Showing posts with label Identity theft. Show all posts
Showing posts with label Identity theft. Show all posts

Thursday, November 18, 2010

Beware of Holiday Season Phishing Scams and Malware Campaigns

US-CERT is receiving reports of an increased number of phishing scams and malicious software campaigns that take advantage of the winter holiday and holiday shopping season. We urge users to be on their guard, mindful of the potential that an email message could be part of a potential phishing scam or malware campaign.

Users are urged to be sensitive to:
  • Electronic greeting cards that may contain malware
  • Requests for charitable contributions that may be phishing scams and may originate from Illegitimate sources claiming to be charities
  • Movie clips, screensavers or other forms of media that may contain malware
  • Credit card applications that may be phishing scams or identity theft attempts
  • Online shopping advertisements that may be phishing scams or identity theft attempts from bogus retailers

We strongly urge users to protect themselves during the holiday season:
  • Don't follow unsolicited web links in email messages. Consider running Firefox with the No-Script Add-in.
  • Use caution when opening email attachments; Is the email from someone you know? Was the email expected? When in doubt, Don't.
  • Maintain up-to-date antivirus and anti-spyware software.
  • Keep your systems patched. Be careful of the latest vulnerabilities. Follow our Weekly Vulnerability and Patch Report, published on our blog, Citadel on Security.

    Friday, September 17, 2010

    Interpol Says Cybercrime is "World's Most Dangerous Criminal Threat"

    Concerned with the growing threat from an estimated $105-billion-dollar illegal business, 300 top law enforcement officials from 56 countries met in Hong King for the first ever national police anti-cybercrime conference.

    Ronald K. Noble, secretary general of the Interpol, told the assembled law enforcement officials that "considering the anonymity of cyberspace, it may in fact be one of the most dangerous criminal threats we will ever face."

    More on this story is available from Yahoo News.

    Sunday, July 25, 2010

    Digital Forensics Association Research Report: Five Years of Data Breaches

    A new report from the Digital Forensics Association confirms the need for organizations to pay careful attention to all aspects of information security.The report "The Leaking Vault - Five Years of Data Breaches" analyzes over 2,800 data loss incidents from publicly accessible sources, with a known disclosure of 271.9 million records.  This study—the largest of its kind to date—provides analysis on which breach vectors carry the most risk, and should help provide organizations with more accurate information when combating this problem.


    Key findings include:

    • Business, government, educational and medical organizations have been responsible for losing on average over 395,000 people's data per day every day for five years.  
    • Hacking was responsible for 45% of all exposed records with an average loss of 716,000 records
    • Stolen laptops were responsible for 49% of breaches but only 6% of lost records per incident.
    • The fastest growing attack vector is social engineering
    • Social Security Numbers (SSNs) are the most frequent data element reported.
    • The Business sector accounted for 70% of breach incidents

    Monday, June 14, 2010

    Free WiFi at Starbucks — Reminder of Cybersecurity Risk

    The New York Times reports that Starbuck's will begin offering free WiFi on July 1. This makes it a good time to remind everyone about the need to be cautious when using public Wi-Fi. While the most common risk is eavesdropping, one cannot overlook the risk of computer compromise. Here are five basic rules anytime you're on a WiFi network whose security cannot be verified:
    1. No online banking or other eCommerce
    2. No email containing sensitive information except via an approved encrypted link from PC to  Mail Server
    3. Keep anti-virus or host intrusion prevention software (better) up-to-date
    4. Make sure software patches are up-to-date
    5. Use VPN for access to office

      Tuesday, April 20, 2010

      Health Care Survey: Slow Hospital Compliance with New Regulations Causing Increased Data Breaches & Medical Identity Theft

      From the Spring 2010 National Survey of Hospital Compliance Executives conducted by Identity Forces:
      • Compliance continues to lag as nearly 85% of hospitals are NOT in compliance with the HITECH Act
      • Breaches are up over 120% from last year's survey
      • 41% of hospitals now have 10 or MORE data breaches annually
      • Potential patient ID fraud and misuse going un‐investigated as 34% of hospitals keep inadequate records
      • 48% of hospitals do not check to make sure vendors and business associates are in compliance with the HITECH act.

      As medical consumers, should we be worried. You betcha! 

      Download the report (PDF).

      Thanks to Hal Amens for this story.

      Rent-a-Fraudster: A Fascinating Look at the Cybercrime Underworld

      KrebsOnSecurity.com reports that a call service catering to online bank and identity thieves has been busted by U.S. and international authorities. The takedown provides a fascinating look at a special niche of service providers in the cybercrime underworld. Suppose, for example, you're a cybercriminal with a thick Russian accent, you have all the appropriate information about David Smith that his bank requires to transfer money, and you want to move $250,000 from David Smith's bank account but Smith's bank requires an out-of-band phone call with the bank before they'll release the money. To get your $250,000, you rent an English-speaking fraudster who calls the bank for you! Another rent-a-fraud service provides a password-protected Web site catering to customers with stolen credit cards. Yet a third Web site, appropriately named the "Fraud Shop," manages cybercriminal transactions at legitimate Web sites, even arranging for shipping stolen merchandise to mules.

      Read the story at KrebsOnSecurity.com ...

      Wednesday, March 31, 2010

      Separating April Fools’ From Fraud on the Web

      NewYorkTimes: On the Internet, every day is April Fools’ Day. ... Thinking about how people get fooled on April 1 is a good way to prepare for the year-round attempts by swindlers to bamboozle the naïve, the witless and those who just aren’t paying close attention. In other words, all of us. ... The same themes run through the e-mail solicitations of Nigerian princes waiting to share their riches, messages by banks to type in your PIN or frantic pleas from Facebook friends trapped overseas without any money. ... How do you tell the real from the surreal today?

      Read more at the New York Times ...

      Thursday, March 25, 2010

      Would You Have Spotted this ATM Fraud?

       KrebsOnSecurity.com: The stories I’ve written on ATM skimmers — devices criminals can attach to bank money machines to steal customer data — remain the most popular at Krebs on Security so far. I think part of the public’s fascination with these fraud devices is rooted in the idea that almost everyone uses ATMs, and that it’s entirely possible to encounter this type of sneaky, relatively sophisticated form of crime right in our own neighborhoods. ... police in Alexandria, Va. — just a couple of miles to the East of where I reside — recently were alerted to a skimmer found on an ATM at a Wachovia Bank there.
       
       Read more at KrebsOnSecurity.com ...

      Wednesday, March 17, 2010

      FCC Broadband Plan Calls For Enhanced Cyber Defenses

      ChannelWeb: The National Broadband Plan, presented to Congress by the Federal Communications Commission this week, contains stipulations that could equip U.S. communications networks with stronger defenses against cyber threats and protect users' privacy online. ... Among other things, the plan gives a boost for the development of cyber security infrastructure, proposing the implementation of online privacy measures and calling for continued cooperation between the FCC and the Department of Homeland Security on public safety issues and initiatives.

      Read more ...


      Google Attacks Highlight Growing Problem of Cyber Security Threats

      VoiceOfAmerica: Google’s recent disclosure that it was the target of a highly sophisticated cyber attack has brought renewed attention to the growing problem of cyber security threats. Officials and security experts say that while past cyber attacks focused largely on national secrets and defense technologies, that focus is changing. ... Speaking at a recent congressional hearing on future threats to U.S. national security, FBI Director Robert Mueller said cyber attacks are increasingly taking a wider aim. [Director Mueller’s Testimony to Senate Committee on Intelligence] "As the global economy integrates, many cyber threats now focus on economic or non-government targets as we have seen with the recent cyber attack on Google," he explained. "Targets in the private sector are at least as vulnerable and the damage can be just as great."

      Read more ...



      Sunday, March 14, 2010

      Identity theft may be prelude to more serious crime

      Los Angeles Times: Identity theft may be the financial world's equivalent of a staph infection. Just when you thought you had a handle on protecting your identity from criminals, the crime has morphed into something new and far more toxic. ... identity criminals are now using your information as they commit felonies, including child abuse and terrorism. Others are using your records to file fraudulent medical claims, experts say. These new forms of identity theft are nearly invisible until they cause serious problems.

      Read more ...

      Tuesday, March 9, 2010

      LifeLock Will Pay $12 Million to Settle Charges by the FTC and 35 States That Identity Theft Prevention and Data Security Claims Were False

      FTC: LifeLock, Inc. has agreed to pay $11 million to the Federal Trade Commission and $1 million to a group of 35 state attorneys general to settle charges that the company used false claims to promote its identity theft protection services, which it widely advertised by displaying the CEO’s Social Security number on the side of a truck. ... “While LifeLock promised consumers complete protection against all types of identity theft, in truth, the protection it actually provided left enough holes that you could drive a truck through it,” said FTC Chairman Jon Leibowitz.

      Read more ...

      Tuesday, March 2, 2010

      Information on U.S. website for medical data thefts is bare-bones

      Los Angeles Times: The medical records of more than 18,000 patients of at least five Torrance doctors were potentially accessed by cyber-thieves on a single day in September, but this is probably the first you're hearing of it. ... Although a new federal law requiring greater disclosure of medical-data security breaches was passed a year ago, it wasn't until recently that the Department of Health and Human Services began posting specific incidents online.

      Read more ...

      Thursday, February 18, 2010

      CVS Caremark Settles FTC Charges that It Failed to Protect Medical and Financial Privacy of Customers and Employees; CVS Pharmacy Also Pays $2.25 Million Fine to DHS

      FTC: CVS Caremark has agreed to settle Federal Trade Commission charges that it failed to take reasonable and appropriate security measures to protect the sensitive financial and medical information of its customers and employees, in violation of federal law. In a separate but related agreement, the company’s pharmacy chain also has agreed to pay $2.25 million to resolve Department of Health and Human Services allegations that it violated the Health Insurance Portability and Accountability Act (HIPAA). ... "This is a case that will restore appropriate privacy protections to tens of millions of people across the country," said William E. Kovacic, Chairman of the Federal Trade Commission. "It ... sends a strong message to other organizations that possess consumers' protected personal information. They are required to secure consumers' private information."

      Read more ...

      Wednesday, February 10, 2010

      ID Theft: Don't Take It Personally

      Forbes Magazine: Identity theft often feels less like a random act of fraud than a personal breach of a victim's secrets. But while consumers feel the sting from having their private data stolen, it's their banks that are increasingly picking up the bill.... That's one finding from an identity theft study released Wednesday by fraud analysis firm Javelin Research. The study, which surveyed around 5,000 Americans last year about their experiences with identity theft, calculated that ID fraud had cost around $54 billion in 2009, a significant jump from the $48 billion it estimated for 2008. That higher cost was driven by a greater number of fraud incidents that affected 11.2 million consumers in 2009, compared with 9.9 million in 2008.

      Read more ...

      Tuesday, February 2, 2010

      Twitter Asks Users To Reset Passwords After Possible Phishing Attack

      Washington Post: Twitter is locking many users out of the system this morning, and sending them notices that they need to change their passwords in order to regain access to the service, due to concerns over a possible phishing attack.

      Read more ...

      Thursday, January 21, 2010

      FTC Says Mortgage Broker Broke Data Security Laws: Dumpster Wrong Place for Consumers’ Personal Information

      FTC: The Federal Trade Commission has charged a mortgage broker with discarding consumers’ tax returns, credit reports, and other sensitive personal and financial information in an unsecured dumpster, in violation of federal law.

      Read more ...

      Wednesday, January 20, 2010

      NY Times: If Your Password Is 123456, Just Make It HackMe

      Back at the dawn of the Web, the most popular account password was “12345.” ...Today, it’s one digit longer but hardly safer: “123456.” ... Despite all the reports of Internet security breaches over the years, including the recent attacks on Google’s e-mail service, many people have reacted to the break-ins with a shrug. ...According to a new analysis, one out of five Web users still decides to leave the digital equivalent of a key under the doormat: they choose a simple, easily guessed password like “abc123,” “iloveyou” or even “password” to protect their data.

      Read more ...

      Sunday, December 13, 2009

      Viruses That Leave Victims Red in the Facebook

      What's happening: Malware is spreading through Web sites like Facebook and Twitter. After stealing a Member's screen name and password, these malicious programs are coded to automatically send spam messages to the Member's friends and followers. Unsuspecting friends have been asked for money, have been directed to web-sites where malware is installed on their computers, and have had their user-names and passwords to online bank accounts stolen.

      What it means: Social networks continue to be the wild wild west of the internet.

      What to do: Stay vigilant. Be suspicious. Report suspected problems. And use a strong hard-to-break password.

      **********************************
      Viruses That Leave Victims Red in the Facebook

      Thursday, November 19, 2009

      Health Net healthcare data breach affects1.5 million

      What's happening: Health Net announced that it is investigating a healthcare data security breach that resulted in the loss of patient data, affecting 1.5 million customers.The Woodland Hills, Calif.-based managed healthcare provider said the lost files, a mixture of medical data, Social Security numbers and other personally identifiable information, were collected over the past seven years and contained on a portable external hard drive, which was lost six months ago. The company said the healthcare data was not encrypted containing data on 446,000 Connecticut patients.

      What it means: This loss illustrates some of the challenges of securely managing sensitive information. Who — if anyone — authorized sensitive information to be stored on a portable—easy-to-lose—hard drive? Why was the drive not encrypted? Why did it take the company 6 months to to notify anyone? What will this cost them? What will they learn from it?

      What to do: Stay vigilant. Every business is at risk that what happened to Health Net can happen to it.

      **********************************
      Health Net healthcare data breach affects1.5 million