Live data from Hacker News

Cybersecurity Incident Involving Consumer Information

investor.equifax.com

181–190 of 551 posts

Re: Cybersecurity Incident Involving Consumer Information

#181
post #93

Suppose Alice is a "victim of identity theft". BigBank gives $10k to Fraudster as a loan, thinking that Alice is the actual recipient. Experian, Transunion and Equifax report this loan as a debt which Alice owes to BigBank. Who is the real victim? The credit reporting agencies want to convince people that the consumer is the victim, and so Alice bears the burden and risk of clearing her name. But it is the credit rep…

What Alice is the victim of is slander, not fraud or identity theft. The bank lent some money to someone who claimed to be Alice (though the bank only relied on the fact that that person knew Alice's SSN as proof of that fact). Then when the bank didn't get paid back, they told a bunch of credit check bureaus that Alice was a credit risk. This was a lie about Alice, which has a material impact on Alice's reputation. The credit agencies then go ahead and repeat that slander.

Re: Cybersecurity Incident Involving Consumer Information

#182
post #62

Earlier quoted context omitted.

Anyone know if there's a way to get your free credit report if you can't answer the questions for the free one? The computer says no, and the phone number just sends a letter that says no. I tried to to buy one from my bank, but as far as I can tell they only sell subscriptions...

You could see if Credit Karma works. I think it is mostly a free interface to Trans Union though.

Funny enough, it also provides your Equifax report.

Re: Cybersecurity Incident Involving Consumer Information

#183
post #121
post #93

Suppose Alice is a "victim of identity theft". BigBank gives $10k to Fraudster as a loan, thinking that Alice is the actual recipient. Experian, Transunion and Equifax report this loan as a debt which Alice owes to BigBank. Who is the real victim? The credit reporting agencies want to convince people that the consumer is the victim, and so Alice bears the burden and risk of clearing her name. But it is the credit rep…

Bigbank is the only one in your scenario that actually has monetary loss since they lent out the money and most likely will never get it back. In identity theft, the company has the financial loss. FBI won't investigate unless its over 250k in losses as well.

Fraud isn't limited to credit. My dad had someone open a savings account in his name and transfer a significant amount of money via ACH. He only found out because he got a welcome or from the bank!

The police investigator told him that the particular fraud that he was a victim to was impacting >500 people and >$5M

Re: Cybersecurity Incident Involving Consumer Information

#184

"Three Equifax Inc. senior executives sold shares worth almost $1.8 million in the days after the company discovered a security breach that may have compromised information on about 143 million U.S. consumers." https://www.bloomberg.com/news/articles/2017-09-07/three-equ... Edit: Also discussed here https://news.ycombinator.com/item?id=15196309

So, that should definitely get them busted for insider trading, no?

Re: Cybersecurity Incident Involving Consumer Information

#185

I strongly encourage anyone in the US to put a full credit security freeze on all three credit agencies. When a credit freeze is in place, you still have access to all of your existing loan accounts and whatnot (e.g. credit cards), but lenders cannot access your credit to open new accounts unless you want them to. It's not difficult nor expensive to do, and the freeze lasts until you decide to revoke it. Whenever you…

Question for you: My card comes with Identity theft protection [1]. Do you think that's a good alternative to freezing credit completely?

[1] https://www.discover.com/credit-cards/member-benefits/securi...

Re: Cybersecurity Incident Involving Consumer Information

#187
post #36
post #4

Earlier quoted context omitted.

It sounds like ssn is not fit for purpose. If the gov is going to issue a 'secret number ' why not a 2fa device?

The SSN was never intended as a national ID. It was originally created alongside the Social Security Administration, to track what individuals put in and what they take out. People only received one upon becoming employed. Over time, the IRS realized that it could be used as a national ID, and adopted it for that purpose. They encouraged people to obtain one from a young age (even for their newborn children), and it…

Why do we need to number people anyway? People are very consistent with spelling their own names. This combined with a birth date and/or a birth city should be enough to uniquely identify anyone.

Think about passwords. A SSN is only nine digits, 0-9. JohnHarrySmith19900101NewYork is far more secure. And doesn't dehumanize the recipient.

Re: Cybersecurity Incident Involving Consumer Information

#188
post #93

Suppose Alice is a "victim of identity theft". BigBank gives $10k to Fraudster as a loan, thinking that Alice is the actual recipient. Experian, Transunion and Equifax report this loan as a debt which Alice owes to BigBank. Who is the real victim? The credit reporting agencies want to convince people that the consumer is the victim, and so Alice bears the burden and risk of clearing her name. But it is the credit rep…

The credit agencies report what has been told to them by BigBank. Once the fraud is detected BigBank should update them that Alice does not in fact have a $10,000 loan with them and it would then be removed from Alice's report. If the loan has been determined to be fraudulent and it has not removed from her credit report, BigBank is victimizing her not the credit agencies.

Re: Cybersecurity Incident Involving Consumer Information

#190
post #160

> The company has found no evidence of unauthorized activity on Equifax's core consumer or commercial credit reporting databases. The information accessed primarily includes names, Social Security numbers, birth dates, addresses and, in some instances, driver's license numbers. So what are they saying? Was all this information accessed or not accessed?

If it wasn't accessed, they would have been very clear about that. They're just mentioning "core consumer or commercial credit reporting databases", whatever those are, to dilute the horrifying message and confuse everyone.
Post reply on HN