Frank Abagnale, world-famous con man, explains why technology won’t stop breaches

pretend.jpg

Frank Abagnale is world-famous for pretending to be other people. The former teenage con man, whose exploits 50 years ago became a Leonardo DiCaprio film called Catch Me If You Can, has built a lifelong career as a security consultant and advisor to the FBI and other law enforcement agencies. So it’s perhaps ironic that four and a half years ago, his identity was stolen—along with those of 3.6 million other South Carolina taxpayers.

“When that occurred,” Abagnale recounted to Ars, “I was at the FBI office in Phoenix. I got a call from [a reporter at] the local TV news station, who knew that my identity was stolen, and they wanted a comment. And I said, ‘Before I make a comment, what did the State Tax Revenue Office say?’ Well, they said they did nothing wrong. I said that would be absolutely literally impossible. All breaches happen because people make them happen, not because hackers do it. Every breach occurs because someone in that company did something they weren’t supposed to do, or somebody in that company failed to do something they were supposed to do.” As it turned out (as a Secret Service investigation determined), a government employee had taken home a laptop that shouldn’t have left the office and connected it—unprotected—to the Internet.

via: Catch me if you can

Sary thing here is that even medical records can be obtained via social engineering.  What do you really need, a name, birth date?  If you have enough information and a phony ID you can get medical services in someone else’s name.  This article is an excellent read.