Equifax compromised 143 million people's Social Security numbers and other data

Authored by theverge.com and submitted by Majnum
image for Equifax compromised 143 million people's Social Security numbers and other data

Equifax announced today that 143 million US-based users had their personal information compromised this year. Attackers reportedly exploited a vulnerability on Equifax's website to steal names, Social Security numbers, birthdates, addresses, and, in some cases, driver’s license numbers. Credit card numbers for approximately 209,000 people and certain dispute documents with personal identifying information for approximately 182,000 people were also accessed. Although Equifax operates in other countries, it didn't detect any stolen personal information abroad.

The company says it discovered the breach on July 29th this year, and has since plugged the security hole. The company also set up a dedicated website — www.equifaxsecurity2017.com — for possible victims to sign up for credit file monitoring and identity theft protection.

Data breaches are fairly common, although those impacting Social Security and driver's license numbers are rarer and more serious. The fact that Social Security numbers are included in the breach makes it likely that victims will be targeted for identity theft. Equifax says it's working with both an independent cybersecurity firm and law enforcement to investigate.

hopeishigh on September 7th, 2017 at 21:46 UTC »

A year of credit monitoring? I don't even understand. The likely hood is that every single person reading this was impacted yet some how after a year it's alright. My social security number never changes, not even after a year.

flunky_the_majestic on September 7th, 2017 at 21:43 UTC »

Guys, it's starting to seem like it's a bad idea to rely on a 9 digit number, kept strictly secret, yet shared with dozens of organizations, in order to authenticate a person to receive credit, interact with the government, access banking, and gain employment.

Edit: counting digits

L1ghtf1ghter on September 7th, 2017 at 21:30 UTC »

Equifax announced today that 143 million US-based users had their personal information compromised this year. Attackers reportedly exploited a vulnerability on Equifax's website to steal names, Social Security numbers, birthdates, addresses, and, in some cases, driver’s license numbers.

Welp. You'd think a major credit reporting agency would have top-grade security infrastructure. The impact of this could be massive -- that's over a third of the American population.

ETA: That "free" credit monitoring service they're so graciously offering is in fact only free for the first year. After that, you get the privilege of paying them in the wake of their fuckup. Also, word is that if you DO enroll in the program, you're also agreeing to binding arbitration, e.g. waiving your right to sue or take part in a class action lawsuit. Win-win-win. For Equifax.