Identity Theft Category
Dear Liz: I think I’ve been scammed, but my credit union has decided I’m simply forgetful. I noticed a debit to my checking account that I did not recognize from a merchant I cannot identify. The merchant name appears on my statement as simply “Portland Portland OR.” My credit union can tell me only that it is a used-merchandise store or secondhand store. I questioned the charge by email and replaced my card. Then I got a letter from the credit union upholding the charge, saying that my card and PIN were present at the time of the transaction. I never did learn the merchant’s name. Can this merchant really not be identified? The $10.48 in dispute is unimportant compared with the complete opacity of the supposed purchase. No name, no address, only a day and time. Is this mystery the best the banking system can do?
Answer: Your credit union could identify the merchant by contacting the card network that processed the transaction, but has apparently decided it’s not worth the effort, said Odysseas Papadimitriou, chief executive of Evolution Finance, which operates the CardHub.com card comparison site. You can demand the credit union identify the merchant for you, but there’s reason to believe this transaction is legitimate, he said.
It’s not just because a personal identification number was used, however, since PINs certainly can be stolen. Hackers have compromised keypads at Michael’s stores and Barnes & Noble, among other retail chains, while Target said encrypted PIN data were stolen in its massive database breach.
But the use of a PIN combined with the small amount of the transaction indicates the culprit here likely is forgetfulness rather than an identity thief, Papadimitriou said. ID thieves are unlikely to make one small transaction and then wait, he said.
“They try to extract the max they can before they get shut down,” Papadimitriou said.
Still, your experience should make you think twice about using a debit card for a retail transaction. With debit card fraud, you may have to fight with your financial institution to get the money back, since the transaction comes directly out of your checking account. With credit cards, you don’t have to pay a disputed transaction until the card company investigates.
Dear Liz: My debit card was part of the recent Target data breach (my credit union called me). I’ve read articles telling me to pull my credit reports. Here’s the thing: I already requested two of my three free credit reports in early December. When I read about the Target incident, I requested the third one. So now, if I pull a credit report, I’d have to pay for it. I’m very concerned about this, as my finances are tight.
Answer: The information that was stolen in the Target breach — and immediately put up for sale on black-market sites — is not the kind of personal information that’s typically needed to open new accounts, said John Ulzheimer, credit expert for CreditSesame.com. So buying your credit reports or investing in credit monitoring, which is how you would spot new account fraud, isn’t strictly necessary, he said.
The information that was stolen can be used in what’s known as “account takeover,” which means the bad guys can take over existing accounts and make fraudulent charges. In the case of a debit card, that means they can drain your bank account. With a credit card, you wouldn’t have to pay the fraudulent transactions, but dealing with them could still be a hassle.
Either way, you would be smart to close any debit or credit card used at Target between Nov. 27 and Dec. 15, the time of the breach, and ask for a replacement, Ulzheimer said.
While holiday blackouts can make redeeming frequent flier miles difficult during the summer, there are still good deals to be had if you know where to look.
Identity thieves are targeting victims at their most vulnerable. Find out what you can do to protect yourself.
A novel approach to managing vacation time could allow you to purchase a day off or sell time you’re not going to use.
Meet the five common personal finance myths and how to avoid them.
The good news is that it’s not too late. The bad news is that it will be if you wait any longer.
You might think breaking into a corporate database would be hard. Not so. A recent report from the Verizon RISK Team found the vast majority of incidents required minimal skills and took place in a few hours. Unfortunately, those breaches often weren’t discovered for months or even years–and it typically wasn’t the company but rather a third party that discovered a breach.
From a Credit.com post on the study:
While one in 10 were so easy the average Internet user could have caused them, another 68 percent were the result of hacking attacks using the most basic methods, requiring relatively few resources to complete. Only one breach suffered in all of 2012 required “advanced skills, significant customizations, and/or extensive resources” to complete.
That is likewise reflected in the amount of time it took to cause most data breaches, the report said. Altogether, 84 percent took hours or even minutes to perpetrate, while these incidents typically took months or even years to discover. Nearly two-thirds of all breaches took at least that long, up from just 56 percent the year before, proving that it’s actually becoming more difficult to spot breaches, as well as contain them. While most were remediated in hours or days, nearly a quarter took months.
The take-away from this is that companies aren’t doing nearly enough to protect the information they collect about you. And the sad truth is that you have little control over what goes into these databases. You can do your best to protect your identity, and still have your information breached.
You should still take steps to reduce your exposure, steps like not giving your Social Security number to companies that don’t need it and refusing to give businesses permission to share your information. You should use tough-to-hack passwords and stop sharing secrets on social media. You also should monitor your credit reports and financial accounts.
Until companies get serious about protecting your data, though, you’re still a target for identity theft.
Dear Liz: My cousin had his house broken into a little over a year ago. A lot of things were taken, but insurance replaced most of what he thought was missing. This year after he filed his return he was contacted by the IRS, which told him that a return using his information had already been filed and the refund check cashed. The IRS is investigating the situation now, but I really worry about what is going to happen to his Social Security in the future if someone else is using his numbers or those of his children. Do you have any information on what steps he should take?
Answer: Theft of tax refunds is a growing problem. In fact, tax identity theft is the No. 1 fraud on the IRS’ list of Dirty Dozen Tax Scams of 2012.
The fraud is often perpetrated by organized criminal gangs that con, steal or buy people’s personal information to create bogus returns. Some people fall right into the bad guys’ hands by responding to emails that purport to be from the IRS. (The IRS doesn’t email people to request personal or financial information.)
If the problem isn’t resolved within a few months, your cousin should contact the agency’s Identity Protection Specialized Unit at (800) 908-4490.
Since the criminals already have his Social Security number and other important financial information, he also should put security freezes on his credit reports at all three bureaus. Links to the bureaus and other information for identity theft victims can be found on the IRS’ site at http://www.irs.gov.