Wednesday, January 28, 2015

Crime Prevention Tip of the Day: Avoid falling prey to the "IRS Scam - Send $ by using Reloadit packs"

STOP

Crime Prevention Tip of the Day: 
IRS Scam- You owe money!
Rich Coleman, PSCC, PTDPS CPAM


Protect yourself from falling prey to the IRS telephone scam.  Residents across Michigan and the country are getting calls from scammers saying they owe money and the police are coming to their home to arrest them if they don't send it by using Reloadit packs.


Here is an announcement from the Reloadit Pack website on this and other scams using their products.  Please pass on to others.

For additional assistance contact your local Police / Sheriff's Department's Crime Prevention personnel for tips.

 

Protect Yourself from Scams!

DO NOT PROVIDE THE PACK NUMBER FROM THE BACK OF THE RELOADIT PACK TO ANYONE OVER THE PHONE YOU DO NOT KNOW OR HAVE NOT MET IN PERSON. PROVIDING YOUR PACK NUMBER IS LIKE SENDING CASH AND CANNOT BE TRACED.

The Reloadit product is intended to load money onto reloadable prepaid cards. It is for personal use only - to add funds onto your own prepaid card or a family member or friend's card.
Beware of scams that ask for Reloadit pack numbers, such as:
REloadit image
  • Government agency claiming you owe money for any penalties or back taxes.
  • Utility company requiring immediate payment for electricity.
  • Law enforcement agency claiming your loved ones, such as a grandchild, is in jail and needs to post bail.
  • Lottery company claiming you have won a prize and need to pay taxes.
If you have been asked to provide Reloadit as a form of payment, please call 1 (888) 633-9434 prior
to purchasing.

Reloadit website

FBI- Business Watch Alert; "Business E-Mail Compromise" 1/22/15

Public Service Announcement

Prepared by the Internet Crime Complaint Center (IC3)

January 22, 2015
Alert Number: I-012215-PSA
FBI Logo


Business E-mail Compromise

The Business E-mail Compromise (BEC) is a sophisticated scam targeting businesses working with foreign suppliers and/or businesses that regularly perform wire transfer payments. Formerly known as the Man-in-the-E-mail Scam, the BEC was renamed to focus on the “business angle” of this scam and to avoid confusion with another unrelated scam. The fraudulent wire transfer payments sent to foreign banks may be transferred several times but are quickly dispersed. Asian banks, located in China and Hong Kong, are the most commonly reported ending destination for these fraudulent transfers.
The BEC is a global scam with subjects and victims in many countries. The IC3 has received BEC complaint data from victims in every U.S. state and 45 countries. From 10/01/20131 to 12/01/2014, the following statistics are reported:
  • Total U.S. victims: 1198
  • Total U.S. dollar loss: $179,755,367.08
  • Total non-U.S. victims: 928
  • Total non-U.S. dollar loss: $35,217,136.22
  • Combined victims: 2126
  • Combined dollar loss: $214,972,503.30
The FBI assesses with high confidence the number of victims and the total dollar loss will continue to increase.
The BEC scam is linked to other forms of fraud, including but not limited to: romance, lottery, employment, and home/vacation rental scams. The victims of these scams are usually U.S. based and may be recruited as unwitting “money mules.”2 The mules receive the fraudulent funds in their personal accounts and are then directed by the subject to quickly transfer the funds using wire transfer services or another bank account, usually outside the U.S. Upon direction, mules may sometimes open business accounts for fake corporations both of which may be incorporated in the true name of the mule.
The “Attorney Check Scam” is another type of fraud that is linked to the BEC scam in the following manner:
  • Attorneys are targeted to represent supposed (BEC) litigants in a payment dispute.
  • Retainers in the form of checks are sent by (BEC) litigants to the attorney.
  • The scam is revealed when either the checks are found to be fraudulent or the (BEC) litigants are contacted.
  • While the payment disputes are real, the (BEC) litigants neither contacted nor retained that attorney for legal assistance.

The victims of the BEC scam range from small to large businesses. These businesses may purchase or supply a variety of goods, such as textiles, furniture, food, and pharmaceuticals. This scam impacts both ends of the supply chain, as both supplies and money can be lost and business relations may be damaged.
It is still largely unknown how victims are selected; however, the subjects monitor and study their selected victims prior to initiating the BEC scam. The subjects are able to accurately identify the individuals and protocol necessary to perform wire transfers within a specific business environment. Victims may also first receive “phishing” e-mails requesting additional details of the business or individual being targeted (name, travel dates, etc). Some victims reported being a victim of various Scareware or Ransomware cyber intrusions, immediately preceding a BEC scam request.

VERSIONS OF THE BEC SCAM

Based on IC3 complaints and other complaint data received since 2009, there are three main versions of this scam:
Version 1
A business, which often has a long standing relationship with a supplier, is asked to wire funds for invoice payment to an alternate, fraudulent account. The request may be made via telephone, facsimile or e-mail. If an e-mail is received, the subject will spoof the e-mail request so it appears very similar to a legitimate account and would take very close scrutiny to determine it was fraudulent. Likewise, if a facsimile or telephone call is received, it will closely mimic a legitimate request. This particular version has also been referred to as “The Bogus Invoice Scheme,” “The Supplier Swindle,” and “Invoice Modification Scheme.”
Version 2
The e-mail accounts of high-level business executives (CFO, CTO, etc) are compromised. The account may be spoofed or hacked. A request for a wire transfer from the compromised account is made to a second employee within the company who is normally responsible for processing these requests. In some instances a request for a wire transfer from the compromised account is sent directly to the financial institution with instructions to urgently send funds to bank “X” for reason “Y.” This particular version has also been referred to as “CEO Fraud,” “Business Executive Scam,” “Masquerading,” and “Financial Industry Wire Frauds.”
Version 3
An employee of a business has his/her personal e-mail hacked. Requests for invoice payments to fraudster-controlled bank accounts are sent from this employee’s personal e-mail to multiple vendors identified from this employee’s contact list. The business may not become aware of the fraudulent requests until they are contacted by their vendors to follow up on the status of their invoice payment.
CHARACTERISTICS OF BEC COMPLAINTS
The IC3 has noted the following characteristics of BEC complaints:
  • Businesses and personnel using open source e-mail are most targeted.
  • Individuals responsible for handling wire transfers within a specific business are targeted.
  • Spoofed e-mails very closely mimic a legitimate e-mail request.
  • Hacked e-mails often occur with a personal e-mail account.
  • Fraudulent e-mail requests for a wire transfer are well-worded, specific to the business being victimized, and do not raise suspicions to the legitimacy of the request.
  • The phrases “code to admin expenses” or “urgent wire transfer” were reported by victims in some of the fraudulent e-mail requests.
  • The amount of the fraudulent wire transfer request is business specific; therefore, dollar amounts requested are similar to normal business transaction amounts so as to not raise doubt.
  • Fraudulent e-mails received have coincided with business travel dates for executives whose e-mails were spoofed.
  • Victims report that IP addresses frequently trace back to free domain registrars.

SUGGESTIONS FOR PROTECTION
The IC3 suggests the following measures to help protect you and your business from becoming victims of the BEC scam:
  • Avoid Free Web-Based E-mail: Establish a company web site domain and use it to establish company e-mail accounts in lieu of free, web-based accounts.
  • Be careful what is posted to social media and company websites, especially job duties/descriptions, hierarchal information, and out of office details.
  • Be suspicious of requests for secrecy or pressure to take action quickly.
  • Consider additional IT and Financial security procedures and 2-step verification processes. For example -
    • Out of Band Communication: Establish other communication channels, such as telephone calls, to verify significant transactions. Arrange this second-factor authentication early in the relationship and outside the e-mail environment to avoid interception by a hacker.
    • Digital Signatures: Both entities on either side of transactions should use digital signatures. However, this will not work with web-based e-mail accounts. Additionally, some countries ban or limit the use of encryption.
    • Delete Spam: Immediately delete unsolicited e-mail (spam) from unknown parties. Do NOT open spam e-mail, click on links in the e-mail, or open attachments. These often contain malware that will give subjects access to your computer system.
    • Forward vs. Reply: Do not use the “Reply” option to respond to any business e-mails. Instead, use the “Forward” option and either type in the correct e-mail address or select it from the e-mail address book to ensure the intended recipient’s correct e-mail address is used.
  • Significant Changes: Beware of sudden changes in business practices. For example, if a current business contact suddenly asks to be contacted via their personal e-mail address when all previous official correspondence has been on a company e-mail, the request could be fraudulent. Always verify via other channels that you are still communicating with your legitimate business partner.

FILING AN IC3 COMPLAINT
If you believe your businesses is the recipient of a compromised e-mail or is a victim of the BEC scam (regardless of dollar amount), you should file with the IC3 at www.IC3.gov. Please be as descriptive as possible, identify your complaint as “Business Email Compromise” or “BEC” and try to include the following information:
  • Header information from e-mail messages
  • Identifiers for the perpetrators such as names, e-mail addresses, websites, bank account information (especially where transfers were requested to be sent), and beneficiary names
  • Details on how, why, and when you believe you were defrauded
  • Actual and attempted loss amounts
  • Other relevant information you believe is necessary to support your complaint

Complainants are also encouraged to keep all original documentation, e-mails, faxes, and logs of all telecommunications. You will not be able to add or upload attachments with your IC3 complaint; however, please retain all relevant information, in the event you are contacted by law enforcement.

1.The IC3 began tracking the BEC scam 10/01/2013.
2.“money mules” are defined as a person who transfers money illegally on behalf of others.

Monday, January 26, 2015

Fire Safety In the Home: National Fire Prevention Association - " Smoke & Carborn Monixide Detectors -replace / inspect "


National Fire Prevention Association (NFPA):


“Smoke alarms on the list of 10 everyday items you probably need to replace”

HNLTV News story: "In the event of a fire, a smoke alarm is a key factor in a safe resolution," says HLNTV. "The National Fire Protection Association urges consumers to replace all smoke alarms every 10 years. And, they suggest testing them every month to make sure your detectors (Smoke & Carbon Monoxide) are working properly."

For details and tips from the NFPA on fire prevention in the home click on the image below from the 2014 Fire Prevention Week campaign:


 


NFPA: Put a Freeze on Winter Fires


NFPA - Home Heating Safety Tips

FTC: Annualcreditreport.com - Don't be fooled by Imposter Websites


FTC: Annualcreditreport.com - Don’t be fooled by Imposter Websites

 
Only one website is authorized to fill orders for the free annual credit report you are entitled to under law, annualcreditreport.com. Other websites that claim to offer “free credit reports,” “free credit scores” or “free credit monitoring” are not part of the legally mandated free annual credit report program. In some cases, the “free” product comes with strings attached. For example, some sites sign you up for a supposedly “free” service that converts to one you have to pay for after a trial period. If you don’t cancel during the trial period, you may be unwittingly agreeing to let the company start charging fees to your credit card.

Some “imposter” sites use terms like “free report” in their names; others have URLs that purposely misspell annualcreditreport.com in the hope that you will mistype the name of the official site. Some of these “imposter” sites direct you to other sites that try to sell you something or collect your personal information.

Annualcreditreport.com and the nationwide credit reporting companies will not send you an email asking for your personal information. If you get an email, see a pop-up ad, or get a phone call from someone claiming to be from annualcreditreport.com or any of the three nationwide credit reporting companies, do not reply or click on any link in the message. It’s probably a scam. Forward any such email to the FTC at spam@uce.gov.   Click on the link to access the site.

 
Annualcreditreport.com - Official website
                            

 

Thursday, January 15, 2015

Better Business Bureau: Fake Emails from Gmail carry Malware


The BBB, in a January 13, 2015, alert provided great tips and information from Google about the recent fake Gmail emails. I've provided some of the information from the article as well as a link to Google.
 
Better Business Bureau:
 
Have a Gmail account? Watch out for scam emails posing as messages from Google. They may look like official notices about your account, but they carry malware.

How the Scam Works:

You receive an email that appears to be a message about your Google or Gmail account. One version of this scam informs you that "You have exceeded your email limit quota." Another tells you that "you have a deferred email." The text is hyperlinked in both, implying that you should click for more information. Don't do it!

 

 
Better Business Bureau- Consumer Protection Tips

Tax Identity Theft Awareness Week January 26-30, 2015


Tax season is getting close and for some people, so is an experience with tax identity theft or IRS imposters. Tax identity theft happens when someone uses your Social Security number to get a tax refund or a job. You usually find out something’s wrong after you file your tax return. Click on the image below for details.


BBB, Tax ID Theft Week 2015

Friday, December 5, 2014

'A Wonderful Time for the Year' - for Cyber Criminals - 12/3/14, Saline Patch , Beth Dalbey, Reporter


12/3/14 Saline Patch, author Beth Dalbey

Data breaches “could get ugly” during the holidays, and retailers are woefully underprepared to defend their customers against cyber attacks, security experts warn.
Last year, cyber criminals stole credit card and personal information for up to 110 million customers of Minneapolis-based Target in a massive security breach that began on Black Friday and continued through Dec. 15.

Problem solved? Not exactly, the San Jose Mercury News reports.
“Compared to two years ago, I would say that not much has changed except the urgency by the criminals,” said Martin Ferenczi, president of North American operations for Oberthur Technologies, a digital security company.

The newspaper cited a study by BitSight Technologies, a Cambridge, MA-based security firm that analyzed the risk of breach at 300 large retail companies and found that 58 percent are less secure than they were a year ago.

The reasons? There’s little cyber-security expertise in board rooms; retailers can’t find the cash to invest in protection systems; and they’re playing catch-up trying to stay ahead of tech-savvy criminals.

Since the sweeping Target breach, there have been at least 20 public data breaches, the newspaper said. Though retailers have beefed up their networks to protect their customers data, thieves have become stealthier, smarter and more efficient hackers, the newspaper said.

“It’s definitely going up,” John Kipp, chief operating officer for the cyber risk security company Sera-Brynn said. “We’ve already eclipsed last year in terms of data breaches, and the holidays haven’t arrived yet. I think it’s going to get ugly.”

At the same time, some retailers have lowered their safeguards to avoid processing delays during the busy holiday shopping season.

“It’s the perfect time to get boatloads of credit cards in one shot,” Kipp said. “The holiday season is a wonderful time for criminals.”

To protect themselves from retail hacks, experts advise consumers to use cash or prepaid cards instead of credit and debit cards. Also, make financial transactions only on encrypted websites beginning with “https,” and avoid making online transactions on public wi-fi.
Forbes offers additional advice:
  • Set one day a week to monitor your credit card statements;
  • Sign up for real-time alerts for purchases deemed “unusual;”
  • Keep your private information private and avoid disclosing too much to unsolicited callers;
  • Routinely change passwords and make them strong;
  • Subscribe to an identity protection service that will keep tabs on your Social Security number, credit card transactions and other data.

Friday, November 14, 2014

Coalitions in Action: Michigan Coalition Sounds the Siren on New Synthetics

CPAM Members / MI Communities -  An increase in Synthetic drug use in our state has been recognized in the most recent CADCA publication. I would recommend signing up for this important resource alerts and notices for your communities. I've attached the alert for review and the link to their website.  Rich Coleman, CPAM

Nov 13, 2014
Drug type: Synthetic Drugs
Forget about Spice and K2. There’s new synthetic cannabinoids in town that a coalition in southeastern Michigan wants you to know about: “Cloud 9” and “Hookah Relax”.

Margaret Farenger, a current member and volunteer at the Bay Haven Prevention Coalition and former director of the Alliance for Coalitions of Healthy Communities, explained that this drug is a “hard one for parents to detect,” since it is sold in gas stations and party supply stores and looks like eye drops. It is commonly marketed as either e-liquid or incense, but could be nothing more opposite.

“The DEA doesn’t even know what’s in it until they test it,” Farenger said, adding that a few youth have been hospitalized this year after using it. “We are trying to notify schools and families and address this through other kinds of drug education. But what can we do to bring in more people in the community to see what types of solutions we can implement?”

Farenger recalled when synthetic cannabinoids first appeared in Michigan back in 2008 with a few isolated occurrences. By 2012, K2 and Spice were an epidemic.

“They were marked ‘not for human consumption,’ and were being retailed as products that were labeled as potpourri or air freshener,” she said. “There were high profile serious illnesses and several crimes associated with a young person being under the influence, here in Oakland County. It prompted community organization.”

Farenger explained that the way the synthetics are produced and sold don’t respond as well to the type of law enforcement that is used for other drugs, such as cocaine or heroin. It almost creates a loophole so people are able to sell the dangerous substances legally.

In 2012, her coalition — which is an umbrella group of 14 other coalitions — went door to door to local retailers, asking that they stop selling the substances.

“The advantage of coalition work is existing relationships,” Farenger said. “We jumped into action when tragedies started happening.”

Many local businesses signed a pledge agreeing not to sell synthetics. However, there were retailers who pushed back, saying that the substances are legal and expressed the desire to keep selling.

“Eventually they all signed, except for a few outliers,” Farenger said, adding that about 90 percent of the retailers willingly complied. “The state of Michigan passed a ban at the state level, which put more pressure on them.”

As with many drugs, you can’t rely solely on law enforcement to fix the problem and that’s especially true with synthetic drugs. “It has to be community/retailer relationships to keep it out of circulation,” Farenger noted.

Farenger believes the same strategies will help pull this new generation of synthetics off shelves.
The key is working with retailers and fostering those relationships. “That’s an area where coalitions can excel. The more coalitions in the area, the more you can do,” she said. “That works as a complementary component to the parent/youth education. Instead of just leaving it at parent and youth, you go on a larger scale and let the community know what it needs to do.”

CADCA Building drug-free communities
CADCA

Tuesday, October 28, 2014

Better Business Bureau Alert -Cyber Security tip: Holiday shopping online EBay Scam alert


Next time you shop on eBay, watch out for this scam. Con artists are exploiting vulnerability in eBay's editing feature to redirect online shoppers to lookalike websites that can steal passwords.

How the Scam Works:  You are shopping on eBay for a laptop, cell phone or other popular item, and you see a listing with a great price. You click on it, but instead of taking you to the item's page, it reroutes you through a series of websites. You end up at a page requesting your eBay username and password.

 Don't enter it! The site might look like eBay's log in page, but it's really a different website.  If you input your username and password, it will end up in the hands of scammers.

This gives hackers the ability to access your account, and, if you use the same password for other websites, free pass into other accounts.

 How does this happen? EBay permits sellers to use JavaScript and Flash to add design elements to their listings. But this flexibility allows scammers to add malicious code instead, a practice called cross-site scripting.

How to Protect Yourself from this Scam:

·         Check the URL of the website. Before entering your password or any other information, make sure you are on the correct website. Check the URL in the browser bar.

·         Look for a secure connection. Make sure your personal information is being transmitted securely by ensuring the web address starts with "HTTPS" and has a lock icon.

·         Be wary of listings that look too good to be true. Be suspicious of listings that have prices significantly lower than those listed elsewhere. It could just be a ploy to get clicks.

 
 For more information from EBay click on link below for more details

 
 

Thursday, October 23, 2014

Federal Trade Commission - Disposing of Consumer Report Information? Rule Tells How


In an effort to protect the privacy of consumer information and reduce the risk of fraud and identity theft, a federal rule requires businesses to take appropriate measures to dispose of sensitive information derived from consumer reports.
 
Any business or individual who uses a consumer report for a business purpose is subject to the requirements of the Disposal Rule. The Rule requires the proper disposal of information in consumer reports and records to protect against “unauthorized access to or use of the information.” The Federal Trade Commission, the nation’s consumer protection agency, enforces the Disposal Rule.

 

For more information on the list of lenders and who must comply click the link below.
 
 
 
FTC- Disposal Rule

Friday, October 17, 2014

2014 Cyber Security Awareness month Tip – SMART Phone Apps and Privacy- Android’s “Flash Light Mobile” Apps could be stealing your personal information


CPAM members and community, today  one of our CPAM members brought a serious concern to my attention about SMART phone “Flash light “ mobile apps.   In 2013, the FTC fined one Android  SMART phone mobile app developer for misleading consumers for their free app which provided a flash light but also planted “malware” on their phones to read email, capture personal financial information, delete information, obtain geo tracking information, and sell information collected to third parties. 
 
We are all at risk with the use of “free” apps for our SMART phones and our personal information being stolen and used.  I’ve attached a link to the FTC report with details on their findings below.

I am also attaching a report by the company “Snoopwall” that has published a report “Flashlight Apps Threat Assessment” . This report summarizes the privacy and risk of the top ten Android Flashlight Apps. 
 
This is not an endorsement of  Snoopwall which has develop a mobile flashlight app but what I see as a crime prevention practitioner a comprehensive report of  how / what developers are doing to gain access to your personal information. This report also provides tips on how to delete and reset your SMART phone if you’ve downloaded one of the products. 
 
Snoopwall’s  website (www.snoopwall.com )states that they are  the world’s first counterveillance software companies focused on helping consumers and enterprises protect their privacy on all of their computing devices, let’s hope they are true to their mission, data breaches, and privacy concerns should be at the top of every consumers concerns !   Check their website and the report at the links below.

 
Rich Coleman, CPAM

 
 
 

Crime Prevention tip: Preparing for Holiday Shopping? Prepare for data Breach Notices as well!


Consumers have received notices of “Data Breaches” from multiple top retailers throughout the year. As we prepare for the holidays the Better Business Bureau has provided tips on what to do if you receive a notice that your credit card has been comprised.
 
Click on the link below for details from the B.B.B.
 
 
                                    Better Business Bureau, Consumer Alert

Crime Prevention Month Tip: “Just Hang UP! On Telephone Scams”


Crime Prevention Month Tip:  “Just Hang UP! On Telephone Scams”

Residents throughout the State of Michigan have been receiving “cold calls” from scam artists with the “IRS tax scam, Grandparent scam - “Help I need money”, Medical alert devices, Medicare services, and others, it is recommended not to engage in the pitch, just “Hang up!”
 
If you do decide to speak with them ask them to send you information in writing, get their name, ID number and their supervisor, if they refuse it’s obvious they are impostors. Avoid future calls by monitoring your caller ID for the same telephone numbers or numbers you don’t recognize.

For more information on avoiding being a victim of a scam click the image below to access the Better Business Bureau's website.


BBB

Friday, October 3, 2014

JPMorgan Chase: 10/3/14- Chase Breach Affects 76 Million Households, 7 Million Businesses

Hackers have once again accessed a banking institution and if you have an account with JPMorgan Chase you want to read their statement below and visit the security center for updates.  Please monitor your credit statements for any unusual activity in small / large amounts and report it immediately to the bank.

JPMorgan Chase Alert posted on their website 10/3/14:

Important Update on Cyber Security

We want to update you further on the cyber attack against our company.  After extensive review, here is what our forensic investigation has found to date.
Here’s what you should know now:
  • There is no evidence that your account numbers, passwords, user IDs, date of birth or Social Security number were compromised during this attack.
  • However, your contact information – name, address, phone number and email address – was compromised.        
Your money at JPMorgan Chase is safe:
  • Unlike recent attacks on retailers, we have seen no unusual fraud activity related to this incident.
  • Importantly, you are not liable for any unauthorized transaction on your account that you promptly alert us to.
We are very sorry that this happened and for any uncertainty this may cause you.  We don’t believe that you need to change your password or account information. Click here for answers to questions you might have.  As always, we recommend you use care with your accounts and information, as we describe in our Security Center (Link to Security Center).
We’re here to help
Attacks like these are frustrating. There are always lessons to be learned, and we will learn from this one and use that knowledge to make our defenses even stronger. 
 
 
 

Thursday, October 2, 2014

FTC Halts Fake Medicare Scheme that Took Money from Seniors’ Bank Accounts

Scams targeting seniors and consumers continue to surface to steal money by getting your bank account numbers, social security numbers, and other personal information.

The FTC has once again provided insight into how these groups are working, here is a blog post on the most recent scam.


How low can scammers go? As low as stealing from older consumers to line their own pockets. The FTC says some scammers claimed to be calling on behalf of the government to verify information for a new Medicare card or Medicare-related package. In fact, it was a ruse to get people’s bank account information to make unauthorized withdrawals from their accounts.

The callers said they needed to verify people’s identities using information that included the consumers’ bank account numbers. According to the FTC, the scammers told people that the information would not be used to debit their bank accounts, and that there was no charge for their services. But the FTC alleges that was a lie. Within a month or two, victims learned their bank accounts had been debited, often for $400 or more.

At the FTC’s request, a federal court has temporarily halted this scheme that took millions of dollars from consumers without their consent. The FTC is seeking to permanently end the operation and return victims’ money.
No matter your age, you may know someone who has been scammed by telemarketing fraud. They may not talk about it, but the statistics do. The good news is, you can do something about it. Become an FTC ambassador.

Share what you know, by passing this blog post on to your friends, family or neighbors. Let them know never to give out their bank account information to someone who contacts them over the phone. It could lead to a scammer taking money right out of their account.

 
 

Friday, September 26, 2014

Home Depot Data Breach: Update - Monitor your credit!


9-26/14, The Home Depot data breach's impact is widespread, and it is being reported that the personal information obtained is being used much faster than in previous data breaches. Consumers who shopped at the Home Depot stores should follow up on the offer of "Credit Monitoring" if you shopped at one of the locations. The "hackers" involved with stealing data are selling this information online an it's being reported that the duplicate cards are being used for "everyday items" not big-ticket items, and they are close to or in the same zip code area as reported by one of the FICO alerts services.  
 
When I'm asked what do I do to protect my credit cards when I travel?, " I use a gift card or a pre-loaded card for all purchases." During a trip to Philadelphia recently, I shopped at Home Depot, and I used the gift card for all purchased there and other locations. I don't have to worry about my credit card information being stolen. 
 
Below is the Home Depot website post and link to access their reports. If you are a victim, please continue to monitor their web page for updates. 
 
Rich Coleman, CPAM, Pittsfield Twp. DPS Crime Prevention Unit 
 


Home Depot's Website:

Customer update on payment breach
On Sept. 8, we confirmed that our payment data systems were breached, which could potentially impact customers who used a payment card at our U.S. and Canadian stores in 2014, from April to September. Today, we are able to tell you that the malware used in the recent breach has been eliminated from our U.S. and Canadian networks.
 
We also want you to know that we have completed a major payment security project that provides enhanced encryption of payment card data at point of sale in our U.S. stores, offering significant new protection for customers. The rollout of enhanced encryption to Canadian stores will be completed by early 2015. Canadian stores are already enabled with EMV “Chip and PIN” technology.
 
We apologize for the frustration and inconvenience this breach may have caused. 
 
We also want to emphasize that you will not be liable for any fraudulent charges to your accounts, and we’re offering free identity protection services, including credit monitoring, to any customer who has shopped at a Home Depot store in 2014, from April on.
 
You can learn more about the identity protection services and how to sign up for them at https://homedepot.allclearid.com/.
 
It is important to closely monitor your payment card accounts and report unusual activity to your issuing bank.