opinion

Trying to Stop Web Fraud Before It Happens

Trying to Stop Web Fraud Before It Happens

You may have read or heard by now that one of the nation’s three major credit reporting agencies was the target of a malicious and illegal breach of security earlier this year.

Equifax has stated that the breach lasted from mid-May through July and the scope of information accessed includes Social Security numbers, birth dates, addresses, credit card numbers, and driver’s license numbers. It has been reported that individuals in Canada and the U.K. have also been affected by this breach.

The best advice we can offer when confronted with a spear-phishing scam is to assume the communication being received is suspect.

Equifax has created a website to help consumers protect their identity, but there’s a wait and the timeframe allotted to enroll is limited. Visit EquifaxSecurity2017.com to check if your personal information may be affected by the breach and be sure to visit soon because the enrollment period ends on Tuesday, Nov. 21.

In addition to placing a freeze and fraud alert on your credit report, there are a few other things you can do to be proactive in protecting your identity.

Placing a fraud alert and credit freeze on your credit profiles will make it more difficult, but not impossible, for someone to establish a credit account in your name without your knowledge or permission. Please note, you’ll need to repeat the process with each credit bureau as not all creditors and lenders use the same reporting agencies.

Check with the other major credit bureaus, Experian and TransUnion and monitor your credit report closely for unauthorized and unrecognized entries. You can check your credit reports at each reporting agency for free once per year at AnnualCreditReport.com. If you find accounts or activity you don’t recognize, visit IdentityTheft.com to take appropriate steps to report and rectify your situation.

Another tip is to file your taxes early, as soon as you have all the documents you need. A common practice of identity thieves is to use stolen Social Security numbers to gain employment, file tax returns fraudulently, and collect the refund owing to you from the federal government.

In the aftermath of the breach, several new trends have emerged within the criminal element, taking advantage of the breach. As if the breach itself isn’t bad enough on its own, this new practice dubbed, “spear-phishing,” is on the rise.

Most are familiar with the practice of phishing, when the intended victim is the recipient of an email from a well-established brand or bank claiming that access credentials have been compromised and a simple password reset will prevent any unauthorized access; all that needs to be done is click the link in the email and the recipient is directed to the password reset page.

Typically, the password reset page is a remarkably good facsimile of the legitimate business, bank, or brokerage and the user is prompted to enter their existing user name and password in order to confirm the new password — except what the user is likely unaware of is that they’ve just sent their perfectly valid and secure credentials to a criminal.

These types of phishing scams are easy to identify, usually due to poor grammar and poor formatting of the email but the new wave of spear-phishing is a little more sophisticated because it includes real and personal details illicitly acquired as a result of the most recent breach. Information such as your Social Security number may be included in the body of an email that has an attachment claiming to be from your bank or broker.

The email may prompt the recipient to click a link or download an attachment to confirm a transaction however, once that action is taken, the recipient of the email may be unknowingly downloading malicious software onto their computer, compromising the operating system, making it vulnerable to hijacking or recording keystrokes and sending them to unintended recipients.

“When you have a sophisticated criminal that has real information about you, it’s far more difficult to spot the fraud,” said Martin Walsh, a financial adviser with the Denver planning firm of Brown & Tedstrom.

The best advice we can offer when confronted with a spear-phishing scam is to assume the communication being received is suspect.

If an email is received from your bank, credit card issuer, or broker and you believe it to be legitimate, visit the company’s website directly or call the toll-free customer service number. Do not, under any circumstance, click the link or download the attachment.

Another, less-original practice of imposter scams, is seeing a resurgence owing to the Equifax data breach. The Federal Trade Commission has warned the public that it expects an increase of imposter scams, with individuals posing as representatives of Equifax “calling to verify your account information.”

Equifax is providing free credit monitoring and credit freezes as a result of the breach so the call may sound legitimate, but don’t ever provide confidential and private information over the phone to an inbound caller.

The purpose of this method is to get the recipient of the phone call, or sometimes e-mail, to disclose additional personal information to the imposter which they can either sell or use to establish new lines of credit fraudulently.

So, what should you do now that this has happened? First, check to see if you were affected by visiting the Equifax website listed earlier in this article. Secondly, take advantage of the free credit monitoring.

When you check to see if you were affected, you’ll be assigned an enrollment date — it’s important to set a calendar reminder for that date because Equifax will not send you a reminder — and you won’t be able to enroll until after your assigned date. Thirdly, freeze your credit, at all three bureaus.

The free credit monitoring is helpful, but it will not prevent identity theft. A credit freeze locks your credit profile to new inquiries and establishing new credit accounts, which can at least slow down, if not prevent, the theft of your identity.

Jonathan Corona has more than a decade of experience in the electronic payments processing industry. As Mobius Payments Inc.’s vice president of compliance, Corona is primarily responsible for day-to-day operations as well as reviewing and advising merchants on a multitude of compliance standards set forth by the card associations. Mobius Payments specializes in high-risk merchant accounts in the U.S., E.U. and Asia.

Related:  

Copyright © 2024 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More Articles

opinion

Strategic Upscaling of Non-4K Content

If content is king in adult, then technical quality is the throne upon which it sits. Technical quality drives customer acquisition and new sales, while cementing retention and long-term loyalty.

Brad Mitchell ·
profile

'Traffic Captain' Andy Wullmer Braves the High Seas as Spirited Exec

Wullmer networked and hobnobbed, gaining expertise in everything from ecommerce to SEO and traffic, making connections and over time rising through the ranks of several companies to become CEO of the mobile business arm of TrafficPartner.

Alejandro Freixes ·
opinion

To Cloud or Not to Cloud, That Is the Question

Let’s be honest. It just sounds way cooler to say your business is “in the cloud,” right? Buzzwords make everything sound chic and relevant. In fact, someone uninformed might even assume that any hosting that is not in the cloud is inferior. So what’s the truth?

Brad Mitchell ·
opinion

Upcoming Visa Price Changes to Registration, Transaction Fees

Visa is updating its fee structure. Effective April 1, both the card brand’s initial nonrefundable application fee and annual renewal fee will increase from $500 to $950. Visa is also introducing a fee of 10 cents for each settled transaction, and 10 basis points — 0.1% — on the payment volume of certain merchant accounts.

Jonathan Corona ·
opinion

Unpacking the New Digital Services Act

Do you hear the word “regulation” and get nervous? When it comes to the EU’s Digital Services Act (DSA), you shouldn’t worry. If you’re complying with the most up-to-date card brand regulations, you can breathe a sigh of relief.

Cathy Beardsley ·
opinion

The Perils of Relying on ChatGPT for Legal Advice

It surprised me how many people admitted that they had used ChatGPT or similar services either to draft legal documents or to provide legal advice. “Surprised” is probably an understatement of my reaction to learning about this, as “horrified” more accurately describes my emotional response.

Corey D. Silverstein ·
profile

WIA Profile: Holly Randall

If you’re one of the many regular listeners to Holly Randall’s celebrated podcast, you are already familiar with her charming intro spiel: “Hi, I’m Holly Randall and welcome to my podcast, ‘Holly Randall Unfiltered.’ This is the show about sex, the adult industry and the people in it.

Women In Adult ·
trends

What's Hot Now: Leading Content Players on Trending Genres, Monetization Strategies

The juggernaut creator economy hurtles along, fueled by ever-ascendant demand for personality-based authenticity and intimacy — yet any reports of the demise of the traditional paysite are greatly exaggerated.

Alejandro Freixes ·
opinion

An Ethical Approach to Global Tech Staffing

One thing my 24-year career as a technologist working to support the online adult entertainment industry has taught me about is the power of global staffing. Without a doubt, I have achieved significantly more business success as a direct result of hiring abroad.

Brad Mitchell ·
opinion

Finding the Right Payment Partner

Whenever I am talking with businesses that are just getting started, one particular question comes up a lot: “How do I get a merchant account?” It’s a simple question, but it has a complicated answer.

Jonathan Corona ·
Show More