Live data from Hacker News

Cybersecurity Incident Involving Consumer Information

investor.equifax.com

251–260 of 551 posts

Re: Cybersecurity Incident Involving Consumer Information

#251
post #154
post #93

Suppose Alice is a "victim of identity theft". BigBank gives $10k to Fraudster as a loan, thinking that Alice is the actual recipient. Experian, Transunion and Equifax report this loan as a debt which Alice owes to BigBank. Who is the real victim? The credit reporting agencies want to convince people that the consumer is the victim, and so Alice bears the burden and risk of clearing her name. But it is the credit rep…

Precisely. In no way was Alice's identity stolen - that's tautologically impossible. Rather, the bank was defrauded by the criminal - Alice is of not a party to whether or not the bank recovers from its own loss. Alice's ownership is entirely unaffected, though the bank's internal processes might not reflect that - again, their problem, not Alice's. Further - this rat race, where I have to give ever more intimate det…

All financial companies are required to have you SSN for reporting income for taxes and also report money movement under the anti-money laundering laws(AML). Know your customer(KYC) requires a financial company to gather documentation and information to verify your identity and to ensure your not on any list of people we're legally not allowed to provide services eg terrorist watch list.

You don't need to provide a SSN to get cell service or provide real information. Lots fraud is done through tethering through burner phones.

Re: Cybersecurity Incident Involving Consumer Information

#252

Earlier quoted context omitted.

> I want to see Equifax's CEO, CTO, CSO and anyone who ever saw a report saying "we need to invest more in security" and ignored it, to pay. The issue here is likely related to business units that were acquisitions, with the breached product in question having been developed pre-acquisition by a code farm staffed by interns in some developing nation. I spent a few years trying to unfuck some of those messes and moved…

We don't know if this has anything to do with any acquisitions - this is a conjecture, at best. At any rate - I don't care. I never gave Equifax permission to collect my personal data. I certainly never gave them permission to store it in a way that it can easily be hacked. If you buy a 3rd party company, "unfuck" and harden their software BEFORE you let the data flow in. Allowing data to slip out is negligent. If yo…

You probably did if you have any sort of bank account or loan or job application or rent. It's pervasive in contracts/agreements that they report to partners and credit agencies.

Re: Cybersecurity Incident Involving Consumer Information

#253
post #171

Earlier quoted context omitted.

When you get your account frozen they provide a PIN to unlock.

And what happens if I call to unfreeze but have lost the PIN? Can I never get a loan again for the rest of my life? Or is there some way around the PIN - perhaps only requiring the already leaked information?

You call them up... but this will probably no longer work b/c of the data breach. Otherwise you snail mail them a letter with a govt ID and they send you a new pin.

Re: Cybersecurity Incident Involving Consumer Information

#254
post #164

Earlier quoted context omitted.

Change the way checks are issued/redeemed. Right now the customer is on the hook for 7 years because a check isn't cleared until it goes back to the bank that issued the check . The customer thinks by seeing the money in the account the check was good and can clear a sale. The reality is the bank can take that money back if it is later determined to be false/fake.

> customer is on the hook for 7 years 7 years? Are you sure it's not something like 7 days?

[deleted]

Re: Cybersecurity Incident Involving Consumer Information

#255
post #171

Earlier quoted context omitted.

When you get your account frozen they provide a PIN to unlock.

And what happens if I call to unfreeze but have lost the PIN? Can I never get a loan again for the rest of my life? Or is there some way around the PIN - perhaps only requiring the already leaked information?

>>And what happens if I call to unfreeze but have lost the PIN? Can I never get a loan again for the rest of my life?

Exactly. There's no shot this "PIN" is like one-way a encryption passphrase. There is definitely a way around it.

Re: Cybersecurity Incident Involving Consumer Information

#257

They got hacked years ago. I know this for sure because I'd used a unique email address to sign up on their website: equifax@ .com No one else had that email address. Guess what, I started getting phishing emails to that exact address. Tried letting them know, but it went nowhere.

They've been hacked 3 times before. Like yahoo waiting years to tell anyone this is just scummy. I hope they make a law sending people to jail over this

Re: Cybersecurity Incident Involving Consumer Information

#258
One possible solution is to use the concept of the public and private keys we use for digital signing/encryption.

You can use my public key/public SSN to make inquiries about me and check my credit history. But to open an account or take out a loan etc, you also need my private key, private SSN, which is not stored once the account modification is done.

IMHO, this never going to happen, but seems like it could be a solution to these problems?

Re: Cybersecurity Incident Involving Consumer Information

#259

Earlier quoted context omitted.

I've worked a bit in the industry and around the industry, the worrying thing for me is that it doesn't seem to be working for anyone apart from equifax/experian/call credit. I have separately worked with one of those companies with a client and their IT staff were utterly incompetent (I won't say which). Loads of different sites, lots of little fiefdoms, utterly inconsistent security policies on each site, blaming e…

You just put the money in an account, pay the capital off every month, lose a little bit of interest and in 2 years you have a shiny credit rating even though it means zilch. I don’t really get that - doesn’t it mean that the person who took a loan is relatively responsible and was able to pay their loan back on time? Any system can be gamed, but I don’t get the impression that credit agencies are attempting to elimi…

For £100 you get a shiny credit rating for no risk. That'll get you a mortgage for £100,000s.

In the 60s/70s it was about knowing your bank manager, so he knew you'd be able to pay. I appreciate that it probably benefited a certain type of person, but the new system probably has the same prejudices built in. Now it's all about the ephemeral and easily game-able credit score. Until a few years ago you would get negatively scored for not having a landline.

These scores are utter bullshit, they're simply about if you haven't screwed up yet, they're not actual assessments of your ability to pay or the risk you've exposed yourself to.

Again, I worked in the mortgage industry before the Northern Rock collapse, brokers used to be able to go to those guys and openly fudge people's incomes by calling them self-employed, they had a good credit score so no-one blinked an eyelid, get 105% mortgage, and then lo-and-behold, the bank collapsed. Yes, part of it was that they lost their access to easy bank credit, but another part of it was they lent to hugely risky people.

As a slight-side, my bank was willing to lend me crazy credit card money a few years ago because for 10 years I never missed a payment. In reality in those ten years I went through a patch of being the most business-un-savvy freelancer ever, selling myself at a stupid rate and not putting enough aside to pay my tax bill, to the point where I had to get a loan from a parent to pay it. I was flat broke, almost bankrupt, and these people were willing to lend me almost 9 months of my income.

I was not a good risk.

But because I paid on time for X years before, I was to the credit agencies.

Re: Cybersecurity Incident Involving Consumer Information

#260
post #144

Earlier quoted context omitted.

That's what I came here for too. They have a site (go to Equifax for a notification banner) but providing the information they want just tells me to check back later. From the text I would assume I wasn't impacted, despite the fact that it seems almost everyone who used the site would have been. Edit: Seems that if you have a date you're impacted. https://www.reddit.com/r/personalfinance/comments/6yq36a/equ...

Have a date? Thanks for the info will check it out, I suppose one saving grace for me is my credit is destroyed. edit: that's funny "I know we just lost your SSN, but could you type it in again?" Also curious if by asking for the last six makes search faster, probably. site to check impact: https://trustedidpremier.com/eligibility/eligibility.html Edit that link (trusted) doesn't even say equifax in it, pulled it fro…

seems to be linked to from the main equifax site : https://www.equifax.com/personal/ (see banner at top)
Post reply on HN