Russian Gang Said to Amass More Than a Billion Stolen Internet Credentials
nytimes.com
nytimes.com
As a victim of identity theft, and as someone who took extreme measure to protect himself from identity theft before it occurred, I can tell everyone without a doubt that the only reason why you're not a victim of identity theft is because of random chance. There is no mechanism to protect yourself, and your information is readily available. The only reason why you haven't gotten your identity stolen is because the thieves simply haven't gotten to you yet.
It's infuriating that these companies can get away with what is essential libel and not have anything done to them. I shredded all my mail, I haven't given any real information about me on any web site since 1997, never gave out any information about me willy-nilly including applying for too many credit cards, and I never fall for phishing attacks. And yet somehow I found myself victim of identity theft, and it took 2+ years to clean up, and it's still not over. Since so many web sites use Experian data to verify my identity, I've lost a lot of opportunity to get credit, loans, etc, because Experian has mixed my information with the fraudulent information, so I get answers to those automated question wrong.
It's truly infuriating, and the system is completely broken, yet no one in government cares.
Equal chances of success as suing them but considerably less expensive.
Also considerably more likely to get you arrested, possibly with overwhelming force.
Which could possibly cause media attention and Internet outrage, so it still feels like a better option than suing.
It took months to fix the address thing and still ten years later I cannot get them to competently resolve the "being financially linked" data error. Sure this was a data provider that caused the problem and they should be responsible for fixing it. But in the end it became impossible to fix because there is no single department in the bank through which the credit record data is passed.
Trying to work with the credit scoring agencies was futile because they just bounce you back to the data provider telling you to tell them to fix their data.
It's like living the the world of Terry Gilliam's Brazil.
(this should be obvious, but just to be sure: IANAL)
Send them a letter where you give them 1 month to resolve the problem, providing full documentation that you are divorced and point that as such the information is incorrect, and that under the Data Protection Act they are legally obliged to ensure incorrect personal information about you is amended or deleted. If you have past correspondence with them where they acknowledge the information is incorrect, then provide copies.
Inform them that if the matter is not resolved, or they have contacted you to agree on how to resolve it, within 30 days, you will file a formal complaint with the Information Commissioner (ico.org.uk).
Provide the same notification to the bank (ensure it is addressed to the legal department).
The credit scoring agencies has a legal obligation under the Data Protection Act to ensure personal information is correct. This applies to all organizations subject to EU data protection rules (which is pretty much everyone with very limited exceptions). That the data comes from a third party is not an excuse if you have provided documentation that the information is wrong. (it may be reasonable that they refer you there first, but if you have tried to get the bank to fix it, and they've not, then it is not reasonable for them to continue to insist).
Ultimately, if even the ICO can not get them to budge, go to a lawyer. Failure to rectify this information is blatant violation of the principles of the Data Protection Act, and you can get a court order to have the information corrected, and in some cases even require that they contact every recipient of the flawed information.
In your case this is important. If either one of you goes bankrupt e.g. you risk the other ones credit score being ruined for about a decade. But frankly, in most cases a threat about a complaint to the ICO ought to be enough. If you've written a letter and complained to ICO, and they fail to correct the information, then a court case will be a walk in the park.
Also note that in certain circumstances you may be due damages incurred as a result of the incorrect information.
See: http://ico.org.uk/for_organisations/data_protection/the_guid...
A last consideration: The Data Protection Act also provides you with some means of insisting that certain types of decisions are not taken automatically, or to have automated decisions reconsidered. This provides you a fallback if e.g. you are often refused credit based on automated scoring based on the flawed data. You can notify the bank in advance in writing that you do not consent to automated decision making, and providing documentation of the divorce, or you can demand a manual reconsideration afterwards (and provide the same documentation).
Under EU data protection laws, in most cases failure to provide you a way to delete or amend incorrect personal information held about you is a clear violation of the law. As is failure to grant you access to information about whom they have passed personal information about you on to.
That doesn't mean they won't try to act like asses sometimes, but bringing up the Data Protection Act and mention a complaint to the Information Commissioner can and does make a difference.
Hey, I don't need to check my account whether I need to chargeback anything. If I need to pay people, I pay people, I don't give them the equivalent to a login.
I was the victim of low-grade identity theft about 10 years ago, all stemming from a credit card number illicitly imprinted by someone at a restaurant. Shit spiraled from there, and it took me years to clean up the fallout.
Dealing with the Big Three credit agencies was a process for which the word "Kafkaesque" somehow falls short of descriptive power. I've been caught in bureaucratic snafus at the DMV and the IRS, and in comparison, both of those processes were a walk in the park on a bright, sunny day.
Our country is basically a consumerocracy, in which one's credit rating is more or less one's fate. If we're going to bestow that much power upon a three-member oligopoly, then we should demand much greater responsibility of its members.
Can you explain this in more detail? I don't understand how a single stolen credit card can cause you years of problems.
Getting this incident wiped from my credit history took an elaborate and drawn-out series of phone calls, letters, forms, interviews, etc. Even then, a decent amount of damage had been done, and various reports had spawned other reports, and I was borked in countless derivative reports and company databases. I had to do some "rebuilding" (in the parlance of the credit companies) for a few years. And this was just one of several, roughly similar purchases that accrued in the system under my name. The irony is that a bolder thief, making bigger purchases and maxing out the card, would have caused less damage to me by catching everyone's attention in flagrante delicto.
To be honest, I'm not sure. All I can do is speculate. All I really know is that my credit card number was obtained and was used to make a few small purchases. Blockbuster was one of them. I didn't find out about Blockbuster -- or its attempts to go after me -- until I got a letter in the mail from a collections agency. That was the first I'd heard of anything involving Blockbuster. I put two and two together and realized it must have stemmed from the credit card theft, which had happened a few months prior, and which I'd assumed had been largely wrapped up by then. I figured that the collections agency hadn't just been called in overnight. No doubt it was the third or fourth step in some procedure at Blockbuster, starting with phone calls and letters, presumably to whatever falsified address and number this guy gave them. When it finally came time to involve collections, collections probably figured that I was some sort of deadbeat, and that "my" address on file with Blockbuster was bogus, and that at least the credit card number and bank were valid. So they found a way to contact me at my real address. (It's also possible they found me, at that point, through some ancient account on file with Blockbuster's system. Who's to say how sophisticated their dedupe practices were with their DB, but I'm guessing not very?)
I have no idea what else was involved in the theft, above and beyond lifting my number. It's possible a fake ID was involved. I really can't say, and I don't want to overstep the bounds of my recollection.
Sadly at this point it would almost be simpler to concoct a new fake identity for yourself and get that entered in than it would be to fix your original corrupted identity.
If you happen to be lucky enough to catch somebody in the act, you can undo the damage pretty quickly, if not altogether painlessly. It'll take a huffy phone call to your credit card company, and some watchful waiting for a month or so afterward. You will get a new card, with a new number, and you'll have to set up new billing numbers for everything. A small, but sharp pain in the ass. [1]
But if you don't catch things right away, and god forbid, if something winds up on your credit report, you are capital-F Fucked. By then it's too late, and your fraudulent data is commingled with your real data in dozens of databases, each one echoing off of the other. The bad data sprouts like kudzu. You can pluck a few shoots out of the ground, and five more pop up in unexpected places, weeks or months later.
[1] You can also set up a proactive solution, like a super-sensitive, early-warning algo at your credit card company. But this net ends up snaring you half the time, like whenever you use your credit card to make small purchases, or buy gas, or out of state, etc. It gets a lot of false positives. My card gets blocked for "fraud" every few weeks, leading to minor headaches at restaurants, bars, and gas stations. But I guess I'll accept this hassle as the price I pay for advance warning of real fraud. At the same time, I'm concerned that this system is just as likely to run into false negatives, which would really suck.
Stories like yours make recovery policies, like [2]this, seem prudent.
[3]My very first post on hacker news, 3.5 years ago, stirred ZERO discussion. "Identity theft is an enormous problem, so what are the solutions? Who's working on something that practically everybody who uses the internet should consider looking into?"
[1]http://www.nbcnews.com/business/consumer/id-theft-tops-ftcs-...
Just so long as there's not a bailout back-door on that.
Not only that but if you pull a whois on the domain it has what appears to be Holden's home address. [1] (I won't post that here but anyone interested can find it).
The gear hanging by what appears to be ethernet cabling is really bizarre. I mean who does that? Especially if you know someone is taking a picture.. (Something isn't right here..)
[1] According to street view.
Original (odd) photo: http://static01.nyt.com/images/2014/08/06/business/06bighack...
Current photo: http://static01.nyt.com/images/2014/08/06/business/06bighack...
It's like the opening shot of a Sofia Coppola film. In my mind, that guy is played by a young Bill Murray.
Was better with the original.
If they set up a bot net to log into as many bank accounts as possible and transfer money around (even if it were just between a users own accounts or accounts already setup for transfer), banks would basically be forced to shutdown internet banking until they could come up with a solution. The economic losses would be tremendous--it would take forever to sort out the mess.
What you're describing would take not just one person who wanted to destroy all of human society, but quite a few of them.
Woah...I'm not talking about something destroying all of human society, I'm talking about a group of people who would like to harm specific countries economically--of which there are more than a few.
Moving money around like what I'm talking about would result in billions of dollars lost. Worst case scenario a stock market crash followed by a recession, not the end of civilization.
That’s it. It knows everything about us, and we think it did this consciously. Yes sir, by manipulating people into doing specific things.
What can it do with this information?
Well sir, it is going to do what it can to establish the ability to keep this information as up-to-date as possible. Nobody is able to escape.
The criminal gangs, Russia and Asia. They were the ones behind this?
Yes and no. They each collected enough information and stole it from each other.
We have to warn the world!
We can’t. It controls everything.
What caused this?
A Meta-pattern within the human psyche reached into the computer and in turn used the computer to amplify its own motives.
The scenario you describe is unlikely. Before such a global catastrophe happens, it's likely that a smaller catastrophe will happen. Like the Titanic, the world will be shocked into preventative action. Governments will make laws.
After that, the difficulty in collecting such massive amounts of information will be greater than the value in that information. Even now, requiring proper software security practices would prevent information-theft from being a viable business. You might get the occasional massive haul, but it wouldn't be an epidemic.
between a blogger criticizing Putin's regime and a hacker who stole a bunch of millions from an American bank - who do you think the Russian government would go after? :)
http://en.wikipedia.org/wiki/Iran_Air_Flight_655#Post-tour_o...
"[T]he Russian hackers have been able to capture credentials on a mass scale using botnets — networks of zombie computers that have been infected with a computer virus — to do their bidding. Any time an infected user visits a website, criminals command the botnet to test that website to see if it is vulnerable to a well-known hacking technique known as a SQL injection, in which a hacker enters commands that cause a database to produce its contents. If the website proves vulnerable, criminals flag the site and return later to extract the full contents of the database.
“They audited the Internet,” Mr. Holden said."
http://www.dailymail.co.uk/sciencetech/article-2703440/There...
Credit cards are surviving in the stone age, firms would rather make it easy for you to get yourself in debt that to provide a service that prevents fraud and abuse. So, VC people out there. If you want to make a billion dollars, you should start a bank. People who work for the credit card community, there are simple upgrades that would make life a lot safer.
Simple upgrades to make security safer:
Chip and pin is low hanging fruit in the US. The fact that most americas have no idea what those threes words mean is an international embarrassment.
READ ONLY passwords for bank account information, in addition to different read write options, that have an extra level of security. I'd gladly use services like Mint, except i'd rather not give write power to anyone except me and a browser i only user for banking only at home.
Tie credit cards to cell phones. Get a text after EVERY purchase (this would honestly not amount to more than 10 or so texts per day). Have this as opt-out, not opt-in. Yes, i would use this, yes it would effectively stunt any fraud. You would not have to respond to the text at all, however, if you suspect fraud, you can immediately cancel the card.
Voice recognition for phone calls. When you take out a card, you are require to read a paragraph or two, and upload, or mail in a recording of your voice. This could immediately alleviate much of the phone security nonsense that i deal with when i'm on the phone. It's not a cure all for passwords, but it's certainly an additional level of security.
IP zones for online credit card purchases. I know about five 100 mile radii that i will be making an online purchase from. Add an extra level of security for any time i'm outside of that.
As far as credit agencies are concerned, there is a serious issue with quasi-oligopoly situations there. Extremely difficult to disrupt, but developing secure credit vehicles could create incentives for the current oligopoly in credit cards to improve security for their own cards.
At the end of the day, i'm more than willing to admit that people themselves are a big part of the problem. Example: a year ago, watching a man freak out on an apple store employee when he would not give a computer to him, that apparently belonged to his son, who gave it to the apple store a week earlier. The son apparently signed off that only he could receive the computer, and only in person. The enraged father was rambling on about how insane it was that they would not surrender the computer to him, and how he would never use apple products again. I wish there were profitable business models for people who actually like following the rules and read the contracts they sign.
tl;dr: I don't want a credit card that makes it easy for me to spend money. I have cash for that. Give me a credit card that makes me feel safe entering the number into any website, and i'll gladly pay a premium for it.
Actually, it would be nice if a service built an API that interfaced with multiple banks, and provided this Oauth natively. Of course, then you have the same problem -- that service has all your passwords. Unless there's some clever end to end encryption that can be done, then sadly we are reliant on all the banks upgrading their systems individually.
You mean like a virtual credit card?
That said, chip and PIN is great and is coming to the US in 2015.
1.2 billion accounts
Modestly estimate they sent emails/posts with 200 million
5 emails from each account
Click rate of 0.01%
Landing page -> offer conversion rate of 15%
Credit card details conversion of 5%
$15 commission on each lead
= $112,000
Even if you tweak that to send more emails or use more accounts, the number is still going to be somewhere around $10-15 million. Not that much.
5 emails from each account? CTR is WAY higher when email comes from someone you personally know.
As far as I can tell, I carry my phone around and it magically does everything to let me into everyplace I'm supposed to be.