Social Engineering and Identity Theft

What is Identity Theft

Identity theft or ID fraud refers to a crime where an offender wrongfully obtains key pieces of the intended victim's personal identifying information, such as date of birth, Social Security number, driver's license number, etc., and makes gain by using that personal data.
Effects of Identity Theft
  • financial loss
  • criminal charges
  • leads to denial of employment, health care facilities, mortgage, bank accounts, and credit card services
  • legal issues
Personal Information that may be stolen
  • passport numbers
  • birth certificate data
  • credit card/bank account numbers
  • driver's license numbers
  • social security numbers
  • names
  • addresses
  • date of birth
  • Mother's maiden name
  • telephone numbers

Types of Identity Theft Attack

How do Attackers Steal Identity?
Social Engineering
It is an act of manipulating people's trust to perform certain actions or divulging private information, without using technical cracking methods.
Phishing
Fraudster pretend to be a financial institution and send spam/ pop‐up messages to trick the user to reveal personal information.
Hacking
Attackers may hack the computer systems to steal confidential personal information.
Theft of Personal items
Fraudsters may steal wallets and purses, mails including bank and credit card statements, pre-approved credit offers, and new checks or tax information.

What do attackers do with the stolen data?

Credit Card Fraud
  • They may open new credit card accounts in the name of the user and do not pay the bills.
Phone or Utilities Fraud
  • They may open a new phone or wireless account in the user’s name, or run up charges on his/her existing account.
  • They may use user’s name to get utility services such as electricity, heating, or cable TV.
Bank/Finance Fraud
  • They may create counterfeit checks using victim’s name or account number.
  • They may open a bank account in victim’s name and issue the checks.
  • They may clone an ATM or debit card and make electronic withdrawals on victim’s name.
  • They may take a loan on victims’ name.
Government Documents Fraud
  • They may get a driving license or official ID card issued on legitimate user’s name but with their own photo.
  • They may use victim’s name and Social Security number to get government benefits.
  • They may file a fraudulent tax return using legitimate user information.
Other Fraud
  • They may get a job using legitimate user’s Social Security number.
  • They may give legitimate user’s information to police during an arrest and if they do not turn up for their court date, a warrant for arrest is issued on legitimate user’s name.

Social Engineering

Social engineering is the art of convincing people to reveal confidential information. It is a trick used to gain sensitive information by exploiting basic human nature.
Social engineers attempt to gather:
  • Sensitive information such as credit card details, social security number, etc.
  • Passwords
  • Other personal information
Types of Social Engineering
Basically, there are two types of social engineering schemes.
Human-based Social Engineering
  • Eavesdropping
    • Eavesdropping is unauthorized listening to conversations or reading of messages
    • It is interception of any form of communication such as audio, video, or written
  • Shoulder surfing
    • Shoulder surfing is the procedure where the attackers look over the user’s shoulder to gain critical information such as passwords, personal identification number, account numbers, credit card information, etc.
    • Attacker may also watch the user from a distance using binoculars in order to get pieces of information
  • Dumpster diving
    • Dumpster diving includes searching for sensitive information at the target company’s trash bins, printer trash bins, user desk for sticky notes, etc.
    • It involves collection of phone bills, contact information, financial information, operations related information, etc.
Computer-based Social Engineering
  • Pop‐up Windows
    • Windows that suddenly pop up while surfing the Internet and ask for users’ information to login or sign‐in.
  • Hoax Letters
    • Hoax letters are emails that issue warnings to the user on new viruses, Trojans, or worms that may harm the user’s system.
  • Chain Letters
    • Chain letters are emails that offer free gifts such as money and software on the condition that the user has to forward the mail to the said number of persons.
  • Instant Chat / Messenger
    • Gathering personal information by chatting with a selected online user to get information such as birth dates and maiden names.
  • Spam Email
    • Irrelevant, unwanted, and unsolicited email to collect the financial information, social security numbers, and network information
  • Phishing
    • An illegitimate email falsely claiming to be from a legitimate site attempts to acquire the user’s personal or account information.
    • Phishing emails or pop‐ups redirect users to fake webpages mimicking trustworthy sites that ask them to submit their personal information.
  • Phony Security Alerts
    • Phony Security Alerts are the emails or pop‐up windows that seem to be from a reputed hardware or software manufacturers like Microsoft, Dell, etc.
    • It warns/alerts the user that the system is infected and thus will provide with an attachment or a link in order to patch the system.
    • Scammers suggest the user to download and install those patches.
    • The trap is that the file contains malicious programs that may infect the user system.
  • Social Networking Websites
    • Computer‐based social engineering is carried out through social networking websites such as Orkut, Facebook, LinkedIn, Twitter, etc.
    • Attackers use these social networking websites to exploit users’ personal information.

    Are you a victim?

    How do you find out if you have been a victim of social engineering fraud?
    • Bill collection agencies contact you for overdue debts you never incurred.
    • You receive bills, invoices, or receipts addressed to you for goods or services you haven’t asked availed of.
    • You no longer receive your credit card or bank statements.
    • You notice that some of your mail seems to be missing.
    • Your request for mortgage or any other loan is rejected citing your bad credit history despite you having a good credit record.
    Other scenarios:
    • You get something in the mail about an apartment you never rented, a house you never bought, or a job you never held.
    • You lose important documents such as your passport or driving license.
    • You identify irregularities in your credit card and bank statements.
    • You receive credit card statement with new account.
    • You are denied for social benefits citing that you are already claiming these benefits.

    What to do if your identity is stolen?

    Steps to take if you have been a victim of Identity Theft:
    1. Check your credit reports.
    2. Freeze your accounts with credit card companies or banks.
    3. Notify all your creditors regarding fraudulent activity.
    4. Change all passwords of your online credit accounts.
    5. Close all credit accounts you know or believe to have been tampered with.
    6. In the Philippines, touch base with either the Philippine National Police or National Bureau of Investigation. The NBI may be reached via ccd@nbi.gov.ph.
    7. You may file a complaint online via the Philippine Government's Cybercrime Investigation and Coordinating Center: https://cicc.gov.ph/report/
    Report the incident if your Social Media accounts have been hacked:

    Identity Theft Protection Checklist

    • Never give away social security information or private contact information on the phone – unless YOU initiated the phone call
    • Keep your Social Security card, passport, license, and other valuable personal information hidden and locked up
    • Ensure that your name is not present in the marketers’ hit lists
    • Shred papers with personal information instead of throwing them away
    • Confirm who you are dealing with, i.e., a legitimate representative or a legitimate organization over the phone
    • Carry only necessary credit cards
    • Cancel cards seldom used
    • Review credit reports regularly
    • Do not carry your Social Security card in your wallet
    • Do not reply to unsolicited email requests for personal information
    • Do not give personal information over the phone
    • Review bank/credit card statements regularly
    • Shred credit card offers and “convenience checks” that are not useful
    • Do not store any financial information on the system and use strong passwords for all financial accounts
    • Check the telephone and cell phone bills for calls you did not make
    • Read before you click, stop pre‐approved credit offers, and read website privacy policies

    Computer-based Identity Theft Protection Checklist

    • Keep the computer operating system and other applications up to date
    • Install antivirus software and scan the system regularly
    • Enable firewall protection
    • Check for website policies before you enter
    • Be careful while opening email attachments
    • Clear the browser history, logs, and recently opened files every time
    • Check for secured websites while transmitting sensitive information