ID Theft And What You Can Do About It Barry Caplin Chief Information Security Officer Minnesota Department of Human Services [email_address] Slides on InfoLink
What we will cover What is ID Theft? How does it happen? Facts, more facts What to do if you are a victim? How to protect yourself. Questions.
Identity theft and identity fraud are terms used to refer to all types of crime in which someone wrongfully obtains and uses another person's personal data in some way that involves fraud or deception, typically for economic gain.
How Is It Done Shoulder Surfing - observation Dumpster Diving Mis-delivered or “public access” mail Mailbox theft Stolen purse, wallet, PDA, laptop Social Engineering Internet By known or unknown thieves!
ID Theft was not a federal crime until 1998 Not a high-tech crime - but technology helps Not a new crime Check Fraud
What Do “They” Want? Social Security number Full Name Bank Acct numbers Credit Card numbers Phone Calling Card numbers Pre-approved Credit applications Blank Checks Other Identifying numbers or info
12/20/03 Associated Press Cancer Patient Accused Of Stealing Identities Man Apparently Used Identities To Purchase Phones LANSING, Mich. --  A cancer patient was charged December 18 with stealing the identities of other patients at a Detroit hospital, the Associated Press reports. The Michigan attorney general's office charged Frank James Horton, 36, with one count of obtaining the personal identity information with the intent to unlawfully use the information, and one count of obtaining phone services with the intent to avoid charges. Horton, who has been a patient at Karmanos Cancer Institute in Detroit, is accused of taking the identities between August 2002 and July 2003 and using them to obtain cell phones and telephone land lines. There were nine victims; some had their identities stolen, and Horton attempted to steal others, authorities said. The investigation is ongoing and may result in further charges. The attorney general's office received a complaint from a family member of one of the victims sometime in late summer or early fall after the person noticed bills that seemed out of the ordinary. The hospital's security staff was then able to determine how the information was being taken once they knew the name of the patient involved. The facility put new security measures in place to prevent future identity thefts, but a hospital spokesman wouldn't provide details. The attorney general's office spokesman said he didn't know what information Horton obtained from the other patients, but it was enough to establish a phone account.
Facts 9.9M victims in 2008 (up after 3 yr down-trend) Total fraud costs up ($48B US) $496 consumer cost per incident (down 31%) Faster detection, lower fraud amount, quicker resolution $4849 mean fraud loss per victim
More Facts But… faster use of stolen info Still more offline than online 43% lost/stolen wallets 11% online 13% “friendly theft”
More Facts How your ID is being used: New Account Fraud – credit cards, loans Account Theft  ID misuse
What If... If you think your Identity has been stolen… Contact one of the three major credit bureaus Close suspect accounts File a police report File a complaint with the FTC by phone  and  in writing! (from the FTC website)
MN Law Identity Theft Law – § 609.527, 2006-07 Defines penalties, restitution, reporting Credit Freeze Law – SB 2002 No fees if report filed Others $5 to place or change freeze www.consumersunion.org/pdf/security/securityMN.pdf
What Can You Do?
What Can You Do? Get your Credit Report Look for, and correct, incorrect information Three Credit Reporting Agencies: Equifax Experian TransUnion Other Credit alert services
Credit Reports Fair Credit Reporting Act (FCRA) provides for 1 free report from each of the 3 reporting agencies each 12 months. https://www.annualcreditreport.com/
Credit Reports You are also entitled to a free copy of your credit report if you: Are unemployed and intend to apply for employment within 60 days. Are receiving public welfare assistance.
Credit Reports You are also entitled to a free copy of your credit report if you: Believe your file contains inaccurate information due to fraud. Have had a denial of credit or insurance, within the past 60 days.
What Can You Do? Look at your bills Does the statement make sense? Did you buy that?  Did you shop there? Did you not receive a bill for a card you own? Did you receive a bill for a card you don’t own? Question it if something seems wrong.
What Can You Do? Care with Credit Cards Separate credit cards one just for use online Cut up old cards ??? Don’t sign your cards - instead write “please ask for picture ID”
What Can You Do? Be Stingy with Personal Information “ need to know” don’t put SSN or other ID numbers on checks phone or online request for your info - did you make the call?
What Can You Do? Shred it! Credit card receipts Utility and other bills Unneeded medical forms Pre-approved credit offers anything else with ID numbers or personal info
What Can You Do? Weigh your Wallet (or Purse) Don’t carry SS card or Birth Certificate except when needed. Carry only the cards you need. Try to minimize the personal info - but use common sense. Know what’s in there
Do This! Make a copy of, or write down the info from all the personal identifiers in your wallet/purse and put it in a safe place at home.  If your wallet is stolen you’ll know who to contact.
What Can You Do? Report Theft If something gets stolen, report it! You need to know who to call! Timely reporting will help you later
What Can You Do? Use care online Don’t email personal information Choose passwords without personal info Use virus protection at home Don’t “click here to unsubscribe” from spam - it verifies to the spammer that you exist Online shopping – reputable vendors Delete doesn’t really delete
Phishing
Phishing Looks real, but rarely is From a familiar business (not) May threaten to close account, warn of fraud or virus Legitimate businesses will not ask for your private info via email Vishing
Phishing
 
Phishing <IMG src=&quot;http://pics.ebaystatic.com/aw/pics/x.gif&quot;> <P>Please sign in to your eBay account and update your billing information:<IMG src=&quot;http://pics.ebaystatic.com/aw/pics/x.gif&quot;> <A href=&quot; http://www.account-info.ne1.net /&quot;>  http://signin.ebay.com/eBayISAPI.dll?SignIn&amp;ssPageName=h:h:sin:US&quot; &gt; Note: ne1.net is in Denmark
 
 
 
Phishing <a href=&quot; http://update.llimited-service.com/images/SignOn.htm &quot;> https://hb.affinityplus.org/SignOn.html </a> Note: the domain llimited-service.com has been removed from the Internet!
What Can You Do? ID Theft Insurance Does not prevent ID Theft! Does not cover theft expenses Covers out of pocket credit repair expenses May help with credit repair activities Included in some homeowner/renter policies Some consumer advocates say not worth the money
What Can You Do? Be stingy with personal information Online personal info can be removed by request - yahoo.com, white pages, etc. Facebook/Social Networking IM (Instant Messaging/chat) Close old, unused accounts Opt-out and Do Not Call - see the info sheet
What Can You Do? Watch your Postal mail Pick up new checks at the bank, don’t have them mailed. Don’t mail checks from home mailbox. Pick up your mail promptly.
What Can You Do? Know who’s listening or watching when... Providing personal info over the phone. Entering a PIN/password. Writing down personal info/filling out forms. You don’t need to be paranoid… just aware.
What Can You Do? Don’t fall to Social Engineering Email/phishing scams Phone call for money/donations, or join a list – check into it! Letter indicating something that is too good to be true…
What Can You Do? You’ve done all that you can but...
Hackers breach Heartland Payment credit card system By Byron Acohido, USA TODAY, Feb. 2009 Heartland Payment Systems  (HPY)  on Tuesday disclosed that intruders hacked into the computers it uses to process 100 million payment card transactions per month for 175,000 merchants. Tech security experts said the breach could set a record. Retail giant TJX lost 94 million customer records to hackers in 2007.
What Can You Do? Reduce – your Identity Exposure Record – monitor bills and credit reports Report – problems or suspected fraud
Discussion?

More Related Content

PDF
Scams and-fraud-presentation
PPT
Avoiding Fraud and Identity Theft - October 2008
PPT
Id Theft Seminar 6
PPT
Avoiding Online Job Scams
PPTX
Lottery scam
PPTX
Frauds and scams
PDF
Common Consumer Frauds & How to Avoid Them
PDF
Online Scams and Frauds
Scams and-fraud-presentation
Avoiding Fraud and Identity Theft - October 2008
Id Theft Seminar 6
Avoiding Online Job Scams
Lottery scam
Frauds and scams
Common Consumer Frauds & How to Avoid Them
Online Scams and Frauds

What's hot (20)

PDF
You Can Fight Identity Theft
PDF
You Have the Power to Stop Identity Theft
PPTX
E business internet fraud
PPT
e-Fraud ppt
PPT
Identity Theft
PPSX
IDENTIFYING CYBER THREATS NEAR YOU
PPTX
ELECTRONIC FRAUD TACTICS
PPT
10 Ways To Prevent Internet Fraud
PDF
PPTX
Internet fraud #scichallenge2017
 
PDF
Identity Theft ppt
KEY
Identity theft
PPT
Identity theft power_point
PDF
Identity Theft Consumer Seminar
PPT
Id Theft
PPT
Internet Fraud
PPT
Identity Theft: How to Avoid It
PPTX
E commerce fraud
PPTX
Identity Theft Presentation
PDF
Identity Theft: The Other You
You Can Fight Identity Theft
You Have the Power to Stop Identity Theft
E business internet fraud
e-Fraud ppt
Identity Theft
IDENTIFYING CYBER THREATS NEAR YOU
ELECTRONIC FRAUD TACTICS
10 Ways To Prevent Internet Fraud
Internet fraud #scichallenge2017
 
Identity Theft ppt
Identity theft
Identity theft power_point
Identity Theft Consumer Seminar
Id Theft
Internet Fraud
Identity Theft: How to Avoid It
E commerce fraud
Identity Theft Presentation
Identity Theft: The Other You
Ad

Viewers also liked (6)

PPT
How to Prevent ID Theft
PDF
ID Theft Prevention
PPTX
Who is the next target and how is big data related ulf mattsson
PPT
Identity theft and there types by pooja kalra
PPT
Id Theft Presentation
PPTX
Biometric authentication ppt by navin 6 feb
How to Prevent ID Theft
ID Theft Prevention
Who is the next target and how is big data related ulf mattsson
Identity theft and there types by pooja kalra
Id Theft Presentation
Biometric authentication ppt by navin 6 feb
Ad

Similar to Identity Fraud and How to Protect Yourself (20)

PDF
Identity theft seminar
PPT
Identity Theft: Protecting & Restoring Your Good Name
PDF
Ftc identity theft kit
PPTX
Senior Audience Presentation
PPTX
PPT
RDrew Identity Theft -- What to Do
PPT
Identity Theft Lake Placid 2012
PPTX
Identity Theft Prevention
PDF
Taking Charge: What to Do If Your Identity Is Stolen
PPTX
ASIS Phoenix February Presentation
PPT
ID Theft
PPT
2002 Identity Theft Chicago Public Library
PDF
Identity Theft Awareness 101 - Basics
PPT
Id theft-phishing-research
PDF
IdentIty Theft - ConsumerCents
PPT
Identity Theft Scams
PPT
Identity Theft Prevention
PDF
Common Consumer Frauds and How to Avoid Them-03-14
PPTX
Identity theft pp presentation
Identity theft seminar
Identity Theft: Protecting & Restoring Your Good Name
Ftc identity theft kit
Senior Audience Presentation
RDrew Identity Theft -- What to Do
Identity Theft Lake Placid 2012
Identity Theft Prevention
Taking Charge: What to Do If Your Identity Is Stolen
ASIS Phoenix February Presentation
ID Theft
2002 Identity Theft Chicago Public Library
Identity Theft Awareness 101 - Basics
Id theft-phishing-research
IdentIty Theft - ConsumerCents
Identity Theft Scams
Identity Theft Prevention
Common Consumer Frauds and How to Avoid Them-03-14
Identity theft pp presentation

More from Barry Caplin (20)

PPTX
Healing healthcare security
PPTX
It’s not If but When 20160503
PPTX
Dreaded Embedded sec360 5-17-16
PPTX
It’s not if but when 20160503
PPT
Wearing Your Heart On Your Sleeve - Literally!
PPTX
CISOs are from Mars, CIOs are from Venus
PPTX
Online Self Defense - Passwords
PPT
The CISO Guide – How Do You Spell CISO?
PPT
Bullying and Cyberbullying
PPT
3 factors of fail sec360 5-15-13
PPT
Tech smart preschool parent 2 13
PPT
Embracing the IT Consumerization Imperative NG Security
PPT
Online Self Defense
PPT
Embracing the IT Consumerization Imperitive
PPT
Embracing the IT Consumerization Imperitive
PPTX
Stuff my ciso says
PPTX
IT Consumerization – iPad’ing the Enterprise or BYO Malware?
PPT
Toys in the office 11
PPT
Accidental Insider
PPT
Teens 2.0 - Teens and Social Networks
Healing healthcare security
It’s not If but When 20160503
Dreaded Embedded sec360 5-17-16
It’s not if but when 20160503
Wearing Your Heart On Your Sleeve - Literally!
CISOs are from Mars, CIOs are from Venus
Online Self Defense - Passwords
The CISO Guide – How Do You Spell CISO?
Bullying and Cyberbullying
3 factors of fail sec360 5-15-13
Tech smart preschool parent 2 13
Embracing the IT Consumerization Imperative NG Security
Online Self Defense
Embracing the IT Consumerization Imperitive
Embracing the IT Consumerization Imperitive
Stuff my ciso says
IT Consumerization – iPad’ing the Enterprise or BYO Malware?
Toys in the office 11
Accidental Insider
Teens 2.0 - Teens and Social Networks

Recently uploaded (20)

PPTX
ANALYZE MARKET DEMAND, MARKET SUPPLY AND MARKET.pptx
PPTX
Q1 PE AND HEALTH 5 WEEK 5 DAY 1 powerpoint template
PPTX
Simple linear regression model an important topic in econometrics
PDF
3CMT J.AFABLE Flexible-Learning ENTREPRENEURIAL MANAGEMENT.pdf
PDF
Lundin Gold - August 2025.pdf presentation
PPTX
balanced_and_unbalanced_growth_theory_ppt.pptx
PPT
Conventional Financial Instruments 1.ppt
PPTX
INDIAN FINANCIAL SYSTEM (Financial institutions, Financial Markets & Services)
PDF
Call cute girls 😀 Delhi, call now pls cute girls delhi call🔙
DOCX
BUSINESS PERFORMANCE SITUATION AND PERFORMANCE EVALUATION OF FELIX HOTEL IN H...
PPTX
General-Characteristics-of-Microorganisms.pptx
PDF
Best Accounting Outsourcing Companies in The USA
PPTX
Very useful ppt for your banking assignments Banking.pptx
PDF
2018_Simulating Hedge Fund Strategies Generalising Fund Performance Presentat...
DOCX
ENHANCING THE DINING EXPERIENCE LESSONS FROM THAI TOWN MELBOURNE’S SERVICE EN...
PDF
2012_The dark side of valuation a jedi guide to valuing difficult to value co...
PDF
Lundin Gold Corporate Presentation August 2025
PDF
In July, the Business Activity Recovery Index Worsened Again - IER Survey
PPTX
Group Presentation Development Econ and Envi..pptx
PPTX
Grp C.ppt presentation.pptx for Economics
ANALYZE MARKET DEMAND, MARKET SUPPLY AND MARKET.pptx
Q1 PE AND HEALTH 5 WEEK 5 DAY 1 powerpoint template
Simple linear regression model an important topic in econometrics
3CMT J.AFABLE Flexible-Learning ENTREPRENEURIAL MANAGEMENT.pdf
Lundin Gold - August 2025.pdf presentation
balanced_and_unbalanced_growth_theory_ppt.pptx
Conventional Financial Instruments 1.ppt
INDIAN FINANCIAL SYSTEM (Financial institutions, Financial Markets & Services)
Call cute girls 😀 Delhi, call now pls cute girls delhi call🔙
BUSINESS PERFORMANCE SITUATION AND PERFORMANCE EVALUATION OF FELIX HOTEL IN H...
General-Characteristics-of-Microorganisms.pptx
Best Accounting Outsourcing Companies in The USA
Very useful ppt for your banking assignments Banking.pptx
2018_Simulating Hedge Fund Strategies Generalising Fund Performance Presentat...
ENHANCING THE DINING EXPERIENCE LESSONS FROM THAI TOWN MELBOURNE’S SERVICE EN...
2012_The dark side of valuation a jedi guide to valuing difficult to value co...
Lundin Gold Corporate Presentation August 2025
In July, the Business Activity Recovery Index Worsened Again - IER Survey
Group Presentation Development Econ and Envi..pptx
Grp C.ppt presentation.pptx for Economics

Identity Fraud and How to Protect Yourself

  • 1. ID Theft And What You Can Do About It Barry Caplin Chief Information Security Officer Minnesota Department of Human Services [email_address] Slides on InfoLink
  • 2. What we will cover What is ID Theft? How does it happen? Facts, more facts What to do if you are a victim? How to protect yourself. Questions.
  • 3. Identity theft and identity fraud are terms used to refer to all types of crime in which someone wrongfully obtains and uses another person's personal data in some way that involves fraud or deception, typically for economic gain.
  • 4. How Is It Done Shoulder Surfing - observation Dumpster Diving Mis-delivered or “public access” mail Mailbox theft Stolen purse, wallet, PDA, laptop Social Engineering Internet By known or unknown thieves!
  • 5. ID Theft was not a federal crime until 1998 Not a high-tech crime - but technology helps Not a new crime Check Fraud
  • 6. What Do “They” Want? Social Security number Full Name Bank Acct numbers Credit Card numbers Phone Calling Card numbers Pre-approved Credit applications Blank Checks Other Identifying numbers or info
  • 7. 12/20/03 Associated Press Cancer Patient Accused Of Stealing Identities Man Apparently Used Identities To Purchase Phones LANSING, Mich. -- A cancer patient was charged December 18 with stealing the identities of other patients at a Detroit hospital, the Associated Press reports. The Michigan attorney general's office charged Frank James Horton, 36, with one count of obtaining the personal identity information with the intent to unlawfully use the information, and one count of obtaining phone services with the intent to avoid charges. Horton, who has been a patient at Karmanos Cancer Institute in Detroit, is accused of taking the identities between August 2002 and July 2003 and using them to obtain cell phones and telephone land lines. There were nine victims; some had their identities stolen, and Horton attempted to steal others, authorities said. The investigation is ongoing and may result in further charges. The attorney general's office received a complaint from a family member of one of the victims sometime in late summer or early fall after the person noticed bills that seemed out of the ordinary. The hospital's security staff was then able to determine how the information was being taken once they knew the name of the patient involved. The facility put new security measures in place to prevent future identity thefts, but a hospital spokesman wouldn't provide details. The attorney general's office spokesman said he didn't know what information Horton obtained from the other patients, but it was enough to establish a phone account.
  • 8. Facts 9.9M victims in 2008 (up after 3 yr down-trend) Total fraud costs up ($48B US) $496 consumer cost per incident (down 31%) Faster detection, lower fraud amount, quicker resolution $4849 mean fraud loss per victim
  • 9. More Facts But… faster use of stolen info Still more offline than online 43% lost/stolen wallets 11% online 13% “friendly theft”
  • 10. More Facts How your ID is being used: New Account Fraud – credit cards, loans Account Theft ID misuse
  • 11. What If... If you think your Identity has been stolen… Contact one of the three major credit bureaus Close suspect accounts File a police report File a complaint with the FTC by phone and in writing! (from the FTC website)
  • 12. MN Law Identity Theft Law – § 609.527, 2006-07 Defines penalties, restitution, reporting Credit Freeze Law – SB 2002 No fees if report filed Others $5 to place or change freeze www.consumersunion.org/pdf/security/securityMN.pdf
  • 14. What Can You Do? Get your Credit Report Look for, and correct, incorrect information Three Credit Reporting Agencies: Equifax Experian TransUnion Other Credit alert services
  • 15. Credit Reports Fair Credit Reporting Act (FCRA) provides for 1 free report from each of the 3 reporting agencies each 12 months. https://www.annualcreditreport.com/
  • 16. Credit Reports You are also entitled to a free copy of your credit report if you: Are unemployed and intend to apply for employment within 60 days. Are receiving public welfare assistance.
  • 17. Credit Reports You are also entitled to a free copy of your credit report if you: Believe your file contains inaccurate information due to fraud. Have had a denial of credit or insurance, within the past 60 days.
  • 18. What Can You Do? Look at your bills Does the statement make sense? Did you buy that? Did you shop there? Did you not receive a bill for a card you own? Did you receive a bill for a card you don’t own? Question it if something seems wrong.
  • 19. What Can You Do? Care with Credit Cards Separate credit cards one just for use online Cut up old cards ??? Don’t sign your cards - instead write “please ask for picture ID”
  • 20. What Can You Do? Be Stingy with Personal Information “ need to know” don’t put SSN or other ID numbers on checks phone or online request for your info - did you make the call?
  • 21. What Can You Do? Shred it! Credit card receipts Utility and other bills Unneeded medical forms Pre-approved credit offers anything else with ID numbers or personal info
  • 22. What Can You Do? Weigh your Wallet (or Purse) Don’t carry SS card or Birth Certificate except when needed. Carry only the cards you need. Try to minimize the personal info - but use common sense. Know what’s in there
  • 23. Do This! Make a copy of, or write down the info from all the personal identifiers in your wallet/purse and put it in a safe place at home. If your wallet is stolen you’ll know who to contact.
  • 24. What Can You Do? Report Theft If something gets stolen, report it! You need to know who to call! Timely reporting will help you later
  • 25. What Can You Do? Use care online Don’t email personal information Choose passwords without personal info Use virus protection at home Don’t “click here to unsubscribe” from spam - it verifies to the spammer that you exist Online shopping – reputable vendors Delete doesn’t really delete
  • 27. Phishing Looks real, but rarely is From a familiar business (not) May threaten to close account, warn of fraud or virus Legitimate businesses will not ask for your private info via email Vishing
  • 29.  
  • 30. Phishing <IMG src=&quot;http://pics.ebaystatic.com/aw/pics/x.gif&quot;> <P>Please sign in to your eBay account and update your billing information:<IMG src=&quot;http://pics.ebaystatic.com/aw/pics/x.gif&quot;> <A href=&quot; http://www.account-info.ne1.net /&quot;> http://signin.ebay.com/eBayISAPI.dll?SignIn&amp;ssPageName=h:h:sin:US&quot; &gt; Note: ne1.net is in Denmark
  • 31.  
  • 32.  
  • 33.  
  • 34. Phishing <a href=&quot; http://update.llimited-service.com/images/SignOn.htm &quot;> https://hb.affinityplus.org/SignOn.html </a> Note: the domain llimited-service.com has been removed from the Internet!
  • 35. What Can You Do? ID Theft Insurance Does not prevent ID Theft! Does not cover theft expenses Covers out of pocket credit repair expenses May help with credit repair activities Included in some homeowner/renter policies Some consumer advocates say not worth the money
  • 36. What Can You Do? Be stingy with personal information Online personal info can be removed by request - yahoo.com, white pages, etc. Facebook/Social Networking IM (Instant Messaging/chat) Close old, unused accounts Opt-out and Do Not Call - see the info sheet
  • 37. What Can You Do? Watch your Postal mail Pick up new checks at the bank, don’t have them mailed. Don’t mail checks from home mailbox. Pick up your mail promptly.
  • 38. What Can You Do? Know who’s listening or watching when... Providing personal info over the phone. Entering a PIN/password. Writing down personal info/filling out forms. You don’t need to be paranoid… just aware.
  • 39. What Can You Do? Don’t fall to Social Engineering Email/phishing scams Phone call for money/donations, or join a list – check into it! Letter indicating something that is too good to be true…
  • 40. What Can You Do? You’ve done all that you can but...
  • 41. Hackers breach Heartland Payment credit card system By Byron Acohido, USA TODAY, Feb. 2009 Heartland Payment Systems (HPY) on Tuesday disclosed that intruders hacked into the computers it uses to process 100 million payment card transactions per month for 175,000 merchants. Tech security experts said the breach could set a record. Retail giant TJX lost 94 million customer records to hackers in 2007.
  • 42. What Can You Do? Reduce – your Identity Exposure Record – monitor bills and credit reports Report – problems or suspected fraud