Saturday, October 10, 2009

Canadians need to take control of their online personal information




Privacy Commissioner of Canada's annual report focuses on importance of making informed choices about sharing personal information online.


OTTAWA, Oct. 10 /Canada NewsWire Telbec/ - As more and more Canadians live their lives online, the Privacy Commissioner is cautioning them to take greater responsibility for securing their privacy and thinking twice about what they post on the Internet.

"Many young people are choosing to open their lives in ways their parents would have thought impossible and their grandparents unthinkable. Their lives play out on a public stage of their own design as they strive for visibility, connectedness and knowledge," says Jennifer Stoddart, the Privacy Commissioner of Canada.

"Such openness can lead to greater creativity, literacy, networking and social engagement. But putting so much of their personal information out into the open can also...leave an enduring trail of embarrassing moments that could haunt them in future," the Commissioner says in her annual report to Parliament, which was tabled today.

The Commissioner's 2008 Annual Report to Parliament on the Personal Information Protection and Electronic Documents Act (PIPEDA) highlights the issue of youth privacy. It also looks at 2008 privacy complaint investigations; technology and privacy issues; and the Commissioner's efforts to encourage the development of international privacy standards.

Commissioner Stoddart noted that many people have been fired, missed out on job interviews and academic opportunities, and been suspended from school for instant messages, wall posts and other types of online correspondence they mistakenly thought were private conversations with friends.

There is also a risk that unguarded personal information could be exploited by identity thieves.

The Office of the Privacy Commissioner recently completed an investigation into the privacy policies and practices of the popular social networking site Facebook. While that investigation focused on Facebook's obligations under Canadian privacy law, the Commissioner emphasized at the time that, with nearly 12 million Canadians on Facebook, it's also important for users to adopt the appropriate privacy settings and to understand how their personal information may be used or shared online.

The Privacy Commissioner's Office has made online youth privacy a key priority, using contests, communications materials and a dedicated youth privacy website to reach out to young people and to encourage them to reflect on privacy issues and to "Think Before You Click."

"As Canada's privacy guardian, it is our role to create awareness of privacy risks, show people how to address those risks, and make it easy for them to make informed decisions," says Commissioner Stoddart.

Adds Assistant Commissioner Elizabeth Denham: "We're not suggesting the clock be turned back; we just want to ensure Canadians have the information they need to make more privacy-conscious decisions."

The annual report, available on the OPC website at www.priv.gc.ca, includes details of complaints received and investigated by the Office in 2008.

The OPC received 422 new PIPEDA-related complaints for investigation in 2008, ending a downward trend that had lasted for several years. In 2007, there had been 350 complaints, fewer than half the 723 received in 2004.


The Privacy Commissioner of Canada is mandated by Parliament to act as an ombudsman, advocate and guardian of privacy and the protection of personal information rights of Canadians

Sunday, September 13, 2009

Do You Know Where Emails Are Coming From?




Just because an email says it’s from customerservice@yourbank.com, how can you be sure? One of the basic necessities of phishing attacks is an identity thief’s ability to convincingly pretend to be someone else. The core of phishing is impersonation. Identity thieves pretend to be legitimate businesses, organizations, or government agencies when they ask for your personal information. They copy the Web sites of those they are impersonating to trick you into providing your information on the sites. And once they have your information, they impersonate you to gain access to your accounts and create new accounts in your name. Authentication – getting proof that someone is who they claim to be – is key in fighting the battle against phishing.

Many phishing attempts start with an email message that pretends to be from a trusted source, such as a bank or an online merchant. Phishers have figured out ways to make it look like an email comes from a certain email address, when that actually isn’t the case. It may be impossible to tell just by looking at the “From” line in the message whether the sender truly is who it claims to be. So, what’s a consumer to do?

For detailed informationabout what to do visit our Cybersecurty for Seniors website.

Monday, September 7, 2009

Fraud Afoot



Seems like everyone has become the recipient of mysterious e-mails promising untold wealth if only one helps a wealthy foreigner quietly move millions of dollars out of his country. The venerable Nigerian Scam has discovered the goldmine that is the Internet. Beware — there's still no such thing as "something for nothing," and the contents of your bank account will end up with these wily foreigners if you fall in with this.

Likewise, look out for mailings announcing you've won a foreign lottery you don't recall entering or claiming that because you share the surname of a wealthy person who died without leaving a will you're in line for a windfall inheritance.

And be especially wary if, while trying to sell or rent anything online (car, boat, horse, motorcycle, painting, apartment, you name it) you're approached by a prospective buyer/renter who wants to pay with a cashier check made out for an amount in excess of the agreed-upon price and who asks the balance be sent to a third party.

Aspiring work-at-homers promised big bucks for acting as intermediaries for international transactions wherein they cash checks for other parties or reship goods to them have been defrauded by con artists. Don't you be next.

If someone calls to announce you've failed to appear for jury duty and will be arrested, do not give the caller your personal and financial information in an effort to prove he's sending the gendarmes after the wrong guy. You're being tricked into giving up this information to an identity thief.

 


Sunday, August 23, 2009

AUTO NEUROTIC:




from This Is True.com

Coggin Pontiac, a car dealer in Jacksonville, Fla., was a
bit suspicious of a check that a woman wrote for a new $70,000 car --
the check identified the account holders as "Mr. and Mrs. Jesus and
Emma Christ". The dealer called the woman's bank, which said the check
was not valid, so their next call was to the Jacksonville Sheriff's
Office. Deputies found Emma Kim-Tashis Harrison, 25, had multiple
credit cards in her purse, some in her name, and others bearing the
name Emma Christ. She insisted she had the money to back the check,
since she owns "a traveling Web site that people just deposit money
into." Deputies arrested her on felony fraud charges. (Jacksonville
Times-Union) ...It's unclear which is crazier: that anyone would "just
deposit money" into her web site, or that anyone would want a $70,000
Pontiac.

Saturday, August 22, 2009

How Do Thieves Steal Your Identity?





from AOL Wallet Pop

First, they steal your personal information by...

...Going through your mail or trash, looking for bank and credit card statements, pre-approved credit offers, and tax information.
...Stealing personal information from your wallet or purse such as identification, credit, or bank cards.
...Completing change-of-address forms to redirect your mail.
...Obtaining your credit report by posing as someone who has a lawful right to the information.
...Acquiring personal information you share on unsecured sites on the Internet.
...Buying personal information about you from an inside source -- for example, a store employee that gets your information from a credit application or by "skimming" your credit card information when you make a purchase.
...Getting your personnel records at work.
Then identity thieves...

...Open new credit card accounts using your name, date of birth, and Social Insurance Number. When they use the credit cards and don't pay the bills, the delinquency is reported on your credit report.
...Establish phone or cellular service in your name.
...Open a bank account in your name and write bad cheques on the account.
...Counterfeit cheques or debit cards, and drain your bank account.
...Buy cars by taking out auto loans in your name.
...Call your credit card issuer and, pretending to be you, change the address on the account. Bills get sent to the new address, so you don't realize there's a problem until you check your credit report or get a call from a collection agency.
...File for bankruptcy using your name to avoid paying debts they've incurred under your name.

Saturday, August 15, 2009

Twishing: Beware of the Latest ID Scam



This tricky combination of Phishing and Twitter Uses Common Scam Techniques to steal your identity.
By Rob Douglas, August 14, 2009 from Webopedia

Every time a new communication method becomes popular, fraudsters look for a new way to commit identity theft. One of the latest popular scams is "twishing."

Twishing is a combination of Twitter and phishing, uses the growing popularity of the microblogging service Twitter.com in an attempt to steal your identity.

Twitter, which limits users to 140-character messages broadcast to the public or directly to "followers" who have chosen to receive the updates, is one of the latest identity fraud schemes because it is growing so quickly in popularity due to the message length limitations.

Fraudsters jump on new communication methods because law enforcement is slow to respond and communications providers often will rush out new technology without thoroughly testing potential security flaws.

Security flaws enable hackers to gain access to accounts, but such thefts require some technical knowledge. It’s much easier to lure someone (the idea of fishing lures gave rise to the term "phishing") to reveal private information than to hack into their account.

The idea of luring someone to reveal private information is nothing new. Famous check scam artist Frank Abagnale, subject of the movie "Catch Me If You Can", used clothing (e.g., dressing like a pilot) to lure people to give him sensitive information. While the movie was based on facts, a fictional television program, "The Rockford Files" also featured the lead character using fake business cards and smooth talk to obtain information.

Twishing works the same way. A short public message like “see what they're saying about you on xyzblog" followed by a link can direct the unwitting Twitter user to a blog that looks like Twitter, but is actually a site operated by the fraudster, who then seeks to gain personal information. Twitter recently changed its look, which will likely deter twishing for at least a while. But fraudsters are always looking for the next scam.

This is very similar to fraudsters who misrepresent themselves as being from a large financial institution while sending out millions of official e-mails trying to trick legitimate account holders into revealing personal account information. While most of these e-mails will go to people who have no banking relationship with the financial institution, the phishing e-mail will reach some legitimate account holders. The e-mail will ask account holders to resend their account information – often with the threat of suspending the account if they don’t.

Some of the telltale signs that a phishing e-mail is a fraud are typos, poor grammar or incomplete information in the phishing message. But the message limitations of Twitter make it easy to overlook such details. Twitter users will use chat and text message abbreviations (e.g., “u" for “you") and grammatical rules are largely ignored. So the hints aren’t as obvious.

However, some of the basic steps to protect one’s identity work to protect against twishing just as they do against phishing:

Don’t provide personal information online

If a message looks suspicious, it probably is

Be cautious in opening “retweeted" items. The last sender may not be aware of the malicious nature of the message.

Sunday, August 9, 2009

Tips To Beat the Scammers



Beat the scammers in 2009! If that was not among your New Year's resolutions, maybe you should think seriously about adding it. Because all the signs are that the scammers are planning a BIG year in 2009.

They know the economy is in trouble and that we're all looking for ways to save, earn extra cash or help those less fortunate than ourselves. And that's all prime territory for crooks planning to hoodwink us into parting with our money.

Plus, more people down on their luck will mean more people tempted to try their hand at scamming.

And please don't think that if you're one of the lucky few who've never been targeted for a scam that you're immune to these tricksters. Sooner or later you'll encounter them -- in your mailbox, your email inbox, on the phone or face to face.

OK, that's enough gloom. We want you to be able to celebrate 2009, so we've put together some tips to help you beat the scammers.

Tip #1. Be very skeptical -- and trust almost no one

That's right, we say trust almost no one. That's because even people we think we know, including family and friends, may have innocently been tricked into becoming part of a scam.

They may pass on investment "advice" from someone they know. Or their identity may have been stolen so what you think is coming from them -- an email for instance -- is really from someone else.

A good example of exploiting our trust is the grandparent scam, where a victim gets a phone call supposedly from a desperate grandchild asking for money.

Thousands of people have been fooled into wiring hundreds or thousands of dollars to the scammer. You can find more on the grandparents scam on our website Cyber Security for Seniors.

Another good example is identity theft. As we've previously reported, fully 50% of reported identity theft is perpetrated by relatives, friends and neighbors, or acquaintances of the victim!

That's why we encourage you to be skeptical. Always ask yourself: What if this isn't what it appears to be? What steps can I take to check it out and confirm it?

Here are the main keys to being a healthy skeptic:

Don't believe sob stories from people you don't know. The vast majority of them are untrue.

Don't believe someone is who they say they are unless they can 100% prove it.

Don't believe you've won, inherited or otherwise gained a huge sum of money from a source you didn't previously know.

Which brings us to our favorite, which we never tire of repeating: Whether it's a miracle cure, a fantastic bargain or incredible luck, if it seems too good to be true, it almost certainly is.

When you do buy, never wire money via Western Union, never deposit a check and return a portion of money sent to you which is an overpayment, and whenever possible, pay by credit card (especially one-use credit cards if they are offered by your credit card company).

More tips to come...