Monday, December 31, 2007

Seasons Greetings

At the start of the holiday season this year my friend Moses Whiffington of Boston, Mass went to fill his car with gas and his credit card was refused. His wife Wilhelmina was turned down at Walgreens Pharmacy an hour later and could not buy Robitussin for little Benjamin – “Sorry, mam, your credit card has been frozen”. The credit card company said they were over their limit in the last hour because of the $6 K charges they had made in Boston at Bonwitt Teller. Moses was at home filling his snowplow with gas when those charges were made. The Whiffingtons had not mail ordered six gold Christmas gift bracelets to be sent by currier to an address only 2 blocks from the store.

The next day they got the notification from the famous MM Kean Outdoor Wear Catalog Company in Pawamatuxet, Maine that, as per application, a business account had been activated and the first shipment of Wully Pully cashmere sweaters in the amount of $12,000 had been shipped, as per instructions, to Whiffington Outlet Bazaar in Amarillo, Texas. And, MM Kean proudly announced “We are pleased to tell you that you’ve been authorized for the Platinum Credit Line of up to $60k. Congratulations and Happy Holidays!”

Moses and Willy are typical of millions of Americans whose credit information is stolen by cyber crooks. Then the long, frustrating, and angry process of trying to recover credit ratings and their good name begins. What a way to spend Christmas!

Moses was innocent and had mostly ignored news stories and reports about ID Theft. His company, Vizagnez Pharmaceutical Packaging had never run an employee training program on Identity Security and Moses who is VP of Marketing had never had alarm bells go off when customers complained that after doing business with Viz (as the company is known) they suddenly had unauthorized charges in the tens of thousands on their company accounts. Little did Moses know that the marketing web site had been hacked, spyware installed, and vital, confidential information leaked out on customers accounts.

Moses called me on my cell and I authorized a download of our book on ID Theft as my Christmas present to him and his family. He followed the check-list of ten steps and is now spending New Years applying for new and more secure credit cards. He also has ordered a complete security review of all customer data. My associate and I are flying out to Boston to do a one-day training seminar for all employees at Viz Packaging. This seminar will be archived and available for all new Viz employees who are required to take it and pass the certification testing of our ID Secure CompanyÔ training program.

Meanwhile, preoccupied with cutting the size of the federal government and “getting government off your back”, the Congress and the Executive Branch have still not stepped up fully and robustly to enact much tougher and proactive identity theft legislation.

Last week Moses got a package from DHL Delivery Services that his corporate account for package delivery and small business credit had been approved. He expects to get approved for many more unsolicited business accounts and the charges that come with those as the thieves continue their spending spree.
Happy Holidays, Merry Christmas, and we hope that your New Year 2008 is free of these hassles.

Labels: , , , , , , , ,

Monday, November 19, 2007

Information Protection and Behavior Modification


In 2006-2007 the National Science Foundation (NSF) and the Iowa State University Center for Information protection (CIP) funded a study on information and identity theft protection of which I am the PI (Principal Investigator). The NSF-CIP project is directed at identifying factors that lead to data and critical information loss and then designing targeted and appropriate educational/training programs that change people’s behavior and lead to more “Security Consciousness” – (SEC-CON).

As a result of this research we are now developing best practices for information and ID protection. Our colleagues in computer science, computer engineering, mathematics, and management information systems (MIS) are working on parallel discoveries that will make information more secure and personal identities less vulnerable. Their work and ours will be incorporated into corporate, government, non-profit organizations and into individual practices.

I am delighted to report some preliminary findings which can help secure information.

Individuals need to have personal security of personal data high on their “awareness” list. In fact research shows that ID security needs to become a “second sense”. It should never be something we do once a month or quarterly.

There is now significant evidence that there is an “Unwarranted Trust” - UT -factor which basically “disarms” people’s behavior when it comes to securing and protecting sensitive data. Understanding UT as a sociological and psychological behavioral phenomenon, we feel, is THE single most critically important factor in successful “Security Behavior Modification” – SBM.

The second phase of the NSF-CIP project is designed to modify and improve and develop a continuous improvement paradigm for training systems for employees who have access to critical information. As one of our sponsors who is with a large multinational company pointed out at a recent briefing SBM is invaluable not only for the protection of traditional data of concern such as Social Security and Credit Card numbers and birth dates but also as a means of sensitizing employees to the risk of revealing or losing proprietary information, business plans, patents, and other information that should be secured and protected.

For more information on the National Science Foundation/Center for Information Protection project please contact us at ---
Michael McCoy - 559 Ross Hall Ames, IA. 50011-1204 or email: mrmccoy@iastate.edu


Steffen Schmidt

Labels: , , , , , , , , , , ,

Friday, May 04, 2007

England Has Their Problems As Well

Experian Inc. a credit checking agency on Thursday reported that identity theft cases in England have increased by 69% between 2005 and 2006.

In England over 2,000 people contacted the Experian victims of identity theft hotline for in the last six months of 2006 alone.

According to Experian, about 45 percent of those victims were alerted to a problem by a financial services company that noticed unusual activity. Forty-one percent found out through their credit report. The rest found out either after a refusal of credit, a theft or through notices they were being awarded credit they had not personally requested.

Watch out when companies like these start offering you services to protect your good name. Isn't there a small conflict of interest?

Labels: , , , , ,

Sunday, April 22, 2007

26 Years of Non Public Information Shared by U.S.D.A.

Apparently individuals that applied for federal grants through the USDA didn’t read the fine print. It was not explained to them that their names and Social Security numbers (non-public information) were going to be shared with the world.

Below was a statement by the USDA -

“USDA believes that immediately prior to April 13th, the website in question contained private identification information relating to approximately 47,000 individuals who receive USDA funding from the Farm Service Agency and USDA Rural Development. USDA has identified between 105,000 and 150,000 individuals whose private information has been entered into a federal government database at some time during the past 26 years. USDA is in the process of notifying, via registered mail, all 150,000 people whose information was exposed and offering them the opportunity to register for free credit monitoring for one year.”

Once again one of our trusty government agencies gives us an identity theft headline. I guess maybe I should not complain, it does give me job security.

Labels: , , , , , , , , , ,

Tuesday, March 20, 2007

Are You At Risk?

Is anyone’s identity really safe these days? There are two big issues that identity theft educators, investigators, and law makers are trying to convey. One is the risk of business identity theft and its ramifications to businesses (of all sizes) and the other is the risk to individuals. Of course, there is overlap with both, because one affects the other. Right now, I want to focus on the personal side of identity theft—your personal risk. The big question is. . . Are you at risk? The answer is absolutely YES!

According to Privacy Rights Clearinghouse, a non-profit consumer information and advocacy organization, security breaches of personal identifying information are accelerating and putting all Americans at HIGH risk for identity theft. Over 104 million data records have been breached in the past two years. Visit www.privacyrights.org to see the National Data Breach List. I have noted this before, but since the total is increasing so fast, you really must see why for yourself.

Types of Identity Theft
Are you aware that there are 5 types of identity theft? Most people are not aware of this fact. Financial identity theft may be the most common, but it is about 28 percent of all identity theft. In the United States, driver’s license, medical, Social Security, and criminal identity theft are just as serious, especially to their victims. Did you know that 12 percent of all identity theft victims end up with a wrongful criminal record?

Think about it. You could be arrested during a routine traffic stop for crimes you did not commit. A thief could use your SS# for employment and you become responsible for paying the taxes on that income. Your medical insurance rates could go up or your health insurance coverage could be cancelled or used up. Unfortunately, in all areas of identity theft, innocent victims are considered guilty until proven innocent. In addition, laws hold victims partially responsible for fraudulent debt after 48 hours, and hold them fully responsible if not reported within 60 days.

The Federal Trade Commission (FTC) says, “People whose identities have been stolen can spend months or years—and thousands of dollars—cleaning up the mess the thieves have made of a good name and credit record.”

Laws Protect Consumers
New federal privacy and identity theft laws protect the consumer. These laws are putting the responsibility on all businesses to protect personal identifying information that is maintained, stored, or discarded.

Consumers are not yet aware that if any size or type of business is in violation of a data security breach resulting in identity theft, then the victims may likely win a class action lawsuit. Some law firms around the country are advertising to represent identity theft victims. Victims of winning cases can be awarded damages with no statutory limitation, including payment of actual losses and attorney fees. Hefty penalty fines can be assessed to the business and executives. And, prison terms for executives may be enforced, depending on which privacy laws were violated.

Based on existing federal and state laws, consumers have the right and power to blow the whistle on businesses not compliant to federal/state security regulations. Some states give a whistleblower reward up to 15 percent of the fines collected. (More on this at a later date.)

The ultimate power consumers have is to stop doing business with privacy and security offenders who are negligent and disrespectful of safekeeping personal identifying information about their customers and employees.

The Reality
The worldwide reality is--identity theft cannot be prevented. It is out of the individual’s control how others use and store personal identifying information. However, increasing your awareness and adopting safe habits at home, in public, and at work will help to lower your risk.

The Best Wall of Defense
The strongest defense for identity theft includes a credit report, daily credit monitoring, and true restoration of your identity (restoration of all 5 of them), plus more. It is a defense system that clicks in immediately when the unexpected happens. I know of only one company that performs all three of these services.

Be Proactive, Not Reactive
The risk is very high for all forms of identity theft and will continue to increase. People need to take protective measures, understand the threats, and not ignore the warning signs. While identity theft emerges as the immensely destructive villain that it is, its wrath is devastating victims and its path is forcing change to lifestyle habits and business practices.


Lois Hale, MS, CITRMS Reno, Nevada USA
ICFE Certified Identity Theft Risk Management Specialist
ADRS Certified Group Security Specialist

Labels: , , , , , ,

Thursday, March 15, 2007

Industry of Ignorance or Greed?

I have stated in my book as well as my lectures and seminars that in my opinion identity theft “insurance” or a “monitoring service” that is proactive as well as reactive will be a must in everyone’s insurance portfolio within three to five years.

You do not have to like this, it is a matter of necessity.

Ask yourself, when is the last time you have made a claim under your auto insurance? What about your home owners insurance? Then why do most of you carry it? It is the same reason you will start to carry identity theft insurance.

The problem with insurance products on the market today is they are not robust enough. Until someone starts to listen to the masses and builds a product for the good of the people instead of for corporate greed the individual will continue to lose.

I am convinced the insurance industry is to lazy and greedy to do the research needed to build a product that will have some real teeth. I am also convinced that the congress is to lazy, greedy and worried about being re-elected to make any "real" changes to the law that, god forbid, is on the side of the public instead of "corporate america." I want to assure the insurance industry, if you get your head out of the sand and realize what opportunity you have in front of you there is a lot of money to be made, while truly fulfilling your client's needs.

In a meeting, roughly one year ago, I attended with a large company that provides an identity theft protection product, I voiced my concern with their product and the lack of “true” proactive coverage and the false sense of security the consumer was getting from it. The answer I received from their managers was flabbergasting. They said their product was … (Another Post for another Time) Even I was shocked.

This is not a local, state, regional, or national issue, this is a global issue that can and will cause financial destruction on a global scale. This global issue will soon become an epidemic if unchecked as the below article from South Africa demonstrates.

In an article written by Nabelah Adams on 15 March 2007 for BusinessOwner.Co.ZA, Nabelah quotes Caroline Buthelezi of the Credit Information Ombud’s Office of South Africa as stating, “Clearing one’s name involves a great deal of effort as many people only discover the consequences of not reporting their ID book stolen when the credit bureau has already handed the matter over to their lawyers.”

“The consequences of ID theft might be even more exacerbated by the fact that attempts to have matters resolved are complicated by having to deal with attorneys,” Buthelezi says. This is of course if you can afford to hire an attorney.

© 2007 Michael R. McCoy

Labels: , , , ,

  • All Material is Copyright © 2009 Michael McCoy and SEAS, L.L.C
  • Deter. Detect. Defend. Avoid ID Theft - www.ftc.gov/idtheft