Equifax hack
I didn't find a thread on this, I hope I didn't miss it. I think most people have heard about it, hackers have our id, ss#'s and all the other personal info they need to try to defraud credit card companies and us by opening and using new credit cards in our names.
I decided to freeze my accounts at all 3 main credit reporting agencies, just for my peace of mind. I have no plans on opening any new credit cards so don't think it will be an inconvenience.
BUT, I noticed today that my junk mail was filled with emails, offering to check my credit scores for free - or with subjects pertaining to the hack, with links to click on. I can tell from the email addresses that they are not legit, but am thinking many people, nervous as they are about this breach, might click on the links. So just be aware before you click that you might be adding malware to your computer by doing so.
eta: if you go to the Equifax site to check to see if yours was breached, apparently there is language requiring you to waive you right to sue the company if you use the service. I heard on NPR a couple of days ago that the AG (of NY I believe) put pressure on them to remove that language and the president of Equifax said people whose info was stolen will NOT be bound by the language in the agreement. I didn't have time to check to see if it has been removed from their site.

I'd heard that the language (which may be removed) was in the part where you registered for the free credit protection. An offer from them but with strings attached. And may not even have been legal wording to begin with.
I used the Equifax tool linked on a Seattle news station website for checking to see if impacted. It asked for email, last - not beginning - numbers of SS to check. Neither of us showed as impacted, I'll look into it further in another day or two when things are not so crazy.
Why would waiving your right to sue the company be a problem for you?
I signed up for the free monitoring. It's the fifth or sixth time (don't remember) I've been offered free monitoring (though not before sponsored by the credit tracking/reporting agency itself) because of the possibility of maybe being affected by a data breach. Nothing has ever come of it.
I'd rather have the monitoring and jettison the need to keep thinking about it or be inconvenienced. If you want the monitoring but feel concerned about signing a waiver, it's available as a commercial service with no strings attached. You'll just the need to pay for it.
Did they ask you for a credit card when you signed up for the free monitoring, Elmer? Here's a link to an LA Times article which might be of interest.
http://www.latimes.com/business/hiltzik/la-fi-hiltzik-equifax-breach-20170908-story.html
No, just name address SSN.
Hot topic for 2 days.
https://dna-explained.com/2017/09/10/genealogy-identity-theft-and-equifax-update/
Imhappy if you think an anonymous (unsigned) piece on a genealogy site is a credible source for financial advice, then read it and be happy. I don't. I'd rather see reports in the legitimate press (NY Times and LA Times link above) and then reach my own conclusion.
Thanks for posting this olychick. I may have been impacted. Great.
Why would you trust the company whose security was breached with the task of monitoring? Seems like their track record is a bit suspect.
That's exactly what I thought. I was going to fill in a form from a link from my insurance company who issued the card, but when I saw it was Equifax I thought "No thanks, you've done enough damage already".
Olychick, as I understand it, the three major credit reporting services - Transunion, Equifax, Experian - share information. Meaning, if an Experian customer (like Bank of XYZ) contacts them to say - "Olychick on Main Street in Anytown, WA is applying for a $10K car loan, what's her score/history?", then the other two get notice of the inquiry and the new loan if granted. All of them keep records of your data and credit history to respond to their customer requests. It's apparently these customer records that were accessed, but that's info they all have all the same.
Going forward, Equifax remains in business and has customers that pay for credit scores and debt history. The service offered as a result of the data theft is to notify individuals of inquiries or activity reported to any of the credit reporting companies that involve that particular individual's name and address. The same service from any of the three will provide the same information from, I believe, the same source- the pooled info.
If some part of what I said is wrong, I'll gladly learn more. Thanks.
Elmer, I understand the info/process the same as you've written. I'm just saying, I'd not choose to go through Equifax for monitoring my credit account, based on their failure to secure the info they had. It's more assuring to me to put a freeze on my accounts in all three companies so no one can open an account in my name. I suppose that requires trust that they'll actually do the freeze, but I feel more confident about that than I do their monitoring.
Freezing your credit is a giant headache and there is little value to be gained unless you know for a fact that your identity has been compromised. Just because your info has been part of a mass attack like this one doesn't necessarily mean it will be used for ill gotten gain by anyone. The last thing I need is to have to freeze and unfreeze accounts every time I make an attempt to get a new card, buy something on time etc. Better to monitor your accounts closely yourself, use really strong passwords along with a completely different one for everything you do online, and set up your security features/notifications with the credit card companies you do business with. I use a lot of credit to my advantage and I do a bit of lite churning as well.
Really this is getting way too much press and a lot of low information advice is being offered. I call it fear mongering. Nothing wrong with accepting free credit monitoring. Not everyone needs or wants it but there is nothing negative to fear. Nothing to be scared of in that regard.
Seriously. If you really want to worry about having private info misused people should worry more about the things they share on social media, including right here.
Equifax is doing a poor job of public relations over this breach, but to blame them for the breach itself is really disingenuous. This could have happened to any of the big 3. There is no such thing as 100% security against this type of thing. That's why companies pay good money to security IT to minimize the risk to the greatest extent humanly possible. You'd have to be some higher power with supernatural spidey skills to 100% prevent it.
It could happen to any of the big three, BUT IT SHOULDN'T. They would have to spend more to put up more defenses protecting sensitive data, the government would have to require them to pay substantial fines and report breaches in a more timely fashion or pay even more substantial fines. But THESE THINGS CAN BE DONE.
And who's to say that they actually do pay good money to security IT to minimize the risk to the fullest possible extent currently? As opposed to spending good money on their CEO, CFO salaries and shareholder returns? It's getting lots of press because these credit reporting companies have everyone's financial lives in data in their hands, which many have assumed were very capable hands. Part of the issue is the decisions that have been made to connect everything one can imagine to the internet, store everything in the cloud, etc. And yes tech companies have oversold what they are doing and/or are capable of providing - the lack of time to or interest in contemplation of possible consequences however unintended, a ripple effect that grows unimaginably from one tiny quirk in a process or program. People have been demanding fast, faster and fastest, we've started to unlearn how to delay gratification just a little bit more over time in the drive for new, shiny and the latest advances available on the market.
But no, I don't plan on going back to handwritten mail delivered by the postal service or giving up my computer with all the interesting things it can connect me to on the internet. That genie isn't going back in the bottle. Evidently, because of the experian hack, neither will people's sensitive financial data.
Watchmelol, I think your warning about freezing is a good one for many people, but I don't buy things on time, nor am I going to open any more credit cards in the future, so I'm hoping it's not too big of a hassle for me personally. If it is, I'll unfreeze it. I don't use much social media. I don't do facebook (I have it under a fake name, same with Nextdoor, fake name). I feel like I'm pretty careful.
I agree completely with watchme. I don't feel a need for either gloom and doom nor credit freezes to be part of my approach. Even with the numerous data breaches I've been told my personal info has been part of in the last 10 years, no nefarious activity has ever resulted. Might it happen this time? Sure. I could also get hit by another car while driving today. Neither possibility will alter what I plan to do.
No data on internet connected systems is entirely safe from invasion and no one should have any expectation otherwise. These systems need to be accessed by third parties and keeping the bad guys out will never be 100% certain. Big companies pay big bucks for security systems and software and the evil-doers will always still find ways to get in. That's the daily reality, something to get used to hearing about.
I have put credit freezes on all three reporting agencies. I have no plans to apply for any new credit cards and I just leased a new car. I can lift the freeze if I want. I see no downside for me.
I just listened to Jill Schlesinger (financial expert) interview on NPR recommending that people put a freeze on their credit file (among other things)....
http://www.jillonmoney.com/equifax-data-breach/
I know a few people who have done credit freezes in a panic and found that having them in place made their own financial lives going forward sometimes awkward and difficult to work with.
I get it that when identity theft leads to phony accounts and transactions in an individual's name, the cleanup can involve a lot of grief, massive hassles and complications but usually not any financial losses. Media personalities in financial and market beats rarely give practical advice, it's usually very cautious and conservative advice. That fits the bill for some but not for everyone. And not for me.
As with many things, there's no one answer that covers all people and situations.
We froze our reports at least ten years ago. There have been VERY few times I needed to 'unfreeze'; very simple.
So...if someone cannot use our information to get credit, what can he do with names, DOB's, SSN's, etc.?
All I can think of immediately is an attempt to withdraw 2017 1040-ES funds. How would a person use the information to establish a new identity -- pseudo-Sue?
Sometimes, they use that info to get a phony passport, or even a real one, using someone else's identity. When my daughter was in college, she was asked to represent her school at an international hotel school conference in Switzerland. On the last night, she and friends went out for drinks - she carefully hid her handbag behind the nightstand in her room and took a few dollars in cash with her to a bar. When she returned, her handbag was gone - passport, credit cards, student ID, driver's license, airplane and train tickets, money and the keys to her car left at the Syracuse airport - just EVERYTHING.
She called us and we contacted the emergency State Dept number (it was a Sat). The State Dept officer said that some little girl in Eastern Europe would most likely assume her identity to come to the US - that these were "stolen to order" based on physical attributes. And they had an entire "life story" due to having all those other things.
It was quite a tedious process to get her home - borrowing money from a girl traveling with her, for train fare to Zurich, having money wired by her then boyfriend, now husband, to be picked up in Zurich (we were in rural ME at the time with the nearest Western Union 2 hrs away in Portland), finding a hotel room and checking in with no ID (bit of a challenge - the Swiss are sticklers for the rules), and then going to the Consulate to get a replacement passport on Monday. Of course, plane tickets had to be changed and penalties paid for at this end, and a duplicate set of car keys FedExed to the the ticket counter in Syracuse so she could drive her car back to Cornell. State had to issue her a temporary license with no photo until she came home for spring break. I can tell you it was a very exhausting process, with much of it having to be done by me at this end! I've often wondered if someone did assume her ID to get into the US. That was a long time ago - 1995.
One of the comments at the link OlyChick posted says:
and try to verify that your history has been affected. It might say
that it "may" have been affected. The operative word is "may" Does that
satisfy or were you expecting a direct, unequivocal yes or no answer.
Now type in a last name, any last name will do, and any series of 6
numbers. Look at what they return ... the site might say that you may
have been affected or it may say that you were not affected. Now
remember, there is no such person as the one you just entered with the
random numbers you chose. So, the information returned is bogus dross
and tells you nothing including if the return generated from your valid
information is correct. But, it just might drive you to panic and sign
up with their wing-ding-bee’s knees credit protection scheme.
So it sounds like they may not have any idea of what data or how much was stolen.
Other stories I read said that the hack started perhaps as early as May, and that they didn't discover it until late July. And then they didn't tell us about it until September. Furthermore after discovering they had been hacked but before releasing the information, several (three?) of their top executives sold large chunks of their stock in the company. How is that not blatantly illegal?
The whole business always seemed weird to me. We don't give permission for our business transactions to be collected -- they just DO it so they can sell the information to other businesses who want to lend you credit.
Have you ever tried to correct misinformation with one of these companies. A mass of red tape leading to no corrections.
Our reports are 'supposedly' frozen. Why would I trust that this is true?
OT: We live in a weird world, where nobody *owns* anything, but lives on CREDIT, paying interest for the 'privilege' and dependent on 'scores'. Reminds me of life 'at court' in the Middle Ages.
We placed credit freezes yesterday. Three quick and easy phone calls to Equifax, Experian and TransUnion. Fees were waived.
http://www.chicagotribune.com/business/ct-how-to-freeze-your-credit-equifax-20170911-story.html
Financial regulations to protect consumers and provide businesses who handle credit transactions a means to verify data and decide whether they want to risk lending or selling on credit to any given individual - that is why companies like equifax exist. Like any business, including the government, there are operation costs to reviewing, collecting, storing, and cataloging data - the government decided that the States couldn't (the job of the Feds includes seeing to matters involving more than one state, ) and the Feds thought private industry would do the job best, allowing anyone "running someone's credit" to see the data but not for free. Of course collections agencies are going to use what they find to try and get repayment of a debt, including those who wade through a pile of debt hoping to resurrect one to create "zombie debt" - they even will try to collect after the amount agreed to under terms of a settlement has been paid by the debtor; debts that have passed the time limit during which it can affect a credit report which results in a charge off (I think that's what they call it). Credit reporting companies can be viewed as the best idea there was to come up with considering the government operates at the speed of the San Andreas fault's moving SoCal to its future location which is where San Francisco is currently, especially when it would affect their campaign fundraising needs if they don't look out for their donor's best interests which have become their own.
OT: We live in a weird world, where nobody *owns* anything, but lives on CREDIT, paying interest for the 'privilege' and dependent on 'scores'
While that may be true for many that doesn't apply to all. I haven't paid a dime in interest in years with the exception of a very low interest auto loan and a whopping 63.00 on the purchase of my kitchen cabinets while I waited to transfer the low interest deal into a zero interest one. Back when we were younger and less wise we needed credit at times to help us get by.Today I use credit as "free" money for up to a month. I get to use the financial institution's cash instead of my own and earn rewards as well at no cost to me other than the time it takes to manage my accounts. Keeping my score high I am able to open new accounts as needed to get promotional zero interest deals as the need for a major purchase arises. I pay them off early and make sure to never exceed my budget and ability to pay them off.