It's late January now and I haven't posted to SCVTalk in several weeks. For that I apologize, but I have a good excuse this time.
You see, almost night and day since the first week of January, I've been in a battle with identity thieves, and it's taking a toll on me. Thankfully, I've got my case mostly put together now and can sit back, survey the damage, and share this cautionary tale with you.
It's a tale that's probably repeating itself in millions of American homes, but my story begins at our local Target store, mostly the Creekside one but also likely the newer one way up Golden Valley Way.
You see, like most SCVers, I Thought SCV and hit up most of the major retail establishments in town after Black Friday and before Christmas. I especially shopped at Target because, well, who doesn't like Target, or Tar-jay as my mom calls it?
Since this was my first Christmas in a real suburban, detached, Single Family Home, I went all out and bought string after string of Christmas lights from Target. Blinking ones. Icicle styles, nets, strings, you name it! I went Tim the Tool Man Taylor on my home Christmas display and I totally geeked out on building a nice display so I could show it off to my boy.
Of course, little did I know that during those frantic, last-minute, gotta-finish-the-lights-before-dusk trips to Target in the weeks leading up to Christmas that all those card swipes at the checkout machine were being harvested by two Russian teenagers organized criminal group who the hell knows.
But my swipes -and apparently a whole lot more- were being harvested. And in short order, the thieves began chipping away at my finances.
January 9: Received a call at work from GE Capital Bank asking me to confirm some details about my application for a JC Penny credit card. Did I really live in Texas, GE Capital Bank asked. No I did not; this was fraudulent, I told them. I then quizzed the person on the phone for every piece of information about the applicant. Did he have my name? Social? DOB? Mother's Maiden Name? Yes to all those, the person told me. I was sufficiently spooked by this that I immediately issued a 90 day Fraud Alert with the three credit reporting agencies.
PS: GE Capital Bank is the banking corporation behind some 70 retail credit cards, including many that you are probably familiar with: Old Navy, Gap, Lowes, JC Penny, etc.
January 12: Sunday morning, hanging out with my boy and relaxing. Home phone rings and I answer. Another call from GE Capital Bank, this time for my wife. The woman on the other end of the phone (they call from Dayton Ohio) refuses to tell me anything so I hand the phone over to my wife.
It seems someone in Texas was able to call up GE Capital bank as my wife, report to the bank that they lost their Old Navy card, and get a replacement card sent -overnight- to Dallas Texas. GE Capital was simply confirming whether or not my wife 1) was in Texas and 2) had spent nearly $4,000 on the card since receiving it.
By now I'm in full state panic mode. Not only does someone have my essentials (For in America, social security + mother's maiden name + date of birth = keys to the kingdom), they have my wife's too. Not only that, they have both our addresses, including the one we've lived at for only two months.
So I insist on speaking with the GE Capital agent and we chat for a good half hour. I learn the following:
- The thieves couldn't identify my wife's mother's maiden name and thus failed GE Capital Bank's internal security tests
- Yet that didn't stop GE Capital from sending a replacement card; indeed, they changed Mother's Maiden Name to match my wife's married last name, Wilson.
Read that last part again. Let it sink in. The fraudsters failed the test, so the bank changed the rules of the test and let them pass go and collect ~$4,000.
But a larger question is this: How many times has your Mother's Maiden name changed?
I asked the woman on the phone the same question, and she was speechless. Why would someone's mother's maiden name change? I insisted.
During this phone call, the call waiting line beeped. Another call from Dayton. I ignored as I was in the process of getting escalated to a supervisor at GE Capital. (one hour later, I picked up the voice mail: another GE Capital Bank, another fraudulent card application, this time for Lowes under my name).
I dilligently recorded all the details I could get from the woman and supervisor I spoke with. Citing my own safety, GE Capital refused to give me any specifics about the Texas thieves who were attempting to impersonate me and my wife. I ended the call with a reminder that all names of the representatives I was speaking to would go into my affidavit which I planned to submit to law enforcement authorities in California and Texas.
January 15: Another notice, but his time at work. American Express sends me an email informing me that my replacement AmEx card (I'm an American Express fan and cardholder for 10+ years) is on its way overnight to Dallas Texas.
I call American Express as quickly as I can, inform them that this is a fraudelent request that didn't come to me, then spend 35 minutes on the phone grilling the helpful but ultimately useless guy on the other end as to how someone successfully impersonated me.
"Well sir, whoever this is has your social, your date of birth, your mother's maiden name, and current/former addresses. What do you expect?" is essentially how it went.
Sensing bullpoop, I ask him what's on file for my Mother's Maiden Name. He says he can't tell me. A strange game of cat 'n mouse commences in which I don't trust him and he doesn't trust me; ryhymes with _______ I hint; no he says.
Eventually I get him to confess that, again, whoever these thieves are, they've managed somehow to flunk telephone security tests and successfully changed my mother's maiden name to Wilson.
But no worries, the AmEx guy says. We've already canceled the card.
January 16: I receive a UPS email noting that my replacement AmEx card is set to arrive today in Dallas Texas. From the UPS tracking log, I get the thieves address. I call a PI in Dallas, ask him whether he'd stake out the address for me, snap photos of the perpetrators, and send me a report with photographs. He wants $60/hour for an unknown number of hours. I hesitate at the cost, and the card -hopefully canceled- gets delivered to a woman at 6:15pm central time.
January 20: Chase sends me a note. I have one Chase card I use for miscellaneous items. The email is preemptive, the bank is simply notifying me that my Chase card, along with my identity, was harvested in the Target retail theft of 2013. They're canceling my card and sending a new one.
Here's a few things I've learned from this process:
- The three credit agencies do report fraud flags to each other. But their assurances that a fraud flag will result in a cessation of credit card offers via US mail aren't true, or at least haven't become true yet
- It's truly frightening how easy it is to impersonate someone on the phone. I work in IT and have become a fan of dual factor authentication, which I use for my Google, Microsoft, and other accounts (pretty much any service provider who offers it, I use it). The way dual factor authentication works is this: knowing a password is only half the equation. If I try to login to Gmail from a computer I've never used before, Google won't let me in until I verify I'm actually Jeff Wilson by receiving a text message over SMS.
- There is no such thinking or even a concept of dual factor authentication over the phone. I asked all these banks if they had any beta programs or increased security programs for card holders; none of them did. GE Capital told me the steepest challenge they issue to callers is "What's your mother's maiden name?" Yet that's a meaningless test when their CSR offer to reset it to whatever the caller requests for it. And I'd argue changing a mother's maiden name on file is a fleetingly small possibility; I can't imagine why it's an option in the first place.
- Law Enforcement: Though I haven't completed the affidavit yet, I did call and talk to a Deputy at the SCV Sheriff's station who was very helpful and encouraged me to bring my case down to the Station or he could even arrange for a Deputy to visit me.
I'll be visiting the station this week with my case. I have phone numbers, addresses, property ownership records (Thanks Dallas County assessor's office!), notes from phone conversations, and more. My goal is to at least get a good copy of a law enforcement report outlining the ID theft against my wife and I, so that I can present it in the future.
Meanwhile, I'm left gawking at the simple security measures my UK colleague has to go through with his credit cards. Each credit card he has has some form of dual factor authentication: possessing the card is not enough. If he tries to swipe a credit card, he has to enter a pin. Stealing & replicating the magnetic signatures on his card wouldn't be enough either; the card has a special chip in it that's more difficult to imitate.
I guess American banks simply haven't lost enough money yet to implement a sane system like this. Until they do, know that even if you practice good security with your online accounts, it doesn't take much to impersonate you on the phone and, even worse, huge corporations like Target aren't able to safeguard your data.
Comments (10)