Results 1 to 5 of 5

Thread: Scammers Target Cell Phone Records

  1. #1
    Senior Member
    Join Date
    Oct 2002
    Posts
    4,055

    Scammers Target Cell Phone Records

    From yahoo.com:

    You wouldn't think that anyone could know that you left a couple of nasty messages for your ex, called the bank to talk about a home equity loan and booked tickets through your travel agent to Tahiti on your cell phone last week. But you'd be wrong.

    Information brokers, through a constantly changing network of Web sites, are selling cell phone records for as little as $110 to any interested party, according to the Privacy Rights *************, a California-based consumer privacy rights group.

    "If you are in a certain life situation where illegitimate access to your cell records could cause problems, like a nasty divorce or custody case or a business lawsuit, or you're the victim of a stalker, you're vulnerable," says Beth Givens, director of the Privacy Rights *************. "Your adversary could obtain your cell phone records through a broker and use them against you."

    The good news is that cell phone companies, regulators and consumers are sitting up and taking notice. On Wednesday, Feb. 1, the House Committee on Energy and Commerce held a hearing at which the chairman of the Federal Trade Commission vowed to crack down on this practice.

    How it happens
    There are a few ways companies or brokers in this business operate. The most common is through pretexting, when someone calls your cell phone company pretending to be you and asks that your records be faxed or e-mailed to a certain fax number or e-mail address.

    Another fairly common scenario occurs when a company or broker gets Web access to your cell phone records by creating an account in your name and using it to check your records, according to the Electronic Privacy Information Center, a consumer privacy rights group in Washington, D.C. If you haven't ever accessed your cell phone account online, you're more likely to be a victim of this type of crime.

    The third method that data brokers use is to pay an employee of a wireless phone company to access and transfer the data.

    What you can do
    Even if you don't think you're vulnerable to having your cell phone records bought and sold, it is better to be safe than sorry. Here's what you can do:

    Password-protect your cell phone account. This doesn't just mean logging on to your online account with your cell phone provider and picking a password that isn't your nickname, your birthday, your phone number, your mother's maiden name, your Social Security number or your kid's birthday. This means picking up the phone and calling your cell phone company and telling them to only allow access to your account to individuals who can come up with the right password and that if you forget it, you'll go to their nearest store and show your ID to get a new password.
    Opt out of CNPI, or customer proprietary network information, sharing. "Cell phone companies use your phone records for marketing purposes, not only to sell you new services but also to sell your information to outside companies that want to market to you," says Chris Jay Hoofnagle, director and senior counsel of the Electronic Privacy Information's West Coast Office. "They hate it when you opt out and make it as difficult as possible to do so. In fact, you have to call the wireless company and insist on it, and then sometimes the customer services rep will say they don't know what you're talking about."
    Set up cell service in your name. The easiest way others can access your records is if they are paying the bill. This includes your spouse or significant other, your employer or your parents. This is a problem if you use your employer-provided cell phone to make personal calls or use it in a search for another job, especially if you are talking to competitors. So to ensure your privacy, get your own phone and put the bill in your name and have it sent to a post office box that is only in your name.
    Ask your wireless provider to remove online access and call details. If you don't access your cell phone records online or plan to do so in the future, call your cell company and ask them to deactivate online access to your account. If you have unlimited minutes or aren't interested in the details of your call history, you can also ask to have this specific information removed from your bill.
    Regulators and cell companies step up to the plate
    Indignation over the illegal sale of cell phone records is boiling over in Congress, where several members of the House of Representatives have vowed to introduce a bill in the next week on this topic, according to Hoofnagle, who attended the hearing on Wednesday. "We are going to see a bill on the federal level that deals with this issue," he says, noting that a number of states have passed laws and that California residents in particular have solid protections in place already.

    Givens says that the cell phone companies are jumping on the bandwagon, suing the brokers and companies that are illegally selling their information. Verizon, Cingular, Sprint and other companies have sued brokers, and in some cases secured injunctions against them, because obtaining phone records under false pretexts is a crime.

    However, while cell phone companies are suing brokers and prodding federal and state regulators to take a tougher line with these companies, they aren't exactly enthusiastic about the possibility of increased regulation of their industry.

    "They don't want more rules," says Hoofnagle. "And this might be reasonable in that there could be a law saying that they must take reasonable precautions to safeguard consumers' data and if they don't do that they have to pay a fine."

    Both the FTC and the Federal Communications Commission are taking steps to curb these practices.

    Jon Leibowitz, commissioner of the FTC, said in his testimony before the House Committee on Energy and Commerce, "Protecting the privacy of consumers' data requires a multifaceted approach: Coordinated law enforcement by government agencies, as well as action by the telephone carriers, outreach to educate consumers and the industry, and improved security by record holders are essential for any meaningful response to this assault on consumers' privacy."
    Heh, I found this article interesting mostly because recently a friend of mine was a victim of something quite like this. He purchased a cell phone from a "non-reliable vendor" and they set him up with the service (was with Nextel, for more background info). However, the vendor had some form of a hack on the phone and data was recorded as was conversations. Worked in the sense of a keylogger to my knowledge (I'm not entirely sure on that, but..).

    Anyways, interesting and informative article nonetheless.
    Space For Rent.. =]

  2. #2
    Keylogger on a cell phone? Hrm...what'll they think up next? Interesting issue...buy used cell phone could put you at risk for hijacking...I suppose, not sure how. What kind of attack scenarios could be carried out? Maybe I'm not thinking clearly about this...thoughts anyone?

    Just wait for the attacks against the Treo-type of devices. 0_0

  3. #3
    The third method that data brokers use is to pay an employee of a wireless phone company to access and transfer the data.
    Happens a lot &.......


    Something to which there is no protection or safeguarding.

    In the end its the human element.

    Parth Maniar,
    CISSP, CISM, CISA, SSCP

    *Thank you GOD*

    Greater the Difficulty, SWEETER the Victory.

    Believe in yourself.

  4. #4
    Junior Member
    Join Date
    Feb 2006
    Posts
    5

    Re: Scammers Target Cell Phone Records

    When I worked for the state government, our emails were all subject to open records requests. The general rule with government email is that if you would not want to see it published in the newspaper, do not put it in an email. It seems that the same principle now applies to personal cell phones. I'm glad I only have a land line!

  5. #5
    Gonzo District BOFH westin's Avatar
    Join Date
    Jan 2006
    Location
    SW MO
    Posts
    1,187
    Originally posted here by ric-o


    Just wait for the attacks against the Treo-type of devices. 0_0
    http://searchmobilecomputing.techtar...159893,00.html


    They have already started for Blackberry...
    \"Those of us that had been up all night were in no mood for coffee and donuts, we wanted strong drink.\"

    -HST

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •