Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

10/21/2008
07:47 PM
George V. Hulme
George V. Hulme
Commentary
50%
50%

Protecting Your Identity: It's About Much More Than Tech

When thinking about identity theft, we often get caught up in the big retail hacks, the lost and unencrypted backup tapes, and how we interact with Web sites. But that's often the wrong focus. Here's why.

When thinking about identity theft, we often get caught up in the big retail hacks, the lost and unencrypted backup tapes, and how we interact with Web sites. But that's often the wrong focus. Here's why.I just read a story in the Mille Lacs County Times about a case of identity theft. The couple in this story pleaded guilty to numerous identity theft charges in federal court. Nothing especially out of the norm there, but the lesson to be learned is in how they were accused of doing it.

The couple pleaded to stealing mail, documents, blank checks, account information, and a slew of other types of documents. They allegedly created counterfeit checks and defrauded merchants from about $50,000 is stuff and services.

The story is available here. Here's how it looks like they were caught:

In September 2006, the Benton County Sheriff's Office searched a vehicle that had been occupied by the couple just moments earlier. Authorities seized documents pertaining to other individuals, including passports, birth certificates, bank statements, credit cards, completed checks, blank checks, motor vehicle certificates, and driver's licenses.

In March 2007, authorities executed a search warrant at the couple's home in Ramsey where they seized numerous checks without information, computer discs containing check writing software, four laptop computers, printers, lamination devices, and stolen mail.

The gist of the story: Low-tech means were used to capture information to be used for identity theft and merchant fraud, while some high-tech equipment was used to create false documents.

The moral: Don't leave documents with sensitive or personal information lying around, and shred any sensitive documents before tossing them into the trash.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Manchester United Suffers Cyberattack
Dark Reading Staff 11/23/2020
As 'Anywhere Work' Evolves, Security Will Be Key Challenge
Robert Lemos, Contributing Writer,  11/23/2020
Cloud Security Startup Lightspin Emerges From Stealth
Kelly Sheridan, Staff Editor, Dark Reading,  11/24/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win an Amazon Gift Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-29367
PUBLISHED: 2020-11-27
blosc2.c in Blosc C-Blosc2 through 2.0.0.beta.5 has a heap-based buffer overflow when there is a lack of space to write compressed data.
CVE-2020-26245
PUBLISHED: 2020-11-27
npm package systeminformation before version 4.30.5 is vulnerable to Prototype Pollution leading to Command Injection. The issue was fixed with a rewrite of shell sanitations to avoid prototyper pollution problems. The issue is fixed in version 4.30.5. If you cannot upgrade, be sure to check or sani...
CVE-2017-15682
PUBLISHED: 2020-11-27
In Crafter CMS Crafter Studio 3.0.1 an unauthenticated attacker is able to inject malicious JavaScript code resulting in a stored/blind XSS in the admin panel.
CVE-2017-15683
PUBLISHED: 2020-11-27
In Crafter CMS Crafter Studio 3.0.1 an unauthenticated attacker is able to create a site with specially crafted XML that allows the retrieval of OS files out-of-band.
CVE-2017-15684
PUBLISHED: 2020-11-27
Crafter CMS Crafter Studio 3.0.1 has a directory traversal vulnerability which allows unauthenticated attackers to view files from the operating system.