Protecting your identity

A greater effort all round by businesses, banks, Government, and the Police is required, not to mention much better consumer education.

A couple of weeks ago, a 47-year-old Siġġiewi resident was condemned to a two-year jail term suspended for four years after he was found guilty of fixing letterboxes to various residences so that letters linked to illicit residency permits to third-country nationals could be posted at those addresses.

It is alleged that this particular case is only the tip of the iceberg.  A couple of weeks earlier, a 30-year-old man who went for a check-up at a public healthcare clinic had been told his medical records listed him as having died months before.  The man was among at least a dozen other people who are said to have discovered that their medical files contained upcoming appointments for serious tests and surgeries they did not need, data about hospital admissions they never underwent, medication they were never prescribed, by doctors they never visited, for illnesses they never had.

People have come forward to reveal that they have been contacted from hospital and clinics over the past months to confirm an upcoming appointment for a test, operation or treatment scheduled for the following weeks. The appointments listed their correct name and ID card number, but the medical details were not theirs. Appointments even included the name of the doctors who had presumably made the referral – only these people had no such conditions and never visited those doctors.

Industrialising identity theft

It seems that Malta has now joined the rest of the world in identity theft.  Not to be outdone when there is something illegal to be done, we are now industrialising identity theft and transforming it into a new business, the hallmarks of which will be fraud, corruption, money-laundering, tax evasion, and you name it.Top of Form

Put simply, identity fraud means criminals using your personal information for monetary gain. However, it can extend to opening bank accounts in your name and redirecting your post to another address.

Without a doubt identity fraud is one of the key enablers of crime today. Unfortunately, it’s getting easier.  Anybody who can use a computer, the internet, a printer and a scanner, can take over some else’s identity.  The effort involved could be considerable if the criminal concerned has to spend time retrieving sensitive information from people’s garbage bags.  Most people don’t shred documents before throwing them away and this could include bank financial statements which they don’t even read.   Over three-quarters of household waste is estimated to contain at least one or more items that could assist fraudsters in stealing an identity.

The synthetic identity fraud

One particular form of fraud is that of synthetic identity fraud.  Increasing digitalisation and the use of online utilities are posing a threat to the personal lives of many individuals. In 2023, synthetic identity fraud worldwide saw a 52% increase compared to the previous year.  According to Identity Theft Statistics 2023, 43% of adults spend an average of 200 hours in 6 months resolving the issues time resolving identity theft issues. By 2026, credit card fraud as a result of identity theft is projected to reach $43 billion.

Synthetic identity fraud, which involves combining real and fake information to create new identities, is on the rise, according to a new report which analysed data breaches and fraud in the public sector over the past year. According to the report, in 2023 some 54% of consumers across 18 countries and regions were reportedly targeted in online, email, phone call or text messaging fraud attempts.

The report found that data breaches, which often exposed consumers’ personal data, including Social Security numbers and driver’s license numbers, also led to an increased risk of fraud against government agencies, like business registrars, motor vehicle agencies, insurance programmes and more, resulting in improper payments and potential loss of access to public benefits for rightful constituents through identity theft and synthetic identity fraud.

One expert says that public sector agencies need to watch out because things like artificial intelligence will make it much easier and faster to create completely realistic-looking, fabricated identities, whether it’s building a financial profile or a digital footprint.  Synthetic identity fraud can also be used to open fraudulent accounts and make purchases.

The push in recent years for government to make its digital services more accessible has led to more people interacting with government agencies across a variety of methods   ̶   websites, email, text messages, phone calls   ̶   which creates multiple entry points for fraudsters to undermine.  Unless the agencies involved practise omnichannel verification, or vetting whether an individual is real or fake through multiple methods, including verbal, digital or even geographical, then criminals can have a field day.

Operation Cookie Monster

Recently, the American FBI, Dutch police and law enforcement agencies across 18 countries, took Genesis Market offline in “Operation Cookie Monster”.  Genesis had 80 million sets of personal credentials available for sale, covering 2 million people.  Online banking, Facebook, Amazon, PayPal and Netflix account information were up for sale alongside so-called digital fingerprints containing data from the victims’ devices. Users of the platform could purchase any information available for between 63 cents and several hundreds euros, depending on the type of information requested.

Genesis Market is one of the top criminal access marketplaces anywhere in the world. It is an enormous’s enabler of fraud and a range of other criminal activity online by facilitating that initial access to victims, which is a critical part of the business model in a whole range of nefarious activity.  The marketplace could be found using normal internet search engines, as well as on the dark web, and users were offered step-by-step guides on how to buy stolen details as well as how to use them for fraud.

Mobile phones

Meanwhile, the risks of doing banking on a mobile handset are also rising rapidly as people’s mobiles are taken over by fraudsters.  In these cases, the phone will have taken them over using malware. Once in control of the email account, and armed with other personal data, the fraudsters then pose as the customer to the mobile company, resetting all the passwords and ordering a replacement sim card.

Having assumed control of someone’s mobile phone it is relatively easy for the fraudsters to pretend to be the bank’s customers, using two-step verification codes sent to the phone itself, and ultimately empty the bank accounts.  Many people unfortunately are not aware that this can happen unless they have 2-step verification turned on to email and other accounts, rather than to the phone itself.  Some banks and credit card companies will refund victims, and others won’t.

Protecting ourselves

As identity theft has proliferated, companies in other countries have started offering identity-theft protection. Those who enroll are promised notification if their information is offered for sale on the internet, their credit reports are monitored for suspicious activity, and users are offered $1m-worth of insurance to compensate them for losses incurred as a result of identity theft.   However, a search on the web did not indicate that Maltese insurance companies offer this cover in Malta

Information about fraud is hard to come by in Malta, but according to the answer to a parliamentary question there have been more than 50 cases of fraud reported to Identity Malta every year since 2014.  This, presumably, does not include the identity fraud cases allegedly committed by the agency’s staff itself.  But it is obvious that a greater effort all round by businesses, banks, government, and the Police is required, not to mention much better consumer education.

Photo: Jan van der Wolf

5 1 vote
Article Rating
Subscribe
Notify of
guest
0 Comments
Oldest
Newest Most Voted