Over the past couple of years there has been an average of 15 million or more people attacked by an ID theft or fraud event in the United States. Last year, the average cost to individuals facing these events had DOUBLED from 2017 to 2018. Yet, are consumers doing enough to protect themselves as their vulnerability to these events grows from the endless avalanche of data breaches?
Our society has created great ways to deal with other personal dangers like car accidents, heart attacks, and home fires. We willingly spend thousands of dollars per year to have protective services & insurance in place, just in case these calamities might occur in our lives.
Interestingly, we are much more likely to experience an ID theft or fraud event than many other common catastrophes:
The FTC reports that 64% of Americans have had their data compromised from a data breach and 31.7% of these breach victims end up having an ID theft or fraud event happen to them. This number has continued to increase over the years despite the availability of so many ID theft companies offering protective services. Jon Iannarelli, a retired FBI Special Agent and well-known presenter on cybersecurity has stated, “Nearly every company will experience a data breach. It’s no longer a question of if it’s going to happen, it’s when.” And, as quoted years ago by Mark Pribish, a recognized ID theft and data breach expert, this simple fact remains: “no company or service can ever guarantee an individual will not become a victim of an ID theft event.” With the number and magnitude of data breaches happening over the past several years (i.e. Equifax, Uber, US Government, Marriott, etc.) it is nearly certain that the majority of consumers, your credit union members, will become a victim of ID theft or a fraud event. Add to this, the most recent data breach by Capital One, affecting 100 million consumers, and it is clear that some kind of member ID protection service needs to be considered.
Just like a heart attack, car accident or natural disaster, there are steps that individuals can take to lessen the likelihood of becoming a victim, but there are no fail-proof ways of completing avoiding the occurrence. This is why consumers have medical, auto and homeowners insurance - to help them financially recover in the event of such misfortunate happenings. And, this is why it’s imperative that consumers have similar recovery protection from ID theft and other fraud events.
So, credit unions have an opportunity to ramp up their focus on this growing problem and distinguish themselves by how they protect their members. Credit unions should pursue programs & services that are available to provide much needed awareness & education to members about the growing dangers they face. And there are services available that can provide invaluable safety nets of protection for members with incredible value propositions.
Imagine being able to bring your members full recovery and restoration services for any kind of ID theft or fraud at rates as low as $4 or $5 per month, which would also include all forms of monitoring. In sharp contrast to what they pay for auto insurance or homeowners insurance, this is an unparalleled value that will further engage members and solidify their loyalty to your credit union.
The value of your members protecting their identities should be far greater than many other things that they gladly pay a higher monthly cost for, such as Netflix, Amazon Prime and ATM Fees outside of the credit union and CO-OP network. A little education and awareness makes this clear to members and allows the credit union, who they trust, a means to now protect their members from the fast growing dangers associated with an identity theft or fraud event…affording them true peace of mind.
*Insurance Information Institution
**Bloom, Ester. CNBC; “Here’s How Much the Average American Spends on Healthcare”
Federal Trade Commission Consumer Sentinel Network Data Book 2018
Republished from CCUL's CU Weekly dated September 10, 2018. By James McCabe.
Synthetic identity theft is a growing threat to credit unions—costing financial institutions billions of dollars. It’s a type of fraud in which a criminal uses fake information, sometimes combined with real (usually stolen) data, to create a fictitious identity. This made-up identity is used to open fraudulent accounts and make fraudulent purchases.
Credit unions and other financial institutions often fall prey to synthetic identity theft since much of the information criminals provide them with is legitimate. Synthetic identity theft allows the criminal to steal from lenders by opening credit card, auto loan and other accounts. In January, Accenture PLC listed synthetic-identity fraud as one of the biggest threats facing financial institutions in 2018.
Synthetic identity theft may account for five percent of uncollected debt and up to 20 percent of credit losses, or $6 billion in 2016, according to some industry analysts. The problem is even more acute with auto loans. TransUnion says a record $355 million in outstanding credit-card balances was owed by people who it suspects didn’t exist in 2017, up more than 8x from 2012.
Synthetic identity fraud exploits a weakness in America’s consumer-credit system. Lenders often consider a loan applicant legitimate if the applicant has a credit report at one of the three credit bureaus. But a new “credit file”—essentially a precursor to a credit report—often gets created when someone simply applies, even if the loan gets denied. If one lender approves a loan for the fictitious individual, that information can make the file a full-fledged credit report.
How a “Phantom Borrower” is Born:
One of the reasons that more criminals are using the synthetic identity scam is because lenders have gotten better at protecting against traditional identity theft, which often involves using stolen data about real consumers. When bypassing actual consumers, scammers send fewer “red flags.”
While individuals probably won’t get a high-spending-limit card or large loan without a repayment history, some identity scammers pay bills promptly to qualify for higher limits, then default on larger loans or when credit card has been “maxed out”. It then costs financial institutions a myriad of hours to track down individuals who don’t exist.
Fortunately for lenders, synthetic identity fraud detection and prevention strategies have evolved, as well. Digital technology, neural networks and predictive analytics powered by machine learning and artificial intelligence are helping to more quickly scan large databases like those generated by data-furnishing front companies.
Protecting Your Credit Union from Synthetic ID Theft
Synthetic identity can cost a credit union thousands of dollars and numerous unrecoverable hours. Protecting your credit union from synthetic identity requires strong security and recovery programs.
Having greater cybersecurity preparedness needs to be the top priority for credit unions. This will help credit unions avoid becoming victims of synthetic identity fraud, as well as will create the basis for the ultimate response to any data breach or identity theft when it happens. Strong cybersecurity preparedness isn’t cheap, so credit unions must search and find solutions that also generates new income streams while delivering cybersecurity preparedness.
Source: "The New ID Theft: Thousands of Credit Applicants Who Don’t Exist” WSJ, 6 March. 2018.
Despite a heightened understanding and awareness of the importance of strong cyber security by everyone, the trend of data breach attacks continues to increase - impacting thousands of businesses and millions of individuals. Last year, there was a 40% increase over 2015 in the number of businesses that were impacted by data breaches. Businesses of all sizes were hacked by criminals that used techniques such as ransomware and non-malware attacks to steal data.
No organization is safe from a data breach. It’s no longer a question of “if”, but “when” a business will have its data compromised…per retired FBI special agent
Over the last five years, data breaches have recurrently made headline news as large businesses such as; Yahoo, Target, Home Depot, Dropbox, Ebay, JP Morgan Chase, Anthem and Living Social, were hit by hackers. Thousands of credit union cardholder members were impacted by these hacks. Yahoo’s 2013 and 2014 hacks took 2-3 years to discover; allowing the criminals and black market even more time to devastate the victims’ identities. Most recently, restaurant chain Arby’s was hacked by malware that affected 1,000 restaurants and even more credit union members – very much like Wendy’s ’16 breach.
Although there are steps that organizations can take to help make themselves less vulnerable to a data breach, it is impossible for any organization to guarantee it won’t happen.
Nearly two-thirds of Americans (64%) have personally been victims of data breaches. And 65% of US Consumers are terrified of experiencing an ID theft.
According to Pew Research Center’s most recent survey:
To make matters worse, coinciding with the rise of data breach victims, there is now the new threat of Civil and Class-Action Lawsuits facing the businesses from these victims – driving new legal and settlement costs.
The aftermath of big company data breaches is almost always characterized by class-action lawsuits. While not every litigation makes its way to the public eye, it is becoming more and more common for organizations of all sizes to face a civil or class-action lawsuit after a data breach. The best way that credit unions and other organizations can protect themselves against litigation is to have a trusted Fully Managed Recovery System in place, such as Vero's IDProSelect.
The majority of Americans expect cyberattack on the nation’s banking and financial systems.
Many Americans lack confidence that various public and private institutions will be able to protect their personal information from bad elements. While Americans often first turn to their financial institution after finding out that they’ve been a victim of a data breach, the majority of them also fear that a major cyberattack will occur on the nation’s banking and financial systems within the next five years. Organizations that have implemented a Fully Managed Recovery System often have clients and members that have greater peace-of-mind.
Having programs in place for cyber security and data breach response is no longer just an option for credit unions. For the second year in a row, the NCUA’s Supervisory Priorities have mandated that credit unions have a plan for 1) cyber security 2) member response and 3) fraud prevention. Vero’s IDProSelect helps credit unions address these areas of NCUA's 2017 Supervisory Priorities.
For more information on how your organization can protect itself from the ramifications of a data breach or to receive more information on Vero’s IDProSelect, please contact Jim McCabe at email@example.com or call (480) 748-0403.
This is the time of year when criminals are most actively plotting and scheming, and credit union members are exposed and vulnerable. Tax scammers are preying on members’ social security numbers for tax-related identity theft and other crimes. In fact, nearly 50% of identity thefts are a result of unauthorized government documents, which include tax filings.
Tax season may just be starting, but these scammers have been hard at work. They’re waiting for an opportunity to steal members’ personal information for fraudulent tax refunds and other transactions. Members that become victims of tax-related identity theft become a high target for other identity crimes since hackers use their same information to sell to the black market, get loans and impersonate the victims in a multitude of other matters.
Being a victim of a tax crime can be a harrowing experience for members. The resolution process with the IRS often takes between 12-24 months. During this time and after, members’ personal information may be used for other crimes. Once the tax-related case has been resolved, IRS will employ measures to help ensure that members’ tax accounts are not compromised again. However, this does not fully protect your members from being victims of other forms of identity theft.
While the tax community must stay on top of security systems to protect taxpaying individuals and their businesses, financial institutions are also being counted on to protect their account holders’ identities and financial account information. Credit unions that offer identity theft recovery and restoration services are best equipped to do this. Victimized members that have been provided with identity theft recovery protection by their credit union can recover and protect their exposed identities easier and more quickly than those that do not have any identity recovery protection. For example, members that are covered by Vero’s IDProSelect through their credit union, are assigned a personal advocate immediately upon confirmation or suspect of any form of identity theft. When members become notified that their social security number has been compromised for tax-related theft, they need only to contact their ID theft advocate, who will handle all resolution steps for the member, as well as will have communication with the member throughout the entire process.
Credit unions should advise their members to:
February 2016 Federal Trade Commission Consumer Sentinel Report