How do you know if your identity has been stolen?

By Anita Byer, Setnor Byer Insurance & Risk

The likelihood of identity theft seems to increase daily. With so many identities being stolen, many believe it’s a matter of when, not if. Taking preventative measures is crucial to reducing the likelihood of being a victim, but nothing is foolproof. When identity theft does happen, early detection is the key to limiting the damage. The sooner you know, the better. But, how do you know when your identity has been stolen? It can be harder than you think.

Fortunately, the Federal Trade Commission offered some helpful advice during this year’s Identity Theft Awareness Week. According to the FTC, you need to understand how thieves might use your stolen identity and be on the lookout for signs.  

An identity thief could use your information to get credit or service in your name.

How to spot it: Get your free credit report at AnnualCreditReport.com. Review it for accounts you didn’t open or inquiries you don’t recognize. A new credit card, a personal loan or a car loan will appear as a new account. A new cell phone plan or utility service (water, gas, electric) will show up as an inquiry.

An identity thief could use your credit card or take money out of your bank account.

How to spot it: Check your credit card or bank statement when you get it. Look for purchases or withdrawals you didn’t make. Sign up to get text or email alerts from your credit card or bank whenever there’s a new transaction. This could help you spot unauthorized or fraudulent activity on your account.

An identity thief could steal your tax refund or use your Social Security number to work.

How to spot it: A notice from the IRS that there’s more than one tax return filed in your name could be a sign of tax identity theft. So could a notice that you have income from an employer you don’t work for.

An identity thief could use your health insurance to get medical care.

How to spot it: Review your medical bills and Explanation of Benefits statements for services you didn’t get. They could be a sign of medical identity theft.

An identity thief could use your information to file a claim for unemployment benefits.

How to spot it: A notice from your state unemployment office or employer about unemployment benefits that you didn’t apply for could be a sign of fraud.

When preventative measures fail, insurance is available to help victims through the expensive and time-consuming process of recovery. Please contact us if you would like more information about insurance specifically designed to protect against identity theft.

Don’t Let Weak Site Security Compromise Your Business’s Cybersecurity

Setnor Byer Insurance & Risk

Small businesses spend a lot of time and money to protect their sensitive and confidential information, and rightfully so. Data breaches can lead to crippling, often insurmountable financial and reputational harm. Unfortunately, many businesses overlook the most basic security measures. Cyber criminals, for example, pose the biggest threat to data security, so most businesses focus almost exclusively on cybersecurity while paying little or no attention to physical (site) security. This can prove disastrous because sophisticated firewalls and advanced security software cannot stop someone from stealing a flash drive or paper file containing sensitive information.

According to the Federal Trade Commission, cybersecurity begins with strong physical security that effectively protects sensitive or confidential information in paper files and electronic devices (hard drives, flash drives, laptops, point-of-sale devices, etc.). The FTC offers the following tips for maintaining physical security.

  • Store paper files and electronic devices containing sensitive information in a locked cabinet or room to keep them secure.
  • Train employees to put paper files in locked file cabinets, log out of networks and applications before leaving and never leave files or devices with sensitive data unattended.
  • Limit physical access to records or devices containing sensitive data to only those who need it.
  • Keep track of documents and devices containing sensitive data so they can be handled accordingly.

To protect sensitive data stored on devices,

  • Require passwords that are long, complex and unique.
  • Require multi-factor authentication, like a password and a temporary code, to access sensitive information.
  • Limit the number of incorrect login attempts allowed to unlock devices.
  • Encrypt portable media, including laptops and thumb drives, that contain sensitive information.

Sensitive and confidential business data can be stolen online or onsite, so businesses must make physical (site) security a key component of their cybersecurity protocols. Since security measures aren’t always enough, small and medium-sized businesses should have Cyber Perils Insurance Coverage to protect against various cyber threats and liability exposures, including the cost of complying with data breach notice laws. Please contact us if you would like more information about insurance specifically designed to protect against cyber threats and data security breaches

Ransomware Attacks Are Becoming More Common and More Expensive

Setnor Byer Insurance & Risk

Did you know that the average ransomware demand in the first quarter of 2020 was $111,605? Ransomware is a type of malware that encrypts critical data so it cannot be accessed without a decryption key. Victims must, you guessed it, pay a ransom to get the key. The costs associated with a successful attack, which can far exceed the ransom, typically include investigation and remediation expenses and lost revenue due to downtime. Ransomware can also inflict insurmountable brand damage and reputational harm.

According to the Federal Trade Commission (FTC), hackers try to exploit network or server vulnerabilities to access a target’s data, but the malicious code used to launch ransomware attacks is often installed on devices and networks by:

  • scam (phishing) emails that appear legitimate;
  • infected websites; and
  • online ads, which often appear on websites you know and trust.

The FTC recommends the following measures to reduce the risk of a successful ransomware attack.

  • Have a Plan. Businesses need a plan to remain operational after a ransomware attack. Plans should be written and shared with those needing to know.
  • Back up Data. Regularly save important data to a drive or server that’s not connected to a network. Make this part of your routine business operations.
  • Update Security Software. Always install the latest patches and updates. Consider adjusting your settings to update automatically.
  • Train Staff. Train all employees how to identify and avoid common threats. Provide examples of the most common ways devices and networks become infected.

If your business experiences a ransomware attack, the FTC recommends taking the following steps.

  • Limit the damage. Immediately disconnect infected devices from your network.
  • Contact Authorities. Immediately report the attack to local and federal authorities (local FBI office).
  • Provide Required Notices. If data has been exposed, compromised or stolen, notify authorities and affected individuals pursuant to any applicable data breach notification laws.

Preventative measures can effectively reduce the risk of a ransomware attack, but they’re not foolproof. Every business should have Cyber Perils Insurance Coverage to protect against various cyber threats and liability exposures, including the cost of complying with data breach notice laws. Please contact us if you would like more information about insurance specifically designed to protect against cyber threats and data security breaches.

Scam Alert: Tax Season Is Identity Theft Season

Should you be concerned about taxpayer identity theft? Here’s a hint. Tax Identity Theft Awareness Week starts February 3, 2020. As a general rule, anything worthy of having its own dedicated Awareness Week deserves your full attention.

Tax-related identity theft occurs when someone uses stolen personal information to file a tax return claiming a fraudulent refund. The problem has become so serious that the Internal Revenue Service has issued numerous publications about safeguarding taxpayer data and preventing identity theft. According to the IRS, you should be alert to possible tax-related identity theft if:

  • you get a letter from the IRS inquiring about a suspicious tax return that you did not file;
  • you can’t e-file your tax return because of a duplicate Social Security number;
  • you get a tax transcript in the mail that you did not request;
  • you get an IRS notice that an online account has been created in your name or that your existing account has been accessed or disabled when you took no action;
  • you get an IRS notice that you owe additional tax or refund offset, or that you have had collection actions taken against you for a year you did not file a tax return; or
  • IRS records indicate you received wages or other income from an employer you didn’t work for.

To protect against taxpayer identity theft, the IRS recommends that taxpayers:

  • Use current security software (firewalls, virus/malware protection, file encryption). Make sure it updates automatically.
  • Treat personal information like cash. Don’t leave it lying around.
  • Use strong, unique passwords and 2-Factor Authentication.
  • Avoid phishing scams and malware that often come in emails that appear to come from a trusted source and emails with urgent messages.

Finally, the IRS wants everyone to know that they will never:

  • initiate contact by email, text or social media to request personal or financial information;
  • call taxpayers with threats of lawsuits or arrests; or
  • call, email or text to request taxpayers’ Identity Protection PINs.

When preventative measures fail, insurance is available to help victims through the often expensive and time-consuming process of recovery. Please contact us if you would like more information about insurance specifically designed to protect against identity theft.