Now Available:

line

Featured Resources:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Rebecca.

« Medical Identity Theft Is On The Rise | Main | GSW Logo »

Sloppy Disposal Aids Cybercriminals

For day 3 of Global Security Week I want to talk a little bit about the importance of securely disposing of your papers and storage media that contains personal information...

Cybercriminals love to do high-tech crime using very low-tech methods, such as digging personally identifiable information (PII) from your trash, and the trash of businesses. They get all sorts of confidential information from papers, statements, and also diskettes, USB drives, computers, cell phones and any other type of item that can be used to store information. The FTC and other studies show that stealing PII from the trash is the number one way that criminals get the PII they use to commit cybercrime, identity theft, fraud, and assorted other bad things.

Almost every morning when I check the news I find reports about PII being thrown into trash bins and other places, not only by people at their homes, but also by businesses. This morning was no exception. Here are just a couple of reports I found...

* From Detroit Channel 20, a report, "ID Theft Targets Kids"

* Police reports are always interesting, and point to disposal problems. Here are some excerpts from the Frisco, Texas, Police Department:

"Known subject took two trash bags containing documents to be shredded from victim's open garage at 12000 block of Verona Court."

And here are some other examples, all from the same little town, of people using others' credit cards, checks, debit cards, etc., which could be related to them using information found in trash...

"Unknown person(s) obtained a copy of victim's checks and forged signature at 16000 block of Buffalo Creek Drive." "Unknown person(s) removed a box of checks without consent at 11000 block of Sonterra Lane." "Victim stated that unknown person used his credit card number without permission at 3000 block of Preston Road." "Unknown person used victim's debit card to make purchases without consent at 8000 block of Stonebrook Parkway." "Unknown subject(s) used victim's credit card to make purchases without consent at 10000 block of Preston Vineyard Drive." "Unknown actor used victim's identifying information to open an account with a phone company at 8000 block of Brookview Drive." "Unknown subject(s) obtained the victim's credit card number and purchased several items without consent at 9000 block of Legacy Drive." "Unknown person(s) used victim's personal information without permission at 7000 block of Preston Road." "Known person made unauthorized charges on victim's credit card at 8000 block of Main Street." "Known person made unauthorized charges on a credit card at 8000 block of Preston Road." "Known person made unauthorized charges on a credit card at 9000 block of Dogwood Street." "Known subject used credit card to make an unauthorized purchase at 3000 block of Preston Road." "Unknown suspect used victim's credit card online to make five purchases totaling $1,174.45 at 11000 block of Dorchester Lane."


Here's just one of the articles I've written about securely disposing of information: "Don't Throw Away Privacy!"

If your business handles your customer information, and you are located in the U.S., chances are you must follow the FACTA Disposal Rule.


Here's some good information from the FTC about the FACTA Disposal Rule.

Here are a couple more good sources of information about information disposal:

* A TechTarget article from a few years ago still has good advice, "Talking trash: Secure information disposal"

* A very interesting and informative article about information disposal, "Getting Rid of the Evidence: Information Disposal"

Are you disposing of your personal information securely?

Is your business?

How about the businesses with whom you share your PII? Be sure to ask them! It would be interesting to hear what they say, wouldn't it?

BTW, for those of you who have asked me...no I did not get my dumpster diving research activity done with my sons this summer due to multiple unplanned events (floods, tornadoes, other unfortunate incidents). However, this is something I *DO* still plan to do! Perhaps this would be a good school project for my sons as well.

TrackBack

TrackBack URL for this entry:
http://www.realtime-itcompliance.com/type/mt-tb.cgi/806

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Rebecca Herold's Bio:

Rebecca Herold,CISSP, CIPP, CISM, CISA, FLMI, has been providing information security, privacy and regulatory assistance and services to organizations from a wide range of industries for over 18 years. Rebecca was instrumental in building the information security and privacy program while at Principal Financial Group, which was awarded the CSI Information Security Program of the Year Award in 1998. IT Security ranked Rebecca as one of the top 59 IT security influencers, and Computerworld put Rebecca their list of the 25 top privacy experts and on their list of the 9 best privacy consulting firms. Rebecca has been CPO for two consulting organizations, and has had her own information privacy, security and compliance business since 2004. Rebecca has written chapters for several books, dozens of articles, and has been writing a monthly privacy column for the CSI Alert newsletter since the beginning of 2001, and is working on her 11th book. Some of her other books include The Privacy Papers, Managing an Information Security and Privacy Awareness and Training Program, The Definitive Guide to Security Inside the Perimeter (Realtime Publishers), The Shortcut Guide to Improving IT Service Support through ITIL (Realtime Publishers), and The Practical Guide to HIPAA Privacy and Security Compliance. In addition, Rebecca is the leader of The Realtime IT Compliance Community where she posts to her IT Compliance weblog. You can contact Rebecca at: rebecca_herold@realtimepublishers.net.