Friday, October 24, 2008
Important News, at least for me
http://www.marketwatch.com/news/story/economic-slump---not-some/story.aspx?guid=%7BC0DC8CAF-CBB2-4465-AFA7-735EF4762E43%7D&dist=hppr
John
Wednesday, October 22, 2008
FTC Announces a Forbearance of the Red Flags Enforcement
May 1, 2009
FTC Grants Six-Month Delay of Enforcement of 'Red Flags' Rule Requiring Creditors and Financial Institutions to Have Identity Theft Prevention Programs
The Federal Trade Commission will suspend enforcement of the new "Red Flags Rule" until May 1, 2009, to give creditors and financial institutions additional time in which to develop and implement written identity theft prevention programs.
NOTE: Today's announcement and the release of an Enforcement Policy Statement do not affect other federal agencies' enforcement of the original November 1, 2008 deadline for institutions subject to their oversight to be in compliance.Read the announcement: http://www.ftc.gov/opa/2008/10/redflags.shtm
This applies to all entities with oversight from the FTC only. All financial institutions with oversight from the federal banking and financial regulatory authorities still must be compliant by November 1st of 2008.
The FTC currently estimates that approximately 11 million entities from private business to municipalities, schools and universities, and non-profits are considered to have covered accounts and need to address the "red Flags" and initiate compliance steps relevant to each organization.
Tuesday, October 7, 2008
Shell fingers IT contractor in theft of employee data
Oil company says outside IT worker used info from database to file fake unemployment claims
Robert McMillan Computerworld
October 6, 2008 (IDG News Service) Shell Oil Co. is warning its employees that an IT contractor used the personal data of four Shell workers as part of an unemployment insurance claims scam in Texas.
Shell Oil, the U.S. subsidiary of Royal Dutch Shell PLC, began notifying employees of the data breach on Friday, via a written notice that was posted on the Houston-based company's Web site.
Shell spokeswoman Robin Lebovitz said company officials noticed early last month that someone had used Shell employee data to file fake unemployment compensation claims with the Texas Workforce Commission (TWC). After investigating, Shell determined that an employee of a third-party contractor had misused information stored in a corporate database, Lebovitz said.
The database includes records for a majority of current and former Shell employees in the U.S., according to Lebovitz. The notice about the breach indicated that the misused data included names, dates of birth, Social Security numbers and some financial information.
The suspected scammer filed four false claims, Lebovitz said, adding that Shell has yet to uncover any evidence that other information from the database was compromised as part of the alleged claims scheme.
Shell didn't identify the company that employed the suspect, saying only that it had been hired to work on a data indexing project involving the database. The notice to employees said that after the fraudulent claims were discovered, Shell escorted the suspect from its premises and terminated its contract with the IT company.
The alleged crime continues to be investigated by Shell, the Houston police and the TWC, Lebovitz said
Monday, October 6, 2008
New Federal Law Targets ID Theft, Cybercrime
"President Bush last week signed into law a bill that seeks to make it easier for prosecutors to go after cybercrooks, while ensuring that identity theft victims are compensated for their time and trouble when convicted identity thieves are forced to cough up ill-gotten gains.
The Identity Theft Enforcement and Restitution Act of 2008 lowers the bar prosecutors need to clear before bringing hacking and other cybercrime charges against an individual. Under current federal cybercrime laws, prosecutors must show that the illegal activity caused at least $5,000 in damages before they can bring charges for unauthorized access to a computer. The new law eliminates that requirement. "
Provided of course that the thief is caught and brought to justice. With less than 5% of identity thieves being nabbed this law will only help a small minority of the victims. It is a step in the right direction however.
Just as important as this new law is, actually another portion of the article really caught my eye.
"Some ID theft victims can spend thousands of dollars and months or years dealing with credit bureaus and debtors from accounts fraudulently opened in their names, but the law doesn't appear to take into account lost opportunities associated with identity theft. According to the Federal Trade Commission, some consumers victimized by identity theft may lose out on job opportunities or be denied loans for education, housing or cars because of negative information on their credit reports. In rare cases, they may even be arrested for crimes they did not commit. "
It is just as important to understand that victims of identity theft are faced with the massive task of fighting nearly overwhelming obstacles in clearing up identity theft episodes. The banking system has certain measures in place to deal with fraud on bank and credit accounts. Once you leave the banking realm however, the bureaucracy of databases and information repositories can prevent a maze of challenges to clearing up false entries and records inaccuracies.
John
Wednesday, October 1, 2008
October 1st 2008
On January 1st 2008 the federal financial institution regulatory agencies and the Federal Trade Commission have sent to the Federal Register for publication final rules on identity theft “red flags” and address discrepancies. The final rules implement sections 114 and 315 of the Fair and Accurate Credit Transactions Act of 2003.
“The final rules require each financial institution and creditor that holds any consumer account, or other account for which there is a reasonably foreseeable risk of identity theft, to develop and implement an Identity Theft Prevention Program”. Institute of Fraud Risk Management report. January, 2008
There has been a good deal of conversation about what is a covered account, financial institution, and consumer account as defined by the federal authorities. The link above leads to the actual “Final Rules”. As it is currently understood and without quoting the legislation a financial institution or creditor is defined as;
- A bank, savings institution, or personal account lender of any type.
- Also a real estate agency, mortgage broker, auto dealership, financial planner, investment broker, or any business that sets up, initiates, or maintains a payment account of any kind with an individual for personal or household purposes.
- Any utility company that establishes an individual payment account with its’ customers.
- Any municipality or county that provides utilities or services and arranges for regular payment from the users of the services provided.
- Any business that extends ongoing credit or arranges for payment accounts for its’ customers or clients. Single payments or intermittent payment arrangements do not qualify as covered accounts.
As the rules went into effect as of January 1st of 2008 all covered entities have until November 1st 2008 to initiate such a breach response and prevention plan.
Compliance is a process, and the intention of these rules is to put procedures in place that will stem the tide of identity theft. Identity theft currently costs American business over $48 billion each year directly or indirectly. It is in the interest of every business entity to address this runaway cost and the risk of litigation and fines. While not all businesses are considered to be covered under the “rules”, all business should adopt the practices and procedures.
With only 30 days to go until compliance, every business and governmental entity in the U.S. whether subject to this legislation or not, should take stock of the risk they are willing to take on this issue. I see a good deal of apathy about this from people who have not yet become victims of identity theft. When a business owner or officer takes an apathetic position they are not just gambling with their own identity issues but those of their employees, customers, vendors, constituents, etc. They are also taking a huge risk for the business. Fines and lawsuits resulting from data breaches without a breach response and identity theft prevention plan can devastate a business both financially and from a public relations perspective. Add to that, federal audits and for retailers the loss of credit card processing accounts, and you have an untenable position that can be entirely avoided with a small investment in time. While we cannot entirely eliminate identity theft we can mitigate the risk with a few simple steps.
Friday, September 26, 2008
Applications and Identity Theft
Major companies involved in the architecture and implementation of web applications are proposing new Internet protocol rules and passkey requirements for data access. In the web 2.0 world of cloud computing these are very important issues, and absolutely need to be addressed. Data collection becomes more ubiquitous for a variety of reasons and the trade off between our individual rights to privacy and the public right to know is under an increased scrutiny.
Beneath the radar of public discussion however, thousands of lists and databases containing yours and my personal information are ripe for the picking.
Below is an excerpt from an article in today’s New York Times.
September 25, 2008
The Fix
Applications and Identity Theft
By JAY ROMANO New York Times
“CO-OP boards, condo boards and even landlords routinely ask applicants for personal data like Social Security numbers, exactly the kind of information that is used in identity theft.
According to lawyers and managing agents for co-ops, condos and rental buildings, applicants are becoming skittish about providing sensitive information. More than 14 million Americans reported being victims of identity theft in the 12 months before August 2007, according to Avivah Litan, a security analyst for the research firm Gartner.
While there is no indication that widespread theft of information has resulted from co-op and condo filings, Habitat magazine, a New York publication covering co-ops and condos, has published two articles in the last year or so dealing with identity theft.
The magazine interviewed two prospective apartment purchasers who believed that carelessness by board members led to the release of sensitive information that was used by thieves to open accounts in their names. One building worker acknowledged that he found 10 years of application packages in a board member’s trash.”
This is a classic example of the sort of database that is overlooked. Smaller local databases are extremely vulnerable to theft and loss mainly due to a lack of understanding of proper procedures and the real risks from loss. What the prevailing wisdom tends to ignore are these thousands of lists and databases that already exist with our personal information.
When someone is victimized by an identity thief in Eastern Europe who has bought his or her information for $25 in bulk and resold it to someone else who files a phony medical insurance claim, or a crack addict who sells it to someone with a criminal record who obtains employment using a stolen SSN, do you think they care which database was the source of the theft? The victim is stuck with the fallout that statistically takes from 3 to 5 years to clear up, and even then often resurfaces at a later time.
The public is essentially unaware of what identity theft is, and business has almost no clue as to their legal and moral obligation to protect and properly store and dispose of sensitive personal information. What happens for example to information kept in your dentists’ office, or your insurance agent? What are their protection and disposal procedures? How about your town and county records? Schools? American business is losing about $50B, that’s billion, in direct and indirect costs each year due to identity theft. When large databases are hacked like the Veterans’ Administration for 26.5 million records, or TJX for somewhere between 41 and 91 million records, UCLA for 800,000 records, etc, it makes the news. Complaints pile up at state and federal legislators’ mailboxes. An upward spiraling argument always follows every large breach with people demanding new laws which when enacted are ineffective in stemming the theft and sale of personal information. As long as the data has value it will continue to be a commodity for sale.
Getting back to my employee group trainings I always ask the group what they think of when they hear the terms data theft and identity theft. Almost invariably the answers are centered on credit reports, bank account and credit card misuse. While that is a significant portion of the identity theft reported to the FTC, the overwhelming majority of cases reported (70%) do not involve finances at all. Only through public awareness can the crimes of identity theft be squelched. The groups we speak with are more aware and proactive both with their own personal information and with the information they handle at work. We are all responsible for each other’s data. Creating better habits of safekeeping it will establish the “culture of security” we all seek.
Tuesday, September 23, 2008
FTC requires towns to add identity theft programs
September 15, 2008
" The Federal Trade Commission (FTC) has issued new requirements for municipalities on the adoption of identity theft programs.A release was distributed to all municipalities by the North Carolina League of Municipalities (NCLM) on Sept. 4, asking all managers, administrators, clerks, attorneys and finance officers to have written procedures in place to help protect consumer identity and fight theft of customer account information.The release stated that all municipalities with utility accounts must participate. According to the Tennessee Valley Public Power Association (TVPPA), utilities rank No. 3 as a place for identity thieves to gain information. Credit cards companies and cell phone companies are the top two.The objective of the program is to identify, detect and respond to red flags, meaning a pattern or practice of specific activity that indicates the possible existence of identity theft.Examples included in the memo were events such as the receipt of warnings from consumer reporting agencies, the presentation to the creditor of suspicious documents, the presentation to a creditor of suspicious personal identifying information and the unusual use of a covered account."
The public, that's' you and me, need to learn as much about what identity theft is, (the reality not the stuff you are fed on TV), and what we can do to prevent being a victim and minimize our risk. Education is the single most important part. That is why training on the job is critical. People who have access to personal information either as part of their job, or in the event sensitive info falls into their laps accidentally, need to know how to handle it and make certain it doesn't get lost or end up in the wrong hands.
The FTC is listening to the professionals and making policy suggestions that are extremely important for all business to follow. There is a great booklet "Protecting Personal Information, a guide for business" available at www.ftc.gov/infosecurity .
Everything any business entity needs to know about setting up a training and breach response plan is in the booklet. As the result of the adoption of the Red Flag Rules, sec.114 of FACTA, the entire retail banking and savings industry is compelled to comply with these practices. If local government and private industry continue to resist these steps a similar law will soon make it mandatory for all employers as is suggested in the article here.
Business has a choice, a voluntary plan to reduce risk and put training and policy in place, or a law forcing these and other steps with stiff penalties for non-compliance. As I wrote in a previous column compliance is a process. While it isn't mandatory for all, it is a matter of choosing the right course of action. Every entity that maintains personal information has an obligation and moral responsibility to protect that information from loss or theft. And when the data is no longer needed, to dispose of it responsibly. Remember, it isn't someone elses' information at stake it is yours and mine.

