Live data from Hacker News

Cybersecurity Incident Involving Consumer Information

investor.equifax.com

431–440 of 551 posts

Re: Cybersecurity Incident Involving Consumer Information

#431
post #93

Suppose Alice is a "victim of identity theft". BigBank gives $10k to Fraudster as a loan, thinking that Alice is the actual recipient. Experian, Transunion and Equifax report this loan as a debt which Alice owes to BigBank. Who is the real victim? The credit reporting agencies want to convince people that the consumer is the victim, and so Alice bears the burden and risk of clearing her name. But it is the credit rep…

Agree with your point on Experian absolving itself, but there are many scenarios in which Alice is also the victom of the thief. With enough info about someone, you can steal digital assets too.

Re: Cybersecurity Incident Involving Consumer Information

#432
post #93

Suppose Alice is a "victim of identity theft". BigBank gives $10k to Fraudster as a loan, thinking that Alice is the actual recipient. Experian, Transunion and Equifax report this loan as a debt which Alice owes to BigBank. Who is the real victim? The credit reporting agencies want to convince people that the consumer is the victim, and so Alice bears the burden and risk of clearing her name. But it is the credit rep…

Agreed. Thought experiment: suppose instead that Fraudster convinced Alice that he represented BigBank, and so Alice was duped and gave her money to Fraudster thinking she was depositing into BigBank. The only thing she could expect from BigBank was politeness while explaining to her that she was duped. If it's a very friendly bank, she may tie up a manager for a couple hours, but that's it. If she keeps coming back,…

An even more analogous experiment would have Alice take out a mortgage with BigBank, then receive a fake notice of debt reassignment to BiggerBank, which is actually Mallory. Alice makes mortgage payments to Mallory for many months. Now BigBank is wondering why Alice fell behind on her mortgage.

Who's the victim?

Re: Cybersecurity Incident Involving Consumer Information

#433
post #339
post #316

Earlier quoted context omitted.

>carrying official ID It's probably not hard to forge a social security card and birth certificate if you have the relevant information. From there, a state ID (or maybe even passport) should be possible to get. I don't believe there is any biometric security on either. A determined identity thief might go that far.

The thief would have to physically resemble the victim's photo, height, age, gender, etc, which is some added defense in depth. For instance it would be hard for most males to pass themselves off as a typical female.

About twenty five years ago a bank allowed someone to cash checks with my name on them with all the correct account info on them as well, but was a different race and gender than I am (the banks had video of the customer). They did this about a dozen times for checks for what I assume was just under the amount that would flag it (about $2000) to empty my account over the course of about an hour, using different drive throughs at different branches in Houston, I lived in Austin at the time and had never visited a branch in Houston.

Re: Cybersecurity Incident Involving Consumer Information

#434
post #372

Earlier quoted context omitted.

What Alice is the victim of is slander , not fraud or identity theft. The bank lent some money to someone who claimed to be Alice (though the bank only relied on the fact that that person knew Alice's SSN as proof of that fact). Then when the bank didn't get paid back, they told a bunch of credit check bureaus that Alice was a credit risk. This was a lie about Alice, which has a material impact on Alice's reputation.…

Defamation laws differ by state, but in NY for example, I believe libel (slander refers to oral defamation) requires that the perpetrator knew, or should have known, that the statements were false. The question would then become whether the bank's identity verification procedures satisfy that burden. I think it would be a difficult endeavor, but it would be good to see it tested.

Yes, libel is correct.

They absolutely should have known it was wrong -- their business is lending money to people! If their procedure is insufficient, they should have fixed this.

I would love to see the banks sued for libel, a massive class action suit. There are real monetery damages it one could put a number on, and the difference between a bad and a good 30 year mortgage will be a big number.

Re: Cybersecurity Incident Involving Consumer Information

#435
post #376

Earlier quoted context omitted.

Seems KYC as used in the real world doesn't do a very good job of verifying whether the "customer" is Alice or the fraudster... It'd be nice if _that_ requirement had enough teeth to reduce the ability of the financial institution to claim Alice is "the victim"...

Curious how would you verify a user? Right now standard solution is to use public records(LexisNexis), credit history(Experian), fraud detection networks(early warning). Along with a bunch reputation providers around IP(Maxmind,Socure), email(emailage), address. Also government based ID and utility bills etc. This isn't cheap and can costs $10+ to run all these checks. Even government can't verify people and its prob…

sïx mönths äġö ï löst mÿ jöb änd äftër thät ï wäs förtünätë ënöüġh tö stümblë üpön ä ġrëät wëbsïtë whïċh lïtërällÿ sävëd më. ï stärtëd wörkïnġ för thëm önlïnë änd ïn ä shört tïmë äftër ï'vë stärtëd ävëräġïnġ 15k ä mönth... thë bëst thïnġ wäs thät ċäüsë ï äm nöt thät ċömpütër sävvÿ äll ï nëëdëd wäs sömë bäsïċ tÿpïnġ skïlls änd ïntërnët äċċëss tö stärt... This is where to start●¦¦¦¦F¦O¦L¦L¦O¦W¦¦M¦E¦¦¦¦¦http://ow.ly/GkdF30eQMaC

Re: Cybersecurity Incident Involving Consumer Information

#436

Not sure if anyone else suggested this, but people should file complaints to the CFPB about this: https://www.consumerfinance.gov/ Not just about the hack, but the fact that their "check to see if you were affected by our shit" sites include a ToS that waives your right to participate in a class-action lawsuit. https://trustedidpremier.com/static/privacy-policy

ToS link:

https://trustedidpremier.com/static/terms

To my reading, the arbitration clause may only apply to people who take the step of signing up for the credit monitoring they offer. But, of course, they are urging everyone to sign up....

Re: Cybersecurity Incident Involving Consumer Information

#437
post #428
post #408

Earlier quoted context omitted.

Hmm, I guess you could call it slander if the person and the dossier were perfectly interchangeable. But all the institutions know is that someone has been failing to pay back loans that were issued based on the information in a dossier. After a series of fraudulent loans to "Alice Doe, SSN 123-45-6789" (the file, not the person), when some random shows up at Yet Another State Bank and tries to take out a loan under…

That distinction holds up only if real Alice isn't inconvenienced in any way.

She would be inconvenienced, but that doesn't mean she was slandered.

If someone steals Alice's car and commits a hit-and-run, she will be inconvenienced when the cops show up at her door, but the person who reports her plates won't be committing slander.

Re: Cybersecurity Incident Involving Consumer Information

#438

I strongly encourage anyone in the US to put a full credit security freeze on all three credit agencies. When a credit freeze is in place, you still have access to all of your existing loan accounts and whatnot (e.g. credit cards), but lenders cannot access your credit to open new accounts unless you want them to. It's not difficult nor expensive to do, and the freeze lasts until you decide to revoke it. Whenever you…

I did this about 8 years ago, and have only needed to temporally unfreeze it 3 times. Besides the big 3, I also froze reporting from Innovis. The only unforeseen hangup from frozen credit reporting I've run into is with car rentals. With a few exceptions, most car rental companies (at least in the US) run your credit. Everything else was pretty predictable.

> Besides the big 3, I also froze reporting from Innovis.

Why Innovis? Who typically uses their reports?

Re: Cybersecurity Incident Involving Consumer Information

#439
post #194

Earlier quoted context omitted.

I think the true error in process is that a SSN is considered to be a secret, unique ID, and many (many!) institutions allow you to use it as a proof of identity. It's short, guessable, would fail all of their own password requirements, and yet somehow it gets a free pass. I just consider my SSN to be public, and move about my digital life with that assumption. I don't go plastering it on walls, but if I encounter a…

It's pretty much the flaw in not having a national ID scheme - everyone reaches for the next closest approximation, with no funding for security systems or refreshes to address flaws. Because this is an issue the government should address seriously.

Even with a national ID scheme, I don't know of any country who has implemented a way to validate that the holder of the ID document is the person who is the person who the ID document corresponds to without the person being present so that their biometric data can be validated.

Re: Cybersecurity Incident Involving Consumer Information

#440
post #93

Suppose Alice is a "victim of identity theft". BigBank gives $10k to Fraudster as a loan, thinking that Alice is the actual recipient. Experian, Transunion and Equifax report this loan as a debt which Alice owes to BigBank. Who is the real victim? The credit reporting agencies want to convince people that the consumer is the victim, and so Alice bears the burden and risk of clearing her name. But it is the credit rep…

If it was on the BigBank to always prove that their identity was indeed stolen, it would quickly become unmanageable. People would commit fraud in the opposite direction, by getting a huge loan from some a bank and claiming that their identity is stolen. I'm sure it would be easier than stealing someones identity to do it, and it would obviously involve some necessary actions to avoid being caught but this would drive loan rates through the roof for the average citizen to make up for all the fraud occurring. I agree with you ideologically, but in practicality i do not believe it would work.
Post reply on HN