Showing posts with label identity theft. Show all posts
Showing posts with label identity theft. Show all posts

Thursday, September 8, 2022

How to Inventory and Protect Your Digital Assets

Digital assets are any personal information stored electronically on any electronic device (e.g., laptop, tablet, cell phone) or “cloud” server. 

Many people have dozens, even hundreds, of digital assets that can be worth tens, if not hundreds, of thousands of dollars (e.g., bank and brokerage accounts, cryptocurrencies, and retirement savings plans).

The best way to determine how many digital assets you have is to identify them by general category (e.g., online retailer accounts and financial accounts) and then prepare a detailed inventory. 

The best way to determine their value is to prepare a net worth (assets minus debts) statement that includes digital assets with monetary amounts.

A digital assets inventory is a detailed list of digital assets along with their username, password, or other identification information (PIN number, challenge question responses). 

This list should be reviewed and revised periodically and shared with trusted individuals who are named in legal documents to manage your affairs. Also make sure that digital assets are referred to in estate planning documents (e.g., will or trust) with a named digital asset executor.

Below are examples of items that fit in each of 12 digital asset categories:

Electronic Devices- This category includes smart phones, tablets, laptop and desktop computers, flash drives, and external hard drives.

Benefit Accounts- This category includes rewards programs for various airlines and hotels, railroad miles, and retailer rewards or loyalty programs.

E-Mail Accounts- This category includes login information for various e-mail programs including Gmail, Yahoo!, Microsoft Outlook, AOL Mail, ProtonMail, and Zhou Mail.

Financial Accounts- This category includes bank/credit union accounts, brokerage accounts, retirement savings accounts, credit card accounts, employee benefit accounts (e.g., health insurance), insurance company accounts, and peer-to-peer payment apps such as Venmo and Zelle.

Online Merchant Accounts- This category includes online retailers such as Amazon, “brick and mortar” retailers’ online shopping sites, driving services such as Uber, theaters, and grocery delivery services such as Instacart.

Member Organization Accounts- This category includes “member access” features for websites run by professional associations, charitable and religious organizations, sports season ticket providers (e.g., universities and pro teams), gated communities, and other “members only” groups.

Health Care Portals- This category includes access to personal health care information on websites run by doctors, hospitals, radiologists, health insurance companies, and Medicare and Medicaid.

Photography/Music Accounts- The category includes personal photo and music collections stored on websites such as Snapfish, Shutterfly, Google photos, Amazon Prime photos, Apple iCloud, Flickr, Google Drive, and Apple iTunes.

Publication Accounts- This category includes personal login credentials for newspaper and magazine subscribers, blogs, and other online content that requires payment to access.

Social Media Accounts-This category includes login credentials for various social media programs including LinkedIn, Twitter, Facebook, YouTube, Vimeo, Pinterest, Zoom, and Tiktok.

Cryptocurrency Accounts- This category includes account access information for cryptocurrencies and crypto exchanges such as Coinbase and crypto.com. Examples of cryptocurrency assets include Bitcoin, Ethereum, non-fungible tokens (NFTs), and stored value in online games such as Fortnite, Minecraft, and World of Warcraft,

Website Accounts- This category includes personal access to accounts maintained for website domain names and hosting services and cloud storage programs such as Apple iCloud, Dropbox, Box, And Google Drive.

In summary, don’t leave your digital assets to chance. Take the time to prepare a digital assets inventory. Benefits include:

¨    Hassle-free access to online accounts

¨    Saving time (to log into accounts) and money (e.g., legal fees and lost assets)

¨    Less stress for heirs, survivors, and fiduciaries

¨    Protecting private information and avoiding identity theft

¨    Avoiding creepy” situations (e.g., Facebook birthday reminders for dead people)


This post provides general personal finance or consumer decision-making information and does not address all the variables that apply to an individual’s unique situation. It does not endorse specific products or services and should not be construed as legal or financial advice. If professional assistance is required, the services of a competent professional should be sought.

 


Thursday, July 28, 2022

How to Keep Personal Information Safe


Widespread data hackings are increasingly common, whether it is a credit bureau (Equifax in 2017), a hotel (Marriott in 2018), an online game producer (Zynga in 2019) a federal government agency (OPM in 2015), or an Internet media company (Yahoo! in 2016). Another common scam is phone calls and e-mails claiming to be from a bank...or Social Security...or the IRS. 


In each of these cases, customers’ personal data including e-mail addresses, log-in credentials, credit card numbers, birth dates, and Social Security numbers can be compromised. There may also be fraudulent requests to wire transfer money, reveal computer login credentials, or purchase gift cards and give fraudsters the numbers above the bar code.



What to do to avoid falling prey to scams? Below are seven suggestions to protect private information and reduce your chances of becoming a fraud victim:

 

Practice Cyber Hygiene- Successful fraudsters successfully reach victims through their “weakest link.” It might be something as simple as a weak password or someone revealing TMI (too much information) online. Consider your potential fraud exposures (e.g., reusing the same password/user name combination). While nobody is 100% immune from fraud, the objective is to make yourself a harder target so fraudsters find victims elsewhere.

 

Mix Up Your Log-In Credentials- Fraudsters know that most people use the same username and password in multiple places. When they obtain personal information from a data breach or the Dark Web, they try to exploit it in multiple places using automated scripts, a process known as “credential stuffing.” It will probably take several hours to create a multitude of unique passwords. Once you are done, be sure to record them in a digital assets inventory.

 

Click Cautiously- Some people are tricked into clicking on links, or even photos, that take them to a website that requests personal data or installs malware on their computer that can be executed later to obtain sensitive data. Often, this happens as a result of a phishing e-mail. A good cyber hygiene practice is to not click on any link if you do not know the sender and/or you receive a cryptic message (e.g., check this out!) and do not know what the link is for. Another hygiene practice is using strong passwords with a variety of types of characters.

 

Set Up Two-Factor Authentication- Every personal website of consequence (e.g., bank and investment accounts, pension, Social Security) should have a two-factor (a.k.a., two step) authentication process where a unique one-time password is sent via e-mail or a text message and is necessary to access an account. Some accounts also have challenge questions that must be answered for account access. Typically, two-factor access is a very simple process to set up through the “settings” and “privacy” functions on a website. Again, it’s all about not being an easy target.

 

Freeze Your Credit- A credit freeze blocks access to credit reports to prevent fraudsters from opening credit in a potential identity theft victim’s name. It, therefore, provides an extra layer of fraud prevention protection. Freezes must be done with each of the “big three” credit bureaus (Equifax, Experian, and TransUnion) individually. They do not affect a person’s credit score and there is no cost to freeze credit or to “thaw” (unfreeze) it for a short time to apply for a bank account, line of credit, or utility service. A PIN or password is typically provided for this purpose.

 

Update Your Computer- Another piece of cyber hygiene is keeping an operating system current by installing updates as they become available. Ditto for anti-virus and anti-malware programs. Some experts also advise using a password manager program with two-factor authentication as well as strict privacy settings for social media. Another common recommendation is text alerts or e-mails from financial institutions when changes are made to an account.

 

Stay Current- Many pundits are predicting a future without passwords. Instead, there will be new authentication protocols such as facial biometric scans and fingerprint swiping. Another promising protocol is behavioral monitoring of users’ typical spending patterns to identify “out of the ordinary” behavior. “Keeping current” also means paying attention to scams that feed off current events such as COVID-19, tax season, wars, and natural disasters.

 

For more information about keeping information safe, review this Consumer Financial Protection Bureau website.


This post provides general personal finance or consumer decision-making information and does not address all the variables that apply to an individual’s unique situation. It does not endorse specific products or services and should not be construed as legal or financial advice. If professional assistance is required, the services of a competent professional should be sought.

 


Need to Knows About Section 530A Child Savings Accounts

I recently attended a webinar about a new way to save money for children: Section 530A (of the IRS tax code) accounts, which became availabl...