Showing posts with label identity theft. Show all posts
Showing posts with label identity theft. Show all posts

Wednesday, January 21, 2009

Possibly the Biggest Credit Data Breach Ever?

A global cyber fraud operation is thought to be behind what may be the biggest credit data breach ever reported, eclipsing the 2007 TJX breach that compromised the data of 45 million customers.

The breach occurred on the internal computer network of Heartland Payment Systems, a major payment processing company that processes 100 million transactions each month from about 250,000 businesses nationwide.

How did this happen?
After a customer swipes a credit or debit card, the information is then transmitted to obtain authorization from a bank or payment company. During this brief transmission, the data is unencrypted. "Sniffer" software, which may have been installed on Heartland's network as far back as May 2008, captured card numbers, expiration dates, and some cardholder names and internal bank codes during this authorization period. Personal security codes are not believed to have been compromised.

What credit and debit cards are impacted?
Visa, MasterCard, Discover and American Express customers are vulnerable.

How many people could be affected?
An exact number of compromised customers is not available; however, according to a report in the New York Times, 600 million or more cardholders might be affected.

When was this breach discovered?
The breach was discovered last week by a forensic investigator following inquiries by Visa and MasterCard of suspicious activity surrounding processed card transactions.

What remedies do customers have?
Heartland has set up a Web site to provide updates to customers about the incident: www.2008breach.com. Cardholders are not responsible for unauthorized fraudulent charges made by third parties. The United States Secret Service and the Department of Justice are actively involved

Please review your credit card statements carefully each month for any charges that you don't recognize.

Tuesday, August 5, 2008

Identity Theft Alert: Anheuser-Busch Workers at Risk

If you work or have worked at Anheuser-Busch, your personal information (including Social Security number, addresses, date of birth, and more) may have been among those stolen when laptops disappeared from Anheuser-Busch's St. Louis headquarters in June.

Nationwide, about 150,000 people are affected; of those, 87,500 are in Florida.

If you have been affected, you are entitled to one year of free credit monitoring service.

Wednesday, July 23, 2008

Identity Theft Alert: Alaska Air Customers' Credit Cards Misused

If you bought tickets from Alaska or Horizon airlines, pay close attention to your credit card statements. (You should be doing this anyway, you know.)

About 1,500 customers have been notified that their credit cards were misused when a call center employee diverted some payments to a personal account.

The airlines' parent company is working with police to resolve the investigation and have stated that customers are not responsible for repaying the diversions that took place between August 2006 and June 2008.

Tuesday, July 8, 2008

Thieves Steal Gas With Stolen Sweetbay/Hannaford Customer Credit Cards

With gas prices floating over $4 a gallon and diesel approaching $5 a gallon, fuel is a valuable commodity that is attracting thieves along the East Coast.

The arrest of five Florida men who drove pickup trucks with hidden gas tanks that could hold up to 1,000 gallons of fuel brought to light a disturbing trend – the use of stolen credit card numbers to purchase excessive quantities of fuel at gas stations in several states. Murphy Oil, which runs Wal-Mart gas stations, reported losses of $1 million in one month as a result of similar gas thefts.

New cases involving the 4.2 million stolen credit and debit card numbers from the recent Hannaford/Sweetbay breach are being investigated as the crooks continue to try to convert the stolen numbers to cash.

If you used a credit or debit card at Sweetbay or Hannaford stores between Dec. 7 and March 10, keep a close eye on your bank or credit card statements and immediately challenge any purchases that are not yours.

Thursday, July 3, 2008

Are You a Recent Victim of Identity Theft? If So, the FTC Wants to Hear From You.

The Federal Trade Commission has announced in the Federal Register that it will conduct a wide-ranging study of identity theft victims in order to assess the current remedies available to them following the crime. Identity theft victims who have contacted the FTC between January 1 and May 30, 2008, will be asked about their experiences after contacting one or more credit reporting agencies and when they sought to use their FACT Act rights.

The FACT Act (Fair and Accurate Credit Transactions Act of 2003) gives consumers certain rights in dealing with identity theft, including the ability to place fraud alerts on their credit files if they are, or suspect they may become, victims of identity theft, to block information on their credit reports that resulted from identity theft, and obtain copies of their credit reports free of charge.

For the seventh year in a row, identity theft has been the top consumer fraud complaint handled by the FTC. The agency's recent report shows that of 813,899 total complaints received in 2007, 258,427 (32%) were related to identity theft. The monetary losses related to identity fraud totals more than $1.2 billion; the median monetary loss per person was $349. Not included in this is the time-value equivalent (for example, the hours spent on the phone with credit bureaus, creditors and police, or monitoring bank and credit accounts for fraudulent activity), which can be significant.

And it appears that even with data breach notification laws in place by nearly all of the states, it has not slowed the proliferation of identity theft. Part of this is attributed to consumers ignoring data breach notification letters. But in most instances, inadequate security practices by companies handling sensitive data are the culprit.

The deadline for submitting comments is Sept. 2, 2008. Comments filed in electronic form should be submitted at: https://secure.commentworks.com/ftcfactasurvey. To ensure that the Commission considers an electronic comment, you must file it on the web-based form.

*** Remember: If you had any type of loan account between January 1987 and May 28, 2008, you are entitled to learn your credit score – free of charge – and get at least six months of a monitoring service from credit reporting giant TransUnion. The monitoring service would provide e-mail notification of late payment reports or accounts opened in your name – red flags that would indicate identity theft. You can file a claim by visiting http://www.listclassaction.com/ or calling 866-416-3470.

Tuesday, June 17, 2008

First, Thieves Steal Identities. Now They Steal Homes.

The Chicago Tribune recently investigated an FBI report on new identity theft tactics being used by thieves to "steal" your home.

The report warns of several ways in which people have been conned out of their homes. While thieves generally target vacation homes or empty homes, the FBI has investigated sales of occupied houses. By law, as the rightful owner, you won't lose your house as long as you have proof that you are the legitimate owner. But it's likely to cause an enormous expenditure of time and money.

Among the cases being investigated by the FBI:
  • Con artists "stole" an occupied house and sold it to someone so enamored of the great price is getting that he's satisfied with online photos.
  • Thieves posed as the rightful owner and took out home equity lines of credit against the property, draining it slowly so it wouldn't be detected.
  • Thieves deposited proceeds from an illegal loan into a business account to get under the lender's radar.
  • Cons changed the title of a house to his name and sold the house.

All of the schemes involved using the owner's personal information to create fake IDs and Social Security cards so that the thief can file the papers to complete and/or transfer the property.

"In one case prosecuted by the feds, the ID thieves used the name-change mechanism offered to people who are getting married or divorced to obtain false driver's licenses, which they used to get Social Security numbers," the Tribune reported. In most cases, though, business records are the main source of private information theft.

A "red flag" rider to the Fair and Accurate Credit Transaction Act of 2003 was recently passed by Congress. This rider, which takes effect Nov. 1, 2008, requires any business that handles personal documents to develop a program to prevent ID theft. That includes financial institutions and creditors.

The guidelines say institutions should be on the lookout for actions such as:
  • ID theft alerts from fraud detection services, customers, law enforcement agencies and others
  • a credit bureau's notice of credit freeze provided to an institution along with the institution's requested consumer credit report
  • an increase in credit report inquiries or other unusual patterns on a credit report
    the appearance of doctored or forged documents
  • inconsistent information
  • identifying information associated with known fraudulent activity
  • use of a single Social Security Number or other identifying number used to open accounts under different names
  • applicants failing to provide all required identifying information
  • information supplied that is not consistent with existing information on file
  • a new revolving credit account used in a manner commonly associated with fraud patterns
  • an account used in a manner not consistent with established patterns of activity on the account
  • mail sent to the customer's on file address repeatedly returned as undeliverable.
Sigh. Yet another good reason to check your credit report regularly.

Tuesday, June 10, 2008

There's No Substitute for Checking Your Bank Accounts

Fraud alerts can only do so much to protect you.

A recent identity theft victim discovered that fraud alerts -- while very helpful in guarding against thieves who try to obtain credit in the victim's name -- don't protect the victim 100% against financial losses.

Meet Patrick Grant. Patrick is a professor at the University of Virginia. According to a story in The Richmond-Times Dispatch, Patrick knew something was amiss when he found three letters in his mailbox that stated they would not raise his credit limit -- because he had never requested it. According to the report:

"Identity thieves in New York had opened a checking and savings account in Grant's name, aided by his Social Security number and a fake New York driver's license with his name on it. Using an online banking feature of the fraudulent checking account, the thieves hijacked Grant's existing Bank of America credit-card account... They drained Grant's credit-card account by authorizing cash-advance payments, which they then withdrew from an ATM. Over the course of nine or 10 days, the thieves obtained $22,000 with Grant's credit card."

While Patrick is not positive how his identity was stolen -- his information had been compromised several times in university-related data breaches -- the first thing he did was purchase credit monitoring and place fraud alerts on his credit file. But the thieves didn't try to use his identity to open new lines of credit. Instead, they just tapped into his existing credit accounts.

In November 2007, the Federal Trade Commission reported that 3.7 percent of all American adults -- or 8.3 million people -- had their identity stolen in 2005. These thefts totaled an estimated $15.6 billion in losses. And the numbers are increasing.

It's a good reason to keep a close eye on what's going on with your bank accounts.

Thursday, May 22, 2008

Texas Man Successfully Uses LifeLock CEO's Identity to Get $500

From the annals of "I could have seen that coming" come reports that LifeLock CEO Todd Davis' widely publicized Social Security number has been successfully used by a man in Texas to trick an online payday lender into giving him $500. Davis learned about the fraud when the lender called him to collect.

This was not the first time people have tried to steal Davis' identity. According to a story today on Yahoo news, Davis reported that at least 87 unsuccessful attempts have been made. Of course, Davis pretty much asked for it by plastering his Social Security number on billboards, television ads and in print, practically daring would-be identity thieves and hackers to test his company's ability to prevent identity fraud.

LifeLock, already facing a lawsuit by credit bureau giant Experian, is now facing lawsuits from consumers in Maryland, West Virginia and New Jersey contending that the service did not work as promised. The lead attorney in these cases, David Paris, is trying to obtain class-action status, and claims he uncovered records of other people applying for or receiving driver's licenses at least 20 times using Davis' Social Security number.

Davis stands by his stunt. He told reporters, "There's nothing on my actual credit report about uncollected funds, no outstanding tickets or warrants or anything… There's nothing to indicate my identity has been successfully compromised other than the one instance. I know I'm taking a slightly higher risk. But I'll take my risk for the tremendous benefit we're bringing to society and to consumers."

LifeLock's services include helping consumers set up fraud alerts with the major credit bureaus, which inform them when someone tries to tap into their credit. The fraud in Texas occurred because the payday lender did not go through one of the three major credit bureaus before approving the transaction.

The services, however, can't completely immunize a consumer from identity theft. If a stolen Social Security number is used on a job application, on a form submitted for medical services or during an arrest, the lack of reporting requirements make it impossible for any company to know with certainty that someone's identity has been compromised.

That's not the end of LifeLock's headaches, however. The company is also being sued in Arizona over its $1 million service guarantee. The plaintiffs in the case claim that the guarantee is misleading because it only covers a defect in LifeLock's service.

The question that remains unanswered: when will tighter mechanisms be put in place to deter and report fraud?

Wednesday, May 21, 2008

Senate Passes "Common Sense Legislation" Regarding Credit Card Receipts

The Credit and Debit Receipt Clarification Act – a bill that says a business that printed an expiration date on a receipt over the past 18 months cannot be found in violation of the Fair Credit Reporting Act as long as the merchant truncated the customer's credit card to no more than the last five digits (and complied with other FCRA requirements) – has passed in the U.S. Senate.

The bill was sponsored as H.R. 4008 in the House by Financial Services Committee member Representative Tim Mahoney, D-Fla., and as S. 2978 in the Senate by Banking, Housing and Urban Affairs Committee member Senator Charles Schumer, D-N.Y.

The decision was hailed by businesses and restaurants and is expected to nullify the more than 300 class action lawsuits that contended that FACTA required merchants to both truncate the credit card number and leave off the expiration date. The lawsuits sought fines as high as $1,000 for each non-compliant receipt and were so potentially damaging that a number of retailers threatened to file bankruptcy. Plaintiffs did not need to demonstrate any real or actual damage caused by the violation or even that the companies had willful intent to cause harm.

Merchants said their interpretation of the law was that they needed to do one or the other, but were not mandated to do both. Most reasoned (and some experts concurred) that the expiration date was of little value without a full credit card number.

According to a release issued by the National Retail Federation and the National Council of Chain Restaurants, the new legislation would protect merchants from lawsuits for expiration dates printed between the time the FACTA rule went into effect and the time the measure is signed into law. But merchants will still be required to both truncate card numbers and leave off expiration dates going forward.

“The continued proliferation of these lawsuits is an unnecessary drain on resources during a time of financial uncertainty in the nation’s economy,” NCCR Vice President Scott Vinson said. “Experts have said truncation of credit card numbers by itself is sufficient to prevent credit card fraud or identity theft regardless of whether the expiration date is printed on a receipt. Retailers and restaurant owners nationwide are delighted that Congress has passed this common sense legislation and look forward to seeing it signed into law as soon as possible.”

President Bush is expected to sign the measure shortly.

Friday, April 25, 2008

LendingTree.com: "When Banks Compete, Your Identity May Be at Risk…"

LendingTree, an online leads company that purports to help consumers shop around for the best mortgage deals, recently admitted in a letter to customers that some of their former employees helped unauthorized mortgage lenders hack into their databases. Customer information collected between 2006 and 2008 – including personal data often used to conduct identity theft, such as name, address, Social Security number, income and employment information – was stolen.

While they say the information was merely used to market mortgage loans, not to commit identity theft, the fact remains that LendingTree's lax security measures contributed to a significant data breach that may very well increase the likelihood that their customers will become identity theft victims.

According to the letter, LendingTree did not disable the passwords of their former employees, some of whom shared the confidential login information with unauthorized lenders who then tapped into the databases to "access LendingTree's customer loan request forms."

LendingTree's Response

LendingTree would not confirm the number of customers affected, and is not offering much in the way of compensation or solutions. They recommended that their customers use their "free annual credit report" benefit to check their credit report for any suspicious activity and monitor their credit reports for the next 24 months.

LendingTree also has filed lawsuits against three small home loan companies based in California in connection with the data breach.

Criticism of LendingTree Practices

Much criticism has been leveled against the leads company for the way it conducts business. Some customers claim that when they selected to have four lenders review their application, LendingTree actually sent it to 10… or more.

Other consumers reported that they started the application process, but changed their minds mid-way. Yet LendingTree sold their incomplete applications – and they started getting bombarded with calls.

"I have worked for 2 big mortgage companies and a broker," wrote one mortgage broker. "I've learned that LendingTree not only sells your information to 2 or 3 lenders, they sell it to other small lenders and broker shops. And then after a while, they resell your information again so they can have continuous profit. If you ever applied with LendingTree, make sure that you have read the Terms & Agreement. They sell it to anyone that can possibly help you."

Some complained that they had so many inquiries generated on their credit reports that their credit score dropped by 60-100 points. Hard inquiries are inquiries where a potential lender is reviewing your credit because you've applied for credit with them. These include credit checks when you've applied for an auto loan, mortgage or credit card. Each of these types of credit checks count as a single inquiry. One exception occurs when you are "rate shopping". That's a smart thing to do, and your FICO score considers all inquiries within a 2 week period for an auto or mortgage as a single inquiry.

However, because LendingTree doesn't just sell information to a handful of lenders one time – they sell them repeatedly over a long period of time – this can, in fact, contribute to a decreased credit score.

Jackie Story – Are You Out There?

For four years, your Credit Mama has fielded phone calls from mortgage brokers and call centers all over the world looking for "Jackie Story." Apparently Jackie Story used to have my cell phone number. It didn't take long for me to figure out that she used LendingTree to apply for a mortgage or refinance. What did surprise me, though, was the sheer number of phone calls I received long after the first few rolled in.

At some point I finally started telling the callers that they had wasted their money by purchasing very old, very useless leads. I still wonder, though, if Jackie Story ever got that low interest rate she was looking for, and if her credit has been negatively impacted by all of the people who received her original application and tried to process it.

It's Not Just LendingTree

What many people don't know is that your information can also be purchased from the credit bureaus. "Trigger leads" – leads generated when you apply for a mortgage – plague mortgage brokers. When you apply for a mortgage, your phone number and address are sold by the credit bureaus to other mortgage companies. That's why many applicants begin receiving volumes of solicitations from companies they have never heard of.

Be wary of any lead company, such as LendingTree.com or LowerMyBills.com. And if you do not wish to receive pre-approved or pre-screened offers for credit or insurance, the Fair Credit Reporting Act allows you to "opt out" of receiving them. To opt-out, call toll free to 1-888-567-8688 or visit optoutprescreen.com.

Tuesday, April 8, 2008

Identity Theft Protection or Legal Extortion?

If you've ever examined your credit card receipts, you've probably noticed that your credit card number has been reduced to a series of Xs with no more than four or five digits visible, and no other identifying information, such as expiration date.

That is, unless you've shopped at Costco, FedEx Kinko's, Toys 'R Us, IKEA, StubHub, Coffee Bean Tea & Leaf, or Jewell Food Stores, eaten at big Burrito Group eateries such as Mad Mex, purchased flowers at 1-800-FLOWERS or watched a movie at AMC Theaters.

These companies, among many others, have been targeted with class action lawsuits for violating a 16-month federal law designed to protect consumers' credit card information. The Fair and Accurate Credit Transaction Act (FACTA) prohibits companies from printing more than five digits of a credit card number or the expiration date on receipts to reduce the threat of identity theft.

Lawsuits have been flooding the legal system as consumers strike back against what they say is flagrant unresponsiveness to the FACTA statute. More than 300 class actions have been filed since the law went into effect in December 2006.

At stake is the livelihood of businesses across the country, from big box retailers and restaurants to small businesses such as parking garages and newsstands. With every noncompliant receipt assessed at anywhere from $100 to $1,000, companies are facing potential damages in the billions of dollars. The lawsuits are so financially damaging that retailers are threatening to file bankruptcy.

At issue is the fact that the plaintiffs don't need to demonstrate any real or actual damage caused by the violation or even that the companies had willful intent to cause harm. All they need is a receipt to claim statutory damages because a company has "flouted the law." Warehouse-club giant Costco is liable for as much as $17 billion – 15 times the company's 2007 profit – despite the fact that there are no claims of actual harm.

"In 22 years, I have never had a plaintiff sit across the table from me and say, 'I have no damages. My identity hasn't been stolen. I'm just bringing this lawsuit because I can,'" said David Block, a lawyer with Jackson Lewis, in a recent Law.com article. "There's something inherently wrong with a lawsuit where the plaintiff has no injury."

Defense lawyers are characterizing the lawsuits as "legal extortion," since the defendants did not profit from the infraction and plaintiffs have not shown evidence of actual harm. And some judges are paying attention – 12 have refused to certify some of these cases as class actions.

Many companies facing massive damage claims are quietly settling. Earlier this year, a class action lawsuit against big Burrito Group eateries was settled for FACTA violations. According to the settlement, customers who used a credit or debit card at various times at various big Burrito Group eateries last year are entitled to a $7 "settlement relief card." The cards can be used only at the company's Mad Mex restaurants under various restrictions. The settlement also calls for the company to pay for $105,000 in legal fees. Coffee Bean Tea & Leaf agreed to give customers free drinks and pay plaintiffs' lawyer fees. StubHub settled for undisclosed terms.

Should companies be compliant with the law? Heck yes. Should they be punished to the full extent of the law? Well, that depends. Bankrupting businesses or imposing maximum financial penalties will ultimately have a lasting negative impact on the quality and price of retail and online services. What price are we willing to pay to punish companies that were slow to comply with the law?

Wednesday, March 19, 2008

Sweetbay Supermarket Latest Data Breach Victim

Another day, another data breach. This one affects more than 4 million Sweetbay/Hannaford customers in New England, New York and Florida who used their credit or debit cards between Dec. 7, 2007 and March 10, 2008.

The breach was discovered in late February when a payment card clearinghouse notified Hannaford of an unusual number of payment card transactions. Hannaford transmits its data over phone lines and uses encrypted wireless communications to transmit numbers inside its stores. The hackers snatched the credit/debit card data sometime between when the customers swiped their cards in the reader at the register and when those transactions were approved.

According to news reports, Hannford's security measures met industry standards with regard to how data is stored and maintained (unlike the TJX breach, which was blamed on lax security). Experts are anticipating that this may be just the first of many cases to surface this year wherein the affected retailer was hacked even though it appeared to be following all of the security rules laid out by the credit card associations.

Cybertrust's Bryan Sartin said,

"[We have] found with a number of very recent compromises that attackers have seized control over the very terminals that control cash registers or point-of-sale systems within a retail store, or the server through which all registers connect to pass transaction data out across the Internet to the store's payment processor." Once these systems have been compromised, the attackers typically eavesdrop on the network using "sniffer" programs that can extract credit and debit card data as it moves across the wire, before it even leaves the store's network.
Kevin Mandia, president of Mandiant Corp., a company that specializes in investigating data breaches, said, "We're seeing at least two new companies a week discovering that they've lost credit card numbers, and at the rate we're going [the criminals] are going to exhaust U.S. retailers as targets.."

To date, about 2,000 cases of fraud have been reported in the Hannaford/Sweetbay breach. The company is asking that consumers contact them with questions or information about their data being used fraudently at 866-591-4580.

Each of you should be regularly reviewing your financial institution and credit card statements, and immediately contacting your credit card company or issuing bank with any questions or concerns about individual charges. If you are concerned that your credit/debit card data has been compromised, you may file a fraud alert on your credit report by calling one (just one) of the three major credit bureaus:

Equifax: 1-800-525-6285
Experian: 1-888-397-3742
TransUnion: 1-800-680-7289

The fraud alert is good for 90 days. Once you place a fraud alert on your credit report, you will receive information via mail about ordering one free credit report from each of the companies. You may want to wait a month before ordering the report as it may take some time for suspicious activity to appear on the report.

Thursday, March 13, 2008

Another Victim of the Housing Market Meltdown: Your Privacy

During the recent housing bubble, millions of Americans purchased or refinanced their homes with mortgage lenders throughout the country. With the implosion of the housing market, many of these mortgage shops closed their doors permanently.

It probably occurred to very few applicants that their files -- loaded with all kinds of personal data, from Social Security numbers and bank statements to tax returns, retirement accounts and credit reports -- would ever be in danger. Yet the records of thousands have been compromised - and not from a gang of thieves breaking into these offices. It seems that once the business is shut down, some mortgage lenders are simply disposing of all these paper records in public dumpsters. According to MSNBC:
  • First Magnus Financial Corp., one of the nation’s largest mortgage lenders whose headquarters was one of the biggest employers in Tucson, Ariz., threw away thousands of mortgage loan records in an unlocked trash dumpster in Ft. Lauderdale, Fla.

  • The records of hundreds of former customers of the defunct Alpha Mortgage Services were left in a recycling bin behind a grocery store in Toledo.

  • After Union Mortgage Services of Ohio shut down last month, confidential files on hundreds of people were thrown out in a dumpster behind a pizza shop in Cleveland.

  • American United Mortgage Co. of Northbrook, Ill., left hundreds of borrowers’ financial documents in an unlocked dumpster, many of them in open trash bags.

  • Sheriff’s deputies in DeKalb County, Ga., outside Atlanta, found the mortgage records of at least 1,200 former customers of Ameriquest Mortgage Co. in a dumpster behind an apartment complex in October, two years after the company, once one of the nation’s biggest subprime lenders, went out of business.

  • In Honolulu last year, a handyman hired by the former president of the defunct Fidelity Escrow Services dumped 39 boxes of financial records in a recycling bin.
While the Fair and Accurate Credit Transactions Act, or FACTA, requires businesses to dispose of sensitive financial documents in a way that protects against “unauthorized access to or use of the information,” it doesn't actually require the physical destruction of the data. To date, only one case has been brought against a company by the FTC (American United Mortgage was fined $50,000 after continuing to violate FACTA after receiving a warning). The challenge is pursuing action against companies that no longer exist.

The breaches leave thousands of consumers at risk for identity theft. For former customers of now-defunct lenders, there isn't much recourse. The best safeguard is vigilant monitoring of your credit report.

Tuesday, March 4, 2008

Attention TJ Maxx and Marshall's Shoppers!

If you made purchases or returned items at TJX Cos. such as T.J. Maxx, Marshalls, HomeGoods, A.J. Wright, Winners and HomeSense, you may be entitled to compensation.

Notices are just now beginning to go out to millions of customers who may have been affected by the largest data breach in history. Last year, TJX disclosed that information from nearly 46 million debit and credit cards was stolen by hackers, and that nearly a half million people who returned items without their receipts may have had personal data (such as driver's license numbers) stolen. Court filings by banks that are suing TJX indicate a much bigger breach, saying that more than 100 million cards may have been compromised.

The breach is believed to have begun in mid-2005 but wasn't detected until December 2006. The stolen information covers transactions dating as far back as December 2002.

Customers who believe their personal financial data was stolen or put at risk, and believe they were harmed, can join the class action lawsuit. They can send in a claim form to ask for benefits if they are eligble, ask to be excluded from the settlement (if they provide notice by June 24) or object to the terms.

Terms of the proposed settlement

TJX will offer vouchers to customers who show they shopped at TJX stores in the U.S., Canada and Puerto Rico — except Bob's Stores — during the breach and incurred costs.

TJX also will provide three years of credit monitoring and identity theft insurance to certain customers who returned merchandise without a receipt and were sent letters notifying them that their driver's license or other identification information may have been compromised.

For more information, call toll-free to 1-866-523-6770 or visit http://www.tjxsettlement.com/.


Thursday, February 21, 2008

Experian Sues LifeLock

Experian is really mad at Todd Davis.

You may not know Todd Davis, but you probably have seen his Social Security number plastered all over magazines, newspapers, television - even wrapped around public buses. (457-55-5462)

Davis is the CEO of LifeLock, a company that focuses on identity theft prevention. Their advertising has been hugely successful, with 700,000 customers each paying $10 per month for the service.

The service essentially consists of continuous fraud alerts being placed on your credit report, to be renewed automatically every 90 days. LifeLock's services also include stopping junk mail and the mailing of pre-approved credit card offers, and a copy of their credit report. The company offers a $1 million guarantee that it will help restore customers’ credit reports if they suffer an identity theft.

Experian says that LifeLock's practices are costing them "millions of dollars." Some of this is due to the thousands of calls funneling through various phone banks from LifeLock, resulting in "excessive phone charges." And, since the credit bureaus make a lot of money by selling consumer data to potential creditors, fraud alerts drastically limit their revenue capabilities.

The Lawsuit

Experian contends that the placing of continuous fraud alerts is illegal - that the Fair Credit Reporting Act only allows the consumer or a person acting on behalf of the consumer to place fraud alerts - and that LifeLock is intentionally deceiving the bureaus by posing as customers.

Experian also says that the fraud alerts can only be placed when the consumer believes that fraudulent activities are imminent, and not just for anyone who wants one.

Pot, Meet Kettle

Experian is bent out of shape that LifeLock would charge consumers a fee to do what they can do legally for free. For example:

  • You can call any of the Big 3 credit bureaus to request an initial fraud alert if you suspect that you have been, or are about to be, a victim of identity theft. Once the alert is in place, potential creditors must use "reasonable policies and procedures" to verify your identity before issuing credit in your name. You do not need to call each of the three credit bureaus - they are required to report this to the other bureaus.
  • In addition, when you place an initial fraud alert on your credit report, you can order one free credit report from each of the three nationwide consumer reporting agencies. You also can request that only the last four digits of your Social Security number appear on your credit report. You also can order a free credit report from annualcreditreport.com.
  • You can stop junk mail and remove yourself from pre-screened offers by visiting http://www.optoutprescreen.com/ or call toll-free to 1-888-567-8688. You can choose to opt-out of offers for five years or permanently. (You also can add yourself back onto the list.)
Experian really has no room to talk, having been the target of criticism that it charges customers for a service that is free through its freecreditreport.com site. The FTC has expressed concern that the site could be confused with annualcreditreport.com, which is the only site mandated by federal law that permits consumers to obtain a credit report for free each year.

With credit monitoring as the centerpiece of Experian's freecreditreport.com service, it's easy to see why Experian is attacking its new competitor.

The Truth Is....

Experian, no stranger to misleading and deceptive advertising, also claims that LifeLock is engaging in misrepresenting the effectiveness of its service. In one ad, LifeLock says, "You’ll find out how to lock down your identity, making it virtually impossible for identity thieves to wreak havoc on your good name."

Fraud alerts, however, don't prevent fraud from happening. It simply makes it harder for identity thieves to open up credit in your name. If an identity thief already has your credit card or Social Security number, a fraud alert won't stop the misuse of those items. Even Davis admitted in an interview that if an undocumented worker is using your Social Security number to obtain employment (a very common form of identity theft), there isn't much that LifeLock can do to stop it.

Is Your Grocer A Crook?

Beyond the legal issues Experian is jawing about, the hot issue seems to be whether LifeLock is a scam for charging consumers to do things they can do themselves for free, or if they simply are providing a convenience at a low monthly cost. LifeLock customers appear to be happy with the service. Yes, you can do these things for free. LifeLock clearly states this on their Web site. But every day, we pay for convenience. After all, you could grow your own food - does this make your grocer a crook?

More and more, people are finding that dealing with the Big 3 is a time-wasting hassle. If you don't want to pay for the service, you've now got the tools to do it yourself. If you want someone else to do it for you, $10 a month is not unreasonable.

One thing to be aware of: Experian states in its lawsuit that LifeLock uses annualcreditreport.com to order the customer's credit report. Customers who are unaware of this practice may try to use their once-a-year benefit and get turned down because LifeLock has already tapped the free report for the year.

Friday, February 15, 2008

Debit Card Traps - Part I

According to a recent article in Reader's Digest, debit cards have replaced credit cards as the "plastic of choice," with debit cards used for 33 percent of in-store transactions compared to 19 percent with credit cards. That number is expected to jump to more than 50 percent in the next three years.

The increase in the use of debit cards has translated into an increase in debit card fraud. In 2007, hundreds of visitors to a national chain restaurant in Sioux City, Iowa, learned that thieves had stolen their debit card numbers by swiping them through a "skimmer" device, and made cloned cards. These cloned cards were then used to make purchases in California and Mexico. This came on the heels of the massive data breach reported by TJX Companies.

One of the biggest misconceptions about debit cards is that they offer the same protection against fraud as credit cards... probably because they both have the familiar Visa or Mastercard logo stamped on the front of the card.

When you make a purchase with a credit card, and the service or product is not delivered or is not what was promised, you can dispute the charge with your credit card company. Under the terms of the federal Fair Credit Billing Act, the credit card company must remove the charge while it investigates your dispute.

There is no such grace period with debit cards. Once the money is pulled out of your account, it's gone - and under the terms of the Electronic Fund Transfer Act, the issuer of your debit card is not legally required to investigate or help you with your dispute.

While federal law generally limits your liability on both credit and debit cards to $50 provided you report the crime within two days of receiving your statement, recouping your cash is not a sure thing. And if you fail to notice the suspicious activity right away, you may be liable for up to $500 or more.

How to Protect Yourself
  • Don't ever hand over your debit card at a place where they process the card out of your sight, such as a restaurant.
  • Don't use debit cards for online purchases or big-ticket items.
  • If a store's card reader prompts for your PIN, override the sale by pressing Credit/Other or ask the cashier to process the transaction as credit.
  • Gas stations are notorious for being "hot spots" for skimming. If you must use a debit card at a gas station, use your PIN and don't let the card out of your hand.
  • Take advantage of your bank's online banking system and check your statements frequently.

Thursday, January 31, 2008

Tricky Thieves Preparing for Tax Refund Heists

Seems that identity thieves are quite entrepreneurial these days. With tax filing season underway, and with some type of economic stimulus package sure to be approved - which would send rebate checks to most U.S. households in May and June of this year - scammers are already attempting to trick people into divulging their personal and financial information.

Among the new scams:

The Rebate Phone Call: Posing as an IRS employee, scammers are calling people and advising them that they are due for a large refund if they file their taxes early. The catch: they can only get the refund by direct deposit - if they don't disclose their bank account information, they don't get the rebate. But the IRS doesn't gather bank routing and account numbers by telephone. And, the IRS doesn't provide advance payments to taxpayers.

The Refund e-Mail: Scammers are sending bogus e-mails to people that appear to come from the IRS. Recipients are advised they are eligible for a tax refund and instructed to click on a link to complete a claim form that asks for personal and financial data. Another version of this scam targets tax-exempt organizations. The IRS does NOT send unsolicited e-mails, and there is only one way to apply for a tax refund - by filing a tax return.

The Audit e-Mail: Some people are receiving personalized e-mail notices that their tax returns are being audited. They are instructed to click on a link to a form that captures personal information. Unlike most spam mails, this one often incorporates the recipient's name. But if you're really being audited, the IRS won't notify you by e-mail.

The Changes to Tax Law e-Mail: Businesses, accountants and "treasury" managers are the targets of this scam, which instructs recipients to download information on tax law changes by clicking on a series of links to various IRS publications. But the links are bogus. What the user downloads is not tax law updates, but malware, which infects computers and sends personal information back to the scammer or allows the scammer remote access to the files on the computer. If you want to download IRS publications, visit www.irs.gov.

The Paper Check Phone Call: Scammers posing as IRS employees are calling people to let them know that the paper check they received from the IRS was not cashed, and they need to confirm the individual's bank account number. But the IRS doesn't really care if you cash your check or not, and won't contact taxpayers to verify any bank information that was provided.

If you get a questionable e-mail:

  • Forward it to phishing@irs.gov
  • Visit www.irs.gov and enter search for additional information by typing in "suspicious e-mails", "phishing", "identity theft", or "e-mail scams" into the search box at the top right corner of the page.

Friday, January 25, 2008

Did You Really Think Your Salary Was Confidential?

In every place I've worked, my paycheck was always delivered in packaging that defied wandering eyes... usually requiring the removal of three separate tear-off strips, a battle with a letter opener, and sometimes even a paper cut or two.

But like any other piece of identifying data that could be possibly be collected and sold for a profit, your salary information is a commodity. Each payday, The Work Number, a product of Equifax, collects, stores and re-sells salary data and job titles on 46 million Americans - one-third of the workforce.

If you've worked for Fortune 500 companies like American Airlines, Boeing, Cisco, Coca Cola, Fed Ex, Ford Motor, GE, Hewlett Packard, Intel, Kmart, Lockheed Martin, Marriott, Microsoft, Motorola, Nokia, Pepsi, Sony, Visa, Wal Mart, Westinghouse, or government employers like the Department of Defense, U.S. Department of Energy, The Coast Guard, State of California, State of Missouri, or the cities of Detroit, Fort Worth and Pasadena sometime during the last 10 years, you're in the database.

There are currently more than 1,700 employers contributing data. The Work Number has 165 million employment records for current and former employees on file. The data, which also includes Social Security numbers, is sold to lenders, employers, landlords, and government-sponsored social service programs (such as food stamps) that want to conduct background checks or verify incomes.

The Work Number claims that problems with the data are rare: just 150 disputes a month (compared with 1.1 million verifications) because the data is automatically updated by the employers each time a paycheck is issued.

If you have been denied a job or loan because of the data provided by this service, the company that bought the report is required by law to notify you. In order to be compliant with the federal Fair Credit Reporting Act (FCRA), consumers are allowed to review and dispute information in The Work Number's database.

With identity theft issues making headlines on a regular basis, some privacy experts view this collection of data as a troubling issue. According to Elizabeth De Armond, an expert on privacy law and assistant professor at Chicago-Kent College of Law, "Any collection of personally identifying information like that leads to the high potential for identity theft. It's sensitive data."

Your Credit Mama agrees... this is just one more reason to check your credit reports regularly!

Tuesday, January 22, 2008

Will the Doctor Still See You After Looking at Your Credit?

Every 30 seconds in the United States, someone files for bankruptcy in the aftermath of a serious health problem. According to a Harvard study, illness and medical bills are the cause of half the personal bankruptcies filed in U.S. An estimated one million Americans are financially ruined by illness or medical bills each year - more than half of them are college educated, homeowners, with good jobs. Surprisingly, more than 75% were insured at the start of the bankrupting illness.

Now I'm going to throw another number at you: 80 percent. That's the number of hospital bills that contain multiple errors, according to the Medical Billing Advocates of America.

Here's one final stat: 250,000. That's the number of medical identity theft victims reported to the FTC each year.

Now there is talk of a medical FICO score being developed by a company called Healthcare Analytics. Like your credit score, which calculates the level of risk via algorithms and the consumers' credit history, the medical FICO score calculates which patients are more likely to pay their medical bills. Healthcare Analytics is already gathering payment information from large hospitals around the country.

Supposedly the benefit of a patient scoring system is to help hospitals decide whether to write off some delinquent bills as charity cases rather than report them as delinquent accounts. According to msbnc.com, American hospitals face $40 billion in unpaid bills every year.

But with so many people already uninsured (47 million in 2007), and with out-of-pocket costs rising, and two million people filing bankruptcy each year due to medically-related issues, this medFICO is a serious concern for consumers and privacy advocates.

Add to that the frustrations of inaccurate billing, and you've got the same headaches as with the credit bureaus - who also have a dismal 79% error rate (nearly 8 out of 10 credit reports contain serious errors).

Will the doctor or hospital decide not to perform certain services or provide inferior care (ie: reducing the length of stay) after looking at a patient's medFICO score? Will an employer decide not to hire someone because they are too expensive to insure? They SAY these things won't happen, but the risk assessment industry is too lucrative for this information NOT to be used in other ways.

Who is Healthcare Analytics? The investors include Fair Issac Corp. (founder of the FICO scoring model) and Tenet Healthcare Corp., one of the nation's biggest hospital operators. Former Tenet CFO Stephen Farber is its CEO.

The product is not expected to launch commercially until the end of this year.

Don't ever give your SSN to a healthcare provider. They do not need it. They need your member number from insurance, not your SSN. Furthermore, it's illegal for them to ask for your SSN unless they are going to lend you money or hire you.

Friday, January 18, 2008

650,000 Affected in Latest Credit Data Breach

In yet another case of sensitive data becoming MIA (missing in action), the personal information of 650,000 people, including names, addresses, account numbers, Social Security numbers, and other information, was comprised when GE Money Americas and its backup storage vendor, Iron Mountain, lost an unencryted backup tape.

The backup tape contained data on customers for JC Penney and up to 100 other retail store customers.

GE Money alerted the New Hampshire Attorney General's office of this security breach on Dec. 28, 2007. According to their notice, the tape was checked into Iron Mountain's secure facility and never checked out, but a search of Iron Mountain's premises and theirs has been unable to locate it.

It is hard to assess if the information on the missing tape is being used inappropriately or whether it will be misused in the future. GE Money is offering 12 months of credit monitoring for those persons that had Social Security numbers on the lost tape.

As anyone familiar with the TJ Maxx data breach knows, 12 months is a short blip in the lifespan of sensitive personal data like Social Security numbers. It becomes the consumer's burden to regularly and consistently check his or her credit report for possible identity theft issues. If you fear that your personal identifiable information has been compromised, you can elect to implement a "freeze" on your credit.

To contact GE Money, call toll-free Monday through Friday, 9:00 am to 7:00 pm EST, at 1-866-913-6690.