Live data from Hacker News

Cybersecurity Incident Involving Consumer Information

investor.equifax.com

371–380 of 551 posts

Re: Cybersecurity Incident Involving Consumer Information

#371
post #154

Earlier quoted context omitted.

Precisely. In no way was Alice's identity stolen - that's tautologically impossible. Rather, the bank was defrauded by the criminal - Alice is of not a party to whether or not the bank recovers from its own loss. Alice's ownership is entirely unaffected, though the bank's internal processes might not reflect that - again, their problem, not Alice's. Further - this rat race, where I have to give ever more intimate det…

> In no way was Alice's identity stolen - that's tautologically impossible. I see this as you being too strict with your definition of "identity". We, as people, have multiple identities. We have one with our government, another with our employer, another with our friends, another on pseudonymous websites, etc. "Stolen identity" in this sense means Alice's attributes (the ones which Big Bank uses to identify a person…

Here's a typical story.

Online loan firm gives money to someone. Months later, they default, so they call who they think is the holder of the debt. That person has no clue what they are talking about. Finds out through first ever credit report they are defrauded. Victim calls loan firm, who requests lots of proof of existence as well as a police report, before they will help them. Process takes weeks. Victim finds out they signed up at Equifax during hack. Now they are in worse shape.

Re: Cybersecurity Incident Involving Consumer Information

#372
post #93

Suppose Alice is a "victim of identity theft". BigBank gives $10k to Fraudster as a loan, thinking that Alice is the actual recipient. Experian, Transunion and Equifax report this loan as a debt which Alice owes to BigBank. Who is the real victim? The credit reporting agencies want to convince people that the consumer is the victim, and so Alice bears the burden and risk of clearing her name. But it is the credit rep…

What Alice is the victim of is slander , not fraud or identity theft. The bank lent some money to someone who claimed to be Alice (though the bank only relied on the fact that that person knew Alice's SSN as proof of that fact). Then when the bank didn't get paid back, they told a bunch of credit check bureaus that Alice was a credit risk. This was a lie about Alice, which has a material impact on Alice's reputation.…

Defamation laws differ by state, but in NY for example, I believe libel (slander refers to oral defamation) requires that the perpetrator knew, or should have known, that the statements were false.

The question would then become whether the bank's identity verification procedures satisfy that burden. I think it would be a difficult endeavor, but it would be good to see it tested.

Re: Cybersecurity Incident Involving Consumer Information

#373

Earlier quoted context omitted.

We don't know if this has anything to do with any acquisitions - this is a conjecture, at best. At any rate - I don't care. I never gave Equifax permission to collect my personal data. I certainly never gave them permission to store it in a way that it can easily be hacked. If you buy a 3rd party company, "unfuck" and harden their software BEFORE you let the data flow in. Allowing data to slip out is negligent. If yo…

Not really conjecture: > The company has found no evidence of unauthorized activity on Equifax’s core consumer or commercial credit reporting databases. Since core business was unaffected (nobody hacked the mainframe), I guarantee you some crappy product they acquired got compromised. And like it or not, you do give them permission to collect your personal data every time you authorize a creditor, utility or employer…

Oh, good, it wasn't their _core_ business. What a bullshit copout - you acquire a company, you own it, warts and all. Who's worse, the crappy company or the company that acquires it and continues to operate it without fixing it?

Re: Cybersecurity Incident Involving Consumer Information

#374

Earlier quoted context omitted.

You're right it was never meant to be a unique identifier, we need a national identification card, link to a video about it. https://youtu.be/Erp8IAUouus

Americans don't like National ID cards because we remember the Third Reich and the USSR.

Germany has rather more intimate knowledge of both of those, and they have national ID cards without sliding into authoritarianism...

Re: Cybersecurity Incident Involving Consumer Information

#375
post #93

Suppose Alice is a "victim of identity theft". BigBank gives $10k to Fraudster as a loan, thinking that Alice is the actual recipient. Experian, Transunion and Equifax report this loan as a debt which Alice owes to BigBank. Who is the real victim? The credit reporting agencies want to convince people that the consumer is the victim, and so Alice bears the burden and risk of clearing her name. But it is the credit rep…

>It is Experian, Transunion and Equifax, by holding this fraudulent loan against Alice, who are victimizing Alice.

I think you're confused. It's BigBank that's falsely placing a debt burden on Alice. The credit reporting agencies are only reporting what they are told. Imagine if Alice doesn't care about her own credit worthiness. Let's say she has no debt, and no intention of acquiring debt. What happens if criminal tricks BigBank? They say, "Alice, you owe us this money." Alice tells BigBank, "No, prove it or pound sand."

What happens then? BigBank goes to the court and tries to get a judgment against Alice for the money owed. If Alice isn't aware of the proceeding, the judge will grant BigBank's request, and now Alice will owe BigBank the money stolen by criminal.

BigBank's poor authentication and the judicial branch are the ones doing the real harm to Alice. If anything, the credit reporting agencies are providing value to Alice by warning her before BigBank goes after her in a secret proceeding and makes the debt hers.

Re: Cybersecurity Incident Involving Consumer Information

#376
post #251

Earlier quoted context omitted.

All financial companies are required to have you SSN for reporting income for taxes and also report money movement under the anti-money laundering laws(AML). Know your customer(KYC) requires a financial company to gather documentation and information to verify your identity and to ensure your not on any list of people we're legally not allowed to provide services eg terrorist watch list. You don't need to provide a S…

Seems KYC as used in the real world doesn't do a very good job of verifying whether the "customer" is Alice or the fraudster... It'd be nice if _that_ requirement had enough teeth to reduce the ability of the financial institution to claim Alice is "the victim"...

Curious how would you verify a user? Right now standard solution is to use public records(LexisNexis), credit history(Experian), fraud detection networks(early warning). Along with a bunch reputation providers around IP(Maxmind,Socure), email(emailage), address. Also government based ID and utility bills etc. This isn't cheap and can costs $10+ to run all these checks.

Even government can't verify people and its problem because people give other people's SSN and DOB when they get arrested which is the worst type of identity theft as it can lead to the victim getting arrested or not getting a job(criminal record showing up in background check).

Re: Cybersecurity Incident Involving Consumer Information

#377
post #202

By enrolling in the free "Identity Theft Protection" you waive your right to "PARTICIPATE IN A CLASS ACTION, CLASS ARBITRATION, OR OTHER REPRESENTATIVE ACTION" https://trustedidpremier.com/static/terms What a scam!

If by that you mean one waives the right to sue Equifax over the data breach, that’s not what it says by my reading.

“Except as otherwise expressly provided in this Agreement, all claims, disputes, or controversies raised by either You or TrustedID, Inc. arising from or relating to the subject matter of this Agreement or the Products (“Claim” or “Claims”) shall be finally settled by arbitration”

But IANAL.

Re: Cybersecurity Incident Involving Consumer Information

#378

I strongly encourage anyone in the US to put a full credit security freeze on all three credit agencies. When a credit freeze is in place, you still have access to all of your existing loan accounts and whatnot (e.g. credit cards), but lenders cannot access your credit to open new accounts unless you want them to. It's not difficult nor expensive to do, and the freeze lasts until you decide to revoke it. Whenever you…

Unfortunately it appears freezing credit reporting is impossible in Canada, presumably because there are no laws forcing these companies to allow it here: https://money.stackexchange.com/a/54677

Re: Cybersecurity Incident Involving Consumer Information

#379

Earlier quoted context omitted.

What Alice is the victim of is slander , not fraud or identity theft. The bank lent some money to someone who claimed to be Alice (though the bank only relied on the fact that that person knew Alice's SSN as proof of that fact). Then when the bank didn't get paid back, they told a bunch of credit check bureaus that Alice was a credit risk. This was a lie about Alice, which has a material impact on Alice's reputation.…

This is a great description of what is going on with "identity theft". I don't usually like changing the name of something to try to push an agenda, but calling "identity theft" "bank slander" would be good idea.

Especially if a very large class action law suit was started from this.

Calling all identity thief peeps....

Re: Cybersecurity Incident Involving Consumer Information

#380
post #225
post #159

Earlier quoted context omitted.

I'll bet $5 that signing up for their monitoring service comes with a class-action waiver sweetener.

> I'll bet $5 that signing up for their monitoring service comes with a class-action waiver It does indeed. https://trustedidpremier.com/static/terms

Please highlight the part where it specifically says one waives the right to sue Equifax over the data breach. Because the agreement is specific about what it covers.
Post reply on HN