The Daily Caveat is written by Michael Thomas, a recovering corporate investigator in the Washington, DC-area.

CARE TO CONTRIBUTE?

TIPS, COMMENTS and QUESTIONS are always welcome (and strictly confidential).

Contact The Daily Caveat via:



Join our mailing list to new posts via email.



Or justrss icon read the feed...


Previous Posts Archives
8/03/2008
Countrywide Financial Analyst Arrested on Identity Theft Charges
Wahid Siddiqi - what a guy. Buying and selling his customer private data. You'd think these Countrywide guys are crooks or something.

-- MDT

Labels: , ,

0 Comments.
Post a Comment
5/05/2008
Lifelock Sued Over False I.D. Theft Protection Claims
You've seen the ads - with bozo CEO, Richard "Todd" Davis, touting that their product makes your personal info so secure, he's put his own social security number up in Times Square.

Actual Lifelock customers have found the results to be somewhat less than stellar, leading to a class action against the firm.

Oh, and the Lifelock CEO's social... (wait for it) ...is currently being misused by maybe 20 different identity thieves. Also, there is the small matter of a Lifelock co-founder siting in jail for unpaid gambling debts.

Get the sad skinny at The Consumerist.

-- MDT

Labels: , ,

0 Comments.
Post a Comment
4/09/2008
Fifteen Bucks
That's about how much your identity is work, according to a new Symantec security threat report.

And, a little more color on the sound footing of cyber crime economies.

Check it out.

-- MDT

Labels: , ,

0 Comments.
Post a Comment
3/11/2008
Top 25 Leaky Institutions
Interesting report from Chris Hoofnagle at Berkeley handicaps what institutions are most likely to bungle the handling of your private deets.

--MDT

Labels: ,

0 Comments.
Post a Comment

Who is Stealing from Kurt Cobain?
No, it's not Courtney Love. But it is an interesting story.

NME has the details.

-- MDT

Labels: , ,

0 Comments.
Post a Comment
1/23/2008
Choicepoint Avoids SEC Investigation
Sighs of relief all around, I'd imagine.

-- MDT

Labels: , ,

0 Comments.
Post a Comment
1/06/2008
Ohio Bureau of Workers’ Compensation Worker Pinched For Selling Personal Data to Private Investigator
PI Newslink has the details.

-- MDT

Labels: , , ,

0 Comments.
Post a Comment
4/04/2007
New Pretexting Rules Delivered By the FCC
Techdirt does their usual bang-up job covering the FCC's new ruling that puts further restrictions on pretexting. Unlike the recent anti-pretexting law that was passed in the U.S., which was aimed squarely at the pretexters themselves the FCC action is designed to plug the holes on the other side of the conversation, establishing more secure practices within telecom companies to prevent the exposure of personal data. Better alert practices for consumers and law enforcement are also part of the package. Amongst the consequences of the FCC's new ruling are:
  • Phone companies cannot release customer phone call records unless the customer provides a password. In the absence of a password, the company can only send the data to the customers' address of record or call the customer back at their phone number of record.
  • Carriers must notify the customer immediately if their password changes.
  • Telcos must get explicit consent from customers before sharing calling data with marketing partners and independent contractors.
  • Carriers must submit an annual certification to the FCC that includes actions taken against pretexters and a summary of relevant complaints from consumers.
Check out the full pretexting piece from Techdirt, or go straight to the horses mouth and read the FCC's order (Look for date: 4/2/07).

-- MDT

Labels: , , ,

0 Comments.
Post a Comment
2/14/2007
FBI Laptops Go Missing (Lost and or Stolen)
Also missing, you might imagine, is a bit of the agency's dignity. But the 160 laptops lost or stolen over the last four years (including some from counter-terrorism and counter-intelligence divisions) is actually down by about HALF from the preceding audit period, when 317 laptops walked out the door or got lost behind the water cooler.

So, um, I guess good work guys...

Due to the recent Veterans Afffairs laptop disappearance and related identity theft concerns, the Federal government issued a directive back in June of '06 that within 45 days all civilian agencies would be required to institute laptop security measures. So far compliance is at about 10%.

You can get the full story (both the '07 and '02 audit reports) over Justice Department's Office of the Inspector General. The '07 report is only available as a PDF at present. There is an HTML version of the '02 report, found here.

-- MDT

Labels: , , ,

0 Comments.
Post a Comment
1/19/2007
More on Bryan Wagner Guilty Plea, HP PI To Flip For Prosecution
From the SacBee, one of those stories I meant to post late on Friday but has gotten held over until today. Last week, when the papers were hinting that HP subcontractor, Bryan Wagner would be testifying for the prosecution, here's why:

Bryan Wagner, who faces federal identity theft and conspiracy charges, is accused of posing as a journalist to access the reporter's private phone records as part of the computer and printer maker's ill-fated attempt to ferret out the source of boardroom leaks to the media. The way Wagner was charged Wednesday - he agreed to waive grand jury proceedings - suggests he's likely cooperating with investigators aiming for more high-profile targets, said Matthew Jacobs, a former federal prosecutor in San Francisco who is now in private practice.

"The government likes to start at the lowest point in the chain of responsibility and flip people," Jacobs said. "What it signals is that the government is trying to build the case against those more senior.

More on Wagner's fate via The Sacramento Bee.

-- MDT

Labels: , , , ,

0 Comments.
Post a Comment
1/17/2007
Sentencing in June for HP Private Investigator
Following Bryan Wagner's guilty plea. a date has been set for his sentencing - June 20th 2007. Wagner's lawyer has also, apparently, confirmed that Wagner will be testifying for the prosecution.

Labels: , , ,

0 Comments.
Post a Comment
1/16/2007
HP Private Investigator Pleads Guilty to Identity Theft
Bryan Wagner takes a fall.

This guy is not even 30...a cautionary tale for P.I.s who put saying "yes" to a client above the client's best interest - and their own...

Wagner's actions were undoubtably pursuant to the request and at the direction of someone. And we'll find out the who, because Wagner seems to be cooperating. Federal prosecutors are not going to settle for busting the chops of some subcontractor when he can give them HP top brass and, perhaps, a few names from Wilson Sonsini too.

Check out the typical great collection of links on the story from The Jurist.

-- MDT

Labels: , , , ,

0 Comments.
Post a Comment
1/12/2007
P.I. Faces Criminal Indictment in HP Pretexting Case
This would not be the folks from the Boston-area firm, Security Outsourcing Solutions, that you've read about previously, but rather P.I. Bryan Wagner our of San Francisco.

Wagner has been indicted in California on charges of utilizing the social security number of a journalist to obtain that individual's telephone records. He apparently did so at the direction of HP execs, their legal team or other investigators working on HP's behalf as a part of their internal "Kona 2" investigation to identify the source of HP's persistent high-level media leaks.

Wagner is facing charges of conspiracy and identity theft, which could carry penalties of up to seven years in jail. That California AG's office had previously announced that they were going to go hard on this matter and it looks like they are following through on the threat. It is expected, though, that the Wagner indictment is just bait to catch bigger fix. He is expected to cooperate with authorities.

Read more on the Wagner indictment via the IHT.

-- MDT

Labels: , , , , , , ,

0 Comments.
Post a Comment
11/16/2006
Data Breaches 2006, A Pictorial Guide
Going back to the well, from earlier in the week... Here's another great post at The Consumerist, a pictorial history of the year's major breaches, a subject we've been following for quite a while now. Check it out here.

-- MDT

Labels:

0 Comments.
Post a Comment
8/03/2006
Kroll Worldwide Hires New York City Official
From the press release:
Senior Criminal Justice Official for NYC Mayor's Office Joins Kroll

Press Release
August 1, 2006

Richard Plansky, formerly the Deputy Criminal Justice Coordinator for the Office of the Mayor of the City of New York, has joined Kroll, the global risk consulting company, as a managing director in its Business Intelligence & Investigations division.

Based in Kroll's head office in New York, Plansky is responsible for corporate investigations, fraud prevention and detection, and integrity due diligence.

Plansky, a 14-year veteran of the criminal justice system, has led complex investigations involving sex crimes, homicides, police shootings, larcenies, and other serious crimes. Most recently, as Deputy Criminal Justice Coordinator, he oversaw the development of multi-agency criminal justice initiatives, including a comprehensive program targeting the distribution and use of illegal guns. He also developed the John Doe Indictment project, a citywide effort to preserve unsolved sex crimes for later prosecution through the use of DNA technology.

Plansky began his career as an assistant district attorney in New York County where, from 1992 through 2001, he prosecuted 30 Supreme Court trials and conducted more than 150 grand jury presentations and investigations. He subsequently served as assistant general counsel at the City University of New York, where he led extensive investigations involving allegations of organized cheating and identity theft, as well as student and faculty misconduct.

In 2002, Plansky was appointed special counsel to the Mayor's Criminal Justice Coordinator, and was promoted the following year to general counsel and director of the Mayor's Office of Midtown Enforcement. In this role, he oversaw all legal affairs, formulated quality of life enforcement strategies, and developed and coordinated a wide spectrum of criminal justice programs, including an initiative to combat large-scale trademark counterfeiting establishments.

Plansky received his Juris Doctor, magna cum laude, from Harvard University.

More on Kroll, here.

-- MDT

Labels: , ,

0 Comments.
Post a Comment
7/26/2006
Let's Call it a Low Risk of Identity Theft
More than 8,000 New York City homeless have their personal data exposed via an errant email.

-- MDT

Labels:

0 Comments.
Post a Comment
6/28/2006
Data Insecurity at the GAO?
Regular readers of this space will already be aware that I am, in general, a big fan of the GAO, the former General Accounting Office, recently given the un-sexy new backronym Government Accountability Office. Normally it is the GAO that lays down the law on government waste, fraud or incompentence, but this week it was their turn to take the credibility hit. Apparently the agency has inadvertently exposed personal information for some 1,000 people via its website, GAO.gov. The personal details were included on 1970s-era defense department travel vouchers. While there has been no indication that data (which included the identity theft rosetta stone, social security numbers) has been misused, the GAO has made a point of removing it from their website.

The Daily Caveat still loves ya guys.

-- MDT

Labels: ,

0 Comments.
Post a Comment
1/27/2006
FBI Director Calls for Greater Cooperation on Computer Fraud
Direct from Davos and the ongoing World Economic Forum comes new rcommedations on how best to deal with the growing international dilemma of computer fraud. On the scene was FBI director Robert Muller who spoke up for greater information sharing and standardization of regulations to help law enforcement track, combat and prosecute fraud across national boundaries. Via the ever venerable Financial Times:
FBI chief urges exchange on computer fraud data

By Peter Thal Larsen in Davos
The Financial Times
January 26 2006

...Speaking at the World Economic Forum in Davos on Thursday, Mr Mueller said there was no need to create a global agency to battle computer fraud, but added: “There can be standardised regulations and rules relating to data retention and secondly a mechanism for the swift exchange of information.”

His comments come amid signs that computer security and the risk of online fraud are an increasing risk for both companies and consumers. A survey of large companies by Swiss Re shows computer-based risks as their main concern, ahead of other worries such as corporate governance and natural disasters. Meanwhile, research by Visa International, the credit card network, shows that identity theft and fraud is the main concern of consumers around the world...

...The FBI has worked together with other law enforcement agencies to track down hackers who co-ordinate attacks on US companies but are based in other countries. However, Mr Mueller stressed that common regulations in areas such as data retention would make it easier for investigators to track down the perpetrators...
The full article appears here.

-- MDT

Labels:

0 Comments.
Post a Comment
1/06/2006
Cell Phone Records For Sale...Legality Optional
The Washington Post ran a story a few months back with a similar theme - that black market vendors of questionable legality are making available cell phone records to anyone with a credit card. A new Chicago Sun-Times article discusses the issue in more depth, describing how internet based vendors use inside sources, either conned or bribed, to surreptitiously snag telephone records. A private investigator is even quoted in the piece stating how he uses these types of tools month-in, month-out.

Frankly, I cannot believe that these stories haven't received wider attention given the recent explosion of identity theft-related stories in the news and Verizon's recent lawsuit against an illegitimate reseller of it's customer data. This type of questionable access to sensitive data is, potentially, the steroid abuse scandal of our industry and, just as in sports competition, a reliance on performances enhancing tools of questionable legality can only mean trouble in the long run.

While there is no doubt that investigators are always on the hunt for new sources of information, as our industry has grown to service a more sophisticated clientele, such as Caveat Research's client base of top-flight legal and financial firms, taking risks on questionable activities while on a client's dime is simply unacceptable. Caveat's work supports crucial business decisions and legal action and our activities have to mirror the best business practices of the clients we service.

Our clients look to us, in part, to recommend courses of action that adhere strictly to federal, state and local regulations. Fraudulently obtained telephone records are simply not a part of that equation. Anyway...enough of my rant. Here's the article:
Your phone records are for sale

January 5, 2006
BY FRANK MAIN
Crime Reporter

The Chicago Police Department is warning officers their cell phone records are available to anyone -- for a price. Dozens of online services are selling lists of cell phone calls, raising security concerns among law enforcement and privacy experts. Criminals can use such records to expose a government informant who regularly calls a law enforcement official.

Suspicious spouses can see if their husband or wife is calling a certain someone a bit too often. And employers can check whether a worker is regularly calling a psychologist -- or a competing company. Some online services might be skirting the law to obtain these phone lists, according to Sen. Charles Schumer (D-N.Y.), who has called for legislation to criminalize phone record theft and use.

In some cases, telephone company insiders secretly sell customers' phone-call lists to online brokers, despite strict telephone company rules against such deals, according to Schumer. And some online brokers have used deception to get the lists from the phone companies, he said.

"Though this problem is all too common, federal law is too narrow to include this type of crime," Schumer said last year in a prepared statement. The Chicago Police Department is looking into the sale of phone records, a source said. Late last month, the department sent a warning to officers about Locatecell.com, which sells lists of calls made on cell phones and land lines.

"Officers should be aware of this information when giving out their personal cell phone numbers to the general public," the bulletin said. "Undercover officers should also be aware of this information if they occasionally call personal numbers such as home or the office, from their [undercover] ones."

Test got FBI's calls in 3 hours

To test the service, the FBI paid Locatecell.com $160 to buy the records for an agent's cell phone and received the list within three hours, the police bulletin said. Representatives of Data Find Solutions Inc., the Tennessee-based operator of Locatecell.com, could not be reached for comment.

Frank Bochte, a spokesman for the FBI in Chicago, said he was aware of the Web site. "Not only in Chicago, but nationwide, the FBI notified its field offices of this potential threat to the security of our agents, and especially our undercover agents," Bochte said. "We need to educate our personnel about the dangers posed by individuals using this site and others like it. We are stressing that they should be careful in their cellular use."

How well do the services work? The Chicago Sun-Times paid $110 to Locatecell.com to purchase a one-month record of calls for this reporter's company cell phone. It was as simple as e-mailing the telephone number to the service along with a credit card number. The request was made Friday after the service was closed for the New Year's holiday.

'Most powerful investigative tool'

On Tuesday, when it reopened, Locatecell.com e-mailed a list of 78 telephone numbers this reporter called on his cell phone between Nov. 19 and Dec. 17. The list included calls to law enforcement sources, story subjects and other Sun-Times reporters and editors.

Ernie Rizzo, a Chicago private investigator, said he uses a similar cell phone record service to conduct research for his clients. On Friday, for instance, Rizzo said he ordered the cell phone records of a suburban police chief whose wife suspects he is cheating on her.

"I would say the most powerful investigative tool right now is cell records," Rizzo said. "I use it a couple times a week. A few hundred bucks a week is well worth the money."

Only financial info protected?

In July, the Electronic Privacy Information Center filed a petition with the Federal Communications Commission seeking an end to the sale of telephone records.
"We're very concerned about Locatecell," said Chris Jay Hoofnagle, senior counsel for the center. "This is the company that sold the phone records of a Canadian official to a reporter 'no questions asked.' "

Schumer has called for legislation to criminalize the "stealing and selling" of cell phone logs. He also urged the Federal Trade Commission to set up a unit to stop it. He said a common method for obtaining cell phone records is "pretexting," involving a data broker pretending to be a phone's owner and duping the phone company into providing the information.

"Pretexting for financial data is illegal, but it does not include phone records," Schumer said. "We already have protections for our financial information. We ought to have it for the very personal information that can be gleaned from telephone records."
The original article appears here.

-- MDT

Labels:

0 Comments.
Post a Comment
12/09/2005
Identity Theft Overblown?
Interesting article forwarded to us by the National Council of Investigations and Security Services, our industry lobbying group:

Fears over identity theft overblown:

US study – From Yahoo News

Thu Dec 8,12:37 AM ET
A new study suggests consumers whose credit cards are lost or stolen or whose personal information is accidentally compromised face little risk of becoming victims of identity theft.

The analysis, released late on Wednesday, also found that even in the most dangerous data breaches -- where thieves access social security numbers and other sensitive information on consumers they have deliberately targeted -- only about 1 in 1,000 victims had their identities stolen.

ID Analytics, the San Diego, California-based fraud detection company that performed the analysis, said it looked at four recent data breaches involving a total of 500,000 consumers. It declined to provide the names of the companies involved in the breaches, but Mike Cook, ID Analytics co-founder, said one of them was a top five U.S. bank.

After six months of study, comparing compromised information against credit applications, ID Analytics said it discovered something counterintuitive: The smaller the breach, the greater the likelihood the information was subsequently used by fraudsters to hijack the identity of victims.

"If you're in a breach of 100, 200 or 250 names, there's a pretty high probability that you're identity is going to be used," said Mike Cook, ID Analytics' co-founder.

"The reason for that is if you look at how long it takes a fraudster to use an identity, they can roughly use 100 to 250 in a year. But as the size of the breach grows, it drops off pretty drastically."

A study conducted earlier this year by Javelin Strategy and Research, which mirrored the methodology of an earlier Federal Trade Commission study, found that 9.3 million Americans said they had been victimized by identity thieves during the preceding 12 months.

ID Analytics said it discovered that identity thieves have a hard time using a stolen credit cards to hijack the identity of cardholders because the cards are usually quickly canceled -- and because piecing together an identity based on the information on the card is hard work. Not one of the card breaches it studied resulted in a subsequent identity takeover.

While the findings will provide some comfort to consumers whose credit cards are lost or lifted or whose sensitive information is compromised when, for instance, a laptop is stolen, as recently happened at Chicago-based Boeing Co.(NYSE:BA - news), some of ID Analytics' suggestions could be controversial.

The company suggests, for instance, that companies shouldn't always notify consumers of data breaches because they may be unnecessarily alarming people who stand little chance of being victimized.

That's likely to rankle consumer watchdogs, who are pushing Congress to enact a law, sponsored by Sen. Arlen Specter (news, bio, voting record), Republican of Pennsylvania, and Sen. Patrick Leahy (news, bio, voting record), Democrat of Vermont, that requires companies to implement tough data security standards and to notify consumers, law enforcement and credit-reporting agencies whenever there's a breach.

"As far as notifications, we think there are certain instances where businesses might want to notify consumers and certain instances where they might not to inform them," said Cook.

"For instance, if they lose data, and they don't know where it is, we think too many notices may not be a good thing. They should probably monitor that and spend dollars on consumers who are actually harmed, rather than spending dollars on 10 million consumers" most of whom won't be affected.

Labels: ,

0 Comments.
Post a Comment


all content © Michael D. Thomas 2010