Equifax website hack reveals data of ~143 million U.S. consumers arstechnica.com/information-technology/2017/09/equifax-website-hack-exposes-data-for-143-million-us-consumers/ massive Equifax data breach could affect half of the U.S. population www.nbcnews.com/tech/security/massive-equifax-data-breach-could-impact-half-u-s-population-n799686 Equifax`s response to the breach has raised concerns among Security experts and consumer advocates From. Security expert Brian Krebs called Equifax`s public relations efforts after the breach «arbitrary,» poorly designed» and a «dumpster fire.» Equifax has created a separate domain – equifaxsecurity2017.com – where consumers can know if their information was compromised during the breach. This resulted in the site being flagged as a phishing threat by browsers. Developer Nick Sweeting bought the securityequifax2017.com domain to show that Equifax`s decision to create a separate domain made it much easier for phishing websites to imitate it and confuse people. Equifax`s Twitter account accidentally tweeted a link from the fake website. Consumers who contacted Equifax immediately after the breach to freeze their funds were given PINs for the date and time of the freeze, making them easier to guess. The cities of San Francisco and Chicago sued Equifax.
San Francisco`s complaint alleges violations of California`s illegal, unfair, or fraudulent business practices law when (1) proper security practices were not implemented and maintained; (2) failed to give timely notice of the violation; and (3) did not provide clear and complete information. It seeks compensation for California consumers who purchased credit monitoring services from Equifax prior to the breach was announced, up to a maximum of $2,500 for each violation of the law, and a court order requiring Equifax to implement and maintain appropriate security procedures. Chicago`s complaint alleges violations of the Illinois Privacy Act, the Illinois Consumer Fraud and Deceptive Marketing Practices Act, and the Chicago Consumer Fraud Ordinance for (1) the disclosure of personal information; (2) failure to report the violation in a timely manner; and (3) mislead consumers by presenting their credit monitoring service as complementary if it includes a mandatory arbitration clause that prevents users of the service from bringing future lawsuits against Equifax. Either way, once the breach became known, Equifax`s immediate response didn`t receive much applause. Their stumbling blocks included setting up a separate dedicated domain, equifaxsecurity2017.com hosting the site with information and resources for potentially affected people. These similar types of domains are commonly used by phishing scams, so asking customers to trust them was a monumental mistake in the infosec process. Even worse, on several occasions, Equifax`s official Social Media accounts mistakenly asked people to securityequifax2017.com instead; Luckily, the person who retrieved this URL used it forever and led the 200,000 (!) Finally, the FTC encourages Equifax employees who feel the company is not keeping its data security promises to email the FTC in equifax@ftc.gov. Consumers can inquire about billing under ftc.gov/Equifax. Equifax can`t protect data, but it can keep a secret www.bloomberg.com/gadfly/articles/2017-10-03/equifax-can-t-protect-data-but-it-can-keep-a-secret Equifax suffered a hack nearly five months before the date it was revealed www.bloomberg.com/news/articles/2017-09-18/equifax-is-said-to-suffer-a-hack-earlier-than-the-date-disclosed The massive Equifax hacking scandal could cost $70 billion www.vanityfair.com/news/2017/09/equifax-hack-lawsuit Meanwhile, the Real equifaxsecurity2017.com Breach site has been deemed dangerous by many observers and may have just told everyone that they were affected by the breach, whether they really were or not. The wording of the website (later removed by Equifax) implied that it was only by checking if you were affected that you waived your right to sue on the matter. And ultimately, if you were affected, you`d be asked to sign up for an Equifax identity protection service — for free, but how much trust the company at the time? What happens if sensitive information falls into the wrong hands? With the advancement of technology in the twenty-first century comes the growing problem of data breaches where sensitive information is exposed.
On September 7, 2017, Equifax, one of the top three credit reporting agencies in the United States, announced one of the largest data breaches in U.S. history. The data breach affected an estimated 145 million consumers and was followed by a wave of consumer class actions. This note explains why class actions and arbitration are not viable remedies for massive data breaches when companies like credit bureaus are hacked and, in this case, where Equifax has been hacked. In addition, this opinion also recommends the creation of an independent victim recovery fund as a solution to the Equifax data breach. The fund would build on other proven victim compensation funds, such as the September 11 Victim Compensation Fund and the Deepwater Horizon Settlement Fund. Three Equifax executives sold shares before cyber hacking revealed www.bloomberg.com/news/articles/2017-09-07/three-equifax-executives-sold-stock-before-revealing-cyber-hack former Senior Equifax executive arstechnica.com/information-technology/2018/03/senior-equifax-executive-charged-with-insider-trading/ accused of insider trading As Equifax collected more and more data, security was a selling point www.nytimes.com/2017/09/23/business/equifax-data-breach.html Congress should prohibit the use of the Social Security number in the private sector without explicit legal authority. They were never intended to be used as a general-purpose identifier.
Equifax was motherboard.vice.com/en_us/article/ne3bv7/equifax-breach-social-security-numbers-researcher-warning it was a lot of fear just to find out if you were one of the unfortunate 40% of Americans whose data was stolen during the hack. Things calmed down in the following years, and now there`s a new website where you can check if you`re affected, with another somewhat confusing name: eligibility.equifaxbreachsettlement.com/en/Eligibility. The revelation of the breach has drawn the attention of lawmakers and regulators at the federal and state levels, several of whom have expressed the view that increased federal regulation of the credit reporting industry and other companies that store large amounts of sensitive personal data may be needed to combat similar incidents in the future. The attorneys general of New York and Massachusetts have launched investigations and prosecutions, and the Consumer Financial Protection Bureau (CFPB), which shares oversight of credit bureaus with the Federal Trade Commission (FTC), is investigating the breach and Equifax`s response. Three committees of the U.S. House of Representatives — judiciary, financial services, energy and commerce — plan to hold hearings on the violation in the coming weeks. Senate Finance Committee Chairman Orrin Hatch (R-Utah) and Senator Ron Wyden (D-Oregon) sent a letter to Equifax management highlighting the seriousness of the breach: «Equifax is a critical partner of the Internal Revenue Service, the Centers for Medicare & Medicaid Services, the Social Security Administration and other federal agencies. who are the sources and recipients of some of the most sensitive information about individuals. and the targets of the vast majority of identity theft at taxpayers` expense. Senators are demanding that Equifax be released by March 28. September 2017 provides answers to 13 questions set out in the letter, which include information such as a detailed timeline of the breach, the steps Equifax is taking to mitigate and respond appropriately to the breach, general information about Equifax`s information security program, whether Equifax has engaged external security experts to test its systems, and whether the company has worked on it. Resolve any issues identified during security testing.