Stories
Slash Boxes
Comments

News for nerds, stuff that matters

Slashdot Log In

Log In

Create Account  |  Retrieve Password

Data Theft Soars to Unprecedented Levels

Posted by Zonk on Sun Dec 30, 2007 08:17 PM
from the never-been-easier-to-be-someone-else dept.
A Wired article reports on data loss in 2007, and the numbers aren't good. Credit card and social security theft was at an all-time high, with even more losses expected in 2008. Information thieves, it seems, are just one step ahead of IT security. "While companies, government agencies, schools and other institutions are spending more to protect ever-increasing volumes of data with more sophisticated firewalls and encryption, the investment often is too little too late. 'More of them are experiencing data breaches, and they're responding to them in a reactive way, rather than proactively looking at the company's security and seeing where the holes might be,' said Linda Foley, who founded the San Diego-based Identity Theft Resource Center after becoming an identity theft victim herself."
+ -
story

Related Stories

This discussion has been archived. No new comments can be posted.
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
 Full
 Abbreviated
 Hidden
More
Loading... please wait.
  • by Slashdot Suxxors (1207082) on Sunday December 30 2007, @08:20PM (#21860990)
    Just provide your credit card number to me and I will make sure no one steals it.
    • Once Throwaway Numbers Become Common I Will.
    • Re: (Score:3, Insightful)

      You joke, but this type of problem is real. The reason spam continues to proliferate is because it, on some dark, evil plane, works. People answer it or by the products it hawks. The reason malware sites, such as the type of phishing sites you quipped about, continue to work, is primarily because people are easy marks.
      Now if you'll excuse me, I have to click this link that says my PayPal account needs updating.
      • I don't know about the rest of you, but I'm not a rich guy, and I'm a slave to debt just like most people. If the financial sector goes to hell in a hand basket and stops being sustainable, I'm not going to be losing anything.

        On the other hand, I'm smart, talented, healthy, educated, a problem solver, a useful person to have around. I don't rely on the interest return on my massive holdings to sustain some overinflated lifestyle.

        So, why should I give a shit about these problems? Seems like it will make m
        • are you kidding me, on the one hand you say your a slave to debt and on the other you don't think it will effect you?

          If the financial market goes to shit who are you going to borrow money off to sustain that debt? what if the banks call in all your loans (as they are entitled to do) would you be able to pay them all out tomorrow?

          more importantly, is someone stole your identify and racked up $10k in debts in your name, how would you feel about it? you'd be pretty stressed i imagine, so don't kid yourslef i

  • by lobiusmoop (305328) on Sunday December 30 2007, @08:27PM (#21861032) Homepage
    This seems like a consequence of being able to carry gigabytes of data around in your pocket. It is probably all too easy for the odd database to duplicate into an employee's thumbdrive these days I suspect.
    • I'd argue that it was an effect of the growth of online transactions and companies retaining that data without proper safeguards more than a consequence of higher data capacities. The thumbdrives' capacity no doubt enable an employee to walk out with an entire database. There should only be a few people in an organization who have the access to do such a thing though. Even better would be a policy of not retaining any personal information such as credit card, SS, etc.

      Required car analogy: It's
      • Actually, I blame the problem squarely on the lack of motivation that financial institutions feel when it comes to preventing fraud. They can suck it up as a cost of doing business, but poor shmucks like us can end up dying a few years sooner because of the stress involved in fixing one's credit history.

        Instant credit without true identity verification is the problem here. Social security numbers and other PII are worth stealing because credit is so easy to obtain, including in someone else's name. Come
  • Something fishy... (Score:5, Insightful)

    by creimer (824291) on Sunday December 30 2007, @08:27PM (#21861036) Homepage
    Is data theft at an all-time high because of hackers or just dumb companies not encrypting their backup data that gets lost in transit?
    • Or laws that don't adequately punish companies for losing personal data, or at least allow for civil suits. My SSN was lost twice last year, both by large organizations, and I had no choice in giving either of them my SSN. One of them had it for health insurance reasons from when I was a child, and the other one was a school I attended. I think it's ridiculous. There's no reason that companies, schools, and other organizations should be able to lose tens of thousands of social security numbers and basically
      • For those of us who don't live in your brain dead country, any chance you could explain what an SSN is, and what it is good for? If it is such an important magical number that you need to keep secret at all times but are required to give over to people who you don't trust maybe, just maybe, it is a stupid idea and not the fault of the health insurance companies or schools you have attended if it gets misused. That said, in my brain dead country you can get someone's electricity turned off if you know thei
        • It's the U.S. analog to the Canadian SIN, and it's not really good for much other than being stolen, and taking your identity with it. Originally, it was intended to only be given to employers, so that they could appropriately give your money to the government, with the promise that it would be given back when you were retired. In fact, it was expressly stated that the SSN was not to be used as it is now being used, but like so many other things, this has been ignored more and more over the years.

          Yes, it
    • Is data theft at an all-time high because of hackers or just dumb companies not encrypting their backup data that gets lost in transit?

      No, it's because we're using shared secrets (hey look, an oxymoron!) to establish identity.

      As far as your finances are concerned, anyone who knows your name/birthdate/SSN/address/card number/etc is *you*, and can do pretty much anything you can do. And of course anyone you do business with knows enough of these things that they or anyone who steals their database can pr

  • One step ahead..? (Score:4, Insightful)

    by ricebowl (999467) on Sunday December 30 2007, @08:29PM (#21861040)

    I don't know what the trouble is with the 'myminicity' thing, so I'll just comment on the synopsis.

    It has to be noted that since much data these days appears to be stored unencrypted, or removed from the premises by 'interns,' that much of the populace is 'one step ahead.' The advantage the bad guys have, beyond institutional stupidity and negligence, is that there's so many of them willing to exchange the data once acquired.

    • myminicity.com is an online game, where the city grows as you get people to visit your city (by clicking a link to it). AC's are posting links to their cities all over slashdot, disguised as tinyurl or the like links.
    • The advantage the bad guys have, beyond institutional stupidity and negligence, is that there's so many of them willing to exchange the data once acquired.

      Huh. So the more "open source" approach of the crackers is beating the "closed source" defensive model of the defenders?

      I'm not a zealot one way or the other (in particular I've always thought that "security through obscurity" actually has some value) but that point seems telling.

  • by LiquidCoooled (634315) on Sunday December 30 2007, @08:29PM (#21861046) Homepage Journal
    We hear about CC theft a lot and I am sure it does occur, but most of the time its embarrassment which is the real culprit.

    "darling, the CC company says we owe them $2400 dollars."

    "thats nonsense, I barely use my CC"

    "it says there were hookers, gallons of gin and a blackjack tableset ordered to an address in Nevada."

    "OMG it must have been the waiter in the diner I went in on the way to the 'conference' with work! (pray you are saying it with a straight face)" ...
    • Oh! So you're saying credit card fraud fraud is skyrocketing!
    • Re: (Score:3, Interesting)

      You laugh but I used to work for a small credit card processing company and that was exactly the reason for many, many charge backs.

      wife: Honey what's this charge for porn on our creditcard?
      man: Oh you know I would never look at THAT. Someone must have stolen our credit card.
  • Not a big surprise (Score:5, Insightful)

    by gta3mobster (1096151) on Sunday December 30 2007, @08:36PM (#21861084)
    Irresponsible data handling by employees at retail stores probably contributes quite a bit.

    One of my friends went dumpster diving at Compusa. On top of finding almost every cable you'd ever need to hook anything up, he found over 70 pages of daily reports disclosing full credit card numbers, expiration dates, first/last names, and card company. Personal checks that were used during that day listed the account #, routing #, first/last name, birthdate, drivers license #, address, phone number, and probably some other stuff. He found this on two separate occasions, with over 300 cards listed total. None of the papers were shredded/torn either. He didn't intend to find this stuff - Imagine how easy it must be for somebody who actually wants the information!

    The majority of the population doesn't understand how seriously security needs to be taken when venturing online to make purchases. If people understood going onto unsecured networks/etc was pretty much the same as leaving your credit card/checkbook in the front seat of your car, leaving the doors unlocked, and parking it in a bad neighborhood they might take security more seriously.

    Sure - Most of the time if you leave stuff in your car unsecured, it'll be there when you get back. But there's always that small chance it'll get stolen.
    • Makes you wonder how much of the Info "stolen" off "the computer" or "the internet" was really just thrown into a dumpster don't it. I have been fighting with people at work to shred everything if they shred anything.
  • by LaughingCoder (914424) on Sunday December 30 2007, @08:38PM (#21861098)
    has itself grown in size to unprecidented levels, I suppose it shouldn't be too surprising that data THEFT has also grown to unprecidented levels. The real question is, when normalized for how much data is "out there", is data theft getting more or less rampant?
  • by schwit1 (797399) on Sunday December 30 2007, @08:41PM (#21861108)
    Knowingly having an unsecure system or not doing basic security due-diligence causes penalties, a second offense and you lose your business license.
  • by Blittzed (657028) on Sunday December 30 2007, @08:42PM (#21861110)
    The post states that "Information thieves, it seems, are just one step ahead of IT security.". I disagree with this, but it all depends on your definition of IT security, mine being more on the tech side in relation to protection, countermeasures and network forensics. The article really does not make any claim that IT security is at fault, but rather that counter measures to known threats are not being empyloyed. In relation to the quoted statement above, I would say that information theives are five steps ahead of those of don't take measures to protect against threats, rather than being ahead of IT security. I guess it could be argued that IT security is indirectly responsible, or failing, as user education and policy are major parts of protecting corporate networks and data. The failure in these cases seems to be more related to a lack of user knowledge or failure to adhere to policy / weak policy, rather than a complete inability of IT security to protect information. Everyone knows that the internet is a dangerous place (TM), even my grandma. For those in government, schools etc to have data stolen and claim that they didn't know about the risks posed of using online data systems is just plain stupid. According to TFA, the biggest theft of information occurred due to the use of a wireless network. "What! Wireless isn't secure? I had no idea!" Only if you had your head firmly wedged up your own back passage could you as a security professional, or even semi professional ;) claim that you had no idea of the many vulnerabilities of wireless networks...
  • RSA Secure ID... (Score:4, Insightful)

    by hxnwix (652290) on Sunday December 30 2007, @08:42PM (#21861112) Journal
    The feds could initiate a program under which all citizens are issued key fobs similar to RSA Secure IDs with verification similar to that required for a passport. Without this fob, one could not open any sort of bank account or acquire a credit card or loan... The program could allow one to specify various levels of rigor beyond this basic minimum, such as pin+fob key verification to complete any sort of electronic monetary transaction.

    It works for managing access to top secret material, hundreds of billions in monetary instruments and the most vital systems of companies in every industry worldwide... I suppose that on an individual basis, any person's assets, credit and livelihood just aren't as important. Or, perhaps the very industries that protect themselves with this system just don't give a fuck about their consumers.

    If these folks were landlords, they'd tell every criminal they could find who you are and were you live, and they'd refuse to install a lock on your door.
  • by Fractal Dice (696349) on Sunday December 30 2007, @09:16PM (#21861332) Journal

    What amazes me about "identity" (financial, blog or otherwise) in the Internet age is how similar it is starting to feel to the concept of identity in fantasy fiction (such as the Earthsea books) where people have disposable day-to-day common names, but also truenames that hold the real power of identity, shared only with the most trusted of companions.

  • One big issue i see in this and other problems in todays society, is there is too much focus on how was spent on a problem and not what was actually done.

    it's all very well to say spending has increased, but what was actually DONE about the problem? Simple and cheap solutions are often the best.

    for example, my bank sends me an sms with a code to complete all online transfers to new billers, rendering fishing useless. the only way to change the mobile number is to answer 2 very personal security questions,

  • Apart from "intellectual property", "identity theft" has to be the stupidest term ever. They don't steal your identity.. they "copy" it. Real identity theft would be taking over someone's identity (probably with some lame face exchange technology) so that the rightful owner can no longer utilize it. And what's most annoying is that there is already a legal term for the activities that "identity theft" is typically used to refer to.. fraud. So what the hell is wrong with "identity fraud"? Not sexy enoug
    • Real identity theft would be taking over someone's identity (probably with some lame face exchange technology) so that the rightful owner can no longer utilize it.

            I've seen interviews of people who say they no longer can utilize their identity to do the things they expect to be able to do, buy a house, open a credit account, and have their previous credit rating.

            So they feel their identity has been stolen.

        rd
       
      • That's the kind of retarded thinking that should be kept out of law. If someone takes a shit on your windshield you don't claim your car has been "stolen" because you have to clean it up before you can drive it again. Fuckin' morons.

        • If someone takes a shit on your windshield you don't claim your car has been "stolen" because you have to clean it up before you can drive it again.

                But you would claim it was stolen if you couldn't drive it again because of it. Same thing.

            rd
          • Seriously, no, you wouldn't. If I burnt your car to the ground with gasoline you could claim I destroyed your property. You could claim I was a vandal. You could put in an insurance claim for "fire". But you couldn't claim I "stole" it. In *any* case, your identity is not your credit rating - at least I fuckin' hope the world hasn't become that consumerist just yet.

            • It has. It's your name, SSN, address, birthdate, credit history. That's what becomes effectively not yours anymore because you can't use it. You can try, but it's no good anymore with all the uses made of it after it was stolen.

              So you try to recover it, and yet at any time a new mortgage application can come in to a credit bureau with your name on it. Takes a lawyer and a lot of money to get it back. So call it recovering stolen goods, ot getting your name back.
  • 'More of them are experiencing data breaches, and they're responding to them in a reactive way, rather than proactively looking at the company's security and seeing where the holes might be,' said Linda Foley, who founded the San Diego-based Identity Theft Resource Center after becoming an identity theft victim herself."
    • The real question is- how can we be sure that the real Linda Foley did and said all these things?
  • in related news (Score:3, Insightful)

    by Darth_brooks (180756) <chico.wccnet@org> on Sunday December 30 2007, @09:57PM (#21861584) Homepage
    Studies have shown that auto theft reached unprecedented levels in 1911. In future news; flying car theft will reach unprecedented levels in 2057.

    More and more common thieves are learning the value of data. So more of it is being stolen. I bet MP3 player and cell phone theft rates are reaching "unprecedented" levels as well.
  • by buss_error (142273) <buss_errorNO@SPAMyahoo.com> on Sunday December 30 2007, @10:26PM (#21861776) Homepage Journal
    At $DAYJOB, we insert fake data in two ways: First, fake data that is in the database with known markers, second, more fake data generated each time a user logs in and present only during that log in for that user. In this way, we know if the data theift occured via authintication (and by whom, from where, and when), or via some hole in the app.

    The way to make this more effective requres a huge amount of work: Longer CC numbers and SSNs. It's the same problem IT has had with users FOREVER. Users expect the moon, stars, and all the oort cloud between, yet do not want to provide the least effort. There's no "buy in" from Soc Sec and the CC companies. As long as they get to pass along the cost to someone else, then the current system is "good enough". No need to expend any of THEIR effort to find, track, and plug up problems.

    But make THEM accountable in a tangable way, and I think we'll start to see effective measures to stop this nonsense. And no few RSG and 419'ers in jail to boot.
  • Why don't Visa, Mastercard, American Express, Diners etc start putting pressure on companies to keep credit card numbers more secure (along with inventing and selling solutions to make that happen)

    Even taking the simple step of changing the merchant agreements such that if the merchant suffers a breach or loss of credit card numbers, they are contractually obligated to notify the people who's numbers have been stolen (either via announcements in the media/on the merchants website or individually somehow) wo
  • by bl8n8r (649187) on Sunday December 30 2007, @10:51PM (#21861986)
    And one that too many companies are willing to put gamble with. Many IT shops haven't got the experience in house to maintain security so they shop around for the doitallforyousecuritygizmo to do it for them. These gizmos are usually 90% snake oil with a hefty support contract. There is also a big lapse in education and awareness across all facets of the security realm. Programmers think security is up to Layer 1 and that they are free to break all the rules at layer 7. Windows admins think security means that if Bitdefender doesn't complain, everything must be peachy and that having software installed through ActiveX by a remote website is just a prank. Management is made up more of bean counters than technically savvy personnel. In the end, it seems management views a spin-of-the-wheel as being more cost effective than re-training a bunch of people that can't see past the Whack-a-Monkey javascript they just got in their inbox.

  • by RickRussellTX (755670) on Sunday December 30 2007, @10:57PM (#21862052)

    It continues to astonish me that people think of "data theft" as the cause of identity theft.

    Data theft is not the problem. The problem is that financial organizations are willing to accept transactions without authentication, or with very weak authentication. Supplying a 9-digit number which is a matter of public record is not a form of authentication. It does not prove that the person speaking is the account holder. Anybody can walk into a store with a fake credit card and buy stuff in my name, no questions asked. People can write checks with my account number on them, and it will be charged to my account. At no point is the slightest attempt made to authenticate the identity of the person making the transaction and certify that they are allowed to post transactions to the account.

    There is no way to "plug" these leaks; most of these names and numbers are a matter of public record and must be surrendered in order to make a transaction in the first place. The identity theft problem will not abate until account holders have enhanced authentication options, and the financial institutions are required to use them. Biometrics, physical security tokens, PINs, it doesn't really matter what solution we use. We just need to use something to verify the identify of the person making the transaction. It's the only solution.

  • by ZWithaPGGB (608529) on Sunday December 30 2007, @11:10PM (#21862162)
    The problem is that the organizations that lose the data, and the people who work there, are not the ones who bear the pain of the result. Furthermore, we usually have no choice in handing over the personal data, most of which is completely unnecessary (but very useful for marketing), in order to get things we need.

    Unless and until that changes, all the hand-wringing in the world won't make a hill of beans of difference.

    It will take something like Sarbanes-Oxley, making the officers of companies and non-profits, and government workers, who handle our data personally criminally liable for failure to take due care, before there is any change. As it is now, it is a simple cost calculation, and security is pure cost. The people in charge are betting that they can cash in their stock options or get promoted/transferred before the failure to protect data causes a problem.

    Last, but by no means least, everything that the naysayers said about Social Security when it was first proposed have come true: the SSID is a national ID number, and is routinely abused; and the Ponzi Scheme has run afoul of demographics. It's time to end the charade: outlaw the use of SSIDs by anyone except the SSA, and to allow people to opt out of SS.
  • by Omniphobic (1210274) on Sunday December 30 2007, @11:14PM (#21862188)
    This information doesn't surprise me. I think the increase is do to the increasing ease of standing up a website. Anybody with minimal computer/coding/security experience can stand up a website that takes your credit card information. I've dealt with COUNTLESS sites that have horrible file permissions, no security apps (like mod_security), and their DB connection password is weak. It's unbelievable how little effort folks will put into securing their business operations. On top of that, customers who repeatedly get hacked won't be willing to go through the hassle of auditing their customers or upgrading their software, so the same vulnerabilities get exploited again.
  • In the olden days (like 10+ years ago), if someone wrote a check in someone else's name, it was called "fraud". It is, in fact, a crime where someone steals money from the bank.

    At some point, someone changed the vocabulary, and now we call this "identify theft", and so we make the crime against the person who's name was forged. In fact, this person has nothing to do with this crime, and is an innocent bystander. The bank is charged with protecting my assets, and if they fail to do so, they should be liable, just as much as if someone walked into the bank with a gun and took it!

    By convincing society at large that the crime is "identity theft" and not "fraud", the corporations, while not solving the problem of fraud, has made it someone else's problem; namely their customers. And the customers accept this, and direct their ire against the criminals, instead of against the company. (Admittedly the criminals are Bad People, so they do deserve to be feared and hated.)

    In some ways, it is a stroke of genius by the corporate world. But not one that we should celebrate. :(
  • by sgt scrub (869860) <saintium AT yahoo DOT com> on Monday December 31 2007, @11:36AM (#21866702) Homepage
    Information thieves, it seems, are just one step ahead of IT security.
    No. IT security would be doing just fine if users and administrators protected themselves with existing security recommendations.
    As long as people act like sheep they will be lambs to the slaughter.
    • Another MyMiniCity link. Don't click. You know the drill.
    • Re: (Score:2, Redundant)

      It's a myminicity link! Mod down!
      This one was posted by an Anonymous Coward, and goes to the "holdenville" account.
      So far, I've counted 4 myminicity accounts spamming slashdot:
      spx2.myminicity.com
      fohootville.myminicity.com
      budgieton.myminicity.com

      holdenville.myminicity.com

      Motion Twin is the company that makes the product, email them and complain about the accounts here:
      contact@motion-twin.com

      However, they don't seem to be very responsive, so perhaps emails to their IP block abuse email:
      abuse@
      • So far, I've counted 4 myminicity accounts spamming slashdot: blah blah blah

        And by comparison, I've given up counting the posts that discuss these links. This is worse than a mailing list letting slip through a spam message, and seeing countless folks take the opportunity to offer as many off-topic comments.

        Deleting a mailing list thread gone nuts is easy, but deleting Slashdot posts isn't an option. Put another way, it's easy to ignore AC posts, off-topic posts (they tend to get modded down fairly quickl