Tuesday, June 14, 2005

Dear Sir: Your Data Was Stolen

Dan Goodin, a regular contributor to Wired, writes about his experience after receiving a letter from his former university that his data had been compromised.

Wired News: Dear Sir: Your Data Was Stolen:

"... With or without government intervention, companies that fail to take effective action will surely suffer for it. Already, I'm thinking twice about donating money to UC Berkeley or continuing my relationship with Bank of America. Better to keep my information out of their hands altogether than risk them losing it."

U.S. Offshoring of Personal Data Grows

Elites TV, a news source I've never heard of before, has a lengthy and negative article on offshoring of personal data processing.

U.S. Offshoring of Personal Data Grows - Elites TV - Your Elite News Source:

"According to the Identity Theft Resource Center in San Diego, CA there have been close to 60 reported security breaches of customer financial information from United States corporations thus far in 2005, involving 13.5 million customers’ identities. The companies include Choicepoint, Inc., Bank of America Corp., Wachovia Corp., Ameritrade Holding Corp., DSW Shoe Warehouse, Time Warner Inc., LexisNexis and most recently Citbank Financial Group. While most lost data has involved data storage tapes lost in transit by courier services or UPS, others involved computer security breaches. And as corporate America looks for ways to shore up its security problems rather than face the wrath of Congress, an even more unwieldy problem is brewing abroad.

As holes still exist in protecting the personal information of both customers and employees of corporations in the United States, many of these same corporations, which include the largest financial institutions and two of the three credit reporting agencies, have offshored information technology units which include-back office functions from customer service to software development and engineering.

Yet American customers or consumers are never informed whether or not their personal information and credit history is being offshored, as it is not required by U.S. corporations to do so. Coming to light is that various U.S. government programs and states are utilizing more and more offshore subcontractors in addition to those corporate entities which indirectly do business with the U.S. government. But unknown to the American consumer or taxpayer is the threat of theft of an individual’s identity and financial resources which remain largely unprotected without the ability to enforce U.S. law on foreign land...."

Monday, June 13, 2005

Using profiling to fight credit card fraud

Credit card providers have been using purchase pattern information to fight fraud for some time. Visa is throwing neural network technology and other analytical techniques to deduce whether a transaction is likely to be fraudulent.

Visa's newest attempt to thwart fraud - Online Banking - MSNBC.com:

"... Visa said that when a card is swiped, its new Advanced Authorization technology provides an instant rating of the transaction's potential for fraud to the card issuer, including whether the card was part of a reported security breach. The issuer can then tell the merchant whether to accept or decline the transaction...."

New shredding laws aren't followed

Stop the presses! Stop the presses!

Apparently some companies are following privacy laws. I'm shocked.

I wonder how many of the companies impugned in this article are even aware of the new mandatory shredding rules?

KRISTV.COM - Corpus Christi, TX - New shredding laws aren't followed:

"CORPUS CHRISTI-- A new federal law is now helping to protect consumers from identity theft. It requires businesses and individuals using consumer credit reports to either shred or burn the information that's obtained from them. The disposal rule went into affect this month, but some people still aren't complying. The new law protecting personal information was created in hopes of reducing the rising number of identity theft cases. The disposal rule makes it a crime for businesses to simply toss out your credit report, without shredding or burning it...."

Identity thefts often inside job

Not sure if this is news to any regular readers of this blog, but privacy incidents are very often the fault of employees. Poorly trained employees and malicious employees:

Identity thefts often inside job:

"You do everything right.

You protect your Social Security number like the Swiss Guard protects the pope.

You shred more documents than a secretary for Oliver North.

You never -- ever -- respond to those e-mails requesting PIN numbers and birth dates.

But before you can say "Club Med, Bora Bora," some identity thief has booked the honeymoon suite there with a credit card in your name.

How could this happen?

Here's the scary reality: It might have been an inside job.

And there's no way you could have stopped it...."

Enterprises Scramble To Protect Off-Site Data

A big part of the raison d'etre of this blog is that it is preferable to learn from the mistakes of others, rather than one's own.

It appears that many companies are learning from CitiGroup's problems:

Networking Pipeline | Enterprises Scramble To Protect Off-Site Data:

"Companies are scrambling to encrypt data on tapes shipped to off-site centers for archiving and disaster recovery, and they're taking other steps to avoid the kinds of data-loss incidents that have been a major source of embarrassment in recent months. Last week it was Citigroup's turn, as the bank revealed that a box of tapes containing information on 3.9 million customers was lost in transit...."

Another senate hearing on ID theft

The US Senate is, once again, holding privacy-related hearings. This time, the US Senate Committee on Commerce, Science, & Transportation is considering ID Theft. I think you can watch it live on C-SPAN on Thursday, June 16, 2005, at 10:00 a.m (Eastern). Thanks to Tamara Thompson's blog.

Sunday, June 12, 2005

Keeping your data secret is up to you

An increasing portion of the mainstream media are picking up on privacy issues, mainly stemming from the string of breaches starting with ChoicePoint and culminating in the most recent CitiFinancial data loss. The Boston Globe is running a column by Michelle Singletary of the Washington Post that calls for legislation but also suggests that consumers become more proactive in protecting their personal information. The columnist shows one example from her own experience:

Keeping your data secret is up to you - The Boston Globe - Boston.com - Your Money - Business:

"... For instance, I recently contracted to have an alarm system installed in my home. As I was filling out the sales agreement, I noticed a request for my Social Security number. I refused to divulge it. The salesman said it was a requirement. He said I ''had" to give it to him.

I unequivocally refused to divulge my number. A manager of the company called. He explained that it was needed to pull my credit score because we were signing up for a three-year monitoring service. He said it had been their experience that people with low credit scores often break the three-year contract.

Even if that was the case, I was appalled at the lack of security about my data from this company. By my rough estimate, from the time the salesman took my service agreement to his office, my data could have been exposed to at least half a dozen of the company's employees. In several of the recent data breaches, employees were doing the pilfering.

I was prepared to leave my home unprotected for the time being in the name of protecting my personal data.

Ah, but here's where it pays to be persistent about protecting your data.

The manager came up with a way to get my Social Security number without me actually giving it to him or anyone else at the company. In a three-way conference call, he phoned the credit bureau and when the automatic system asked for the customer's Social Security number, I punched it in. All he heard on his end was a beeping sound. In a few seconds he got my credit score without having to know my Social Security number.

So folks, it's up to us. We have to become our own data protectors. You may not win the battle all the time, but if you're fierce enough you can reduce the number of companies that have your information."

Incident: Equifax Canada mis-faxes personal information

Note to self: Make sure you are sending your faxes to the right place. Addendum: Make sure that if you do screw up, you don't accidentally send faxes to someone who is already mad at you.

CANOE -- CNEWS - Canada: Credit info in wrong hands:

"It seems Equifax Canada can't get the fax or the facts right after the credit agency sent detailed personal information about three Canadians to a Lindsay man.

Scot Paterson, 42, who's been battling the agency for two years to update his credit history, received a fax this week with the addresses, social insurance numbers, driver's licences and credit card information on three people living in Scarborough, Ottawa and Montreal.

When his wife called the company to notify them of the privacy breach, she was told it was 'impossible' for such an error to occur and that they were too busy to check their faxes, he said.

Paterson got the profiles on three strangers within minutes of faxing his own personal information to Equifax in a bid to straighten out his credit history...."

Incident: Medical Documents Spilled On Highway in Alabama

From News Channel 10 in Rhode Island:

News Channel 10 - News - CVS Apologizes For Customers' Documents Spilled On Highway:

"CVS, based in Woonsocket, R.I., apologized to some customers Friday after a truck licensed by the company spilled documents with personal information on a highway in Birmingham, Ala.

CVS told News Channel 10 the incident in Alabama is an accidental situation due to a truck malfunction.

A portion of Interstate 65 in Birmingham was littered with medical documentation about CVS customers.

"We deeply regret the incident that occurred today (Friday) when a Waste Management truck that was traveling from one of our distribution centers broke open and spilled information about customers on the road,” said CVS corporate spokesman Todd Andrews, in an interview with the NBC station in Birmingham.

"What happened today (Friday) was that the information which travels from our pharmacies to our distribution center, which is then packaged and then brought to a secure landfill, was somehow relieved in transit either through a door being unsecured or somehow being damaged and opening."

After receiving calls that the documents were strewn all across the Interstate, Andrews said the issue was addressed by CVS immediately.

"We immediately took action and contacted Waste Management, which is the licensed hauler of this material,” said Andrews. “We are working with Waste Management now and their cleaning crews to secure all of this information."

CVS said they've asked the waste management company to do a full investigation into how the documents became unsecured and blew off the truck and were allowed to remain on the roadside, uncollected."

I would think this information should be shredded, rather than sent to a "secure landfill".