On the trail of my identity thief
msn.com
msn.com
Over a year I tracked them down and in the end got my money back by sending facebook messages to his mother and brother. Found out his real name because some school friend of him had posted a screenshot of a windowed game which facebook open in the background where you could see his friendlist. Crazy stuff. Even BBC wrote about it later [2]
Fun fact: Since that article aired (8 years ago) I'm still getting 2 to 5 messages per week from random people who ask me to track down their scammers too
[1] https://blog.haschek.at/2016/how-a-scammer-stole-500-dollars...
https://www.bostonglobe.com/2024/05/15/magazine/on-the-trail...
Things will get better when the customers realize they aren't the victims of the thieves. Banks are the victims of the thieves. Customers are actually the banks' victims.
This kind of thing has been framed from day 1 very carefully by banks. Don’t fall for it.
Someone had printed a business check with our account number, made out to a name that matched a dead person on the sex crimes registry, and then someone had cashed that check at a bank in New Jersey. The check was for over $11k, and left about $20 in the account.
Now, we never left that much money in the account generally but we had transferred some in to settle with the various vendors and for spending cash on the honeymoon.
The good news was that Chase saw it as fraudulent immediately and the money was back in our account in less than 48 hours, and they put a few thousand in before then so we could travel.
That said, bank security in the US is generally awful. Checks should not exist - they are a concept out of another era. Actually, in the US, just having someone's account number enables you to withdraw money from their account. That is just nuts.
By now, all money transfers should be electronic and immediate. Where I am, we use the "Twint" service. Want to pay in a shop? Scan a QR code off the card reader, then click ok. Want to send money to a private person? Select them from your contacts, enter the amount, click ok. Transfers are completed in seconds, which also eliminates the issue of bouncing checks.
What confuses me is that the bank has my photo ID already. So when someone comes in to make a large cash withdrawal using a fake ID with my name on it, doesn't the teller see my face on screen to match?
I find it hard to believe that the thiefs managed to find a mule that looks exactly like the victim.
I've had my primary checking account since the 80s, the photo would not look anything like me. When I opened my passbook savings in the 70s I didn't even have a photo ID, just a socical security card.
They originally sent a mail with that requirement, but changed it to the interview instead. I don’t know the internal policy. Presumably they thought they had enough from “public records” as they called it.
I agree with the ‘insane’ moniker… but realized a few years back we’re not in Kansas anymore.
Just went to a concert where you’re not allowed to attend w/o a internet connected terminal in your hand. ((boggle))
https://www.theguardian.com/commentisfree/2018/nov/25/identi...
Banks are notorious for adopting new technology at a glacial pace, often only when forced to do so.
Witness the adoption of chip and pin in the U.S. oh wait, we still haven’t properly adopted it and a stolen card can just be tapped on the terminal of most retailers in 2024 with no additional authentication.
Actually, when someone signed up for a Bank of America checking account with my AT&T information, I notified AT&T once I was done with BofA... And AT&T ignored it, until 2 years later.
Whatever BS shreading and information hygeine I do amounts to nothing when a big company lets stuff out. Or when my employer's HR person keeps unencrypted payroll files on a USB drive in their car in SF.
But the bank also has to deal with dishonest people who might make fraudulent claims about being defrauded.
If the bank is concerned about fraudulent claims about being defrauded, that's just another case of them needing to improve their fraud detection process.
US banking is notoriously sloppy about allowing withdrawals with just knowledge of routing number and bank account number, while every check written contains both numbers -- in Europe, the bank account number can only be used to transfer money to the account (and checks practically don't exist).
One day out of the blue, some hundreds of dollars were transferred out of my American bank account, seeming to claim purchases in a city several hours away. I didn't authorize such transactions. They were direct debits of my account, not credit card charges. A few days later, my money was returned. How was that possible? Why did the bank agree to transfer money out of my account?
All the way back in the 90s, my European bank gave me a one-time codebook, to be used in addition to username and password to authenticate online transfers. Whenever I was close to running out of codes, they gave me a new codebook. Managing to steal my password wouldn't have let an attacker easily empty my account.
My European bank in a small city, that I had been a customer of for decades, and whose employee that I was interacting with being a family friend, verified my passport before discussing a loan.
I've got to wonder how much people's broken understanding of these situations is an extension of that same old mistaken belief that banks hold your money in their safe or something. Notice how she's continually going on about "my money". Whereas actually your bank balance is merely a debt the bank owes you, which cannot have been altered by the bank being defrauded. Any more than a cursory one or two business days to fix her account ledger is unacceptable. If after 60, 90, or however many days the bank cares to spend investigating it turns out that the account owner lied when disputing the original transaction, that would be its own fraud and can be prosecuted post-facto the same as anything else.
Three if you consider that New York let the criminal walk and go on the lam without posting any bail, due to a 2020 (presumably late 2020) 'law'
From the post:
> The bail reform law, which took effect in New York in 2020, eliminated the requirement for defendants to put up cash bail for most misdemeanors and nonviolent felony charges. It was meant to limit incarceration of defendants in New York who couldn’t afford to get out on bail while their cases play out, according to the New York Civil Liberties Union. The nonprofit’s website says reform has been essential to “upholding due process, advancing racial justice, and protecting public health” during the pandemic.
It's often amusing--and sometimes enlightening--to imagine how well the same nonsense-logic would work if it was being used to the benefit of a consumer instead of an institution:
"Hi Bank, I just sent enough money to fully pay off my mortgage! Now I fully own my house and our business is done... Wait, you didn't get it? That was some scammer who showed up randomly at my door with a fake business card? Well, that sucks.... for you, that is. I hope you manage to get your money back from them someday, ciao!"
Could we write laws that require banks to both reimburse the money stolen and to either catch the criminal or to pay more?
I think the banks would just deny that a crime occurred.
As tempting as it is, I have to be against it for now
For this and many other reasons, I will never use a commercial bank again, if I can possibly avoid it.
What worked was to file CFPB (consumer financial protection bureau) complaints against both banks involved. At that point I got to talk to executive support, who is responsible for handling such complaints, and was able to get the two banks to talk to each other. Should've done that about 6 months or so sooner.
https://www.bitsaboutmoney.com/archive/banking-in-very-uncer...
I could easily see it being worked into something satirical in the style of Snow Crash, where there's a loyalty program in silver/gold/platinum, and then an undisclosed super-tier of investor ruby, investor diamond...
But, let's say the laws got fixed and it became the bank's fault. Would there be un-intended consequences or only good ones? I'd expect banks to maybe get rid of checks. Or, require every check to be approved when received. You send a check, the check gets deposited, the bank pings you (email, sms, app) .. did you write this check? Or maybe something else.
If I understand correctly, some countries (Estonia?, Singapore?) when you use a credit card, the bank requires some form of 2 factor. I've seen that once in a while with USA cards, usually only when ordering something abroad. In Japan some banks require a 2 factor calculator that generates codes. No idea if that's prevented much fraud.
Do you have amazon or equivalent? Does every time you order you have to second factor or do you just have to do it once when you sign up for an account?
with other purchases it depends on the site. some ask you every time and others don't. i'd assume charges in the same range don't have to be approved again, but idk how it works exactly
For Amazon and other larger merchants I feel there is some rules system taking as parameters the merchant size (also as a "trustworthiness" score of sorts), recency of last identified purchase (or even some kind of re-using identified auth codes on that merchant), and amount of purchase since almost all larger purchases I make online seem to require 3-D Secure even on larger merchants.
It's not a big hassle, sometimes buying through a new checkout process requires me to authorise the transaction even for small amounts but where I live I can do it through a electronic identification app on my phone, takes some seconds.
The banks use the sort of risk factors they do for other kinds of fraud protection.
If you make a larger transaction than usual, or try to make a transaction with a merchant you've not used before, then you'll usually be prompted to authenticate.
There's also a limit to how many unauthenticated transactions you can make within a period of time.
As with any extra step in a purchase its a balance between security and conversion rates. It seems companies have decided it reduces conversion too much in the US hence the low uptake, whereas UK/EU seem to use it very often.
I think it is a little more nuanced. While I think banks should shoulder more of the responsibility account owners also need to be invested in keeping their personal information secure. If I left my passport, driving license, pin, password, phone (unlocked of course) and 5 years of bank statements by the side of the road a stranger could pick those up and pretend to be me with very little effort, and the bank would be very hard pushed to distinguish the stranger from the real person. If it was purely the bank's problem what incentive would there be for people to secure their information? They'd just reclaim the loss back from the bank.
Someone stole 2k$ from me by using my CC number recently. Well, awesome, why wasn't there even an OTP ? When I want to buy a 10$ crap on Amazon they send me 3 SMS... They leave these things a bit open to reduce friction, they have to pay for it. My bank paid me back the same day, and that was the least they could do.
Plus, fingerprint is super unreliable. Every time I’m hand sanding a wood project, or go windsurfing or wingfoiling for a couple of hours, my fingerprints are unusable for some days.
Until you report those items as stolen, after which they should be not useful at all. Especially the 5 years of bank statements should have no power of authenticating you.
But if it's all on the bank (and to generalise, the other party trying to authenticate the request) why would you report the items stolen? You've got no incentive to do that.
Im exaggerating of course, but the point is that authentication is really difficult if the party you're trying to authenticate isn't motivated to work with you (and why would you be if there's no cost to you if a mistake is made?)
Imagine a world where bank fraud was only possible in that rare scenario you described, and then only for a limited amount of time since you can be required to report loss of identity documents, and then only for transactions that cannot be reverted in time, and even then financial liability might be pushed on to the bank(/'s insurance). That'd solve practically all of the current day bank fraud, without in any way solving your hypothetical.
Not at all. As I said originally:
> I think it is a little more nuanced. While I think banks should shoulder more of the responsibility account owners also need to be invested in keeping their personal information secure.
Some of the comments on this article just strike me as quite idealistic about the ability of banks to bear full responsibility for authentication and authorisation. Practically, I think it works more smoothly when both parties are invested.
I agree, although I'd say it was the banks that need to be more invested, not their customers.
I take significant precautions to maintain the security of my account details and debit/credit cards. My bank is, to say the least, inconsistent about such things. If I travel more than 50 miles (~80km) from my home and attempt to use my debit card, my bank will sometimes (but not always) decline such transactions unless I call them and authenticate myself. Then again, I just had to cancel my debit card, as someone was using it in the Dominican Republic (I live in the US/Northeast) -- and my bank just approved the charges without question.
And so, because my bank doesn't enforce its anti-fraud rules consistently, I get the worst of both worlds -- declined valid charges when I travel, and approved fraudulent charges when fraud is definitely more likely. Sigh.
Edit: Clarified why the Dominican Republic wasn't likely as a valid place for my debit card to be used.
Checks would be completely unaffected, as they're already reversible like any other ACH transaction.
If there is any affect it would be on cash withdrawals and wire transfers seeing increased authentication requirements (places where the transaction "hardness" of money increases). But that's precisely what we want to happen! I do personally withdraw thousands of dollars in cash at a time. But if say I had to use my ATM card + PIN instead of merely writing my 9-digit account number on a paper withdrawal slip, I would certainly understand.
I have high hopes for contactless payments to finally force reader upgrades, because the difference is something the consumer notices and might appreciate. With magnetic strip vs chip, the user experience was too similar.
(Of course, my phone fails to pay about half the time at the local grocery store, but at least the credit card tap works.)
Ditto all government credentials - birth certificates, passports, other licences. All should have been changed decades ago.
But we are talking about the USA. The credit / debit card industry figured this out and published the EMV standard (aka "chip and PIN") in 1995. A few countries made EMV mandatory for credit/debit cards in 2003, most had done it by 2015. The USA waited to 2021 to force the issue using a liability shift.
Now identify fraud is approaching epidemic proportions. In Australia at least the major source of these identity document leaks is data breaches of organisations who were forced by the government to collect copies of licences by Know Your Customer regulations. The penny has finally dropped finally here, with our Feds finally moving to mandating electric ID's and licences. If the governments in haven't realised they a similar position now, they will be soon.
I have deep empathy for how costly these experiences are, that I can then just learn from in 5-10 mins. I hope that in the future more of the bad stuff can be avoided upfront but in the meantime I think this is wonderful and something to foster (which I should remind myself of and participate in more often).
x=https://www.msn.com/en-us/news/crime/an-identity-thief-stole-5000-from-me-i-spent-two-years-tracking-down-how/ar-BB1mqh0b
x=https://assets.msn.com/content/view/v2/Detail/en-in/${x##*-}
(echo "<meta charset=utf-8>";tnftp -4o'|grep -o "<p>.*</p>"' $x|tr -d '\134') > 1.htm
firefox ./1.htm
links 1.htmDoes this seem a little far-fetched? The reporter lost $5000 - a lot of money! - but if it required a high-tech impossible-to-detect fake ID, layers of shadowy criminal gangs and cash mules it seems like there won't be a huge profit left. It seems more likely that this kind of fraud is much less sophisticated, and is exactly the same technology used by adolescents to get into bars.
This feels like another argument that this is an unsolvable problem, and banks are helpless against mysterious dark web hackers. Dive bars are held reasonably accountable over verifying identity, it seems crazy that we accept that banks can't/won't do the same.
It sucks that the criminal skipped bail, so without bail reform that would have only been allowed if she passed a certain threshold of wealth. Thats not mentioned because its clearly not a better outcome.
But this was secretly an article about bail reform, trying to paint a sympathetic picture and then redirect your anger at bail reform.
I hate that. Bail reform is a good, wise policy that works, and no amount of dishonest articles like this will change that.
There is however the question of a potential negative balance. For this, do not allow overdraft protection beyond a small amount. Also, don't have a linked account such as a savings account that gets used for potential overdrafts.
You can have separate account that doesn’t have any cards attached.
Give that account number to your employer and then when you need transfer amounts to account with debit/credit cards.
1. An investment account to move money into, even if it's not invested.
2. A savings account at a second bank from which transactions or even withdrawals cannot be done, only transfers to your checking account at the first bank can be done.
3. A CD (Certificate of Deposit) at a bank, although this locks up your funds for the designated time.
Any checking account leaves you most at risk.
If a victim of fraud, file a police report, go to the bank with it and get your money back. Then change banks as they are incompetent.
It's the banks problem now.
It's always the banks problem to keep your money safe and authenticate things.
It's insane this kind of theft is possible.
Also, OP got the money back:
"two and a half months after the theft — the stolen $5,000 was back in my account."
Someone taking cash off my debit card would need to do it via 3d secure and me approving it via phone.
Someone doing this via check in a bank would get them laughed off... I'm not sure people even know what those are still.
Someone trying to use my identity to withdraw money at a bank agency... they'd need an inside man and police would catch that idiot on complaint... plus since corona going to bank agency is via appointment...
I can also complain to government entities if banks wont help, that would lodge official complaint from consumer protection agency and they need to do due diligence to not get fined...
https://abcnews.go.com/Business/bank-america-florida-foreclo...
Sees the issue with bail reform right away, then wishes we had more regulations like the UK.
On a blockchain, we could have a contract that says "To move more than $X of my money per week, I need to agree by signing with my private key.".
So the bank can only mess up $X per week. And if I lose my private key, I still can get the money out in chunks of $X per week.
So the 5% of people every year who are going to lose their private key can no longer buy a house or car for the rest of their life?
So if one loses their key, they would tell the bank to transfer the money in amounts of $X per week to a new account.
If they have set $X to 2% of their savings, they would have to wait 50 weeks until they can use the full sum again.
Your bank is still a single point of failure.
In the article, the bank claims:
Someone had actually come into the bank and spoken
to a teller, presented a driver’s license, and then
correctly answered some authentication questions to
validate the account.
The bank does not claim that someone just "used the website".The criminal pretends to be injured after cops arrest her while she is running from them, and she composes herself so she looks like a victim. LOL!
Then the criminal gets the victim to feel sorry for her.
Then she gets released almost immediately, so she can do it again!
This is why we used to hang criminals on the day of the trial.