Study: ID Theft from Data Breaches Rare

By Ed Oswald | Published December 9, 2005, 12:12 PM

Detailed analysis of four separate data breaches involving a half-million identities indicates that misuse of the information could be lower than what some may expect. Identity risk management firm ID Analytics announced the results of the findings on Thursday.

Research suggests the level of the breach and how the data was lost contribute to the risk factor. For example, the firm separated the incidents into two categories, "identity-level," where names and social security numbers were stolen, and "account-level," where account numbers were stolen, occasionally tied to accountholders.

The study found that identity-level breaches pose the greatest risk. However, even here less than 1 in 1,000 identities were used for fraudulent purposes.

Fraud experts with the firm surmised that the reason for the low rate of misuse is likely due to the amount of time it takes to actually commit identity theft. Credit applications take an average of five minutes to fill out, and in order to fully utilize a file with one million identities it could take a half-century to do so, researchers say.

ID Analytics also suggested that notification of breaches seemed to slow use of that data for the purposes of identity theft. In any case, the firm says the study will help companies figure out how to best deal with the problem, and who is most at risk.

"The risk to consumers and businesses varies considerably based on the type and scope of the data breach, which is why we think assessing the degree of risk for a given breach is critical to determining the best next steps," said Mike Cook, ID Analytics' co-founder and vice president of product.

"The good news is not only that we have technology that can measure the risk of a breach, but that we can actually distinguish which sets of breached data are actively being used to commit fraud."

Comments

View comments by with a score of at least

It's becoming more accepted that the internet/online shopping isn't the big culprit in ID/CC theft. I first heard this on NPR and then on 20/20 not too long ago. Think of it - if your CC# is stolen/misused, the first thing you think of is some internet transaction you made. Well, why not think about the hundreds of times you've used your card to buy gas, groceries or food at a restaurant? After all, at a restaurant you give your CC to the waiter and he disappears for 10 minutes! What happens during that time? ALOT COULD happen - he could have a cardreader in the back, or just simply write down all the information on the card. Theft is probably alot more complicated than this, but I have more confidence in shopping online (on my own PC mind you) than handing my CC to a stranger.

Score: 0

|

While I haven't had my identity used (yet) when stolen, my credit card number sure were. I've had CCs stolen three times from venders with on-line servers. Why go to all the trouble setting up new cards and credit lines, when the victim's are waiting for use.

Score: 0

|

Finally some good news about this for a change. I'm still only sparingly using the web for buying things, and only when the website allows me to disable cookies on it when I make the purchase.

Score: 0

|

Mark Russinovich on MinWin, the new core of Windows

The next version of Windows three years hence will likely build onto a significant architectural change implemented in Windows 7 and Server 2008 R2.

Security firm: Windows patches not responsible for 'Black Screen of Death'

On second thought, maybe that access control list thingie with the lockdown something-or-rather didn't trigger an alleged, perhaps non-existent, pandemic.

My Windows 7 confession (and why you should confess, too)

I've held back the real reason for sticking with Windows 7, even as, gulp, iLife calls me to go back to the Mac.

Apple settles with Psystar except for 'circumvention devices'

The fracas with the Florida clone computer maker might have ended today had Apple not have muddled the issue over a cheap piece of Psystar software.

Google begrudgingly adjusts news crawling for paid publishers

If publishers want to make readers pay for news content, and thereby drive down its popularity and Google ranking, the company says, they can just go right on ahead.

Fee or free? Murdoch, Huffington square off over the cost of Internet news

Participants in an FTC workshop yesterday witnessed the two extremes of the Web news publishing debate, still centered on the issue of long-term profitability.

Microsoft denies latest 'Black Screen of Death' claims

After an anti-malware producer announced a fix to what it says is a swarm of recent KSoD problems, evidence of the swarm itself has yet to turn up.

Latest Firefox 3.6 beta fixes 133 bugs, promises faster page load times

A once-sluggish beta testing process has kicked into overdrive, with astonishing success at finding serious bugs. Will Mozilla be able to fix all the others in time?

Confirmed: Office 2010 to ship in June

Two weeks after Microsoft had been expected to draw a clearer roadmap for its principal applications suite, it's finally ready to commit to the end of H1.

New EU antitrust commissioner will oversee Microsoft, Oracle+Sun, Intel issues

As one of Europe's most prominent politicians shifts positions in January, her replacement remains a question mark over technology's biggest issues.

Without its own 'iTablet' yet, is Apple missing the boat?

Steve Jobs is on record as dissing "single-purpose" devices like e-readers. But given their recent popularity, was that a mistake?