Help Prevent Home Robberies

Robert Siciliano Identity Theft Expert

Robbery as defined in Wikipedia is the crime of seizing property through violence or intimidation. At common law, robbery is defined as taking the property of another, with the intent to permanently deprive the person of that property, by means of force or fear. Precise definitions of the offence may vary between jurisdictions. Robbery differs from simple theft in its use of violence and intimidation.

In Lewisville, Texas the Star Local News Courier Gazzette reports a woman was just arriving home when she was confronted by a subject with a knife. He attacked her and stole her wallet. This victim also fought back and was able to take the suspect’s knife away from him, causing him to flee the location.

That’s a pretty awful situation, but one that the victim successfully survived and even made the attacker run. Many of us are told that when you are attacked to let it happen so it doesn’t get any worse. In some cases that may be your only option. Studies have also shown that fighting back is a better option. Showing resistance and making it difficult for your attacker to do their job often helps you get to safety.

The fact that she was attacked right at her home is disturbing. There are some things that can be done to reduce the chances that your home is targeted for robbery:
1. Make sure you have an acute awareness of your environment when you are getting out of your car and walking to your destination. If anything feels wrong seek safety immediately.
2. Install outdoor lighting that may keep the bad guy away.
3. Use your cell phone when in a less than secure situation so anyone paying unwanted attention sees help is close by.
4. Make sure your home has a lived in look so from outside your home may look like a tougher target, again, help is close by.
5. Install security cameras.
6. Have a panic button for your home alarm that calls for help and sends a screaming alarm.
7. Use your car alarms to draw attention.
8. Always run to safety when attacked. The worse thing you can do is nothing.

Robert Siciliano is a personal security and identity theft expert for Home Security Source. (Disclosures)

See Robert discussing personal and home security on Fox Boston

*Content expressed in Home Security Source does not represent the thoughts and opinions of ADT Security Services, Inc. unless explicitly indicated.

Russian Hackers Make Millions Breaching 7/11 and ATMs

Robert Siciliano Identity Theft Expert

It started simply by hacking 7-Elevens public website using a SQL injection.  SQL is abbreviation of Structured Query Language.  Pronounced  ”Ess Que El” or ”Sequel” depending on who you ask.  This led to 7 elevens main servers compromised which led to ATMs within 7-Eleven hacked.

Wired reports

““The Russians, evidently using an SQL injection vulnerability,  “gained unauthorized access to 7-Eleven, Inc.’s servers through 7-Eleven’s public-facing internet site, and then leveraged that access into servers supporting ATM terminals located in 7-Eleven stores,” the plea agreement reads. “This access caused 7-Eleven, Inc., on or about November 9, 2007, to disable its public-facing internet site to disable the unauthorized access.””

The investigation began with noticeable fraud at a Citibank followed by a stakeout and arrest. From there a traffic stop connected a mule to the rest and the name dropping began.

This is brilliant:

“Federal prosecutors in New York had by then charged three more people in the ATM-cashing conspiracy, including 32-year-old Ukrainian immigrant Yuriy Ryabinin, aka Yuriy Rakushchynets, and 30-year-old Ivan Biltse.

In addition to looting Citibank accounts, Ryabinin had participated in a global cybercrime feeding frenzy that tore into four specific iWire prepaid MasterCard accounts, issued by St. Louis–based First Bank,  in the fall of 2007. On Sept. 30 and Oct. 1 — just two days — the iWire accounts were hit with more than 9,000 actual and attempted withdrawals from ATM machines around the world, resulting in $5 million in losses.

At the time of the ATM capers, FBI and U.S. Secret Service agents had been investigating Ryabinin for his activities on Eastern European carder forums. Ryabinin used the same ICQ chat account to conduct criminal business, and to participate in amateur-radio websites. The feds compared photos of Ryabinin from some of the ham sites to video captured by New York ATM cameras in the Citibank and iWire withdrawals, and determined it was the same man — right down to the tan jacket with dark-blue trim.

When they raided Ryabinin’s home, agents found his computer logged into a carding forum. They also found a magstripe writer and $800,000 in cash — including $690,000 in garbage bags, shopping bags and boxes stashed in the bedroom closet. Another $99,000 in cash turned up in one of the safe-deposit boxes rented by Ryabinin and his wife, Olena. Biltse was also found with $800,000 in cash.

Ryabinin’s wife told investigators that she witnessed her husband “leave the couple’s house with bundles of credit cards in rubber bands and return with large sums of cash,” a Secret Service affidavit (.pdf) reads.”

This is all “account takeover”. All this money comes from consumer accounts who used ATMs at a convenient store and sometimes at a bank. Once the criminal gets your account data and PIN via the processors server they then burn the data to a white card. There’s no way to protect yourself from this crime when the data is breached at the processor level.

Check your statements frequently, at least every week online. Some banks give less than a week to refute unauthorized charges. Check with your bank to find out exactly what their time frame is if your account is compromised. Call the “claims” department and ask them “what’s the cut off date when making a claim?” My bank told me I can make a claim up to a year, but after 60 days there are federal regulations the limit their liability.

I asked my bank what their thoughts were on using a debit card and they said:

  1. Not to use it at a gas pump or a convenient store ATM where you enter your PIN
  2. They suggested using it as a credit card and not as a debit card
  3. Not to use at their own branch after hours to withdraw cash due toi skimming, which wasn’t new information to me but I didn’t expect my bank to say that.

Unfortunately your security, or lack thereof, is in the hands of others. Take control. Protect your identity. Get a credit freeze. Go to ConsumersUnion.org and follow the steps for your particular state. This is an absolutely necessary tool to secure your credit. In most cases, it prevents new accounts from being opened in your name. This makes your Social Security number useless to a potential identity thief.

Invest in Intelius identity theft protection and prevention. Not all forms of identity theft protection can be prevented, but identity theft protection services can dramatically reduce your risk. (Disclosures)

Robert Siciliano, identity theft speaker, discusses ATM skimming on NBC Boston

Beware Online Auction Fraud & Identity Theft

Robert Siciliano Identity Theft Expert

Scammers often set up pages on auction sites during the holiday season. Consumers should be aware of deals that are obviously too good to be true. Most too good to be true online deals bite unsophisticated shoppers or “newbies” to the online auction world. The victim either gets goods that are inferior, counterfeit or they never get anything and still get charged.

My spouse needed some skin care products and went online to eBay to make a purchase. She’s a newbie at this and doesn’t have a lot of experience. She called me over to help complete the transaction and was all happy she found her products so cheap. She told me the other companies were charging almost double so she doubled her order because she was saving so much. I looked at the seller “feedback” that others are supposed to give and it seems my spouse was the first ever buyer.

I told her I didn’t feel comfortable with the purchase that she should wait a day to see what happens. She begrudgingly agreed with me. The next day she logged on to complete her purchase and she saw a message stating: “The eBayer has been suspended from eBay because our records indicate the account was involved in activities that violate our terms” or something like that.

If it seems like online fraud, it is.

Scams can happen inside or outside the auction’s website.eBay recommends being aware of “spoofed” emails.

Stay safe online by protecting yourself from spoof (fake) emails and Web sites. Spoof emails and Web sites can be a major problems for unsuspecting Internet users. Claiming to be sent by a well-known company, spoof emails direct users to Web sites asking for personal information such as a credit card number, Social Security number, or account password. Most “legit” websites will never ask you for such personal information when making a simple purchase. Because it’s so difficult to tell when an email or Web site is a spoof, eBay recommends that you:

1. Download and use eBay Toolbar with Account Guard, a feature that indicates whether you are on the real eBay or Paypal Web sites, or are on a potential spoof site.

2. Learn about spoof protection by taking eBay’s spoof tutorial.

3. Never enter sensitive personal information (such as your password or credit card, bank account, and Social Security numbers) in an email.

Avoid online scams and identity theft by looking for “Feedback” internally on eBays website

1. Buy with confidence by reviewing a seller’s eBay feedback.

2. Before you bid or buy on eBay, it’s important to know your seller. Always look at your seller’s feedback ratings, score and comments first to get an idea of their reputation within the eBay marketplace.

3. Each comment and rating – whether positive, neutral or negative – is an opportunity to understand the history and experience of a seller, a chance to form your own opinions, and a visual cue to help you make a smart buying decision.

Two men were recently arrested when they pocketed the buyer’s payment, then used the buyer’s credit card number and then made fraudulent charges. You can’t be too careful here.

In most cases I recommend using PayPal for online auctions to help prevent online identity theft. If you use your credit card, make sure to check your statements frequently and refute unauthorized charges immediately.

Online buying can help make life easier. Make sure you follow these tips when making online purchases to help protect your identity.

Robert Siciliano is a personal security and identity theft expert for HomeSecuritySource.com See him in action discussing holiday scams on Fox’s Mike and Juliet show. (Disclosures)

*Content expressed in Home Security Source does not represent the thoughts and opinions of ADT Security Services, Inc. unless explicitly indicated.1

Burglars Prey On Churches

Robert Siciliano Identity Theft Expert

It doesn’t matter where, when or who, a burglar will go where there is easy access and easy money, or goods to be resold. The Miami Herald reports a burglar has holy targets for his unholy acts.

Targeting synagogues, churches and a Jehovah’s Witnesses hall in Miami Beach, the man steals expensive audio equipment and cash from collection boxes, police say.

Apparently it’s a male who “looks like everyone else” which is what they all say. Opposed to he looks like one of those aliens with the big eyes and big heads with little hands and a skinny neck and he is green. Burglars generally look like people because they are. The only thing that would make them stand out is if they are disheveled. Which may mean they are homeless or on a heavy drinking or drug binge.

Otherwise expect burglars to be normal. Someone you may even know. Often it’s those on the inside that have knowledge of how things work and where they are. So it’s important to beef up security to protect from the inside out and from the outside in.

In some cases, he has entered through unlocked doors; in others, he has broken windows and busted doors off of their frames. Outdoor surveillance video caught him getting picked up by a cab following one burglary.

“He had a good line. He claimed to be having an appointment with me and was let in,” Geller said. The rabbi, who was out of town, returned to find speakers, amplifiers and a guitar missing from the synagogue.

A security camera at the synagogue caught footage of the thief, from which police have pulled a grainy photo.

The man stole electronics, TV speakers, cash, credit cards and more.

Theft happens. Protect against it.

  1. Lock up. Even if it’s an “open access” environment.
  2. Have someone always watching the door.
  3. Install visible motion sensitive security cameras everywhere recorded by a DVR.
  4. Install hidden motion sensitive security cameras everywhere recorded by a DVR.
  5. Install “Monitored by Video Surveillance” signs everywhere.
  6. Lock doors and windows always.
  7. Install glass break prevention film.

Robert Siciliano is a personal security and identity theft expert for HomeSecuritySource.com See him in action discussing holiday scams on Fox’s Mike and Juliet show. (Disclosures)

*Content expressed in Home Security Source does not represent the thoughts and opinions of ADT Security Services, Inc. unless explicitly indicated.

The Feast of the 7 Phishes

Robert Siciliano Identity Theft Expert

Being a “Siciliano” and having roots in Italy, namely Sicily, the little island at the bottom of the boot, we have a tradition where we celebrate “the vigil” (La Vigilia), with a Feast of the Seven Fishes (festa dei sette pesci).

It’s a day of cooking, eating and enjoying your favorite beverage in substantial quantity. I do the cooking and start serving at noon. I generally cook to order and serve lobster, mussels, little neck clams, scallops, squid, also known as calamari, a white fish, sword fish, and a small fish called “smelt”. Funny name, but tasty. Everything is prepared either fried, white sauce or red gravy. It’s a yummy day.

Tis also the season for scamming everyone and anyone who is duped into responding to a “phish” email. Phishing is when you receive an email that looks like it’s a legitimate communication from a bank, retailer, government agency or some other entity informing you that you’ve won something or stand to lose something if you don’t respond.

Around the holidays scammers are in full force and sending lots of emails that look like they are coming from legitimate retailers but are in fact fake and meant to lure you into entering your personal information.

Here are the 2009 7 Phishes to look out for, pulled directly from my inbox:

1. Great Holiday Deals!: “Find out some new facts about the original Swiss things! Leather wallets, authentic jewelry and Swiss watches – are the main details in your life.” Click the link and go to a fraud based retailer that sends you fake goods.
2. Official Viagra Reseller: “There’s no better time of the year to show your lover how much you care. Gift them a years subscription to Viagra!” OMG! They didn’t just say that! It’s a fake, don’t bother.
3. Give Credit Repair for Xmas and Have a prosperous New Year!: “Log in now and get your loved one an updated credit score and start 2010 off looking better financially than ever.” This also means giving some scammer your spouse’s social security number. Not a good idea.
4. Gift Yourself a Russian Bride for the Holidays: “Wide choice of fine Russian girls for any taste are available here.” They first ask you for a deposit to start the “searching for a bride”. Once you wire money anywhere overseas in response to an email kiss it goodbye.
5. Lose That Holiday Ham!: “I lost 17 pounds drinking coffee in time for New Years Eve! You can too!” Do I even need to explain?
6. Bankcard Account Suspention: “We have disabled your account to inactivity. If you plan to go shoping (typo) for your families you should contact us now.” Two typos and bad English. Need I say more?
7. Have a Happier New year with a new Job!: “Shipping managers needed now. Start your own home based business with no money and no inventory.” And become a shipping mule for organized criminals.

Robert Siciliano is a personal security and identity theft expert for HomeSecuritySource.com See him in action discussing holiday scams on Fox’s Mike and Juliet show. (Disclosures)

*Content expressed in Home Security Source does not represent the thoughts and opinions of ADT Security Services, Inc. unless explicitly indicated.

Craigslist ATM I bought Causes Industry Stir

Robert Siciliano Identity Theft Expert

Apparently I raised a hackle or two. Seems my little stunt got the attention of industry insiders, and not all of them believe that I bought a used ATM on Craigslist, which turned out to contain thousands of credit card numbers. Well, it did actually happen, and despite what many say, that the ATM couldn’t have contained 16-digit credit and debit card numbers on it, it did.

The most intense resistance to my experiment came from one Boston cop who watched me plant this thing in Downtown Crossing. He crossed his arms, glared at me, and when I walked away from the ATM, asked what I was doing. When I told him, he yelled for the women who were already using my ATM to stop, then took down my information while screaming at me. He later told me that his main concern was the possibility that the ATM might have contained a bomb!

According to ATMmarketplace.com, the ATM industry is braced for a backlash in the face of security concerns. There should be a backlash. We definitely need some regulation as to who can or can’t buy an ATM. And according to Mike Lee, the chief executive of the ATM Industry Association, “while ATMIA does not condone the auctioning of ATMs, online or otherwise, the association has little control over how they are sold.”

Personally, I think that the association needs to start establishing some control, and throwing your hands up in the air is lame. Both eBay and Craigslist have prohibited certain items. Why can’t I buy an old credit card off eBay, but I can buy an ATM with thousands of credit and debit card numbers on it? I can’t buy a “traffic signal control device” off eBay either. Because someone recognized in the wrong hands, the device can wreak havoc.

James Phillips, director of North American sales for ATMGurus, a Triton company, says that “an ATM that has old software or one that retains card numbers does not provide enough information for the owner to compromise consumer accounts,” but that my experiment still “has the potential to be so damaging to the industry’s reputation.” First of all, a 16-digit number is enough to turn data into cash. Even without a PIN, the 16-digit number can be used to buy goods online, or encoded on a blank card to buy goods in a store. This is why Visa and MasterCard require new software to block out the numbers. Second, Jim, you’re right, this is damaging. So please, fix it, and don’t allow lame excuses. And my machine is a Triton 9100. She’s a beauty by the way. Works nice off a 12-volt car battery, too.

Wendy Amaral, an account manager at Nationwide Money Services, says that while it’s possible that some companies could provide processing without collecting the required background information about the ATM owner, Visa, MasterCard, and other financial institutions are firm about the rules, and that audits are unlikely but possible. I think “possible audits” sounds like another cop out. For those of us who use ATMs, the idea that we are protected by “possible audits” is a slap in the face.

George McQuain, chief executive of ATM ISO Global Axcess Corp., which provides ATM processing, says he’s skeptical that I was able to set up my ATM for processing without a background check or even any questions. I haven’t revealed the processors who agreed to set up my ATM because they seemed to be small shops, and I don’t intend to destroy their livelihoods in my attempt to point out the inadequacy of the industry’s regulations. But the first processor set me up over the phone, and all I had to do was fill out a PDF and fax it back. The second showed up to my house in a pickup truck to service the ATM in my garage.

McQuain also says that it is rare for an ATM to have such outdated software that it would allow the owner to print so much customer information. But it was easy for me to find one. And even when they are replaced with newer models, where do they go? Where does the data go? I’ll tell you. On Craigslist, and then to the criminals.

There have been tons of reports on my story:

You can protect yourself from these types of scams by paying attention to your statements. Refute unauthorized transactions within 60 days. Consider never using a debit card again, since credit cards are safer. When using an ATM, pay close attention to details, and look for anything that seems out of place. If your card gets stuck in the machine or you notice anything odd about the appearance of the machine, such as wires, double sided tape, error messages, a missing security camera, or the machine seems unusually old and run down, don’t use it. Don’t use just any ATM. Instead, look for ATMs in more secure locations. Cover your pin!! And invest in Intelius Identity Theft Protection and Prevention. Not all forms of identity theft can be prevented, but identity theft protection services can dramatically reduce your risk. “Disclosures”

Robert Siciliano Identity Theft Speaker rolling an ATM around on Fox

Lack of Laptop Security Leads to Identity Theft

Robert Siciliano Identity Theft Expert

In 2003, an estimated 1.5 million laptops were stolen worldwide. Today, that number has climbed to 2.6 million. That’s a 70% increase in just a few years. That’s one stolen laptop every 12 seconds.

Laptop computers have been the source of some of the biggest data breaches of all time. 800,000 doctors were recently put at risk for identity theft when a laptop containing their personal data went missing from the Chicago-based Blue Cross and Blue Shield Association.

As the years pass, laptop prices come down and their computing power goes up, making them increasingly vulnerable.

According to yet another interesting Ponemon Institute study, more than half of IT and security professionals worldwide believe their companies’ laptops and other mobile devices pose security risks, and only half of them have CEOs who are strong advocates and supporters of data security efforts. Kelly Jackson Higgins’ article at Dark Reading gives a good summary of these findings.

In the United States specifically, the situation is even worse, with only 40% of IT and security pros believing their CEOs to be security supporters. When it comes to compliance with regulations, “US firms were also less inclined to consider compliance helpful to security of their endpoints.”

This report is both quite troubling and yet unsurprising. It models the philosophies that produce what we see in the real world: data breaches are quite commonplace, decent security is quite achievable, and most businesses just don’t really care, at least until they learn the hard way. It’s akin to a widespread lack of interest in wearing seat belts, with only those who experience accidents deciding that, sure enough, it’s not very hard to buckle a seat belt and the benefits are enormous.

Many businesses have a department, or at least a group or individual, that handles security. (Note that the report also exposes a woeful lack of collaboration with this section of the business.) Yet “the security department,” or the IT department in general, tends to find that upper management just doesn’t “buy in” with security efforts.

Dan Yost, Chief Technology Officer of MyLaptopGPS, states, “It seems good to let the upper management take a serious fall when (not if) breaches happen. They choose not to support the buckling of seat belts, because it’s ‘not important’ or at least not a priority. It’s only fair that their necks be on the line during the next ‘accident’.”

Unfortunately your security, or lack thereof, is in the hands of others. Take control. Protect your identity. Get a credit freeze. Go to ConsumersUnion.org and follow the steps for your particular state. This is an absolutely necessary tool to secure your credit. In most cases, it prevents new accounts from being opened in your name. This makes your Social Security number useless to a potential identity thief.

Invest in Intelius identity theft protection and prevention. Not all forms of identity theft protection can be prevented, but identity theft protection services can dramatically reduce your risk. (Disclosures)

Robert Siciliano, identity theft speaker, discusses Laptop Security on The Today Show.

Identity Theft 2010 Top 10 Predictions

Robert Siciliano Identity Theft Expert

I’ve joined forces with the Identity Theft Resource Center to expand the pool of knowledge about identity theft issues. As nationally recognized experts in this crime, we have come up with ten predictions for what the nation can expect in the area of identity theft in 2010 and beyond.

1. More Scams: The recession will lead to more scams. Whenever our nation has faced a difficult time, thieves have found a way to use the problem to their advantage. In my adult life, I’ve never seen more variations of old scams and the degree of sophistication in newer scams.

2. Job Scams: Criminals will take advantage of increasing unemployment rates by tricking desperate people searching for job listings. These fake job listings and work-at-home scams will eventually end with the job seeker providing Social Security numbers to criminals. If the job description is not one that you would see printed on a business card or you are asked to front money, it’s a scam.

3. Newbie Low Tech “Desperate” Identity Theft: Additionally, there will be an increase in the number of individuals – who have no criminal history – beginning to explore the crime of identity theft for financial gain. For these thieves, it will be about quick money. Once desperate people max out their credit limits and wreck their own credit histories; they will start to use Social Security Numbers that they can easily access.

These new identity thieves will take advantage of low tech methods – stealing credit card numbers, dumpster diving, making phone calls, or phishing for credit card numbers. These techniques may also include placing ads in auctions and Craigslist for phantom products for sale to get either credit card numbers or cash.

4. All-in-the-Family ID Theft: Desperation will lead to more child identity theft and “all-in-the-family” cases, as well as the fraudulent use of numbers belonging to close friends, roommates and fellow workers. It has long been documented that a significant percentage of identity theft cases are perpetrated by people close to the victim. We predict that this number will increase during these tough economic times.

5. Child Identity Theft: The ITRC has noted that nearly 10 percent of its case load, for the past six months, involved child identity theft issues. These cases often involve more varied components of identity theft than ever before. Some people have finally realized that a child’s SSN can be used for more than just opening a line of credit.

6. Medical Identity Theft: While not a new crime, this will reflect the distress of those who have become unemployed. High COBRA premiums, growing individual medical insurance costs, or the inability to afford insurance or medical care will cause a spike in this area of identity theft. The Social Security Administration has noted an increase in uninsured people using the coverage of a friend, relative or even a stranger to get medical care.

7. Insider Identity Theft: In the coming year, this will increase due to the failure to follow simple security protocols in the workplace. This will create opportunities for thieves to gain access to personal identifying information retained in databases or paper files. Additionally, the lack of computer security measures and the increasing skill levels of hackers will lead to larger and more financially harmful breaches. Although a few sophisticated hackers have been arrested recently, these large, extremely damaging hacking events will continue to occur. These thieves are educating young protégées on high tech methods to access “secured” information and will likely continue to coordinate malicious attacks from their jail cells.

8. Governmental Identity Theft: More individuals will discover that they have become identity theft victims as they apply for government assistance and/or benefits. Not only will their own SSNs be used, but they may be temporarily denied benefits due to the use of their child’s SSN, which has been used fraudulently. This type of identity theft, identified as “Governmental Identity Theft,” may be associated with complications with the IRS, Social Security Administration, Departments of Motor Vehicles, Medicare and Welfare.

9. Criminal Identity Theft: The number of cases of criminal identity theft will continue to grow. This type of crime is defined as the use of an individual’s personal information to avoid being tied to their own criminal record. In the current environment, the effects of criminal identity theft on the victims will be more apparent with the loss of employment, loss of benefits and the increased number of arrests of victims ranging from failure to appear warrants for traffic citations all the way to felony level crimes. Criminals will continue to exploit the weaknesses of the current system and revictimize the individual whose information has been used.

10. Social Media Identity Theft: The meteoric rise in social media use has also created a launch pad for identity thieves. Social media identity theft happens when someone hacks an account via phishing, creates infected short URLs or creates a page using photos and the victims identifying information. My prediction for 2010 is that the increase in social networking activity, along with a user’s failure to implement security and privacy settings and protocols, will lead to an increased exposure of not only the user’s personal information but possibly that of their “friends.”

Bottom line, there will be an increase in identity theft crimes and the number of victims over the next two years unless significant changes are made in information security. Our most important asset is our identity. And we are functioning under a completely antiquated system of identification with wide open credit and few safeguards to protect the consumer. When state governments agree with federal agencies on effective identification and industry comes together, not to profit from the problem but to solve it, only then will we prevail.

Protect your identity. Get a credit freeze. Go to ConsumersUnion.org and follow the steps for your particular state. This is an absolutely necessary tool to secure your credit. In most cases, it prevents new accounts from being opened in your name. This makes your Social Security number useless to a potential identity thief.

Invest in Intelius identity theft protection and prevention. Not all forms of identity theft protection can be prevented, but identity theft protection services can dramatically reduce your risk. (Disclosures)

Robert Siciliano identity theft speaker discussing social media identity theft on  on Fox Boston

Facebook Newest Portal for Social Media Identity Theft

Robert Siciliano Identity Theft Expert

Imagine trying to log into your online accounts one after the other and being locked out. At first you think the site you are visiting screwed up but then it keeps happening over and over again no matter where you go.  Then you start receiving messages from friends and family asking you why you are behaving so freakishly online.

This is what happened to Matasha Allen as described in the Eastern Michigan Universitys Eastern Echo.

“Allen, 28, was a substitute teacher at the time, teaching music as well as elementary classes. Her only outlet to the Internet was limited to libraries and public computer labs, where she would check her accounts, look through e-mail and stay in touch with friends on Facebook. It was during one of these trips to the computers that it happened, Allen deduced. She thinks her Facebook account wasn’t completely logged off, or the computer didn’t log out. However it happened, someone found their way onto Allen’s accounts and took complete control.

“Social media is built on the honor system. There are no checks and balances to prove who is who. Anyone can pose as you and blog as you. This makes for social media identity theft,” said Robert Siciliano, a security consultant for Intelius.com and a speaker on preventing identity theft.

“The problem with social media identity theft is that when it takes over your account, all the people that you communicate with within your account may believe the identity thief is you. And when that identity thief begins to ask for money, from your friends and from your family and your coworkers, then they may actually pull money out of their pocket and send it via Western Union to the imposter. They think that you’ve actually come into the trouble that the identity thief is saying you’re in.”

In Allen’s case, her identity theft didn’t escalate to the thief asking for money from friends, but the thief was malicious. Messages were sent to friends and family, using profanity and insults. One of the incidents Allen related was toward an organization focusing on eliminating poverty in children. The identity thief sent the organization a message reading, “I hate children. I hope they all starve.””

  1. Steer clear of public computers whenever possible, or at least not accessing accounts or sites that require passwords.
  2. If you use a public PC get a USB drive that has a built in browser that allows you to surf securely
  3. No matter what PC you use to access accounts always log out when your are done
  4. Register your name at as many social media sites as possible. Use Knowem.com to do it for you.

Protect your identity. Get a credit freeze. Go to ConsumersUnion.org and follow the steps for your particular state. This is an absolutely necessary tool to secure your credit. In most cases, it prevents new accounts from being opened in your name. This makes your Social Security number useless to a potential identity thief.

Invest in Intelius identity theft protection and prevention. Not all forms of identity theft protection can be prevented, but identity theft protection services can dramatically reduce your risk. (Disclosures)

Robert Siciliano identity theft speaker discussing social media identity theft on  on Fox Boston

Child Identity Theft Protection

Robert Siciliano Identity Theft Expert

In a blog I guest contribute to called “NextAdvisor” they offer the following advice on child identity theft protection:

The following post in our Reader Question series is an actual user submitted question.

Q: I found out that someone used my grandson’s Social Security number to get phone service. How can I stop this? He’s only 11 years old.

A: If someone has used or is using a child’s Social Security number to secure a service, the child is a victim of identity theft. You should file a report with a local police department immediately. Having a police report will make it easier to have the fraudulent item or items removed from the child’s credit report. You should also file a complaint with the Federal Trade Commission.

You should also call the phone company to inform them that the service has been fraudulently obtained using a minor’s Social Security number. If you are your grandson’s legal guardian, you can request a copy of his credit report from all three credit bureaus, and ask that fraudulent items be removed and that his credit report be frozen until he turns 18. If you are not your grandson’s legal guardian, one of his parents will need to make this request.

When a parent or legal guardian contacts a credit bureau on their child’s behalf, they need to provide the child’s complete name, address, and date of birth, and copies of the child’s birth certificate and Social Security number. The parent or guardian must also provide a copy of their own drivers license or other government-issued proof of identity, including their current address, and a utility bill containing the current address.

Here is the contact information for the three credit bureaus:

Experian
(888)397-3742
http://www.experian.com

Experian
PO Box 9532
Allen , TX 75013

Equifax
(800) 658-1111
http://www.equifax.com

Equifax
P.O. Box 105069
Atlanta , GA 30348

TransUnion
(800) 916-8800
http://www.transunion.com

TransUnion
PO Box 6790
Fullerton , CA 92834”

And my advice. For your own good, protect your identity. Get a credit freeze. Go to ConsumersUnion.org and follow the steps for your particular state. This is an absolutely necessary tool to secure your credit. In most cases, it prevents new accounts from being opened in your name. This makes your Social Security number useless to a potential identity thief.

Invest in Intelius identity theft protection and prevention. Not all forms of identity theft protection can be prevented, but identity theft protection services can dramatically reduce your risk. (Disclosures)

Robert Siciliano identity theft speaker discussing child identity theft on NBC Boston