Identity Theft Category
You might think breaking into a corporate database would be hard. Not so. A recent report from the Verizon RISK Team found the vast majority of incidents required minimal skills and took place in a few hours. Unfortunately, those breaches often weren’t discovered for months or even years–and it typically wasn’t the company but rather a third party that discovered a breach.
From a Credit.com post on the study:
While one in 10 were so easy the average Internet user could have caused them, another 68 percent were the result of hacking attacks using the most basic methods, requiring relatively few resources to complete. Only one breach suffered in all of 2012 required “advanced skills, significant customizations, and/or extensive resources” to complete.
That is likewise reflected in the amount of time it took to cause most data breaches, the report said. Altogether, 84 percent took hours or even minutes to perpetrate, while these incidents typically took months or even years to discover. Nearly two-thirds of all breaches took at least that long, up from just 56 percent the year before, proving that it’s actually becoming more difficult to spot breaches, as well as contain them. While most were remediated in hours or days, nearly a quarter took months.
The take-away from this is that companies aren’t doing nearly enough to protect the information they collect about you. And the sad truth is that you have little control over what goes into these databases. You can do your best to protect your identity, and still have your information breached.
You should still take steps to reduce your exposure, steps like not giving your Social Security number to companies that don’t need it and refusing to give businesses permission to share your information. You should use tough-to-hack passwords and stop sharing secrets on social media. You also should monitor your credit reports and financial accounts.
Until companies get serious about protecting your data, though, you’re still a target for identity theft.
Dear Liz: My cousin had his house broken into a little over a year ago. A lot of things were taken, but insurance replaced most of what he thought was missing. This year after he filed his return he was contacted by the IRS, which told him that a return using his information had already been filed and the refund check cashed. The IRS is investigating the situation now, but I really worry about what is going to happen to his Social Security in the future if someone else is using his numbers or those of his children. Do you have any information on what steps he should take?
Answer: Theft of tax refunds is a growing problem. In fact, tax identity theft is the No. 1 fraud on the IRS’ list of Dirty Dozen Tax Scams of 2012.
The fraud is often perpetrated by organized criminal gangs that con, steal or buy people’s personal information to create bogus returns. Some people fall right into the bad guys’ hands by responding to emails that purport to be from the IRS. (The IRS doesn’t email people to request personal or financial information.)
If the problem isn’t resolved within a few months, your cousin should contact the agency’s Identity Protection Specialized Unit at (800) 908-4490.
Since the criminals already have his Social Security number and other important financial information, he also should put security freezes on his credit reports at all three bureaus. Links to the bureaus and other information for identity theft victims can be found on the IRS’ site at http://www.irs.gov.
Dear Liz: In a recent column, you discussed two instances in which the tax preparer screwed up, and yet you concluded the problem was with the post office. I’m not a fan of the post office, but your logic escapes me.
Answer: In both instances, sensitive financial documents were entrusted to the U.S. mail system. Although this is common, it’s certainly not secure, since such mailings aren’t tracked and they certainly aren’t encrypted. The two taxpayers didn’t think to question the way their papers had been handled until those papers went missing, but both taxpayers and tax preparers would be wise to use more secure methods to transmit sensitive data.
Dear Liz: I sent my tax preparer everything he needed for my return, including the originals of my W2 forms, bank 1099s, property tax bills (including a copy of the check showing the payment) and a year-end mortgage statement. A week later he said it was done and that he had mailed the return and paperwork back to me. It’s been three weeks and I still haven’t received the paperwork. What I did get was a direct deposit of my refund, so apparently he filed the return without telling me. I am sick to death that all my private financial information is floating around in the mail system somewhere and that it could get into the hands of a dishonest person.
Answer: You’ve learned a couple lessons, foremost among them that you need a new tax pro. Filing your return without letting you see it was a definite no-no.
Another lesson is that your private financial data probably shouldn’t be entrusted to the U.S. mail system. It’s more secure to drop your documents off with your tax preparer and pick them up yourself, along with a copy of your return, when he or she is done. The original return can be electronically filed using the IRS’ secure, encrypted system, eliminating the need to use the mail.
You can put 90-day fraud alerts on your credit reports at the three major bureaus (Experian, Equifax and TransUnion). Fraud alerts notify lenders that they should take extra steps to verify identity before opening accounts in your name. For more protection, you may want to consider a credit freeze, which doesn’t rely on lenders’ sometimes-wavering vigilance but that allows you to shut off access to your credit reports, preventing thieves from opening new credit accounts. For more information, visit the Consumers Union site www.financialprivacynow.org.