Many years ago, (like ten or more) there was a major US bank (BoA, CitiBank I don’t remember) that had a major security breach. I don’t remember all the details, and Google has been less than helpful, but the bank in question was very forth coming, they announced the incident, released a press release, and detailed what happened. They then spent millions to revamp their entire security posture to prevent it from happening again. That bank lost millions of dollars of business afterwards despite the fact that after the breach it was probably the most secure bank in the country at that time.
Looks like banks have learned their lesson and now are keeping as quiet as possible about any and all compromises in their security.
Kevin Poulsen has written an excellent article over at Wired detailing the recent breach of ATM card numbers and their PINS. Seems that someone broke into a server that controlled CitiBank branded ATMs in various 7-11s across the country and then used the card numbers and PINs to create fake cards and drain bank accounts. There are a lot of unanswered questions about this case such as who was actually responsible for this server. Citibank is pointing the finger at a third party transaction processing company and that company seems to be denying any involvement. No one is being very forthcoming with the details, probably afraid of bad publicity and the loss of business that may result from it.
Consumers of course are protected by law from actual monetary losses but the hassle of having to get a new card number can’t be fun. Unfortunately there isn’t much the consumer can do to protect themselves against this sort of attack. You can try to avoid those stand alone ATM kiosks like those found in convenience stores and rely solely on ATMS at actual banks but in many cases that is just not practical. So keep a close eye on those statements, verify every line item and call your bank at the first sign of anything weird.
UPDATE: Thanks to NR for sending me a link to the CitiBank breach from 1995 that I referenced above.
Only You Can Prevent ID Theft
I was at Autozone yesterday getting a set of Upper Strut Mounts for my 167K mile old Saturn when the sales guy asked me for my phone number. I didn’t hesitate a bit and just rattled off ten digits. The same ten digits I always give out. Ten digits which in fact are not my phone number.
While I waited for the cashier to finish ringing up the pair of $42.99 parts I overheard the guy next to me arguing with the cashier about having to give up his phone number in order to complete his purchase. (Didn’t Radio Shack try this years ago?) The cashier assured him that the number would go nowhere other than Autozone and was only used to identify his purchase for warranty purposes. However, I didn’t see any privacy policy posted or offered for the customer to read, not that privacy policies are legally binding or anything. Once Autozone (or anyone else) has your info they can do whatever they please with it including selling it to someone else.
So what does this have to do with anything? Hopefully it serves as a reminder that the only one who is going to protect your identity is you. Some people obviously think they can hire some other company to protect their identity for them. A company like LifeLock which promises to “guarantee your good name.” Since the company’s founder publishes his own social security number on its web site and in print advertisements they must be able to protect people from identity theft, right? Why worry? Just pay Lifelock and your good name is guaranteed!
Well come to find out the company is currently being sued by customers in at least three states who say that LifeLock did anything but protect their identities. In the course of gathering information for the trial the lawyer for the case found 87 instances where people have tried to steal the identity of the CEO of the company, 20 of which were attempts at obtaining fake drivers licenses. And one instance of fraud being perpetrated in the name of the CEO! (I wonder if the CEO can get a refund?)
So what is the lesson to be learned? You can either pay your $10 a month and live in blissful ignorance until you get burned or you can expend a little effort and protect yourself. Don’t give out personal information to people who don’t need it (which is just about everyone), don’t use your PIN in point-of-sale machines, check your credit reports once a year, and don’t do what the CEO of Lifelock did and publish your social security number on your website.