Showing posts with label ID Theft. Show all posts
Showing posts with label ID Theft. Show all posts

Tuesday, December 27, 2011

Employee Fraud Thanks to the Cloud

Peer-to-peer and cloud-based file sharing may have been designed by punk kids to get free music, but now some of those punk kids are punk employees of the world's financial institutions. They have not forgotten their craft, according to the Federal Trade Commission:

"when P2P file-sharing software is not configured properly, files not intended for sharing may be accessible to anyone on the P2P network. ... we found health-related information, financial records, and drivers’ license and social security numbers--the kind of information that could lead to identity theft."
 -- FTC Chairman Jon Leibowitz on the FTC's website.
A very small fraction may intentionally use these technologies to steal sensitive or private information about the institution or its clients, but a far larger number are unwittingly exposing this information to the open Internet.


Coverage also at the Washington Post.
Many of my clients block P2P clients and websites as well as related traffic on company-owned PCs within the institution's firewall. PCs on desks in offices are probably safe. But before you pat yourself on the back, though, make sure you're looking at all potential exposure points. Wherever there's a hole punched in your corporate firewall, there's a potential loss. Ask yourself two questions:
  1. Is the same level of protection and surveillance being placed on VPN, email, webmail, virtual web conferencing, mobile email, and all other devices which span across your firewall DMZ?
  2. Is your monitoring / blocking technology based solely on the sources and destinations of traffic (ex. "safe" and "prohibited" IPs) or does it also monitor content? Perfectly benign channels such as email or virtual web conferencing usually allow files to be transmitted outside the institution in order to facilitate essential communication and collaboration. Can you, without killing these valuable tools, control WHAT data is transmitted?
 If not ... time to make a little space on the roadmap for new controls.






Monday, June 13, 2011

The Convergence of Data, Identity, and Regulatory Risks

This blog started 2011 with a post arguing for the inclusion of financial crime as a type of risk:
"Financial Crime (including topics like Money Laundering, Identity Theft, Fraud, Unauthorized Access, and Data Theft) is the next frontier in the evolution of Risk Management." 1/3/2011
Halfway through the year, this has been borne out in the headlines. While no institution is immune, headlines this week have given one clear example of what I was talking about:
"Citibank has revealed that it detected a data breach last month that exposed fully 1% of all its North American credit card customers’ account details. Citi has about 21.2 million credit card customers in North America according to its annual report, implying that close to 210,000 accounts may have been hit." Andy Greenberg, Forbes Blog.
Only 11 months ago, the remnants of Countrywide Financial settled a class-action lawsuit by setting aside $56.5 million (not including court costs) to cover claims of anyone impacted by an alleged data breach of 2.5m identity records. They, like Citi, were particularly criticized for delaying disclosure. This presumably allowed them time to assess vulnerability, fortify security controls, and perhaps get their legal arguments in order. At the same time, their delay gave identity thieves extra time to use the stolen data to defraud Countrywide's unsuspecting customers.

Countrywide's negotiated settlement puts the average hard-dollar cost of losing an identity record at $22. Many analysts estimate that the all-in number is four times as much once you factor in the soft costs such as reputation damage, lost business, and cost of additional controls. As a result, the rule of thumb I and many of my clients use to size up the cost of a data breach is $100 per identity. That makes Citi's breach quite costly!

In fact, Citi's latest incident comes atop a tide of recent compromises at a number of global firms, including a particularly disturbing breach of the "gold standard" RSA SecurID tokens which are used by many firms as an enhanced security measure for things like sensitive network access and large-dollar online banking transactions.

To pretend that these events "won't happen here" or "are black swans" and thus don't need to be factored into the price of doing business is as negligent as saying that mortgages never go underwater. Blithe assumptions like these are precisely why big, smart firms end up in catastrophe.

Finstitutions need to view financial crimes including data theft, identity theft, and fraud as risks which:
  • are intrinsic to their business, just like credit and market risks
  • are not outlier events, but rather are inevitable (and growing more frequent)
  • must be mitigated, monitored, and controlled
That's lesson one of 2011.

Today, 47 states have data privacy laws. It's the Internet, people! State-by-state laws don't make sense in this context. The good news is that, without a doubt, legislators and regulators alike have noticed these headlines and have stepped up their efforts to develop additional regulatory requirements to address the issue.

The Forbes blog goes on to say:
"The White House’s proposed cybersecurity policy outlined last month would include a mandatory federal breach disclosure law, and another bill proposed by Senator Patrick Leahy would similarly make concealing a data breach a federal crime."
These legislative proposals are atop upcoming FDIC regulations and FFIEC standards on authentication which will likely contain provisions addressing:
  • More frequent risk assessments focusing on authentication and related controls at least every 12 months and prior to implementing new electronic financial services
  • More robust controls as the risk level of transactions increases.
  • Layered security to detect and effectively respond to suspicious or anomalous activity both at initial login access and at initiation of online transaction
  • Multi-factor authentication, well beyond simple device identification and easily answered challenge questions
  • Increased customer education and awareness
Therefore, lesson two of 2011 is that regulatory compliance is another risk which should be incorporated into every FI's risk management framework, policy, and practice.

Sunday, February 13, 2011

Are You a Proud Dad?

My dad gave me one dollar bill
'Cause I'm his smartest son,
And I swapped it for two shiny quarters
'Cause two is more than one!
And then I took the quarters
And traded them to Lou
For three dimes -- I guess he don't know
That three is more than two!
...
And then I went and showed my dad,
And he got red in the cheeks
And closed his eyes and shook his head--
Too proud of me to speak!

- Shel Silverstein
People working in anti-fraud live and breathe money: losses, recoveries, write-offs. If it costs $1,000 to investigate and recover $500, we all intuitively know that would be a waste of time. We might as well just write off the $500 and move on. And yet...

The following conversation is hypothetical, but its strikingly similar to what I've heard from several clients in recent weeks:

Client: "Our detection systems are solid, but we're always on our back foot! We want to prevent fraud, not just detect and chase it! We need some sort of prevention system to cut our losses.”

Me: “You might not need a new system. Does your existing technology really ensure your team looks at the biggest risks first?”

Client: “Of course! We do the big transactions first. We have a ‘red’ queue for stuff that requires immediate action.”

Me: “So I imagine if there was a $50k wire, way out of normal for the customer, it would pop into the ‘red’ queue and get looked at right away.”

Client: “Right.”

Me: “And if, at the same time, your systems saw a different account with a series of unusual log-in and balance inquiry events, it would put that in a lower-priority queue?”

Client: “Yeah, unless it was linked to a financial transaction.”

Me: “What if those logins were for the CFO of a very profitable business banking client?”

Client: “Well, the system wouldn’t really know that. We’d see it during investigation.”

Me: “What if the CFO had online access to draw on a $1m revolving line of credit without secondary approval? What if he hadn’t logged in since 2008, but then one day logged in several times, browsed all over your Business Banking portal, and changed wire instructions for an approved beneficiary?”

Client: “Hopefully that would set off alarms! Probably not a ‘red’ alert, but we’d notice for sure. I know we get reports from the wire room every morning. We could call the client and verify the change.”

Me: “What if, at 3:55pm Eastern Time that same day, the CFO logged back in, drew down the line of credit and wired $1m out?”

Client: “NOW there would be a ‘red’ alert!”

Me: “And you'd be on your back foot. How much would you have to spend to drop everything and investigate in order to get the money back?”

Client: “Well it might not be our loss. We can't prevent the client from having a criminal at the CFO spot.”

Me: “How much would you spend to determine if it was really the CFO or an identity thief? No matter what, the client's not going to be happy. Odds are, they're going to close their account. What kind of heat would you get from the banker in charge of the client? Maybe they even drag you to court. What would that cost? ”

Client: “Welcome to my daily nightmare! It's the hassle of a lifetime!”

Me: “Wouldn't it be better if your systems could just prevent the wire in the first place? What if my team could get your existing technology to do that?”

Client: “When can you start?”

Just like Silverstein's "proud dad" in the poem, this client was a bit red in the face with frustration. His technology and teams clearly had some growing-up to do.

The problem is that, just like Silverstein's "son," nearly all of today's anti-fraud technologies and business processes misunderstand the real objectives ... through no fault of their own. They've been tasked with monitoring a narrow set of intermediate metrics like transaction size, out-of-profile behavior, or unknown IP address.

The key is to take the blinders off and refocus the technology on the true business metrics. Tell them what you're really trying to achieve. Is it minimized losses? Is is minimized operational cost? Is it minimized customer defection? Is it some balance of these? Then empower them with enough contextual data to make an intelligent determination of what's at stake, and what to do about it.

In upcoming blogs, I'll go "down in the weeds" to examine how technologies and business processes can be transformed in this way. Stay tuned!

Thursday, January 20, 2011

The World is Flat for Fraud

This blog entry describes a very common fraud pattern in which criminals, using the internet, can very easily and cheaply collaborate globally to reach halfway around the world ... and right into your customers' pockets.

If you're a Fraud Prevention Exec at a financial institution (FI), this story should sound like a thousand others you hear every day from your investigative staff. If it isn't, you might want to have a look at your defenses.

If you're NOT a bank Fraud Prevention Exec, this blog post is for you! As I discussed in a recent blog post, risk management must comprehensively address all types of risk, including identity theft, unauthorized access, and financial fraud. Read the story below and ask yourself whether your FI is addressing this holistically as a risk to the enterprise.

  1. A teenage hacker in Alabama (or Shenzhen China, for that matter) downloads the code for a Zeus, URLzone, or Champi trojan virus. He experiments and figures out how to secretly place it on a computer via email.
  2. He brags online about his feat, and soon is contacted by a more seasoned fraudster, who buys the virus for $100. The teenager is ecstatic! Party on!
  3. The fraudster sends it out to 1,000 random email addresses from an anonymous account. The virus takes hold on several hundred computers. It is structured to avoid most common virus scans.
  4. The fraudster then places an ad online offering to sell access to the infected computers (yes, there are Craigslist-like sites just for criminals) for about $30 to $300 for one month. He knows he has broken some laws, but feels his exposure is limited.
  5. A criminal in Eastern Europe buys access, allowing him to activate the trojan and receive the victims' balances, account numbers, usernames, passwords, pins, identifying info, and even secret questions.
  6. The criminal uses this real customer info to set up a series of "mule" accounts at FIs he knows are vulnerable. The real customer doesn't even know these accounts exist.
  7. The criminal then uses all the usernames and passwords he has gathered to set up funds transfers from the unsuspecting customer accounts to his mule accounts. He knows to do it quietly over a period of time in order to stay under everyone's radars. He probably knows, from anecdotes of other criminals (yes, there are fraudster blogs and chatrooms), exactly what patterns or thresholds the FI is looking for.
  8. The criminal opens anonymous or mule offshore accounts in countries with weak laws Anti-Money Laundering and Know-Your-Customer laws so he doesn't have to provide any of his own identifying info.
  9. The criminal places an add on Monster.com or Craigslist for a "work-from-home payroll analyst" who can naively move money for him without raising any alarms.
  10. He hires a person in the US who, based on the criminal's legitimate-looking instructions, transfers money from the mule accounts to offshore accounts over a period of weeks. By the time the "payroll analyst" realizes they're not getting paid for their work, it's too late. The criminal is gone and his tracks are covered. Once FIs and police investigate the fraud, the "payroll analyst" looks like the prime suspect.
  11. Meanwhile, the criminal launders the funds through a series of transfers, checks, debit card transactions, bill pays, and stored value card purchases. Once the money is clean, he puts it right in his pocket and takes a 6-month vacation with YOUR paycheck.