Showing posts with label malware. Show all posts
Showing posts with label malware. Show all posts

Wednesday, July 29, 2009

Business Identity Theft - Dangers, Gaps, Solutions

I stress that these views are mine and influenced by the works cited here, they are not necessarily the views of ID Experts.



UPDATE 08/06: Panda Security reports 44% of SMBs admit falling victim to cybercrime.

Generally speaking, when most people discuss identity theft, they are referring to an individual using the personal identifying information of another individual, without their consent, to obtain some profit or advantage. Identity theft is largely viewed as a “people” problem, and for good reason- Most state and federal laws, websites, non-profit organizations and consumer advocacy groups tasked with the job of helping identity theft victims address the American consumer at large.

Yet, small and medium sized businesses (SMBs) are an attractive target for identity thieves. According to the Institute of Consumer Financial Education (ICFE), SMBs usually qualify for larger lines of credit, “enjoy extended payment terms and less transactional scrutiny for large purchases or high value ticket items than individual customers.” They often have physical property such as computer equipment of value, or perhaps inexperienced employees that may be susceptible to phishing attempts or bribes. Many SMBs are located in shared business buildings, making it even easier to obtain credit cards and loans. All a criminal has to do is rent a small space or mailbox in your building- the address will verify as correct, and he’ll get the credit cards, loan documents, and bills instead of you. Before you even know something is wrong, he has skipped town without a trace- except for the damage to your business.

In addition to being lucrative, small and medium size businesses are often careless with privacy and security because they are preoccupied with- well, running their business. According to the ICFE, “Many businesses do not regularly review their business credit report.. [or] ..always carefully scrutinize employee charge card billing statements before they are paid, particularly those accounts for which multiple cards are issued.” Additionally, a recent survey from security firm Panda Security shows SMBs in the United States are increasingly the victims of cybercrime, yet many do not take simple precautions to protect themselves. By the numbers:

* (44 percent) were hit by some form of cybercrime

* (10 percent) surveyed were hit so bad that they had to stop production -- worldwide, the average was 30 percent.

* (50 percent) of companies in the survey lost time or productivity as a result of being infected.

* (97 percent) of U.S. SMBs have installed anti-virus and (95 percent) claim their security systems are up to date. YET (29 percent) said they have no anti-spam in place, (22 percent) are without anti-spyware technology and (16 percent) do not have firewalls. (52 percent) said they have no web filtering solution in place. (39 percent) of respondents said that they have yet to be trained about IT threats.

When you combine large cash /credit flow and little scrutiny or security, it is easy to see what a gold mine this is to thieves. I’m not done yet- There is another factor that makes these threats an increasing danger in an age of government transparency and online communications. Not only are you an attractive target, but obtaining the documentation necessary to impersonate a business or pose as a representative of the business is often easier than for an individual.

Your business information is easily obtained from a variety of offline and online sources. Business stationary and business cards are easy to obtain and duplicate, and since “most businesses are eager to open new accounts for other businesses, and the process can be quite simple- such as submitting a request on company letterhead along with the business license number and Tax ID.” (ICFE) Since most businesses display their business license on their wall (as many are required to by law), this theft is dangerously easy. Additionally, businesses may engage in high-risk sharing of their business information. Because many companies such as Costco require an EIN to give users status as a business, the EIN is tossed around a lot on documents and over the phone. Small business owners may even be using their own social security number in place of an EIN, increasing their risk and potential for damage. SMBs aren’t just a gold mine; they’re a gold mine filled with diamonds.

There are unfortunate gaps in our system. There are hundreds of companies, pre-paid legal services, private investigators, non-profits and consumer advocacy groups that are trained and versed in handling personal identity theft- but find themselves either unprepared or unable to assist businesses when they become victims. Their hands are often tied by either state laws, procedural technicalities, binding contracts and user agreements or just plain ignorance.

As pointed out in a recent article by Business Week, “While business identity theft can often be prosecuted under other statutes, like mail fraud or wire fraud, businesses victimized lose many of the protections afforded to consumers under identity theft laws, like access to information about their credit. Before California last year amended its 1997 identity theft law explicitly to include crimes targeting business entities, a business whose identity had been co-opted could not even get a police report. ‘We were having businesses being taken over and their names being used and I could not prosecute them, at least under ID theft statutes,’ California Deputy Attorney General Robert Morgester says.” (The state legislature amended the “person” in identity theft cases to encompass associations, organizations, partnerships, businesses, trusts, companies and corporations, in addition to logos and “photographic representation” as legally recognized personal ID data.) Yet, there are many other states that still do not recognize business identity theft as a separate crime at all.

Additionally, many loan contracts and credit agreements may have fine print that could leave you high and dry. According to ICFE, “liability provisions in many cardholder agreements specifically exclude: unauthorized transactions involving business cards and cards used for business purposes…and instances where a transaction by an individual, who at some point was given permission to use the card by the cardholder, ‘exceeds authority’ given by the account owner.” Since insider threats are still the biggest concern when it comes to loss prevention, this particular fine print can mean a lot to a business owner. Perhaps most devastating: “Most loan documents contain a provision which states that if the lending bank ‘deems itself insecure’, repayment of the loan may be accelerated. If numerous fraudulent accounts have caused the bank to no longer be confident of the business’ long term viability, a business’ loans or credit lines may suddenly be called and most businesses would simply not have sufficient cash or liquid assets available to fully service the debt.” While there has been a little progress in this area, like state laws, there are a lot of gaps. Visa, MasterCard, and American Express no longer distinguish between small business and individual credit card fraud, which helps companies to clear the purchases made by thieves. We can only hope that others follow suit.

A thief with access to EIN, address, key names, and letterhead or company logos can easily apply for credit or obtain loans and merchandise as a “representative” of your company. There are painful gaps in consumer law and business practices that make the extensive, time-consuming, complex and potentially expensive process of recovering from identity theft even harder. Dealing with the theft can take months or years. Don’t take chances, and protect yourself:

Shred. Shred. Shred. Dumpster diving is still a common source of information.

Don’t hold onto documents any longer than absolutely necessary.

Obtain an EIN and use it instead of your SSN. Be cautious with your EIN and give it out sparingly.

Obtain regular credit reports for yourself and your business. Review them carefully.

Review your Better Business Bureau report regularly. In addition to identity theft, business can also become the victim of professional impersonation. In many cases, evidence of both types of crimes will show up on the BBB report.

Owners should review transactions statements and account for all items. If you give review power to another individual, be aware they are now a target for bribes and extortion. The best solution is to take matters into your own hands and report any unusual activity immediately.

Improve your business physical, technical, and personal security. Alarms, firewalls, encryption and anti-virus are all important components, but more important is the education of you and your staff. How to detect and deter phishing attacks, how to report suspicious behavior anonymously, and what to do if you believe you may have compromised information are all topics every employee should know by heart.

Be an informed consumer- ask what precautions businesses take with your applications and other business identifying documents and data. Explain your concerns. Enough business owners bring up these concerns, they will listen.

Other advice includes;

“Consider using electronic payment options. Since the networks are password-protected and the messages are encrypted, wire transfers and ACH payments are much safer than using paper checks…

And lastly, consider a post office box or a lockbox for your mail. This ensures that business mail is retrieved by appropriate personnel and is not left in a box at the reach of any passerby.”

Practical advice for changing the outlook for SMBs: Put your money where your mouth is, and the squeaky voting wheel gets the grease. Do business with companies with good security practices- even if it means it makes it more difficult to do business with them. Write to your representatives and voice your concerns. Bring awareness to the dangerous of identity theft for small and medium businesses to your associates, your lawmakers and your financial institutions. If legislation regarding personal identity theft rights is any indication, it is going to require a concerted grass roots effort to bring awareness to the issue and create change. It is time.

UPDATE 07/30/2009: Another threat to businesses highlighted by the Better Business Bureau, "Scam artists send an invoice for a product commonly purchased by the business. For example, paper or other office supplies, in hopes that the busy staff will pay the funds without question."

Copyright 2009 Rachel James. Please do not republish without written consent. You are welcome to link in reference.

Thursday, July 23, 2009

Getting Engaged can lead to Identity Theft

republished from ID Experts blog.

A few news stories have been circulating about the looming identity theft threat to couples who have decided to tie the knot. Thieves prey on our deepest and strongest emotions, and two people madly in love and about to take the plunge are certainly full of emotions and stress. Stress makes us more apt to decide quickly, without thinking the situation through. The sense of relief we feel may encourage us to accept an offer that seems “too good to be true” when we might otherwise hesitate. Our families and friends may also be targeted, for much the same reasons. Think like a thief- on average weddings cost over $20,000 and guest gifts range between $50-150 each. That places a rather large bulls-eye on anyone involved. Here is just a small list of the kinds of scams that are lurking out there:

  • Fake vendors- these are identity thieves or card frauders. They are online, at bridal shows, and call individuals out of the blue. You may be even approaching them for a genuine service advertised in the classifieds or a bridal magazine, or it may be a “sweepstakes”. As part of the “contract” or “application” you answer personal questions in great detail or provide a credit card number that is later used to defraud you.
  • Fraud vendors- this category is not technically identity theft, but still leaves you stung. Often you are promised a “free” sample and hand over your credit card for shipping and handling, and then find yourself with outrageous charges. Vendors take a deposit for renting you an item as pictured on their site, and when the big day comes, nothing arrives or what arrives bears little resemblance to the model. Sweepstakes and Giveaways should be especially scrutinized if you get a call and you “won” – there may be strings attached.
  • Crooks- these people take advantage of the fact you share so much about your event. They may rob your house while you’re exchanging rings, or wait until you’re away on honeymoon. While everyone at the reception is distracted, they snatch purses or sneak into hotel rooms. Honeymooners are easily targeted by pickpockets, camera snatchers, and hustlers.
  • Disappearing act- this can be anything from a deposit you paid disappearing from the books to a company suddenly going bankrupt. Bankruptcies are up 47% from last year, so this is a big concern. While insurance can help protect you, it is important to purchase coverage carefully.
  • Malware - There are tons of “free” applications out there to help out couples. Cost calculators, dress design software, websites, countdown clocks, reminders, calendars, the list goes on… Then there are the flash animations and videos of weddings, decorations, crafts, flowers and more. However, some of these may contain harmful code that could harvest your information and place you at risk for identity theft and fraud.
  • Robocalls and junk mail – While shopping around online or in person, you’re often asked to leave your contact information. This can result in an increase in junk mail offers and robocalls. Some of these are likely phishing attempts, and are cleverly disguised. Another risk with increased junk mail is the possibility of mail theft going unnoticed for a longer period of time. Pre-approved credit card offers may inflate your mailbox, also increasing your risk of fraud.
  • “In distress” scam- this is commonly used while a couple is on honeymoon, but can strike at any time. Fraudsters may call, email, or take over your email or social networking accounts to contact your friends and family claiming to need emergency money. Excuses range from medical emergencies, to being kidnapped. Often they have “been robbed” and need the money to get home. The rest is ALWAYS to wire money or send Western Union.
  • YOU – of all the threats, YOU might be your own worst enemy. Many couples have wedding announcements; send emails, e-vites, wedding websites, social networking pages, online gift registries with their personal information, personal details, family details, and wedding, reception and honeymoon specifics available to the public at large. Brides and grooms alike tend to become excited and may share greater detail about themselves, their partners and the event with coworkers and friends… and florists, photographers, DJs (or anyone else who will listen).

With a few minor changes and some awareness, you can still have all the bells and whistles to your big day while keeping your friends, family and your identity safe.

  • Assume the numbers and addresses you are using to contact vendors, get quotes, order catalogs are going to be stolen, traded and sold over and over. Set up a PO Box and a separate number to use for your contact information.
  • Contact the Better Business Bureau in your area about any vendor, sweepstakes, or service you are going to fork over a large amount of money to, or that you are unfamiliar with. Do this before you provide them any personal or contact information.
  • Always assume that calls you receive are compromised and never reveal any personal information. You may trust calls you initiate to a trusted business more, but still exercise caution.
  • Read ALL fine print carefully. TWICE.
  • Keep all receipts; require everything in writing and document, document, document. Go over all your credit card and bank statements monthly and notify your financial institution right away if you notice any unusual activity.
  • Quarantine. Don’t use the same passwords or email account for your social networking sites, registry, and wedding webpage. You should never attach your “trusted” email account you have been using to communicate with your friends and family to another site. A compromise of a social networking site can easily lead to an email compromise, and makes it easier for fraudsters to contact your entire address book for money. If your quarantined email is hacked and messages sent to all your friends, they should be more cautious since it is a different email than they are used to communicating with you. This will buy you enough time that you can then use your “trusted” email account to notify them all of the fraud (or better yet- call them!).
  • Never send money Western Union- this is one of the few ways you can send money and never get it back. Provide contact information to their nearest consulate if you are met with this scam online.
  • Limit access to personal information- If you are going to list the details of your big day and honeymoon, look for websites that allow you to create a wedding website for friends only, or that is password protected so you can control who has access.
  • Be careful of accidentally revealing personal information like your mother’s maiden name (which may be derived from guest lists or online friend list on social networking sites) and your date or place of birth. Also, you will be asked a lot of questions so people can “get to know you” before your big day- make sure none of these questions and answers correspond to the security questions of any account you have. Go through each online account and determine what questions are asked if you click “I forgot my password”. You may wish to change those answers.
  • Find gift registries that allow you to control privacy, and insist on revealing as little about yourself as possible. Gift registries often offer a disturbing amount of detail about you, and often are generally open to the public.

Check your credit reports regularly with www.annualcreditreport.com or by calling 1-877-322-8228. If you do experiance fraud or a scam, report it to your Better Business Bureau and the FTC and place fraud alerts with the major credit bureaus.