Posts

Showing posts with the label ID Theft

UK Identity Fraud on the Rise

Image
UK identity fraud is on the rise according to the latest research by Equifax. The data shows UK ID crime is going up within all age groups, with those living in the London and Manchester areas increasingly the most likely to become victims of ID fraud. Equifax has asked me to share the following infographic on their research, which includes good advice to stay protected. Are you losing your identity? We look at the growth of identity fraud and what can be done about it

Stay Safe from Cyber Crime - Top Ten Tips InfoGraphic

Image
Given I am regularly asked to explain cyber attacks and then advise on how to protect against them, particularly to home users of late, I thought I would try my hand at creating a simple InfoGraphic to help. It was a challenge to create due to the limitation to the amount of space for text, which means you can't cover everything and you can't go into much detail. However concise messaging is kind of the point of infographics, especially when using them as awareness tools.  This InfoGraphic is squarely aimed at the average "home user", it highlights what the bad guys are after, their most popular and most successful attack methods, and then provides 10 tips to help avoid and detect home user cyber attacks, simples. If this InfoGraphic proves popular I'll create some more, starting with one covering home IoT Security advice, another subject I'm regularly asked about at the moment. Download full version here

Dealing with persistent web based harassment in the UK

Even in 2013 reporting internet crime to the UK police force is a hit and miss exercise, and is certainly more miss unless you are a celebrity, or report the crime in the right way.  Here is my advice on reporting continued (persistent) web based harassment. If you are aged 16 and under, and are suffering from online harassment, you must tell your parents, teacher or legal guardian. 1. Identify your harasser If you are subjected to weeks and months of persistent anonymous harassment over the web, 9 times out of 10, it will be by someone you know. You can work out who it is likely to be, by examining the nature of the harassment;  the type of language used, the subjects they harass you about, the websites they harass you on, and your own recent history in disagreeing and falling out with people, these are all clues to who your harasser is. They tend to be people who likely will bare a grudge against you; ex-boyfriends are very typical. I...

4 Ways Your Child is Vulnerable to Identity Theft

Scary American made awareness video on Child identity theft by Good Money .  It's titled "5 Ways", but it's actually 4 ways for UK parents, we can ignore number 2 on Social Security numbers. My recommendation is to educate and monitor your children/teenagers online activity, and teach them to secure their personal information digital footprint online. 5 Ways Your Child is Vulnerable to Identity Theft Online from Good Money by CreditScore.net on Vimeo . According to the United States Bureau of Justice Statistics, in 2010, 7% or “8.6 million households had at least one member age 12 or older who experienced one or more types of identity theft victimization.” But identity theft is not just reserved for tweens and adults. In this age of information, children are increasingly vulnerable to the same kinds of attacks that cripple credit scores and bust bank accounts. Check out this video to learn about five ways you could be exposing your child’s sensitive...

The Spy Next Door: Stealing your life for £44

Image
How easy can it be to steal your life?  For less than 44 quid is it possible to steal your bank account username, password and bank account security questions? For less than 44 quid is it possible to harvest your credit card details, including your credit card security code and Verified by Visa or MasterCard SecureCode password? Is it possible to read your private Emails and access your Email account?  Is it possible to monitor all your private web surfing habits and instant messenger conversations, and obtain your username and passwords for all your websites? Well for £43.83 all this is possible by using the Spy Cobra USB drive .  Once plugged into your Windows PC, it installs a hidden monitoring application in less than 20 seconds, after which the drive can be removed. From that point on every single key stroke is recorded, it records all websites visited and even takes screenshots of what is displayed on the screen, and stores these screenshots at regular intervals. T...

How Secure is your UK Online Banking?

Image
The UK maybe still in the midst of a recession, but these times are proving anything but a recession for cybercriminals, as UK Online Banking fraud is sky rocketing at the moment. The ‘Financial Fraud Action’ showing a 55% increase for the first half of 2009, while the ‘UK Payments Administration’ figures reports a 44% year on year rise. Through my own research and underground monitoring of UK cybercriminal activity, I am seeing increasing numbers of stolen UK online bank account access details being put up for sale, and increasing numbers of keylogger malware being deployed, which are specifically targeting the theft of UK online bank access credentials covertly. Despite these increases in criminal activity and years of warnings, UK banks still aren’t doing enough to protect their customers from the dangers of the internet. Many UK banks are still yet to provide their customers with a security best practice Two-Factor authentication access to their online banking, so are making it...

Protect Your Identity & Don’t Implicitly Trust

Image
I was looking at new cars over the weekend, I saw a car I liked and naturally wanted to take it out for a test drive. On making this request, the car sales guy immediately asked to see my driver’s license or credit card.  A little puzzled by the “or credit card”, I asked whether he needed either one to prove I was lawful to drive, or for identification purposes.  The sales guy said told me it was their policy, and need it to prove my identity and to keep hold of for “security” while I took the car out. Identity theft is the fastest growing crime in the UK, and there are certain elements which we cannot control in protecting ourselves, such as when companies lose or have stolen our personal information. But there are many elements we still can control, such as protecting the personal information we have in our possession. A UK driver’s license is one of the strongest forms of proving our identity in the UK, and therefore has value to identity thieves, who can easily clone fa...

Credit Crunch causing CyberCrime Shift

The "Credit Crunch" is not only fuelling more cyber crime and online fraud, but the latest malware, phishing and fraud trends show the credit crunch is having an affect within the sinister cyber criminal underworld. It seems the bad guys are having trouble opening new fake accounts, obtaining credit cards with stolen identities, and are even having trouble getting store credit using fake identities. Why? Well it is because the financial industry have been cracking down and fully vetting credit applications (about time). You really have to ask why it has taken the near collapse of the world's financial system to kick financial institutions into properly checking just who they are actually going to provide credit to, after all that’s what caused all this credit crunch mess in the first place, right? So this is good news on the identity theft front, but as always in cyber fraud the bad guys just move onto the next lowest hanging fruit, and so are increasingly going after...

And Yet another UK Government Data Breach

It's the same old recipe...Take one UK Government department, a couple of Discs, copy thousands of records containing sensitive personal data of UK citizens on the Discs unencrypted and then post. Don't these people ever learn! This time it was the turn of Driver and Vehicle Agency (DVA) in Northern Ireland who dispatched two discs by Parcelforce on either 20th or 21st November. The discs holding around 6,000 people's personal details, never arrived at the intended destination, namely the DVLC Headquarters in Swansea. The head of the DVA said the information was not encrypted and included the details of 7,685 vehicles and more than 6,000 vehicle keepers. The data included the keeper's name, address, registration mark of the vehicle, chassis number, make and colour. The DVA also said they were not optimistic that the discs would ever be found. I'm not even going to post any more on this, in fear of repeating myself, just read my last post made last Friday... ...

UK Government InfoSec is Systemically Broken

I don't really like knocking my own government, but their approach to protecting our personal information is like a banana republic. This week another government department, namely the Driver and Vehicle Licensing Agency (DVLA), posted over 100 questionnaires holding people's details including their dates of birth and "Motoring Offence History" to the wrong addresses. The DVLA said it was caused by human error, as if to say it makes this breach acceptable. So this is another government violation of the government's own Data Protection Act, however it pretty pointless fining these government departments isn't it, as it would be like fining yourself. There is just no "stick" to push information security in these organisations, it's not like the private sector where companies are heavily fined and breach publicity has a serious impact on a business brand, which is always important in competitive marketplaces. In my view there definitely needs to b...

HMRC: CDs should be treated the same as the Server Room

This is rapidly turning into the HMRC data breach blog! I post a lot about this issue at the moment because I have personal vested interest as do many others, there are further developments almost on a daily basis, and for anyone who cares about the security of personal information in the UK, this is still a huge issue which frankly still gives me great cause for concern, and provides much thought about data security in general, which I feel compelled to write about. Anyway, I was in discussion with several people today in regards the missing HMRC CDs, one view was that HMRC regarded the internal mail as "private" postage, a view which doesn't sit with me at all. The way I think about it is like this, if you were to copy the company's entire database, "The" Crown Jewels of the organisation to a piece of media. Shouldn't you be applying the same security measures as to the live database, as held on the Servers? Think about all the physical security as...

HMRC: More Discs Go Missing, Is it Foul Play?

Yet more CD/DVDs have gone missing within HMRC's internal postage system, this time a batch of 6 "discs" have disappeared in transit in between Preston and London. This incident was spotted by HMRC on 30th October and apparently held customer complaint conversations, which I certainly would regards as personal information. This is the third HMRC postage containing sensitive CDs which has gone missing within the same month, October 2007. Don't forget the CD which HMRC sent(lost) to Standard Life, which held 15,000 records, as reported on 2nd November, I can't forget that missing disc, as my personal details were on it! So I have to ask whether there could be foul play? I can't answer that for certain as I don't work for HMRC or know all the facts, however I'm going to have a go at speculating since two of incidents involve my peronal information. Organised criminals have been know to target large intuitions just for their data, going through exte...

HMRC: Emails Confirms Poor CD Password Protection

NAO have released details of their Email correspondence with HMRC leading up to the HMRC data breach, and answers a couple more questions I had with incident. Click Here for NAO Emails From the NAO Emails it is very clear to understand the HMRC data was zipped (compressed to make the data files smaller), likely with an application called Winzip. The so called password protection of CD we are told about is just a Winzip password, which wouldn't be very hard to defeat. See http://www.zipcure.com/ for instance. On analysing what was said in the Emails further and ignoring the political spin about them... NAO rep. states "I do not need address, bank or parent details in the download - are these removable to make the file smaller?" - Clearly NAO were not asking for the removal of the sensitive data for security, it appears the NAO wanted to receive a smaller database on the grounds of it being easier to manage on a single CD, i.e. a single zip file. This is contrary t...

HMRC: Who asked for the data and why?

I have now found out the answer to one of my burning questions in relation to the HMRC data breach. Which was, Why on earth would HMRC have any requirement to send the entire database outside their organisation? The lost HMRC CDs were destined for The National Audit Office (NAO), a body which scrutinises public spending on behalf of Parliament. http://www.nao.org.uk/ “The role of the National Audit Office (NAO) is to audit the financial statements of all government departments and agencies, and many other public bodies. We also report to Parliament on the value for money with which these bodies have spent public money. As well as providing accountability to Parliament, we aim to bring about real improvements in the delivery of public services.” As part of the preparations for the 2007/08 audit of the HMRC by the NAO, the NAO instead of requesting the usual sample of data to audit, requested a full copy of client benefit data. No doubt because the funding and costs of child benef...

HMRC: The Identity Theft Risk

Just to confirm what data was on those missing HMRC CDs (unencrypted): Full Name Full address National Insurance Number Date of Birth Partner's details Names Sex and age of children Bank/savings account details If those CDs fall into the wrong hands then half of the UK population are at increased risk at identity theft. I think the information would be difficult to use break into online bank accounts directly, although it's worth noting some people do use their children’s names as passwords and there are the odd password reset process which ask for your date of birth and mother's maiden name, but the fraudster would need to compromise the account holders Email account or PC. The real risk with this information is with Identity Theft, which is the UK's fastest growing crime. What is Identity Theft? - Simply put, it is when a someone assumes your identity and racks up credit\loans in your name with no intent of paying it, and/or commits to other fraudulent...

HMRC: UK's Biggest Data Breach Ever

The lost of two CDs holding 25 Million personal records by HMRC, is the biggest data breach in UK history, it's almost half the population. The data lost included children's names, full addresses, dates of birth, National Insurance numbers and where relevant bank and building society account details. How did this breach occur? In October, a junior HMRC employee downloaded the entire HMRC database and placed all the data onto two CDs, and then put the CDs in Jiffa bag and stuck it in the internal post for the attention of NAO, who requested it. This package never arrived at the destination NAO, so on finding out the same junior HMRC employee downloaded the entire database and placed the data on CDs again, but this time sent it by recorded mail, this did arrive. The lost CD is described as password protected by HMRC, however I would like to make it very clear the data on the CD is NOT encrypted, therefore is far from secure being read, and I understand the password system can ...

Shambolic HMRC loses yet another CD

It’s well documented on this blog, on how the UK Government department, Her Majesty's Revenue & Customs (HMRC), failed to protect my own and 15,000 others personal information,losing a couriered unencrypted CD a couple of weeks back, and then there was the incident with an unencrypted HMRC laptop going missing a couple weeks before that. Now they have completed the hat-trick big time, this time losing a bunch of CDs holding 15 Million children benefit records, which I understand held names, address, date of birth and bank account details for around 7 million British families. Apparently the CD went missing after being couriered between HMRC headquarters in Washington, Tyne and Wear and London, when exactly how this happened isn’t clear yet, however ministers have known about the problem for 9 to 10 days. I understand another HMRC internal investigation is underway, while the police are still investigating. So yet again the CD was sent unencrypted and yet again I wish to h...

Frank Abagnale's advice to me Re:HMRC

I know all about the various methods and processes in which HMRC could of protected my private information, but now my info could be in the wild and in the hands of bad guys, who better to give me some advice than Frank Abagnale. If you haven't heard of Frank, he's the guy the "Catch Me If You Can" movie was based on, after serving his time Frank provided consultancy to several banks, helping them to beat fraudsters, and he went on to be known and respected as a leading expert in Identity Theft. Here is his advice to me... "Sorry that this happened to you. Most of the time when identities are lost/stolen in this method, the people who steal the information sell it to a buyer who sits on it normally for about 2 -3 years. Unlike stealing credit card data where the credit card issuer can cancel the cards, you can't change your name, date of birth, National Insurance Number/Social Security Number, etc. So the longer they sit on the information the more valuab...

Lack of Data Discloure Laws

Well I lodged a complaint about HMRC with the Information Commissioner today, basically the guys who enforce the Data Protection Act, as I am still far from happy about the bad practice which led to my personal details being lost by HMRC, the time it took for disclosure and then being misled about the data encryption of the CD. I'll post up the response when I get it. Meanwhile I noticed my involvement with this was discussed on Martin McKeay's (and Rich Mogull's) excellent Network Security Podcast , by the way I heartily recommend this podcast for anyone who is interested in learning more about Information Security and the latest topics within the field. One interesting point was made about our lack of disclosure laws we have in the UK compared to the US, which I have to say is true, we don't have any clear laws on breach disclosure within the public and private sectors, we rely and trust companies and organisation ethics. I think it would of been a very dangerous ga...

HMRC Data Breach CD was NOT Encrypted

I phoned HM Revenue & Customers (HMRC) again today to obtain further clarification on whether their missing CD was encrypted or not, as on Monday I was categorically told by a HMRC representative the CD was encrypted, although he couldn't say what type of encryption was used, in fact I repeated the question three times to be sure. After reading conflicting press reports about encryption of the CD, I decided to phoned HMRC again today. This time I was told by HMRC the CD wasn't encrypted after all, so I was completely mislead by them on Monday then. This just goes from bad to worst. And get this, I was then told not to worry as although the names were readable within the files in the CD, my National Insurance, Date of birth and pension reference details would be "difficult" read! In other words the data was in an unformated state. I explained to the HMRC rep. that is was actually something to worry about, as it probably wouldn't take too long to render the ...