Search This Blog

Monday, March 09, 2009


JUNK MAILERS ONE OF BEST EXAMPLES OF LACK OF REGULATION


Junk mail publication, Direct, attempts to mimic con man Harold Hill of Music Man in its headline, "Obama’s FTC Spells Trouble with a Capital T.” The columnist’s whining is both tiring and with a complete lack of substance. But this is typical since most of these hacks continue to defend an industry that has needed regulation for years.

The author, no doubt representing the attitude of many junk mailers, thinks President Obama’s pick of Jon Leibowitz to head the Federal Trade Commission, spells doom for the business. This, because Leibowitz is a firm believer in consumer rights, which might lead one to believe the junk mail industry isn’t. And I come to this conclusion based on my 35 years as a list/data broker, observing the concern for profits taking priority over the security of consumers’ personal data.

Apparently the writer of this article pines for the Bush administration style of consumerism, which is one of complete neglect. That is exactly what junk mailers want so they can continue to run their business in the secretive manner they have for years. They don’t want you to know how many times a day your private information is manipulated for revenues that exceed $4 billion dollars annually, and they don’t want you to ask why the name-holder—that’s you—doesn’t have the opportunity to share in the wealth.

I did a post on January 19, asking the question, "Will Federal Trade Commission Change its Tune to Placing Consumers Before Business under President-Elect Obama?” I guess I got my answer in the naming of Jon Leibowitz to head the FTC. Earlier, in April of 2008, I did two posts re. Leibowitz’s just held meeting on the dangers of behavioral or target advertising. That’s when junk mailers use lifestyle lists to zero in on households that smoke, gamble and/or drink, among a host of other consumer daily habits neatly tucked away in databases.

The Direct author tells of an interview in 2006 with Leibowitz, quoting the commissioner as saying “online information can be personally identifiable even if the advertiser doesn’t have a Web site visitor’s name or address.” When Leibowitz continued explaining that there are unique identifiers that can lead to a person’s true identity—which there are—he was called “ludicrous.” What is lucicrous is that these journalistic cheerleaders don’t want you to know just how much junk mailers know about you.

The junk mail industry has been able to get away with a lack of regulation for years—except for minor instances like being required to let you opt out of having your name and personal data sold, and a major move by the FTC when enacting the Do-Not-Call registry. The first is buried in any advertisement you receive; the latter, of course, was a matter of consumer demand. The reason Congress has failed its constituents on this issue is that they don’t have enough understanding of junk mail to create effective legislation. And…US consumers haven’t demanded it.

I’m ready to enlighten Congress. It’s up to you to make sure they do something. Contact: House of Representatives; Senators.

Friday, March 06, 2009


MORE DISTURBING STATS ON ID THEFT…THIS TIME FROM THE FEDERAL TRADE COMMISSION


The FTC has just released their 2009 report on top consumer complaints for the year 2008. For the ninth year in a row, identity theft remains a strong number one with 313,982 complaints representing 26 percent of the total received. Keep in mind: these are actual complaints filed by real victims in incidents of identity theft. In case you aren’t familiar with the procedure, here is the FTC’s site. As you can see, they are fairly thorough in their explanations and instructions to consumers who need help.

I have been told by readers of this blog that the agency is useless in their attempts to solve problems with business or government. To a point, I agree, as do many top privacy advocates. But many of these concerns do stem from the incompetence and/or unwillingness of the Bush administration to do anything for the average consumer.

However, there are two major reasons why you should file a complaint when wronged. First, it goes into reports like the one I am covering here today, and becomes a tool used by the privacy community to convince Congress and the new White House to strengthen privacy law. Second, President Obama has named Jon Leibowitz, an FTC commissioner since 2004, and the lone Democrat on the commission, to serve as FTC Chairman. And yes, that means something, because it has become obvious we cannot depend on the Republican side of the aisle to do anything for the average consumer.

That said, let’s now turn to the FTC’s 2008 Top Consumer Complaints Report.

ID theft was ranked number one for the ninth straight year, receiving 313,982 complaints, representing 26 percent of the total of 1,223,370. Here are the hard facts folks. This is an increase of 21.5 % in identity theft over 2007, with a whopping 50.3% more total complaints registered with the FTC in 2008 over 2007. And here’s another revelation. Complaints against credit bureaus and other data purveyors rose from not even being counted separately in 2007 and 2006 to number six in 2008 with 3 percent of the total. I’d like to think The Dunning Letter, in its coverage of the Experian Credit Bureau’s treatment of consumers, had something to do with this.

The credit bureau entry into the race actually bumped sweepstakes and lotteries into the number seven position, which is significant when you consider the scams in that category. Another “newbie” is banks which are in control of much of our personal financial data, and don’t seem to always realize its value on the Internet black market. Junk mailers, including catalog sales, came in third, and Internet services came in number four.

My next grassroots movement is to convince American consumers they should demand to know everything that is in their credit reports, including any credit scoring techniques, including results, used by business to extend credit. And it should be free every quarter, not once a year, based on the fact that identity theft can happen at any time. Further, individuals should be able to correct their personal information within days, not months or years, as some of my readers have charged in their experiences.

Wednesday, March 04, 2009


BAD ECONOMY, GOOD OPPORTUNITY…FOR SCAMS


Here’s another of my pet peeves; people who still reply to advertising offers that are obviously too good to be true. I know we’re in a desperate economy, but that doesn’t mean you should fork out more money to get taken by the crooks. The latest is apparently rebate processing jobs, according to an MSNBC article by Herb Weisbaum. In general, the work-at-home scam has been worked over for years in the media, but the suckers are still out there and the bad guys know it.

Cindy Dalton tells us Rebate Processor Jobs is, “…unlike anything you may have heard of before! That's because this is not some 'get rich quick' or MLM program. This is actual, get paid every two weeks, work!” Denial works every time as part of the “convincing us” formula. Cindy will help you make from $200 to $1,000+ per day…if you pay her $39.00 first. Of all the complaints received by Gary Almond, vice president of the Los Angeles BBB, he says not one indicated they had made one penny. Along with Process At Home.com, Rebate Processor Jobs.com gets an “F” rating from the BBB.

Angel Stevens fronts for Process At Home, and she exclaims you need no experience, education or special skills, but you are guaranteed an “immediate position.” That’s a new way to make the pitch sound more official. Further, the latter will put up to $225 a day in your pocket. But wait, there’s more! It only takes you 60 minutes to make that. Now I’m sorry but anyone who bites after that is not working with all their faculties. If that wasn’t enough, one woman paid $197, apparently without first checking the BBB.

The National Consumer League has a couple pages of tips to stay out of harm’s way. Most are so obvious they shouldn’t have to be said over and over. To start, know who you’re dealing with because the scamsters just continue to come out of the woodwork. And it’s incredibly easy to broadcast millions of e-mails, so check out each one you plan to follow up on carefully. In other words, do your homework before you react. There are eleven tips in all, and I recommend that you visit the NCL site before you make any move on future work-at-home offers.

Someday, hopefully, there will be an official clearing house we can go to that will cover all categories of fraud, carefully grouped for simple searching techniques that don’t discourage the average consumer. I know, there are many organizations that document scams, but I am talking about an all-encompassing agency environment similar to the FTC’s Do-Not-Call Registry. I know I have a tendency to depend on government controls and regulation, but after what we have witnessed since last Fall, apparently the business world cannot be trusted to regulate itself.

In the meantime: IF IT LOOKS TOO GOOD TO BE TRUE…IT PROBABLY IS.

Monday, March 02, 2009


This is Part II of Grant Hall’s article, “Stalking Solutions.” Part I was posted last Friday. Grant’s e-book, Privacy Crisis, is one of the leading advocates in the field for individual privacy.


STALKING SOLUTIONS


Part II

By Grant Hall

MONEY AND BANKING PRIVACY

This writer has written extensively on the techniques necessary to conceal personal and investment funds for privacy purposes. While the needs of each individual will vary greatly, generally speaking, the use of entities including trusts, Limited Partnerships and LLC’s are valuable for privacy and asset protection. Additionally, check cashing stores and an anonymous safe deposit box prevent the freezing of accounts and any link to the funds once checks are cashed.
Useful websites for money and “banking” privacy are www.24-7PrivateVaults.com and www.PrivacyCrisis.com

WORK PRIVACY

While work privacy can be accomplished most easily by certain practitioners and the self employed, shielding one’s work place will be a challenge-especially for the majority of people who derive their income from wages, salaries and commissions paid by a traditional employer.
When one desires vocational or professional privacy, a sound plan is necessary in order to eliminate one’s name and Social Security number from any number of data bases that store this information. Trusts and LLC’s have been used with success as the employer and this re-structuring of the employer/employee relationship has been accomplished through negotiating with flexible, open-minded employers. A win-win situation for both parties will facilitate the negotiating process.

ANONYMOUS COMMUNICATION SYSTEM

Through the use of the aforementioned mail drop nominees and re-mailing of sensitive letters, one can keep their postal mail their own business.
The traditional one and two year cell telephone contracts-complete with a credit check that the public usually opts for is a definite no-no for the serious privacy seeker. You will want your entire communication system to reveal no link to your name. Therefore the purchasing of a cell phone off the shelf with no contract or registration requirements assures private telephone calls. Land lines at home are not a good telephone option. Land line telephones can be traced and the physical location of the telephone can be obtained.
Proxy servers enable the computer user to surf the net without being recognized by their IP address. The best companies provide a different IP address once or twice daily. When an anonymous proxy server is used in conjunction with email addresses that have no resemblance to your identity, computer security is greatly enhanced.
Computers should be purchased with cash. Software and all computer-related materials and online purchases are necessarily purchased with anonymous debit cards, money orders or cash.
Internet Service can be privately obtained through the use of company held accounts or an account can be secured by a nominee as explained in Privacy Crisis.

REFERENCES

Ohlson, Kristin, Stalking the Divine: Contemplating Faith With the Poor Clares, 2003, Hyperion
Hall, Grant, Privacy Crisis: Identity Theft Prevention Plan and Guide to Anonymous Living, 2006, James Clark King, LLC (eBook available at: www.PrivacyCrisis.com)
Copyright: James Clark King, LLC, August 28, 2008

Friday, February 27, 2009


Grant Hall’s e-book, Privacy Crisis, shows readers “where to get the goods and services to remain invisible.” Grant is a hardcore privacy advocate who portrays the personal data collection system as completely out of control, and provides consumers a way to solve their individual situation. This is a continuation of a series of guest articles in which I feel readers will have interest.


STALKING SOLUTIONS


By Grant Hall

One in twelve women will be stalking victims during their lifetimes and most stalkers are ex-husbands and previous boyfriends (Ohlson).
More than eighty percent of women who are stalked by ex-lovers are assaulted by their stalker and thirty-one percent of these women are sexually assaulted. Seventy-six percent of the women murdered each year were previously stalked by their killers according to Ohlson who wrote Stalking the Divine: Contemplating Faith With the Poor Clares.
Since the odds of being stalked and harmed by a tormentor increase when accessible information is readily available, a prudent plan to avoid these dangerous individuals would be the implementation of a high-level privacy plan.

HOME SECURITY

One’s home address is the quickest link to their physical location-unless privacy tactics are in place.
Homes can be owned anonymously through the use of a Trust and an Administrative Trustee can sign any and all required forms on behalf of the Trustee-the manager equivalent of the trust (Hall).
Mail drop nominees can be used to receive and forward mail thereby avoiding the use of a home address for mail communication purposes.
Only trusted friends and relatives should have access to a privacy seeker’s home location.
Without a link to a victim’s home address, a stalker’s efforts toward harassing a victim at their physical location will be thwarted.

TRUST OWNED AUTOMOBILE

The importance of separating one’s name and home address from their car is a necessary privacy tactic to avoid having the normal driver’s name and address surface when data bases are searched.
A trust is the most private entity as only those forming the document and those included in the trust documents have a need to have knowledge of the provisions of the trust. A trust does not have registration requirements.
Trust owned automobiles are more easily insured than those owned by Limited Liability Companies and Corporations in most cases. And when the trust owned car is registered properly with the Department of Motor Vehicles or other state agency, there will be no mention of the trustee and normal driver on the automobile registration. This important detail assures the driver absolute and total privacy as he or she travels.
Stalkers frequently hire individuals who have access to automobile registration data bases in order to locate their victim’s car and address.

CREDIT BUREAU FILES

Today, many states allow for the freezing of a consumer’s credit files. This is a huge privacy advantage and should be accomplished in order to preserve privacy.
Once credit files are frozen, only the consumer’s release of a password allows for the viewing of the credit file.
Serious privacy advocates never provide their home address to anyone except those in their close circle of friends and relatives-and this includes the credit bureaus and ALL businesses.

Part II of “Stalking Solutions” in my next post. In the meantime, visit Grant Hall’s site for lots of free information and his e-book, Privacy Crisis.

Wednesday, February 25, 2009


IT’S TAX TIME AND THE PHISHING SCAMS ARE BACK


They are lurking out there again as they always do around tax time. Although we have gone through the attacks before, we will suffer and encore of identity losses between now and April 15 that makes me wonder what it will take to convince consumers never to give up their personal data unless they are sure who they are giving it to. Maybe we could enlist all of you that were made victims in 2008 to spread the word around that this is a fraud.

The Dept. of Homeland Security has taken notice of what’s going on and issued a bulletin on the scam from its U.S. Computer Emergency Readiness Team (US CERT). Just scroll down and click on “Feb. 6, IRS Stimulus Package Phishing Scam” to get the details. You’ll be asked in an e-mail to provide your private information by following a link to the crook’s website, or to complete an attached document. No matter how much they are offering you in a refund, don’t do it. The IRS never corresponds with taxpayers for matters like refunds or asking for personal data by e-mail. They only do it by regular mail.

Homeland Security gives a link and encourages users receiving fraudulent e-mails to forward the message to their e-mail: phishing@irs.gov. There are also four points supplied to help the public mitigate the risks. If you read this and have a friend or relative, or business associate you know to be somewhat apathetic about the possibility of someone stealing their identity—and there are hundreds of thousands out there—I urge you to suggest that they visit this site.

As always, you can depend on MSNBC’s Consumer Man to cover the latest scams. Herb Weisbaum’s article, “Latest 'phishing' scam lures you with tax return,” talks about how the bad guys suck you in with a promised tax rebate. And who can resist that? Unfortunately, a lot of “gullibles.” That’s my term, and I’m sorry, but after years of grinding away at what to avoid on this issue, there are still those who bite. Someone should do research on the victims so we might begin to realize just how to solve the problem.

As Weisbaum indicates, the scam does deal with a substantial refund, and these are tough times when you just hope that today will bring better news, and, then, there it is. The author calls it a “sense of desperation” that is known to exist by the crooks, and which they prey on with the utmost sophistication.

They ask for your Social Security number, date of birth, mother’s maiden name, credit card information, even your ATM PIN number. First of all the IRS already has your SS#, and why could they possibly need the PIN for your ATM card? Red flags are hoisted all over, but all the victim is thinking about is the promise of something they probably already know they don’t have the right to. As the article indicates, the IRS does not send refunds by e-mails, don’t audit people by e-mail, and don’t collect taxes by e-mail.

CAUTION: If you get one of these e-mails, first, forward it to the IRS e-mail, above, then DELETE it at once, and never look back. Then help everyone you know to avoid the scam.

Monday, February 23, 2009


JAVELIN STRATEGY AND RESEARCH RELEASES 2009 IDENTITY FRAUD SURVEY REPORT


“For the first time in the past five years, identity fraud rates increased over the prior year. Yet during the same period, average consumer costs decreased sharply, according to the new Javelin report on identity theft.” Discouraging, yet somewhat encouraging. But some figures in the “Executive Summary” are downright frightening.

• Identity Fraud Victims Increased 22% to 9.9 Million in 2008
• Existing Credit Card Frauds Drive Expanding Incidence Rates
• Economic Downturn Historically Results in Increased Domestic Fraud
• Traditional Access to Private Data Continues to Be Commonplace
• Social Security Numbers/name and address Top Compromised Data among Victims

Let’s explore each of these points with hard figures. 1.8 million more ID theft victims in 2008 over 2007 means an additional $892,800,000 out of the consumers’ pockets, and $7.8 billion lost by business. Total loss for 2008 is $48 billion compared to $45 billion in 2007.

Annual credit card fraud grew by 16 percent from $19 billion to $22 billion in 2008. New credit card accounts fraud also rose by 20%, from $15 billion to $18 billion. For four years now, I have been expressing my concerns over unsolicited credit card mailings in this blog, one of the vehicles the crooks use to open new accounts.

With the unemployment rate topping 7 percent and thousands more jobs lost each month, there is desperation in the air in this economic downturn that is not likely to end any time soon. It provides the perfect environment for fraud, and today the fraud of choice seems to be stealing someone’s identity with whatever financial gain the crooks can extort. This demands the closest scrutiny ever for any transaction involving personal data.

While online access to private information remains at 11 percent according to the 35 percent of victims knowing who accessed their data, traditional access is still extensive. Things like the losing or stealing of your wallet, checkbooks or credit cards, totaling 43 percent of incidents where access is known. And here’s the kicker…a point I have been harping on for two years. There was an increase in data used that had been stolen and held for use until the one and two-year time periods ran out for free credit report inspections given by the breachers. I still believe this is the biggest threat to the security of our sensitive data.

Don’t give away the bank…in this case your Social Security number. In 38 percent of Javelin’s survey respondents, the data compromised was SS numbers. Name and address accounted for 43 percent, and when you add date of birth to the latter, that is all that’s necessary to wreak havoc with your credit.

Along with all the above, when you consider that the resolution time to correct the problem climbed again to 30 hours in 2008 from 26 in 2007, it should be obvious to all that protection is the way to go, and I don’t mean paid protection but simple preventive measures consumers can use on a daily.

An interesting point: with the millions of individuals buying protective ID theft services in 2008, we still had a 20.7 percent increase in fraud victims as a percent of U.S. population. From 3.58% in 2007 to 4.32% in 2008. Think about it.

If you want solid, thorough and concise information on how your identity can be breached, and how you can protect yourself from fraud, go to the Javelin 2009 Identity Fraud Survey Report – Consumer version. There is no easy way to handle this dilemma, and until the American public realizes that they must take responsibility in the protection of their names and personal data, we won’t see an end to the identity crisis.

Friday, February 20, 2009


ON THE LIGHTER SIDE OF JUNK MAIL


Based on my 35 years as a list/data broker, I have tried to convey to readers the danger of how junk mailers, and non-junk mail companies, recklessly collect, manipulate, and sell your names and personal data. It is rare that I can digress and talk about a junk mail company other than to criticize.

Vermont Country Store has been around for 64 years doing what most good catalogs do best: unearth the unusual for its customers. But Lyman Orton, the proprietor, resurrected an item recently that is sure to spice up the demure Vermont company, and bring back memories of my catalog days. I’ll explain the resurrected part later.

Lyman, age 64, added sex aids to the pages of his catalog known for selling heavy-duty toenail clippers and pine tar soap, according to an article on MSNBC. Items like pleasure gels, arousal creams and a six-speed vibrator. In case you aren’t familiar, that’s another name for dildo. But six-speeds? And that is where the “resurrected” part comes in.

When I was director of marketing for the Sunset House catalog some 30 years ago, we received a letter from one of our female customers who exclaimed that we had saved her marriage by introducing a six-inch vibrator to our catalog. In over two pages of hand-written copy, she praised this new item as if it saved her life, not her marriage.

The letter was circulated among top executives with everyone, of course, adding their own personal comments. The episode was talked about for a while, then forgotten. That is, until we received a second letter from the same customer. It was much more serious.

She started by thanking us again profusely for selling the six-inch vibrator in our catalog. She even stated that her marriage was still as healthy as before, but she did have a request. She had heard somewhere there was a nine-inch vibrator available. She implored us to please include this new version in our next catalog.

The catalog’s merchandise people had already reviewed the item and it was front-and-center in the next edition. Needlessly to say, we were thanked for coming through again.

It’s nice to write a feel-good story like this, and there will be a follow-up in the future reporting on how Vermont Country Store eliminates junk mail through predictive modeling, a practice that many junk mailers shun. In the meantime, visit their site here.

Wednesday, February 18, 2009


DUMBING DOWN ON PRIVACY


It would seem Facebook founder, Mark Zuckerberg never learns. Once again he changed policy granting the social networking site the ability to control users’ information forever, even if you cancel your account. Zuckerberg apparently did not take heed after the 2007 debacle where he had to back off a tracking tool called “Beacon” that displayed customers’ shopping habits and activities all over cyberspace. In another article on MSNBC, he recanted again just a day after the latest boondoggle, when apparently tens of thousands of users complained. Zuckerberg said the move was temporary, until the company develops new terms defining its privacy policy. What that means to me is that Mr. Z hasn’t yet comprehended the right of the individual to maintain control over their names and personal data, and, believe me, this is not only a Facebook problem. This is the dilemma of the entire data collection business. On the other hand, Maine police credit Facebook in the solving of a crime by posting pictures of teenagers who vandalized a crime caught on surveillance cameras. President Obama reneges, somewhat, on “open government” policy. It seems Justice has decided to retain some Bush policies on keeping the data collection and secret surveillance of U.S. citizens. They want to determine whether it will conform to the rewrite by the new administration of the Freedom of Information Act guidelines. After former Attorney General John Ashcroft supported Bush’s warrantless domestic wiretapping, Obama pledged “an unprecedented level of openness in government.” Several requests are pending based on the FOIA re. the former administration’s tactics, and there is some doubt if these will ever be satisfied. I think most everyone agrees we should look to the future and not belabor the past, but when the American public has just experienced the worst case of Big Brother since Orwell’s 1984, many agree that we should at least know what really happened. The question today is who we can trust to define what information is too sensitive for release to the public? Opinion piece in junk mail industry publication, DM News, promotes respecting consumer privacy. David Henkel, President of Johnson & Quin, specializing in printing, mailing, and database management for junk mailers, says “Consumer privacy must be respected.” He talks about personalization in the business of reaching the right customer with the right offer, and how it must not be carried too far. Targeting is good if it does not get into individual household personal data that clearly invades the person’s privacy. Things like whether or not you gamble or drink, what specific ailments you suffer from, and what medications you are taking. Targeting can be accomplished at acceptable levels larger than the individual household. But Henkel really caught my eye when he started talking about how customers’ credit card numbers are stored by junk mailers, those you buy from, even if you haven’t made a purchase for years. As the director of marketing for a large catalog company, I can confirm that the credit card number was maintained as a normal part of the customer’s record. That was awhile ago, and it occurred to me that we need to know what junk mailers are doing about this today in a much more volatile marketplace. Report on this later.

Monday, February 16, 2009


CREDIT CARD SOLICITATIONS GO UNDERGROUND


If your income is less than $100,000 annually, you received 26 percent less credit card offers in 2008, compared to 2007. A prime example of how the junk mail industry manipulates your personal data to maneuver consumers to respond the way they want them to. According to Mintel Comperemedia, who does research for junk mailers, announcing in a ConsumerAffairs report, funds for lending were down, and with the credit card companies already losing on current loans—apparently from those with incomes less than $100,000—they cut mailings back significantly.

Does that halt the barrage on our mailboxes? Not really. They just found another surrogate: businesses you are already dealing with that veil the solicitation under their name, hoping you will make the assumption they endorse the credit card offer. Of course, the business gets a cut from each application returned.

It goes like this. Holland America Line’s headline exclaims: “Presenting the Holland America Line Rewards Visa Card…Your next cruise is closer than you think.” We are cruisers but we have never been on Holland America, so why would I feel any relationship toward them. This is relationship marketing, or affinity, or third party, meaning the company uses their relationship with the customer to sell you something they have absolutely no control over if something goes wrong.

On the other hand, we have been on Princess Cruises, from which we have received two offers in the last couple of weeks. U.S. Airways has hit us twice in the same period of time, and the list goes on. This has been going on in junk mail for at least 35 years, and in bad economic times can be a boon to both of the businesses involved. By sharing the cost of the mailing, or riding piggyback in the company’s regular mail, everyone wins, except the consumer.

I say that because a 2009 survey just released by Javelin Strategy & Research says that 33 percent of the respondents reported that new credit card accounts were opened fraudulently in their name in 2008. That’s an increase of 27 percent over 2007. It only takes the crooks a few minutes on the underground Internet to buy your personal information like Social Security, date of birth, etc., and they are on their way.

You may eventually prove to the credit card provider that you weren’t the bad guys, but you will have a much larger battle convincing the three credit bureaus, Equifax, TransUnion and Experian, to correct your credit history, especially Experian. As an example, the average resolution time to fix your credit in 2008 was 30 hours, up from 26 in 2007.

In the near future I am going to review the complete Javelin 2009 Identity Fraud Survey Report. Here’s a preview of what they found. Identity fraud victims increased 22 percent to 9.9 million in 2008. Economic downturn historically results in increased domestic fraud. Traditional access to private data continues to be commonplace (emphasis added by me). For the consumer version—which I highly recommend reading for some great insights into preventing or dealing with ID theft—go here.

Friday, February 13, 2009


IDENTITY THIEVES WILL PERFECT THE "INSIDE JOB"


Wikipedia defines the “inside job” as “…a crime, usually larceny, robbery or embezzlement, committed by a person with a position of trust who is authorized to access a location or procedure with little or no supervision, e.g., a key employee or manager.” It goes on to identify former employees knowing the company’s layout as potential perpetrators. In Wednesday’s post, “IDENTITY THEFT INCREASES 47 PERCENT IN 2008 OVER 2007,” I quoted a just published report by Identity Theft Resource Center (ITRC) finding that Insider theft doubled in 2008 over 2007. When the times get bad, the bad get smarter.

At the end of 2008, there was an article from MSN Money with some facts that are both scary and eye-opening. It stated that 18 percent of the corporate world saw an increase in monetary theft among employees, with another 41 percent unsure. Here’s a statement that should jar any company: “Employers are hot targets for theft because workers "…know their systems, controls and weaknesses, and they can bide their time waiting for the right opportunity." This from Jack L. Haynes Int’l, supplier of workplace crime-prevention services.

And the employees guilty of the biggest heists frequently are the most highly trusted. These are the ones who can get into company computers and make off with your names and personal data. They are close to it every day, often with unlimited access. I am not just talking about junk mail databases of millions of names and private information, but also non-junk mail companies that also warehouse your sensitive data. Folks, there are few corporations out there that don’t maintain thousands of personal records on their customers and/or employees.

A Pricewaterhouse study even found that senior-level workers that had been around over seven years were responsible for 25 percent of all reported internal fraud. Most are men and they are well educated. Jack L. Haynes Int’l reports that about one out of every 28 employees was apprehended for stealing in 2007. Combined, these are all the ingredients for a disaster if the downturn in the economy gets worse and more people get desperate.

TechNewsWorld said it back in 2007: “A ticking time bomb of sorts is hidden away in the cubicles and workstations of many businesses. When it goes off, the personal financial information of customers and workers could be laid bare.” Yet one more survey provided some of the most significant findings. A Compuware commissioned study by Ponemon Institute revealed that 75 percent of all breaches in the U.S. were caused by insiders, while only one percent by external hackers.

So what’s the solution?

Bring the consumers of this country together to demand that Congress and the new administration get together to pass legislation that gives consumers control over their names and personal data. In the same bill, allow for compensation to the name-holder when it is sold to encourage individuals to assume this new protective responsibility. Now is your time to be heard. Contact your U. S. Representative; your Senator; The White House.

Wednesday, February 11, 2009


IDENTITY THEFT INCREASES 47 PERCENT IN 2008 OVER 2007


If you thought you had seen the worst of the identity crisis, think again. A report just released by the Identity Theft Resource Center (ITRC) shows 656 breaches disclosed in 2008 compared to 446 in 2007, a whopping increase of 47 percent. Like The Dunning Letter has been saying since mid 2008, the bad guys are just getting started, and, unfortunately, they are getting better. ITRC breaks the breaches down into five groups: Business had 36.6%; Education 20%; Government 16.8%; Healthcare 14.8%; and Financial Institutions 11.9%. While Government improved from first to third, Business took over this unenviable position.

The most frightening figures proving the sheer recklessness of all data collectors is that only a pitiful 2.4 percent of all breaches had encryption, and just 8.5 percent had password protection. Folks, we are in year three of this identity dilemma which started when the ChoicePoint data hit the fan in February of 2005 and brought this whole mess out into the open. Apparently the term “what does it take” is completely lost on those who collect, manipulate and sell our names and personal data.

ITRC breaks data loss down into five methods: insider theft; hacking; data on the move; exposure; and subcontractor. Further, they divide the latter by financial institutions, general business, education, government and healthcare. In last Monday’s post, “JUNK MAIL NEEDS REGULATION…AND NOW!” I talked about data on the move in the junk mail industry, specifically from mailing list/data brokers. Hundreds of thousands of names and private information sent to the wrong address and never retrieved. It would be an ID thief’s dream if he or she knew how to locate this gold mine…and eventually they will learn.

Electronic breaches still maintain a significant lead over paper breaches: 82.3% versus 17.7%. Insider theft has doubled in 2008 over 2007, which leads me to believe that more employees are discovering the value of the sensitive data they handle. Although I have absolutely no confirmation that this has ever happened, it seems to me that it would be terribly easy, and almost impossible to detect, an intentional shipment of a storage disk with consumers’ private information to a pre-arranged “wrong address,” delivering it right into the hands of identity thieves.

ITRC reports that 41.9 percent of data breaches in 2008 went unreported; down from the last figure I could find where a 2006 Ponemon Research survey said it was 79 percent. The current estimate means that hundreds of breaches not being reported could be yielding the loss of millions of consumers’ personal records that we do not know of. When you combine that with the number of ID theft victims that do not report their loss, the results could be astronomical.

One of the recommendations from ITRC is that when sending data from one location to another, it should be encrypted. When only 2.4 percent of 2008 breaches had encryption, their suggestion sounds like a cry in the wilderness. Like we have learned over the last eight years, business is not going to regulate itself. Only federal legislation is going to get the job done, and we are fast running out of time.

Monday, February 09, 2009


JUNK MAIL NEEDS REGULATION…AND NOW!


Two articles recently from junk mail industry publication, Direct, caught my attention, because they forecasted the possibility that more data breaches could eventually originate within that business. The first, “Why Direct Marketers Switch Jobs-Often,” quotes a recent study that says “…entry-level people work for 10 to 12 companies.” These are the folks that actually handle the processing of your names and personal data for junk mailers’ advertising campaigns. The typical employee spends about 2.8 years with a company, which isn’t unusual in the current marketplace.

So how can this potentially affect the mishandling of your names and private information? Part of the problem is obvious with the regular turnover of people serving in that capacity; training is limited and experience is short. In my 35 years as a list/data broker, I personally witnessed situations where data storage devices were laying out in the open at catalog companies, list/data brokers, and computer facilities where millions of consumer records were processed daily.

There is no doubt in my mind that security has increased at every level since the 2005 ChoicePoint debacle, but this is still an entry-level clerk’s position, and you do get what you pay for. Privacy Rights Clearinghouse (PRC), one of the country’s leading privacy advocates, has “A Checklist of Responsible Information-Handling Practices” on its website. The Direct Marketing Assn. (DMA) has its own “INFORMATION SECURITY GUIDELINES“ Any company, junk mail or non-junk mail that follows these guidelines would have a reasonably secure environment for its personal data.

As an example, they both recommend establishing a center for privacy control and putting one person in charge. PRC suggests doing penetration studies regularly to determine if the crooks can get through your security network. The DMA advises that junk mailers should insure that all third-party handlers of their data take responsibility for securing their data. Both PRC and the DMA stress making sure private information is secure in transit from one location to another. And herein lays one of the biggest dilemmas in junk mail.

Once again during my tenure as a list/data broker, although the clerk handling our list order(s) had a typed “ship to” address right in front of them, somehow in the process of transferring that to their list order instructions, they sent it to the wrong address. Since by the time we received confirmation of this it was out of their door into the hands of UPS or FedEx, it was impossible to stop. It was re-shipped but on occasion when we asked the clerk if they found the other data storage device, the answer was almost always no.

The second article from Direct was just as unnerving since it stated that nearly half of all junk mail companies have a hiring freeze, and 20 percent of them are planning to reduce staff. Obviously this is happening in all industries and cannot be helped in the down economy. Which brings me back to the headline, above, that accentuates the need for regulation. The government should establish guidelines for the handling of names and personal data by the mailing list business, much more stringent than those already on the books.

Billions of sensitive data records are handled by junk mailers each year, yielding these companies $4 billion of revenue on an annual basis. It’s time to put some of this back into protecting the consumer.

Friday, February 06, 2009


YOUR NAME AND PERSONAL DATA IS WORTH LESS IN 2009 THAN LAST YEAR


As a sign of the times, a recent headline on MSNBC said: “Even porn industry hit by slumping economy.” Currently residing in Arizona where golf courses are as plentiful as convenience food stores, I had heard from a friend that golfing has followed the trend. But I was more than amused when Worldata, a large junk mail list/data broker, published the results of its latest List Price Index, which is a survey documenting how much junk mailers pay for mailing lists with your name and private information. There was a significant decline across major categories of lists such as books, CDs, consumer magazines, and general merchandise buyers.

If you want to see the full report of to what degree your sensitive data is precariously peddled around the U.S., even around the world in some cases, go here. If you want me to paint the poignant story for you, read on. Almost four years ago when I launched The Dunning Letter, I contacted a number of sources from the Direct Marketing Assn. (DMA) to junk mail industry publications like DM News and Direct to learn the total revenue the list business raked in from your names and private information. Not only did they not know—or, at least, they weren’t telling—but they suspiciously wanted to know why I wanted to know.

In most cases it was made clear to those asked that the information was for a piece I was writing on the industry. Doors slammed shut and telephones went “click,” which basically ended my efforts to acquire this figure from those who could most accurately determine the annual results. After a couple of months assembling numbers from a conglomeration of reports provided to the public by the DMA, and doing research through the archives of DM News and Direct, I was able to create my own formula and arrive at the total. It was determined that every year the junk mail list business grosses around $4 billion from the sale of consumer names and personal data.

I am all for free enterprise, but why is this a one-way path to the pockets of junk mailers when they would have nothing to sell if not for the name-holder? That’s YOU, of course. Most of my regular readers have heard this over and over, but why not share the wealth with those without which no revenue would be possible? Another interesting formula I have come up with reveals that if half the $4 billion was placed in a simple interest-bearing account for the name-holders, at age 65 they could supplement their retirement with an additional $607 monthly.

Getting back to a sign of the times, with pension plans and Social Security in jeopardy as they are, has someone got a better idea? If so, please come forward. My contention is that with a new administration in Washington, it is time to get back to individual rights, and there is nothing more individual than our sensitive data.

Wednesday, February 04, 2009


VISHING, PHISHING, SMISHING. THEY ALL SPELL TROUBLE FOR THE CONSUMER.


Continuing with the Liz Pulliam MSN Money column, red flags should have gone up all over the place when the crooks were developing their latest method of stealing our sensitive data. They would have if we had a CIA-type surveillance of the Internet underground. And why not? With the economy tanking, and identity thieves rushing to take advantage of the situation, this would be the perfect time for industry to step in and form a consortium to infiltrate the bad guys. The cost would be small across the board, and the results could be significant. It’s an idea that could happen; that is, if business is really serious about securing our private information.

Vishing is the latest consumer scam that is a spin-off from phishing, which is when the ID thief sends you an e-mail, claiming to be a legitimate company with the idea of heisting your sensitive data. Vishing, on the other hand, uses the telephone or cell phone to do the same thing by leaving a voice or text message that says your bank or credit card account has been compromised. Recipients are told to call a toll-free number where they are instructed to dial in credit card or bank account numbers, including PIN numbers.

It suddenly occurred to me while writing this article that one of the most unique factors in the identity crisis is the number of names we have had to come up with, almost on a daily basis, just to keep up with the spate of consumer scams.

Vishing has been around for a while, but has recently picked up speed according to a December 2008 FBI report identifying new techniques exploiting the software used in the scam. Asterisk is free software used with Voice over Internet protocol (VoIP), which allows the bad guys to call multiple numbers leaving their automated messages. You should never reply to these calls; neither banks nor credit card companies use this form of communication to contact customers. One documented incident as late as mid-January 2009 used American Express as the target company.

In another article in The Washington Post by computer security columnist, Brian Krebs, he outlines “The Anatomy of a Vishing Scam.” Krebs leads with a reality that has been troubling to Internet providers and users for some time; the fact that there are gaping holes in our technology that allow these breaches. It could lead one to believe that the scam artists are much smarter than the technicians that maintain our names and personal data. The piece confirms the use of the VoIP software, and documents the sophistication used by the crooks.

As an example, one group of attacks were directed to financial institutions’ customers’ cell phone numbers, but restricted to only the geographic area served by the bank to maintain credibility. After compromising a web site to serve as their host, they downloaded the phone numbers that would receive the vishing messages and they were on their way. What is frightening is the fact that Lawrence Baldwin, who was brought in to investigate the attacks, learned that from one server alone about 4,400 people actually called the bogus number, and worse, 125 of those (2.8 percent) entered their full credit/debit card number, expiration and PIN.

Like P.T. Barnum said: “There’s a sucker born every minute.”

Monday, February 02, 2009


CAUTION ADVISED ON POTENTIAL FOR ID THEFT IN THESE TOUGH TIMES


If you think the heisting of our sensitive data has already been as bad as it can get, then think again. Preying on the elderly and the suckers among us is bad enough, but taking advantage of bad economic times—which much too often still involves the elderly—is a step that establishes the identity thieves as the worst of the scumbags. But this is the normal approach for the greedy, and we should have anticipated their plans. However, their tactics and modern technology seem to move at a pace just ahead of law enforcement, which is unfortunate for the consumer.

Liz Pulliam Weston’s column on MSN Money, as usual, does an excellent job of taking us from the present into the future of where we can expect to go with the identity crisis. Yes, we had fewer victims in 2007 (2008 results are not out yet) by .67 percent. The Javelin Research report goes on to recount just where your private information breaches are coming from: 33 percent lost or stolen wallets; 23 percent lifting your pin or credit number while looking over your shoulder during a transaction; 17 percent by your family or friends; 12 percent online; and 7 percent resulting from data breaches.

Pulliam has indicated in her piece the fact that ID theft resulting from data breaches ranks last, but let me point out that, even in last position, it produced just-under 600,000 victims in 2007. At $5,720 each, that’s $3.3 billion lost by consumer fraud, and 14.7 million hours wasted by them in repairing their credit. Of course this is only one method of stealing your stuff. One can only wonder if all this has taken its toll on the productivity of the American worker. It has certainly established its position in whittling away at the family budget of those affected.

The article has some good points on how to protect your personal data from maintaining a file of credit card telephone numbers in case of loss, to whether or not you should freeze your credit. I strongly urge you to read this piece in its entirety for a wealth of facts that will help keep your identity safe. In particular is a section on ATM use, and the protection of your pin numbers due to the fact that the crooks are increasingly targeting bank accounts. You close one door they open a new one immediately in their quest to steal our private information. What Pulliam is saying—as is about every privacy advocate in the world—be vigilant any time you are in the process of a financial transaction.

Pulliam also covers the latest twist on “phishing,” which is when the bad guys send you an e-mail, claiming to be a legitimate company with the idea of heisting your sensitive data. The new spin on this is called “vishing,” which involves leaving a voice message on your telephone landline or cell phone, or text messaging your cell phone. That’s next time.

Friday, January 30, 2009


WHAT DOES THE BERNIE MADOFF SCANDAL HAVE TO DO WITH ID THEFT? MORE THAN YOU THINK


Bernie Madoff awoke one morning in his East Side apartment to face two FBI agents. Special Agent Theodore Cacioppi asked him: “We're here to find out if there's an innocent explanation," referring to reports his investment firm had stolen billions from its customers. Madoff replied: “There is no innocent explanation.” And that is one of the comparisons to identity theft; the only reasoning in either case is the greed of an individual that overrides all common sense and decency.

When the tanking economy prompted many of Madoff’s investors—which included big names like real-estate magnate Mortimer Zuckerman, Nobel laureate Elie Wiesel, Sen. Frank Lautenberg, Hollywood director Steven Spielberg and Zsa Zsa Gabor, some, close friends—to pull out their money, the fraud was finally discovered. Employees actually went to his apartment where Madoff admitted the fraud. His two sons, also among the shocked employees, called the Securities and Exchange Commission, which tipped off the FBI, according to a New York Daily News article.

Thus, the second comparison to ID theft. According to Javelin Strategy & Research, almost half of identity fraud is perpetrated by friends, neighbors, employees, family members or relatives.

Bernie Madoff is charged with the biggest Ponzi scheme ever, costing his victims $50 billion that many experts believe is a complete loss. Coincidentally, almost $50 billion was lost to identity theft in the last Javelin survey, this through a network of crooks that come across almost as sophisticated as Madoff. The point here is that it would be near-impossible to protect against an investment conspiracy like Madoff’s, since years of reputation and friendship were used to pull off the scam. Of course, questioning the spectacular results being experienced in such a down economy would have helped.

On the other hand, it is possible to prevent identity theft by giving consumers control over their names and personal data, and compensating them when it is sold to encourage taking over this new responsibility.

In the meantime, I thought we might start a “Buddy System” to help friends, relatives, even strangers if they will listen, to guard their private information from the bad guys. You remember summer camps when you went swimming and everyone was assigned a buddy for both of you to watch each other. Of course, today’s breast cancer buddy system is one of the most prominent and successful.

As a privacy advocate who lives the part every day, I am amazed at the number of people I run into who either do not understand the basics of protecting their sensitive data, or are of the group that thinks it could never happen to them. In other words, it is at the bottom of the priority list, and is likely to stay there until public recognition is aroused. Perhaps those of us who understand the problem can pass the word around of just how important it is to safeguard our private information.

Just tell them if they don’t, and their identity is stolen, it could cost them $5,720 and at least 25 hours to take back their credit. That’s the facts, folks.

Wednesday, January 28, 2009


SHADY CHARACTERS ABOUND IN THE IDENTITY CRISIS


Remember the old days when we used to think of something on the black market being either jeans, CDs, videos, even body organs? Now there’s a new player on the block and they are interested in your name and personal data. It’s a well organized, calculated business to acquire all the consumer private information that can be had, either easily, or no matter how much effort it takes to get it. The idea is to steal your sensitive data, and, rather than capitalize on what they have themselves, the thieves sell it around the Internet underground to thousands of takers who then proceed to cop your identity.

Newsweek had an article last December, by Benjamin Sutherland, quoting a French security specialist who estimates there are several hundred online marketplaces just bursting with your latest personal data. My take is that number is conservative. It’s the general run of information that is available. Bank accounts that go for 5 to 10 percent of your balance. But credit cards are the most in demand, garnering around $450 for 10 accounts if you are in the U.S. or Western Europe. Like any other commodity, it is quality that determines the final price.

Naturally, I still believe that my concept of giving consumers control over their names and private information would put an end to this black market trade. Let’s set up a scenario where the crooks have stolen your personal data, including your Social Security number, and have sold it extensively to the underground.

The next move by the bad guys who bought your private information would be to open all the new accounts they can before being discovered. Then, either make purchases in your name or go for whatever cash is available in the credit line. Regardless, you’re on the line for the dirty dealings until, and if, you can prove it is ID theft. But wait…resulting from federal legislation, you were given the right to control your sensitive data, and through a process of approval necessary, whenever your private information is used, you have the ability to stop any and all transactions, ultimately spoiling the heist.

If you want to see the mechanics of how this control over your name would work, go here.

Since much of the thievery of our private information originates outside the U.S., it is sometimes near impossible for the American government to identity the bad guys, must less get the country to take action against them. As an example, in a 2006 study of phishing, 4 percent came from Great Britain, 6 percent from China, 8 percent from India, and 14 percent from South Korea. It is a well known fact that a great deal of identity scammers reside in Russia. In case you’re wondering, phishing is sending an e-mail posing as an established company to get the receiver to give up sensitive data.

In a crooked reseller’s market, the number of times your personal data is sold is unlimited, which means that there are endless possibilities where your identity can be breached and stolen. This is all escalating to a point where current methods of protecting the individual’s identity are proving useless. If someone has a better idea than giving consumers control over it, let them come forward. Pretty soon it will be too late.

Monday, January 26, 2009


DUMBING DOWN ON PRIVACY


A Penton Media junk mail online publication, Chief Marketer, looks at the future of Direct Marketing after the election. Lots of plans, but nary a mention of how the industry would strive to improve sensitive data security. Of course we wouldn’t want it to be top priority, with identity theft running at the head of the consumer fraud class. With the Direct Marketing Assn. trade group downsizing recently, there is even less oversight for junk mailers who push the envelope or even commit outright deception. Hopefully, the age of “let business police itself” went out the door with George W. Bush. Sorry, but it is obvious from the economic mess we are in right now that has affected so my industries that greed at the top has more appeal than doing the right thing. With around 60 million junk mail households in the country, they have the right to expect that this business lives up to the highest standards in handling their names and private information. Therefore, I hope that the new administration will consider some regulation of junk mailers when it addresses the identity crisis…and soon! Wrong conclusion on new Better Business Bureau strategy. First of all, I don’t believe the BBB is consumer oriented enough; it is clearly more in the corner of business. But an article on MSNBC by Eve Tahmincioglu, misses the point completely about the new agency’s approach. The author takes them to task over a revision in rating businesses that sets up a report card system (A thru F) that is much easier to interpret when deciding to deal with a company or group. She even makes a statement in the piece that proves my point. She says: “Before, if you were a business owner all you had to do was get yourself off the unsatisfactory list and you'd be okay with customers.” A few years ago when the qualifications were “satisfactory” or “unsatisfactory,” I questioned the “satisfactory” rating of a “get rich quick” junk mail company for having a large, and I mean large, number of complaints. The BBB’s answer was that, with regard to the number of complaints in relation to the amount of business they did, the formula considered them OK. Having spent over 25 years as a junk mail list/data broker at the time, I knew that their “amount of business” was reported as the number of suckers that responded to an appeal that promised they would get rich overnight. No wonder the proportion worked in their favor. The new system would probably give them as F, at least a D. Here we go again with another anti-identity theft bill. OK, at least it is designed to make it harder for the bad guys to get your Social Security number. Senators Judd Gregg (R-NH) and Dianne Feinstein (D-CA) introduced the bill in January, according to junk mail publication, Direct. Called the Protecting the Privacy of Social Security Numbers Act, it prohibits the sale, purchase or display of a Social Security number by any person without the number holder’s consent. That’s good for legitimate business, but what about the Internet underground that could care less about federal legislation. Why can’t these lawmakers just realize that there is only one way to end the identity crisis? Give consumers control over their names and personal data, and compensate them when it is sold to encourage the acceptance of this new responsibility.

Friday, January 23, 2009


WILL PRESIDENT OBAMA TAKE ACTION ON THE IDENTITY CRISIS AND WHEN?


First, let’s all congratulate our new President, and wish him well in the next four years. It has become painfully obvious since the election just how much Barack Obama will need our support, and he has made it clear on several occasions, there is only so much government can do. The rest is up to the people, as once again we can expect that their voices will be heard by a new administration that is telling us it wants our input.

As a matter of fact, the Obama transition team established a website where consumers can ask questions of President Obama, while suggesting what should be done in the next four to eight years. Change.gov has already taken more than 76,000 questions from over 103,000 people, and you can be next. Naturally, I have asked the President if he would consider federal legislation that would give consumers control over their names and personal data. The top questions so far are would Obama investigate the Bush/Cheney administration for its wrongdoing and would he favor legalizing marijuana?

According to a 2007 article in junk mail industry publication, DM News, a then Senator Obama sent a letter to the Federal Trade Commission in May of 2007, suggesting they increase their efforts to protect elderly citizens from telemarketing scams. It was directed at junk mailers who took advantage of seniors, and was a result of the New York Times article that same month covering the problem. You can see a copy of his letter here. Junk mail data broker, InfoUSA, was singled out as providing lists of older Americans to telemarketing fraudsters. Lists with titles like, "Suffering Seniors" (people with cancer or Alzheimer's disease); and "Oldies but Goodies" (gamblers over 55 years old).

When I worked as a list/data broker, the list business had a nickname for them: the “gullibles.”

Robert Gellman, a privacy and information policy consultant and DM News columnist voiced concern this kind of publicity would “play negatively” for junk mailers. In response to a spokesman for InfoUSA, Stormy Dean, who was quoted as saying, “When it comes to these telemarketer scams, how a list purchaser uses a list is out of our control," Gellman commented that this position was wrong, that InfoUSA had a problem and should acknowledge it.

My comment: It is Dean’s kind of attitude that sends chills down the spines of privacy advocates, confirming once again that the junk mail industry does not exercise adequate security to protect the identities and sensitive data of its customers.

No matter what direction the Obama administration takes on behalf of privacy, particularly the identity crisis—I am not naïve enough to think it ranks up there with the problems of the economy, the Iraq War, or the mideast situation—but if something is not done soon to protect the public’s sensitive data, the entire infrastructure of the American family will be in danger.

The new President asked for our help; let’s give it to him in the form of suggestions you might have on this important issue.

Wednesday, January 21, 2009


WHO OWNS YOUR NAME AND PERSONAL DATA? ACCORDING TO THE JUNK MAIL LIST INDUSTRY, THEY DO


Surprised? Probably not. Some of you don’t care, many don’t want to worry about it, a lot think it doesn’t make any difference. You’re all lumped into a category I call the “Apathetics.” Oblivious to what is happening to your private information until you’re hit with identity theft...and then it’s too late. Mailing lists are a big business, bringing in an annual gross figure of around $4 billion. That’s a number I worked on for several months, using my own formulas and sources of data because junk mailers won’t tell anyone how much this profit center is worth. My figures are based on 35 years as a junk mail list/data broker, so you can see they do have credibility.

Naturally, list owners—as they refer to themselves—are quick to protect this revenue stream that produces approximately 60 percent profit. Keep in mind, this is actually a by-product of the purchase you made of a product or service from some junk mailer. Somewhere in the order form, almost hidden at times, you will be told that your name—not mentioned, but including private information in some instances—will be “shared” or “exchanged” with other reputable mailers. Never, will they come right out and say that they sell your name up to 50 times in a year, based on each purchase you make. Some let you opt out of this, yet others, even some large junk mailers, do not.

The way they protect this gold mine is by forcing other junk mailers to sign a “list rental agreement” with terms that restrict the selling of your name and address. That’s good for the consumer since most contracts prevent sending you pornography, or fraudulent offers. But also included in each arrangement is the verbiage stating that your name, address, possibly personal data, being sold to the other junk mailer remains the exclusive property of the list owner. Although, perhaps, a technicality to define who originally collected the names and addresses, most junk mailers take this literally as a mandate of their sole proprietorship of our private information.

As an example I picked one of the largest list/data brokers to prove the point. Worldata, out of Boca Raton, Florida clearly states in their agreement that the List Renter “…agrees that this information is the exclusive property of the List Owner.” “Information,” of course, is your name, address, maybe personal data. In the beginning you can see that this is a current instrument used by the junk mail industry today because of the 2009 dateline.

Don’t get me wrong. I don’t think the individual should own their name and private information either, due to the number of con artists out there that would take advantage of those who are vulnerable. My concept is that your name and personal data should remain as a free spirit, much akin to how the airwaves used to be in delivering broadcast media. Like the radio and TV stations that transmit the programming do, consumers should have control over their sensitive data. And, they should be compensated when it is sold to encourage taking on this new responsibility.

However, it will be impossible to sell this concept as a federal law until American consumers convince their congressional leaders they want control over their names and private information. Only then will we stem the tide of junk mail industry lobbyists that somehow have prevailed upon Congress that they are the rightful owners of America’s individual identity.

Monday, January 19, 2009


WILL FEDERAL TRADE COMMISSION CHANGE ITS TUNE TO PLACING CONSUMERS BEFORE BUSINESS UNDER PRESIDENT-ELECT OBAMA?


It can’t get much worse; I’m talking about George W. Bush’s rein over making sure the business community takes complete preference over the lowly consumer. We were simply pawns to this man and his renegade posse that almost put this country in an economic stupor. But rather than rail over the incompetence and deplorable decision-making by “W,” let’s look at how the Federal Trade Commission can change its tactics back to the agency that is supposed to stick up for U.S. citizens in the marketplace.

Of course, my primary concern is over the individual’s privacy, specifically how this relates to the identity crisis. It won’t be long before Javelin releases its 2008 report on identity fraud, and I expect, with some exceptions, it won’t look nice. As an example, in 2007, although down almost 10 percent from 2006, ID theft victims still numbered 8.4 million, and lost $49.3 billion, also down somewhat from the earlier year. The average fraud amount in 2007 went down to $5,720 from $6,278 in 2006, and on average it took you 25 hours to solve your predicament. Even if it improves in 2008 by proportion, we still have a long way to go in resolving the identity crisis.

In October of 2002, a warning headline in junk mail industry publication, DM News, “List Industry Could Be Next Target for the FTC,” cautioned junk mailers that investigations could be underway soon into some of the questionable techniques used by data brokers to sell your names and personal data. Howard Beales, then, director of the FTC’s bureau of consumer protection, said in an October 24, 2002 meeting, “We’re very interested in pursuing investigations involving lists and list brokers.”

As a former junk mail data broker for 35 years, I filed a request with the FTC in Sept. of 2003 under the Freedom of Information Act for more specifics on this meeting, but received little because there really wasn’t much more than what was covered in the above article. Knowing what I know about the selling of mailing lists, I could have turned the get-together into a consumer rumble for the rights of individuals to their sensitive data.

Beales did say they had caught Eli Lilly releasing e-mail addresses for 600 users of Prozac; Microsoft did not maintain the level of security promised for its Passport System; and American Student List Co., along with National Research Center for College and University Admissions sold students’ names, addresses and dates of birth in the marketplace after promising they wouldn’t. All meaningful consequences to our privacy, but still not addressing the root problem: the fact that thousands of junk mail companies out there have consumers’ names and private information, most of which still think it is their "proprietary" property, to do with as they please. As if the individual name-holder has no rights in this issue, except an opt-out section in most junk mail offers that is, at best, misleading.

As far as I can tell, that was the end of any meaningful investigations into the secret world of selling names and personal data. By the way, Howard Beales resigned from the FTC about two years later and returned to academic life.

Next time: data broker and junk mail company contracts written to maintain ownership of your names and private information.

Friday, January 16, 2009


THE TIME HAS COME TO HOLD EXPERIAN ACCOUNTABLE


Most posts in The Dunning Letter result from bringing you current events, with some analysis on how they relate to your privacy. On other occasions, such as today, there is a necessity involved that dictates speaking out. The opportunity that presents itself is one of far-reaching concern over the credit bureau Experian, and its level—or lack of—customer service.

On August 18, 2006, I did a post, “Experian Denies My Right to Dispute Credit Report Problem,” after which I have received a parade of comments (28 to date on just this post), e-mails, and visits to this blog with searches titled “Experian dispute.” Earlier in August of 2006, I had done another post, “Level of Competence at Experian Credit Bureau Found to Be Low,” that documented my personal experience of having my credit report go temporarily missing from the paid service I used, Credit Manager, which normally provided 24/7 access online.

In other words, I had uncovered a rash of complaints against Experian, that did not appear to be anywhere near as prevalent with the other two credit bureaus, Equifax and TransUnion.

Speaking of TransUnion, they had their bout with the government and lost, all the way to the Supreme Court. Back in 1992, the Federal Trade Commission filed suit against TransUnion for selling information that was taken from their consumer credit database. The country’s highest court agreed with the FTC, and the practice was stopped.

But in the last couple of weeks I have received at least five comments, some desperate, accompanied with numerous e-mails, from exasperated victims of Experian’s abominable customer service. I can’t imagine what is taking the FTC so long to take action against this credit bureau; The Dunning Letter, alone, has recommended on numerous occasions that Experian casualties file complaints with the FTC.

I even posed this question with a top privacy advocate who also has no idea how long it will take the agency to wake up. This source does emphasize: always file a complaint because eventually the number will be too large to ignore.

This all brings me to an article I read recently in a junk mail industry publication headlined: “Experian Lays Off 130.” Agreed, this was not the company’s credit bureau operation, but rather the marketing arm for selling their database with well over 200 million consumer names and private information. Things like age, income, whether you drink or gamble, what your ailments are and the medications you take for them. The list goes on numbering hundreds of personal things this company knows about you and sells on a daily basis.

The irony of this is, why couldn’t Experian retrain these people and use them in the credit bureau’s “customer service” department, instead of putting them out of work? Anything would be better than the attention the public is getting now.

Experian’s last reported six month period revenues in 2008 generated $1.04 billion in revenue and $251 million is profit. Total company employees number 15,500, less 130. You’d think out of 15,370 people Experian could find someone to handle you complaint.

Maybe it’s time this action made its way to the Supreme Court.

Wednesday, January 14, 2009


NOW WE HAVE TO WATCH THE ONES WHO ARE SUPPOSED TO WATCH OUT FOR ID THEFT


If you have become a victim of identity theft, it’s your local police department that you turn to by filing an identity theft report as required by the Fair Credit Reporting Act. You will no doubt have to give law enforcement your date of birth, which they will enter into the report, which could eventually become available to others. And that is the problem. Connected to your name and address—also in the report—your date of birth is one of the primary elements the crooks need to steal your identity.

In a recent article from the Arizona Republic, in some cases Phoenix Police censor critical personal data, such as your date of birth and Social Security number, and sometimes they don’t. Apparently, in a lot of incidents the DOB is necessary to narrow the search down to the exact person being looked for when additional investigations are conducted. The state of Arizona does have a law that protects residents’ private information, and the Phoenix City Manager says the city “began restricting public documents, at the request of city attorneys, to comply with an Arizona law designed to protect residents’ personal information.”

Other police departments confirm that date of birth is necessary to prevent mistaken identities, and this is supported by private individuals and companies who have to access these records for business purposes. What we have here is one of those situations that can give privacy advocates a bad case of heart burn. This, combined with an active terrorist movement, plus bad guys that seem to find new and better ways to rob us each day, provides a real dilemma. And it doesn’t appear that either side is willing to give in completely, nor should they.

If your state has a law protecting this sort of personal data collection, please share it with us all, and provide any information you might have on what your local law enforcement jurisdictions collect and make available to the public.

Somewhere in the future, either technology will give us the ability to solve the identification process without giving up the family private history. Or, Congress will eventually implement the Real ID Act. You remember this fiasco, the one that requires each state to come up with an ID card that is standard by federal guidelines. The Act was delayed in 2008 with an extension to December 31, 2009. I wouldn’t have bet on anything of this nature backed by the Bush administration, but perhaps Obama’s “heads” can figure out a way to ID each of us without potentially giving away the farm.

What I do know is that with each announcement of this type, we get closer and closer to the time when the data burglars won’t have to spend more than a few seconds to determine from where to steal your private information. The way things are going, it’s only a matter of time before the crooks compile their own “Directory of ID Theft Sources.” And with public apathy toward the identity crisis continuing at a steady pace, those sources will persist and become more valuable each day.

Monday, January 12, 2009


TARGET DEMANDS YOUR DATE OF BIRTH TO PURCHASE WINE


Just before this last Christmas, my wife was shopping in a Target store when she realized she needed a gift for an upcoming party. Since a good California wine is always acceptable, she headed for the liquor section, eventually finding what she wanted. At the checkout stand the clerk asked her for her driver’s license to confirm that she was over 21. My wife looks great and they did card her at restaurants up into her late 30’s, but the fact is she will be 65 this month and anyone with common sense would know she is over 21. Willing to show the ID, she quickly withdrew her license when the clerk indicated she was going to scan it into Target’s database. The purchase was, of course, cancelled.

We had already gone through this earlier with Safeway re. the cashing of a check. Even earlier it had been OfficeMax, who wanted to scan my wife’s driver’s license number to return an ink cartridge just because the purchase date was older than 30 days. Back in October of 2007, I did a post on Albertsons/OSCO when they sold our family’s personal data, including medication information, to the pharmaceutical industry. Their pharmacy, OSCO, also once asked me for my Social Security number for their database, which I refused as did my wife in the other incidents. But back to Target.

Since the store manager was clueless over why they had to scan the date of birth into their database saying over and over—“it’s just store policy”—my wife opted to buy the wine somewhere else, and, of course, it was my decision to tell this story to the President of Target by e-mail. I explained to him how complete the Arizona license is with identifiable info, including a picture, and that checking it should be sufficient. An afterthought, however, was that they might not trust the judgment of their clerks, but that is another complete story.

I had my answer within two hours from Joe, who wouldn’t give me his last name due to security purposes. They are worried about Joe, but not what might happen to my wife’s sensitive data once it is in their database. By the way, all that is necessary to commit identity theft is your name, address and date of birth, and I don’t have remind you how many companies had their customers’ private information raided in 2008. Some big names include: Hannaford Bros. (Eastern) Supermarket Chain, 4.2 million personal records; Countrywide Mortgage, 2 million; Starbucks 97,000. Target gets “A” for response time but “F” for policy.

Agreed, companies have to be careful who they sell booze to, but it borders on the ridiculous when the separation in the components in question—this case age—is 45 years. Rethinking my earlier statement of not trusting the clerk’s judgment, it is obvious they don’t even trust the store manager to make this decision, much less update them on the specifics of the policy.

In closing, Joe did tell me that Target only keeps the birth date after swiping the driver’s license, and that the company has a new policy under consideration in relation to this kind of incident. But added that he couldn’t guarantee quick action. Until that new policy is enacted, our family has decided to stop buying any alcoholic beverages at Target, and only other products there not available at other stores at comparable prices.