The Federal Trade Commission has announced in the Federal Register that it will conduct a wide-ranging study of identity theft victims in order to assess the current remedies available to them following the crime. Identity theft victims who have contacted the FTC between January 1 and May 30, 2008, will be asked about their experiences after contacting one or more credit reporting agencies and when they sought to use their FACT Act rights.
The FACT Act (Fair and Accurate Credit Transactions Act of 2003) gives consumers certain rights in dealing with identity theft, including the ability to place fraud alerts on their credit files if they are, or suspect they may become, victims of identity theft, to block information on their credit reports that resulted from identity theft, and obtain copies of their credit reports free of charge.
For the seventh year in a row, identity theft has been the top consumer fraud complaint handled by the FTC. The agency's recent report shows that of 813,899 total complaints received in 2007, 258,427 (32%) were related to identity theft. The monetary losses related to identity fraud totals more than $1.2 billion; the median monetary loss per person was $349. Not included in this is the time-value equivalent (for example, the hours spent on the phone with credit bureaus, creditors and police, or monitoring bank and credit accounts for fraudulent activity), which can be significant.
And it appears that even with data breach notification laws in place by nearly all of the states, it has not slowed the proliferation of identity theft. Part of this is attributed to consumers ignoring data breach notification letters. But in most instances, inadequate security practices by companies handling sensitive data are the culprit.
The deadline for submitting comments is Sept. 2, 2008. Comments filed in electronic form should be submitted at: https://secure.commentworks.com/ftcfactasurvey. To ensure that the Commission considers an electronic comment, you must file it on the web-based form.
*** Remember: If you had any type of loan account between January 1987 and May 28, 2008, you are entitled to learn your credit score – free of charge – and get at least six months of a monitoring service from credit reporting giant TransUnion. The monitoring service would provide e-mail notification of late payment reports or accounts opened in your name – red flags that would indicate identity theft. You can file a claim by visiting http://www.listclassaction.com/ or calling 866-416-3470.
Showing posts with label fraud alert. Show all posts
Showing posts with label fraud alert. Show all posts
Thursday, July 3, 2008
Tuesday, June 10, 2008
There's No Substitute for Checking Your Bank Accounts
Fraud alerts can only do so much to protect you.
A recent identity theft victim discovered that fraud alerts -- while very helpful in guarding against thieves who try to obtain credit in the victim's name -- don't protect the victim 100% against financial losses.
Meet Patrick Grant. Patrick is a professor at the University of Virginia. According to a story in The Richmond-Times Dispatch, Patrick knew something was amiss when he found three letters in his mailbox that stated they would not raise his credit limit -- because he had never requested it. According to the report:
"Identity thieves in New York had opened a checking and savings account in Grant's name, aided by his Social Security number and a fake New York driver's license with his name on it. Using an online banking feature of the fraudulent checking account, the thieves hijacked Grant's existing Bank of America credit-card account... They drained Grant's credit-card account by authorizing cash-advance payments, which they then withdrew from an ATM. Over the course of nine or 10 days, the thieves obtained $22,000 with Grant's credit card."
While Patrick is not positive how his identity was stolen -- his information had been compromised several times in university-related data breaches -- the first thing he did was purchase credit monitoring and place fraud alerts on his credit file. But the thieves didn't try to use his identity to open new lines of credit. Instead, they just tapped into his existing credit accounts.
In November 2007, the Federal Trade Commission reported that 3.7 percent of all American adults -- or 8.3 million people -- had their identity stolen in 2005. These thefts totaled an estimated $15.6 billion in losses. And the numbers are increasing.
It's a good reason to keep a close eye on what's going on with your bank accounts.
A recent identity theft victim discovered that fraud alerts -- while very helpful in guarding against thieves who try to obtain credit in the victim's name -- don't protect the victim 100% against financial losses.
Meet Patrick Grant. Patrick is a professor at the University of Virginia. According to a story in The Richmond-Times Dispatch, Patrick knew something was amiss when he found three letters in his mailbox that stated they would not raise his credit limit -- because he had never requested it. According to the report:
"Identity thieves in New York had opened a checking and savings account in Grant's name, aided by his Social Security number and a fake New York driver's license with his name on it. Using an online banking feature of the fraudulent checking account, the thieves hijacked Grant's existing Bank of America credit-card account... They drained Grant's credit-card account by authorizing cash-advance payments, which they then withdrew from an ATM. Over the course of nine or 10 days, the thieves obtained $22,000 with Grant's credit card."
While Patrick is not positive how his identity was stolen -- his information had been compromised several times in university-related data breaches -- the first thing he did was purchase credit monitoring and place fraud alerts on his credit file. But the thieves didn't try to use his identity to open new lines of credit. Instead, they just tapped into his existing credit accounts.
In November 2007, the Federal Trade Commission reported that 3.7 percent of all American adults -- or 8.3 million people -- had their identity stolen in 2005. These thefts totaled an estimated $15.6 billion in losses. And the numbers are increasing.
It's a good reason to keep a close eye on what's going on with your bank accounts.
Wednesday, March 19, 2008
Sweetbay Supermarket Latest Data Breach Victim
Another day, another data breach. This one affects more than 4 million Sweetbay/Hannaford customers in New England, New York and Florida who used their credit or debit cards between Dec. 7, 2007 and March 10, 2008.
The breach was discovered in late February when a payment card clearinghouse notified Hannaford of an unusual number of payment card transactions. Hannaford transmits its data over phone lines and uses encrypted wireless communications to transmit numbers inside its stores. The hackers snatched the credit/debit card data sometime between when the customers swiped their cards in the reader at the register and when those transactions were approved.
According to news reports, Hannford's security measures met industry standards with regard to how data is stored and maintained (unlike the TJX breach, which was blamed on lax security). Experts are anticipating that this may be just the first of many cases to surface this year wherein the affected retailer was hacked even though it appeared to be following all of the security rules laid out by the credit card associations.
Cybertrust's Bryan Sartin said,
Each of you should be regularly reviewing your financial institution and credit card statements, and immediately contacting your credit card company or issuing bank with any questions or concerns about individual charges. If you are concerned that your credit/debit card data has been compromised, you may file a fraud alert on your credit report by calling one (just one) of the three major credit bureaus:
Equifax: 1-800-525-6285
Experian: 1-888-397-3742
TransUnion: 1-800-680-7289
The fraud alert is good for 90 days. Once you place a fraud alert on your credit report, you will receive information via mail about ordering one free credit report from each of the companies. You may want to wait a month before ordering the report as it may take some time for suspicious activity to appear on the report.
The breach was discovered in late February when a payment card clearinghouse notified Hannaford of an unusual number of payment card transactions. Hannaford transmits its data over phone lines and uses encrypted wireless communications to transmit numbers inside its stores. The hackers snatched the credit/debit card data sometime between when the customers swiped their cards in the reader at the register and when those transactions were approved.
According to news reports, Hannford's security measures met industry standards with regard to how data is stored and maintained (unlike the TJX breach, which was blamed on lax security). Experts are anticipating that this may be just the first of many cases to surface this year wherein the affected retailer was hacked even though it appeared to be following all of the security rules laid out by the credit card associations.
Cybertrust's Bryan Sartin said,
"[We have] found with a number of very recent compromises that attackers have seized control over the very terminals that control cash registers or point-of-sale systems within a retail store, or the server through which all registers connect to pass transaction data out across the Internet to the store's payment processor." Once these systems have been compromised, the attackers typically eavesdrop on the network using "sniffer" programs that can extract credit and debit card data as it moves across the wire, before it even leaves the store's network.Kevin Mandia, president of Mandiant Corp., a company that specializes in investigating data breaches, said, "We're seeing at least two new companies a week discovering that they've lost credit card numbers, and at the rate we're going [the criminals] are going to exhaust U.S. retailers as targets.."
To date, about 2,000 cases of fraud have been reported in the Hannaford/Sweetbay breach. The company is asking that consumers contact them with questions or information about their data being used fraudently at 866-591-4580.
Each of you should be regularly reviewing your financial institution and credit card statements, and immediately contacting your credit card company or issuing bank with any questions or concerns about individual charges. If you are concerned that your credit/debit card data has been compromised, you may file a fraud alert on your credit report by calling one (just one) of the three major credit bureaus:
Equifax: 1-800-525-6285
Experian: 1-888-397-3742
TransUnion: 1-800-680-7289
The fraud alert is good for 90 days. Once you place a fraud alert on your credit report, you will receive information via mail about ordering one free credit report from each of the companies. You may want to wait a month before ordering the report as it may take some time for suspicious activity to appear on the report.
Labels:
data breach,
fraud alert,
Hannaford,
identity theft,
Sweetbay
Thursday, February 21, 2008
Experian Sues LifeLock
Experian is really mad at Todd Davis.
You may not know Todd Davis, but you probably have seen his Social Security number plastered all over magazines, newspapers, television - even wrapped around public buses. (457-55-5462)
Davis is the CEO of LifeLock, a company that focuses on identity theft prevention. Their advertising has been hugely successful, with 700,000 customers each paying $10 per month for the service.
The service essentially consists of continuous fraud alerts being placed on your credit report, to be renewed automatically every 90 days. LifeLock's services also include stopping junk mail and the mailing of pre-approved credit card offers, and a copy of their credit report. The company offers a $1 million guarantee that it will help restore customers’ credit reports if they suffer an identity theft.
Experian says that LifeLock's practices are costing them "millions of dollars." Some of this is due to the thousands of calls funneling through various phone banks from LifeLock, resulting in "excessive phone charges." And, since the credit bureaus make a lot of money by selling consumer data to potential creditors, fraud alerts drastically limit their revenue capabilities.
The Lawsuit
Experian contends that the placing of continuous fraud alerts is illegal - that the Fair Credit Reporting Act only allows the consumer or a person acting on behalf of the consumer to place fraud alerts - and that LifeLock is intentionally deceiving the bureaus by posing as customers.
Experian also says that the fraud alerts can only be placed when the consumer believes that fraudulent activities are imminent, and not just for anyone who wants one.
Pot, Meet Kettle
Experian is bent out of shape that LifeLock would charge consumers a fee to do what they can do legally for free. For example:
With credit monitoring as the centerpiece of Experian's freecreditreport.com service, it's easy to see why Experian is attacking its new competitor.
The Truth Is....
Experian, no stranger to misleading and deceptive advertising, also claims that LifeLock is engaging in misrepresenting the effectiveness of its service. In one ad, LifeLock says, "You’ll find out how to lock down your identity, making it virtually impossible for identity thieves to wreak havoc on your good name."
Fraud alerts, however, don't prevent fraud from happening. It simply makes it harder for identity thieves to open up credit in your name. If an identity thief already has your credit card or Social Security number, a fraud alert won't stop the misuse of those items. Even Davis admitted in an interview that if an undocumented worker is using your Social Security number to obtain employment (a very common form of identity theft), there isn't much that LifeLock can do to stop it.
Is Your Grocer A Crook?
Beyond the legal issues Experian is jawing about, the hot issue seems to be whether LifeLock is a scam for charging consumers to do things they can do themselves for free, or if they simply are providing a convenience at a low monthly cost. LifeLock customers appear to be happy with the service. Yes, you can do these things for free. LifeLock clearly states this on their Web site. But every day, we pay for convenience. After all, you could grow your own food - does this make your grocer a crook?
More and more, people are finding that dealing with the Big 3 is a time-wasting hassle. If you don't want to pay for the service, you've now got the tools to do it yourself. If you want someone else to do it for you, $10 a month is not unreasonable.
One thing to be aware of: Experian states in its lawsuit that LifeLock uses annualcreditreport.com to order the customer's credit report. Customers who are unaware of this practice may try to use their once-a-year benefit and get turned down because LifeLock has already tapped the free report for the year.
You may not know Todd Davis, but you probably have seen his Social Security number plastered all over magazines, newspapers, television - even wrapped around public buses. (457-55-5462)
Davis is the CEO of LifeLock, a company that focuses on identity theft prevention. Their advertising has been hugely successful, with 700,000 customers each paying $10 per month for the service.
The service essentially consists of continuous fraud alerts being placed on your credit report, to be renewed automatically every 90 days. LifeLock's services also include stopping junk mail and the mailing of pre-approved credit card offers, and a copy of their credit report. The company offers a $1 million guarantee that it will help restore customers’ credit reports if they suffer an identity theft.
Experian says that LifeLock's practices are costing them "millions of dollars." Some of this is due to the thousands of calls funneling through various phone banks from LifeLock, resulting in "excessive phone charges." And, since the credit bureaus make a lot of money by selling consumer data to potential creditors, fraud alerts drastically limit their revenue capabilities.
The Lawsuit
Experian contends that the placing of continuous fraud alerts is illegal - that the Fair Credit Reporting Act only allows the consumer or a person acting on behalf of the consumer to place fraud alerts - and that LifeLock is intentionally deceiving the bureaus by posing as customers.
Experian also says that the fraud alerts can only be placed when the consumer believes that fraudulent activities are imminent, and not just for anyone who wants one.
Pot, Meet Kettle
Experian is bent out of shape that LifeLock would charge consumers a fee to do what they can do legally for free. For example:
- You can call any of the Big 3 credit bureaus to request an initial fraud alert if you suspect that you have been, or are about to be, a victim of identity theft. Once the alert is in place, potential creditors must use "reasonable policies and procedures" to verify your identity before issuing credit in your name. You do not need to call each of the three credit bureaus - they are required to report this to the other bureaus.
- In addition, when you place an initial fraud alert on your credit report, you can order one free credit report from each of the three nationwide consumer reporting agencies. You also can request that only the last four digits of your Social Security number appear on your credit report. You also can order a free credit report from annualcreditreport.com.
- You can stop junk mail and remove yourself from pre-screened offers by visiting http://www.optoutprescreen.com/ or call toll-free to 1-888-567-8688. You can choose to opt-out of offers for five years or permanently. (You also can add yourself back onto the list.)
With credit monitoring as the centerpiece of Experian's freecreditreport.com service, it's easy to see why Experian is attacking its new competitor.
The Truth Is....
Experian, no stranger to misleading and deceptive advertising, also claims that LifeLock is engaging in misrepresenting the effectiveness of its service. In one ad, LifeLock says, "You’ll find out how to lock down your identity, making it virtually impossible for identity thieves to wreak havoc on your good name."
Fraud alerts, however, don't prevent fraud from happening. It simply makes it harder for identity thieves to open up credit in your name. If an identity thief already has your credit card or Social Security number, a fraud alert won't stop the misuse of those items. Even Davis admitted in an interview that if an undocumented worker is using your Social Security number to obtain employment (a very common form of identity theft), there isn't much that LifeLock can do to stop it.
Is Your Grocer A Crook?
Beyond the legal issues Experian is jawing about, the hot issue seems to be whether LifeLock is a scam for charging consumers to do things they can do themselves for free, or if they simply are providing a convenience at a low monthly cost. LifeLock customers appear to be happy with the service. Yes, you can do these things for free. LifeLock clearly states this on their Web site. But every day, we pay for convenience. After all, you could grow your own food - does this make your grocer a crook?
More and more, people are finding that dealing with the Big 3 is a time-wasting hassle. If you don't want to pay for the service, you've now got the tools to do it yourself. If you want someone else to do it for you, $10 a month is not unreasonable.
One thing to be aware of: Experian states in its lawsuit that LifeLock uses annualcreditreport.com to order the customer's credit report. Customers who are unaware of this practice may try to use their once-a-year benefit and get turned down because LifeLock has already tapped the free report for the year.
Subscribe to:
Posts (Atom)