JEDDAH, 22 June 2007 — Susan Slowe, a resident of a tiny community near the city of Bangor in the US state of Maine, picked up the phone and was taken aback by who was on the other end of the line: a stranger’s voice claiming to be a newspaper reporter in Jeddah, Saudi Arabia.

“How did you get this number?”

“I Googled your name and it came up on a government website: Susan Slowe, county assessor for the town of Vanceboro, Maine.”

“And you’re calling from where? Saudi Arabia?”

“I know this seems strange, Ms. Slowe, but we have a picture of a credit card here bearing the name ‘Susan S. Slowe’. It showed up in the city of Jeddah, Saudi Arabia. Police arrested two men on Saturday for trying to use this card last week. I would like to confirm if you are the owner of this card.”

There was a pause and then noticeable angst in the woman’s voice after that. She had every reason to be upset. Slowe told Arab News that she received an e-mail from Bank of America regarding a $12,000 charge on June 11 originating in Saudi Arabia.

Bank of America had mailed a new card to her on June 1 but that the card never arrived. Instead, in just 11 days the card traveled to the west coast of Saudi Arabia and was used by crooks to try to buy furniture from a store off Jeddah’s main thoroughfare, Madinah Road.

Police arrested two Nigerian men in a gold souq in Jeddah on June 16 trying to use the card. During interrogation the men kept changing their story. They claimed that Susan Slowe was their sister.

“Their story smelled more and more fishy,” a Jeddah undercover police inspector told Arab News on condition of anonymity. “The question that I don’t have any answer for at the time is: Why is the card still valid?” The inspector said authorities are still looking for a Yemeni suspect who they believe was the man who used the card in the June 11 furniture-store transaction.

The answer to the police inspector’s question is that Slowe didn’t realize her card had been stolen from the mail and activated. Bank of America’s anti-fraud system blocked that charge from going through, but its unclear if the charge was blocked due to the location of the purchase or the amount of the purchase.

Would the transaction have been blocked if the crooks had made a series of smaller purchases? Bank of America officials declined to discuss matters pertaining to their security policy. Regardless, Slowe is angry that the bank allowed the people who stole her card to change her home phone number, which is a key element to activating a newly issued credit card.

“Ms. Slowe, I realize this is upsetting…”

“Of course it’s upsetting. I’ve had my identity stolen!”

After faxing Slowe a picture of her credit card to help prove to her that she was talking to a newspaper reporter she was willing to speak about her experience. (She later admitted that she called local authorities after the first phone call from Arab News and that they traced the second call to Saudi Arabia.)

“It was very simple how they stole my identity,” she said. “They snagged the card; they paid $9.95 on some background-check service on the Internet, PeopleFinder dot com or something like that. They paid the $9.95 and they got my date of birth. And all Bank of America asked for was a date of birth to verify the caller. Then (the bank) changed my home phone number and (the criminals) asked to allow international charges.”

The story of how a stolen credit card could be activated by crooks and sent 12,000 km away to be used to buy items in Jeddah begins with the activation process for newly issued cards.

The system, which was created and implemented by the US Postal Inspection Service, the government organization responsible for mail security, works this way: When a new or replacement credit card is issued in the United States it is mailed with a removable sticker on the back. The sticker has a toll-free phone number printed on it and instructions for how to activate the card. Customers must call from the home number listed on the account.

Slowe claims that the people who stole her card as it was being mailed to her were able to change the home number listed on the account by calling Bank of America.

The customer service representative at Bank of America asked a so-called “prompt question”, a security question that ostensibly is something only the customer would know, such as the mother’s maiden name, the last four digits of a social security number, or, in Slowe’s case, simply a date of birth.

“I got an e-mail from Bank of America on Monday (June 11) saying that there’s possibly fraud on my account,” she said. “I called them and the first thing they said to me was: ‘you’re not calling from your home phone number.’ I said I most certainly was. They said ‘that’s not the number we have on file.’”

Slowe said she is upset because the prompt question is too easy for other people to answer correctly. Dates of birth and maiden names can be acquired through online background-check services or public marriage records.

“They were able to get Bank of America to change that home phone number with very little information,” said Slowe.

Arab News contacted Diane Wagner, Bank of America’s senior vice president for media relations, to ask about the bank’s official policy on prompt questions. She declined to answer whether Bank of America’s customer-service policy allows people to change account information by providing simply the date of birth of the cardholder.

“For security reasons, we can’t get into specifics about our monitoring, but in general we weigh the balance between customer convenience and fraud risk when approving transactions,” Wagner said in an e-mailed statement to Arab News. “Our objective is to maximize customer convenience while minimizing fraud losses.”

Wagner points out that the $12,000 charge that posted to Slowe’s account never went through thanks to the bank’s policy of checking suspicious activity.

“It is my understanding that, yes, we were able to stop the fraudulent activity,” she said by e-mail. “As for the verification process, I know that there are a series of steps we take to verify account information. In this instance, I would need time to investigate further and again, I would not be able to disclose the specifics.”

Slowe confirms that the transaction was never finalized, and that Bank of America contacted her about the pending transaction. However, Slowe said the bank should do more due diligence because her home number should never have been changed by a third party.

“The bank actually tried to call me (when the $12,000 charge posted to the account), but, of course, the number they had was either disconnected or the person who answered said there was nobody there by that name,” she said. “So they e-mailed me. That was a little late. Why didn’t they e-mail me when the phone number was changed to verify the change of the phone number? I honestly believe the credit card companies need to do more for security.”

What if the crooks had been able to change the e-mail address, too? Or what if they had answered the fraudulent phone number and made up a story about Susan traveling to Saudi Arabia for her job? Or what if the transaction had occurred inside the United States?

Slowe said her husband also called to change his security details on his Bank of America card after they learned of the identity theft. She said he too was only asked for a date of birth to make this vital change to the account.

The question of how the credit card could have been stolen in the first place remains unknown.

Joanne Veto, a spokeswoman from the US Postal Service in Washington D.C., says that incidences of theft from within the system are very low.

“Two studies, including one by the White House, say that ID theft of mail (from within the US Postal Service) is the least likely to occur,” she said in a telephone interview with Arab News. “According to the Federal Trade Commission, less than 4 percent of all ID theft can be traced back to mail theft. The Number One cause of identity theft, including credit card theft, is employee and other insider theft. You can’t rule it out, but we believe the odds are very slim that the mail was stolen out of the US Postal Service.”

Wherever these crooks are stealing the mail, one thing is certain: identity theft works quickly and internationally.

In the case of Susan Slowe’s credit card, it took 11 days for it to appear in a furniture store 12,000 km away — all within the period of time customers are waiting for credit cards to be mailed to them, unaware that they have already been snatched from the mail system, activated through a weak security-verification system and shipped half-a-world away. The US Department of Homeland Security estimates that this and similar types of fraud costs US consumers and companies $500 million per year. The United Kingdom estimated in 2003 that this fraud costs their consumers and companies nearly $850 million annually.

Slowe advises owners of credit cards to boost the security on their cards. Banks offer the option of password protecting account information instead of using the system of asking prompt questions. Slowe said she has requested the creditors of her three cards not to ask prompt questions.

“No hints. They should not be asking you questions like: ‘where did you live ten years ago?’ because that information is out there as public record. It’s just upsetting.”