How to Prevent Business Identity Theft: A Houston Owner's Guide
Most of us have spotted a fraudulent charge on a credit card statement at some point. It wasn’t your purchase, but you still had to jump through hoops to get it removed: real time, energy and frustration for something you didn’t even do. Now imagine that, but multiplied across your whole life and your whole business. That’s identity theft, and it’s one of the most dangerous cyberattacks a Houston business can face.
This post is adapted from Chapter 8 of my book, Protecting Your Business Against Hackers. If you’d rather read the whole thing, you can download the full book here.
What Business Identity Theft Actually Looks Like
A single fraudulent charge is annoying. A stolen identity is something else entirely. When a criminal gets hold of your information, you’re not facing one bad charge; you’re facing everything: your Social Security number, your business ID number, access to your personal and business bank accounts, even your retirement accounts. Your personal and business credit cards can be maxed out. If a thief has your debit card details, your checking account can hit zero in no time.
And it gets worse than money. You could lose your client database, your financial records, and every work file your company has ever produced. Think about what would happen to your business if, one day, the money you use to make payroll or pay vendors was simply gone.
There’s an even darker version of this. What if a criminal stole your identity to commit other crimes in your name? It happens. Could your business survive a news story about how you or your company ripped off hundreds of people? In the eyes of the media, your customers and your competitors, “innocent until proven guilty” doesn’t always apply.
The numbers are sobering
The financial impact is hard to pin down to the dollar, but it’s real, and the emotional toll lands on you personally, which always ripples into the business. A few statistics worth sitting with:
- 40% of consumers worldwide have been targeted for identity theft.
- There were 16.7 million identity theft victims in the US in 2017, totaling $17 billion in losses.
- In the first half of 2018 alone, roughly 8 million records were stolen per day, adding up to 3.3 billion compromised records.
But the most telling number is time. It takes the average identity theft victim more than 600 hours to clear their name and clean up the fraud. That’s nearly three months of full-time work. Can you afford to drop everything and spend three months getting your money back and defending your reputation? Almost nobody can.
Why Small Businesses Are More Vulnerable
With technology changing constantly and new threats appearing daily, it takes a highly trained technician to secure even a basic network for a small team. Yet to save money, a lot of businesses try to handle IT in-house: they hand the job to whoever is “most technical” and call them the part-time IT manager.
That rarely works. This makeshift IT person already has a full-time job to do, and usually isn’t equipped to properly support an entire network. The result is a network that’s poorly maintained and unstable, where backups, virus updates and security patches fall behind. That gives you a false sense of security right up until a hacker finds the gap.
This is exactly the problem we exist to solve for Houston companies with 10 to 200 employees: you get a real IT team without having to build one on your payroll. (See our cybersecurity services page for how the layers fit together.)
How Online Identity Thieves Get In
Some identity theft still happens the old-fashioned way: a stolen wallet, an overheard phone call, a raided filing cabinet. Common sense handles a lot of that: lock your cabinets, don’t discuss financial details in public. Internet threats are more sophisticated. There are four basic ways criminals get at your information online:
- Phishing. Scammers send spam or pop-ups that look like legitimate messages from your bank or credit card company, usually with a link asking you to “update” your information. The fake site can be a perfect replica, but entering your details hands over the keys to the kingdom.
- Tech support scams. Someone calls claiming to be a tech from a well-known company like Microsoft, says they’ve found a virus, and pressures you into granting remote access or paying for software you don’t need. The real goal is your money, and sometimes remote tools that capture your keystrokes and logins.
- Email scams. Offers, slick sales pitches, links to “informational” sites. The classic “Nigerian” scam promises to move a fortune into your account if you cover some fees first; the catch is there’s no fortune, just escalating “emergencies” that drain you. A common modern variant: the “boss” emails an employee to buy gift cards as client gifts and send over the codes, straight to a scammer.
- Spyware. Software installed without your consent to monitor your computer. Warning signs include a barrage of pop-ups, a browser that redirects to sketchy sites, unexpected toolbars, random errors and sluggish performance. Sometimes there are no symptoms at all.
Four Ways to Protect Your Company from Identity Theft
You can’t plan for every scenario, but a little proactive planning and proper network precautions will prevent or greatly reduce the vast majority of identity theft you’d otherwise face. Here’s where I tell every owner to start.
Step 1: Encrypt your backups
It amazes me how many businesses run backups with no encryption. Encryption scrambles every keystroke and every piece of data into dozens or hundreds of other characters, a single letter “A” can become 256 different characters, so a hacker who gets the data can’t read it. Without encryption, you’re leaving your identity and your most important data wide open. Make sure your backups are properly secured.
Step 2: Keep virus protection always on and current
You’d have to be living under a rock not to know how devastating a virus can be. Attacks come through spam, downloads, instant messages, websites, and emails from people you trust. A virus doesn’t just corrupt files and bring down your network: it damages your reputation. If you or an employee unknowingly spreads a virus to a customer, or it hijacks your email address book, you’ll make a lot of people very angry. Up-to-date protection isn’t optional.
Step 3: Set up a firewall and update it regularly
The “we’re just a small business, no one would bother” mindset is exactly what gets companies hit. There are thousands of people who think it’s fun to steal your information simply because they can. They strike randomly, scanning the internet for open, unprotected ports. Find one, and they can delete files, dump huge undeletable files onto your drive, or turn your computer into a “zombie” for storing pirated software or sending spam, which can get your ISP to shut you down entirely.
Step 4: Apply critical security patches as they’re released
If you don’t have the latest security patches and virus definitions installed, attackers can get in through something as simple as a banner ad or an email attachment. Here’s the part most owners don’t realize: most hackers don’t find these loopholes themselves. They learn about them when Microsoft or another vendor announces the vulnerability and issues a fix. That announcement is their starting gun: they reverse-engineer the update and build an exploit for every network that hasn’t patched yet. The window between the fix and the exploit gets shorter every day, so you need a process that applies critical updates fast.
Frequently Asked Questions
What is business identity theft?
It’s when a criminal steals the information that identifies you and your company: Social Security number, business ID number, bank and credit card access, and uses it to drain accounts, run up charges, or even commit other crimes in your name. Beyond the money, you can lose client databases, financial records and work files, and you may spend hundreds of hours clearing your name.
Why would a hacker target my small business?
Because smaller companies often have weaker defenses, especially when IT is handled part-time by whoever happens to be the most technical person on staff. Attackers frequently strike at random, scanning the internet for unprotected networks rather than picking targets by size or industry. Convincing yourself you’re too small to bother with is one of the reasons there’s a target on your back.
How do criminals usually get my information online?
Four main ways: phishing emails and pop-ups that impersonate your bank, tech support scams over the phone, email scams like fake transfers or gift-card requests, and spyware installed without your knowledge. Most of these rely on tricking a person rather than breaking through technology, which is why training and good defenses matter together.
What’s the single most important technical step I can take?
There isn’t one silver bullet. The four steps work together. Encrypted backups, current virus protection, a maintained firewall, and a real patching process each close a door that attackers count on finding open. Skip any one and you leave a gap. The good news is none of this has to be complicated when you have the right team handling it.
Ready to Close Your Gaps?
Identity theft is one of today’s most dangerous cyberattacks, but proactive planning makes a formidable defense. If you’re a Houston business owner who wants to know exactly where your gaps are, let’s talk. Book a free discovery call, request a cybersecurity risk assessment, or call us in Houston at 281-367-8253.