Tuesday, December 13, 2005

Incident: ID fraudsters target job centre staff using UK tax credit website

From the Register:

ID fraudsters target job centre staff | The Register:

Crooks may have defrauded the UK tax credit system out of millions after exploiting a lack of safeguards in an internet site designed to service claimants.

HM Revenue & Customs shut down its tax credit portal website at the start of December after uncovering an attempt to defraud the system using the identities of Department of Work and Pensions (DWP) staff.

Initially it was thought that up to 1,500 job centre workers might have had personal information stolen. Now it is feared that up to 13,000 job centre staff might have been exposed to attack, with some reporting fraudulent claims made in their name. Fraudsters are reckoned to have secured the National Insurance numbers, names and dates of birth of thousands of job centre staff working in London, Glasgow, Lancashire and Pembrokeshire.

The information obtained was enough to make fraudulent tax credit claims redirected upon false addresses and accounts controlled by crooks. False claims of up to £1,000 a year appear to have been siphoned into fraudsters' bank accounts, PCS spokesman Alex Flynn told The Independent. 'Some people have had shadow bank accounts set up and their money diverted to that account. Other people have had their accounts hijacked,' he said....

We are experiencing technical difficulties. Please stand by.

Or at least that's what I would have said if I had been able to actually post anything to my blog since Monday morning. My service provider moved their data centre, which caused dodgy connections and then a complete inability to update the site. I am told we are back to normal. I reserve judgement.

Monday, December 12, 2005

Incident: Security breach at Sam's Club exposes credit card data

From Computerworld:

Security breach at Sam's Club exposes credit card data - Computerworld

DECEMBER 12, 2005 (COMPUTERWORLD) - Sam's Club, a division of Wal-Mart Stores Inc., is investigating a security breach that has exposed credit card data belonging to an unspecified number of customers who purchased gas at the wholesaler's stations between Sept 21 and Oct. 2. In a brief statement released Dec. 2, the Bentonville, Ark.-based company said it was alerted to the problem by credit card issuers who reported that customers were complaining of fraudulent charges on their statements.

It's still not clear how the data was obtained, according to the statement. But "electronic systems and databases used inside its stores and for Samsclub.com are not involved," the company said.

Sam's Club is currently working with both Visa International Inc. and MasterCard International Inc. to investigate the breach. The company also has notified the U.S. Attorney's Office for the Western District of Arkansas and the U.S. Secret Service .

Sam's Club officials didn't respond to calls for comment.

In a statement, Visa said it has alerted all of the affected financial institutions, asked them to provide independent fraud-monitoring services to affected customers and requested that they issue new cards as needed.

Incident: hackers nab details of 2000 donors from UK online charity

Out-law.com, via the Register, is reporting that hackers recenly breached the website of a UK charity, Aid to the Church in Need, and swiped personal information of about 2,000 donors. Some donors have been contacted by the thieves. See: Hackers target Christian charity | The Register.

CMAJ charges editorial interference over privacy-related story

The Canadian Medical Association Journal, a well-respected medical journal, has accused its parent, the Canadian Medical Association, of censorship as part of the fallout over recent privacy issues surrounding the dispensing of Plan B, also known as the "morning after pill". The Journal has accused the CMA of trying to pressure the journal to not publish its article on the dispensing of Plan B that highlighted questions to be asked of patients (Privacy issues raised over Plan B: women asked for names, addresses, sexual history -- Eggertson and Sibbald 173 (12): 1435 -- Canadian Medical Association Journal.) The CMAJ has released an editorial on the issue and highlights the recent experience with the article in question (The editorial autonomy of the CMAJ). (See the CPhA Patient Screening Form.)

For more coverage, see: Medical journal charges medical association with editorial interference - Yahoo! News; The Globe and Mail: Furor erupts at medical journal. Also, check out the CPhA Patient Screening Form.

Credit Card Security: Where Are We Now?

E-Commerce Times is running a three-part series of articles, the first of which is E-Commerce News: E-Commerce: Credit Card Security: Where Are We Now?. It discusses what credit card companies are doing in the wake of the high profile breaches in the past year or so.

Sunday, December 11, 2005

Greater risk of fraud if personal data is stolen in smaller batches

According to Finance Tech, a recent study suggests that individuals are at greater risk of indentity theft and other fraud if their personal information is compromised in smaller batches. Much of the focus of media attention has been on large breaches, but fraudsters would have to work overtime for years to exploit all that data. See: Small Data Breaches Pose Big Identity Theft Risks.

Cardsystems acquisition closes

The acquisition of Cardsystems by Pay by Touch announced in October (The Canadian Privacy Law Blog: Another suitor for CardSystems) has been concluded, according to a release issued on Friday: Pay By Touch Completes Acquisition of CardSystems Solutions: Financial News - Yahoo! Finance.

For those who may have forgotten, Cardsystems was involved in a high-profile data breach earlier this year: The Canadian Privacy Law Blog: Incident: Security Breach at CardSystems Solutions Inc. Could Expose 40M to Fraud.

Canadian draft guidelines to shield personal information from the USA Patriot Act

The Canadian Press just released a story about new draft guidelines for Canadian federal government departments designed to (at least try to) shield information about Canadians from the reach of the USA Patriot Act. The guidelines remain in draft form as the election has intervened to prevent them from being tabled in Parliament this fall and more internal consultations are taking place.

Canada drafts proposals to shield personal data from U.S. anti-terror law - Yahoo! News

... The draft guidance document suggests, in the interest of upholding Canadian privacy laws, that federal databases of sensitive personal information created by contractors be located in Canada and be accessible only within the country.

However, it recognizes international trade obligations may make this impossible. In such cases, the government suggests contractors must agree to respect Canadian privacy laws as a condition of contract.

The guidelines say that if the privacy risk is considered high, a federal department might go so far as to cut off the flow of personal information to a foreign firm should it be "presented with an order" - such as an FBI notice - compelling release of data about Canadians.

In general, the guidelines encourage departments to assess each potential contract case-by-case to gauge the possibility of privacy invasion, the expectations of Canadians, and likelihood of injury to a person's "career, reputation, financial position, safety, health or well-being."

Treasury Board spokesman Robert Makichuk said the draft guidelines were undergoing revision following internal federal consultations....

Saturday, December 10, 2005

The fight over mobile phone-derived location information

Today's New York Times has a good and thorough piece on the fight over location information from mobile phones and other unwired devices:

Live Tracking of Mobile Phones Prompts Court Fights on Privacy - New York Times:

In recent years, law enforcement officials have turned to cellular technology as a tool for easily and secretly monitoring the movements of suspects as they occur. But this kind of surveillance - which investigators have been able to conduct with easily obtained court orders - has now come under tougher legal scrutiny.

In the last four months, three federal judges have denied prosecutors the right to get cellphone tracking information from wireless companies without first showing 'probable cause' to believe that a crime has been or is being committed. That is the same standard applied to requests for search warrants.

The rulings, issued by magistrate judges in New York, Texas and Maryland, underscore the growing debate over privacy rights and government surveillance in the digital age.

With mobile phones becoming as prevalent as conventional phones (there are 195 million cellular subscribers in this country), wireless companies are starting to exploit the phones' tracking abilities. For example, companies are marketing services that turn phones into even more precise global positioning devices for driving or allowing parents to track the whereabouts of their children through the handsets.

Not surprisingly, law enforcement agencies want to exploit this technology, too - which means more courts are bound to wrestle with what legal standard applies when government agents ask to conduct such surveillance....