Protect your identity

November 2010 Access Control & Identity Management, Information Security

Identity fraud, according to Wikipedia is “a form of fraud in which someone pretends to be someone else by assuming that person’s identity, typically in order to access resources or obtain credit and other benefits in that person’s name. The victim of identity theft (here meaning the person whose identity has been assumed by the identity thief) can suffer adverse consequences if he or she is held accountable for the perpetrator’s actions.”

But how can an identity be ‘stolen’? In a time when almost anything can be done on a computer, phishing is a common process of attempting to acquire sensitive information such as usernames, passwords and credit card details by masquerading as a trustworthy entity in an electronic communication. Communication claiming to be from a popular social web site, for example, can be used to lure the unsuspecting public.

Usually in the form of an e-mail or instant message, phishing typically directs recipients to enter details at a fake website which has been designed to closely resemble a legitimate one. The fraudsters then have the information they need to pose as the person who supplied the details, and the information is used for activities such as opening accounts or purchasing items fraudulently.

The public is regularly warned of such threats, but what about those phone calls we may innocently answer…

Remember this call?

Your cellphone rings. The caller ID is hidden…

“Hello.”

“Good afternoon Mrs Jones, I am phoning you from VMC Mobile. Your number has been selected and you qualify for two free tickets to the fourth game of the world cup”

“Tell me more.”

“First I need you to confirm your ID number please.”

You wait for the caller to read out your ID number so that you can confirm it. Nothing is forthcoming.

“Your ID number please,” the caller continues.

If you unthinkingly rattle off your ID number, followed by your address and any other information you are asked to ‘confirm’, you are supplying the caller with enough information for them to effectively pose as you!

Are you a victim?

Jayson O’Reilly, regional manager Africa, McAfee describes identity theft as a serious crime that can cost victims a lot of time and money by destroying their credit and ruining their reputations.

“Identity thieves and hackers target home computers because they know families often do not maintain adequate security protection on their PCs. This makes these family users easy and lucrative targets. Many hackers access your personal information in order to steal your identity and your money. Others might want to use your home computer as a shield to mask their identity as they steal from others,” says O’Reilly. “Phishing is a particular type of identity theft: the online method of fraudulently obtaining personal information for identity theft, such as passwords, social security numbers, and credit card details, by sending spoofed


e-mails that look like they come from trusted sources, such as banks or legitimate companies.”

According to O’Reilly typically, phishing e-mails request that recipients click on the link in the e-mail to verify or update contact details or credit card information. Like spam, identity theft e-mails are sent to a large number of e-mail addresses with the expectation that some percentage of recipients will read the messages and disclose their personal information.

Wally Gast, regional profit centre manager at Chartis South Africa, Personal Lines, Africa Region, defines identity theft as “the unauthorised and illegal use of personal information to obtain a loan or open credit accounts that the victim did not authorise.”

According to Gast, identity theft is on the rise, not only because of the vast amount of personal information that can be accessed via the Internet, but also the ‘low tech’ ways that this crime can be committed.

“This can happen when people lose or have their ID books stolen, when criminals go through your garbage to find old accounts and statements or swipe your mail for the same purpose. People really need to take care with documents when they throw them away. Shredding documents before disposal is a very good idea,” says Gast.

“We also take note of notorious cases where the Department of Home Affairs has issued duplicate identification books using the identification number of an innocent person. There are also a lot of cases where people have discovered they are ‘married’ to someone only when they start getting massive bills in the post. It is worthwhile to have protection against this type of crime especially as it is so prevalent in South Africa. Getting your identity back can take weeks of personal time and could cost tens of thousands of Rands in legal fees,” he adds.

O’Reilly further points out that this form of cybercrime is a federal crime in the United States and the country’s Federal Trade Commission has named identity fraud as the most popular form of consumer fraud.

In South Africa the issue continues to plague general trade, with authorities continuing to receive more complaints than in the past. It is particularly prevalent within the world of finance and fraudsters have emerged far more tech-savvy than in the past. It occurs when a criminal uses personal information to produce false FICA documents, to steal financial resources,” he adds.

Get protected

“As with any threat, the more a person is empowered with knowledge, the better. An example of identity fraud is when someone steals personal information, opens a credit account in your name without permission, and charges merchandise to those accounts. Conversely, identity fraud does not occur when a credit card is simply stolen. Stealing one’s credit card may be consumer fraud, but is not identity fraud” he adds.

Aside from being informed and staying informed, the consumer and user of information, communication and digital lifestyle technology has various options available to ensure that they do not fall victim to this fraud. The problem cannot completely be eradicated, but there are a number of steps that can be taken to reduce risk.

“Criminals can commit identity theft relatively easily because of lax credit industry practices, careless information-handling practices in the workplace, and the ease of obtaining personal information. But you can reduce your risk of fraud by following a few very practical tips. The most important advice we can give you is to check your credit report at least once a year. If you are a victim of identity theft, you will catch it early by checking your credit report regularly,” Gast concludes.

Buyer beware

* When using your credit and debit cards at restaurants and stores, pay close attention to how the magnetic stripe information is swiped by the waiter or clerk. Dishonest employees have been known to use small handheld devices called skimmers to commit fraud.

* When creating passwords and PINs (personal identification numbers), avoid using common information or combinations that would easily be linked to your details.

* Install a firewall on your home computer to prevent hackers from obtaining personal identifying and financial data from your hard drive. This is especially important if you connect to the Internet by DSL or cable modem.

* Install and update virus protection software to prevent a worm or virus from causing your computer to send out files or other stored information.

* Subscribe to an Identity Protection Services that offers insurance against identity theft.

Proactive steps for victims of ID theft

* Report the theft to local law enforcement representatives.

* File a complaint and complete the ID theft affidavit.

* Inform all relevant institutions of the fraudulent activity – both telephonically and in writing.

* Send follow-up letters to the credit bureaus detailing the status of resolution with institutions and creditors.

Telephone tactics

* When a caller asks you to ‘confirm’ any information, they need to supply that information first and you either confirm it as correct or not.

* Private information, eg, your full name, phone numbers, e-mail address, credit card numbers, postal address and e-mail address, could be used for identity theft. Do not give these out over the phone unless you have made the call and you are certain of whom you are talking to.

* Ask the caller to identify themselves by name and company. If you have any suspicion, ask to be transferred to their superior, and ask for a reference number for the call.

For more information contact:, Ideco, +27 (0)11 745 5600, www.ideco.co.za



Credit(s)




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Zero-touch automation certificate life cycle management loop
Products & Solutions Information Security Security Services & Risk Management
ManageEngine completes the certificate life cycle management loop with CA-agnostic, zero-touch automation. New post-deployment automation in Key Manager Plus removes the last manual step in certificate renewal as lifespans gradually shrink to 47 days

Read more...
Sophos launches AI-native cybersecurity defence system
News & Events Information Security Security Services & Risk Management
Built for a threat landscape reshaped by AI, Sophos Fusion unites security operations, endpoint, network security, identity, email, and cloud into one defence system that prevents, detects, investigates, and responds at AI speed.

Read more...
AI agents become ‘First Class Identities’
Access Control & Identity Management
AI agents are now approving transactions, accessing systems, triggering workflows, and making decisions autonomously. But uncontrolled AI agents are becoming one of the largest security gaps in modern enterprises.

Read more...
Balancing secure access control and fire safety
Editor's Choice Access Control & Identity Management Fire & Safety
In modern building management, few topics create as much tension as the intersection between security access control and fire evacuation safety. Nichola Allen of G2 Fire sheds light on this delicate balance.

Read more...
Securing water infrastructure for industry and community
Access Control & Identity Management Fire & Safety Government and Parastatal (Industry)
The Badirammogo Water User Association needed a solution that could secure remote sites, reduce reliance on physical guards, and ensure uninterrupted service delivery while remaining aligned with its values and long-term strategy.

Read more...
How ‘TikTok Brain’ is breaking legacy security training
Training & Education Information Security
Between doomscrolling, rapid-fire Slack notifications, and algorithmic video feeds, the average employee is trapped in an aggressive, highly engineered dopamine loop that automatically shuts down in traditional training situations.

Read more...
Quantum is coming
Infrastructure Information Security
The global cybersecurity landscape is approaching a turning point as quantum computing accelerates faster than most organisations realise; the shift is not a distant, theoretical concern, but a present-day business risk that demands immediate action.

Read more...
Outpacing cyberthreats in the age of AI
SMART Security Solutions Technews Publishing News & Events Information Security
SMARTpod talks to Fred Streefland, Global Field CISO for EMEA at Check Point Software Technologies, about framing modern cyber defence around adaptability, rapid decision-making, and the OODA loop adapted for cybersecurity.

Read more...
Disconnect between confidence in identity security and operational reality
Access Control & Identity Management News & Events
New FIDO Alliance and HID study reveals gap between identity security confidence and reality; 94% of enterprises claim they can revoke employee access within 24 hours, yet 35% experienced delays or failures in the past two years.

Read more...
Paxton Solo training available to security installers
Paxton Access Control & Identity Management News & Events
Following the launch of Solo, Paxton’s brand-new access control system, the security manufacturer is rolling out dedicated Solo training sessions across South Africa to support security installers working with the system.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.