Monday, August 10, 2015

8/6/`5 - IRS Warns Taxpayers to Guard Against New Tricks by Scam Artists; Losses Top $20 Million

August 6, 2015 - IRS

WASHINGTON — Following the emergence of new variations of widespread tax scams, the Internal Revenue Service today issued another warning to taxpayers to remain on high alert and protect themselves against the ever-evolving array of deceitful tactics scammers use to trick people.
These schemes — which can occur over the phone, in e-mails or through letters with authentic looking letterhead — try to trick taxpayers into providing personal financial information or scare people into making a false tax payment that ends up with the criminal.
The Treasury Inspector General for Tax Administration (TIGTA) has received reports of roughly 600,000 contacts since October 2013. TIGTA is also aware of nearly 4,000 victims who have collectively reported over $20 million in financial losses as a result of tax scams.
“We continue to see these aggressive tax scams across the country,” IRS Commissioner John Koskinen said. “Scam artists specialize in being deceptive and fooling people. The IRS urges taxpayers to be extra cautious and think twice before answering suspicious phone calls, emails or letters.”
Scammers posing as IRS agents first targeted those they viewed as most vulnerable, such as older Americans, newly arrived immigrants and those whose first language is not English. These criminals have expanded their net and are now targeting virtually anyone.
In a new variation, scammers alter what appears on your telephone caller ID to make it seem like they are with the IRS or another agency such as the Department of Motor Vehicles. They use fake names, titles and badge numbers. They use online resources to get your name, address and other details about your life to make the call sound official. They even go as far as copying official IRS letterhead for use in email or regular mail.
Brazen scammers will even provide their victims with directions to the nearest bank or business where the victim can obtain a means of payment such as a debit card. And in another new variation of these scams, con artists may then provide an actual IRS address where the victim can mail a receipt for the payment — all in an attempt to make the scheme look official.
The most common theme with these tricks seems to be fear. Scammers try to scare people into reacting immediately without taking a moment to think through what is actually happening.
These scam artists often angrily threaten police arrest, deportation, license revocation or other similarly unpleasant things. They may also leave “urgent” callback requests, sometimes through “robo-calls,” via phone or email. The emails will often contain a fake IRS document with a telephone number or email address for your reply.
It is important to remember the official IRS website is IRS.gov. Taxpayers are urged not to be confused or misled by sites claiming to be the IRS but ending in .com, .net, .org or other designations instead of .gov. Taxpayers should never provide personal information, financial or otherwise, to suspicious websites or strangers calling out of the blue.
Below are five things scammers often do that the real IRS would never do.
The IRS will never:
  • Angrily demand immediate payment over the phone, nor will the agency call about taxes owed without first having mailed you a bill.
  • Threaten to bring in local police or other law-enforcement groups to have you arrested for not paying.
  • Demand that you pay taxes without giving you the opportunity to question or appeal the amount they say you owe.
  • Require you to use a specific payment method for your taxes, such as a prepaid debit card.
  • Ask for credit or debit card numbers over the phone.
Here’s what you should do if you think you’re the target of an IRS impersonation scam:
  • If you actually do owe taxes, call the IRS at 1-800-829-1040. IRS workers can help you with a payment issue.
  • If you know you don’t owe taxes or do not immediately believe that you do, you can report the incident to the Treasury Inspector General for Tax Administration (TIGTA) at 1-800-366-4484. 
  • If you’ve been targeted by any scam, be sure to contact the Federal Trade Commission and use their “FTC Complaint Assistant” at FTC.gov. Please add “IRS Telephone Scam” to the comments of your complaint.
For more information on reporting tax scams, go to IRS.gov and type “scam” in the search box.
 

DEA Prescription Drug Take Back Event * Contact your local Police Agency so see if they are participating

DEA Announces 10th National Prescription Drug Take-Back
Event will take place from 10 am-2 pm on Saturday, September 26th

JUL 28 (WASHINGTON) - DEA Acting Administrator Chuck Rosenberg today announced that the 10th National Prescription Drug Take-Back will take place September 26th from 10 am-2 pm local time in every state but Pennsylvania and Delaware, where the event will take place on September 12.

As with the previous nine Take-Back events, sites will be set up throughout communities nationwide so local residents can return their unwanted, unneeded, or expired prescription drugs for safe disposal.

Collection sites in every local community can be found by going to www.dea.gov . This site will be continuously updated with new take-back locations.

The National Prescription Drug Take-Back addresses a vital public safety and public health issue. Many Americans are not aware that medicines that languish in home cabinets are highly susceptible to diversion, misuse, and abuse. Rates of prescription drug abuse in the U.S. are at alarming rates, as are the number of accidental poisonings and overdoses due to these drugs. Studies show that many abused prescription drugs are obtained from family and friends, including from the home medicine cabinet. In addition, many Americans do not know how to properly dispose of their unused medicine, often flushing them down the toilet or throwing them away – both potential safety and health hazards.
“Prescription drug abuse is a huge problem and this is a great opportunity for folks around the country to help reduce the threat,” Rosenberg said.  "Please clean out your medicine cabinet and make your home safe from drug theft and abuse.”

In the previous nine Take-Back events nationwide from 2010-2014, 4,823,251 pounds, or 2,411 tons of drugs were collected.

DEA website - Collection sites

Tuesday, July 28, 2015

CNET - 7-27, 15 - Most Android phones at risk from simple text hack, researcher says

Last year, more than 1 billion Android devices shipped around the globe. Security firm Zimperium says this vulnerability could affect 95 percent of them.
 
A security research company claims to have found a vulnerability baked into Android that could endanger nearly all devices running the popular mobile software.
The flaw, says researcher Zimperium, exists in the media playback tool built into Android, called Stagefright. Malicious hackers could take advantage of it by sending to an Android device a simple text message that, once received by the smartphone, would give them complete control over the handset and allow them to steal anything on it, such as credit card numbers or personal information.
So far, Zimperium told National Public Radio, the flaw has not been exploited, but in a blog post on its own website, it said that 95 percent of Android devices worldwide are vulnerable.

And that is potentially a lot of phones. In 2014, over 1 billion Android devices shipped worldwide, according to researcher Strategy Analytics, which expects the number to rise in 2015 and beyond. Zimperium called Stagefright the "mother of all Android vulnerabilities."
Google's Android software has been highly susceptible to security flaws for years, in part because of the open design that makes it popular as an alternative to Apple's iOS, the software that underlies the iPhone and iPad. In the first quarter, 99 percent of mobile malware targeted Android devices, according to security firm F-Secure.

And fixes to Android can take time to get to people's smartphones as those updates ripple through various phone makers and wireless service providers.
Zimperium said it discovered the issue in April and promptly informed Google.
A Google spokeswoman said that those intermediaries are armed with the patches they need to safeguard devices, though she did not offer specifics on which were ready to push those changes through, or when that might happen.

"The security of Android users is extremely important to us and so we responded quickly and patches have already been provided to partners that can be applied to any device," the Google spokeswoman said. "Most Android devices, including all newer devices, have multiple technologies that are designed to make exploitation more difficult. Android devices also include an application sandbox designed to protect user data and other applications on the device."

How the vulnerability gets exploited

The malware that would exploit the Android vulnerability hides inside a short video sent to a person's phone number, according to NPR, which reported on the bug Monday. As soon as the malicious text is received, features built into Stagefright to reduce lag time for viewing videos process the video to prepare it for viewing. That processing apparently is enough for bad guys to get their hooks into the platform and take control.

Exactly when the device might be exploited depends on the messaging platform a person employs. Those using the standard Messenger app built into Android would need to open the text message (but not necessarily watch the video) to fall victim to the trap. Those who are running Google's Hangouts app to handle text messaging, however, need not even open the application, according to Zimperium. As soon as Hangouts receives the text, it processes the video and the hacker is in. (The Google's Play app marketplace says Hangouts has been downloaded between 1 billion and 5 billion times.)
To compound the threat to Android devices, Google is largely powerless when it comes to actually getting patches to users. Phone makers including Samsung, LG and Huawei, as well as wireless carriers, all have control over how updates are sent to products.
Once Android is bundled into a product, it's typically been modified by those third parties. When security updates are required, Google can only send out a patch and after that, it's up to the phone maker or carrier to push those updates to phones.

Acknowledging that Android has become a destination for malware, Google in June announced a rewards program that pays researchers cash for finding bugs and holes that may be exploited in the operating system. Google has offered similar rewards programs to researchers for years with great effect. The company has doled out rewards to researchers who find flaws or security vulnerabilities in its Chrome browser and other software. In 2013, one security expert going by the name Pinkie Pie earned $50,000 for finding a particularly nasty bug in Chrome. Last year alone, Google paid out over $1.5 million to security researchers finding flaws in Chrome and other Google products. In total, the company has paid out $4 million since its bug bounties started in 2010.
Zimperium, which sent a patch to Google that the Android maker has accepted, told NPR that he estimates only 20 percent to 50 percent of Android devices currently in the wild will actually get the updates due to vendors  being slow to react -- if they react at all.

While Zimperium says the risks are high for Stagefright to be exploited, and it's possible that malicious hackers will soon take advantage of the flaw, Android device owners have been dodging at least some malware. In April, Google issued a report claiming that malware installs on Android devices fell by 50 percent in 2014. By the end of the year, Google said that fewer than 1 percent of all Android devices had "potentially harmful applications" installed on them.

According to Zimperium's blog, it will show exactly how Stagefright works and can be exploited at the Black Hat hacker conference in Las Vegas, which starts August 1.
Zimperium did not immediately respond to a request for comment.                                                                                                           
 
 

Tuesday, July 21, 2015

FTC: Dept. of Justice, 1st arrests of six Nigerian nationals from Sth. Africa for Internet Fraud acts in America

It’s A Criminal - 1st Arrests Dept. of Justice, Arrests made for Internet Scams and Fraud


You hear from us fairly often about imposter scams. In recent months, we’ve told you about IRS imposters, romance scams, and work-at-home scams. We always give you tips on how to spot and avoid these scams. We tell you about the cases we’ve brought to shut down the scammers. But, as a civil law enforcement agency, we don’t often get to tell you about the criminal charges brought against the scammers. Until today.

The Department of Justice (DOJ) recently announced the extradition of six Nigerian nationals from South Africa to Mississippi to face a nine-count federal indictment for various Internet frauds. These six people join 15 others who were previously charged with, among other things, conspiracy to commit mail fraud, wire fraud, bank fraud, identity theft, and money laundering.

What were the scams? According to the indictment, the defendants found and reached out to their potential victims through online dating websites and work-at-home opportunities. In some cases, they carried on so-called romantic relationships with their targets, trying to get their victims to do things like re-ship merchandise purchased with stolen credit cards, deposit counterfeit checks, and send money to the defendants – whether via wiring money or sending prepaid debit cards.

Here’s where you come in. If you know someone who lost money or information to romance, reshipping, fake check, or work-at-home scammers, please tell them to visit DOJ’s announcement. Why? Because there’s a list of aliases and email addresses that the defendants allegedly used in carrying out these scams. If you recognize a name or email address, you could help in the investigation of these crimes.

It’s not every day you get to help lock up alleged bad guys. Unless, of course, you work at the Department of Justice, the US Postal Inspection Service, or Homeland Security Investigations – all of which had a hand in this case. Please check out the list and see if you might have information to share with the investigators.

* Click on the link below for the Dept. of Justice announcement on the arrests of six Nigerians for scams and fraud. The names and email addresses used are listed.

Department of Justice

Monday, July 6, 2015

Michigan Cyber Security Initiative Newsletter , July 2015

Michigan Cyber Initiative News offers updates on Governor Rick Snyder’s cyber initiative as well as knowledge and awareness on cybersecurity issues. This monthly newsletter is produced by the Michigan Department of Technology, Management and Budget , Office of Cybersecurity.
Click on the link below for the current issue.


MI Cyber Security Newsletter for July 2015

Monday, June 8, 2015

Data Breach: Office of Management and Budget- “ 4 Million Federal Employees data breached”


June 4, 2015, by Lisa Weintraub Schifferle, Attorney, FTC Division of Consumer and Business Education

 
A data breach at the Office of Personnel Management (OPM) and you’re a current or former federal employee whose personal information may have been exposed. What should you do? Take a deep breath. Here are the steps to take. 

First Steps

Check your credit report at annualcreditreport.com. Look for accounts or charges you don’t recognize. Even if the breach didn’t involve credit card information, thieves may use your Social Security number, address and date of birth to open accounts in your name.

OPM announced that it plans to offer credit report access, credit monitoring, and identity theft insurance and recovery services to potentially affected individuals. Take advantage of this offer.

Place a fraud alert on your credit reports. With a fraud alert, businesses must verify your identity before providing new credit. An initial fraud alert lasts 90 days but you can renew it.    

 
To access the remaining recommendations click on the link below:


FTC - Federal Employees what to do if your information has been comprised

Wednesday, May 20, 2015

FTC / MI Attorney General: Charity Scams


5/19/15, LANSING – Michigan Attorney General Bill Schuette today joined state law enforcement partners in every state in the nation, the District of Columbia, and the Federal Trade Commission, to jointly file a federal lawsuit against four phony cancer charities and their operators, who allegedly scammed more than $187 million from consumers throughout the country.
The joint complaint alleges the defendants including Cancer Fund of America, Children’s Cancer Fund of America, Cancer Support Services and The Breast Cancer Society, portrayed themselves to donors as legitimate charities with substantial nationwide programs.
     “Federal and State law requires honesty of our charities and fundraisers.  We will not tolerate those who employ unscrupulous fundraising tactics to deceive donors in Michigan and across the country,” said Schuette.  “Our actions today mean that those charities aiming to deceive those who want to help children with cancer and breast cancer patients will be held accountable.” 
For more details on the groups sited and how to find out if a charity is credible click on the link below.
MI Attorney Generals Website

Wednesday, May 6, 2015

Better Business Bureau: Purchase Property Deed $83 when you can get it for $2 ? - “Record Transfer Services- Unsolicted request”


The BBB has received complaints about the "Record Transfer Services" unsolicited letter asking you to pay $83.00 for a copy of your home deed and assessment profile.
 
You have to read the fine print where they acknowledge on the second page that you can get this from your local County Clerk.
 
If you received a letter from Records Transfer Service Company charging $83.00 for a copy of your “Current Grant Deed and Property Assessment Profile” it is an unsolicited request for you to pay for something that you don't need.   It fits the classic scam formula.
 
See the attached:
 

If you received this letter please call your local County Clerks office to alert them to the letter and asked to get it from them if needed but don't fall prey to the unsolicited letter

Milwaukee Journal - Public Investigator "Deed Scam".
 

 

Tuesday, May 5, 2015

Netsmartz - Online Safety PSA contest


Don't forget about the Speak Up for Safety PSA contest. There's still time to enter!

Encourage teens to submit a 30 to 60-second video explaining the one thing they think teens need to know about being safer online. The deadline for entries is May 12, 2015.

Click on the link for details from Netsmartz about the PSA contest.




 
 
 
 
 
 
 
 

Tuesday, March 31, 2015

FTC: Reluctant to be rude?


March 25, 2015, Amy Hebert Consumer Education Specialist, FTC

Respectfulness and politeness, they’re valued in many close-knit communities. But when you’re dealing with a scammer, those values can backfire, as we’ve heard during our ongoing effort to fight fraud in every community. Scammers try to take advantage of your politeness to get you to hand over money or personal information.

Here are some situations when it would be just fine to interrupt, hang up, and not give a caller the time of day: 

1.)   They want your personal information

2.)   They want you to spend money right away

3.)   They keep talking

4.)   They are threating you

 
For more details from the Federal Trade Commission on the situations sited above click the link below.

FTC- Fraud, It's ok to be rude,,,,,

National Missing and Exploited Children: Rethinking “Stranger Danger”


“Stranger danger” It’s short. It’s simple. It even rhymes! But is it really the most effective abduction prevention lesson for our children?  Children do not understand the concept of a stranger. Many believe that strangers are mean, ugly people — so the nice man asking for help to find his lost puppy? Not a stranger.

A New Message

Although “stranger danger” seems like an easy way to teach our children basic personal safety, it actually puts them at a disadvantage. Children who are taught stranger danger may: Be afraid to ask helpful strangers for assistance when they need it Not knowing how to recognize and avoid risky situations. Instead of teaching “stranger danger,” try the following tips when talking to your child about abduction prevention safety:

Don’t say: Never talk to strangers.

Say: You should not approach just anyone. If you need help, look for a uniformed police officer, a store clerk with a nametag, or a parent with children.

Don’t say: Stay away from people you don’t know.

Say: It’s important for you to get my permission before going anywhere with anyone.

Don't say: You can tell someone is bad just by looking at them.

Say: Pay attention to what people do. Tell me right away if anyone asks you to keep a secret, makes you feel uncomfortable, or tries to get you to go with them.

 
For more tips for parents, grandparents, child care providers, and the faith community, click on the National Missing and Exploited link below.

 

NC for ME Children- Kidsmartz

Monday, March 16, 2015

MI AG Bill Schuette- "Avoid being a victim -2015 Tax Scams" information for consumers

CONSUMER ALERT
 
BILL SCHUETTE
ATTORNEY GENERAL
 
The Attorney General provides Consumer Alerts to inform the public of unfair, misleading, or deceptive business practices, and to provide information and guidance on other issues of concern.  Consumer alerts are not legal advice, legal authority, or a binding legal opinion from the Department of Attorney General.
 
 
IRS Will Never Ask for Taxpayers' Personal Information by Phone or in E-mails
 
Anybody contacting you claiming to be from the IRS and asking you for personal identifying information is a crook.  Every year the IRS issues warnings about rebate or other scams being perpetrated by con artists claiming to work for the agency.  The goal of these crooks is to commit identity theft, take control of personal computers, or simply duping people out of cash.  IRS scams enable con artists to get bank account information, Social Security numbers, or credit and debit card details that are then used to commit identity theft.
 
IRS E-MAIL SCAMS
 
E-mail continues to be the method of choice for IRS scams.  Common e-mail tricks used by these crooks include using:
  • the official IRS logo,
  • whole sections of text from the IRS's website,
  • a fake "from" address (reported Michigan variations include irs@getrefundnow.com, support@irs.gov, service@irs.jg.gov, tax-refunds@irs.gov and other variations on the irs.gov theme),
  • forms with numbers similar to those the IRS already uses, often with a jumble of numbers and letters.
Don't fall for any e-mail scams! The IRS never initiates e-mails to taxpayers!
 
Refund E-mail.  Several variations of this bogus e-mail exist, all falsely claiming to come from the IRS and informing the recipient to click on a link to access a refund claim form that requires personal identifying information.  The crooks try to make this look legitimate by using a specific refund sum that sounds convincing (reported Michigan variations include $134.80 and $184.80).  A recent new twist is aimed at tax-exempt organizations and includes the name and a fake signature of an actual IRS employee.
 
The "Where's My Refund?" variation of this bogus e-mail offers track your refund and asks for your last name, Social Security Number, and credit card information.
 
Audit E-mail.  This bogus e-mail informs the recipient that his or her tax return will be audited.  As if the threat of an audit was not enough to get someone's attention, the e-mail may include a greeting in the body addressed to the specific recipient by name.
 
Tax Law Changes E-mail.  Directed at accountants and businesses, this bogus e-mail invites the recipient to download information on tax law changes.  Clicking on the link downloads malware.  Malware is short for malicious software and describes software designed to infiltrate or damage a computer system without the owner's informed consent.  Malware can take over the victim's computer hard drive, giving someone remote access to the computer, or it could look for or record passwords or other information and send that valuable personal identifying information to the crook.
 
Cash Reward for Completing Online Customer Satisfaction Survey.  This e-mail purports to pay taxpayers for completing an online survey that, of course, includes questions asking for personal identifying information.
 
 
IRS PHONE SCAMS
 
Back Taxes or Penalty Phone Call.  High pressure calls threaten legal action that can only be avoided by immediate payment. Payment must be made by difficult-to-trace Green Dot or similar money transfer methods. Victims provide the card numbers and PINs to the caller, and the caller quickly wipes the cards clean of cash.

Rebate Phone Call. 
 Aimed at seniors, the caller identifies himself as an IRS employee and tells the targeted victim that he is eligible for a sizable rebate for filing taxes early.  The fake IRS employee states that he needs the target's bank account information for direct deposit of the rebate.  Providing your bank account details gives criminals access to your funds.
 
Paper Check Phone Call.  In this telephone scam, a fake IRS employee indicates the IRS sent a check that has not been cashed and the IRS needs to verify the individual's bank account number.  The only way the IRS collects your bank account details is if you choose to put them in your tax return. 
 
 
WHAT TO DO IF YOU GET AN E-MAIL OR PHONE CALL PURPORTING TO COME FROM THE IRS
 
If you know the e-mail or call purports to be from the IRS, don't open the e-mail or answer the phone.  You may forward e-mails to phishing@irs.gov, the address established by the IRS to receive, track, and shut down these scams.  Detailed instructions for how to send the e-mails are in the IRS's publication "Protect Yourself from Suspicious E-Mails or Phishing Schemes."  You may not receive an individual response to your e-mail because of the volume of reports the IRS receives each day.
 
You may also report misuse of the IRS name, logo, forms, or other IRS property to the Treasury Inspector General for Tax Administration toll-free at 1-800-366-4484.
 
Also remember that the only genuine IRS website is www.irs.gov.  You should never get to this site using a link embedded into an e-mail - instead enter the address in your browser.  A website embedded into an e-mail can easily take you to a fake site.
 
 
BEWARE OF ADVANCE REFUND LOANS
 
An advance refund loan is a loan based on money you are expecting to get as a tax refund.  These loans can be legitimate but lenders charge huge rates of interest and fees.  Sending your return in on time will sometimes get your money is just a few weeks, without a hefty price.


TAX-RELATED IDENTITY THEFT
Tax-related identity theft occurs when someone uses your stolen Social Security number to file a tax return claiming a fraudulent refund. The IRS is often the first to inform a victim that identity theft has occurred.  Victims should immediately contact the IRS Identity Protection Specialized Unit at 800-908-4490. Report the fraud and ask for ID Theft Affidavit Form 1439 (form is also available online throughPublication 5027 Identity Theft Information for Taxpayers). 
Complete the form and continue to pay your taxes and file your tax return, even if you must do so by paper. 
One of the most effective ways to protect yourself from this type of identity theft is to file your tax return as soon as possible.  Additional identity theft prevention measures are outlined in the Attorney General’s Identity Theft Information for Michigan Consumers consumer alert.

 
ADDITIONAL INFORMATION
 
Consumers may contact the Attorney General's Consumer Protection Division at:
 
Consumer Protection Division
P.O. Box 30213
Lansing, MI 48909
517-373-1140
Fax: 517-241-3771
Toll free: 877-765-8388
www.mi.gov/ag (online complaint form)

Friday, February 13, 2015

Turbo Tax: Intuit Working With State Governments to Solve Emerging Tax Fraud Problem


MOUNTAIN VIEW, Calif. – Feb. 6, 2015 – Intuit Inc. today announced it is working with state agencies to address growing concerns over state tax fraud. During this tax season, Intuit and some states have seen an increase in suspicious filings and attempts by criminals to use stolen identity information to file fraudulent state tax returns and claim tax refunds.

To assist any customers who believe they are victims of tax fraud, Intuit has implemented a plan that includes a dedicated toll-free number, 800-944-8596, with direct access to specially trained identity protection agents who will provide comprehensive support and filing assistance. In addition, Intuit will provide identity protection services and free credit monitoring, as well as provide access to all versions of its software or to the assistance of one of Intuit’s credentialed tax experts who will prepare taxes for affected customers at no expense.

Click on the link below for more information on what to do if you use Turbo Tax and or a victim of fraud because someone has used your information to obtain a tax return through this program.

 



Intuit, Inc. TurboTax