Credit monitoring agency Equifax revealed shocking news late Thursday: A data breach of the company’s servers from mid-May through July 2017 resulted in the theft of the personal information of up to 143 million U.S. consumers—a huge chunk of the country’s 324 million population. Equifax says the breach leaked highly sensitive information, too, including “names, Social Security numbers, birth dates, addresses and, in some instances, driver’s license numbers.” 

That’s everything crooks need to open up credit lines in your name, or worse. And now it’s in nefarious hands.

Equifax hack: Was I affected?

Shamefully, Equifax won’t be contacting most of the 143 million victims directly to let them know they’ve fallen prey to data hackers. The hackers also swiped credit card numbers for 209,000 people, and “certain dispute documents with personal identifying information” for 182,000 more. Equifax will mail those particular victims—far less than 1 percent of everyone affected—a notice that they were affected by the breach.

Brad Chacos/IDG

The FAQ page on equifaxsecurity2017.com says Equifax doesn’t need to notify hack victims because it issued a press release and made a webpage.

Finding out if you were affected by the Equifax hack is trickier (and murkier) if you’re not part of that sliver. Equifax created the www.equifaxsecurity2017.com website for U.S. consumers to “see if your personal information is potentially impacted.” Let’s be frank: It looks like a fraud site. It’s frighteningly bare-bones and runns on WordPress, the URL differs from Equifax’s main site, some browsers were throwing up phishing warnings due to back-end configuration issues, and Equifax even asks for your social security number to confirm whether it leaked your social security number. Those are all classic signs of a malicious phishing site, but fear not: equifaxsecurity2017.com is legitimate.

Head to the Potential Impact page of the Equifax Security website to find out if you were affected. Simply click the “Check potential impact” button and supply your last name and the last six digits of your social security number.

equifax real boy Brad Chacos/IDG

If the credit agency doesn’t believe you were impacted, it’ll tell you so and pitch you to register for Equifax’s “TrustID Premier” credit monitoring service, which the company will provide for free for one year regardless of whether or not your data was stolen.

thank you Brad Chacos/IDG

Alternatively, the site may report that “We believe that your personal information may have been impacted by this incident” and again prompt you to enroll for TrustID Premier.

equifax fail Brad Chacos/IDG

TechCrunch points out that TrustID Premier’s terms of service—which were last updated September 6, the very day before Equifax disclosed this hack after knowing about it since July 29—state that users waive their right to bring a class-action lawsuit against Equifax. So if that’s something you’re considering, maybe hold off signing up for the free year of TrustID Premier on your “enrollment date.”



Source link