Showing posts with label credit fraud. Show all posts
Showing posts with label credit fraud. Show all posts

Sunday, September 27, 2009

Recession prompts shift in cybercrime tactics




Rates of all but one type of online crime have increased over the past year, with a crime being committed on the internet every 10 seconds, according to the latest report from security vendor Garlik.

And losses due to banking fraud have more than doubled since last year.

The report details how cyber criminals have adapted their methods to take into account the effects of the recession. Instead of opening new accounts with stolen identities now more difficult because of tighter credit checks criminals are taking over existing accounts.

Tom Ilube, chief executive of Garlik, said that fraud cases involving hijacking legitimate accounts have increased 207 per cent in the past year.

We fear that account-takeover fraud will continue to increase in 2009 due to the decline of available credit and tighter credit-checking by the banks,” he said.

“Consumers must be extra vigilant of all their online and financial accounts as well as avoiding increasingly convincing phishing scams.”

The report predicts the activity is likely to continue into 2009 in line with the continued restrictions on credit.

The report also highlights that online banking fraud has increased by 132 per cent, with losses totalling £52.5m, compared with £22.6m in the previous year.

Garlik detected nearly 44,000 phishing web sites specifically targeting banks and building societies in the UK.

Zikkir

Saturday, September 26, 2009

Ohio Police uncover credit fraud: Three arrested in Brimfield



BRIMFIELD — Township police arrested three men Wednesday, charging them with stealing the identities and credit card numbers of more than 70 people nationwide. The trio also were in possession of equipment police believe can overwrite credit card information.

“The magnetic strip allowed them to turn anyone’s credit or debit card to another number,” said Brimfield Police Chief David Blough. “This is a very interesting case. It’s complex, and there are so many victims.”

Blough said officers did not know what they were getting themselves into when they responded to the Circle K on Tallmadge Road on Tuesday afternoon for a report of a “suspicious” credit card transaction.

They met with suspects 28-year-old Lorinzo Sampson and 26-year-old Richard Barringer III, both of Cleveland; and 27-year-old Alfred Woodall, of Canton, who were purchasing debit cards.

A clerk at the store called because the numbers on the front of the credit cards did not match the numbers being debited.

Sampson, Barringer and Woodall were taken to the Portage County jail. Each face four charges of identity fraud, a fourth-degree felony; four counts of criminal simulation, two counts of possession of tools and one count of telecommunications fraud — all fifth-degree felonies.

All of the about 70 stolen accounts were from out of state, Blough said.

He said the department is tracking down other fraudulent purchases possibly made by the men in other area businesses.

Record Pub

Saturday, August 22, 2009

Cybercrime Is a Growing Problem for Small Businesses


Cybercrime Is a Growing Problem for Small Businesses
Ever-more-sophisticated computer hacking of business networks and Web sites will require more safeguards and constant vigilance.

Think cyber crooks aren’t interested in your business? Think again. It’s not only the biggest or best-known companies that get hacked by organized syndicates or smaller cybercrime actors looking to steal corporate secrets and customer data.
Every company is a potential victim, even firms that spend heavily on security systems and IT staff. A determined and knowledgeable hacker will find a way to penetrate, and it can be costly. Losses are hard to calculate, but estimates from theft range as high as $1 trillion a year worldwide.
You may have been hit already and don’t know it. Many criminals operate under the radar, planting spyware and stealing valuable company data for months without businesses knowing it until it’s too late. Some thieves will tap into your customer base, grabbing credit card and other bank account information. Others copy trade secrets and sell them to competitors who may then lure away your customers. This is in addition to those who crash sites with the aim of keeping your online operation down for days and costing you business.
Not all of the popular targets are obvious. Charities and other nonprofits are targets because their lists and information on benefactors and donors can be valuable. And criminals often go after beneficiary lists from life insurers.
Organized crime rings are behind a high percentage of the attacks, often operating from abroad -- Russia, Ukraine and China, especially.
Fail-safe protection doesn’t exist. Even the Pentagon, with a battalion of the best computer specialists, gets hit repeatedly.
But it’s important to do whatever you can. Crooks will go where the taking is easiest, just as car thieves will grab a radio from an unlocked car before going through the trouble of circumventing a security system.
Many small businesses have no protection. One in five does not have antivirus software, and more than half don’t use encryption for wireless links. Two in three have no formal security policy, essentially banking on good luck that they won’t be victimized.
Computer safety doesn’t have to cost you a fortune. Some basic steps to take:
Install security software that includes antivirus, antiphishing, antispyware and networkwide anti-intrusion features and with automatic updating. The subscription cost is not much, about $100 a year.
Set up a firewall to protect all confidential information. Use multiple walls to guard your most sensitive data or keep it on a separate server or on paper. Use so-called smart passwords with numbers, letters and symbols, and change them periodically.
Be sure to block access to your network to ex-staffers. Beware of disgruntled workers who may be out to get you through computer stealth. Give employees in different departments and positions access only to parts of the network they need.
Also, vet anyone who buys advertising on your Web site. This, too, can be a source of malicious software. A personal phone call can trip up those who buy ads and use them to lure your customers to phony sites.
Train employees in safe computer practices. It’s the most important best practice and often overlooked by companies. Let them know that visiting nonwork-related sites puts the firm at risk. Eighty percent of malware is downloaded unknowingly at adult pornography sites.
Opening attachments from unknown sources can render a firewall useless. Laptops carried out of the office or left at a business conference are prime targets for theft.
Also, consider contracting with a certified “ethical hacker” to test your system regularly and to offer guidance to your in-house computer staff.

FTC Announces Expanded Business Education Campaign on 'Red Flags' Rule



To assist small businesses and other entities, the Federal Trade Commission staff will redouble its efforts to educate them about compliance with the "Red Flags" Rule and ease compliance by providing additional resources and guidance to clarify whether businesses are covered by the Rule and what they must do to comply. To give creditors and financial institutions more time to review this guidance and develop and implement written Identity Theft Prevention Programs, the FTC will further delay enforcement of the Rule until November 1, 2009.

The Red Flags Rule is an anti-fraud regulation, requiring “creditors” and “financial institutions” with covered accounts to implement programs to identify, detect, and respond to the warning signs, or “red flags,” that could indicate identity theft. The financial regulatory agencies, including the FTC, developed the Rule, which was mandated by the Fair and Accurate Credit Transactions Act of 2003 (FACTA). FACTA’s definition of “creditor” includes any entity that regularly extends or renews credit – or arranges for others to do so – and includes all entities that regularly permit deferred payments for goods or services. Accepting credit cards as a form of payment does not, by itself, make an entity a creditor. “Financial institutions” include entities that offer accounts that enable consumers to write checks or make payments to third parties through other means, such as other negotiable instruments or telephone transfers.

The FTC’s Red Flags Web site, www.ftc.gov/redflagsrule, offers resources to help entities determine if they are covered and, if they are, how to comply with the Rule. It includes an online compliance template that enables companies to design their own Identity Theft Prevention Program through an easy-to-do form, as well as articles directed to specific businesses and industries, guidance manuals, and Frequently Asked Questions to help companies navigate the Rule.

Although many covered entities have already developed and implemented appropriate, risk-based programs, some – particularly small businesses and entities with a low risk of identity theft – remain uncertain about their obligations. The additional compliance guidance that the Commission will make available shortly is designed to help them. Among other things,
Commission staff will create a special link for small and low-risk entities on the Red Flags Rule Web site with materials that provide guidance and direction regarding the Rule. The Commission has already posted FAQs that address how the FTC intends to enforce the Rule and other topics – www.ftc.gov/bcp/edu/microsites/redflagsrule/faqs.shtm. The enforcement FAQ states that Commission staff would be unlikely to recommend bringing a law enforcement action if entities know their customers or clients individually, or if they perform services in or around their customers’ homes, or if they operate in sectors where identity theft is rare and they have not themselves been the target of identity theft.

The three-month extension, coupled with this new guidance, should enable businesses to gain a better understanding of the Rule and any obligations that they may have under it. These steps are consistent with the House Appropriations Committee’s recent request that the Commission defer enforcement in conjunction with additional efforts to minimize the burdens of the Rule on health care providers and small businesses with a low risk of identity theft problems. Today’s announcement that the Commission will delay enforcement of the Rule until November 1, 2009, does not affect other federal agencies’ enforcement of the original November 1, 2008, compliance deadline for institutions subject to their oversight.

The Federal Trade Commission works for consumers to prevent fraudulent, deceptive, and unfair business practices and to provide information to help spot, stop, and avoid them. To file a complaint in English or Spanish, visit the FTC’s online Complaint Assistant or call 1-877-FTC-HELP (1-877-382-4357). The FTC enters complaints into Consumer Sentinel, a secure, online database available to more than 1,500 civil and criminal law enforcement agencies in the U.S. and abroad. The FTC’s Web site provides free information on a variety of consumer topics.
FTC Red Flags Rule