by Bob Sullivan
Is using a forged Social Security Number -- but your own name -- to obtain employment or buy a car an identity theft crime? Lately, U.S. courts are saying it's not.
The most recent judicial body to take on the issue, the Colorado Supreme Court, ruled last month that a man who used his real name but someone else's Social Security number to obtain a car loan was not guilty of "criminal impersonation," overturning convictions by lower courts.
That follows a ruling last year by the U.S. Supreme Court that a Mexican man who gave a false SSN to get a job at an Illinois steel plant could not be convicted under federal identity theft laws because he did not knowingly use another person's identifying number. The ruling overturned an opinion by a federal appeals court in St. Louis -- and contradicted earlier findings by circuit courts in the Southeast, upper Midwest and the Gulf states.
It hasn’t been a shutout for identity theft prosecutors, however. In July, an Iowa state appeals court came to the opposite conclusion, affirming a lower court decision that a man who used a California woman's SSN to obtain employment was guilty of breaking that state's identity theft law.
Identity theft can take many forms, but one of the most vexing is so-called "SSN-only" ID theft. In it, an imposter uses a victim's SSN --- sometimes purchased from a broker, sometimes nine digits pulled out of thin air -- to obtain credit or to provide necessary documentation to obtain work. In many cases, SSN "borrowing" is successful and the imposter goes undetected for years.
At the heart of all these cases is a simple question: Does the mere use of an anonymous victim's SSN break identity theft laws?
Mari Frank, a California-based lawyer and identity theft victim advocate, said courts are failing to recognize the real harm caused by imposters, even if imposters are unaware of that harm.
"You can't say there's no victim,” she said. “That Colorado ruling really aggravated me," she said. Courts are mis-applying impersonation laws, and that could really hurt victims. "(The judges) just don't get it."
To read the entire article, click here - http://redtape.msnbc.com/2010/11/courts-using-anothers-ssn-not-a-crime.html
Tuesday, November 30, 2010
Monday, November 29, 2010
Holiday Consumer Alert "Identity Thieves Don't Take a Holiday"
By Identity Theft Resource Center
May 3, 2007 - 12:00:07 PM
Every year ITRC gets more calls about lost and stolen wallets than any other time of the year. This is the season to enjoy, not to be stressed as an identity theft victim. The time between Thanksgiving and Christmas is the biggest shopping season of the year. As we enter the holiday season, we would like to remind everyone to take additional precautions against identity theft. Identity theft is not just something you read about in the paper. About 10 million people fall victim to this crime every year. No one is immune – from birth to beyond death. Because of the distractions of the holidays and crowded shopping environments, conditions are ripe for identity thieves and pickpockets to take advantage of the situation. Who’s in your wallet?©
The following are the Identity Theft Resource Center’s Tips and Suggestions to be safe during the holiday season.
*Social Security Numbers: Never carry your Social Security card or its number with you on a daily basis. This is true not only during the holidays but year-round. That number is more valuable than gold to identity thieves. Only carry it on the single days you need it and keep it in a locked box at all other times.
*Mail Awareness: Watch for monthly bills. We all know that the holidays will cause some mailing delays. However, if you have not received your bills within a few days of their regularly scheduled dates, contact both the issuer and the Post Office. Failure to receive a bill could be as innocent as a delay, or it could be an indicator of mail theft. If this is a case of theft, let the Postal Inspector’s Office know. Remember- a locked mailbox is a necessity in today’s world. It is also a great family gift- the gift of protection.
*Mailing bills: Each year we see Post Office boxes filled to overflowing with outgoing mail. We recommend that you mail envelopes containing checks or sensitive information inside the post office before the last pickup of the day. During the holidays, make sure that the post office box is sufficiently empty enough that your mail doesn’t sit within easy reach of someone’s inquiring hands.
To read the entire article, click here - http://www.idtheftcenter.org/artman2/publish/m_press/Holiday_Consumer_Alert_Identity_Thieves_Don_t_Take_a_Holiday.shtml
May 3, 2007 - 12:00:07 PM
Every year ITRC gets more calls about lost and stolen wallets than any other time of the year. This is the season to enjoy, not to be stressed as an identity theft victim. The time between Thanksgiving and Christmas is the biggest shopping season of the year. As we enter the holiday season, we would like to remind everyone to take additional precautions against identity theft. Identity theft is not just something you read about in the paper. About 10 million people fall victim to this crime every year. No one is immune – from birth to beyond death. Because of the distractions of the holidays and crowded shopping environments, conditions are ripe for identity thieves and pickpockets to take advantage of the situation. Who’s in your wallet?©
The following are the Identity Theft Resource Center’s Tips and Suggestions to be safe during the holiday season.
*Social Security Numbers: Never carry your Social Security card or its number with you on a daily basis. This is true not only during the holidays but year-round. That number is more valuable than gold to identity thieves. Only carry it on the single days you need it and keep it in a locked box at all other times.
*Mail Awareness: Watch for monthly bills. We all know that the holidays will cause some mailing delays. However, if you have not received your bills within a few days of their regularly scheduled dates, contact both the issuer and the Post Office. Failure to receive a bill could be as innocent as a delay, or it could be an indicator of mail theft. If this is a case of theft, let the Postal Inspector’s Office know. Remember- a locked mailbox is a necessity in today’s world. It is also a great family gift- the gift of protection.
*Mailing bills: Each year we see Post Office boxes filled to overflowing with outgoing mail. We recommend that you mail envelopes containing checks or sensitive information inside the post office before the last pickup of the day. During the holidays, make sure that the post office box is sufficiently empty enough that your mail doesn’t sit within easy reach of someone’s inquiring hands.
To read the entire article, click here - http://www.idtheftcenter.org/artman2/publish/m_press/Holiday_Consumer_Alert_Identity_Thieves_Don_t_Take_a_Holiday.shtml
Saturday, November 20, 2010
PCI: Small Merchants Need to Catch Up
New Survey Finds Small Merchants Don't Invest in PCI Compliance
By Tracy Kitten
Why has industry-wide compliance with the Payment Card Industry Data Security Standard proved so challenging? PCI-DSS is not new -- the standard is six years old. And changes to the standard, though somewhat significant during the early days, have not, as of late, been so dramatic.
The PCI Security Standards Council has been very vocal about its decision this year to keep standards relatively stagnant. The council says the PCI-DSS is mature and inclusive. And it wants to give the payments community a chance to catch up on compliance.
To read the entire article, click here -
http://blogs.bankinfosecurity.com/posts.php?postID=775&rf=2010-11-19-eb
By Tracy Kitten
Why has industry-wide compliance with the Payment Card Industry Data Security Standard proved so challenging? PCI-DSS is not new -- the standard is six years old. And changes to the standard, though somewhat significant during the early days, have not, as of late, been so dramatic.
The PCI Security Standards Council has been very vocal about its decision this year to keep standards relatively stagnant. The council says the PCI-DSS is mature and inclusive. And it wants to give the payments community a chance to catch up on compliance.
To read the entire article, click here -
http://blogs.bankinfosecurity.com/posts.php?postID=775&rf=2010-11-19-eb
Saturday, November 13, 2010
Planning Well Ahead For 2011 Charity Golf Scramble
Golf Scramble to Raise Money to Fight Cancer; To Feature Local Celebrities, Athletes, Companies
By Steve Huelsman, Executive Vice-President
GLG and Associates, LLP
The POWER Group Organization® Team
As the Fall season slowly slips away, many area golfers are trying to get in many rounds of their sport before putting up the clubs for a couple of months. Meanwhile, a small group of individuals are constantly brainstorming on the details of hosting its first charity golf scramble that would benefit the local Kentuckiana community.
"We are putting together a different kind of golf scramble that will reach more charities than originally anticipated, mainly because of the great support of area businesses that have come on-board to help make everything a reality", says G.L. Giddings, Chairman and CEO of GLG and Associates, LLP, an affiliate and specialty marketing company, located in Louisville, KY. "Almost everyone I know has been affected by cancer in some way shape and form. In the last four years, I lost my grandmother, my mother on August 15th, and my sister over two years ago. My fiancee', Catrina, is currently in remission with cervical cancer. Raising the funds to help combat this disease by putting on a golf scamble has become very personal to me."
The scramble isn't scheduled to tee off until August 15, 2011, the first anniversary of Joan O. Giddings , G.L.'s mother, passing from uterine cancer. "If she were here, I know she'd be proud that we were out doing our part to help combat this disease. The fight has to keep going till there is a cure for ALL forms of cancer. However long it takes is what we'll deal with", he says This isn't a SPRINT, but a MARATHON, and The PGO® will be here hosting this tournament and giving back for many years to come!"
To find out more about the golf scramble and to participate, please click here for more details - http://events.linkedin.com/POWER-Group-Organization-R-Charity-Golf/pub/484857
By Steve Huelsman, Executive Vice-President
GLG and Associates, LLP
The POWER Group Organization® Team
As the Fall season slowly slips away, many area golfers are trying to get in many rounds of their sport before putting up the clubs for a couple of months. Meanwhile, a small group of individuals are constantly brainstorming on the details of hosting its first charity golf scramble that would benefit the local Kentuckiana community.
"We are putting together a different kind of golf scramble that will reach more charities than originally anticipated, mainly because of the great support of area businesses that have come on-board to help make everything a reality", says G.L. Giddings, Chairman and CEO of GLG and Associates, LLP, an affiliate and specialty marketing company, located in Louisville, KY. "Almost everyone I know has been affected by cancer in some way shape and form. In the last four years, I lost my grandmother, my mother on August 15th, and my sister over two years ago. My fiancee', Catrina, is currently in remission with cervical cancer. Raising the funds to help combat this disease by putting on a golf scamble has become very personal to me."
The scramble isn't scheduled to tee off until August 15, 2011, the first anniversary of Joan O. Giddings , G.L.'s mother, passing from uterine cancer. "If she were here, I know she'd be proud that we were out doing our part to help combat this disease. The fight has to keep going till there is a cure for ALL forms of cancer. However long it takes is what we'll deal with", he says This isn't a SPRINT, but a MARATHON, and The PGO® will be here hosting this tournament and giving back for many years to come!"
To find out more about the golf scramble and to participate, please click here for more details - http://events.linkedin.com/POWER-Group-Organization-R-Charity-Golf/pub/484857
Phishing Attacks On The Rise
Global Effort is Only Way to Fight Threat to Banking Customers
Tracy Kitten, Managing Editor
A recent rash of targeted phishing schemes -- which included hits to military accountholders and their families at USAA and Navy Federal Credit Union, as well as a separate attack on officials at the World Bank -- has again brought the crime to the fore.
It's just the latest spree in a long line of phishing and vishing attacks that have grown to be more selective in their approaches, using malicious e-mails or phone calls that send unsuspecting users to spoofed websites, where malware hijacks banking credentials.
The schemes are more targeted than they were 18 months ago, says John Buzzard, client relations manager for FICO, which provides decision management and predictive analytics solutions. Those targeted launches, which hit customers and members at specific financial institutions, often reap more rewards for the fraudsters.
"For the criminal, you get more out of targeting a specific institution, because a lot of these folks are not used to getting scammed," Buzzard says. "Oftentimes, they are targeting people who are not quite so savvy and don't have a lot of experience with the Internet and banking online."
In the USAA and Navy FCU cases, Buzzard says, targeting military families has proven profitable. "It's not that military members and their spouses are less savvy; but when you have one parent overseas fighting and the other at home taking care of all of the finances, they can be stressed and distracted and may not be paying so much attention," he says. "Stressed-out military spouses are juggling many things, and they could be in a hurry to respond to something without thinking about it thoroughly."
To read the entire article, click here - http://www.bankinfosecurity.com/articles.php?art_id=3080&rf=2010-11-13-eb
Tracy Kitten, Managing Editor
A recent rash of targeted phishing schemes -- which included hits to military accountholders and their families at USAA and Navy Federal Credit Union, as well as a separate attack on officials at the World Bank -- has again brought the crime to the fore.
It's just the latest spree in a long line of phishing and vishing attacks that have grown to be more selective in their approaches, using malicious e-mails or phone calls that send unsuspecting users to spoofed websites, where malware hijacks banking credentials.
The schemes are more targeted than they were 18 months ago, says John Buzzard, client relations manager for FICO, which provides decision management and predictive analytics solutions. Those targeted launches, which hit customers and members at specific financial institutions, often reap more rewards for the fraudsters.
"For the criminal, you get more out of targeting a specific institution, because a lot of these folks are not used to getting scammed," Buzzard says. "Oftentimes, they are targeting people who are not quite so savvy and don't have a lot of experience with the Internet and banking online."
In the USAA and Navy FCU cases, Buzzard says, targeting military families has proven profitable. "It's not that military members and their spouses are less savvy; but when you have one parent overseas fighting and the other at home taking care of all of the finances, they can be stressed and distracted and may not be paying so much attention," he says. "Stressed-out military spouses are juggling many things, and they could be in a hurry to respond to something without thinking about it thoroughly."
To read the entire article, click here - http://www.bankinfosecurity.com/articles.php?art_id=3080&rf=2010-11-13-eb
Saturday, November 6, 2010
ID Theft: SSN Is 'Key to the Kingdom'
Incidents Prove Link Between Social Security Numbers, ID Theft
Tracy Kitten, Managing Editor
The Colorado Supreme Court decision to reverse a conviction for criminal impersonation has stirred debate among identity theft protection advocates. In short, advocates say the Oct. 25 ruling sets a precedent that provides a loophole for those who impersonate others by stealing and/or misusing Social Security numbers.
"The Social Security number is the key to the kingdom of almost every type of identity theft," says attorney and certified information privacy expert Mari Frank. "It's the key to medical-benefit theft, government-benefit theft, you name it. This case, I think, sets a very bad precedent," she says, "because there are a number of people with bad credit or a criminal record or even illegal immigrants in this country that would use a stolen Social Security number to get a job, take out a car loan or get other benefits."
The Colorado Supreme Court overturned by a 4-3 decision the 2006 conviction of Felix Montes-Rodriguez for misusing another person's Social Security number to find work and apply for a car loan. Montes-Rodriguez' immigration status is not known; but the court found that because he used his own address, birth date and place of employment when he applied for the car loan, the use of the stolen Social Security number did not constitute false identity.
To read the entire article, click here -
http://www.bankinfosecurity.com/articles.php?art_id=3069&rf=2010-11-06-eb
Tracy Kitten, Managing Editor
The Colorado Supreme Court decision to reverse a conviction for criminal impersonation has stirred debate among identity theft protection advocates. In short, advocates say the Oct. 25 ruling sets a precedent that provides a loophole for those who impersonate others by stealing and/or misusing Social Security numbers.
"The Social Security number is the key to the kingdom of almost every type of identity theft," says attorney and certified information privacy expert Mari Frank. "It's the key to medical-benefit theft, government-benefit theft, you name it. This case, I think, sets a very bad precedent," she says, "because there are a number of people with bad credit or a criminal record or even illegal immigrants in this country that would use a stolen Social Security number to get a job, take out a car loan or get other benefits."
The Colorado Supreme Court overturned by a 4-3 decision the 2006 conviction of Felix Montes-Rodriguez for misusing another person's Social Security number to find work and apply for a car loan. Montes-Rodriguez' immigration status is not known; but the court found that because he used his own address, birth date and place of employment when he applied for the car loan, the use of the stolen Social Security number did not constitute false identity.
To read the entire article, click here -
http://www.bankinfosecurity.com/articles.php?art_id=3069&rf=2010-11-06-eb
Friday, November 5, 2010
Incident Response: Drafting the Team
What are the Key Skills for Your Organization?
Upasana Gupta, Contributing Editor
Nearly a year ago, IBM's client organization suffered a major malware attack. When Don Weber, then an incident response professional with IBM, arrived on-site with his team, they demonstrated timeline-based analysis that quickly provided them with system-based artifacts associated with the malware on the compromised systems.
Although the malware solutions were able to tell them which systems were currently infected, they had no way of telling which systems had been compromised, or whether the malware had been removed or instead rolled over to something that was not being detected.
Using the information available, Weber and his team took a step back from data analysis and developed a perl-based tool that detected specific registry keys that would work on live systems. Using this tool, the client's security team was able to distribute and reach all of their resources. This allowed them to systematically (over the course of several days) identify approximately 10 systems out of over 30,000 that needed to be added to the scope of the incident.
To read the entire article, click here - http://www.govinfosecurity.com/articles.php?art_id=3060&rf=2010-11-05-eg&
Upasana Gupta, Contributing Editor
Nearly a year ago, IBM's client organization suffered a major malware attack. When Don Weber, then an incident response professional with IBM, arrived on-site with his team, they demonstrated timeline-based analysis that quickly provided them with system-based artifacts associated with the malware on the compromised systems.
Although the malware solutions were able to tell them which systems were currently infected, they had no way of telling which systems had been compromised, or whether the malware had been removed or instead rolled over to something that was not being detected.
Using the information available, Weber and his team took a step back from data analysis and developed a perl-based tool that detected specific registry keys that would work on live systems. Using this tool, the client's security team was able to distribute and reach all of their resources. This allowed them to systematically (over the course of several days) identify approximately 10 systems out of over 30,000 that needed to be added to the scope of the incident.
To read the entire article, click here - http://www.govinfosecurity.com/articles.php?art_id=3060&rf=2010-11-05-eg&
Where Entrepreneurs Need Nerves of Steel
By Steven Gray, Contributor
FORTUNE -- For Glenn Oliver , it took a certain amount of faith in the unseen to launch a business in Detroit, the poorest major city in America. Oliver is a lawyer, not a businessman, whose experience included clerking for a Michigan Supreme Court justice and approving utility contracts. But an entrepreneurial streak that runs in his family emerged when Oliver began to ponder the potential of a resource the Great Lake State has in abundance: water. Rising demand has spurred a global boom in water-supply projects. So why not create a marketplace for all the new business, where contractors and suppliers can bid on projects around the world? The result of Oliver's inspiration is a website he spent nine months building, H2bid.com, which charges $450 a year for a membership and bills itself as the "largest clearinghouse" for water contracts. Oliver's venture isn't profitable yet, but he's confident that his startup will help the battered city. "Entrepreneurship," he notes, "is the largest creator of wealth."
To read the entire article, click here - http://money.cnn.com/2010/10/11/smallbusiness/Detroit_minority_startups.fortune/index.htm
FORTUNE -- For Glenn Oliver , it took a certain amount of faith in the unseen to launch a business in Detroit, the poorest major city in America. Oliver is a lawyer, not a businessman, whose experience included clerking for a Michigan Supreme Court justice and approving utility contracts. But an entrepreneurial streak that runs in his family emerged when Oliver began to ponder the potential of a resource the Great Lake State has in abundance: water. Rising demand has spurred a global boom in water-supply projects. So why not create a marketplace for all the new business, where contractors and suppliers can bid on projects around the world? The result of Oliver's inspiration is a website he spent nine months building, H2bid.com, which charges $450 a year for a membership and bills itself as the "largest clearinghouse" for water contracts. Oliver's venture isn't profitable yet, but he's confident that his startup will help the battered city. "Entrepreneurship," he notes, "is the largest creator of wealth."
To read the entire article, click here - http://money.cnn.com/2010/10/11/smallbusiness/Detroit_minority_startups.fortune/index.htm
Labels:
entrepreneurship,
minority companies,
small business
Thursday, November 4, 2010
Leveraging Loyalty: How to Keep Customers Hooked
By Teri Evans
FOXBusiness
Attracting new customers is an obvious way to grow your business, and often the primary focus of a small business owner.
But like any important relationship, experts say it's what you do after you win the business that really determines long-term success.
Here are five cost-effective ways to keep customers coming back without coupons, gimmicks or giveaways. Don't wait for complaints to step up the charm. Use a personal touch to cement the relationship with your most loyal customers. A simple handwritten card letting them know you appreciate them will stand out far more than a mass e-mail.
In a high-tech world where few people put pen to paper anymore, receiving a snail-mail note makes customers feel special, said Lauri Flaquer of Saltar Solutions, a small-business consultancy in St. Paul, Minn.
Making an unexpected phone call to check in with the customers who bring in the greatest revenue, for example, will also leave a lasting impression. And be consistent, Flaquer recommended. Contact them every 30 to 90 days, but remember that it should always be a sincere gesture of appreciation -- not an attempt to sell them more stuff. "You don't want to just call when you need them."
To read the entire article, click here - http://www.foxsmallbusinesscenter.com/sbc/2010/10/07/leveraging-loyalty-customers-hooked/
FOXBusiness
Attracting new customers is an obvious way to grow your business, and often the primary focus of a small business owner.
But like any important relationship, experts say it's what you do after you win the business that really determines long-term success.
Here are five cost-effective ways to keep customers coming back without coupons, gimmicks or giveaways. Don't wait for complaints to step up the charm. Use a personal touch to cement the relationship with your most loyal customers. A simple handwritten card letting them know you appreciate them will stand out far more than a mass e-mail.
In a high-tech world where few people put pen to paper anymore, receiving a snail-mail note makes customers feel special, said Lauri Flaquer of Saltar Solutions, a small-business consultancy in St. Paul, Minn.
Making an unexpected phone call to check in with the customers who bring in the greatest revenue, for example, will also leave a lasting impression. And be consistent, Flaquer recommended. Contact them every 30 to 90 days, but remember that it should always be a sincere gesture of appreciation -- not an attempt to sell them more stuff. "You don't want to just call when you need them."
To read the entire article, click here - http://www.foxsmallbusinesscenter.com/sbc/2010/10/07/leveraging-loyalty-customers-hooked/
Tuesday, October 26, 2010
ID Theft: SARs On The Rise
Identity Theft Reports Jump; Most Attributed to Family
Tracy Kitten, Managing Editor
The majority of identity theft incidents reported by U.S. financial institutions don't relate to phishing attacks and spoofed website pages. According to a new ID theft report from the Financial Crimes Enforcement Network, most cases of ID theft are linked to a victim's family members or coworkers.
John Summers, a project officer at FinCEN and a lead in FinCEN's report, "Identity Theft: Trends, Patterns and Typologies Reported in Suspicious Activity Reports", says ID theft perpetrated by family, friends and business partners ranked No.1 among SARs filed by U.S. depository institutions in 2009. "In 27.5 percent of the filings, this was the highest," he says. "It basically means someone close to them was getting access to their files and using their information."
Summers says only 3.5 percent of the ID theft incidents reported in SARs related to computer viruses and Trojans, such as Zeus. For vishing and phishing, the incidents reported were even fewer. "The only ones I found were in new data, and it would only come out to .15 percent," he says. "That does not mean those types of attacks did not occur and account for theft and losses. It just means that the victim was not aware and did not report it as a phishing (or vishing) attack."
To read the entire article, click here - http://www.bankinfosecurity.com/articles.php?art_id=3031&rf=2010-10-26-eb
Tracy Kitten, Managing Editor
The majority of identity theft incidents reported by U.S. financial institutions don't relate to phishing attacks and spoofed website pages. According to a new ID theft report from the Financial Crimes Enforcement Network, most cases of ID theft are linked to a victim's family members or coworkers.
John Summers, a project officer at FinCEN and a lead in FinCEN's report, "Identity Theft: Trends, Patterns and Typologies Reported in Suspicious Activity Reports", says ID theft perpetrated by family, friends and business partners ranked No.1 among SARs filed by U.S. depository institutions in 2009. "In 27.5 percent of the filings, this was the highest," he says. "It basically means someone close to them was getting access to their files and using their information."
Summers says only 3.5 percent of the ID theft incidents reported in SARs related to computer viruses and Trojans, such as Zeus. For vishing and phishing, the incidents reported were even fewer. "The only ones I found were in new data, and it would only come out to .15 percent," he says. "That does not mean those types of attacks did not occur and account for theft and losses. It just means that the victim was not aware and did not report it as a phishing (or vishing) attack."
To read the entire article, click here - http://www.bankinfosecurity.com/articles.php?art_id=3031&rf=2010-10-26-eb
Saturday, October 23, 2010
PCI: Smaller Merchants Threatened
Criminals Now Picking Less Compliant Targets
Linda McGlasson, Managing Editor
The Payment Card Industry's Security Standards Council may be doing a good job helping lock down larger retailers, but the smaller "Mom and Pop" merchants are becoming the new targets of cyber criminals, says a PCI expert.
A recent report on PCI compliance by Verizon Business shows some unsettling trends, says Jen Mack, Verizon's director of global PCI consulting services.
Mack says Level 3 and 4 retailers are now being targeted by cyber criminals for the theft of credit card data. Examples of these targets include restaurants in several states that were hit in the past several months -- the latest being one that had its POS system breached in Tallahassee, Fla.
Level 3 merchants are defined by those merchants that have 20,000 or more credit card transactions annually. Level 4 are those that have fewer than 20,000 credit card transactions per year.
The PCI report shows that businesses of every size "are better at planning, doing -- not at checking if they are compliant," says Mack, a former member of the PCI Security Standards Council. The overwhelming majority of data breaches occur because of failures to check things were in place. Despite arguments to the contrary, Mack says "There's no open hole causing data breaches that isn't covered by the PCI standards."
To read the entire article, click here - http://www.bankinfosecurity.com/articles.php?art_id=3019&rf=2010-10-23-eb
Linda McGlasson, Managing Editor
The Payment Card Industry's Security Standards Council may be doing a good job helping lock down larger retailers, but the smaller "Mom and Pop" merchants are becoming the new targets of cyber criminals, says a PCI expert.
A recent report on PCI compliance by Verizon Business shows some unsettling trends, says Jen Mack, Verizon's director of global PCI consulting services.
Mack says Level 3 and 4 retailers are now being targeted by cyber criminals for the theft of credit card data. Examples of these targets include restaurants in several states that were hit in the past several months -- the latest being one that had its POS system breached in Tallahassee, Fla.
Level 3 merchants are defined by those merchants that have 20,000 or more credit card transactions annually. Level 4 are those that have fewer than 20,000 credit card transactions per year.
The PCI report shows that businesses of every size "are better at planning, doing -- not at checking if they are compliant," says Mack, a former member of the PCI Security Standards Council. The overwhelming majority of data breaches occur because of failures to check things were in place. Despite arguments to the contrary, Mack says "There's no open hole causing data breaches that isn't covered by the PCI standards."
To read the entire article, click here - http://www.bankinfosecurity.com/articles.php?art_id=3019&rf=2010-10-23-eb
Friday, October 22, 2010
Two Cyberfraud Advisories Issued
Protecting Against Account Takeover, Money Mule Schemes
Linda McGlasson, Managing Editor
An industry group and federal law enforcement agencies have issued a set of much anticipated cyberfraud advisories for businesses and consumers. The two advisories address one of the fastest growing crimes, corporate account takeover, and related fraud, money mule schemes.
The two advisories, Fraud Advisory for Businesses: Corporate Account Take Over, and Fraud Advisory for Consumers: Involvement in Criminal Activity through Work from Home Scams, were issued by the Financial Services Information Sharing and Analysis Center (FS-ISAC), the Federal Bureau of Investigation, the United States Secret Service and the Internet Crime Complaint Center.
These advisories come just weeks after authorities in the U.S. and Europe arrested more than 100 people involved in a cybercrime gang that was stealing millions from U.S. businesses.
To read the entire article, click here - http://www.bankinfosecurity.com/articles.php?art_id=3023
Linda McGlasson, Managing Editor
An industry group and federal law enforcement agencies have issued a set of much anticipated cyberfraud advisories for businesses and consumers. The two advisories address one of the fastest growing crimes, corporate account takeover, and related fraud, money mule schemes.
The two advisories, Fraud Advisory for Businesses: Corporate Account Take Over, and Fraud Advisory for Consumers: Involvement in Criminal Activity through Work from Home Scams, were issued by the Financial Services Information Sharing and Analysis Center (FS-ISAC), the Federal Bureau of Investigation, the United States Secret Service and the Internet Crime Complaint Center.
These advisories come just weeks after authorities in the U.S. and Europe arrested more than 100 people involved in a cybercrime gang that was stealing millions from U.S. businesses.
To read the entire article, click here - http://www.bankinfosecurity.com/articles.php?art_id=3023
The Future of Mobile Payments
Solutions are Here, But Security Remains Top Concern
By Tracy Kitten, Managing Editor
Mobile technology is already having a big impact on financial services, from remote banking to mobile payments. The continued proliferation of smart phones is only going to accelerate that impact. Mobile is already revolutionizing the way consumers interact with their financial institutions, and banks have to stay ahead of the technology and the security concerns.
Randy Vanderhoof, executive director of the Smart Card Alliance, says mobile banking is a given. Payments are now the next frontier, and a number of technologies and services, such as remote deposit capture, are converging to make mobile payments readily accessible to consumers.
"By 2011, we can expect to see more NFC (near-field communications)-enabled devices being rolled out by the handset manufacturers," Vanderhoof says. Once that happens, the connection between the mobile device and contactless payments will be bridged.
To read the entire article, click here - http://www.bankinfosecurity.com/articles.php?art_id=3017&rf=2010-10-19-eb
Tuesday, October 19, 2010
Getting To Inbox Zero - How To Stop Drowning In Email
Posted by Nitasha Tiku
Spark Capital's Bijan Sabet doesn't blame you for tweeting when you get to inbox-zero. "It feels good getting to that magical place." Sabet offers a few comment now on his blog, and his savvy followers chime in with their own. For starters: Watch how many e-mails you send out--they tend to invite responses. Delete e-mails you never want to see again. Tweet or blog while you're on vacation--it's more of a deterrent against would-be inbox cloggers than an "out-of-office" auto-responder. And, finally, never get into a serious debate from your inbox.
SoundCloud founder David Noel manages 6 e-mail inboxes for his company. In the comments, he recommends answering immediately then archiving or deleting, marking with a star if you need to follow-up, and only keeping e-mails in your inbox that you intend to answer that day. Turkish VC Cem Sertoglu has started using direct mails on Twitter in lieu of short e-mails. DigiSpeaker owner Jon Smirl says in Gmail, the trick is two inboxes. Set the top one to "is:unread" and the bottom to your normal inbox and filter subscription items so that they are set to archive and bypass your inbox.
To read the entire article, click here -
http://www.inc.com/staff-blog/2010/01/yelp_bags_50_mi.html
Spark Capital's Bijan Sabet doesn't blame you for tweeting when you get to inbox-zero. "It feels good getting to that magical place." Sabet offers a few comment now on his blog, and his savvy followers chime in with their own. For starters: Watch how many e-mails you send out--they tend to invite responses. Delete e-mails you never want to see again. Tweet or blog while you're on vacation--it's more of a deterrent against would-be inbox cloggers than an "out-of-office" auto-responder. And, finally, never get into a serious debate from your inbox.
SoundCloud founder David Noel manages 6 e-mail inboxes for his company. In the comments, he recommends answering immediately then archiving or deleting, marking with a star if you need to follow-up, and only keeping e-mails in your inbox that you intend to answer that day. Turkish VC Cem Sertoglu has started using direct mails on Twitter in lieu of short e-mails. DigiSpeaker owner Jon Smirl says in Gmail, the trick is two inboxes. Set the top one to "is:unread" and the bottom to your normal inbox and filter subscription items so that they are set to archive and bypass your inbox.
To read the entire article, click here -
http://www.inc.com/staff-blog/2010/01/yelp_bags_50_mi.html
Friday, October 15, 2010
Guarding Your Good Name - Protect Your Identity Week Offers Classes, Info and Free Shredding
Posted by Donna Freedman on Friday, October 15, 2010
Almost 10 million Americans were victims of identity theft fraud in 2008, according to the Federal Trade Commission. Apparently you can't be too careful: 16% of the victims knew the person who had committed the crime -- and 6% of the time it was a family member.
How can you avoid being ripped off?
The third annual Protect Your Identity Week is a good start. Oct. 17-23, you can avail yourself of:
Document shredding. Cell phone recycling. Credit report reviews.
Short seminars such as "Avoid Scams and Fraud," "Protect Your Identity," "Keeping Your ID Safe on the Internet" and "Get Smart About Credit."
To read the entire article, click here - http://articles.moneycentral.msn.com/SmartSpending/blog/page.aspx?post=1816442&_blg=1,1816391
Almost 10 million Americans were victims of identity theft fraud in 2008, according to the Federal Trade Commission. Apparently you can't be too careful: 16% of the victims knew the person who had committed the crime -- and 6% of the time it was a family member.
How can you avoid being ripped off?
The third annual Protect Your Identity Week is a good start. Oct. 17-23, you can avail yourself of:
Document shredding. Cell phone recycling. Credit report reviews.
Short seminars such as "Avoid Scams and Fraud," "Protect Your Identity," "Keeping Your ID Safe on the Internet" and "Get Smart About Credit."
To read the entire article, click here - http://articles.moneycentral.msn.com/SmartSpending/blog/page.aspx?post=1816442&_blg=1,1816391
Tuesday, October 12, 2010
FTC: No Major PHR Breaches So Far
Only Incidents Listed Are Lost or Stolen Credentials
October 11, 2010 - Howard Anderson, Managing Editor, HealthcareInfoSecurity.com
In the year since the breach notification rule for personal health records took effect, no major breaches affecting 500 or more individuals have been reported, according to the Federal Trade Commission.
A personal health record is an "electronic record of identifiable health information on an individual that can be drawn from multiple sources and that is managed, shared and controlled by or primarily for the individual," according to the FTC.
Last year, the FTC issued a PHR breach notification rule, as called for under the HITECH Act. Under the rule, which took effect Sept. 24, 2009, major breaches must be reported to the FTC within 10 business days. PHR vendors, and certain companies with which they do business, must report any size breach to the individuals affected within 60 days. But they only have to report the smaller incidents to the FTC annually, 60 days after the start of the calendar year.
To read the entire article, click here - http://www.govinfosecurity.com/articles.php?art_id=2996&rf=2010-10-12-eg
October 11, 2010 - Howard Anderson, Managing Editor, HealthcareInfoSecurity.com
In the year since the breach notification rule for personal health records took effect, no major breaches affecting 500 or more individuals have been reported, according to the Federal Trade Commission.
A personal health record is an "electronic record of identifiable health information on an individual that can be drawn from multiple sources and that is managed, shared and controlled by or primarily for the individual," according to the FTC.
Last year, the FTC issued a PHR breach notification rule, as called for under the HITECH Act. Under the rule, which took effect Sept. 24, 2009, major breaches must be reported to the FTC within 10 business days. PHR vendors, and certain companies with which they do business, must report any size breach to the individuals affected within 60 days. But they only have to report the smaller incidents to the FTC annually, 60 days after the start of the calendar year.
To read the entire article, click here - http://www.govinfosecurity.com/articles.php?art_id=2996&rf=2010-10-12-eg
How to Evaluate Your Social Media Team
By Cindy Vanegas
Published October 11, 2010
FOXBusiness
After two expensive and lackluster contracts with so-called “social media specialists,” Kathy Costello was ready to abandon her foray into social media.
“We hired one company that was going to set up SEO [search engine optimization] and help us with social media,” recalled Costello, the founder of KCB Accounting Solutions. “We spent close to $1,000. They wanted money up-front and a monthly retainer. I didn’t see anything tangible so we left them. I met with another group--everything they said sounded good, but I didn’t really understand what they were doing.”
As social media gains traction, small business owners are forced to keep up with trends to generate customers and drive revenue. But in a world where everyone claims to be a social media expert, how does a business owner avoid costly mistakes?
To read the entire article, click here - http://www.foxsmallbusinesscenter.com/entrepreneurs/2010/10/11/evaluate-social-media-team/
Published October 11, 2010
FOXBusiness
After two expensive and lackluster contracts with so-called “social media specialists,” Kathy Costello was ready to abandon her foray into social media.
“We hired one company that was going to set up SEO [search engine optimization] and help us with social media,” recalled Costello, the founder of KCB Accounting Solutions. “We spent close to $1,000. They wanted money up-front and a monthly retainer. I didn’t see anything tangible so we left them. I met with another group--everything they said sounded good, but I didn’t really understand what they were doing.”
As social media gains traction, small business owners are forced to keep up with trends to generate customers and drive revenue. But in a world where everyone claims to be a social media expert, how does a business owner avoid costly mistakes?
To read the entire article, click here - http://www.foxsmallbusinesscenter.com/entrepreneurs/2010/10/11/evaluate-social-media-team/
Wednesday, October 6, 2010
How Identity Theft Happens: Small Business is Big Profit
From Jerri Ledford, former About.com Guide
Jennifer and Rick took over the company that their father built from the ground up. In the years they’ve worked at and owned the company, they’ve grown it by offering compliance services in the transportation industry. On a daily basis, they struggle with Department of Transportation regulations, transportation tax issues, and myriad other details of owning the business. What they never dreamed they would have to deal with was identity theft.
Business identity theft is growing at an astounding rate. And many small and medium-sized businesses just don’t realize how at risk they are. Take Jennifer and Rick’s company for example. It’s a small company, with less than ten employees and a few hundred customers. Why would an identity thief be interested in them?
To read the entire article, click here - http://idtheft.about.com/od/businessidtheft/a/smallbizidtheft.htm
Jennifer and Rick took over the company that their father built from the ground up. In the years they’ve worked at and owned the company, they’ve grown it by offering compliance services in the transportation industry. On a daily basis, they struggle with Department of Transportation regulations, transportation tax issues, and myriad other details of owning the business. What they never dreamed they would have to deal with was identity theft.
Business identity theft is growing at an astounding rate. And many small and medium-sized businesses just don’t realize how at risk they are. Take Jennifer and Rick’s company for example. It’s a small company, with less than ten employees and a few hundred customers. Why would an identity thief be interested in them?
To read the entire article, click here - http://idtheft.about.com/od/businessidtheft/a/smallbizidtheft.htm
Cybersecurity as a Catalyst for Economic Growth
Lessons from Sputnik: Producing Benefits Beyond Safeguarding IT
Eric Chabrow, Executive Editor, GovInfoSecurity.com
Fear is a great motivator. Fear helped the United States overtake the Soviet Union in the space race after the launch of Sputnik in the late 1950s. Americans feared our Cold War adversaries would conquer space, so the United States invested heavily, not only in technology, but in educating our young citizens in math and science to challenge the Soviets.
"We were really pretty far behind and we were kind of surprised that the Soviet Union was so far ahead in science and technology," Patrick Gorman, former associate director of the Office of the Director of National Intelligence, said in an interview with GovInfoSecurity.com (transcript below).
The return on that investment, just over a decade later, resulted in the United States landing men on the moon. And, the investments produced additional benefits such as the creation of the IT industry and other technological advancements unrelated to space.
To read the entire article, click here - http://www.govinfosecurity.com/articles.php?art_id=2982&rf=2010-10-06-eg
Eric Chabrow, Executive Editor, GovInfoSecurity.com
Fear is a great motivator. Fear helped the United States overtake the Soviet Union in the space race after the launch of Sputnik in the late 1950s. Americans feared our Cold War adversaries would conquer space, so the United States invested heavily, not only in technology, but in educating our young citizens in math and science to challenge the Soviets.
"We were really pretty far behind and we were kind of surprised that the Soviet Union was so far ahead in science and technology," Patrick Gorman, former associate director of the Office of the Director of National Intelligence, said in an interview with GovInfoSecurity.com (transcript below).
The return on that investment, just over a decade later, resulted in the United States landing men on the moon. And, the investments produced additional benefits such as the creation of the IT industry and other technological advancements unrelated to space.
To read the entire article, click here - http://www.govinfosecurity.com/articles.php?art_id=2982&rf=2010-10-06-eg
Tuesday, October 5, 2010
Is CyberScope Ready for Prime Time?
Survey: Most Agencies Had Yet to Employ FISMA Reporting Tool
Eric Chabrow, Executive Editor, GovInfoSecurity.com
If you're a federal CIO or CISO, you either love CyberScope or are ignorant about it.
That's the takeaway of a survey published Monday by six IT security vendors on CyberScope, the automated FISMA reporting tool unveiled a year ago by Federal Chief Information Office Vivek Kundra. Major federal departments and agencies are to employ CyberScope by Nov. 15 to report on how they have complied this past year with the requirements of the Federal Information Security Management Act, the law that governs cybersecurity in the federal government, according to a memo issued by Kundra and White House Cybersecurity Coordinator Howard Schmidt in April.
Only 15 percent of the 34 federal chief information and chief information security officers surveyed in July had used CyberScope. Those CIOs and CISOs grave CyberScope a grade of A or B.
To read the entire article, click here - http://www.govinfosecurity.com/articles.php?art_id=2978&rf=2010-10-05-eg
Eric Chabrow, Executive Editor, GovInfoSecurity.com
If you're a federal CIO or CISO, you either love CyberScope or are ignorant about it.
That's the takeaway of a survey published Monday by six IT security vendors on CyberScope, the automated FISMA reporting tool unveiled a year ago by Federal Chief Information Office Vivek Kundra. Major federal departments and agencies are to employ CyberScope by Nov. 15 to report on how they have complied this past year with the requirements of the Federal Information Security Management Act, the law that governs cybersecurity in the federal government, according to a memo issued by Kundra and White House Cybersecurity Coordinator Howard Schmidt in April.
Only 15 percent of the 34 federal chief information and chief information security officers surveyed in July had used CyberScope. Those CIOs and CISOs grave CyberScope a grade of A or B.
To read the entire article, click here - http://www.govinfosecurity.com/articles.php?art_id=2978&rf=2010-10-05-eg
Subscribe to:
Posts (Atom)
Do Do You Keep Your Career Options Open?
OSBW Blog Archive
- January (1)
- October (3)
- September (1)
- March (2)
- December (1)
- November (1)
- October (4)
- August (1)
- March (2)
- February (1)
- January (3)
- December (13)
- November (11)
- July (2)
- March (2)
- February (1)
- January (2)
- December (7)
- November (9)
- October (17)
- September (11)
- August (5)
- July (15)
- May (3)
- April (7)
- March (23)
