, Professor
For our latest Course that ANYONE can take visit;
http://www.eol.iastate.edu/Professional-Development/Courses/idtheft.html

Labels: , , , , ,

Tuesday, February 15, 2011

Online Sites Offer Connections That May Not Be Sweetheart Deals

I wanted to share a great article with our readers. Stacy has written for our blog in the past and is writing this on behalf of www.pplmediaroom.com.

Thanks,

Michael MCCoy

By Stacy Whelchel

Online sites offer connections Happy Valentines Day! In recognition of this day celebrating sweethearts, we are subject to not only numerous ads promoting the “perfect” gift for loved ones, but also online websites which offer services designed to find that special someone. However, profiles posted on single or dating sites are not always who or what they claim to be, says the Better Business Bureau.

The Bureau reported that oversea scammers are preying on consumers who seek connections through online venues. Thousands of victims have been tricked each year at a cost of millions of dollars.

The con artists use websites where they create fake profiles and use kind words to gain victims’ trust. The targets might even receive flowers and gifts, most likely bought using stolen credit cards. Unfortunately, since these criminals are overseas, it is more difficult to investigate and prosecute, according to the BBB.

The BBB says to avoid online relationships with those who:

* Only communicate through email, instant message and cell phone
* Are charming, understanding, flattering, sensitive, have a caring personality
* Have a career or life circumstances that takes him or her overseas
* Is quick to develop a relationship and talk about love
* Have a young child, typically a boy or girl between the ages of 5 to 12
* Have a sudden emergency, often involving a child's health
* Have a reason he or she cannot get money and need your financial help
* If you help them, they ask for more money

Caution is always advised when sharing any type of confidential data, especially with those sight unseen. If identity theft is a threat because of breached information, Pre-Paid Legal’s Identity Theft ShieldSM and its team of restoration experts will be there for you.

Labels: , , ,

Saturday, January 29, 2011

Online Identity Theft Awareness course

I want to thank the hundreds of people that have signed up to be one of the few individuals to join our test group for the Iowa State University online Identity Theft Awareness Certificate Course managed by ISU Engineering Online Learning. There will be a second trial group after we have collected the feedback and make suggested changes.

If you are interested in taking this certificate course in the future add your name to our "subscriber" list found on the right hand column of this page. Find "Pleas Subscribe to Receive Updates" area and add your Name, email and State the press subscribe button. Or use link directly below.

Labels: , , ,

Thursday, August 26, 2010

Does ID Theft Weigh-In On Immigration Debate?

by Sue B. Martines J.D. and Michael McCoy M.Sc.

“It’s a black and white issue,” the gal next to me on the plane volunteers, as she peers over at the newspaper article I’m reading about Arizona’s latest immigration law battle. And then it taints my entire train of thought -- is it as simple as that? Is it as simple as saying someone is either lawfully in this country or they’re not? Is it that you either jumped through the justice hoops and got it done or you need to go back from whence you came?

Foregoing the more esoteric consideration, perhaps, about whether borders are indeed a necessity, when identity theft is factored into the immigration debate, how can it ever be black and white? The July 16, 2010 USA Today article discusses how immigration is re-entering the national debate and is back in the spotlight for November’s races. But nowhere is identity theft addressed in the article.

And yet, there are dozens of websites where anyone with $20 and a credit card can buy a fake ID. You gotta wonder upon what document is the “sending one back from whence they came” based?

If an illegal immigrant turns into an identity thief by buying a Social Security number in order to remain in the U.S., and it’s happening at an alarming rate, then is there an additional argument in favor of such laws being looked at in Arizona – where immigration is reviewed with nearly every bust?

A Center for Immigration Studies article cites that approximately 75 percent of working-age illegal aliens use fraudulent Social Security cards to obtain employment. (And that was in 2009.)

Understandably, regardless of which end of the potentially black and white immigration spectrum one stands, there cannot be a laundry list of potential crimes to be evaluated with every charge, but identity theft needs to be factored into the mix somehow. In fact, if identity theft doesn’t weigh-in now, the immigration issues we’re facing may never really get addressed.

Labels: , , , , , ,

Thursday, June 17, 2010

Red Flags Or No Red Flags, Businesses Need To Act


The FTC may imply that part of the latest Red Flags enforcement delay is to await clarification which pending legislation may bring, but the reality is that the legislation is purely an appropriation consideration not an appropriateness one! In other words – for the pending legislation to consider whether or not certain potential indicators of data fraud in the workplace ought to require attention or not begs the question. Of course they should! The real issue is whether the needed attention can be afforded.
According to the Privacy Rights Clearinghouse’s infamous “chronology of data breaches,” over 300 million data breaches have taken place between April 20, 2005 (the date it began tracking breaches) and the time of this writing. www.privacyrights.org Assuredly, if any of the victims of those millions of data breaches were asked if their data was less worthy of protecting than others the answer would be NO!
The Red Flags Rule, as it’s commonly known, is designed to ensure that entities that extend credit detect, prevent and reduce cases of identity theft under penalty of fines. http://www2.timesdispatch.com/rtd/business/local/article/B-FLAG29_20100528-221006/347604/
Originally passed in 2008, the FTC just announced that enforcement of its Red Flags Rule is yet again delayed – this time allowing compliance through December 31, 2010. http://tampabay.bizjournals.com/tampabay/stories/2010/06/07/story7.html
The pending legislation will determine if it ought to extend to workplaces with fewer than 20 employees, but common sense would tell us that protection from identity theft ought to be extended to all. If common sense dictates that, then, Red Flags or no Red Flags, all businesses ought to do everything they can to protect data on their own – for even if applicability is decided, monies to assist may or may not be attached. http://www.ftc.gov/bcp/edu/microsites/redflagsrule/RedFlags_forLowRiskBusinesses.pdf

By Sue B Martines, J.D.

Labels: , , , ,

Tuesday, June 08, 2010

Book Review Preview – “Cyber War,” by Richard A. Clarke and Robert K. Knape, 2010



Written by two gentlemen from intentionally disparate generations – a tricenarian (someone in their 30’s) and a sexagenarian (someone in their 60’s), as though modeling for us the evolution from a relatively theoretical threat to a very real one, unpeel not only the chronological journey but also the practical impact of a modern day cyber war. Imagine your city’s system of traffic signals being out of sync due to lengthy blackouts, or your financial records being rearranged or pipe system exploding??
Yes, indeed, this would be a different kind of war. Authors Clarke and Knape posit that US civilians have one of the greatest chances of high impact in such a cyber war, and in fact, that countries are already positioning themselves for battle. And these writers should know – Clarke served as a counterterrorism advisor to both Presidents Bill Clinton and George W. Bush, and Knape won a prestigious Fellowship at the Council on Foreign Relations to study cyber war.
Our own Pentagon, the authors recap, admit to thousands of “pings” a day upon their computer armor – probes from foreign computers seeking to penetrate where weaknesses may lie. And on occasion, they succeed – fighter planes not yet in the air have had their details hacked into. And our nation’s very own computer supply chain is global and not necessarily trustworthy they point out… (for example, even while you’re reading this article, your computer could be “drafted” into a cyber war against a foreign bank, without your even being aware).
Some solutions are presented that may benefit readers – for instance, if you’re going to make purchases online, use a card with a low limit used solely for that purpose, they suggest; use your work computer at work, and your home computer at home; and make sure your online bank uses more than just a password for its security protection. But how would one protect from the story outlined in Cyber War?
Their book describes a supposedly hypothetical scenario where hackers incapacitate the US from behind their computer screens. In an NPR “Fresh Air” interview, author Clarke admits he cannot explain why such a hypothetical situation hasn’t already come to pass . Couple that fact with the point that the government is predominantly focused on protecting our nation’s defense capabilities… This writer can’t help but reminisce upon the Y2K preparations and wonder about the value of their revival…
Reviewing, Cyber War: The Next Threat To National Security And What To Do About It, Copyright 2010, by Richard A. Clarke and Robert K. Knape, published by Harper Collins, and as reviewed on NPR.org.
Sue B Martines, J.D.

Labels: , , , , ,

Friday, May 14, 2010

Sleuthing Your Own Employees


Are you sure your very own employees are not divulging non-public information on social networking sites such as Facebook, Twitter, MySpace or LinkedIn? There are certainly potential issues relating to the appropriateness of social networking while on-the-job (addressed in an earlier article on this blog), but more and more employers have a presence on these trendy sites and in many instances, encourage it. However, there may need to be protections for your business from your very own employees according to a Blogger News Network, April 6, 2010 article on the topic. (http://www.bloggernews.net/124226)
Really -- who needs thieves, when our own employees can be duped by users of crafty social networking sites to share logins and passwords to our company network. The above-referenced article describes one test of such a fact pattern which found nearly half of all the employees tested fell for the demands of a well-crafted, illegitimate duplicate site of their employer’s.
It’s nevertheless hard to put too much blame on the vulnerable employees – the duplicate site looked like very credible outreach from their HR department. And a recent Time Magazine article reported 70% of US HR officers reported utilizing social networking sites to screen employees. (“Social Networking Sites Can Lead to Legal Pitfalls,” http://www.bizjournals.com/dayton/stories/2010/04/05/focus3.html?b=1270440000^3132331) This begs the point that internal policies for any workplace can only help give guidance in this situation.
Because we can’t expect the social networking sites to do our sleuthing for us! As the Blogger News Network story suggests, employers ought best appoint a site administrator to oversee work-related online employee interfacing for the time being. And the best legal defense remains the best offensive strategy and taking extra measures to protect access to company websites and having a corporate policy/training on the topic just makes sense.
Sue B Martines, J.D.

Labels: , , , , , , , , ,

Wednesday, May 05, 2010

Educate Girls and Reduce ID Theft Risk


Arguably , if you better educate anyone about risk, you reduce the potential harm. So why focus on girls? Pick the highest risk group, and generate exponentially greater potential payoff is why. One recent study found women to be 26 percent more likely to be victims of identity theft and fraud than men. (Javelin Strategy & Research’s, 2009 Identity Fraud Survey Report, http://www.mybackgroundcheck.com/blog/post/2009/02/Why-Women-Suffer-More-Identity-Theft-and-Fraud-than-Men.aspx.)
That same study attributes the results to women making purchases more frequently “in-person,” as opposed to online, than men, and to their being three times more likely to report being a victim than men!
In Greg Mortenson’s book Stones Into Schools (the sequel to #1 bestseller Three Cups of Tea), wherein it’s undertaken to build schools for girls in outlying parts of Afghanistan and Pakistan, it’s noted that the education of girls leads to increased income for not only the girls themselves but for their entire nation.
Knowing how identity theft can lead to losing the next most valuable asset after one’s health, it’s really not that far of a cry to see that focusing on girls’ education can not only improve basics like income level and health, but the ability to keep what is so hard gotten, like one’s identiy. Identity theft need not disproportionately impact women in any part of the globe when education can be a potential cure.
Sue B Martines, J.D.

Labels: , , , , , , , ,

Monday, April 12, 2010

Social Networking Deception Leads to ID Theft?

So, first of all, Classmates.com agrees to a proposed settlement of $9.5 million to users who complained about its false advertising – you know the email – “hey, someone’s been looking for you…and if you just upgrade from the free to the subscription membership, we’ll tell you who it is…”

And just about the time you realize you’ve been duped and no one’s looking for you, you’ve already enrolled with your credit card online…

But then you find your personal information on the site may have gone inappropriately public and there are unexplained charges on your credit cards?! Whoa.

It’s no wonder Classmates.com’s problems have now snowballed into a class action lawsuit for invasion of privacy, the above-referenced consumer settlement offer awaiting court approval, and congressional inquiries into the unexplained charges, according to a socialnetworkinglawblog.com article.

Juxtapose that with my nearly 12 year-old daughter asking today whether or not she ought to accept any of the Facebook and similar social networking type invitations to join which she receives on a daily basis. Hmmm. What so often begins as an innocent interest in connecting with friends, classmates, business colleagues, etc., can too often now digress to identity theft, fraud or criminal consequences.

Us social networkers need beware, but so do the site sponsors.

Sue B Martines, J.D.

Labels: , , , , , , ,

Monday, April 05, 2010

Top Things That Computer Users Should Fear in 2010

Can the Internet be a scary place? Yes, and it may be an even more dangerous place this year, according to this MSNBC story.
The daunting story makes predictions including:
  1. Anti-virus products will have more difficulty screening out viruses
  2. Increased buying of fake anti-virus software
  3. Social networking sites will continue to be platforms for impersonation/identity theft
  4. Spam numbers will keep climbing
Even though this may not be the most uplifting news, it’s important that the Internet always be treated as a powerful communication tool of seemingly endless possibilities - both positive and negative.

Caution is always the key to safe surfing. If something seems suspicious, avoid it and take precautions to safeguard all your confidential information, both online and during in person interactions.

It’s one thing to hope that these predictions don’t come true; it’s quite another to ignore the warnings and not take steps to protect your identity and leave the door wide open for cyber criminals.

- - - - - - - - - - - -

Written by Stacy Whelchel, a Corporate Writer at Pre-Paid Legal Services, Inc. Pre-Paid Legal's signature products, including the Life Events Legal Plan and Identity Theft Shield, serve more than 1.5 million families in North America.

Labels: , ,

Friday, January 08, 2010

Identity Theft Left Victim Unable to Marry


by Aleshia Altizer

Getting married should be an exciting and very special occassion. But for one identity theft victim, a trip to the courthouse to get a marriage certificate turned into a four year nightmare when court records showed she was already married to someone else.

According to a New York Post article detailing the incident, the victim’s identity was stolen over ten years ago, and the thief used it to marry and even file state and federal tax returns among other crimes. All this went unnoticed until the victim went to get a marriage license and was turned away from the registrars’ office because records showed she had married over ten years ago.

According to the article, it’s been four years since the identity theft discovery, and since then the victim has endured problems with the IRS and her personal life and is also waiting for the marriage to be expunged so she can finally get married and move on with her life.

- - - - - - - - - - - - - -

Aleshia Altizer is a Corporate Writer at Pre-Paid Legal Services, Inc. Pre-Paid Legal's signature products, including the Life Events Legal Plan and Identity Theft Shield, serve more than 1.5 million families in North America.

Labels: , , ,

Tuesday, December 29, 2009

Social Networking and Some Employment Law Snafus (Part 2)

     In this article, we try “round two” of stumping the HR person!  That is to say -- let’s take a look at a few additional employment-related social networking challenges, and how an HR person (or supervisor) might best respond.

1.     Management allows some online posting during work hours, but notice one employee who averages 100 Tweets per day on Twitter.
Does it matter if it is part of their job to post Tweet updates?  How many posts are too many, is the question!?

A reasonable course of action by any standard, would be to warn the employee of the excessive number of posts.  Thereafter, it needs to be determined whose function it is to monitor such media outreaches – HR? Corporate Communications? IT? – which may depend on resources.  Larger employers may consider having a media department that would oversee such outflow.  Tweets can positively impact business! 
One Wall St. Journal article noted that the number of Tweets regarding a movie release does affect the numbers at the box office!

2.      You receive a phone call saying one of your employees has been posting derogatory comments on her ex-husband’s blog.
Does it matter how high-profile the employee or ex-spouse are?  What about whether it was posted during work hours or whether it depicts a company uniform or logo?

Ask for evidence of the postings!  (Such as a print out of the posting.)  Certainly one would need to determine whether or to what extend the company was identified within the post, and whether it was posted during work hours, and warn accordingly.

3.      What if you WANT your employees to help grow your business through social networking??
Are you going to want to require that employees join a social networking site?

A good solution for this may be to identify which sites would be acceptable for business purposes, (some favor Linked-In, for example).  You will need to decide if such postings are mandatory (in which case, you need to be prepared to pay for this time), or optional (in which case, you need to decide if work time can be allotted for this).  In any event, some guidelines ought best be established regarding content, and all postings should be monitored. 
Some employers are finding ways to block social networking, although that can turn away employees as well!  Why not have a separate business page from personal, on those sites that allow it?!

Continue your feedback…we may have a social networking and employment law snafu, part 3 at some later time! 

Labels: , , , , ,

Monday, December 21, 2009

Social Networking and Some Employment Law Snafus (Part I)

Imagine yourself the Human Resource Specialist for a large employer – as the arena of social networking explodes, you are faced with a series of issues that were never even considered before the days of internet insanity. Let’s try out a handful of these situations, and see how you would fare –
1. One of your employees is found to have posted their photo, complete in company logo shirt, on Facebook.

Does it matter that it’s a personal site? How ‘bout that the logo is represented in the photo?

The outcome might be to consider prohibiting the display of a company logo, or product, etc., on even an employees’ personal site. (Keeping in mind that certain businesses may want to have their logos or products given higher exposure.)

2. What if the employee’s photo is of themselves at work in a skimpy bikini?

Certain websites have privacy abilities where such photos may not even be seen, however, coworkers often bring to your attention items that even the employee themselves may not realize is visible. Can someone’s behavior after work hours be monitored? How does such monitoring balance with freedom of speech protections?

In reality, a situation like this is probably best handled in consultation one-on-one with the involved employee. The best case scenario would be the employee didn’t realize the photo was publicly visible and agrees to remove it. However, another outcome might be to consider prohibiting the posting of photos of work area, or on-duty activities. (For certain companies there is a security justification for such posting prohibition.)

3. What if employees take a pay cut because business is down, and then photos are posted by the boss’ wife on Facebook?

And then the employees start circulating a union petition…and demand a raise?? Isn’t there some similarities to the boss driving up to work in a new car?

At its heart, this is all about perception. If workplace executives or managers are counseled on the business impact of personal posts, along with the encouragement of using privacy settings, it should help. Also, it can’t hurt to increase your transparency, so to speak, of business finances. (And possibly gear up for a union election campaign at the same time!)

We want to hear from you – send your social networking and employment law snafu situations to us this week at suebmartines@gmail.com, and stay-tuned for Part II!

Labels: , , , ,

Friday, December 18, 2009

Terrorists using Internet for Money Laundering, Fundraising…and Identity Theft

by Aleshia Altizer

How serious would you be about protecting your identity if you knew terrorists were on the prowl, seeking to use fraudulent funds to finance activities? Discovery.com has posted a Q&A with Tom Kellermann, a former member of the Treasury Security Team at the World Bank. Kellermann advised central banks on monitoring illicit online activity and had some startling things to say about how terrorists are funding their attacks.


In the article, Kellerman discusses how one terrorist funded an attack with more than $150,000 he hacked from American bank accounts and credit lines. On top of that, he wrote a book on hacking to educate his followers.


Terrorists don’t have to be hackers themselves to get their hands on stolen data either. They can hire assistance from underground chat rooms. “There is a complete community now where you essentially can hire mercenaries to build code to attack a targeted system and to data mine that system for your own use,” said Kellerman.


- - - - - - - - - - - - - - - -


Aleshia Altizer is a Corporate Writer at Pre-Paid Legal Services, Inc. Pre-Paid Legal's signature products, including the Life Events Legal Plan and Identity Theft Shield, serve more than 1.5 million families in North America.

Labels: , , ,

Monday, December 07, 2009

Medical Identity Theft on the Rise

By Aleshia Altizer

Imagine finding out that someone has used your identity to get more than $100,000 worth of medical treatment. Imagine finding out there’s incorrect information in your medical file like the wrong medical history, blood type and allergies. The Wall Street Journal recently posted an article on the increasing prevalence of medical identity theft and the impact it has on its victims.

As more and more medical records become electronic, the information becomes easier for thieves to steal. Unfortunately, many don’t realize an identity theft has occurred until their medical records have been distorted and medical bills ran up.
The impact can be very serious if personal medical records are altered with the wrong medical history, blood type and allergies. The article says that consumers could also exhaust their lifetime coverage or be considered uninsurable, if their insurance has been used by someone else.
- - - - - - - - - - - - - -
Aleshia Altizer is a Corporate Writer at Pre-Paid Legal Services, Inc. Pre-Paid Legal's signature products, including the Life Events Legal Plan and Identity Theft Shield, serve more than 1.5 million families in North America.

Labels: ,

Tuesday, December 01, 2009

CPA’s, Identity Theft, and the Law

By: Sue B Martines J.D.

The attorneys may have gotten off the hook for the Red Flags Rule requirements, but so far, not the CPA’s, among other “professionals” (such as physicians). Picture this – two so-called “professionals,” one an attorney and one a CPA, discuss identity theft and the Red Flags Rule implemented by the FTC to help businesses develop “Red Flag” indicators for fraud – the conversation might go something like this:

Attorney, “being a busy professional, I sure am grateful to not have another burdensome requirement made of me by the government!”

CPA, “being a busy professional, I sure am grateful for the opportunity to have guidance on how to better guard against the time-consuming, professionally-damaging and high client impact of an identity theft or data breach!”

Two different professionals, two different treatments so far, by the law!

In a previous posting, we discussed the recent court decision finding attorneys exempt from the “burdensome” requirements of the Red Flags Rule; here we make the somewhat absurd double-standard comparison, you might say, to one of their counterparts -- CPA’s.

We all know there’s no immunity from identity theft risk. The American Institute of CPA’s itself fell prey to the #1 risk factor – human error – when in 2006 a damaged hard drive containing personal information was sent out for repair and was lost in transport. (http://www.pro2net.com/x52999.xml)

However, in an IRS online publication regarding CPA’s and identity theft, you will find zero things unique to the CPA that wouldn’t equally apply to an attorney! (http://www.irs.gov/pub/irs-utl/identity_theft_what_cpas_need_to_know.pdf)

Certainly the fight may not be over for CPA’s, or other “busy professionals” whose attorneys will challenge the Red Flags Rule “requirements” to have an identity theft prevention and mitigation plan in place by June 1, 2010.

Yet, if only all CPA’s could look at identity theft and data protection measures like the one in the discussion above – it could mean less lawsuits for the “burdened” attorneys, and better protection of client data!

Maybe the requirements of the law aren’t that bad of an idea after all!

Sue B Martines is a recovering attorney of 12 years now living in Oregon. Sue can be reached at, suebmartines@gmail.com

Labels: , , , , , ,

Tuesday, November 24, 2009

Red Flags Extension, Trends in ID Theft and Attorneys as “above” the law?





By Sue B. Martines J.D.



Any time there is an “exception to the rule,” as the saying goes, it feels like someone is getting off the hook.  And truth be told, most would say attorneys get off the hook all too often.   So here it comes again, with the latest argued exception to the thrice-postponed Red Flags Rule – attorneys shouldn’t have to create written policies outlining how they will prevent, detect and respond to identity fraud.

My, what a burden that might be for them!

But most laws are somewhat burdensome – especially when they’re first mandated and folks are figuring out how to comply.  So it comes as no surprise that the same has been true with businesses scrambling to determine if they are a “creditor” and thus, subject to the identity verification requirements of the “Red Flags Rule.” * The Federal Trade Commission (FTC), tasked with imposing the Rule designed to slow identity theft, lost its most recent battle defending the applicability of the Red Flags to attorneys.

In a  The Daily Record online posting, the FTC argues that as attorneys accept payments from their clients so they ought  be subject to the “creditor” requirements of the Red Flags Rule.  But this U.S. District Court for the District of Columbia sided with the American Bar Association, saying…what was it?  Ah yes, that that would be too “burdensome” on those hard-working attorneys!

Stay-tuned as the courts test the burden-ability of various acclaimed creditors between now and June 1, 2010 (the new deadline)!  And as The Record notes, the FTC can appeal the ruling.

Sue B Martines is a recovering attorney of 12 years now living in Oregon.

Labels: , , ,

  • All Material is Copyright © 2009 Michael McCoy and SEAS, L.L.C
  • Deter. Detect. Defend. Avoid ID Theft - www.ftc.gov/idtheft