Tampilkan postingan dengan label fraud. Tampilkan semua postingan
Tampilkan postingan dengan label fraud. Tampilkan semua postingan

Jumat, 16 Juli 2010

Protect Yourself from Identity Theft

Copyright 2006 Francesca Black Some law-enforcement authorities call identity theft the fastest growing crime across the country right now. In fact, identity theft is the most called-about subject on the Privacy Rights Clearinghouse's telephone hotline. Most victims don't even know how the perpetrators got their personal information. Such fraud may account for as much as 25% of all credit card-fraud losses each year. Not surprisingly 49% of the victims, who have had their identities stolen, stated that they do not feel they know how to adequately protect themselves from this crime. What Steps Can you Take to Avoid Identity Theft? 1. Credit Report Order your credit report each year from each of the three major credit reporting agencies. Check each credit report carefully for accuracy and for indications of fraud, such as credit accounts that you did not open; applications for credit that you did not authorize; credit inquiries that you did not initiate; charges that you did not incur; and defaults and delinquencies that you did not cause. Check the identifying information in your credit report to be sure it is accurate pay particular attention to your identifying information like your name, address, and Social Security number. Make sure that you recognize every line of information established in your file. 2. Social Security Report Additionally order your social security earnings and benefit statement once a year so that you can check to make sure your earnings are correctly recorded. If the numbers are inflated it maybe because someone is using your Social Security number for employment. (Note - The Social Security Administration now automatically mails these statements annually to all eligible workers age 25 and older). 3. Checks Call the payees of any outstanding checks that you are not certain you wrote. The payee is the person or business to whom you wrote the check. Explain to each payee that you are the victim of identity theft and that you have to close your checking account for that reason. Ask each payee to waive (forgive) any late payment or returned check fee. Then send each payee a replacement check drawn on your new account and stop payment on the check that it replaces. It's a good idea to enclose a note with each check explaining why you are sending a replacement check and reminding the payee that the payee has agreed to waive the late payment or returned check fee. 4. Mail If you are traveling be sure to stop your mail delivery at the post office, rather than having it accumulate unattended in your mailbox. If you do not receive your credit card statement on time or if you do not receive a new or renewed credit card when you expect it, your mail may have been stolen. If you notice your mail is dwindling, check with the post office to see if they have any change of address posted. If a change of address request has not been filed at the post office check if one has been filed with the creditor. Guard your mail from theft. Deposit outgoing mail in post office collection boxes or at your local post office, rather than in an unsecured mailbox. Promptly remove mail from your mailbox. Install a lock on your mailbox if you live in an area where mail theft has occurred. This will reduce the risk of mail theft. 5. Good Record Keeping Be sure to keep a list of all your credit card account numbers, expiration dates, and telephone numbers of the customer service and fraud departments in a secure place, not in your wallet or purse, so that you can quickly contact your creditors in case your cards are lost or stolen. Make a list of, or photocopy, all of your credit and debit cards. For each card, include the account number, expiration date, credit limit and the telephone numbers of customer service and fraud departments. Additionally be sure to store a list of bank accounts in secure location, along with access numbers. 6. Lost or Stolen A thief may steal, or the consumer may lose, the consumer's purse or wallet. The thief then may use the consumer's stolen personal identification information to obtain credit in the consumer's name. 7. Collection If you receive calls from collection agencies or creditors for an account you don't have or that is up to date. Someone may have opened a new account in your name, or added charges to an account without your knowledge or permission. Financial account statements show withdrawals or transfers you didn't make. A creditor calls to say you've been approved or denied credit that you haven't applied for. Or, you get credit card statements for accounts you don't have. You apply for credit and are turned down, for reasons that do not match your understanding of your financial position. 8. Notebooks Laptops and notebooks are treasure troves of useful information. Be sure to password protect any sensitive information. When creating passwords and PINs (personal identification numbers) do not use any part of your Social Security number, birth date, middle name, spouse's name, child's name, pet's name, mother's maiden name, address, telephone number, consecutive numbers, or anything that a thief could easily deduce or discover. For tips on strong passwords refer to: http://www.password-software.com . Avoid using an automatic log-in feature that saves your user name and password; and always log off when you are finished. 9. ATM/ Credit Cards If your ATM card has been lost, stolen or otherwise compromised, cancel the card as soon as you can. Get a new card with a new PIN. If you suspect unauthorized use, contact the provider's customer service and fraud departments immediately. Never give out your credit card, bank account or Social Security number over the telephone unless you placed the call and you have a trusted business relationship with the business or organization. Place passwords on credit cards, bank and phone accounts. Avoid using easily available information like mother's maiden name, your birth date, the last four digits of your SSN or your phone number, or a series of consecutive numbers. Cancel your unused credit cards so that the accounts will not appear as being "open" or "active" on your credit report. Shield your ATM or telephone key pad when using an ATM or making a phone call with your phone calling card. Some shoulder surfers' use binoculars or video cameras to record your numbers. If you use ABMs or point-of-sale terminals, always shield the entry of your PIN, and never give your access code (PIN) to anyone. Choose a PIN that can't be figured out easily, as you could be liable if you use a PIN combination selected from your name, telephone number, date of birth, address or Social Insurance Number (SIN). Remember that no one from a financial institution or the police will ask you for your PIN. Always take credit card, debit card and ATM receipts with you. Never throw them in a public trash container. ear them up or shred them at home when you no longer need them. 10. Trash One person's trash is another person's treasure. Shred documents before throwing them away. Be sure to shred credit card statements, bank statements, pre-approved applications, any important papers with identifying numbers. Memorize ALL passwords and PIN numbers. Keep them private. Some thieves create identities by retrieving personal information in your garbage or recycling bin by "dumpster diving". 11. Public Information Some thieves use public information, Searching public sources, such as newspapers (obituaries), phone books, and records open to the public (professional certifications). Consider not listing your residence telephone number in the telephone book, or consider listing your name and residence telephone number without an address. If you decide to list your name and telephone number, consider not listing your professional qualification or affiliation (for example, "Dr.," "Atty.," or "Ph.D ."). 12. Online Banking After completing a financial transaction or online banking, make sure you sign out of the Web site and clear your Internet file/caches (Internet files are retained in your computer automatically and thus should be cleared so that hackers cannot obtain the information). Most financial institutions provide instructions on how to clear the caches under their "security" section. Look for "https" in the URL header and a padlock icon on your Internet toolbar at the bottom of the screen; both indicate that a secure connection is in effect. With Microsoft Internet Explorer, click Tools then Internet Options. On the General tab, click Delete Files, Delete Cookies and Clear History buttons. 13. Posing Do not release any information to anyone calling. Thieves often pose as a creditor, landlord or employer to get a copy of your credit report or access to your personal information from other confidential sources.

Kamis, 24 Juni 2010

How to identify Spoof/Phishing emails - Protect yourself from identity theft.

What is a spoof email? Spoof emails (sometimes also called "Phishing") are emails that pretend to be from a company or bank. The most common often come from eBay, PayPal, Barclays Bank etc. These emails will then contain a web link, if you click on this link then you will be taken to a login page and asked to enter your details. Most of these scammers go a long way to try and get your details, most spoof emails contain links to identical websites and users are tricked into entering their personal information. If you submit your information through one of these spoof websites then the fraudster has all of your details and can commit crimes using your identity. How do they get my email address? You may wonder how the scammers got your address or knew you were a member of a particular bank or institution. Often it is just good luck on the part of the scammers. They normally do not target individuals, but send out thousands of scam emails to randomly generated email addresses, in the hope that just a few will be successful. They also trawl the web for valid addresses they can use, and swap this information with each other. If you have ever posted on an Internet forum or published something on the web, there's a good chance your address is out there somewhere just waiting to be found. If you have fallen victim before, your address is normally added to a list of 'easy victims', and you are likely to then receive even more scams. How can I identify these emails? Here are 4 simple tests that you can perform on any email you suspect is a spoof. Your email can only pass the test if it passes ALL FOUR of the tests. If your email passes all of the four tests then you can be 99.9% certain that it is a genuine email. If your email passes all four of the tests then we would also advise you to check the "Other Tips" section just to double check that your email is genuine. If your email fails If your email fails JUST ONE of the four tests then the email is a spoof and shouldn't be replied to and should be deleted immediately from your computer. Even if your email fails the test, I would still advise you to check out the "Other Tips" page for more good ways to spot a spoof email. If you are still in doubt Unless you are 100% sure that your email is genuine, DO NOT click on any links within the email. Contact the company in question (See the "reporting a spoof" page) and ask them to confirm if the email is genuine or a spoof. Test 1 - Who is the email addressed to? Have a look at how the email addresses you. Most spoofs will say something along the lines of "Dear eBay user". This is the very first thing you should look for in a spoof email. Any email that doesn't address you by your name is a spoof. Ebay, PayPal and banks always address you by the name you registered with on their site, they NEVER send out emails saying "Dear valued customer", "Dear member" etc. If your email isn't addressed to you personally then it is a spoof! If your email is addressed to you then move onto the next test to see if it is a spoof email. Some more advanced spoof messages have started to include your name or email address instead of the generic "Dear member" or "Dear user". So even if your email were addressed to you I would strongly advise you to carry out the 3 other tests. Test 2 - Where does the link go? Most spoof emails will contain a link telling you to verify your details. You can quickly tell if your email is a spoof by hovering your mouse over the link. When your mouse is over the link, look in the bottom left hand corner of your screen and you will see the "link destination". The destination of a spoof link will usually look something like this: "http://slp.clinker.net.mx/.sh/.a/index.htm?SignIn&ssPageName=h:h:sin:us" Compare this with a real eBay link: http://k2b-bulk.ebay.co.uk/ws/eBayISAPI.dll?MyeBaySellingSummary And you can see the difference. You can easily check if you email is a fake by looking at the first part of the link destination, if the destination is a combination of numbers (102.382.54.23) or a link like the one in my spoof link above then the chances are that your email is a spoof. Any non-spoof link will contain the name of the company in the first part of the link, eg: http://cgi.ebay.co.uk http://cgi.ebay.com http://cgi.paypal.com Please note: Some spoof links will contain the words "eBay" or "PayPal" in the final part of the link. These are also spoofs! All real emails will only contain the company name in the very first part of the link; after http://. If you still aren't sure if you have a spoof email, move onto the next test. Test 3 - Who really did send you the email? This test may seem a little confusing but don't worry it isn't as difficult as it looks. What we are going to do is find out where the email came from. Most people don't know this but you can trace the origin of your emails in most mail programs. To do this we have to view the "FULL message header", here is how you do this in the following email programs. If your program isn't listed here please contact your email provider for instructions: Hotmail 1. Click on "Options" 2. Click on "Mail display settings" 3. The 3rd option can be used to display the header settings, select "Full" from the check boxes 4. Click on "OK" to save your settings Outlook Express 1. Right click on the email and select "Properties" 2. Select the "Details" tab Now that we can view the message headers, here is how you identify a spoof: Look in the part of the header that says "Received From". If the email has come from anyone other than the sender it's a spoof. I had a spoof email and performed this test and notice that the email had been sent from a Yahoo account. Obviously a real email from eBay would not have been sent from a Yahoo address! Test 4 - Click on the link Only try this if your email has passed the previous 3 tests. Some spoof emails have been known to contain viruses that are activated by clicking on the link. Please ensure that you have a good virus scanner installed on your PC before proceeding. If you have important data on your PC you may also wish to backup that data on a removable backup device. When you click the link in your email a web browser will open and take you to what looks like a legitimate login page. There are two ways to identify a spoof login page, and I will show you both of them! Have a look in the address bar at the top of the login page. Have a look at the http:// part of the URL. Any genuine login page from eBay, PayPal or your bank WONT start with "http://" it will start with: "https://" The "s" in https:// stands for "secure" and is there to show you that you are about to submit data over a secure connection. Any page not starting with https:// is a spoof. The second difference between the two pages is the padlock icon in the bottom right hand of the screen. Notice that the spoof login page doesn't have a padlock, and the genuine eBay login page does. This padlock appears to show you that you are about to submit data over a secure connection. If your login page DOESNT have a padlock icon in the bottom corner of the screen then it is a spoof! Other Tips for spotting Spoofs 1. Punctuation Read your email carefully and look for any spelling mistakes. You can be sure that any genuine emails wont contain simple spelling mistakes. 2. Adverts? Real emails from eBay don't contain adverts for burger king! 3. Hotmail identity check A new feature in hotmail now warns you if a senderID could not be verified. Any spoof email will contain this warning. (please note that recently I received a genuine email from eBay that contained this warning, so don't judge an email purely by this method) 4. PIN number Any website asking for your PIN (personal identification number) is a spoof. Do not enter your PIN number! If you have entered and submitted your PIN then contact your bank immediately. 5. Popup boxes Some spoof sites will include popup message boxes like the one below. Genuine sites don't use popup boxes telling you to enter details. 6. False sense of urgency Most spoof emails will make you think that your account is at threat if you don't act quickly. This is not the case. 7. eBay Messages Any genuine email sent to you from eBay will also appear in the "My Messages" section of eBay. To access your eBay messages, login to ebay and click on "My eBay". On the left hand side of the screen you will see a "My Messages" link. Click on this; if the email you received in your inbox isn't listed there then it is a spoof email. 8. Ignore the email address Ignore the email address that the email was sent from. Almost all spoof emails will appear as if they are from a genuine address. Some of the emails I receive are "from": service@paypal.com memberservices@paypal.com awconfirm@ebay.com safeharbour@ebay.com operator_862736743@halifax.com 9. Download the eBay toolbar The eBay toolbar is a great piece of software that can be used to spot spoofs. As soon as you enter a spoof website from eBay or PayPal the toolbar will give you a warning telling you that web page is a spoof. The Ebay toolbar is FREE to download. Dan Thompson has been creating websites for over 7 years. You can visit his website and receive 6 free e-books, check out the website on http://www.elpassobooks.co.uk