Friday, December 20, 2013

14 IRS Audit Red Flags

14 IRS Audit Red Flags

Kiplinger
       
 
 
Ever wonder why some tax returns are eyeballed by the Internal Revenue Service while most are ignored? The IRS audits only slightly more than 1% of all individual tax returns annually. The agency doesn't have enough personnel and resources to examine each and every tax return filed during a year. And its resources are shrinking: The number of enforcement staff dropped nearly 6% in 2012, partly due to budget cuts. We expect the 2013 audit rate to fall even lower as the agency continues to deal with less funding and even more employees are reassigned to work identity theft cases. So the odds are pretty low that your return will be picked for review. And, of course, the only reason filers should worry about an audit is if they are fudging on their taxes.
Making Too Much Money
Although the overall individual audit rate is about 1.03%, the odds increase dramatically for higher-income filers. Recent IRS statistics show that people with incomes of $200,000 or higher had an audit rate of 3.70%, or one out of every 27 returns. Report $1 million or more of income? There's a one-in-eight chance your return will be audited. The audit rate drops significantly for filers making less than $200,000: Less than 1% (0.94%) of such returns were audited during 2012, and the vast majority of these exams were conducted by mail.
We're not saying you should try to make less money--everyone wants to be a millionaire. Just understand that the more income shown on your return, the more likely it is that you'll be hearing from the IRS.
See More: How the Government Shutdown Could Affect Your Tax Return
Failing to Report All Taxable Income
The IRS gets copies of all 1099s and W-2s you receive, so make sure you report all required income on your return. IRS computers are pretty good at matching the numbers on the forms with the income shown on your return. A mismatch sends up a red flag and causes the IRS computers to spit out a bill. If you receive a 1099 showing income that isn't yours or listing incorrect income, get the issuer to file a correct form with the IRS.
Taking Large Charitable Deductions
We all know that charitable contributions are a great write-off and help you feel all warm and fuzzy inside. However, if your charitable deductions are disproportionately large compared with your income, it raises a red flag.
That's because IRS computers know what the average charitable donation is for folks at your income level. Also, if you don't get an appraisal for donations of valuable property, or if you fail to file Form 8283 for donations over $500, you become an even bigger audit target. And if you've donated a conservation or faƧade easement to a charity, chances are good that you'll hear from the IRS. Be sure to keep all your supporting documents, including receipts for cash and property contributions made during the year, and abide by the documentation rules. And attach Form 8283 if required.
See More: Don't Miss One of These 21 Most-Overlooked Tax Deductions
Claiming Day-Trading Losses on Schedule C
Those who trade in stocks and securities have significant tax advantages compared with investors. The expenses of traders are fully deductible and are reported on Schedule C (investors report their expenses as a miscellaneous itemized deduction on Schedule A, subject to an offset of 2% of adjusted gross income), and traders' profits are exempt from self-employment tax. Losses of traders who make a special section 475(f) election are fully deductible and are treated as ordinary losses that aren't subject to the $3,000 cap on capital losses. And there are other tax benefits.
But to qualify as a trader, you must buy and sell securities frequently and look to make money on short-term swings in prices. And the trading activities must be continuous. This is different from an investor, who profits mainly on long-term appreciation and dividends. Investors hold their securities for longer periods and sell much less often than traders.
The IRS knows that many filers who report trading losses or expenses on Schedule C are actually investors. So it's pulling returns and checking to see that the taxpayer meets all of the rules to qualify as a bona fide trader, including frequent and continuous buying and selling of stocks and securities.
Claiming Rental Losses
Normally, the passive loss rules prevent the deduction of rental real estate losses. But there are two important exceptions. If you actively participate in the renting of your property, you can deduct up to $25,000 of loss against your other income. But this $25,000 allowance phases out as adjusted gross income exceeds $100,000 and disappears entirely once your AGI reaches $150,000.
A second exception applies to real estate professionals who spend more than 50% of their working hours and 750 or more hours each year materially participating in real estate as developers, brokers, landlords or the like. They can write off losses without limitation.
The IRS is actively scrutinizing rental real estate losses, especially those written off by taxpayers claiming to be real estate pros. It's pulling returns of individuals who claim they are real estate professionals and whose W-2 forms or other non-real estate Schedule C businesses show lots of income. Agents are checking to see whether these filers worked the necessary hours, especially in cases of landlords whose day jobs are not in the real estate business. The IRS started its real estate professional audit project several years ago, and this successful program continues to bear fruit.
Deducting Business Meals, Travel and Entertainment
Schedule C is a treasure trove of tax deductions for self-employeds. But it's also a gold mine for IRS agents, who know from experience that self-employeds sometimes claim excessive deductions. History shows that most underreporting of income and overstating of deductions are done by those who are self-employed. And the IRS looks at both higher-grossing sole proprietorships and smaller ones.
Big deductions for meals, travel and entertainment are always ripe for audit. A large write-off here will set off alarm bells, especially if the amount seems too high for the business. Agents are on the lookout for personal meals or claims that don't satisfy the strict substantiation rules. To qualify for meal or entertainment deductions, you must keep detailed records that document for each expense the amount, the place, the people attending, the business purpose and the nature of the discussion or meeting. Also, you must keep receipts for expenditures over $75 or for any expense for lodging while traveling away from home. Without proper documentation, your deduction is toast.
Claiming 100% Business Use of a Vehicle
Another area ripe for IRS review is use of a business vehicle. When you depreciate a car, you have to list on Form 4562 what percentage of its use during the year was for business. Claiming 100% business use of an automobile is red meat for IRS agents. They know that it's extremely rare for an individual to actually use a vehicle 100% of the time for business, especially if no other vehicle is available for personal use. IRS agents are trained to focus on this issue and will scrutinize your records. Make sure you keep detailed mileage logs and precise calendar entries for the purpose of every road trip. Sloppy recordkeeping makes it easy for the revenue agent to disallow your deduction..
As a reminder, if you use the IRS' standard mileage rate, you can't also claim actual expenses for maintenance, insurance and other out-of-pocket costs. The IRS has seen such shenanigans and is on the lookout for more.
Writing off a Loss for a Hobby Activity
Your chances of "winning" the audit lottery increase if you have wage income and file a Schedule C with large losses. And if the loss-generating activity sounds like a hobby--horse breeding, car racing and such--the IRS pays even more attention. Agents are specially trained to sniff out those who improperly deduct hobby losses. Large Schedule C losses are always audit bait, but reporting losses from activities in which it looks like you're having a good time all but guarantees IRS scrutiny.
You must report any income you earn from a hobby, and you can deduct expenses up to the level of that income. But the law bans writing off losses from a hobby. For you to claim a loss, your activity must be entered into and conducted with the reasonable expectation of making a profit. If your activity generates profit three out of every five years (or two out of seven years for horse breeding), the law presumes that you're in business to make a profit, unless the IRS establishes otherwise. If you're audited, the IRS is going to make you prove you have a legitimate business and not a hobby. So make sure you run your activity in a businesslike manner and can provide supporting documents for all expenses.
Claiming the Home Office Deduction
Like Willie Sutton robbing banks (because that's where the money is), the IRS is drawn to returns that claim home office write-offs because it has found great success knocking down the deduction and driving up the amount of tax collected for the government. If you qualify, you can deduct a percentage of your rent, real estate taxes, utilities, phone bills, insurance and other costs that are properly allocated to the home office. That's a great deal. And beginning with 2013 returns, you have a simplified option for claiming this deduction. The write-off can be based on a standard rate of $5 per square foot of space used for business, with a maximum deduction of $1,500.
To take advantage of this tax benefit, you must use the space exclusively and regularly as your principal place of business. That makes it difficult to successfully claim a guest bedroom or children's playroom as a home office, even if you also use the space to do your work. "Exclusive use" means that a specific area of the home is used only for trade or business, not also for the family to watch TV at night.
Don't be afraid to take the home office deduction if you're entitled to it. Risk of audit should not keep you from taking legitimate deductions. If you have it and can prove it, then use it.
Taking an Alimony Deduction
Alimony paid by cash or check is deductible to the payer and taxable to the recipient, provided certain requirements are met. For instance, the payments must be made under a divorce or separate maintenance decree or written separation agreement. The instrument can't say the payment isn't alimony. And the payer's liability for the payments must cease upon the death of the former spouse. You'd be surprised how many divorce decrees run afoul of this rule.
Alimony doesn't include child support or noncash property settlements. The rules on deducting alimony are complicated, and the IRS knows that some filers who claim this write-off don't always satisfy the requirements. It also wants to make sure that both the payer and the recipient properly reported alimony on their respective returns. A mismatch in reporting by ex-spouses will almost certainly trigger an audit.
Tax Planning for Same-Sex Couples
Running a Small Business
Small business owners, especially those in cash-intensive businesses--think taxis, car washes, bars, hair salons, restaurants and the like--are a tempting target for IRS auditors. Experience shows that those who receive primarily cash are less likely to accurately report all of their taxable income. The IRS has a guide for agents to use when auditing cash-intensive businesses, telling how to interview owners and noting various indicators of unreported income.
Other small businesses will also face extra audit heat, as the IRS shifts its focus away from auditing regular corporations. The agency thinks it can get more bang for its audit buck by examining S corporations, partnerships, limited liability companies and sole proprietorships. So it's spending more resources on training examiners about issues commonly encountered with pass-through firms.
See Also: 8 Tax Breaks for the Middle Class
Failing to Report a Foreign Bank Account
The IRS is intensely interested in people with offshore accounts, especially those in tax havens, and tax authorities have had success getting foreign banks to disclose account information. The IRS has also used voluntary compliance programs to encourage folks with undisclosed foreign accounts to come clean--in exchange for reduced penalties. The IRS has learned a lot from these amnesty programs and has been collecting a boatload of money (we're talking billions of dollars). It's scrutinizing information from amnesty seekers and is targeting the banks that they used to get names of even more U.S. owners of foreign accounts.
Failure to report a foreign bank account can lead to severe penalties, and the IRS has made this issue a top priority. Make sure that if you have any such accounts, you properly report them. This means electronically filing FinCEN Form 114 by June 30 to report foreign accounts that total more than $10,000 at any time during the previous year. And those with a lot more financial assets abroad may also have to attach IRS Form 8938 to their timely filed tax returns.
Engaging in Currency Transactions
The IRS gets many reports of cash transactions in excess of $10,000 involving banks, casinos, car dealers and other businesses, plus suspicious-activity reports from banks and disclosures of foreign accounts. A report by Treasury inspectors concluded that these currency transaction reports are a valuable source of audit leads for sniffing out unreported income. The IRS agrees, and it will make greater use of these forms in its audit process. So if you make large cash purchases or deposits, be prepared for IRS scrutiny.
Also, be aware that banks and other institutions file reports on suspicious activities that appear to avoid the currency transaction rules (such as persons depositing $9,500 in cash one day and an additional $9,500 in cash two days later).
12 Smart Year-End Tax Moves To Make Every Year
Taking Higher-than-Average Deductions
If deductions on your return are disproportionately large compared with your income, the IRS may pull your return for review. But if you have the proper documentation for your deduction, don't be afraid to claim it. There's no reason to ever pay the IRS more tax than you actually owe.

http://finance.yahoo.com/news/14-irs-audit-red-flags-050001166.html

Friday, December 13, 2013

2014: The year that security becomes strategic to the business


2014: The year that security becomes strategic to the business

Renee Bradshaw, solution marketing strategist, NetIQ
Renee Bradshaw, solution marketing strategist, NetIQ
The headline-grabbing data breaches of 2013 are driving organizations to reconsider their security approach. While many started their security program with a compliance-driven focus, companies are realizing that compliance alone cannot sufficiently protect an organization.
There are signs that indicate that in the year ahead, we will see more companies develop a proactive, strategic security program and supplant the traditional notion of “achieving compliance” as an equivalent to security. In fact, a study conducted by CyberSource, a credit card processor for business, electronic payment and risk management solutions, found that only 26 percent of survey respondents cited avoiding penalties resulting from non-compliance as their primary motivator, while 70 percent of those vendors in the study identified their desire to protect their brand image as the main driver for improving their network and data security defenses to keep hackers out of their systems.
Further to this, evidence of business objectives being linked to data protection and mitigation of organizational risk is now being seen in 10-K annual forms filed by public companies around their performance.  Across almost every industry, a company's operations rely on strengthening their security measures.  In company annual reports, security is becoming one of the key drivers of business processes and is an area that businesses are proactively addressing to protect the confidentiality, integrity, and availability of their sensitive data.
KBR, an American engineering, construction, and private military contracting company, relies on information technology systems to achieve their business objectives. In their 2012 10K filing statement, the company recognized that any failure, disruption, or security breach of these systems could adversely affect their business. With the company relying upon industry-accepted security measures and technology to securely maintain confidential and proprietary information maintained on their IT systems, this was a step forward from 2009, where the company did not mention either as being strategic to the business.
Humana, a health care company that markets and administers health insurance, acknowledged in their 2012 10-K statement that if they fail to properly maintain the integrity of their data by not strategically implementing new information systems, the company will not be in a position to protect their data and defend against cyber attacks.  Ultimately, this could lead to failure in business operations that negatively impact their financial position and cash flow of the company.
Back in 2009, the company recognized that the integrity of the data in their information systems was the key to adequately price products and services, provide efficient service to customers, and deliver timely and accurately reports of financial results. However, to achieve this, they simply relied on agreements with customers, employees and third-parties to protect any misappropriation of the company's proprietary information. 
Wells Fargo, a provider of banking, mortgage, investing, credit card, insurance, and consumer and commercial financial services has been the target of various denial-of-service and other cyber attacks. In their 2012 10-K report, the company included a section addressing risk management. With over 70 million customers, the institution relies on their ability to process, record and monitor a large number of transactions on a continuous basis.  The company recognized that regulatory expectations around operational and information security have also increased, and operational systems and infrastructure must continue to be safeguarded and monitored for potential failures, disruptions and breakdowns.
However, back in 2009, the company did not include an Operating Risk Management section in their 10-K. They simply stated that if personal, confidential or proprietary information of customers or clients were mishandled or misused by the company or by third-parties, the company could suffer significant regulatory consequences, reputational damage and financial loss.  
As we turn to 2014, it is expected that similar forward-looking companies such as the ones mentioned, will continue to develop a proactive security program that will focus on data protection and risk mitigation that aligns with business objectives. With a strategic security program, companies will also be able to mitigate organizational risks that emerge with cloud, mobility, bring-your-own-device (BYOD) and social computing models. As a result of this progression, compliance will be repositioned from a leading driver of security to a security best practice.  
Compliance remains a necessary concern and business driver as being out of compliance can mean huge fines and reputational damage to a company. While most executives understand that being compliant is a business requirement that must be funded, organizations can and should use these funds to achieve compliance through a proactive security program. The compliance audit process can be used to evaluate and communicate organizational risk, and the results can be used as feedback to drive improvement of security controls and processes. In this way, organizations can achieve a robust security program to properly mitigate risk while aligning to business objectives.

Wednesday, December 4, 2013

98% of Top 100 e-Commerce Sites Leave Shoppers Open to Cyber-crooks

http://www.infosecurity-magazine.com/view/35971/98-of-top-100-ecommerce-sites-leave-shoppers-open-to-cybercrooks/?utm_source=twitterfeed&utm_medium=twitter

04 December 2013

As the “Cyber December” holiday buying season gets underway, new research shows that only two of the top 100 e-commerce websites automatically protect users by directing them to highly secure HTTPS versions that use always-on SSL.



The research into how SSL certificates are implemented, from High-Tech Bridge, also shows that only 27% of websites have a secure HTTPS version for all customer-facing pages, leaving critical details such as passwords and billing information openly available to identity thieves.
While an SSL certificate on an e-commerce website does not have any direct impact on web application security, it confirms website identity and assures te encryption of data transferred between web application and user browser.
“All sites and mobile apps must recognize the importance of securing the data transmitted between users and their sites,” said Craig Spiezle, executive director and president of Online Trust Alliance (OTA), in a statement. “Banking, social, government and e-commerce share this responsibility to implement these best practices to better protect consumers from harm. Always on SSL and HTTPs are effective measures to enhance the security and privacy of users. Failure to adopt unnecessarily puts users in harm’s way.”
To carry out the research, High-Tech Bridge compiled a Top 100 list from three different independent sources: the 20 Most Popular Web Retailers from the Washington Post, Alexa’s Top Sites in Shopping and Top 50 Most Popular Online Shopping Websites by My App Magazine. Using its ImmuniWeb SSL Certificate Monitor, High-Tech Bridge found a number of positive and negative findings.
In the good news column, none of the websites have expired or untrusted SSL certificates; and only one of the websites had certificates set expire in less than one month.  Also, 99 out of 100 of websites have 2048-bit or stronger encryption certificates in place.
However, in addition to only two of them actually protecting users by automatically using a secure HTTPS version (SSL) by default, only a quarter of websites have SSL extended validation (EV) certificates. And two of the websites do not have an SSL certificate at all, leaving their customers totally unprotected.
Seven websites are putting customer information at risk by failing to enforce the use of HTTPS for the most sensitive operations such as login, checkout and payment. And a third (33%) of websites display non-SSL content together with SSL content on their pages.
A majority (73%) of websites do not have a secure HTTPS version at all for some "non-critical" online activities of their customers, such as shopping cart management, for example.
“Alarmingly, only 2% of leading global online retailers automatically ensure their customers use the secure HTTPS version of their website when making orders or adding goods to their shopping carts,” said Marsel Nizamutdinov, chief research officer at High-Tech Bridge. “Unfortunately these websites seriously underestimate the importance of encrypting user-transmitted data beyond logins and passwords, and this is a very dangerous approach to privacy management. In many cases, if such ‘non-critical’ data is stolen by third-parties, it may not just harm the buyer, but the online store as well.”

This article is featured in:
Encryption  •  Internet and Network Security  •  IT Forensics

Monday, December 2, 2013

Dutch Regulator Finds Google in Breach of Privacy Law

Dutch Regulator Finds Google in Breach of Privacy Law


01 December 2013

The Netherlands is one of the six EU member states that have undertaken a formal investigation of Google's privacy compliance following the 2012 amalgamation of its various privacy policies. The Dutch Data Protection Authority has now found Google to be in breach of multiple aspects of the the Dutch data protection act.


"Google spins an invisible web of our personal data, without our consent. And that is forbidden by law," says Jacob Kohnstamm, chairman of the DPA. He has not yet decided whether to take formal enforcement action, but has invited Google to attend a further hearing before that decision.
In its findings titled Investigation into the combining of personal data by Google, the DPA defines Google users as either authenticated (signed in with an account), unauthenticated (users of services such as Search that don't require an account) or passive (visitors to sites that deliver Google cookies). It then looked at these users in relation to four specific purposes for which Google collects and combines personal data: "the personalization of requested services, product development, display of personalized ads, and website analytics."
Google's basic arguments for the lawfulness of its data collection are that users imply consent to the collection of personal data, that it is necessary for the company's business model, and that the company provides adequate safeguards for users to protect their data  (such as opt-outs and using the incognito browsing mode in Chrome). Throughout its investigation, however, the DPA concluded that Google failed to meet the underlying legal requirements of proportionality (legitimate, suitable, necessary and reasonable) and subsidiarity (the smallest degree necessary) when collecting personal data.
"Google has not demonstrated and this investigation has not shown that the investigated data processing activities relating to the combining of data about and from multiple services are necessary (i.e. meet the requirements of proportionality and subsidiarity)."
The DPA also points out that 'implied' consent is insufficient in Dutch law, which requires unambiguous consent. "There is no evidence," it says, "of unambiguous consent... since Google does not offer data subjects any (prior) options to consent to or reject the examined data processing activities."
Because of the lack of proportionality, subsidiarity and unambiguity, Google has no legal grounds for collecting personal data in the way that it does; and because of that, "the personal data collected by Google from all three types of users are not being collected for legitimate purposes (as being examined here), with the result that Google is acting in breach of the provisions of Article 7 of the Wbp in this respect as well."
The report's final conclusion for all three types of user and the four specified purposes is, "Google does not obtain unambiguous consent for the examined data processing activities and has no other legal grounds under Article 8 of the Wbp. For this reason, by combining data from and about multiple services for the four examined actual purposes Google is acting in breach of Article 8 of the Wbp."
Before deciding whether to impose enforcement of these findings, the DPA will hold a further hearing with Google. In response, a Google statement said, "Our privacy policy respects European law and allows us to create simpler, more effective services. We have engaged fully with the Dutch DPA throughout this process and will continue to do so going forward."

This article is featured in:
Compliance and Policy
 
http://www.infosecurity-magazine.com/view/35903/dutch-regulator-finds-google-in-breach-of-privacy-law/?utm_medium=referral&utm_source=pulsenews

Tuesday, November 12, 2013

70,000 customers at risk from 'sophisticated criminal attack'


Supervalu customers who took advantage of a holiday offer are at risk

Supervalu customers who took advantage of a holiday offer are at risk

Up to 70,000 people in Ireland who took advantage of a customer loyalty offer could have been victims of a "sophisticated criminal attack".
The company, Loyaltybuild, said it had suffered a security data breach.
Supermarket chain Supervalu has asked 62,500 people involved in its Getaway Breaks scheme to contact their banks - 6,800 of those are in Northern Ireland.
AXA Ireland has said up to 8,000 of its customers may have been affected.
Loyaltybuild has advised the Data Protection Commissioner of Ireland and the police.
In a statement on its website, it added: "As part of our ongoing investigation, into a system breach identified last month, Loyaltybuild has discovered that it has been the victim of a sophisticated criminal attack.
"We are working around the clock with our security experts to get to the bottom of this and to further enhance our security in order to protect our valued customers, who are of paramount importance to us."

Start Quote

We are working around the clock with our security experts to get to the bottom of this”
End Quote Loyaltybuild statement
Customers are advised to check their payment cards for suspicious activity.
The breach was discovered on 25 October and a third party firm has been running forensic tests.
Supervalu said the incident was more extensive than initially thought. Customers who made Getaway Break bookings between January 2011 and February 2012 have been advised to contact their financial institutions.
Customers are also being warned to treat any unsolicited communication claiming to represent Supervalu Getaway Breaks or Loyaltybuild with "extreme caution".
Supervalu said it was continuing to work with Loyaltybuild to resolve the issue as quickly as possible but had also engaged its own IT security consultants to investigate the Loyaltybuild system.
It also emphasised that the breach of security was in data collected and held by Loyaltybuild on Getaway Breaks customers only and did not involve other customers of Supervalu.
AXA Ireland confirmed its customers' data may also have been compromised by the Loyaltybuild breach. Up to 8,000 customers may have been affected.
In a statement, the company said: "Loyaltybuild's forensic team has now advised that there is a high risk that an unauthorised third party accessed details of payment cards used to pay for AXA Leisure Breaks between January 2011 and February 2012.
"This investigation is still ongoing in relation to whether other personal data of customers has been compromised," it added.
AXA said all other customer transactions by payment card were unaffected.

Banken worstelen met kosten compliance en toezicht

Foto bij het bericht Banken worstelen met kosten compliance en toezicht

De krimpende financiƫle sector heeft steeds meer moeite om de honderden miljoenen te verdienen die nodig zijn om te voldoen aan regelgeving uit Brussel en Washington. Ook het toezicht, waaraan de banken meebetalen, wordt ieder jaar duurder.
Een en ander blijkt uit een rondgang langs banken, vermogensbeheerders en handelshuizen door Het Financieele Dagblad. De toezichtskosten van De Nederlandsche Bank (DNB) zijn dit jaar begroot op 149 miljoen euro. Dat was in 2008 nog 98 miljoen euro. AFM zag de kosten stijgen van 68,5 miljoen euro naar 85,3 miljoen euro. Vanaf volgend jaar draagt de overheid niet meer bij aan deze instellingen en moet de sector volledig de kosten dragen.
Wetgevingspakketten als het Brusselse Emir, Mifid-II en het Amerikaanse Dodd-Frank zorgen er bovendien voor dat banken hele teams van consultants en juristen aan het werk hebben om te voldoen aan de regels. Ondertussen is sinds de crisis ongeveer een kwart van de werknemers bij banken en verzekeraars zijn baan kwijtgeraakt.

Sunday, November 3, 2013

Baltimore County workers' personal information stolen

Baltimore County workers' personal information stolen


The personal information of current and past Baltimore County employees was stolen by a former employee of a county information technology contractor.
How many victims? More than 12,000 current and former Baltimore County employees.
What type of personal information? Social Security numbers, home addresses, salaries, leave balances, and county identification numbers.
What happened? The personal information of current and past Baltimore County employees was found on the computer of a man who was a former employee of an information technology contractor hired by the county. County officials believe the information was accessed when the suspect brought a new computer to a county employee who had downloaded the information as part of a work assignment.
What was the response? County officials sent letters to those affected by the breach, informing them that no personal financial information of any current or former employee was found on the computer.
Details: Authorities discovered the data while investigating an unrelated identity theft case in which the alleged perpetrator was involved. In spring of 2013, he was indicted by the Baltimore County state attorney's office after a neighbor filed a complaint that he had made purchases using fake checks and IDs. After authorities executed a search warrant on his home, personal items, including his computer, were seized. He fled the state and wasn't arrested.
On October 15, he was taken into custody in another state and he will now be extradited to Maryland to face identity theft charges that are unrelated to the Baltimore County employees incident.
Quote: “At this time, there is no evidence that any employee's information was misused in any way,” Fred Homan, county administrative officer, wrote in a letter to those affected by the breach.
Source: baltimoresun.com, The Baltimore Sun, “Former employee of contractor obtained Balt. Co. workers' personal data,” Oct. 31, 2013.

http://www.scmagazine.com/baltimore-county-workers-personal-information-stolen/article/319162/