Showing posts with label identity theft. Show all posts
Showing posts with label identity theft. Show all posts

Thursday, October 8, 2009

Inactive Credit Cards Might Not be So

Maybe I shouldn’t be putting this information out there for just anyone to read because if it falls into the wrong hands it could be used wrongly. But for the rest of you take what I’m about to tell you as a caution.

We all get new credit or debit cards in the mail and they always have that paper sticker that instructs you to activate it by calling a toll free number from your home phone. Right? Right, you know the drill. And you probably assume that until you’ve called the activation line the card is dormant and secure. Right? Well, maybe, but not always.

It’s true that if someone should try to use some unactivated cards them they would be declined, but that’s not true for all cards. Some “unactivated” cards are actually live and could be used.
"Very few banks send out a card that can't be used, at least in low-risk situations," says Scott Stevenson, founder and CEO of Eliminate ID Theft, a credit protection service. "But I'd bet most Americans think you cannot use a card unless you call and activate it."

That means that someone could come along and take a card out of your mailbox and use it. You’ll probably never know if your card is actually inactive or not. Credit card companies, of course, tend not to disclose this information. Some cards allow only small purchases as a convenience to continue service for customers. A small purchase might be anything under $200. A few card companies do not set limits and a few others completely lock down their cards until activation.
So why do they bother with the sticker at all? Mostly it’s a fraud precaution. The activation procedure lets the card issuer know that the card has reached your home. It also can discourage would be thieves.

Whenever you receive a new card in the mail, first check to see that no one has tampered with the envelope. Then activate it and store it either in your wallet or a locked unit. Don’t leave unactivated cards lying around in your to-do pile. Remember, a large percentage of identity theft is committed by someone who knows the victim.

Oh, and if you’ve taken out a credit card that you only want to use for emergencies (not carry in your wallet) do be sure to activate it. If the card issuer sees that you haven’t activated a card after it’s been sent they will deactivate it for security purposes—usually after about one month.

Monday, September 28, 2009

Yard Sale Update, Craig's List and Spam

You're probably logical enough to figure out what this post is about by the title, but here are the details.

First of my yard sale did not go so well. However, like all experience it taught me some things, or one thing. Don't start your sale late in the morning. My daughter had soccer practice at 9, so I started the sale at 11a.m. I did post a sign on my garage that was large and clearly stated that we started at that time, and I don't think there was any confusion. It's just that garage sale mentality kicks in early and doesn't last that long. What I mean is that most people will get out early to get the best stuff. After a few hours of saleing they are exhausted. By 11 or so they are ready to go home, have some lunch and get on with their lives. I did sell a few items and had several people stop by saying things like, "Oh I wish I had seen your sale first...I just bought an X, but yours is nicer...Darn, I paid to much for this X at another sale." Whatever.

Originally I hoped that I could unload my stuff all at once and avoid Craigslist, but after the preparation and boring hours sitting in my front yard I turned back to Craig. I already had everything cleaned up and ready. So I took some pictures and did quick posting.

This morning I was excited to see that I had 8 replies to my items. But once I opened the first one my excitement died. (I'm sure you've guessed why) Here's what it said...

Goodmorning, Would you be interested in working online?
Bing™ brings you maps, menus, and reviews organized in one place. Try it now.
this message was remailed to you via:
sale-pbav6-1395391794@craigslist.org

There were 4 emails with similar messages. The "Try it now." was hyperlinked. I did not click it and have removed the hyperlinks for this post.

Four other emails contained messages similar to this one below (again, hyperlinks removed):

I saw the inStep trailer - found here: http://boulder.craigslist.org/bab/1395388031.html jumped out at me. I, too had been doing the same thing since I lost my job. 3months ago, it was aweful, but I needed to sell my boy's games just to make our house payment and it was most definitely the lowest point in my life.
Saying it was demoralizing couldn't even describe it right,but I knew I had to make the house payment or we would be homeless (I was already several months behind).Thank goodness that will be the last time I'll have to hurt my babies like that.
One of my good buds showed me what he's doing to earn ethical income working on his home computer. I couldn't believe he would share this with me, but I'm so grateful that I have been sharing this with anyone who needs a financial break and who might be in the same situation.
Thank God it's easy or I would not have been able to complete it, in additionit is the most financially stable I have ever felt before. I promise you'll find this link worth the 30 seconds it takes to look it over. Oh, there is the link: http://g4.ms/moreforus
Take great care, and Bless You!

The four previous emails all advertised Bing and came from hotmail.com addresses. The second set of emails all included links to "articles" and came from gmail.com addresses. The hotmail emails had sender and subject lines in all capital letters. Both sets of emails used similar subject lines, i.e. "RE: Kelty Backpack" which is the same as the name of my posting. The articles are linked through a cloaking service that could be used for marketing, redirecting and/or click tracking--or perhaps spyware.

It doesn't matter whether these are malicious or not, they are an annoyance at the least and potential dangerous. Virus software is not enough to protect you--you've got to be proactive as well.

Friday, September 25, 2009

Skimmers do Exist

This is a security camera video of a man in Brazil installing a skimmer onto an ATM. This guy was caught and arrested, but the video shows that it's alarming easy to do and not so easy to detect.

Wednesday, September 23, 2009

How to Really Destroy a Credit Card

I am not sure what my dad was thinking, but whenever he had an expired credit card he would give it to me to bend back-and-forth until it broke. Then he would toss it in the trash. Did he think this was fun for me? Well to this day I can’t stand that task or the smell of plastic on my fingers. Back then this might have been an effective way of thwarting credit card theft, but today you need to be extra cautious.

When you cut up a card you shouldn’t just simply slice the thing in half. You’ll need to slice each set of four numbers into six pieces (see the video below). You’ll also need to cut through your signature and the magnetic strip.

Really don’t forget that magnetic strip it contains a lot of information about you. Running a magnet over the strip will scramble the data. For even more insurance take a hammer and bang it along the strip to smash any RFID chips that may be embedded.

Some home shredders are capable of slicing credit cards. If you choose to use a shredder be sure it has cross-cutting functionality, so that your card is sliced and diced. A good shredder will have a slot to align the card for proper shredding and reduced jamming.

Don’t assume that you can safely toss your old cards into recycling. Though they might be expired thieves do know how to extract data. Recycling centers often employ more hand picking techniques and could be even more risky for identity theft.

I guess some people burn their cards, at least that’s what I’ve heard. While it does completely destroy the data, I wouldn’t recommend this because it is environmentally bad and stinks.
Once you’ve chopped up your card, even if you use a shredder, separate the pieces into at least two different trash bins. That way they have less likelihood of being pieced back together.

This video shows you how to simply and effectively destroy any plastic card.

Thursday, September 10, 2009

Quick Assessment of your ID Theft Risk

I stumbled upon a free service that assesses your ID theft risk in an instant. MyIDScore.com is by ID Analytics the same company that provides financial, healthcare, retail and government services with data intelligence and interpretation. ID Analytics’ network contains billions of basic identity elements such as name, Social Security number, phone number, date of birth, and address.

With My ID Score you type in some basic information such as name, current address, phone number and birth date. Within seconds the program scans it database to find previous address matches to narrow down the data.

You then get a scoring. Below is mine:
"A My ID Score of 463 indicates a MODERATE risk of identity fraud.
There is a moderate likelihood that information pertaining to you has or will soon be used to commit fraud endangering your good name. People with this level of risk are approximately four times more likely to be a victim of identity theft than the average consumer. Because your personal My ID Score is at an elevated level, and while no system can detect 100% of possible fraudulent activity, we recommend you take the following preventative steps as a precautionary measure:"

The precautionary measures include ordering your credit report, putting a fraud alert on your credit accounts and, naturally, ordering some of ID Analytics protection products.
My IDS core is not a credit score. Credit scores are calculated from the information held in the files of credit bureaus. My ID Score, in contrast, assesses the likelihood that an individual's identity information is being used fraudulently.

Though a little creepy, it’s not surprising that My ID Score can locate information about you. Have you ever Googled someone? It’s not hard.
I like the barometer reading on ID theft risk that this site gives, but I’m not likely to purchase one of their products. I would say that it is definitely worth checking.

Monday, September 7, 2009

Taco Bell I.D. Theft

Identity theft really can happen anywhere, even a Colorado Taco Bell. Three Colorado Springs residents were convicted last week for stealing credit cards from gyms and Taco Bell restaurants in Woodland Park, Broomfield, Lakewood, Canon City and Pueblo.

The article in The Gazette from Colorado Springs states that two men gathered credit card numbers from locked and unlocked gym lockers and from Taco Bell patrons. They used a skimming machine in a young woman's apartment.

A credit card skimming machine copies information from a credit card by reading the magnetic strip. The data thieves then use this information to make up fake credit cards that they use in person or for online transactions. These machines are disguised to look like any credit card swipe machine. That's why some identity theft protection literature will tell you to watch your card in restaurants. Sometimes they can be installed under the counter or in the back. If a worker leaves your site with your card you should be suspicious.

But this was not the case here. These people stole the cards and then took them to another location to skim.

Tuesday, September 1, 2009

How do you securely store passwords?


While our brains have an amazing capacity to store knowledge, it has been said that we only use 10% of this ability. I see that in this guy I know. He has an uncanny knack for remembering numbers. He can tell you the phone number and street address of everyplace he has ever lived within moments. But the guy loses his keys almost daily.

My friend is also great at remembering multiple passwords and logins. Most people aren’t, so we need to store them somewhere. Keeping them secure is the problem. There are basically three ways to do it:
1) Write them down,
2) Create a password protected file on your computer that includes all your usernames, account numbers and passwords.
3) Or, use technology.

I wouldn’t recommend the first option. Storage of a piece of paper is problematic. Where does it get stored? Will you remember where you put it? Is it convenient when you need it? If it is convenient, is it safe?

The second option isn’t bad, but doesn’t give me peace of mind. It is, however, the method I’ve been using. I use a Microsoft Word document that I’ve secured with a password, but over the last several months I’ve had this nagging feeling that it’s not enough. So, I’ve begun to explore the technology frontier.

There are many programs available to help store passwords. Ideally I’d like something that is highly secure, accessible through the Internet, and free. This isn’t as easy as it sounds. What I’ve found are a number of systems that could be accessible from anywhere but carry a price or downloadable systems that reside on my computer and are free.

Of the free I started using Password Safe. Like most of the programs I looked at Password Safe isn’t exclusively for storing passwords. Password Safe locks up any file on your computer of your choice. Password Safe does offer a U3 disk-on-key version for remote accessibility, but there is a nominal fee and really isn’t what I’m looking for.

Billeo is another free program. This one has a more sophisticated look than Password Safe. It also offers features that I wouldn’t use like a bill payment system. I’d say more about this program, but I couldn’t get the download to work.

1Password, is one that’s been recommended quite a bit. This one costs $39.95 after a free 30-day trial. There are applications for iPhone and Palm OS. I’ve heard that the iPhone app is $4.99.

Another system that was recommended is Roboform. The full version costs $29.95. There is a free version of this and it does have applications for Windows Mobile, Palm, Symbian and Blackberry.

After looking at all of these options I’m sticking with the basic Password Safe for now. It’s not pretty and doesn’t have a lot of bells and whistles, but that’s just fine. Most of the other programs offered much more than I was looking for which made downloading complex and time consuming. And I don’t need to pay for a bunch of features that I don’t really need.

What do you use to keep track of all of your passwords?

Friday, August 28, 2009

Read This Before You Recycle Your Old Cell Phone

This post originally ran on August 29th, 2008.


Recycling your old cell phone is a great idea and many charities accept used phones that they can either turned into cash or give to clients in need. But before you drop your phone in a collection box remember it's filled with personal data. You should remove personal information before you dispose of your phone. Permanent deletion usually requires several steps.

First, if you use a memory or subscriber identity module (SIM) card remember to remove it from the phone.

You'll also want to remove the following: contacts, any lists of calls (received and made), voicemails, sent and received email and text messages, organizer folders, Web search history and photos.

But manually deleting this information may not permanently erase the data--only the references to the data storage. The actual information is lodged deep within the phone's operating system.

The simplest way to completely erase the data is to take it to your provider. When you upgrade your phone take the old phone with you. Most providers will transfer the data to the new phone. But remember to ask them to wipe out the old phone. And you must ask for this because it's not part of their routine. The service is usually free as long as your upgrading. Some providers have a written policy that without an upgrade they will charge a fee to transfer and remove data. Still it's usually a nominal amount and well worth your peace of mind.

If you are the do it yourself type you'll find instructions on how to permanently remove all data in your phone's user manual. Your service provider may also list instructions on their website. But you better know what you're doing because I don't want you dropping my name and phone number into some data collection box and neither does anyone else.

Wednesday, July 15, 2009

Beware of Handsome Strangers


A good looking person catches your eye at the mall and begins conversation. Could it be a love at first sight or just a clever scam?

Canadian police are warning shoppers of debit card thefts that include distraction from a handsome stranger.

As reported by The Gazette, a Canadian publication:

“…fraud artists have been active for months and have developed a method where they follow a target through a large retail store, peek over their shoulder as they enter their PIN while making a purchase at a cash register and then approach the unsuspecting person outside the store.
In some cases, the person used to create the distraction is attractive and speaks with a European accent while asking for help with street directions.
Within the brief amount of time a person is distracted, their wallet is snatched away and their debit card is cloned. The wallet is returned without the victim noticing, but their bank account is quickly cleaned out.”

The comments on the article whose intent is to warn the public are rather interesting:
Bonzola “ I would be happy to pay the price for having an attractive person talk to me.”
DON'T LET THEM GET CLOSE TO YOU “While performing a transaction, don't hesitate to "accidentally" elbow someone in the face if they don't respect your space. It's very easy to suddenly get scared and have an involuntary reaction. If people start getting hurt, word will get around and people will start to behave correctly and respecting the privacy and space of others.”

Remember what your mother said about talking to strangers.

Thursday, June 4, 2009

Should you have a safe deposit box?

Sometimes I live in the land of make believe. I "believe" that I've got everything under control. What usually happens when you live in a fantasy is that something rudely awakens you. This time I'm waking myself up before that rude awakener comes along.

Last night I was clearing out my electronic reading. That's stuff like my Google reader feeds and emails that I've saved for later reading. I came across an article about safe deposit boxes. I almost clicked delete thinking that I knew everything about them. But I read it anyway and it got me thinking...

When I used to work at a credit union safe deposit boxes were a hot commodity. You literally had to wait for someone to die to get a box. I'm not that patient so we've always had a fire proof box for important papers. Honestly, I couldn't understand why anyone would pay between $30-$75/month for a box at the credit union or bank. Well after reading a small blurb I did some Internet searching and discovered that my cheap little fire proof box is just a false sense of security.

Safe deposit box vs. Home box

Safe deposit boxes are kept in a bank or credit union's vault. The companies that manufacture safe deposit boxes and the vaults that house the boxes make them highly "resistant" to fire, flood, heat, earthquakes, hurricanes, explosions or other disastrous conditions. However, the key word here is "resistant." There's no 100 percent guarantee against damage, and substantial losses sometimes occur.

Home boxes vary in their resistance.

  • Theft: A thief might pick up the entire box and carry it away to pry open later.

  • Fire: Though manufactured to resist high heat, the box should be kept where it is least likely to succumb to fire/heat. The best places are lodged in cement, like in your basement or garage floor or walls.

  • Earthquake, flood and other disasters: Many boxes are designed to endure one or two dangers not multiple like say a fire and a flood.

Safe deposit boxes are not covered by deposit insurance. The FDIC and NCUA do not provide insurance for the items in your safe deposit box. Your home owner's insurance also does not cover your safe deposit box. You can insure these items, however, you'll need to discuss that with your insurance agent.

Home boxes are covered by your home owner's policy since they reside in your home.

Be careful about what you put into a safe deposit box. Do not place your original will in a safety deposit box. State vary on laws regarding who can access the box. In Colorado, if you should die only a named beneficiary may open the box upon your death. (Unless the State has reason to access.)

Also don't put in documents that you need to access frequently or in a moments notice, since you'll have to wait until the credit union or bank is open for access.

At least one article that I read on this topic claimed that a safe deposit box is cheaper than a good home box in the long run. I still don't know about that. But I do know that the little box I keep in my home office isn't worth a dang.

Wednesday, May 20, 2009

Check Your iTunes Purchases

Here's another reason to pay detailed attention to purchases charged to your credit and checking accounts. Rapant fraud has been running around for some time connected to iTunes. This article from the Consumerist points to a story that ran on Fox news.

The story is that some consumers are finding fraudulent iTunes purchases on their accounts. You don't have to be a user of iTunes to become a victim. As Fox reported no one seems to know how these purchases occur or who is behind them. The only way to solve the problem once you've been hit is to report it to the financial institution and close the account.

Curiously over at WiseBread writer Torley Wong tells of the experience he had while searching on eBay. Wong found numerous sellers of iTunes gift cards for cheap, very cheap. These auctions were also a hotbed of activity. Wong eventually purchased a $200 value gift card for just $47. He was emailed the card information. He then went to iTunes to try it out. The card code worked and his iTunes account was indeed credited for $200. But Wong is not dishonest and the experience left him queasy thinking that it was somehow unethical.

Even my poor detective skills smell that Wong may have hit on stolen account data. Possibly this is connected to what Fox is reporting. But, however, I leave the sorting of the fraud details to someone else.

Meanwhile, it's vital that you watch your transactions. If you have several people signing on to your iTunes account like our family does it can be easy to just gloss over the charges. You've got to look at the detailed receipts and confirm that the purchases are legitimate. Often the thieves will test the waters by making a small $.99 purchase. If they are successful then they go in for a bigger hit.

Remember, however, you do not need to have an account with iTunes to become a victim. These charges will show up with APL*ITUNES in the description. I use Mint.com to manage our spending and usually Mint will throw the iTunes purchases into miscellaneous. So I need to check for the APL *ITUNES description to review these transactions.

Wednesday, May 13, 2009

Who’s Behind Phishing Scams

“Why did you send me this scam!” That’s the G-rated version of what some people say when they call to complain about receiving a phishing scam.

It’s easy to understand the recipient’s anger. Receiving a phish whether on the phone or through email can seem like a personal invasion. They’ve got your number. They know where you bank. They know that you use e-Bay. Or do they?

The whole reason these scams fall into the phishing category is because like actual fishermen, phishers throw out a lot of bait in hopes of making even just one catch. They don’t really know where you specifically conduct financial business, but there making a pretty good guess.

Phishing scams can be documented as early as 1996. Back in 2003, Internet access provider Earthlink became so angry over phish scams sent in their name that they went on a manhunt. What they found was a bunch of kids in Eastern Europe and Asia. Today it’s not uncommon for more than 250,000 phishing attempts to be sent in one day against any one financial institution. But it’s not just bored teenagers anymore. Phishing has become a complex organized crime. According to a report by Cloudmark, Inc. “Phishing does not occur in isolation, but rather, operates within a complex network. In fact, individuals involved in phishing do not typically understand how to orchestrate an entire phishing attack.”

This flow chart (you can click to enlarge) created by Cloudmark shows the various steps in creating a single phish scam. The individuals involved in each component probably don’t all know each other they are just performing their task.

The recipient lists can be acquired in numerous ways. One way is to just randomly generate email names with common provider extensions. Another is purchase lists via the black market. It isn’t unusual for one individual to receive phish scams from several financial institutions within a few days. Remember, their phishing to get the right bait.

I don’t pretend to understand all the techno gobbledygook about how phish scams actually happen or operate. But I can tell you that it’s not your credit union, eBay, PayPal or any other reputable company that’s setting this up.

For consumers, phishing most often results in monetary loss. I read one story on the FDIC site that said that one victim responded to a phish at 12:10 am and money was taken from their account at 12:13 am. Frighteningly fast! But there’s more…

For businesses preventing phishing spoofs leads to rising costs in prevention and remediation, as well as brand-erosion and loss of customer trust.

What can you do to deter phishing? Be suspicious! And forward any suspicious messaging whenever possible to the organization being impersonated.

ONE LAST THING: Phishing isn’t restricted to email. Phish scams have been sent through phone calls and text messaging too. Don’t click links. Don’t press buttons. Don’t call back. Just don’t.


masked woman by greendragonflygirl

Tuesday, May 12, 2009

Sunny with a chance of door-to-door scammers

One fine day a young couple showed up at my door drunk and dirty trying to sell magazines so she could win some trip. It was late evening and starting to get dark. I know that I don’t have to answer the door but sometimes that is out of my control because 1) my 5 year old sometimes runs to the door and flings it open 2) sometimes we leave the wooden door open and just the storm door is closed.

Door-to-door salespeople are more than just a nuisance, often there are trained scammers. My recent run-in was similar to this scam in which teenagers are recruited to pull off a magazine selling scam. Some other common scam characteristics are:

- They may greet you by name, saying that a neighbor referred them. Actually they’ve sifted through your mail or some listing directory.
- They prey on your good nature by whining when you say “no” and claim that some children in a third-world country are counting on your support.
- They want to make it easy for you so they’ll split offer installment plans on your credit card.
- They’ll show you identification with a company name and their picture. But remember, anyone make something off a home printer.
- They’ll use tricks to slide into your home. Such as showing you how well their product cleans your dirtiest spots.
You stand to lose much more than a bit of cash to door-to-door scammers. If you do make a purchase and you give them a check or credit card number, you’ve just handed over valuable personal information.
If a product really seems legitimate, and it is something that you are interested in, ask for a brochure or business card. A legitimate product will always be available later. But don’t get talked into filling out a "request for information" or any other form. This is likely an attempt to collect your personal information.
Of course you have the right to just not answer the door, but that may not be the best idea either. In a recent rash of burglaries in my neighborhood the thieves actually posed as door-to-door salesmen. And, when a door wasn’t answered they attempted to open it anyway. For the homeowners who tried ignoring the initial knock the result was much worse.
Many towns and home owners associations are requiring door-to-door solicitors to register and attain permits before canvassing neighborhoods. That’s great because you always ask to see the permit and you’ll know which businesses are legitimate, but that’s not until after they’ve rung your doorbell.
I’m considering adding something that I believe to be very ugly to my front door. It’s a “No Soliciting” sign. I also don’t like them because I don’t want to scare off everyone. I want the guy who does our aeration to stop by because I can never find his phone number. I want the Boys Scouts and Girl Scouts to sell me cookies and popcorn. But, now that the weather is getting consistently warmer the door-to-door scammers are multiplying.
Oh well, what’s one little sign anyway? Hey, while I’m at it maybe I’ll put up a “No Pooping” to shoo away my neighbor’s dog, and then a “No Butts” for the Marlboro smoker who likes my lawn so much. Let’s see what else could I add….

Friday, May 8, 2009

Still Phishing After All These Years

This post originally ran back on June 22, 2008. The point was to let you all know that phishing is still a prevalent scam. Sadly though phishing hasn't decreased. It's gotten worse and know this type of imposter scam has spread to text messaging and telephone forms. Beware of anyone claiming to contact you from any company that you have a financial relationship with. No company that you do business with will ask for your account number, passwords or PINs by contacting you. They only ask for this info when you contact them.

WHEN IN DOUBT, DON'T GIVE IT OUT

Check out this email message from PayPal.

Yep, it's a fake. But you can safely click on these images. I captured them from an actual message that showed up in my email box yesterday morning. Get a look at how realistic this bait is. But then there's that tricky "Dispute" link.
I decided to click the link. But Internet Explorer picked up the phony. If the link were to work it would likely ask me for personal information like my PayPal login and credit card or account info.
Really, I'm am surprised that phishing is still so popular. Yet it must be lucrative since it's still going on. This particular message looks quite authentic. And since I hadn't made the noted purchase I might have actually fallen for the the "Dispute". But I'm not at all trusting of email that I didn't initiate and you shouldn't be either. Consider this a reminder--be suspicious.
Phishers are getting more sophisticated, but you can outwit them. And if you do encounter a phishing bait notify the Anti-Phishing Workgroup.

Friday, April 10, 2009

Locking Your Wallet in Your Car Won't Stop Theft

This post originally ran on June 9, 2008. But in re-reading it I am reminded of a disturbing event that occurred in Ohio in December 2008. The moral of this story is that your car holds valuable information--don't be careless. Thieves can access nearly anything they want if they try hard enough. The post states that they'll often leave your cash but might take a credit card. However, it's becoming more likely that they won't touch your wallet at all. Instead they take your registration and/or insurance cards which are much more valuable.


Everybody knows that it's not a smart idea to leave your wallet in a gym locker room. It doesn't matter if you have a lock or not. But the old advice of leaving your stuff in your car isn't working either.

Last year a posh health club near my home experienced a rash of car break-ins. In this case the thieves were smashing car windows and grabbing purses. The purses were easy to spot as they were usually hidden under a jacket or a blanket. Vehicles with car seats seemed to be a sure sign to thieves that something valuable would be within reach.
photo by Kevin Saff

But smashed windows are loud, messy and tend to draw attention. So now stylish thieves come prepared. They prowl gym parking lots, trail heads and baseball/soccer field parking lots were victims are likely to leave their wallet behind. All it takes is a little bit of locksmith tools and know how and their discreetly in your car. Then they look in the usual places: under a jacket, glove box, under the seat, or in the compartment between seats. They leave your cash and only lift a card or two. Then they re-lock your car.

This sneaky strategy is successful in fooling you for a bit. Your car is locked, your cash is there. So it may not be until you get to your next destination that you notice your Amex is missing. By that time at least 1-2 hours have passed and they've racked up thousands of dollars in high-end electronics and gift cards (gift cards are tough to track).

Earlier this year Aurura police busted a ring of parking lot thieves that made news around the country. They caught 20 people who made over $400,000 worth of stolen credit card purchases. They were reselling their purchases in various places including eBay.

No one needs the extra heart palpitations of finding your credit card was stolen while you were exercising. There's really only one way to avoid being hit--If at all possible leave your cards and valuables at home or carry them with you. This is tough to do when you're at the gym. If anyone has other suggestions it would be kind of you to share.


Thursday, April 9, 2009

Cell Phone Scam Alert


Recently another Colorado credit union reported that its members were receiving fraudulent calls to their cell phones. It works a lot like phishing. The recipient gets a call to their cell phone. Upon answering they will hear a recorded message such as, "This is a message from your bank, XYZ Credit Union, announcing that your Visa Debit Card has been temporarily suspended. Please dial 0 to reactivate your card." As you might have guessed, if someone presses 0, they are then asked to enter the debit card number, the expiration date and the security number.

Please don't fall for this. If you should receive a call like this be sure to capture the incoming phone number. Then contact the credit union or any other named financial institution and follow up by contact the Anti-Phishing Working Group.

Wow, that sure would be some fancy technology if your credit union could reactivate your card in this manner. But rest assured even if they could, they wouldn't. Remember, not your credit union nor any other financial institution would never ask you for ANY personal information such as account numbers, social security or PIN via the telephone or email.

Friday, April 3, 2009

Online banking in your underwear--good. Online banking in the coffee shop--bad.

I'm rerunning this post from September 5, 2008, because I'm so amazed that I encountered this situation again. Please don't try this in public.
photo by Daquella manera

Okay I didn't take that photo above and that's not my local ;) coffee shop ;), but if I had been thinking last Sunday I would have had my camera out because right before my very eyes was the most amazingly foolish person doing something no one smart enough to have a broker account should ever do. (Hey, stop correcting my grammar in that run-on sentence, just go with it.)

My friend and I were headed outside with our super designer coffees to enjoy the parking lot tables when we both spied said guy. He was sitting with his back to the door, laptop open and checking his Fidelity investments. We paused long enough that I could not only have taken a great photo but maybe sized up his portfolio.

Let's circle the things that are wrong with this picture. First, his back was to the door and he didn't not have an anti-peeking screen. Two, he was either blissfully unaware that anyone could see his screen or he wanted everyone to see his investment package. And three, he was using an unsecured connection. That's right not insecure--UNsecure--free wireless cafes are not password protected. I hope this is obviously wrong to the rest of you.

This is the kind of Internet banker that ID theives love. These theives sit in the parking lot attempting to swipe passwords and logins. Well, they might come inside, but I think they like staying in the car. They love to cruise by wireless cafes especially. However, just two nights ago my husband (I call him Robocop) claimed he saw a guy sitting across our street in his car for quite awhile using a laptop. Now the guy could be innocent, but these types of theives do cruise neighborhoods looking for hot, unsecured wireless.

I am a huge fan of online banking biggest. BUT I urge you and everyone you know to be smart about it. Your credit union, bank, investment broker spends oodles of money, thought and time into protecting your investments, but you must also be diligent. Don't believe that the https is enough. Only access your accounts through secure password protected communications. The more layers of security the better.

I probably should have told our guy to be more careful. Sorry man.


Monday, November 10, 2008

How to Safely Bargain Shop Online


This is the way that I shop online. I see something I really want, like a new pair of Keen shoes. I might go to the store and try them on, but usually I don't have time for that. So first I visit one of the online shoe stores, but maybe there's still more than I'm willing to pay. So I spend some time searching until I find a price that I like. Oh, but wait I've never heard of this retailer. Are they trustworthy?

Now it's time for investigation. Look for the obvious:


  1. Do they have a security/hacker prevention or testing certificate?

  2. Does the LOGIN process use an encrypted HTTPS page? Notice I've capitalized LOGIN, that's because you want the pages where you enter all your personal information to be secure.

  3. Does the checkout process use an encrypted HTTPS page? Naturally you want the payment pages to be secure.

  4. Read the privacy policies. It's so easy to just blindly click "Accept" here. But you should 1) ensure that there isn't a big blank after the small amount previewed in the acceptance screen and 2) read it to see if you agree with it.

  5. Find out how to contact the company if there is a problem. Keep the site bookmarked or better yet, write down (or keep an electronic file) of the company name, web address, customer service contact info.

Beyond this you can do some research to check out the company.



  • Search Google for the store name and words like "scam" and "customer service."

  • Check the Whois to see what the website registration looks like. It is not a good sign if it was just registered last week.

  • Check if the company has a yellow pages listing and street address. If you have a phone number, a company with a street address is a lot more reassuring. Check the address on Google Maps to see if it is a vacant lot.

  • See if the site has a warning listed on McAfee SiteAdvisor.

It can take a lot more time to go through this investigation. But it's worth it. You goal should be to get a good product at a great price from a company you can trust.

Thursday, November 6, 2008

Don't leave your stuff laying around

photo by imadoofus123
On Sunday I went for a beautiful hike. We've had such a gorgeous fall in Colorado. The trail was rather busy but encounters with other hikers were still spread far enough apart to make it peaceful. At the end of the trail I found a notebook. I'm sure I wasn't the first to find it since it was placed up on a sign with hope of being retrieved. As I was waiting for my friend while she used the outhouse I kept glancing at the book. Finally I couldn't help but discreetly flip through the pages. And then I couldn't stop myself from picking it up and reading.

My friend soon came to join me and inside we found someone's personal account of what they did every day. Most of it was mundane such as grocery lists or other errands, but as times the writing was more personal. There were several trips to the bank with records of who they talked to. Scribblings of money worries occurred over and over. This person was worried about banking security, Internet security and if their computer might fail and lose all their data.

Generally, this was a book filled with worry. You might think this was paranoid writing, but all these worries are things that most of think about from time to time. Is my bank safe? Could a computer virus detect my passwords? But the really disturbing thing about this notebook was that it wasn't protected. It was left out on the trail for nosey people like me and my friend to read. I could have easily gleaned enough information to figure out where this person lived, where their children go to school, and where they bank. Who knows if I'd read more maybe I'd learn some other key information. There were even a few first and last names of people the writer knows.

This carelessness is exactly how personal information gets stolen. Did you know that the majority of identity theft incidences are committed by friends or relatives--even kids? Think about all the bank statements, credit card information, social security numbers, bank account numbers that are in your house. It's sadly easy for anyone to get that info.

Be safe with your important documents and passwords. Invest in file cases that lock, safe deposit boxes, shredders, virus protection software and personal firewalls. Sure, these are basic precautions but it's surprising how so many of don't take the time to put them in place. I'm no different, my shredded broke from over use a few weeks ago and I've been too lazy to replace it. It's on my list to do before I have company come in this weekend.

As for the notebook, let's hope that it found it's owner, but who knows how many other curious hikers took a peak or more.

Tuesday, October 7, 2008

I guess it can happen to anyone...

Like most people I think I'm pretty resilient. But still I do take basic precautions. I wear my seat belt, shred anything that could be used to lift personal information, don't write down passwords or PINs. Still most of the time I don't worry about fraud or identity theft, because usually I don't fall for sketchy offers and keep things relatively safe. And then there's eBay.

A few days ago my husband received an email from eBay that his listing for a Tiffany necklace set had been posted. He asked me if I'd posted it. Are you kidding? I don't own or have access to such jewelry. I assumed it was a fraudulent email. But something didn't sit right so I looked at our account. Sure enough there was a posting for the Tiffany set.
I contacted eBay live help. They determined that the posting was fraudulent. So they removed it. Then they gave us a temporary password. They've got additional security that identifies the computer you are using. If you should login from a computer other than the one you've registered with then you'll be asked some basic security questions before you log in.
All seemed well and it appeared that our PayPal account had not been compromised either. Until we decided to check eBay again. Neil (my husband) tried to login with his new password--the one he created after logging in with the temporary given by eBay. The security questions came up. He answered them. They are not difficult. I think one was his birthdate. So we sure he answered them correctly. But he could not login.

Somewhere along the way he received an message from eBay that the account owner name--for our account--is Theresa. No one in our house is named Theresa. So here we go back and forth and hours online trying to get this straightened out. After sometime working on it yesterday, I had to give up and go to sleep.
So today I'll be back at pushing aside my real priorities and hopefully cancelling the eBay account. How did this happen? Not sure. Neil could have clicked a phishing email though he never mentioned anything like that. Meanwhile if you'd like to learn more about eBay login fraud here's a good post by the Auction Spider. You can also wait and see what unfolds next in this ugly web.