Jump to content

4 posts in this topic

Recommended Posts

Filed: Country: Belarus
Timeline
Posted

IN AN INSTANT, RETIREMENT SAVINGS VANISH

Posted: Friday, January 5 at 04:00 am CT by Bob Sullivan

One moment Dave DeSmidt had $179,000 in his 401(k) retirement account, the next he had nothing. In an instant, 25 years of savings had disappeared.

With a few clicks, someone raided DeSmidt’s retirement account with J.P. Morgan & Co and ordered a full disbursement to a private checking account.

Then came the really bad news. While credit card and online banking accounts are legally protected in the event of fraud, DeSmidt’s brokerage account came with no such insurance. Two months after the theft, his balance still read $0.

With hacking of brokerage accounts increasing, the legal gap facing DeSmidt and other victims has regulators and critics debating the need for new consumer protections.

‘I don’t have a clue’

The theft was the shock of a lifetime for DeSmidt, who plans to retire in a few years with his wife in their Mukwonango, Wis., home.

"That was a pretty good chunk of what we were going to retire on," DeSmidt said. "I don't have a clue how it happened."

The theft occurred on Oct. 23, while DeSmidt was on assignment for his company in China, near Shanghai. Just before lunch, someone else logged onto J.P. Morgan's Web site from a computer connected to the Internet through Comcast Cable Communications in Cherry Hill, N.J., and entered DeSmidt's user ID and personal access code.

While DeSmidt slept on the other side of the world, his imposter found that he had a balance of $179,000.43 in his account. A few more clicks, and the DeSmidts’ linked checking account was changed to a Bank of America account and an electronic transfer of all available funds was requested.

A report by J.P. Morgan suggests the criminal was a bit anxious, perhaps disbelieving the good fortune of hacking such a valuable account. The imposter logged in again from the same computer 41 minutes later, at 1:06 p.m., and again at 11:30 p.m. to review the pending transaction.

The next day, the money was sent to Bank of America. The name on the checking account didn't match the name on the 401(k) account, but that discrepancy didn’t raise a red flag high enough to halt the transfer.

DeSmidt didn't know it yet, but a quarter century worth of savings and investment gains had just disappeared.

The theft wasn’t tax-efficient. Since DeSmidt isn't yet of retirement age -- he’s 57 -- there were severe penalties for the early 401(k) withdrawal, and J.P. Morgan held back about $35,800.09 to pay these taxes. Still, it was a good day's work for the hacker. The company sent the remaining balance -- $143,200.34 -- to an account under his or her control.

SEC: Brokerage attacks ‘on the rise’

Computer criminals have made the logical progression from credit card fraud to online bank attacks and now to big-ticket brokerage accounts, analysts say.

Hacker attacks on brokerage accounts make sense from a criminal’s point of view. Brokerage accounts tend to have higher balances, making them worthwhile targets. And while a six-figure transfer out of a checking account would surely trigger fraud pattern detection software, large transfers from brokerage accounts are fairly standard.

John Reed Stark, chief of the Securities and Exchange Commission’s Office of Internet Enforcement, acknowledged that online brokerage hacking is “on the rise” and warned of possible consequences for consumers.

With simple credit card fraud, customers need only call their bank and refuse to pay for an item, he said, but brokerage account hacking is much more dramatic.

“People need to understand this kind of fraud,” Stark said. “This is very serious stuff. … People wake up in the morning, look in their account, and their money is all gone.”

Stark said any consumers who have encountered brokerage account fraud should contact his office for assistance at enforcement@sec.gov.

Covering tracks

Criminals who target brokerage accounts clearly know their craft. A day after successfully transferring DeSmidt’s money out of the 401(k) account, the hacker started trying to cover his or her tracks.

On Oct. 25, logging in through an SBC Internet Services connection in San Francisco, the criminal deleted the Bank of America account information from DeSmidt's account. Four hours later, using a Cox Communications connection out of Atlanta, the hacker re-entered DeSmidt's original checking account information. Other than the zero balance, there were no obvious signs remaining of the hacker’s visits.

A few days later, DeSmidt checked his retirement balance online, as he does regularly, and spotted the theft. Then the paperwork nightmare began.

"This has been very stressful,” he said. “My wife is going crazy."

A flurry of e-mail, faxes and registered letters followed. JP Morgan ordered an investigation, and sent the results to DeSmidt on Dec. 1.

"J.P. Morgan concludes there was no external or internal breach of controls with the J.P. Morgan environment," the report said. "Access and authentication controls established within J.P. Morgan worked appropriately."

The report dismissed the possibility that the crime was an inside job, as the request came from outside computers and the criminal knew DeSmidt's user name and password.

The report's conclusion: "Investigation Status: Closed."

It wasn't clear to DeSmidt what that meant; the firm never said it wouldn't issue a refund. But he was stuck in limbo, awaiting further instructions.

Promised a refund

Two more weeks passed, and DeSmidt started to fear his retirement money was indeed gone for good. By the time he contacted MSNBC.com, he said he had written to every government agency he could think of to no avail and hadn’t been able to find a lawyer willing to take his case.

"I can find lots of attorneys that will defend me if I am the one accused of the crime," he wrote.

DeSmidt's story, however, had a happy ending.

When MSNBC.com contacted J.P. Morgan, the firm said its continuing investigation had borne fruit. Spokeswoman Mary Sedara said the stolen funds had been recovered and would be refunded in time for Christmas. The firm would even make good on any market gains DeSmidt missed out on while the money was missing, she said.

The story didn't have to end this way, though.

Few consumers appreciate the fact that, unlike credit card and checking account transactions, there are no federal consumer regulations specifically protecting consumers in the event of brokerage account hacking, said Gartner fraud analyst Avivah Litan. And with hackers targeting investment accounts more frequently, the legal loophole could leave investors with some ugly surprises.

'They need to protect the assets'

"This should be a call to action for the regulators," she said. "They are never going to protect against all the (criminal) methods. They need to protect the assets."

Both credit card transactions and electronic account transfers, such as online banking payments, are governed by Federal Reserve regulations that strictly limit consumers’ losses from theft. Consumers who report credit card fraud are only liable for $50; liability for fraudulent checking account transfers is capped at $500 if the consumer reports the theft within 60 days. Refunds for checking account thefts must generally be issued within 10 days.

The regulations are designed to boost confidence in the systems. But the Federal Reserve doesn't regulate investment firms, and the Securities and Exchange Commission doesn't mandate any similar protections for brokerage accounts.

And Desmidt's tale is hardly an anomaly. Last year, several trading firms revealed they were hit by hackers. E-trade, for example, reported in October that it had lost $18 million to crime rings based in Eastern Europe and Thailand.

Despite the lack of legal compulsion, some investment firms have taken to offering broad consumer protections anyway. Both e-trade and Charles Schwab offer credit-card style guarantees. Money stolen from Charles Schwab's Web site will be returned to consumers as long as the theft is reported in a timely way, said Schwab's Greg Gable.

'We want people to feel secure'

"There is a fundamental business need to do it," Gable said. "We don't want clients concerned about the safety of their assets. … We want people to feel secure."

Gable wouldn't say how many Schwab customers had asked for theft refunds, saying only such cases were "very rare."

Stark said that in every recent case of brokerage hacking he’s familiar with, consumers who complained have received full refunds. But the largesse is voluntary – unless the brokerage makes a clear promise like Schwab or e-Trade -- and it may not last forever.

“Firms are reimbursing everyone (who) has that kind of loss,” he said. “But they didn’t always do that (and) I don’t know how long they can continue doing it.”

Brokerage account hijacking has the attention of regulators, but at the same time criminals are getting cleverer. In late December, the SEC moved to stop a pump-and-dump scheme involving an Estonian firm.

The SEC said the firm's Russian owner earned $350,000 by purchasing penny stocks, then hacking into other investors' accounts and purchasing large blocks of the stock before selling his own shares at inflated prices.

Web-based investing scams have DeSmidt's attention, too. He is grateful JP Morgan promised to return his funds, but he's not about to let lightning strike twice. He told the company to shut down Web access to his accounts.

"I prefer to keep the account access only over the telephone for now," he said.

http://redtape.msnbc.com/2007/01/one_moment_dave.html#posts

"Credibility in immigration policy can be summed up in one sentence: Those who should get in, get in; those who should be kept out, are kept out; and those who should not be here will be required to leave."

"...for the system to be credible, people actually have to be deported at the end of the process."

US Congresswoman Barbara Jordan (D-TX)

Testimony to the House Immigration Subcommittee, February 24, 1995

Filed: Country: Philippines
Timeline
Posted

That is scary and I'm glad that JP Morgan says they'll recover his 401K. Whether there are laws on the books or not - a brokerage who has your money should be responsible against theft. We shouldn't have to worry about things like this.

Filed: IR-1/CR-1 Visa Country: Peru
Timeline
Posted

What's really ignorant about banking laws/procedures--is that I took a loan against my 401K a paper check was sent to me at my home address after thrice confirming who I was and what I wanted with my 401K Administrator: Web, Phone, and written confirmation of a loan amount--about $18,000. So then I go to Bank of America where my account has been for years with several forms of picture ID and drivers license and bank account that matches my name and address exactly as it appears on the 401k check. Anyway--the bank clerk put my $18,000 check on-hold and would only allow me to have access to $1,800 of the balance--for 30 days. So it seems the system is still geared to the old bonnie and clyde/catch me if you can type robberies--where as a real sophisticated individual can get off scott free with 140K of someone else's money to an account that does not even match. I think JP Morgan and Bank of America should reimburse this guy--and maybe Comcast too.

squsquard20060929_-8_HJ%20is.png

dev216brs__.png

In accordance with Georgia law, "The Georgia Security and Immigration Compliance Act," I am required to display the following in any and all languages that I may give immigration related advise:

'I AM NOT AN ATTORNEY LICENSED TO PRACTICE LAW AND MAY NOT GIVE LEGAL ADVICE OR ACCEPT FEES FOR LEGAL ADVICE.'

"NO SOY ABOGADO LICENCIADO PRACTICAR LEY Y NO PUEDO DOY ASESORAMIENTO JURÍDICO O ACEPTO LOS HONORARIOS PARA El ASESORAMIENTO JURÍDICO."

hillarymug-tn.jpghillarypin-rwbt.jpgballoons-tn.jpg

 

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
- Back to Top -

Important Disclaimer: Please read carefully the Visajourney.com Terms of Service. If you do not agree to the Terms of Service you should not access or view any page (including this page) on VisaJourney.com. Answers and comments provided on Visajourney.com Forums are general information, and are not intended to substitute for informed professional medical, psychiatric, psychological, tax, legal, investment, accounting, or other professional advice. Visajourney.com does not endorse, and expressly disclaims liability for any product, manufacturer, distributor, service or service provider mentioned or any opinion expressed in answers or comments. VisaJourney.com does not condone immigration fraud in any way, shape or manner. VisaJourney.com recommends that if any member or user knows directly of someone involved in fraudulent or illegal activity, that they report such activity directly to the Department of Homeland Security, Immigration and Customs Enforcement. You can contact ICE via email at Immigration.Reply@dhs.gov or you can telephone ICE at 1-866-347-2423. All reported threads/posts containing reference to immigration fraud or illegal activities will be removed from this board. If you feel that you have found inappropriate content, please let us know by contacting us here with a url link to that content. Thank you.
×
×
  • Create New...