Live data from Hacker News

Cybersecurity Incident Involving Consumer Information

investor.equifax.com

391–400 of 551 posts

Re: Cybersecurity Incident Involving Consumer Information

#391

They got hacked years ago. I know this for sure because I'd used a unique email address to sign up on their website: equifax@ .com No one else had that email address. Guess what, I started getting phishing emails to that exact address. Tried letting them know, but it went nowhere.

They've been hacked 3 times before. Like yahoo waiting years to tell anyone this is just scummy. I hope they make a law sending people to jail over this

This administration won't be doing shit about companies like this. We need to fix the political system if there's to be any hope of justice for these types of crimes.

Re: Cybersecurity Incident Involving Consumer Information

#392
post #386
post #375

Earlier quoted context omitted.

>It is Experian, Transunion and Equifax, by holding this fraudulent loan against Alice, who are victimizing Alice. I think you're confused. It's BigBank that's falsely placing a debt burden on Alice. The credit reporting agencies are only reporting what they are told. Imagine if Alice doesn't care about her own credit worthiness. Let's say she has no debt, and no intention of acquiring debt. What happens if criminal…

What actually happens: 1. Alice does have debt, and does intend to acquire debt in the future, like most people. The presence of this fraudulent debt in her credit report makes credit more expensive and hard to get. 2. Before filing suit and going to court, BigBank makes persistent but usually polite attempts to collect. But when she says "that wasn't me" they don't believe her, because lots of deadbeats say that sor…

Step 3 is the insidious part. If Alice files a paper with the reporting agencies, they're required to remove the false report. But the collection agency will just as persistently file an equal but opposite paper to reinstate. The reporting agency is legally caught in the middle of he said, she said. And if asked for proof? The collection agency says BigBank told them Alice owed it, and sold them that debt. So now the originator of the loan has harmed the collection agency as well as Alice.

Don't kill the messenger. The credit reporting agencies are doing what they are obligated to do in that business. There needs to be penalties for BigBank beyond the money BigBank lost in the scam perpetrated by criminal.

Blaming the credit reporting agencies for bad credit reports is intellectually lazy. Blaming them for garbage computer security is much more appropriate in this story. A more interesting discussion here would be about the technical details of the hack.

Re: Cybersecurity Incident Involving Consumer Information

#393
post #66

Earlier quoted context omitted.

I leave my home with a house sitter. The house sitter throws a kegger, and his guests cause six figures worth of property damage, including stealing the house sitter's laptop. Who are all the criminal parties here?

So you're saying that companies that get hacked are "asking for it", or are complicit in the criminal activity? That's an incredibly broad stretch.

Yes, because they're too lazy or it cuts into their profits too much to implement correct security.

Re: Cybersecurity Incident Involving Consumer Information

#394

Earlier quoted context omitted.

I also noted that it asked for the last 6 digits of your social. Could be they need more digits to avoid duplicates, but I've never heard anyone ask for 6 digits. Usually it's just the 4. Honestly, they should have used a subdomain off of Equifax.com.

The bad thing about that is the first 3 digits are the location digits, so someone that has the last 6 digits can easily guess your full SSN if they know where you were born (or where you lived when you got your SSN). https://en.wikipedia.org/wiki/List_of_Social_Security_Area_N...

This only works for social security numbers issued before June 25 2011. See https://www.ssa.gov/employer/randomization.html

Of course, this is cold comfort for adults today whose SSNs were issued around the time of their birth.

Re: Cybersecurity Incident Involving Consumer Information

#395
post #93

Suppose Alice is a "victim of identity theft". BigBank gives $10k to Fraudster as a loan, thinking that Alice is the actual recipient. Experian, Transunion and Equifax report this loan as a debt which Alice owes to BigBank. Who is the real victim? The credit reporting agencies want to convince people that the consumer is the victim, and so Alice bears the burden and risk of clearing her name. But it is the credit rep…

[deleted]

Re: Cybersecurity Incident Involving Consumer Information

#396
post #150

Earlier quoted context omitted.

Work at a financial firm and have built a bunch of identity theft detection features. Curious what your fix would be. Identity theft and friendly fraud losses are in the tens of billions annually and identity verification services is a huge industry.

I've never talked about this with anyone who knows the industry so it may be stupid in some obvious way, but I would gladly accept the inconvenience of having to go to my bank in person, carrying official ID, when opening lines of credit, if it would make the whole process secure. Banks could serve the process of relatively slow but reliable authentication for specific financial transactions, and communicate those au…

Thats how traditional banks work. You walk in Chase with your government ID to open up an account. It doesn't work. You can get high quality forgeries of government IDs made in China and there's no public DB to verify information on the card. RealID requirement for states to open up their driver license DBs only applies to government agencies(eg: TSA).

Also would you want to go in person to signup for paypal, venmo, etrade, betterment etc?

Re: Cybersecurity Incident Involving Consumer Information

#397

I strongly encourage anyone in the US to put a full credit security freeze on all three credit agencies. When a credit freeze is in place, you still have access to all of your existing loan accounts and whatnot (e.g. credit cards), but lenders cannot access your credit to open new accounts unless you want them to. It's not difficult nor expensive to do, and the freeze lasts until you decide to revoke it. Whenever you…

I did this about 8 years ago, and have only needed to temporally unfreeze it 3 times. Besides the big 3, I also froze reporting from Innovis. The only unforeseen hangup from frozen credit reporting I've run into is with car rentals. With a few exceptions, most car rental companies (at least in the US) run your credit. Everything else was pretty predictable.

Can you call and it get it unfrozen immediately if it needs to be run?

Re: Cybersecurity Incident Involving Consumer Information

#398
post #302

Earlier quoted context omitted.

I've never talked about this with anyone who knows the industry so it may be stupid in some obvious way, but I would gladly accept the inconvenience of having to go to my bank in person, carrying official ID, when opening lines of credit, if it would make the whole process secure. Banks could serve the process of relatively slow but reliable authentication for specific financial transactions, and communicate those au…

My information was used to open a fraudulent mortgage loan, then when I asked my bank to not allow opening credit lines or transfers online was told "we can't do that!"

Time to fire your bank.

Re: Cybersecurity Incident Involving Consumer Information

#399

Earlier quoted context omitted.

I was not saying either really. I was asking what sure fire way we have other than a number / name for identity.

Well, there is biometry, with the simplest form being a picture, if you want to somewhat reliably identify people.

While I thoroughly agree with everything you've said on the subject thus far...

How does being in possession of a picture, or any other biometric data, help? These data are reproducible, like any other attribute that supposedly identifies only-Alice.

Re: Cybersecurity Incident Involving Consumer Information

#400
post #394

Earlier quoted context omitted.

The bad thing about that is the first 3 digits are the location digits, so someone that has the last 6 digits can easily guess your full SSN if they know where you were born (or where you lived when you got your SSN). https://en.wikipedia.org/wiki/List_of_Social_Security_Area_N...

This only works for social security numbers issued before June 25 2011. See https://www.ssa.gov/employer/randomization.html Of course, this is cold comfort for adults today whose SSNs were issued around the time of their birth.

So, everyone above the age of 16 that wasn't a naturalized citizen/resident? I feel like most of them would have credit scores.
Post reply on HN