Showing posts with label idtheft. Show all posts
Showing posts with label idtheft. Show all posts

06 August 2007

Rating Credit Safety


Javelin Announces Security Elements of Dream Credit Card to Fight Fraud; Scorecard Ranks Best Card Issuers in Consumer Fraud Protection

[August 01, 2007]

Javelin Announces Security Elements of Dream Credit Card to Fight Fraud; Scorecard Ranks Best Card Issuers in Consumer Fraud Protection

SAN FRANCISCO --(Business Wire)-- Today Javelin Strategy & Research announced the security features of a dream credit card that put consumers in the driver's seat when it comes to protecting them from identity fraud and knowing exactly what's happening with their accounts. Javelin also announced the top credit card issuers that provide the best features that prevent, detect and resolve identity fraud. The findings are detailed in Javelin's comprehensive research study, "2007 Card Issuers' Identity Safety Scorecard."

"Card issuers have a golden opportunity to increase loyalty and retention, and strengthen relationships and their brand reputation, by giving consumers simple identity fraud prevention tools they like to use," said James Van Dyke, President of Javelin Strategy & Research. "Identity fraud is a major pain point for consumers and can damage the relationship between the consumer and the card issuer."

Why it's important to address identity fraud today

Last year, 8.4 million Americans became victims of identity fraud, with total fraud amounting to $50 billion. The average victim paid $587 out-of-pocket for fraud on an existing account. If the thief opened a new account in the victim's name, the average victim paid $792. On average, victims spent 25 hours resolving their fraud case(1).

Security elements of a dream credit card for protection against identity fraud

Javelin's research has determined the optimal combination of available, effective tools and policies that best protect consumers. Below are the ideal security elements of a dream credit card and research findings in support of them:

For Fraud Prevention

-- Provides customers the ability to restrict or allow certain types of transactions (e.g. cash advances, foreign transactions, card-not-present transactions).

-- Uses identifiers other than social security numbers for identity verification.

-- Truncates all customer-sensitive data while interacting with customers.

-- Encourages customers to protect their home computers with anti-virus software by partnering with security software vendors (e.g. Bank of America's partnership with Symantec).

-- Offers photo of account holder on card.

For Fraud Detection

-- Provides mobile device or email alerts of high-risk changes to accounts (e.g. replacement card sent out, PIN or password reset, change of physical address or email address), initiation of higher-risk transactions (e.g. card not present, foreign transactions, activity on dormant account), and status of accounts (payment past due). Over two-thirds of account takeover cases are due to a fraudulent change of address. Alerts for changes to personal information are one of the top desired alerts by consumers.

-- Notifies customers of new account set-ups. New accounts fraud is traditionally the most difficult for consumers to detect. Credit cards continue to be the most abused category of fraudulent new accounts.

-- Facilitates consumer ordering of credit reports and credit monitoring services. New fraudulent accounts can be virtually invisible to a consumer without a credit monitoring service.

For Fraud Resolution

-- Institutes a comprehensive, up-to-date data breach resolution plan.

-- Provides an identity fraud assistance team to help customers affected by fraud.

-- Offers zero liability for fraud.

-- Offers next-day card replacement in addition to 24/7 account suspension capabilities.

-- Offers free identity fraud insurance.

The results of Javelin's Card Issuer Scorecard Study:

Overall: Safest card issuers

1. Bank of America (Visa Platinum)

2. American Express (Blue from American Express)

3. (2-way tie) Discover (Discover Platinum), First National Bank Omaha (Platinum Edition Visa)

4. Citibank (Citi Platinum Select)

5. Navy Federal Credit Union (Platinum MasterCard)

Fraud Prevention: Top card issuers

1. Citibank (Citi Platinum Select)

2. (3-way tie) Bank of America (Visa Platinum), First National Bank Omaha (Platinum Edition Visa), Navy Federal Credit Union (Platinum MasterCard)

3. Discover (Discover Platinum)

4. JPMorgan Chase (Chase Platinum Visa)

5. Nordstrom (Platinum Visa)

Fraud Detection: Top card issuers

1. American Express (Blue from American Express)

2. U.S. Bank (U.S. Bank Visa Platinum

3. Bank of America (Visa Platinum)

4. Discover (Discover Platinum)

5. (3-way tie) Capital One (Capital One Platinum MasterCard), First National Bank Omaha (Platinum Edition Visa), Wachovia (Wachovia Visa)

Fraud Resolution: Top card issuers

1. (12-way tie) American Express, Bank of America, Capital One, Citibank, FNB Omaha, HSBC, National City, Navy FCU, RBS National, State Farm Bank, Target, Wachovia

2. (8-way tie) BB&T, Commerce Bank, Discover, Nordstrom, Sun Trust, U.S. Bank, WaMu, Wells Fargo

3. (3-way tie) Fifth Third, GE, USAA

4. Advanta

5. JPMorgan Chase

Key findings from the report

-- Many issuers are not providing consumers with the ability to specify limits or prohibitions on particular types of account activity. Only 24% of card issuers provide user-defined limits and/or prohibitions (UDLAPs) on cash advances.

-- More than half (56%) of top card issuers still require full nine-digit Social Security numbers when interacting with customers, whether by phone, Internet or mail. This is a risky practice that unnecessarily increases the customer's exposure to identity fraud.

-- The number of issuers offering transaction alerts for transactions such as payment past due, new account set up, foreign transactions and replacement cards is a missed opportunity for issuers.

-- The lack of alerts for changes to personal information makes issuers especially vulnerable to new accounts fraud and account takeover. Only 16% of card issuers provide an alert for physical address change.

-- 84% of issuers report having a data breach resolution plan in place, given the ever-increasing awareness of incidents such as the TJX breach. Considering the tremendous risk to brand posed by a security breach, it is imperative that any issuer appropriately handle customer notification and assessment in the event that a breach occurs.

Where the industry can improve -- stronger fraud prevention and detection

To date, issuers have provided consumer security guidelines, multi-factor log-in authentication and online purchase authentication. However, this does not go far enough. Issuers have an opportunity to do better in prevention and detection.

Issuers can strengthen their brands and increase customer loyalty by placing some of the responsibility into the hands of their customers, specifically, by implementing UDLAPs on specified activities and dynamic, two-way alerts for suspicious transactions. Customers must also be given greater authority over their user profiles and have the ability to receive alerts for any high-risk changes to their records or any activity that they have defined as abnormal.

Javelin's research found that customers know their own spending habits best and can set the appropriate levels of security when armed with the ability to impose restrictions on their own accounts. "Consumers play an essential role in security, detecting nearly half of all identity fraud cases," said Rachel Kim, Javelin Risk & Fraud Analyst. "Consumers want to be involved in protecting their accounts, with 60% viewing this as a duty they share with their financial institution."

What consumers need to know

Because fraud can be committed through so many methods, consumers are advised to utilize a variety of the most effective measures to protect themselves. Note to editors: Javelin has prepared a document entitled "How Consumers Can Protect Themselves from Identity Fraud," which includes ways to avoid becoming a victim, ways to detect fraud, stop criminals and lower your liability, and ways to resolve identity fraud. It is available upon request or here.

The most comprehensive research on consumer-facing identity fraud features

Javelin conducted the most rigorous and comprehensive research on consumer-facing identity fraud detection, prevention and resolution features to date. Javelin ranked the nation's top 25 credit card issuers on the services and measures they have implemented in partnership with consumers to protect against identity fraud. It analyzed data supplied by the issuers' customer service representatives (CSRs) and consulted information available on card issuers' Web sites. Javelin researchers validated the process with firsthand reviews of actual features in selected cases.

The research employed a multi-disciplinary approach: statistical analysis, mystery shopping with senior level customer service representatives, and monitoring and review of features and policies on card issuer Web sites. The prevention and detection categories were weighted more heavily than resolution due to the greater potential benefits and cost savings.

For More Information

Additional information and a copy of the complete July 2007 Card Issuers' Identity Safety Scorecard, as well as other Javelin reports, are available at www.javelinstrategy.com/research or by calling (925) 225-9100 x26.

About Javelin Strategy & Research

Javelin is the leading provider of independent, industry-specific, quantitative research and strategic direction for payments and financial services initiatives. www.javelinstrategy.com.

(1) Javelin Strategy & Research, 2007 Identity Fraud Survey Report, February 2007.




It is nice to see a demonstration showing how easy it would be to knock out a substantial amount of account application identity theft. The reality is, (as was discussed in the posts Suing the Creditor For Liability and Identity Theft Protection For Healthcare Companies) the suggestions coming from Javelin may not protect a consumer from becoming a victim of Synthetic Identity Theft. The best protection for consumers would be not providing credit reports to creditors solely based upon a social security number. Like a consumer wishing to order their own report, the creditor should be required to submit a full set of PII and answer a consumer generated security question. The answer to the security question would be provided during the application process. The security question and answer would be on file with the credit bureau.

Secondly, the creditor should be required to run a skip trace and verify the identity of the consumer. If the identity does not match exactly, the creditor could either deny the application or request evidential documentation to verify the consumer's PII.

Third, making the creditor pay for any remediation services needed by a victim as a result of the credit issuers actions would serve as a direct incentive for the credit issuer to utilize every reasonable measure to prevent a fraudulent application from being approved.

Identity theft will continue to be a factor in the P/L of credit issuers for many years to come. However, reducing the impact and the number of victims is an achievable and realistic goal.

Stumble Upon Toolbar

03 August 2007

Junior's SSN

Protecting Your Child's Identity
By Aleksandra Todorova
Published: August 2, 2007


SENDING YOUR CHILD off to their first summer job is a proud moment for any parent. For Kristin Smith of Mesa, Ariz., however, that milestone marked the beginning of a stressful battle to reclaim her child's identity.

It all began in mid-July, shortly after her 16-year-old son started a summer gig at a local car dealership. His new employer conducted a routine background check that returned shocking news: A man living in Phoenix was using his Social Security number. Even more shocking was the discovery by the local police department that there was more than one perpetrator. In 1994, a man from Pennsylvania with a DUI arrest on his record had been using Smith's son's Social Security number as well.

Was there any other damage, such as credit cards or other loans taken out using her son's information? Frustratingly, Smith — whose name we've changed for privacy concerns — hasn't yet been able to find out. When she tried to pull her son's credit report from the three credit bureaus, her requests were denied. The bureaus were not able to confirm her son's information, most likely because his Social Security number was already in use by someone else. (For more on this type of Social Security number-only identity theft, click here.)

Smith is now sending out letters to the bureaus, along with copies of her son's Social Security card, birth certificate and other documents to prove that his information is being used fraudulently. Ideally, the phantom credit files attached to her son's number will be deleted and he won't have any difficulty obtaining credit on his own once he comes of age. But there's no guarantee the issue will be resolved that cleanly. The experience has been eye-opening for the now more vigilant Smith. "I have a 14-year-old daughter and now I have to watch out for her credit as well," she says.

Many parents don't realize how vulnerable their children are to identity theft. Typically, a child is issued a Social Security number soon after they're born. Parents need that number for tax returns, but beyond that, it isn't really put to use until the child first applies for credit or a job when they're 18 or older. As a result, if someone uses the child's number — whether in combination with their real name or using a fake one — the fraud could go undetected for years. "It creates an 18-year window of opportunity," says Linda Foley, founder of the Identity Theft Resource Center, a nonprofit organization that helps victims.

No one knows for sure how many children become victims of identity theft. In 2005, roughly 5% of all identity theft complaints received by the Federal Trade Commission were about victims 18 years old or younger. But that might be a significant underestimation since not everyone files a complaint with the FTC. For example, a large portion of child identity theft cases remain unreported because the thief is a parent or close relative. "If the perpetrator is the parent, they won't be calling," Foley says.

In Mesa, Ariz., the Smiths' brush with identity theft is just one in a recent string of similar cases that Helen Simmonds, a detective in the local police department, has been handling in the past months. She notes that almost all involve Social Security numbers issued in the early 1990s to children who are now turning 16, 17 and 18, and trying to obtain credit for the first time. "We think there's going to be an epidemic [of such cases]," she says.

Prevention: Credit monitoring
With all that in mind, it's no surprise that credit-monitoring services are beginning to target concerned parents, offering to monitor their child's identities for just a few bucks. At LifeLock, credit monitoring for your child costs only $25 a year in addition to the $10 monthly charge for adults.

Sounds like a deal, but parents can easily avoid these costs by doing the job themselves, for free, says Adam Levin, chairman of Identity Theft 911, a company that works with institutions, such as banks and credit-card companies, to provide identity theft prevention and resolution services to their customers.

LifeLock, for example, requests a child's credit report once a quarter, according to Todd Davis, the company's CEO. Parents can do that themselves, and if there is no report for the child, they won't have to pay a dime. (Keep in mind, the procedure for requesting children's credit reports is slightly different than those for adults. See table for details.)

"The important thing for parents is to periodically run reports through the credit bureaus," Davis says. "If nothing comes back, you're fine." If the bureau finds a report but is unable to confirm your child's identity, that's a red flag. A perpetrator might be using your child's number with a different name, or your child's name and number, with a different address.

There is one exception: Experian's recently launched FamilySecure monitoring service will alert parents as soon as anyone applies for credit using their child's name. But at $19.95 a month, the cost is steep.

LifeLock also claims to "audit the Social Security Administration" once a year to find out if there's been any work history reported for the child's number. An SSA spokesman says parents can simply call their local Social Security office and get that information, also free of charge. Keep in mind, if an impostor is using your child's Social Security number, but with a different name, the SSA will not find a matching record for your child.

Disaster response: Navigating the credit bureau maze
What if you find that your child has been a victim of identity theft? The credit bureaus claim this shouldn't have harmful consequences if parents follow the necessary procedures to report the fraud. "We can investigate to see if the child's information has been used and if it has, we can prevent it from being used in the future," says Clifton O'Neal, a spokesman for TransUnion, one of the three major credit bureaus. The procedures, however, differ widely among the credit bureaus and can be frustratingly confusing.

At Experian, for example, as long as parents provide a police report they can place what is known as a "victim statement" on their child's credit file. That means the bureau will attach a note saying the credit information belongs to a minor and warns creditors not to approve credit applications until the child turns 18. TransUnion will "cloak" the victim's file, hiding it from creditors entirely. Equifax said it will delete any fraudulent information from the child's report, take it offline and flag the Social Security number as belonging to a minor, so it cannot be used until the child turns 18.

Bottom line: If your child falls prey to identity thieves, calling just one of the credit bureaus — a common scenario in adult identity theft cases, since each bureau is required by the Fair Credit Reporting Act to inform the other two — isn't sufficient.

Carol Gomez, a homicide detective in Mesa, Ariz., experienced this firsthand when her car, an unmarked police vehicle, was stolen earlier this year while she was on duty. The car was later found, but her purse was missing, along with both her and her 11-year-old son's Social Security cards. The credit bureau she contacted placed a security flag on her credit file, but not her son's, since he didn't yet have a file. "They said that since he was a juvenile, they wouldn't be able to put an alert on his file," she says. "They didn't act like it was a big deal. And we know that it is."


Click to Expand


Links in this article:
1http://www.smartmoney.com/debt/advice/index.cfm?story=ssn2004
2http://www.familysecure.com/
3mailto:childidtheft@transunion.com



Except for using Lifelock as a source (other than for marketing) which is a questionable decision, overall this is a useful article.

Child victims of identity theft more often are made a victim by a family member than not. It is increasingly the case that identity theft perpetrators are looking for children's Social Security Numbers as part of a synthetic identity theft, a routine utilizing various alias identifiers merged together. This sort of fraud is harder to track down and the credit bureaus disclosure policies often conceal the fact from a consumer their SSN has been used with an alias name.

When a consumer becomes a legal adult and applies for credit after their SSN has been used previously, they can find it quite difficult to establish their true identity. The perpetrator often appears on the credit report and in skip tracing as the true consumer. Correcting the problem of minor identity theft is a time consuming process and not what one wishes on a young person beginning their adult life.

Stumble Upon Toolbar

02 August 2007

Suing the Creditor For Liability


May an Identity Theft Victim Sue the Lender that Allowed the Thief to Open the Account?
from the CL&P Blog


Suppose an identity thief takes out a loan in your name with a lender, defaults, and so blemishes your credit record. Do you have a claim against the lender for opening the account ? (The question of what the lender's obligations in its role as a furnisher of information is dealt with by the FCRA in § 1681s-2 and I won't address that in this post.) Up to now, the answer has usually been no. If you could show that the lender had obtained your credit report and that it lacked a reason to believe that the imposter was in fact you, then under FCRA § 1681b the lender would have obtained your credit report without a proper purpose, and it would be liable. See Andrews v. TRW, Inc., 225 F.3d 1063 (9th Cir. 2000), rev'd on other grounds sub nom. TRW Inc. v. Andrews, 534 U.S. 19 (2001). But often the lender will indeed have a reason to think that you are the person applying for credit. Many common law claims are preempted by FCRA § 1681h(e) and courts have generally rebuffed consumers arguing for creation of a new claim, such as negligent enablement of imposter fraud. See, e.g., Polzer v. TRW, 256 A.D.2d 248, 682 N.Y.S.2d 194 (1st Dept. 1998). But a new case offers more hope to identity theft victims. In Wolfe v. MBNA America Bank, 485 F.Supp.2d 874 (W.D.Tn. 2007), plaintiff alleged that the defendant had issued a credit card to an identity thief using the plaintiff’s name without verifying the accuracy of the information in the identity thief’s application. The court refused to dismiss plaintiff’s negligence claim, saying:

With the alarming increase in identity theft in recent years, commercial banks and credit card issuers have become the first, and often last, line of defense in preventing the devastating damage that identity theft inflicts. Because the injury resulting from the negligent issuance of a credit card is foreseeable and preventable, the Court finds that under Tennessee negligence law, Defendant has a duty to verify the authenticity and accuracy of a credit account application before issuing a credit card. The Court, however, emphasizes that this duty to verify does not impose upon Defendant a duty to prevent all identity theft. The Court recognizes that despite banks utilizing the most reasonable and vigilant verification methods, some criminals will still be able to obtain enough personal information to secure a credit card with a stolen identity. Rather, this duty to verify merely requires Defendant to implement reasonable and cost-effective verification methods that can prevent criminals, in some instances, from obtaining a credit card with a stolen identity. Whether Defendant complied with this duty before issuing a credit card in Plaintiff's name is an issue for the trier of fact. Accordingly, Defendant's motion to dismiss Plaintiff's negligence and gross negligence claims in the first factual context is DENIED.

The court also found that plaintiff’s allegations stated a claim under the Tennessee UDAP statute and were not preempted by the FCRA.

Posted by Jeff Sovern on Thursday, August 02, 2007 at 11:52 AM in Identity Theft | Permalink




This is good news for consumers. Creditors should take extra precautions to prevent opening fraudulent accounts. The calculation by credit issuers of whether to open the new account without verifying the identity of the applicant thereby risking an identity theft versus the cost of losing the consumer's business along with the additional cost of performing due diligence on the application may have changed.

Until now, the value of the loss due to fraud has been deemed a measured risk cost of business compared to the need to sign up new accounts quickly. The more accounts, the greater profit from the business of collecting fees and interest.

For a credit based identity theft to be successful, the address of the victim must somehow be changed or appear to be changed by the perpetrator. This is always the case with true name fraud. With synthetic identity theft, the creditor may be eager to approve the application since the synthesized identity has little or no credit history (more risk, more interest). To verify the application by attempting to contact the consumer based upon skip trace results and not the application would be responsible but bad business, until now.

"Rather, this duty to verify merely requires Defendant to implement reasonable and cost-effective verification methods that can prevent criminals, in some instances, from obtaining a credit card with a stolen identity."

The cost of not performing an ID check on the identity (not the application) may have just increased to the advantage of the American consumer who pays for fraud losses at the check out lane. This is a situation to watch.

Stumble Upon Toolbar

What Words Offend Arabs? The Truth.

Children's Poetry Booklet Recalled After Arabs Complain
(Israeli censorship kowtows to Arabs.
When Will We Tell The Truth Without Fear)

(IsraelNN.com 7 Sivan 5768/June 10, '08) Ynet's web site and Arab complaints against a ten-year-old boy's poem about terrorists has resulted in the recall of all of the Nes Ziona municipality's children's poetry booklets.

Ynet boasts that its coverage of the poem resulted in its being recalled.

The text of the poem (Ynet's translation):

Ahmed's bunker has surprises galore: Grenades, rifles are hung on the wall. Ahmed is planning another bombing!What a bunker Ahmed has, who causes daily harm.Ahmed knows how to make a bomb. Ahmed is Ahmed, that's who he is, so don't forget to be careful of him.We get blasted while they have a blast!Ahmed and his friends could be wealthy and sunny, if only they wouldn't buy rockets with all their money.

Poetry competition director Marika Berkowitz, who published the booklet, was surprised at the protests and told Ynet: "This is the boy's creation and this is what he wanted to express. Of course there should be a limit, but I think the there is no racism here. 'Ahmed' is a general term for the enemy. These are the murmurings of an innocent child."

The Education Ministry told Ynet: "The local authority that published the booklet should have guided the students in a more correct manner through the schools. The district will investigate the issue with the local authorities."
4Torah.com
4Torah.com Search from Pre-Approved Torah sites only
Photobucket
Custom Search

Twitter Updates

    follow me on Twitter