« March 2006 | Archives Home | May 2006 »


Blog / April 2006

94,000 Los Angeles County Residents Exposed to Identity Theft

Apr 2, 2006 by Tom Fragala

GuardmyCreditFile reports The Los Angeles County Office of the Department of Public Social Services announced today that it has sent letters to 94,000 county residents that they may have been exposed to identity theft. In January, documents containing their names,...

Read more »

US Secret Service cracks down on data thieves

Apr 4, 2006 by Tom Fragala

From a press release on the USSS’ web site: UNITED STATES SECRET SERVICE’S OPERATION ROLLING STONE NETS MULTIPLE ARRESTSOngoing Undercover Operation Targets Cyber Fraudsters March 27, 2006 Washington, D.C. – The United States Secret Service today made public an ongoing...

Read more »

100,000 Florida State Workers at Risk in Data Leak

Apr 4, 2006 by Tom Fragala

ComputerWorld reports Personal information of state employees in Florida may have been compromised after work on the state's People First payroll and human resources system was improperly subcontracted to one or more firms in India.About 108,000 current and former employees...

Read more »

Beating phishers at their own game

Apr 4, 2006 by Tom Fragala

Cnet has a story about a company called Cyota. They are doing something pretty cool to fight back against phishers. It’s sort of simple and obvious..and very clever. RSA Security's Cyota division is helping fight phishing attacks by giving the...

Read more »

FTC: Advance-Fee Credit Card’ Swindlers Settle Charges

Apr 5, 2006 by Tom Fragala

From the FTC website: Two corporate defendants and their principals have settled Federal Trade Commission charges for duping consumers into paying an advance fee for credit cards they never received, in violation of the FTC Act and the FTC’s Telemarketing...

Read more »

Internet Explorer hit by new phishing flaw

Apr 9, 2006 by Tom Fragala

From ComputerWeekly… Another serious security hole has been unearthed in Microsoft’s Internet Explorer browser, which could lead to users being tricked into thinking fake phishing sites are genuine.The error in the browser can be exploited to fake the address bar...

Read more »

Data breach at Progressive highlights insider threat

Apr 9, 2006 by Tom Fragala

This article from Computerworld digs into the security threat from insiders, using the example of a recent data breach. A recent case in which an employee at Progressive Casualty Insurance Co. wrongfully accessed information on foreclosure properties she was interested...

Read more »

Story tells how ID theft can ruin lives, not just credit

Apr 9, 2006 by Tom Fragala

XTVWorld has a story about how identity theft caused a Pentagon employee to lose his job, career and potentially his home, car and life savings. If you think ID theft is over-hyped or not a big deal, read on… Thaddeus...

Read more »

Kudos to Microsoft Messenger team

Apr 10, 2006 by Tom Fragala

In the Windows Messenger software I run, when I click to send a message I always see this first “Never give out your password or credit card number in an instant message conversation.”. Good advice. In most cases, instant messaging...

Read more »

SpoofCard: I have a bad feeling about this

Apr 11, 2006 by Tom Fragala

Have you heard about SpoofCard? It's a calling card that let's you change the CallerID number that appears on the phone you are calling to. And it doesn't even have to be a 10 digit number. You could send "411"...

Read more »

Minnesota passes identity theft bill

Apr 12, 2006 by Tom Fragala

The AP reports The Minnesota Senate united Monday to approve safeguards against identity theft for consumers and provide help for victims who are trying to clean up their records. The bill from Sen. Dan Sparks, would allow Minnesotans to put...

Read more »

Utah Introduces New Identity Theft Reporting System

Apr 12, 2006 by Tom Fragala

KUTV has this story The state attorney general’s Office introduced a new identity theft reporting system Monday that it says will cut down on the amount of time victims spend proving their identity has been stolen.Victims of identity theft can...

Read more »

Credit freezes and protecting your credit file from fraud

Apr 13, 2006 by Tom Fragala

I recently got a question from a reader. Someone told him that everyone should get a credit freeze. I emailed a response and I thought you might want to see my thoughts on this matter (slightly edited for this blog). There...

Read more »

Ross-Simons says security breach exposes customers

Apr 14, 2006 by Tom Fragala

Computerworld reports Ross-Simons, which sells specialty merchandise through retail stores and more than 60 million catalogs each year, late yesterday said a security breach could allow unauthorized access to its customers' confidential financial information.The company -- whose products include jewelry,...

Read more »

Data Brokers and Government Not Compliant with Privacy Act

Apr 16, 2006 by Tom Fragala

SANS NewsBites - Vol: 8, Issue: 28 reports According to a Government Accountability Office (GAO) report, the Departments of Justice, Homeland Security and State and the Social Security Administration spend a total of US$30 million to acquire data from information...

Read more »

Phone Privacy Bill in US Senate

Apr 16, 2006 by Tom Fragala

U.S. PIRG Consumer Blog  reports on what it calls an “Awful Phone Privacy Bill.” Here's a consumer letter (PIRG, Consumers Union, Consumer Federation of America) opposing S 2389, a bill marked up today in Senate Commerce that purports to protect...

Read more »

Cleaning Up Caller ID Spoof Services

Apr 16, 2006 by Tom Fragala

In a recent post, I talked about a Caller ID fake out service called SpoofCard. Looks like I was right when I said the FCC has jurisdiction over these types of services. Wired News has a story on proposed legislation...

Read more »

No credit card data breach in N.H. server case

Apr 17, 2006 by Tom Fragala

Computerworld reports An FBI investigation has concluded that no consumer credit or debit card information was stolen from a New Hampshire state computer server in February because a suspect Cain & Abel password recovery program found on the hardware had...

Read more »

Beware the 'pod slurping' employee

Apr 17, 2006 by Tom Fragala

CNET News.com has the story: A U.S. security expert who devised an application that can fill an iPod with business-critical data in a matter of minutes is urging companies to address the very real threat of data theft.  Abe Usher,...

Read more »

Mail carrier arrested on suspicion of identity theft

Apr 19, 2006 by Tom Fragala

The Santa Cruz Sentinel has a story of a substitute mail carrier that is a suspect in stealing mail. The post service is one of my biggest concerns and people don’t seem to talk a lot about it. The mail...

Read more »

Arizona House OKs bill to curb identity theft

Apr 19, 2006 by Tom Fragala

Arizona has probably the worse ID theft problem in the country. And many people I talk to attribute the problem, at least partly, to weak laws and lax enforcement. A January 2006 report by the FTC, entitled  “Consumer Fraud and...

Read more »

New Colorado security freeze - July 1 2006

Apr 21, 2006 by Tom Fragala

Colorado has a new credit freeze law going into effect July 1st. Here’s the details from the Colorado Attorney General: Beginning on July 1, 2006, consumers will have the option of requesting any consumer reporting agency to place a security...

Read more »

Wired's Article on the So-called Anti-ID-Theft Bills

Apr 21, 2006 by Tom Fragala

Bruce Schneier has an article in Wired News about the new identity theft bills floating around Congress. Probably the biggest flaw with these potential federal laws are they are written to wipe out stronger state laws that already exist. I wrote about it previously...

Read more »

Massive Social Security Number Fraud for Employment

Apr 23, 2006 by Tom Fragala

Using a SSN fraudulently to get employment is nothing new. But there’s a lot of new buzz surrounding the issue of “undocumented” workers stealing or using stolen social security numbers. This is not a small matter. If someone uses a...

Read more »

University of So. Carolina exposes student SSNs

Apr 24, 2006 by Tom Fragala

MSNBC.com reports University of South Carolina officials are advising students to watch their credit reports after the Social Security numbers of as many as 1,400 students were mistakenly e-mailed to classmates. A department chairwoman distributing information about summer classes accidentally...

Read more »

Arizona Drops the Ball With Weak Data Breach Bill

Apr 26, 2006 by Tom Fragala

GuardMyCreditFile reports Arizona’s state legislature has passed a data breach notification law that is currently awaiting the signature of Governor Janet Napolitano. While the law may have been well intentioned, it has some critical flaws and we are urging the...

Read more »

Identity Theft Crimes Rarely Solved

Apr 28, 2006 by Tom Fragala

Click2Houston.com has an article on fraud and ID theft in Houston: “HPD records show in the last year, only 2 percent of forgery and counterfeiting cases and only 12 percent of fraud cases were actually solved.”...

Read more »

Univ. of Texas data breach exposes 197,000 people

Apr 28, 2006 by Tom Fragala

Computerworld has the story on a new data breach at the University of Texas. In another reminder of the vulnerability of university networks, the University of Texas at Austin over the weekend announced that someone had broken into a computer...

Read more »

Fraudsters steal details on 2,000 credit cards

Apr 28, 2006 by Tom Fragala

CNET News.com says “Fraudsters stole the credit card details of 2,000 MasterCard holders in a major security breach last week.” This appears to effect card holders in the U.K. only....

Read more »

LexisNexis Says Data Breach Honesty is Best Policy

Apr 28, 2006 by Tom Fragala

SANS NewsBites - Vol: 8, Issue: 34 talks about this interesting insight from a company responsible for a major data breach last year. Speaking at the Infosec Europe 2006 conference in London, LexisNexis senior director for information security Leo Cronin...

Read more »

Iowa proposes ID theft 'passport'

Apr 29, 2006 by Tom Fragala

CNET News.com has this story: Lawmakers in Iowa are proposing a special "passport" meant to protect victims of identity theft against false criminal action and credit charges. The "Identity Theft Passport" will be a card or certificate that victims of...

Read more »

Wisconsin Governor Proposing New ID Theft Law

Apr 29, 2006 by Tom Fragala

WXOW TV-19 reports Wisconsin Governor is proposing a new ID theft law which would include an ID theft passport, which sounds similar to what Iowa is proposing. It will be interesting to see how this plays out, in light of...

Read more »

Data Breach Disclosure State Laws

Apr 29, 2006 by Tom Fragala

About.com had a valuable writeup on security breaches called Understanding Data Breach Disclosure. In it, Brian Koerner, has some super links with detailed and up to date state laws on data breaches, which are worthwhile linking to directly. Definitely check...

Read more »

North Carolina "Scam Jams"

Apr 29, 2006 by Tom Fragala

The New Bern Sun Journal has an article on public forums in North Carolina to educate citizens on common scams and ID theft. There will be 24 of the Scam Jams held in NC through November. The Scam Jams will...

Read more »

Aetna Data Breach Effects 38,000

Apr 29, 2006 by Tom Fragala

The blog Make Money Fast Hall of Humiliation points to a story in the Consumerist that reports insurance company Aetna has an employee’s laptop stolen....

Read more »

Organized Crime Behind Online Crime

Apr 29, 2006 by Tom Fragala

The mmfhoh blog has an interesting post about organized crimes impact or influence on Internet-based crime. No question in my mind here that organized crime, especially the Russian mob, plays a huge part in fraud and scams. Some that spring...

Read more »