SCV Talk · Archive
Nine years of the Valley’s town square · 2006–2015
SCV Talk
January 27, 2014· santaclarita.com · SantaClarita.com (SCVTalk 5.0) · Wayback capture

Who wants to be Jeff Wilson? Apparently lots of people

It's late January now and I haven't posted to SCVTalk in several weeks. For that I apologize, but I have a good excuse this time. 

You see, almost night and day since the first week of January, I've been in a battle with identity thieves, and it's taking a toll on me. Thankfully, I've got my case mostly put together now and can sit back, survey the damage, and share this cautionary tale with you.

It's a tale that's probably repeating itself in millions of American homes, but my story begins at our local Target store, mostly the Creekside one but also likely the newer one way up Golden Valley Way.

You see, like most SCVers, I Thought SCV and hit up most of the major retail establishments in town after Black Friday and before Christmas. I especially shopped at Target because, well, who doesn't like Target, or Tar-jay as my mom calls it? 

Since this was my first Christmas in a real suburban, detached, Single Family Home, I went all out and bought string after string of Christmas lights from Target. Blinking ones. Icicle styles, nets, strings, you name it! I went Tim the Tool Man Taylor on my home Christmas display and I totally geeked out on building a nice display so I could show it off to my boy. 

Of course, little did I know that during those frantic, last-minute, gotta-finish-the-lights-before-dusk trips to Target in the weeks leading up to Christmas that all those card swipes at the checkout machine were being harvested by two Russian teenagers organized criminal group who the hell knows. 

But my swipes -and apparently a whole lot more- were being harvested. And in short order, the thieves began chipping away at my finances.

January 9: Received a call at work from GE Capital Bank asking me to confirm some details about my application for a JC Penny credit card. Did I really live in Texas, GE Capital Bank asked. No I did not; this was fraudulent, I told them. I then quizzed the person on the phone for every piece of information about the applicant. Did he have my name? Social? DOB? Mother's Maiden Name? Yes to all those, the person told me. I was sufficiently spooked by this that I immediately issued a 90 day Fraud Alert with the three credit reporting agencies. 

PS: GE Capital Bank is the banking corporation behind some 70 retail credit cards, including many that you are probably familiar with: Old Navy, Gap, Lowes, JC Penny, etc. 

January 12: Sunday morning, hanging out with my boy and relaxing. Home phone rings and I answer. Another call from GE Capital Bank, this time for my wife. The woman on the other end of the phone (they call from Dayton Ohio) refuses to tell me anything so I hand the phone over to my wife. 

It seems someone in Texas was able to call up GE Capital bank as my wife, report to the bank that they lost their Old Navy card, and get a replacement card sent -overnight- to Dallas Texas. GE Capital was simply confirming whether or not my wife 1) was in Texas and 2) had spent nearly $4,000 on the card since receiving it. 

By now I'm in full state panic mode. Not only does someone have my essentials (For in America, social security + mother's maiden name + date of birth = keys to the kingdom), they have my wife's too. Not only that, they have both our addresses, including the one we've lived at for only two months. 

So I insist on speaking with the GE Capital agent and we chat for a good half hour. I learn the following:

  • The thieves couldn't identify my wife's mother's maiden name and thus failed GE Capital Bank's internal security tests
  • Yet that didn't stop GE Capital from sending a replacement card; indeed, they changed Mother's Maiden Name to match my wife's married last name, Wilson. 

Read that last part again. Let it sink in. The fraudsters failed the test, so the bank changed the rules of the test and let them pass go and collect ~$4,000. 

But a larger question is this: How many times has your Mother's Maiden name changed? 

I asked the woman on the phone the same question, and she was speechless. Why would someone's mother's maiden name change? I insisted. 

During this phone call, the call waiting line beeped. Another call from Dayton. I ignored as I was in the process of getting escalated to a supervisor at GE Capital. (one hour later, I picked up the voice mail: another GE Capital Bank, another fraudulent card application, this time for Lowes under my name). 

I dilligently recorded all the details I could get from the woman and supervisor I spoke with. Citing my own safety, GE Capital refused to give me any specifics about the Texas thieves who were attempting to impersonate me and my wife. I ended the call with a reminder that all names of the representatives I was speaking to would go into my affidavit which I planned to submit to law enforcement authorities in California and Texas. 

January 15: Another notice, but his time at work. American Express sends me an email informing me that my replacement AmEx card (I'm an American Express fan and cardholder for 10+ years) is on its way overnight to Dallas Texas. 

I call American Express as quickly as I can, inform them that this is a fraudelent request that didn't come to me, then spend 35 minutes on the phone grilling the helpful but ultimately useless guy on the other end as to how someone successfully impersonated me. 

"Well sir, whoever this is has your social, your date of birth, your mother's maiden name, and current/former addresses. What do you expect?" is essentially how it went. 

Sensing bullpoop, I ask him what's on file for my Mother's Maiden Name. He says he can't tell me. A strange game of cat 'n mouse commences in which I don't trust him and he doesn't trust me; ryhymes with _______ I hint; no he says. 

Eventually I get him to confess that, again, whoever these thieves are, they've managed somehow to flunk telephone security tests and successfully changed my mother's maiden name to Wilson. 

But no worries, the AmEx guy says. We've already canceled the card. 

January 16: I receive a UPS email noting that my replacement AmEx card is set to arrive today in Dallas Texas. From the UPS tracking log, I get the thieves address. I call a PI in Dallas, ask him whether he'd stake out the address for me, snap photos of the perpetrators, and send me a report with photographs. He wants $60/hour for an unknown number of hours. I hesitate at the cost, and the card -hopefully canceled- gets delivered to a woman at 6:15pm central time. 

January 20: Chase sends me a note. I have one Chase card I use for miscellaneous items. The email is preemptive, the bank is simply notifying me that my Chase card, along with my identity, was harvested in the Target retail theft of 2013. They're canceling my card and sending a new one. 

Here's a few things I've learned from this process:

  • The three credit agencies do report fraud flags to each other. But their assurances that a fraud flag will result in a cessation of credit card offers via US mail aren't true, or at least haven't become true yet
  • It's truly frightening how easy it is to impersonate someone on the phone. I work in IT and have become a fan of dual factor authentication, which I use for my Google, Microsoft, and other accounts (pretty much any service provider who offers it, I use it). The way dual factor authentication works is this: knowing a password is only half the equation. If I try to login to Gmail from a computer I've never used before, Google won't let me in until I verify I'm actually Jeff Wilson by receiving a text message over SMS. 
  • There is no such thinking or even a concept of dual factor authentication over the phone. I asked all these banks if they had any beta programs or increased security programs for card holders; none of them did. GE Capital told me the steepest challenge they issue to callers is "What's your mother's maiden name?" Yet that's a meaningless test when their CSR offer to reset it to whatever the caller requests for it. And I'd argue changing a mother's maiden name on file is a fleetingly small possibility; I can't imagine why it's an option in the first place. 
  • Law Enforcement: Though I haven't completed the affidavit yet, I did call and talk to a Deputy at the SCV Sheriff's station who was very helpful and encouraged me to bring my case down to the Station or he could even arrange for a Deputy to visit me. 

I'll be visiting the station this week with my case. I have phone numbers, addresses, property ownership records (Thanks Dallas County assessor's office!), notes from phone conversations, and more. My goal is to at least get a good copy of a law enforcement report outlining the ID theft against my wife and I, so that I can present it in the future. 

Meanwhile, I'm left gawking at the simple security measures my UK colleague has to go through with his credit cards. Each credit card he has has some form of dual factor authentication: possessing the card is not enough. If he tries to swipe a credit card, he has to enter a pin. Stealing & replicating the magnetic signatures on his card wouldn't be enough either; the card has a special chip in it that's more difficult to imitate. 

I guess American banks simply haven't lost enough money yet to implement a sane system like this. Until they do, know that even if you practice good security with your online accounts, it doesn't take much to impersonate you on the phone and, even worse, huge corporations like Target aren't able to safeguard your data. 


Who wants to be Jeff Wilson? Apparently lots of people

Comments (10)

  1. NFICMonday, January 27th, 2014 at 11:54 am
    US Banks and retailers have just not lost enough money yet through credit card fraud. The Target hack is huge and should push the country to the more advanced European standards. We've been penny wise but pound foolish. The sad part is that individuals can be very careful about protecting their data but if a merchant has poor data security the individuals credit gets compromised. The slack approach by GE Capital is disappointing but they'll be on the hook for the losses. One question - had you provided Target information to enroll in their rewards program or frequent shopper program? I'm becoming more reluctant to do so given the significant data breeches at major retailers.
  2. ValMonday, January 27th, 2014 at 12:49 pm
    I am simply astonished that anyone could manage to spend $4000 at Old Navy. How is that even possible?! That's crazy. I am also grateful for my low credit score because even though my card was also in that batch, I haven't had any issues at all.
  3. Coastal SageMonday, January 27th, 2014 at 1:19 pm
    Jeff, I suggest writing a letter, with the detail you included in your blog post, to the Federal Trade Commission (http://www.ftc.gov/contact-federal-trade-commission) forwarding your recommendations because it looks to me that FTC is taking an interest in identity fraud. The beauty of the FTC enacting new regulations governing the security operations of financial institutions who issue credit and debit cards is that legislation by the deadlocked Congress is not required. I also want to alert everyone that our home alarm systems present a gaping hole for identity thieves to take advantage of. Last October we were at an art fair when my husband got a call from Lifelock.* He has been alerted that a company in Provo had pulled his credit report. My husband notified Lifelock that the accessing of his credit report was unauthorized and asked that the 3 credit reporting agencies be alerted. We were able to get the name and address of the company which pulled the credit report without my husband's permission. It was a little grubby house on a residential street in Provo, where at least 10 companies operated according to the Utah Secretary of State's records. I called the company which pulled the credit report and asked them who they were working for. The man said it didn't matter, because all a person has to have is someone's birthdate in order for him to pull their credit report, because he is an authorized receiver of credit reports for one credit agency. I reported him to the Provo law enforcement agency, which never responded. Of course we worry and wonder who the guy in the grubby little house in Provo was selling my husband's credit information to. (We've already been through one identify theft which occurred when an employee of a rental car company photocopied and counterfeited my husband's drivers license, which is why we have Lifelock.) It turned out that a part time employee of our alarm company, VIvint, had acquired all of the data on the Vivint security system at our house. That man then went to work for another alarm company. He and other employees of the second alarm company were canvassing neighborhoods where Vivint's customers are located, and telling people who answered the door that they are technicians for VIvint and that they needed to update the alarm equipment. (Apparently the second alarm company won't pull the scam on people with bad credit.) I searched the second alarm company on the internet, and it turns out that they have been caught in multiple states suckering alarm company customers into switching to the company operating out of Provo without the customers even realizing it. After the equipment switch is done under the guise of switching out Vivint's equipment, the on-the-ground men get the unsuspecting customers to sign a "Work Acknowledgment" which in tiny type refers to a contract on the back of the page which is a whole alarm contract with the new company. Apparently this second company also takes it upon itself to notify the home owner's old alarm company that they are cancelling. So the unsuspecting home owner not only has a new, more expensive alarm contract but they also get stuck paying their original alarm company's cancellation fees and paying for the VIvint alarm equipment which the second alarm company's employees rip off. Fortunately we were not home when the fraudster knocked on our door, and my daughter had the presence of mind to tell the man at the door that no one is allowed to touch any equipment in the house without her dad being there. Amazingly, the man started calling my husband's cel phone number, pulled from VIvint's records. The man represented that he was from VIvint, and was pressuring my husband to tell my daughter to let him in "Because I have 15 houses to re-equip each day, and you are putting me behind schedule". If not for that Lifelock alert we would not have figured out that the guy, his employer, and the credit report churning boiler room in Provo were fraudsters. Vivint's security department was understandably angry and concerned that someone was masquerading as their employee. They told my husband this happens all the time to all alarm companies, and that the company operating out of Provo was not the only one pulling this scam. So if someone calls you or knocks on your door wanting to "fix" your burglar alarm system, do not let them in and call your alarm company to double check their bonafides. Sadly what this incident taught me is that neither our property nor our lives are made safe in our homes just because we get a fancy alarm system. I can now understand why entertainers have armed body guards. Just this last weekend my son told me that a well known woman Senator has at least 4 burly, armed body guards. He commented on it at work and was told by his boss "She's not even running for President but the crazies are still stalking and harassing her." Apparently her home alarm system was not enough to protect her either. Enough said.
  4. Ex-EverywhereMonday, January 27th, 2014 at 3:12 pm
    Mother's maiden name... well, mine mom's maiden name is prominently displayed on Facebook, with my photos tagged and dutifully linked to her. There goes that "secret."
  5. yoshkapundrickMonday, January 27th, 2014 at 6:41 pm
    Follow Clark Howards advice and place a credit lock through the 3 credit agencies. Its cheap, simple and effective at locking out any further activity through your SSN.
  6. Don't AskTuesday, January 28th, 2014 at 7:12 am
    So I am confused. Have you not written the blog because you were tied up dealing with this mess, or because you were too busy being a parent (your earlier post this year)? :<)
  7. MikeTuesday, January 28th, 2014 at 5:57 pm
    Are you calling his baby a thief?
  8. Bill ReynoldsTuesday, January 28th, 2014 at 10:48 am
    What a completely despicable act by those cowards. Sorry to hear this, Brother Jeff....
  9. Teresa ToddTuesday, January 28th, 2014 at 10:56 am
    What an unimaginable saga and ordeal. Straightening this out will be a nightmare at least until next holiday season, right? So sorry you must go through this, Jeff. Changing a mother's maiden name? Unbelievable!
  10. LeslieSaturday, February 1st, 2014 at 2:51 pm
    Bottom line, why in the world would any bank change a security question and of all things a maiden name!! This makes no sense and sounds like a lawsuit. There needs to be change and Jeff you may be the one to do just that! Just blows my mind!!! I'm sorry you have been through all this unnecessary *#%%*#@$!!

Preserved as part of the SCV Talk Archive. Text is presented as originally published; presentation has been standardised for readability. The original capture is available at the Internet Archive.

Support