Showing posts with label identity. Show all posts
Showing posts with label identity. Show all posts

Thursday, 24 March 2011

Second hand phones contain extensive personal data

People are unsuspectingly selling their personal information to complete strangers as a new report from CPP finds half (54%) of second hand mobile phones contain extensive personal data.



Second hand mobile phones and SIM cards purchased on eBay and used electronics shops by CPP were examined in a live experiment to see what personal information was available on the handsets and whether it constituted a threat to their former owners' identities.

The experiment revealed 247 pieces of personal data that had been carelessly left on a range of mobile phones and SIM cards. The personal data included credit and debit card PIN numbers, bank account details, passwords, phone numbers, company information and log in details to social networking sites like Facebook and LinkedIn.

In research that supported the experiment, half of second hand mobile owners said they have found personal information from a previous owner on mobile phones and SIM cards they have purchased second hand.

Worryingly, the vast majority (81 per cent) of people claim to have wiped their mobiles before selling them, with six in ten confident they have removed all of their personal information from them. However, the experiment revealed that 54 per cent of mobile phones and SIM cards contained sensitive personal information putting people at unnecessary risk of identity and card fraud.

The variance could be explained by the fact that most people who claimed to have 'wiped' their handsets tried to erase the data manually – a process that security experts acknowledge leaves the data intact and retrievable.

And it seems personal information comes cheap with individuals selling their old handsets and SIMs for an average price of 47 pounds Sterling.

As people rely heavily on their mobile phones to store personal data such as e-mail addresses, social networking log in details, banks account details and even debit and credit card PIN numbers, CPP is calling on people to make sure they remove all of their personal and financial information from their mobile phones and undertake adequate security measures to protect themselves from identity theft.

Senior Vice President of CRYPTOCard Jason Hart said: "The safest way to remove all of your data from a mobile phone or SIM card is to totally destroy the SIM and double check to ensure that all content has been removed from your phone before disposal. With new technology does come new risks and our experiment found that newer smartphones have more capabilities to store information and that information is much easier to recover than on traditional mobiles due to the increase of applications."

[Net-Security]

Wednesday, 23 March 2011

Most users unaware of smartphone security risks

Consumers are indifferent to the many serious security risks associated with the storage and transmission of sensitive personal data on iPhone, Blackberry and Android devices, according to The Ponemon Institute.



Following are three of the most alarming results of the survey:
  • 89 percent of respondents were unaware that smartphone applications can transmit confidential payment information such as credit card details without the user’s knowledge or consent.
  • 91 percent of respondents were unaware that financial applications for smartphones can be infected with specialized malware designed to steal credit card numbers and online banking credentials, yet nearly a third (29 percent) report already storing credit and debit card information on their devices and 35 percent report storing “confidential” work related documents as well.
  • 56 percent of respondents did not know that failing to properly log off from a social network app could allow an imposter to post malicious details or change personal settings without their knowledge. Of those aware, 37 percent were unsure whether or not their profiles had already been manipulated.
Other smartphone security dangers include geo-tracking based on location data embedded onto image files; the transmission of confidential payment information without the user’s knowledge or consent; and unauthorized (and often unnoticed) premium-service orders on the monthly bill.


"The findings of this study signal what could be an overlooked security risk for organizations created by employees' use of smartphones. Because consumers in our study report that they often use smartphones interchangeably for business and personal, organizations should make sure their security policies include guidelines for the appropriate use of smartphones that are used for company purposes," said Dr. Larry Ponemon, chairman and founder of Ponemon Institute.

According to the study, 28 percent of respondents were unaware that using their smartphone for business and personal reasons can put business information at risk.

[Net-Security]

What To Do When Your Identity Gets Stolen


OK, so it happens. A lot. Companies and people don’t always do the right things and sometimes, criminals win. They steal identity data and get the chance to commit massive fraud. We all know about it. We hear the stories and we hear people talking, but we don’t think it will happen to us, until it does.
What now? What should you do when such an event occurs in your life? Well, this great article from our friends over at Help Net Security summarizes best practices for identify theft victims and their support systems as described by the Consumer Federation of America (CFA). I thought the article was not only good content, but an excellent point of reference for folks who might be impacted by identity theft. You should check it out here. Here are some more tips:
  1. You should also be well aware of your legal rights and responsibilities and not be afraid to engage with your state Attorney General’s office if you suspect vendors are not playing by the rules. You can find a list of state Attorney General contacts here: http://www.consumerfraudreporting.org/stateattorneygenerallist.php
  2. Legal representation may also be of assistance if the fraud you face is large enough to warrant the cost of representation. Don’t be afraid to engage with an attorney if the fraud costs are large or the legal complexity you face is astounding. Contact your state bar association for information on finding reputable consumer law attorneys in your area.
  3. If you are considering something like one of these consumer data/life “locking” services or the like, please check out a DIY approach here.
We hope you never have to use this information, but if you do, these are a few quick tidbits to get you started while avoiding further scams, fraud and abuse. As always, thanks for reading and stay safe out there!

[StateOfSecurity]

Thursday, 3 March 2011

Teen cybercrime forum boss jailed

A UK teenager who ran a prolific cybercrime forum from home has been jailed for five years.

Nick Webber, 19, maintained the Ghostmarket.net market which boasted 8,000 memberships and facilitated a range of crimes including the sale of stolen credit card and personal details.

Police recovered the details of thousands of credit cards from Webber's machines when he was busted in October 2009 after trying to use a counterfeit credit card to pay for a hotel stay. Confronted by mounds of evidence Webber, from Southsea, Hampshire, pleaded guilty to fraud.

Southwark Crown Court heard that members of the gang may have defrauded banks and individuals anywhere between £12m and £20m, depending on whose estimates you believe. In court, Ghostmarket.net was described as a supermarket for cybercrooks, providing guides on how to commit cybercrimes as well as a marketplace for stolen wares.

The personal details of around 65,000 victims were traded through the site.

Even after his release on bail, Webber continued to engage in cybercrime, an aggravating feature that led to a far tougher sentence than might otherwise have been the case.

Three other convicted suspects were convicted in the same case. Gary Kelly, 21, from Manchester, was also jailed for five years after he also pleaded guilty to the same fraud charges as Webber along with conspiracy to make or supply articles for use in fraud and conspiracy to cause unauthorised modification to computers.

Ryan Thomas, 18, from Beaconsfield in Buckinghamshire, who acted as the site admin for Ghostmarket.net, was jailed for four years. Shakira Ricardo, 21, from Swansea, was imprisoned for 18 months after she pleaded guilty to conspiracy to commit fraud and handling criminal property, the BBC reports.

Webber and Thomas jumped bail soon after their initial arrests in December 2009 before they were captured in Majorca and returned to the UK, The Guardian adds. ®

[The Register]

Tuesday, 1 March 2011

Facebook security best practices: Protect your privacy and identity on Facebook

ID fraudsters target Facebook and other social networking sites to harvest information about you. Here's how we recommend you set your Facebook privacy options to protect against online identity theft.

How to adjust your settings

This guide walks you through Sophos-recommended privacy settings in Facebook, and shows you how to set more secure levels of privacy and reduce the chance of becoming a victim of online identity theft.

General security tips for Facebook

Adjust Facebook privacy settings to help protect your identity

Unlike some other social networking sites, Facebook has provided some powerful options to protect you online—but it's up to you to use them!

Read the Facebook Guide to Privacy

At the very bottom of every page on Facebook, there's a link that reads "Privacy." The linked page is "A guide to privacy on Facebook," which contains the latest privacy functions and policies. For example, with the latest changes in May 2010, Facebook discloses information that it sets as visible to everyone and that you cannot make private. This information includes sensitive information like your name, profile picture, gender and networks.
When in doubt, use the "Preview my profile" button on any privacy settings page to check how your information appears to others.

Think carefully about who you allow to become your friend

Once you have accepted someone as your friend they will be able to access any information about you (including photographs) that you have marked as viewable by your friends. You can remove friends at any time should you change your mind about someone.

Show "limited friends" a cut-down version of your profile

You can choose to make people 'limited friends' who only have access to a cut-down version of your profile if you wish. This can be useful if you have associates who you do not wish to give full friend status to, or feel uncomfortable sharing personal information with.

Disable options, then open them one by one

Think about how you want to use Facebook. If it's only to keep in touch with people and be able to contact them then maybe it's better to turn off the bells and whistles. It makes a lot of sense to disable an option until you have decided you do want and need it, rather than start with everything accessible.

[Sophos]

Thursday, 24 February 2011

8 years for ID fraudster

An identity thief who fraudulently claimed more than £1.3m in tax credits under false names has been imprisoned for eight-and-a-half years.
Olaide (John) Taiwo, 35, a security guard from Camberwell, South East London, who was earlier found guilty of conspiracy to commit tax credit fraud and acquiring criminal property, was jailed at a sentencing hearing at Inner London Crown Court on Tuesday. He was convicted along with a female accomplice, Olajumoke Ademuyiwa, who faces a sentencing hearing in April, of conspiring to steal the identities of at least 350 people before submitting more than 300 fraudulent tax credit claims.
Ademuyiwa, 42, of Canning Town, London, abused her position as a a Jobcentre Plus employee to obtaining the details of low-income people who might be eligible for tax credit repayments. These payments were directed towards accounts controlled by Taiwo and Ademuyiwa.
The scam ran from June 2004 until July 2008, when the fraud was detected and an investigation launched that ultimately resulted in the August 2010 arrest of Taiwo. HMRC investigators seized "details of numerous bank accounts held in the defendants’ names and aliases, plus documentation which held hundreds of innocent people’s identities". Investigators also seized £70,000 as suspected proceeds of crime pending the conclusion of confiscation proceedings, which remain ongoing.
Richard Young, senior investigating officer for HM Revenue & Customs (HMRC), said: "This pair ... deliberately attacked and abused a system designed to provide financial help to the most vulnerable people in our society. The sentences given will be a warning to anyone considering committing this type of fraud – it will not be tolerated. HMRC will pursue, prosecute and reclaim the financial gain from those found to commit these types of crime." ®

[The Register]