Tag: identity theft

  • Notes of Hybrid meeting – 27th October 2022

    Just 11 of us in-person, room for more?

    The meeting started with a welcome to new members – Anne, Kate and Mo (in-person) and Martin, John, Lynette, Yvonne and Linda (over Zoom, with 5 others). I asked the new members to introduce themselves and tell the group what they hoped to get from their membership of it.

    I sought to clarify the arrangements where people had been allocated to groups. I do not want this to be prescriptive. If you know you can’t attend a meeting in-person, just let me know that you’d like to come to the one before your scheduled Thursday, or the one after.

    It would seem to me that there is room for at least another 5 members in-person at Sight Life from this meeting, so I’ll be monitoring attendance and perhaps inviting people to move to “the attend all meetings in-person” category. Similarly, if people would like to change their preference for the meeting they would like to attend in-person, just let me know. Finally, if people would like to join the Zoom-only category, please let me know that as well.

    We had some difficulties with the audio for the Zoom attendees at this meeting. My apologies. I’ve ordered a table microphone to use at Sight Life and this (hopefully) will solve that problem. I had been using the microphone integral to the camera, and this was apparently not picking-up all that was being said in the room. Kate and Mo wondered whether they might have trouble in using Zoom. I suggested they wait behind at the end of the meeting and I’d talk them through setting-up Zoom and using it. There a couple of useful documents about using Zoom on the Cardiff u3a website, and I’ve added a guide to setting-up meetings on Zoom on this website.

    I then repeated a few things I’s said at the previous meeting about how the group is run. I referred to the fact that generally we don’t try and solve hardware/software problems on members computers, but we do recommend and refer members to “We will fix your PC” as an excellent resource and repair one-stop shop. I shared the “Toolkit” handout to a few members who’d not picked it up from their email. I explained and demonstrated how the Thought grazing website works and some of its features, its origins as part of my pre-retirement role at Cardiff University, and the public version – which is where Jenny (with my assistance) had recently posted an article about the switch-off of the analogue PSTN (public switched telephone network). I wondered whether Jenny might review the article to see whether it needed any additions to it?

    I also suggested (and strongly recommended) that members join the Signal group we’ve set up to assist in giving support/advice between meetings. You need to download an app to your smartphone, connect your phone number to the Signal account. You can then download an app for your tablet, or desktop/laptop and view messages from these devices as well.

    I went on to promote the Thought grazing Flipboard magazine – the place where I and a couple of other members add articles they have come across that they think might be of interest to the group. I also mentioned that anyone could be a contributor to the magazine. They would need to have a Flipboard account (which you don’t need to just read the magazine) and let me know; I can then add them to the list of contributors.

    I concluded the introductory remarks by mentioning what I’d found to be the most common misconception for new members. What is an internet browser, and what is a search engine. I’ve written before about this – here, here and here. My most recent post however compares and reviews the various most common browsers and search engines available. I also stressed my preference (wherever possible) to use Open Source software, or to pay a subscription for software (rather than get free software with advertisements, and all the targeting and spam that involves).

    I then reviewed the news that caught my eye in the previous two weeks, with links and comments to articles on the Flipboard magazine. Jonathan had posted this article on Windows Security, for instance, whilst Paul had found a nifty desk tidy device that could also charge your phone. I rushed through a number of Apple related articles which have my comments attached to them. This one, on sharing an iCloud Photo Library will be one I certainly want to follow-up, and then there were a few articles on the new Apple devices just announced, and the new versions of MacOS (Ventura), iPadOS and iOS. I cautioned (as I always do) against rapid adoption of an operating system, and referred members to an issue with Malwarebytes (for the latest MacOS release), but celebrated the fact that Dropbox had finally (after a year) released a native application for MacOS M-series machines.

    There’s a lot of information in the above, so please get back to me if you want any clarification – preferably on Signal.

    I finished my spot by detailing how I’d spent some time trying to subscribe a friend to use an upgrade to Apple’s iCloud system, but had found out – after nearly three months of trying, and having had finally to admit defeat and use Apple’s Support service – that the problem was that payments wouldn’t work because the software on her phone and MacBook was too out-of-date. The security system just wouldn’t allow payments to be made successfully. A very good reason to keep your operating systems up-to-date … even if you don’t rush to upgrade them!!!

    Sianed then took over the facilitation of the meeting so that members could raise issues, and for existing members – how had they benefited from membership of the group. She stated that she’d benefited from learning from everybody else

    Don described the Computer Group as a life-jacket. He’d taken over responsibility from some computer activity with hsi church and this had forced him to learn. He mentioned the recent scam whereby someone had lost their house through identity theft. This was discovered when it was found a person was trying to sell that property online! Apparently the identity had been stolen through a replacement driving licence that the estate agency had accepted as valid ID. Apparently there is protection from the Land Registry for a £40 fee. He had downloaded and installed Norton Anti-virus for his new machine – mainly for the internet banking security window. It provided him with re-assurance, even though I suggested that Windows Defender was probably as good as anything, and free!

    Fred queried the strange URLs he’d recently seen – I explained these were URL-shortners. Often I use bit.ly.

    Jenny described her work as a campaigner for Digital Inclusion, and mentioned specifically that she’d just become involved in lobbying for the Social Tariff for broadband more widespread, not something people had to opt in for. I had shared a link after the meeting on Signal, and she would be working on an article soon. She admitted to real problems with too much disorganised email from Gmail. I offered to do a session on Google settings, but in the meantime this page on the website might be a start.

    Anne had a new laptop and it was running Windows 11. She was concerned that some of the software, especially that which she used for photography, might not run on the new machine. I responded (after the meeting) with this reply …

    I’ve done a bit of searching around. It would appear that Picasa can still be downloaded and at least works with Win 10, so it probably works with Win 11 as well. Can’t confirm that.
    
    Here’s an article that explains the status of Picasa, with a download link in it, which looks OK.
    
    You might instead consider using Google Photos 
    
    … where your earlier photos may already be. Google Photos is an Online Editor - I’ve covered its use a couple of times in the Group and there are posts on the website.
    
    Alternatively you could look at Microsoft’s Photos app
    
    … or an open source alternative such as Gimp …
    
    … hope this helps.

    She also asked whether she needed to take out a fresh licence for her Kaspersky Anti-virus software. Apart from the questionable source of the software (Russia), I suggested that this would not be the case, she needed to register her new machine. I also mentioned (as I had above) that Windows Defender was probably as good as any anti-virus software for our type of computer use.

    David Hughes described the frustration in not seemingly to be able to switch off his Facebook Portal machine. [No comment – perhaps its spying on him :-)]

    John Silk was interested in what I’d said about the iCloud Photo Library and reminisced on how it used to be the practice to just save photos on a USB-disk, or memory stick. How can you do that from your photos app on your phone now. I offered to write something about this workflow.

    John Mitchell had a most interesting problem. It appeared that a lot of files (photos) had vanished from the folders they used to be in. The group discussed several possible scenarios where this might have happened. After the meeting I sent this email to John …

    I’ve been puzzling over your missing files issue, and found this link
    
    … which seems to suggest that you might have dropped into an issue that is not unique. I wouldn’t recommend trying to solve this one yourself, but I would recommend you taking your machine (esp. if it’s a laptop) to the guy we show hardware problems to; We will fix your PC
    
    Neil is really good and I’m sure he’ll give you good advice. Mention the u3a Computer Group.
    

    … and that was about it. If I’ve forgotten anything, my apologies. Please add to the Comments below the post.

    Until the next time when I’ll revisit (again) privacy and security. Cheers.

  • Identity Theft

    This will probably be one of the most challenging posts I’ve ever attempted to write because in all truth, I don’t think we really still know what actually happened to my daughter’s online identity, let alone wholly knowing how it happened, but I’m going to try and explain the sequence of events as an alert to you all, and a reminder to us too!

    Some background and a plausible explanation of why they got themselves into the situation they found themselves.

    They’d been self-employed for a short while now, working as a freelancer, and had just submitted their first tax returns in that capacity.

    They were working from home, with two young children with one under six months old, and both very demanding of their time.

    The family is living in another family member’s house whilst they “do up” their new house.

    They’re adept at multi-tasking (obviously too adept as it turns out) and is (as many of their age are able to do) capable of nestling their phone between chin and shoulder whilst doing other tasks!

    What happened next!

    She had a phone call purporting to come from HMRC (we’re presuming this was just a fortuitous coincidence from the fraudster’s point of view – they had no way of knowing the employment status of the family member) – saying that they had a refund owing. As explained above she thought this was quite possibly the case as she had just completed a tax return – again an unhappy coincidence! She was told to click on a link in a text message to complete the process of getting the refund. She had their youngest child on her hip, was preparing a meal and was “distracted”. She filled-in the required information from the link!!!!

    Agh! No!

    Shortly afterwards (the same day) she presented her credit card at a supermarket and payment was refused. She realised something was wrong. She found she didn’t have access to her online banking. She contacted the bank by phone. The bank “supposedly” froze the account there and then but it was apparent that at least two transfers of money had been made to someone who was a Payee in her account – why? That’s the clever bit of the scam, I’ll explain later!

    More payments appeared to have been made … help!!!

    How could this be? The account was frozen … wasn’t it?

    Get the family involved!

    Having a son who’s an IT expert comes in useful, especially if he lives on the other side of the world! He worked through the night (day) in securing as many of her accounts as he could. Changing passwords, which were admittedly rather weak and used more than once (should have listened to Dad) – but he had no idea just how much data had been downloaded, or indeed just how much they had to start with as a result of perhaps a previous “pwned” event.

    Having another local son who’s also very practical and logical helps also. He suggested that she contact the payee and tell them about the payment and request it be refunded. What transpired next turns out to be the “clever” part of the scam, although on this occasion it wasn’t conducted very expertly because they attempted multiple payments to the same payee. The payee confirmed that they’d had this payment, wondered what it was and had been a bit puzzled as to why Mr X had contacted them and requested a refund to a bank account because “he’d made a mistake”.

    This was obviously NOT the same account as that from which the payment had originated and turned out to be the way the scammers were hoping to transfer funds from the hi-jacked bank account to one of their own! Fortunately, my son’s suggestion alerted the payee and the payee advised their bank NOT to transfer the money.

    Phew! How did this all happen when the bank account was supposed to be frozen?

    The key to this scam was getting control of my daughter’s mobile phone number. She didn’t realise it immediately, but soon became aware that it had been “stolen” through a scam called SIM swapping. This usually is done by a seemingly distressed person going into a mobile phone shop and pleading for a new SIM with a phone number “because their phone has been stolen” and “it’s absolutely imperative they have their number back immediately as there’s something very important happening right now”.  This is described here.

    Why do they want to do this? Because they can transfer calls made to the rightful owner of the phone to their own phone.

    Why do they want to do this? Because they can then request the bank account to be unfrozen, and also use their access to the phone number for any number of authorisation features.

    And what is more they can lock you out of your phone accounts.

    How did they do this in this case? Well GiffGaff is an online service provider and they have stated that they did everything they were supposed to do to authenticate the request for a SIM swap – but it is evident that there are serious weaknesses in their processes. They have stated they are looking at this for the future. Just Google “GiffGaff SIM swap Fraud” to see what is returned – it’s frightening!

    So what happened next, and was there a happy ending?

    Well, believe it or not, even with a personal visit to the bank and assurances that no more payments would be made, the bank did allow the account to be unfrozen and transfers out of her account were attempted. A second visit to the bank resulted in heartfelt apologies being made and offered over the way their fraud department had handled the problem and a complaint being raised by the branch against their own department on my daughter’s behalf – I don’t know the outcome of that!

    Well, there was a happy financial outcome. Thanks to the prompt action and thinking of my local son, the initial transfer was halted. It’s not conclusive whether my daughter could have received compensation (as detailed here) as she was the instigator of the problem through her own mistake (the HMRC phone call). All other attempted transfers were eventually trapped by the bank and refunded to her – so no financial loss.

    However …

    Much more significant than the potential financial loss was what it did to her confidence. She insisted on getting a new phone, because she wouldn’t accept any advice from any family member (especially me) that there wasn’t anything on her phone that wouldn’t continue to monitor her.

    She also lost all confidence in using any online systems – which up until then she’d been very reliant upon.

    She also lost a lot of confidence in herself as she realised just how gullible (but extremely unfortunate) she’d been … but the positive side of this, and the main reason for sharing this is that she’ll be much more careful in the future!

    Postscript.

    We don’t know whether the identity theft side of this will ever be resolved. We all know that a huge amount of information is held on us on the internet. We all know that some websites have had their security breached and identity information stolen. We don’t know what was held by others about my daughter. She had a public profile, they now have the potential to add even more information to their database about her if they had managed to download information from her email (and other) accounts before my son locked them down. We just don’t know.

    There was a mysterious book that arrived at her house with a cryptic message in it.

    There have been some scamming emails purporting to come from her since this event.

    She now uses a different email account.

    We just don’t know whether these are connected to the fraud event or are just strange random occurrences … and I suppose we never will know just how much additional information they may have downloaded – emails, photographs, documents, etc. etc. Very frightening.

    NatWest Guide to Fraud
    Some privacy tips for iPhone users.

  • Scams, SIMs and security – 27th June 2019

    Boot-up
    Feedback from the last meeting (John). Any progress with websites from anyone else??
    Thought grazing: Jim posted on Google Photos, Google Drive and Backup and Sync. This is Google’s blogpost on the changes they are making and here is the help document explaining what will happen after July 10th.
    I posted about using URL shorteners and reminded you how I use Pocket and Flipboard.
    The Computer Group for next year. We’ll meet as we meet now, every second and fourth Thursday of the month.
    Digital Picture Frames – anyone use them? I’ve had Nix recommended to me. Alternatives – try Foliobook on an iPad, or a screensaver linked to Dropbox on a Desktop PC.
    Travel and digital photography.
    SMART meters, SMETS2 and Hive. Discussion on optionsswitching suppliers. Hold off for now?
    How do Password Managers Work?  Should you use one? Which one should you use?
    Anything else, issues, problems.
    News
    Apple’s WWDC Showcase summary – loads of updates and new hardware. The 8-minute video summary. Apple’s promotional videos from the event. Apple splits iPhone and iPad operating systems by introducing iPadOS – what’s new in both?
    What new features will there be in iPadOS? Mouse support for the iPad. Finally, external drive support for the iPad – this is how it will work.
    New features for MacOS – Catalina coming in the autumn.
    Apple’s iOS 13 will provide some protection against spam phone calls.
    New features in iPadOS, iOS and MacOS for photographers. Click here and here too!
    Apple finally kills off iTunes!
    New features for Dropbox on the Apple platforms.
    What Wireless Security are you using, and should you consider changing your router?
    Don’t charge your phone/tablet under your pillow at night – and other electrical tips!
    Identity Theft
    This will probably be one of the most challenging posts I’ve ever attempted to write because in all truth, I don’t think we really still know what actually happened to my daughter’s online identity, let alone wholly knowing how it happened, but I’m going to try and explain the sequence of events as an alert to you all, and a reminder to us too!
    Some background and a plausible explanation of why she got herself into the situation she found herself.
    She’s been self-employed for a short while now, working as a freelance journalist, and had just submitted her first tax returns in that capacity.
    She’s working from home, with two young children with one under six months old and both very demanding of her time.
    The family is living in my local son’s house whilst they “do up” their new house.
    She’s adept at multi-tasking (obviously too adept as it turns out) and is (as many of her age are able to do) capable of nestling her phone between chin and shoulder whilst doing other tasks!
    What happened next!
    She had a phone call purporting to come from HMRC – we’re presuming this was just a fortuitous coincidence from the fraudster’s point of view – saying that she had a refund owing. As explained above she thought this was quite possibly the case! She was told to click on a link to complete the process of getting the refund. She had her youngest son on her hip, was preparing a meal and was “distracted”. She filled-in the required information from the link!!!!
    Agh! No!
    Shortly afterwards (same day) she presented her credit card at a supermarket and payment was refused. She realised something was wrong. She found she didn’t have access to her online banking. She contacted the bank by phone. They “supposedly” froze her account but it was apparent that at least two transfers of money had been made to someone who was a Payee in her account – why? That’s the clever bit of the scam, I’ll explain later!
    More payments appeared to have been made … help!!!
    How could this be? The account was frozen … wasn’t it?
    Get the family involved!
    Having a son who’s an IT expert comes in useful, especially if he lives on the other side of the world! He worked through the night (day) in securing as many of her accounts as he could. Changing passwords, which were admittedly rather weak and used more than once (should have listened to Dad) – but they had no idea just how much data had been downloaded, or indeed just how much they had to start with as a result of perhaps a previous “pwned” event.
    Having a local son who’s also very practical and logical helps also. He suggested that she contact the payee and tell them about the payment and request it be refunded. What transpired next turns out to be the “clever” part of the scam, although on this occasion it wasn’t conducted very expertly because they attempted multiple payments to the same payee. The payee confirmed that they’d had this payment, wondered what it was and had been a bit puzzled as to why Mr X had contacted them and requested a refund to a bank account because “he’d made a mistake”. This was obviously NOT the same account as that from which the payment had originated and turned out to be the way the scammers were hoping to transfer funds from the hi-jacked bank account to their own! Fortunately, my son’s suggestion alerted the payee and they advised their bank NOT to transfer the money.
    Phew! How did this all happen when the bank account was supposed to be frozen?
    The key to this scam was getting control of my daughter’s mobile phone number. She didn’t realise it immediately, but soon became aware that it had been “stolen” through a scam called SIM swapping. This usually is done by a distressed person going into a mobile phone shop and pleading for a new SIM with a phone number “because their phone has been stolen” and “it’s absolutely imperative they have their number back immediately as there’s something very important happening right now”.  This is described here.
    Why do they want to do this? Because they can transfer calls to the rightful owner of the phone to their own phone.
    Why do they want to do this? Because they can then request the bank account to be unfrozen, and also use their access to the phone number for any number of authorisation features.
    And what is more they can lock you out of your phone accounts.
    How did they do this in this case? Well GiffGaff is an online service provider and they have stated that they did everything they were supposed to do to authenticate the request for a SIM swap – but it is evident that there are serious weaknesses in their processes. They have stated they are looking at this for the future. Just Google “GiffGaff SIM swap Fraud” to see what is returned – it’s frightening!
    So what happened next, and was there a happy ending?
    Well, believe it or not, even with a personal visit to the bank and assurances that no more payments would be made, the bank did allow the account to be unfrozen and transfers out of her account were attempted. A second visit to the bank resulted in heartfelt apologies over the way their fraud department had handled the problem and a complaint being raised by the branch against their own department on my daughter’s behalf – I don’t know the outcome of that!
    Well, there was a happy financial outcome. Thanks to the prompt action and thinking of my local son, the initial transfer was halted. It’s not conclusive whether my daughter could have received compensation (as detailed here) as she was the instigator of the problem through her own mistake (the HMRC phone call). All other attempted transfers were eventually trapped by the bank and refunded to her – so no financial loss.
    However …
    Much more significant than the potential financial loss was what it did to her confidence. She insisted on getting a new phone, because she wouldn’t accept any advice from any family member (especially me) that there wasn’t anything on her phone that wouldn’t continue to monitor her.
    She also lost all confidence in using any online systems – which up until then she’d been very reliant upon.
    She also lost a lot of confidence in herself as she realised just how gullible (but extremely unfortunate) she’d been … but the positive side of this, and the main reason for sharing this is that she’ll be much more careful in the future!
    Postscript.
    We don’t know whether the identity theft side of this will ever be resolved. We all know that a huge amount of information is held on us on the internet. We all know that some websites have had their security breached and identity information stolen. We don’t know what was held by others about my daughter. She was a public figure, a journalist on a national newspaper, they now have the potential to add even more information to their database about her if they managed to download information from her email (and other) accounts before my son locked them down. We just don’t know.
    There was a mysterious book that arrived at her house with a cryptic message in it.
    There have been some scamming emails purporting to come from her since this event.
    We just don’t know whether these are connected to the fraud event or are just strange random occurrences … and I suppose we never will know just how much additional information they may have downloaded – emails, photographs, documents, etc. etc. Very frightening.
    NatWest Guide to Fraud
    Some privacy tips for iPhone users.