Showing posts with label identity theft. Show all posts
Showing posts with label identity theft. Show all posts

Friday, April 2, 2010

Identity Thieves/Fraudsters Find New Hunting Grounds

Identity thieves and fraudsters continue to find new ways to ply their trade. An article in today’s "Voice&Data" Magazine identifies three non-traditional domains where identity related crimes are proliferating:

E-Payments
New online and mobile payment methods, such as peer-to-peer (P2P) payments (already available as a Facebook application) are creating opportunities for identity thieves. According to the article, some of these payment modes do not ensure adequate identity verification when processing a transaction.

Mobile Payment
Many mobile devices can now be used as “electronic wallets” to facilitate financial transactions. Unfortunately, this technology provides additional opportunities for fraudsters to not only steal your identity, but your money as well.

Social Media
Social networking sites, such as Facebook and LinkedIn, contain personal information which can be “borrowed” by identity fraudsters to create fake accounts in your name.

The article goes on to recommend the use of multi-factor authentication, with biometrics, including voice, as one of the factors, to help prevent identity fraud.

For more information on identity theft, including steps you can take to safeguard your personal information, click
here.

Friday, March 12, 2010

U.S. Secret Service on Identity Theft

Last night, I attended a seminar on "Identity Theft" presented by a U.S. Secret Service Special Agent. According to Javelin Strategy and Research (Wall Street Journal -- 2/10/2010), identity-theft is on the rise in the U.S. A record 11.1 million adults, up 12% from 2008, were victims. The total cost was $54 billion, up 12.5% from 2008.

The agent covered a number of topics including: how fraudsters get personal information, how fraudsters use that information, what to do if personal information is stolen and, finally, how to safeguard personal information.

How Fraudsters get Personal Information

According to the Secret Service, some of the methods used by fraudsters to get personal information are:


• Stealing mail (e.g., credit card statements, tax information, etc.)
• Rummaging through trash
• Bribing employees who have access to personal information
• Hacking databases containing personal information
• Stealing personal information from a place of work
• Obtaining a person’s credit report by posing as their landlord, employer, etc.
• Stealing card numbers by capturing data in an electronic “skimming” device
• Stealing wallet or purse
• Breaking into a home to steal personal information
• “Phishing” for personal information via email

How Fraudsters use Personal Information

According to the Secret Service, some of the ways fraudsters use personal information are:

• Call credit card issuers to change victim’s billing address
• Open new credit cards in victim’s name
• Establish new phone service in victim’s name
• Open a bank account in victim’s name and write bad checks
• Counterfeit checks or credit cards in victim’s name
• Authorize electronic transfer of victim’s funds
• File for bankruptcy in victim’s name to avoid debts fraudster incurred using victim’s name
• Taking out a loan in victim’s name
• Seeking employment in victim’s name
• If arrested, giving victim’s name to police

What to do if Personal Information is Stolen

According to the Secret Service, the following four immediate steps should be taken if personal information is stolen:

• Review and place a fraud alert on credit reports
• Close all accounts that may have been tampered with or opened fraudulently
• File a police report
• File a complaint with the Federal Trade Commission

How to Safeguard Personal Information

According to the Secret Service, these are some of the ways to safeguard personal information:


• Setup “strong” passwords for all accounts (e.g., avoid easily available information)
• Secure personal information at home
• Be vigilant when providing personal information on the phone, through email, etc.
• Deposit outgoing mail at post office and remove mail from mailbox promptly
• Shred personal information before placing in trash
• Don’t carry Social Security Card
• Limit amount of identification information and credit/debit cards when going out

• Install virus protection software
• Don’t open files sent by strangers
• Don’t store financial information on laptops
• Delete personal information from computers before disposing

After the presentation, the agent and I spoke about how voice biometrics can help stem the rising tide of U.S. identity theft and fraud. For example, financial institutions could deploy voice biometrics in their call centers. Fraudsters who obtained a victim’s personal information (e.g., mother’s maiden name, date of birth, etc.), would be thwarted when they are prompted to provide a sample voiceprint (which would then be compared to the victim’s base voiceprint). Also, credit card companies could require voice biometrics identity verification, at point of purchase, for certain transactions. These are just some of the ways that voice biometrics could be used to reduce identity theft related crimes.

Friday, March 5, 2010

Voice Biometrics Case Study - Bell Canada

In 2007, Persay and IBM Global Services Canada began the rollout of the first large-scale customer-facing voice biometrics system. It is only fitting that the client was Bell Canada. After all, in 1867, Alexander Graham Bell’s father began work on developing an early voiceprint.

Bell is Canada’s largest communications company. According to Persay’s Website, the principal project driver for Bell was to fight identity theft and make the privacy protection (i.e., verification) process more convenient for customers.

Enrollment process:
• Customer calls Bell’s contact center and is presented with the option to enroll using an IVR system
• If the customer opts in, the enrollment process is initiated. Or, if the customer opts out, they can ask for a re-prompt to enroll in 60 days
• Customer enrolls by repeating a pass phrase “At Bell, my voice is my password” three times (process takes approximately 2 minutes). The captured “base” voiceprint is stored in the database for future verification
• The enrollment is secured by the customer’s PIN and an account number and they are notified (via callback or SMS) when the enrollment process is completed


Click here for a demo.

Verification process:
• In subsequent calls to Bell’s contact center, the customer is prompted to repeat their “At Bell, my voice is my password” pass phrase. The captured “sample” voiceprint is then compared to the customer’s “base” voiceprint
• If the voiceprints match, the customer is successfully verified and is automatically granted access to the IVR or a live agent (who is alerted that the customer’s identity has already been verified – saving time)
• Customer can add multiple voiceprints per account to enable access for additional authorized co-users (e.g., spouse)


Click here for a demo.

To date, more than 2,000,000 Bell Canada customers have voluntary enrolled and verification rates exceed 4,000,000 a year.