What it's like to steal someone's identity

By Joan Goodchild, CSO |  Security, identity theft, pen testing Add a new comment

Chris Roberts, founder of One World Labs, too often meets people who assume they have nothing worth stealing. His Colorado-based consultancy assists businesses with security assessments, including what Roberts calls "the human side of pen testing." In other words, he helps organizations find out which employees pose a security risk because they're likely to fall prey to social engineering traps and other cons.

"So many people look at themselves or the companies they work for and think, 'Why would somebody want something from me? I don't have any money or anything anyone would want,'?" he said. "While you may not, if I can assume your identity, you can pay my bills. Or I can commit crimes in your name. I always try to get people to understand that no matter who the heck you are, or who you represent, you have a value to a criminal."

As part of his penetration testing services, Roberts is sometimes called on to penetrate the identity of an individual to find out just how easy it is to get sensitive information. He explains how quickly it can be done by detailing a recent assignment.

Chris Roberts: We conducted a test on a high-net-worth individual. We were engaged to see what their profile was like online and what we could find out about them. We were asked to do it by the physical security guards looking after that person.

Also read The 6 things you need to know about executive protection

This person traveled a lot in Hollywood circles, so there was a lot of media data out there about him, but it was well-controlled and well-looked-after data. We started looking for more. Fairly quickly we found an e-mail address. It was a somewhat obscured address, but not very well obscured. So we searched for the e-mail address online were able to find a telephone number because he had posted in a public forum using both. On this forum, he was looking for concert tickets and had posted his telephone number on there to be contacted about buying tickets from a potential seller.

The phone number turned out to be an office number. Now we have the office number and an e-mail. We easily figured out where the office was located and phoned up and used a bit of social engineering. We posed as a publicist and said we needed to get a hold of him. Using some information we got on the Web, we got the office to give us his personal cell phone number.

Now I have a cell phone number, an office number, and an e-mail address. I managed to do some more research and got an address which corresponded to a very nice house. Now I know the house, so I can pull public records on the property. I found out who the mortgage was with and now I have some of the mortgage data. I call the mortgage company and, using some of the information I have, I get them to give me even more information.

We then ran a LexisNexis report, and a few other reports, on this person and fairly quickly we had their Social Security number. He is married and has kids. So we then did a lot of digging around at a few of the local schools pretending to be this person's secretary. We found out where the kids went to school.

From there we had one of our guys go around and do a Bluetooth assessment and see if you we could pick up any other information. We were able to pull a Bluetooth signal from the residence. Now we can drop some software on it, monitor where he is, match the GPS tracking, listen to his calls and conversations.

Now we know his e-mail, his office and cell number, his home address, his mortgage information, his Social Security number, where his kids go to school and how to monitor his calls and comings and goings. It took us half a day to do this work and I essentially own this person. I own him and can do whatever I want with him. I could go open up bank account in his name, assume his identity or act on his behalf, say to reserve a suite at a hotel.

Once we had their information, identity and bank account, we realized we could go on a spending spree. However, both of us working on this account realized not only that we didn't look like the person, but we also were aware that his own security team knew us and where we were. We spent about 20 minutes laughing about buying an island somewhere in the middle of nowhere, having the Ferraris shipped out and getting a large stash of weaponry to defend our ill-gotten-gains!


Originally published on CSO |  Click here to read the original story.

ITworld LIVE

SecurityWhite Papers & Webcasts

Webcast On Demand

Seven Deadly Sins of Cloud Security (Video)

As cloud computing gains popularity, too few people are aware of the security threats that are emerging. In this short video, experts from HP discuss the latest cloud security threats and explain measures to help overcome them. Hear about the seven deadly sins of cloud security and learn how to avoid becoming a victim of poor security in your cloud environment.Intel and the Intel logo are trademarks of Intel Corporation in the U.S. and/or other countries.

Sponsor: HP & Intel

White Paper

Establishing a Strategy for Database Security is No Longer Optional

The options for securing increasingly valuable databases are very broad and deep, and can be confusing. This research provides an overview of three categories of controls that should be implemented to ensure that enterprise data is protected in the most efficient and effective manner.

White Paper

Database Activity Monitoring Is Evolving

Read the analyst report and learn how you can leverage the core capabilities of a DAP solution for better database security.

White Paper

Protecting Against Database Attacks and Insider Threats: Top 5 Scenarios

Read this new eBook to learn the top five scenarios and essential best practices for preventing database attacks and insider threats.

Webcast On Demand

Distributed Database Security with Real-time Monitoring

View this demo and learn how IBM InfoSphere Guardium database activity monitoring can help protect your sensitive data in distributed DBMS environments with a holistic approach to data security and compliance.

Sponsor: IBM

See more White Papers | Webcasts

Ask a question

Ask a Question