Not all fraud increases in an economic downturn
Red Bank, March 2 - There have been a number of recent articles outlining how the economic downturn will result in increased fraud, which I believe have inaccurately portrayed the real fraud risks in an economic downturn. I am currently compiling a definitive article on the topic for broader release (internal fraud, friendly fraud, first and third party fraud, organized fraud) but would offer some counter arguments for feedback to some of the assumptions and predictions that are being presented in the press today.
In a recent article from The Wall Street Journal entitled "Small Businesses Face More Fraud in Downturn" the author makes the case that in an economic downturn there is a higher incidence of employee fraud. This actually is not entirely true, while there may be more attempts, the number of successful fraud cases decreases. In terms of underwriting risk, employee or internal fraud is more likely in times of boom than in bust. Why? Because employers aren't typically paying as close attention to the books and as long as cash flow is good the focus is on closing business.
What we are seeing in the press is how these fraud cases tend to be more exposed in bust times. Consider the recent investment ponzi scams that have come to light with Madoff and Stanford, these are not fraud scams that were perpetrated in a bust economy, they happened in the boom, and came to light in the bust. In times of economic downturns businesses are sharpening their pencils and digging into costs, expenses and cash flow and this tends to uncover internal fraud that may have been overlooked.
In another article found on Security Watch and written by Fortify Software the author theorizes that online fraud will increase by 33% in 2009 because fraudsters are being impacted by the ongoing economic credit crunch and will be selling card data for less money. In short their premise is that the fraudsters in the card reselling segment are experiencing higher competition for card data and are having to push more inventory to get the same financial yield. They cite the economic recession for the reduction in average cost for a stolen identity(card, cvv and expriration date). These identities have dropped from $15.00 18 months ago to $2.00 last October. While I can understand making a correlation to increased fraud due to increased and cheaper supplies of card data, I don't really buy the idea that this correlates to the economic rescission. The card data reselling market has become competitive, and the availability of compromised data is high, which means there is higher supply than demand today. I am not an economist, but I would be more inclined to believe that price points on compromised cards are falling due to simple supply and demand over the idea that the downturn in the economy is hurting the sales of card resellers.
Showing posts with label internal fraud. Show all posts
Showing posts with label internal fraud. Show all posts
Thursday, March 19, 2009
Layoffs? Watch Out.
Don't learn the hard way about what a disgruntled employee is capable of doing.
Red Bank, Feb. 2/The FraudBlog Newsletter/- While it isn't easy to do layoffs and it is uncomfortable for most managers to perform; don't let your discomfort be the cause of a potential hack or malware attack from a disgruntled employee. As ZDNet's Larry Dignan reported, Fannie Mae almost learned the hard way what a disgruntled employee could do to a company. In this case a contractor, who had root access to their servers, was let go recently but his root level access was not removed. This individual planted malware that would have shut down all of their systems. The impact would have been enormous.
The following is not intended to be a complete list. It is a starting point for managers to start thinking about protecting their company's exposure in the sensitive area of payments and fraud. If you are letting people go that work in your payments and fraud departments you should consider:
Red Bank, Feb. 2/The FraudBlog Newsletter/- While it isn't easy to do layoffs and it is uncomfortable for most managers to perform; don't let your discomfort be the cause of a potential hack or malware attack from a disgruntled employee. As ZDNet's Larry Dignan reported, Fannie Mae almost learned the hard way what a disgruntled employee could do to a company. In this case a contractor, who had root access to their servers, was let go recently but his root level access was not removed. This individual planted malware that would have shut down all of their systems. The impact would have been enormous.
The following is not intended to be a complete list. It is a starting point for managers to start thinking about protecting their company's exposure in the sensitive area of payments and fraud. If you are letting people go that work in your payments and fraud departments you should consider:
(Prior to them being notified) - perform an access assessment of the individual:
- What access did they have to sensitive data?
- How much do they know about your fraud settings and controls?
- Are they aware of weak spots in your systems?
(When you notify them) -perform a formal notification:
- Remind them of confidentiality agreements and their obligations.
- Have them sign off on the access assessment.
- Shut off their access to any corporate systems that have sensitive data or are a part of payment processing.
(After they have left) - perform audits:
- Look at anything they may have accessed in the weeks leading up to their departure for signs of abuse, misuse or unauthorized access.
- In the event of a hack, malware attack or complaint of credit card data breach, you should perform a cursory review of these personnel as part of your investigation.
Labels:
internal fraud,
malware attack,
payments and fraud,
weak spots
When the Fraudster is Someone you Trust
Friendly fraud taken to new heights.
Red Bank, Aug. 15 2008/The FraudBlog Newsletter/- The number of articles related to internal fraud have been rising considerably over the past couple of months. If you are like most fraud managers, your focus has been on stopping the fraudster from coming in the door, and not paying attention to the fraudster lurking inside. It can be easy to overlook how easy it is for employees to copy down customer credit card information, to help a friend exploit a weakness in the companies systems or to directly steal from the company.
While I don't believe the individuals involved in these cases were criminals targeting these companies, I do believe they serve as a good example to putting in checks and balances to keep honest people honest...
To illustrate my point I have taken quotes from a recent case. These quotes were taken from the article "Former Sailor Gets 2 years for fraud with Navy Credit Card" by Austin Wright in the Virginia Post on August 10, 2008.
"I know that I'm a good person. I know that I made a bad decision," Gibbs said in court. "I'm aware of all my consequences.""Her supervisors encouraged this type of behavior," defense attorney David Price said in court. He elaborated after the sentencing that no one monitored what Gibbs and others were purchasing with the government-issued cards."For this to go on for as long as it did and for the amount of money that was involved - there's no excuse," Price said. "There are other people who didn't do their jobs right." Other cases in the news:
Customer Service Representative - An Alaska Airlines call center employee misused credit card data between August 2006 and June of 2008. When processing reservation changes, the employee allegedly diverted payments into her own personal bank account instead of the airline's. The fraud affects about 1,500 customers.
Receptionist - An Illinois Eye Center receptionist used patient information to obtain credit cards and then had the bills mailed to her home. Gast said the theft occurred from August until December of last year. Some of the victims didn't know their names had been used.
Mail Man - four counts of mail theft and one count of defrauding the U.S. Postal Service by using an agency credit card for personal use.
Administrative Assistant - charged more than $240,000 in personal expenses last year on a corporate credit card belonging to a pharmaceutical research and development company, a subsidiary of Johnson & Johnson. Federal prosecutors said she used the card to pay for a 1968 Ford Mustang and 1969 Chevrolet Camaro and to restore those vehicles. She also used company funds to pay for cosmetic surgery and a cruise vacation, a granite kitchen countertop, a residential air-conditioning unit and American Express gift cards..
Candidate for Sheriff - a candidate for the position of Navajo County sheriff, was arrested July 22 on charges of theft of a credit card and fraudulent use of a credit card, both felonies.
Bank Clerk - The clerk allegedly played a role in a conspiracy to embezzle funds from Sperry Marine Federal Credit Union by using other names to take out loans from the credit union.
Neighbor - Buellton California residents 47-year-old Karen Peterson and 49-year-old Debra Mangino are accused of stealing their one-time neighbor's mail and activating a credit card in his name.
Purchasing Agent - Navy sailor uses military credit card to steal hundreds of thousands of dollars from the government. Defense and prosecution lawyers agreed this could have been prevented through minimal oversight. From 2006 to 2007, she used the card to buy 162 notebook computers, 65 big-screen televisions and 22 digital cameras, items she and an unnamed co-conspirator sold for cash.
Father - A New York man says he used his son's Social Security number to obtain credit cards and loans from several banks, and from a firm that gave him loans to buy two cars. The crimes occurred between 1997 and 2005.
Credit Card Fraud Officer - A former senior Sussex Police officer who used his force credit card to buy goods for himself has been ordered to pay nearly £100,000. Sorority Sister - Danielle Sue All, 29, is believed to have charged more than $2,000 on a Purdue University sorority adviser's card reported missing Aug. 5.
Secret Service Informant - charged with breaking into the computer systems of nine of the nation's largest retail companies and stealing more than 40 million credit and debit card numbers.
Red Bank, Aug. 15 2008/The FraudBlog Newsletter/- The number of articles related to internal fraud have been rising considerably over the past couple of months. If you are like most fraud managers, your focus has been on stopping the fraudster from coming in the door, and not paying attention to the fraudster lurking inside. It can be easy to overlook how easy it is for employees to copy down customer credit card information, to help a friend exploit a weakness in the companies systems or to directly steal from the company.
While I don't believe the individuals involved in these cases were criminals targeting these companies, I do believe they serve as a good example to putting in checks and balances to keep honest people honest...
To illustrate my point I have taken quotes from a recent case. These quotes were taken from the article "Former Sailor Gets 2 years for fraud with Navy Credit Card" by Austin Wright in the Virginia Post on August 10, 2008.
"I know that I'm a good person. I know that I made a bad decision," Gibbs said in court. "I'm aware of all my consequences.""Her supervisors encouraged this type of behavior," defense attorney David Price said in court. He elaborated after the sentencing that no one monitored what Gibbs and others were purchasing with the government-issued cards."For this to go on for as long as it did and for the amount of money that was involved - there's no excuse," Price said. "There are other people who didn't do their jobs right." Other cases in the news:
Customer Service Representative - An Alaska Airlines call center employee misused credit card data between August 2006 and June of 2008. When processing reservation changes, the employee allegedly diverted payments into her own personal bank account instead of the airline's. The fraud affects about 1,500 customers.
Receptionist - An Illinois Eye Center receptionist used patient information to obtain credit cards and then had the bills mailed to her home. Gast said the theft occurred from August until December of last year. Some of the victims didn't know their names had been used.
Mail Man - four counts of mail theft and one count of defrauding the U.S. Postal Service by using an agency credit card for personal use.
Administrative Assistant - charged more than $240,000 in personal expenses last year on a corporate credit card belonging to a pharmaceutical research and development company, a subsidiary of Johnson & Johnson. Federal prosecutors said she used the card to pay for a 1968 Ford Mustang and 1969 Chevrolet Camaro and to restore those vehicles. She also used company funds to pay for cosmetic surgery and a cruise vacation, a granite kitchen countertop, a residential air-conditioning unit and American Express gift cards..
Candidate for Sheriff - a candidate for the position of Navajo County sheriff, was arrested July 22 on charges of theft of a credit card and fraudulent use of a credit card, both felonies.
Bank Clerk - The clerk allegedly played a role in a conspiracy to embezzle funds from Sperry Marine Federal Credit Union by using other names to take out loans from the credit union.
Neighbor - Buellton California residents 47-year-old Karen Peterson and 49-year-old Debra Mangino are accused of stealing their one-time neighbor's mail and activating a credit card in his name.
Purchasing Agent - Navy sailor uses military credit card to steal hundreds of thousands of dollars from the government. Defense and prosecution lawyers agreed this could have been prevented through minimal oversight. From 2006 to 2007, she used the card to buy 162 notebook computers, 65 big-screen televisions and 22 digital cameras, items she and an unnamed co-conspirator sold for cash.
Father - A New York man says he used his son's Social Security number to obtain credit cards and loans from several banks, and from a firm that gave him loans to buy two cars. The crimes occurred between 1997 and 2005.
Credit Card Fraud Officer - A former senior Sussex Police officer who used his force credit card to buy goods for himself has been ordered to pay nearly £100,000. Sorority Sister - Danielle Sue All, 29, is believed to have charged more than $2,000 on a Purdue University sorority adviser's card reported missing Aug. 5.
Secret Service Informant - charged with breaking into the computer systems of nine of the nation's largest retail companies and stealing more than 40 million credit and debit card numbers.
Labels:
Credit Card Fraud,
Fraudsters,
internal fraud
Subscribe to:
Posts (Atom)
