Showing posts with label financial self defense. Show all posts
Showing posts with label financial self defense. Show all posts

Tuesday, December 9, 2014

The 12 Scams of Christmas: Financial Self Defense

The holidays are a time of family togetherness and celebration. Scammers know you're distracted, busy, and emotional. That's why their schemes are so devilish around Christmas time.

 In the interest of keeping things in the holiday spirit, let's look at 12 scams of Christmas. Don't get taken in by these or similar schemes. Otherwise, you might be footing the bill for twelve drummers drumming and all the rest!

1.) Mobile malice

 Be wary of "season-themed" apps that perform frivolous functions, yet demand top-level security access. An app that makes it look like there's snow on your background image doesn't need to send or receive texts. Such an app might send premium text messages and leave you holding the bill.

2.) E-card danger
 
Everyone with an email address will send these little flash programs. Scammers have designed some with malicious code. They can install data leaching programs on your computer and do untold damage. Don't click links in emails unless you know the sender. Even then, if it looks a little out of the ordinary, it probably is. They may have already fallen victim and it would be good to let them know.

3.) Fake packages

You'll be receiving unexpected packages this season. Scammers know this and will send realistic-looking delivery failure notifications. They expect you to follow up with them and reveal personal identification information! Head to your local post office or call the parcel delivery service to check with a clerk before you hand over information on the Internet.

4.) Hotel "Lie"-Fi

The FBI issued a warning to this season's travelers about a malicious pop-up at hotel chains around the country. This scam requests people install a foreign program before connecting to a hotel Wi-Fi network. This foreign program turns out to be data-stealing malware. Remember, Internet connections you don't own or control can easily be used against you. Before you use the Internet at a hotel, ask yourself if it's worth the risk. If you do need access, be wary of what you're installing--there shouldn't be a need to install anything.

5.) Festive spam

 We've all gotten used to filtering out spam in our email. Now prepare yourself for it to take on a more holiday-oriented theme. Messages will suggest that off-brand Rolex watches and cheap pharmaceuticals would make excellent gifts. Be careful, though, because these companies might just be in the market for your personal information.

6.) Bogus gift cards

There's a bonanza of savings to be had buying gift cards through second-hand retailers. Be careful, though, because many of these retailers might be a front for scammers. Gift cards may be invalid, used, or forgeries, and you'll be left holding the bill.

7.) Fake charities

 These crop up every time there's a major disaster, but they also show up at the holidays. Leaflets and phone calls from organizations with familiar-sounding names will soon appear. To be safe, don't give to any charity with whom you didn't start the contact. Do your research and give to charities whose values align with your own.

 8.) Must-have gift scams

 There will soon be an "it" gift. You'll know it by the high demand, low supply, and hugely inflated prices. Almost on cue, websites will pop up offering the rare widget at unbelievably low prices. This is a scam - the advertiser doesn't have the product and is only using the offer to harvest personal information or bilk you of your hard-earned money through sites like Craigslist or eBay, where they will seek payment through PayPal and never send the item you purchased.

9.) Christmas catfishing

"Catfishing" means pretending to be seeking a romantic partner on the Internet to dupe people. Scammers take advantage of the loneliness the holidays can evoke to trick people out of gifts or worse. As tempting as it is to believe in love stories at Christmas, keep your feet on the ground and practice safe Internet dating.

 10.) Holiday vacation scams

 If it's cold and miserable where you are, it's always tempting to go someplace tropical for a few weeks. If you're thinking about getting away, be careful of unrealistic prices or "too-good-to-be-true" travel offers. Scammers have been setting up phony travel sites to harvest personal information. Only book through reputable websites.

11.) Devious Christmas games

If you're facing a 5-hour flight and a 3-hour layover, it's fantastic to have a distracting mobile game to pass the time. Be careful, however, not to download the wrong one. Mobile games can harvest data from your phone or steal password information. Always do a quick search to check the validity of the app you're downloading and read the permissions carefully. A fun game should never ask for permission to send texts or send information to third parties.

12.) Free USB Tricks

Be careful with unsolicited gifts of "free" USB thumb drives. Security firm McAfee warns that many of these devices come pre-loaded with malware. Such scams often target company computers, so ensure you only use approved hardware on your work network. USB storage is cheap enough that you can pass on the freebies.

Monday, October 27, 2014

Card Security Breaches: Why They Occur And Who's To Blame











It seems like there's another financial disaster at every turn lately. Target's card databases get hacked. Heartbleed puts your passwords at risk. Home Depot's credit card numbers are compromised. JP Morgan Chase's credit information is breached. Shellshock threatens the integrity of the Internet. It's enough to make you long for the days of the corner store keeping credit on a sheet of graph paper.

 To better understand how these things happen, let's first take a look at the steps involved in a financial transaction. Then, we'll see where vulnerabilities exist. Finally, we'll check out a few strategies you can use to keep yourself safe.

 When you swipe your debit or credit card at a terminal, the only thing you see is an approval screen. Behind the scenes, the process from the moment you swipe a card to leaving the store with your purchases is complicated. And you want it to be that way. A less complicated process would remove many layers of security.

 First, there's an "authentication" process. The POS terminal in which you swipe your card reads the card's information from the magnetic strip, encrypts it, and sends it to a payment processing center. This facility streamlines the data into a format your issuing company can understand and sends it along. Your card network company - Visa, Mastercard, Discover, etc. - validates the legitimacy of the information. You may be prompted for some information, most commonly your billing ZIP code. This is done to help authenticate the card.

 Second, there's the reconciliation process. This is usually done at the end of the day for most retailers. The retailer sends all the day's receipts to a payment processor, which then sends them to the issuing institution - the credit union, bank, or credit card company. That institution debits its member or customer accounts for the amount of the transaction, then sends that money to the payment processor, which sends it to the retailer.

 This is an explanation of how things work in a very simplified example, but it gives you an idea of the complexity that's involved in the process of paying with a card. While it's a lot of steps, it's the best system that the brightest minds in the financial industry could develop. Unfortunately, each step also introduces a layer of vulnerability.

 The encryption protocol for card authentication can be busted (that was, in part, what Heartbleed was about). The retailer's receipt records they use for reconciliation can be hacked (like what happened to Target and Home Depot). The credit union or bank can have their register of accounts hacked (like JP Morgan did). So many layers of complexity create more possibilities for hackers to compromise sensitive information.

 You might notice that there's only one step in the process that involves Pen Air FCU or our computer systems. That comes at the very end of the process, when member records are debited for purchases. In the latter example, the only victim of that theft was a big Wall Street bank. In such cases, the kind of hacking hardware and know-how that is required to orchestrate such an attack are expensive. Because credit unions are smaller and less centralized, they're much less likely to be targeted by this kind of attack.
 
That's not to say Pen Air FCU doesn't take cyber security seriously. We keep up-to-date with the latest in computer hardware and software to make sure our members are secure against illegal access. We also have to adapt to a world where everyone else doesn't follow those same values. That means we have to adjust our security protocols to cover for the failings of other parts of that big, messy system.

We're all in this together. The convenience of the modern economy makes things better for everybody. If you go on vacation, you don't have to fuss with traveler's checks or currency exchange troubles. You can take your debit card or credit card and spend just the same. Electronic record keeping helps financial institutions keep costs down and we all benefit from a growing economy. If we want to keep getting these benefits, we all need to put the work in to make sure our networks are secure. Here are five small tips to make your little corner of the Internet more secure.                                        
  1. Install updates for your computer, tablet, and mobile phone regularly.
  2. Don't open suspicious e-mails or questionable links.
  3. Don't install software you don't recognize.
  4. Monitor your financial statements closely to check for unauthorized activities.
  5. Get an anti-virus program and run it regularly.                      
If you follow these five steps, you can help make the Internet a safer place for people to share things they love and buy things they need. You can help make sure the big system of merchants, processors, and institutions keeps chugging along while providing benefits to everyone.