With all of the articles about breaches, including the ones I have posted, sometimes it is important to get back to basics about identity theft itself. Below is an excerpt from a PC World article published yesterday which outlines the definition of identity theft as it has evolved.
"Identity theft happens when your personal information is accessed by someone else without your explicit permission."• "Identity fraud occurs when criminals take that illegally obtained personal information and misuse it for their financial gain, by making fraudulent purchases or withdrawals, creating false accounts, or attempting to obtain services such as employment or healthcare. Personally identifying information such as your Social Security number, bank or credit card account numbers, passwords, telephone calling card number, birth date, name, address and so on can be used by criminals to profit at your expense."• "Almost 10 million Americans learned they were victims of identity fraud in 2008, up from 8.1 million victims in 2007.
"Identity theft also falls into this category [of financial fraud]; cases classified under this heading tend to be those where the perpetrator possesses the complainant's true name identification (in the form of a Social Security card, driver's license, or birth certificate), but there has not been a credit or debit card fraud committed."
Data breaches have become so ubiquitous that more often than not they go unnoticed, and often unreported.
I wonder how any victims of identity theft resulting from those breaches feel? While it is reported here that the number of breaches is on a decline the number of breached records is increasing and the number of ID theft victims holds steady. vIts all in the numbers.
ITWire.com reports that the number of data breaches reported to the media has declined significantly over the past 18 months. The article cites an Open Security Foundation blog post that says the number of breaches reported in global media has dropped from about 1,000 per month between 2005 and 2008, to about 500 per month. The blog speculates that boredom in the press may be a cause. "Just another data breach" isn't news anymore, the report states.
Full Story
In its annual report on data breaches The Identity Theft Resource Center (ITRC) says that 2009 marks the first time that malicious attacks have moved beyond human error as the leading cause of data breach, Dark Reading reports. According to the ITRC's "2009 Data Breach Report," hackers and insider theft accounted for 36.4 percent of breaches, human error 27.5 percent. The ITRC also found that compromised paper documents were involved in 26 percent of data breaches. In the 2009 report, the ITRC says that while the number of officially reported data breaches fell in 2009, it cannot determine if the overall breach rate is falling because of the number of unreported breaches.
Full Story
Ever hear of the phrase "An armed society is a polite society"? It does take things a bit far but the principle is right on the money. I've said time and again that if you can successfully remove the value from the data then you can actually reverse the trend in data theft and misuse. It shouldn't be the sole responsibility of the "data keepers" to protect it from lurking thieves. Just as in terrorism or any crime of attack, the good guys have to be right 100% of the time where the attacker only has to be right once. Not exactly great odds.
When you look at the practical percentages of theft surrounding your personal data you can see that the odds are lower of your stuff being stolen and used, than is widely perceived. Currently there are roughly 10 million domestic identity theft victims each year according to FTC and Ponemon Institute estimates. A little over 60% of those cases are the result of data theft from a public or private entity. But that doesn't mean that it is any less devastating. The problem is that when you entrust the data keeper to report the loss to you, or to fix a breach weak link, or frankly do anything for you after the fact, you are dreaming. No breached entity will tell you that the breach will likely result in identity theft. They will run damage control instead, meaning that they will downplay that aspect to protect their public image. The problem with that is that time is now on the side of the thieves to sell or use your personal information. A breached entity can take months or in some cases years to notify you of the loss. Sometimes not at all if the breach doesn't rise to the threshold the states' reporting laws have in place.
In light of that reality why then can't we all empower ourselves to be our own first line of defense when it comes to our personal data? With the power to act in our hands we are able to react to incidents of breach and identity theft much faster and with greater precision than is possible from the university, government agency, employer, or hospital, etc, that lost it in the first place. A professional agency dedicated to notifying us when our information is misused and report that misuse within hours is our best line of personal defense. If that agency can not only report these incidents to you in a timely way but also act as your proxy to correct the errors and false records entries on your behalf when it does occur is the most direct way to protect ourselves.
Tangentially, by having such a representative we are lowering the value of the data to the thieves. Illicit data brokers and identity thieves rely on time being on their side to profit from the misuse of your information. They need days or weeks to actually use the data to make purchases or obtain insurance, file false claims, get employment, etc. Draining bank accounts or running up credit purchases, while pretty awful, are largely handled by the banks and credit card companies themselves. With timely reporting a bank generally will help the victim but only with timely reporting. That means within hours or a day or so at the longest. Beyond a few days a banks' responsibility is much reduced. If you are not aware of the misuse you cannot report it to the bank. An agency that can notify the client within hours of an identity theft episode can shut down the misuse and render that identity information nearly useless almost immediately. The client is isolated from the incident, identified as a victim of identity theft, and the agency then can begin the restoration of the records or credit files affected. They will also look for other misuse within other databases in the event the incident is more widespread than the original incident. This can all take place within hours of the incident. Not a bad timely response to the attack in my opinion.
Now that we have successfully transitioned into 2010 with our skin intact I want to once again return to the subject of our PII, those who wish to have their way with it, and the hapless aggregators and keepers with file cabinets and servers chock full of it. To that end I have included links to a couple of things to ponder in these first few days of the year.
Navy's InfoSec Chief Suffers Sixth Breach The Navy's Chief Information Officer Robert Carey recently received notification of a compromise of his personally identifiable information (PII), reports govinfosecurity.com. For Carey, it was the sixth such notification, and came from the Army--where he hasn't worked in 24 years. Carey used the event to describe his philosophy on data protection and enumerate a seven-point summary of his department's efforts to reduce the risk of a breach within the Department of the Navy. "In today's Information Age, PII must be treated with extreme care because unauthorized access to someone's digital identity can and does cause grave consequences," Carey wrote.
Full Story
Three Breaches Compromise 30,000 at Penn State The Pittsburgh Post-Gazette reports that Penn State has begun the process of notifying nearly 30,000 individuals that their personally identifiable information (PII), including Social Security numbers, may have been compromised as a result of three separate malware infections discovered in late December. The school said it has no evidence that the individual or organization behind the malware gained access to the PII, but has decided to notify as a precautionary measure. "We do not have any indication that it was accessed by unauthorized parties. We prefer to err on the side of caution," said spokesperson Annemarie Mountz. The event was the second known breach at Penn State in 2009. Full Story
Does it occur to anyone that for as long as we have been entrusting our personal information to others they have been losing it, a lot? One of life's principals is that "Continuing to do the same things while hoping for different results" is a hopeless waste of time. If they continue to lose our personal information why then do we continue giving it to them without any sort of check and balance? Certainly all of the laws passed have not had any nulling effect, nor any of the so-called procedures and software "solutions". This is not a problem that we have to accept as a given that requires a highly technical or overly complex set of controls. This is a very basic condition that if we, as the actual owners of the prize were to take into our own hands, could quite well nip in the bud. Think about it. Do we all put our prized silver in a big building or a bunch of buildings and then hire people to guard it or do we keep our own at home and watch it our selves?
The examples above are not isolated cases unless you consider the US Navy and Penn State to be marginal. This is big time mainstream stuff.
I intend to take the balance of the year (two plus weeks) off from this column. In the meantime the link below is to a very good article written by a colleague, Julie Friend. I would encourage everyone to read this piece that shows how data loss and identity theft can have far reaching effects on individuals and businesses alike.
Someone recently told me that the release of those emails proved that the case for climate change was overstated. This individual was showing his ignorance of the realities of global weather changes. Similarly, I see a number of people who should know better who think that those of us who write and work in the field of data protection are overstating the case. I guarantee that not one single victim or breached business would agree with that. Ms. Friend and I along with many others have seen too many cases of devastating loss, arrest, character assassination, and records corruption to think for a moment that this is an overstated issue. If anything we have not reached enough people.
Originally published in Voluntary Benefits magazine Ms. Friend has graciously allowed me to provide this link for you.
Now is the time to start gearing up for compliance with the Bay State's strict new data protection regulations, reports the Boston Herald. The rules take effect in March. Businesses that ignore them "could be at risk," said Bob Baker of the Smaller Business Association of New England. The regulations are widely considered the strictest in the nation. They require entities that possess personal information on any Massachusetts resident to employ certain measures to protect that data. According to Barbara Anthony of the Massachusetts Office of Consumer Affairs, the goal of the law is to "create a culture of security consciousness with respect to the handling of personal information." Editor's note: Privacy Tracker subscribers, for a compliance guide on the Mass. data protection regulations, visit the Privacy Tracker Web site. Full Story
All covered businesses should follow these guidelines carefully. What will happen within the next 12 months is that this will become a federal set of regulations, and at that point there will be no time to argue over compliance and exemptions. Smart companies will put this sort of program in effect prior to that.
The author is a Certified Identity Theft Risk Management Specialist, and Associate of Pre-Paid Legal Services of Ada, Oklahoma.
Our main business is providing the world's Gold Standard in identity theft services and affordable access to private law firms for small businesses and individual families. My main focus however, is making these services available as an employee benefit. I am also engaged in assisting businesses to develop their identity theft prevention and response plans, and providing identity theft awareness training to these employee groups.
“Assisting a business in creating a culture of security, and making our services available to employees is simply the most satisfying work I have ever done. I feel as though I am truly contributing to the welfare and security of individual families and the companies they work for.”
Over the past 37 years Pre-Paid Legal Services has emerged as not only the pioneer but also the only nationwide public company to provide legal service plans. We also pioneered the field of identity theft services in 2003 with the Identity Theft ShieldSM, a fully comprehensive restoration service.