Do Identity-Theft Protection Services Work?

Identity-theft protection services are a hot topic in security circles. Do these services work? Should you use them?

By Nick Mediati, PC World |  Security, identity theft, privacy Add a new comment

Todd Davis is best known as the CEO of identity-theft protection company LifeLock who used his own Social Security number in his company's advertising as a sign of his confidence in the service. In May, it was widely reported that Davis's identity had been stolen at least 13 times. The controversy over LifeLock's advertising ultimately cost the company $12 million in fines.

Granted, most of us won't plaster our Social Security numbers all over billboards. But real threats exist out there, and it is important to protect your identity. Are online identity-protection services worth the cost? Can you trust them? Are there more-effective ways to protect your personal information without the services of a specialized company? We did some digging, and here's what we found.

How Identity Theft Works

Criminals can steal your identity through a variety of ways, including phishing scams, malware on your PC, and even rooting through your trash for sensitive paper documents. You can defend yourself against such attacks by keeping an eye out for phishing tactics, running antimalware utilities, and shredding documents.

One method of identity theft that you can't directly guard against is a data breach against a company--such as a bank--that you do business with. According to the Identity Theft Resource Center, 498 such breaches occurred in 2009. Often criminals will sell personal information harvested from data breaches to other crooks on online black markets. Criminals could use your identity for anything from opening bank or credit card accounts to seeking medical care using your name.

To make matters worse, laws requiring companies to disclose data breaches are spotty: Some states have tough reporting laws, but no national standard exists. In other words, you could do everything right, and still have your identity stolen without realizing it. No wonder there's a market for identity-theft protection services.

What ID Protection Services Do (and Don't Do)

Identity-theft protection services typically monitor your credit or public records for any suspicious charges, or offer other identity-theft safeguards, for a monthly fee. In some cases they provide services to help clean up the mess left behind in the wake of identity theft and assist in rebuilding your credit. Banks frequently offer several degrees of identity-theft protection to their customers, as well.

You won't find any hard and fast guidelines about what to look for if you decide to buy into an identity-theft protection service. "Consumers need to do their homework," says Jay Foley, executive director with the Identity Theft Resource Center. Before signing up, you should ask what these companies offer, and evaluate whether their services fit your needs.

According to Privacy Rights Clearinghouse, identity-theft protection services don't monitor certain types of identity theft, such as prior instances of identity theft, Social Security number fraud (a point of contention with the LifeLock advertising), debit/check card fraud, criminal identity fraud (that is, a criminal assumes your identity when arrested), and medical fraud (a criminal assumes your identity when seeking medical attention). Paul Stephens, director of policy and advocacy with Privacy Rights Clearninghouse, notes that these sorts of crimes "are more difficult to recover from than financial identity theft."

Privacy Rights Clearninghouse provides a list of the sorts of services you should look for in an ID-theft protection service. In particular, you should determine what sorts of credit-monitoring services the company provides (which credit bureaus it gets reports from, how often it obtains reports, whether you can have unlimited access to your credit reports and scores), whether the company provides services you can't do by yourself or find elsewhere, and what kinds of extra services and insurance the company offers.

You should also look for whether a company performs additional identity monitoring. For example, does it track whether someone is using your address, or is receiving medical care under your name? "Do [ID-theft protection services] do more than monitor your credit? If they can say 'yes,' then maybe they're worth some value," says Foley.


Originally published on PC World |  Click here to read the original story.

ITworld LIVE

SecurityWhite Papers & Webcasts

Webcast On Demand

Seven Deadly Sins of Cloud Security (Video)

As cloud computing gains popularity, too few people are aware of the security threats that are emerging. In this short video, experts from HP discuss the latest cloud security threats and explain measures to help overcome them. Hear about the seven deadly sins of cloud security and learn how to avoid becoming a victim of poor security in your cloud environment.Intel and the Intel logo are trademarks of Intel Corporation in the U.S. and/or other countries.

Sponsor: HP & Intel

White Paper

Establishing a Strategy for Database Security is No Longer Optional

The options for securing increasingly valuable databases are very broad and deep, and can be confusing. This research provides an overview of three categories of controls that should be implemented to ensure that enterprise data is protected in the most efficient and effective manner.

White Paper

Database Activity Monitoring Is Evolving

Read the analyst report and learn how you can leverage the core capabilities of a DAP solution for better database security.

White Paper

Protecting Against Database Attacks and Insider Threats: Top 5 Scenarios

Read this new eBook to learn the top five scenarios and essential best practices for preventing database attacks and insider threats.

Webcast On Demand

Distributed Database Security with Real-time Monitoring

View this demo and learn how IBM InfoSphere Guardium database activity monitoring can help protect your sensitive data in distributed DBMS environments with a holistic approach to data security and compliance.

Sponsor: IBM

See more White Papers | Webcasts

Ask a question

Ask a Question