• Welcome to the Internet Infidels Discussion Board.

Equifax hack

https://krebsonsecurity.com/2017/09/experian-site-can-give-anyone-your-credit-freeze-pin/

An alert reader recently pointed my attention to a free online service offered big-three credit bureau Experian that allows anyone to request the personal identification number (PIN) needed to unlock a consumer credit file that was previously frozen at Experian

The first hurdle for instantly revealing anyone’s freeze PIN is to provide the person’s name, address, date of birth and Social Security number (all data that has been jeopardized in breaches 100 times over — including in the recent Equifax breach — and that is broadly for sale in the cybercrime underground).

After that, one just needs to input an email address to receive the PIN and swear that the information is true and belongs to the submitter. I’m certain this warning would deter all but the bravest of identity thieves!

The final authorization check is that Experian asks you to answer four so-called “knowledge-based authentication” or KBA questions. As I have noted in countless stories published here previously, the problem with relying on KBA questions to authenticate consumers online is that so much of the information needed to successfully guess the answers to those multiple-choice questions is now indexed or exposed by search engines, social networks and third-party services online — both criminal and commercial.


What’s more, many of the companies that provide and resell these types of KBA challenge/response questions have been hacked in the past by criminals that run their own identity theft services.

Game over, man. Game over.

There's nothing you can do to protect yourself, all that's left is just to hope that you win (lose?) the reverse lottery.
 
I have done nothing about in response to this. Is that stupid?
 
I have done nothing about in response to this. Is that stupid?

No, one of the websites they gave out to go to was phishing.

If anyone went to the wrong website, then you should go to iamstupidhacked.com and put your name and social security number in. They will tell you if you are at risk.
 
I have done nothing about in response to this. Is that stupid?

The best thing to do is to keep an eye on things--sites like creditsesame and creditkarma. Since I already use both there was nothing more to do.
 
I have done nothing about in response to this. Is that stupid?

I froze my credit on four agencies, and keep a close eye on Credit Karma and USAA (which gives me my Experian report) but it is a crap shoot as to whether it will do any good.
 
I have done nothing about in response to this. Is that stupid?

The best thing to do is to keep an eye on things--sites like creditsesame and creditkarma. Since I already use both there was nothing more to do.
I like how I'm supposed to keep an eye on whether credit card companies provide criminals fraudulent accounts under my name. Especially because of third party companies who took my personal credit history without consent and allowed a bunch of criminals (or foreign intelligence) to go in the front door and walk out with it.

Only in America! Free Market says the buck always stops with you. Does the US Government understand yet that this helps provide foreign intelligence groups information about who is and isn't more likely to be easy to turn into a mole?
 
The best thing to do is to keep an eye on things--sites like creditsesame and creditkarma. Since I already use both there was nothing more to do.
I like how I'm supposed to keep an eye on whether credit card companies provide criminals fraudulent accounts under my name. Especially because of third party companies who took my personal credit history without consent and allowed a bunch of criminals (or foreign intelligence) to go in the front door and walk out with it.

Only in America! Free Market says the buck always stops with you. Does the US Government understand yet that this helps provide foreign intelligence groups information about who is and isn't more likely to be easy to turn into a mole?

A few years ago our local hospital had its records hacked. Someone in China did it. Could they have just been looking for social security numbers, banks account numbers, credit card numbers,? Yeah sure. But if they got into some of the medical records I wouldn't be surprised if they got some good blackmail information in there. Somebody may have some diseases good moral Christian people aren't supposed to get and they may show on their records they use certain drugs or were treated for using certain drugs they aren't supposed to be using.
 
No bid contract?!
article said:
Reps. Suzan DelBene (D-Wash.) and Earl Blumenauer (D-Ore.) separately penned letters to IRS Commissioner John Koskinen demanding he explain the agency's rationale for awarding the contract to Equifax and provide information on any alternatives the agency considered.

"I was initially under the impression that my staff was sharing a copy of the Onion, until I realized this story was, in fact, true," Blumenauer wrote.
 
Back
Top Bottom