FREE NEWSLETTER

Articles › Abuse

For Safety’s Sake

ON JUNE 15, THE NEWS was broken by The Oregonian of a massive hack at Oregon’s Department of Motor Vehicles, apparently leading to the theft of sensitive details about most of Oregon’s 3.5 million holders of a driver’s license or ID card. Incidents like this, along with the huge 2017 Equifax hack, give criminals cheap and easy access to key personal information that many organizations routinely use to verify our identities and screen our credit applications.

That kind of data make it a breeze for crooks to appropriate your identity for the purpose of opening credit accounts in your name. It also makes it simple for criminals to open a bank or investment account in your name, one which they control and which could potentially be linked to your existing, legitimate accounts. Once linked, they quickly transfer out funds you might never see again.

I’ll wager more than a few HumbleDollar readers and authors, as well as folks they know, have been victims of crimes involving identity theft. Cybercrime today seems unstoppable, but the worst thing you can do is ignore the risk and hope you won’t be affected. Hope is not a plan.

My daughter, an Oregon resident, just asked me what she could do to protect her identity, money and sensitive accounts from security breaches. My response: Three simple steps can help you avoid the worst consequences of identity theft and an assortment of cybercrimes.

1. Freeze your credit reports at Equifax, Experian and TransUnion until you next need credit. It’s been nearly a decade since I froze ours at the big three credit reporting companies, after a security incident at a nonprofit where we volunteered regularly. Today, it’s simpler to both freeze and temporarily unfreeze credit files when you need access to credit. While your files are frozen, it’s much harder for someone to use your stolen identity to open a fraudulent account in your name.

2. Enable two-factor authentication (2FA) on all sensitive online accounts. This technology makes it extremely difficult for thieves to log into your account, even when they’ve guessed your password or acquired it through phishing or a big hack. There are several 2FA technologies in wide use today. Some types are more secure, but enabling any 2FA on your key accounts is far better than no 2FA at all.

The most important accounts to protect with 2FA are your Apple, Google or Microsoft ID accounts, email accounts which receive password reset links, cellular service provider accounts, and banking or investment accounts.

3. Check your bank and brokerage balances monthly, and your credit reports annually. When you suffer an identity theft crime, your chances of recovering any lost money, or reversing unauthorized credit account charges, rise a lot if you catch and report it early, as one couple learned.

Yes, if you want to improve your investment behavior, it’s best to automate your financial life, so you can ignore what Mr. Market is doing each day to your investments, as Rick Connor noted recently. Still, for security purposes, it’s wise to glance monthly at your accounts to see if there’s been a sudden, unexpected drop in your balance or some other suspicious activity. To check for fraudulent new accounts, it’s also good to review your free credit reports each year.

More On This Topic

Email Alerts for this Comment Thread
Notify of
12 Comments
Newest
Oldest Most Voted
Thomas Taylor
3 years ago

Thanks for the tips. It’s one of those tasks we shouldn’t have to do, but the “black” hats always seem to be steps ahead of the game. Like you, I froze my credit reports years ago. Whenever 2FA is available, I’ll set it up. I wish a few more financial companies I use would do it, but it seems to be getting better. I do check our bank account more frequently than once a month, but I keep to a monthly schedule for credit cards and investment accounts. Some of the other readers’ tips were good as well and some I hadn’t thought of before. I believe the big 3 credit reporting companies are still offering a free weekly report through the end of 2023.

tshort
3 years ago

These are some great tips. Having had our credit card compromised twice in the last year, I’d also add the following to protect that form of hacking/theft:

  1. At gas pumps, if a no-contact payment option at the pump is available use it. Avoid swiping your card on the pump, as this is where thievery happens via credit card skimmers.
  2. When using a free public Wi-Fi network (airports, train stations, etc), use a VPN on your mobile device to cloak your identify. These can be purchased by subscription by the month or by the year and are easy to use. I’ve used SurfShark in the past and it does the job for a few dollars. If you don’t use a VPN, I recommend never logging into any financial accounts or entering your credit card number on your mobile device while connected to a public Wi-Fi network.
Sharon Edwards
3 years ago

Do you have suggestions for how to use 2FA on joint accounts? And in the event of one account owner passing? And in the situation where one account owner not being as “tech savy” as another?

David Powell
3 years ago