Equifax Hacked - 143M US Consumers could be affected

Page 8 - Seeking answers? Join the AnandTech community: where nearly half-a-million members share solutions and discuss the latest tech.

Pantoot

Golden Member
Jun 6, 2002
1,764
30
91
Yeah, I also think the number of people that are freezing their credit (and opting out of prescreened offers as a result) have to be hurting their bottom lines.

[edit: freeze doesn't opt you out like I thought it did]
 
Last edited:

rh71

No Lifer
Aug 28, 2001
52,856
1,048
126
So if you don't freeze your credit and you become an actual victim, is none of it reversible? Are we in any way protected after the fact?

Or are people going through the trouble to freeze because they don't want to go through the hassle later if something does happen?
 
Nov 8, 2012
20,828
4,777
146
Yeah, I also think the number of people that are freezing their credit (and opting out of prescreened offers as a result) have to be hurting their bottom lines.

Something I haven't confirmed yet - does freezing your credit automatically opt you out of pre-screened offers? Or is possible to freeze your credit and still get pre-screened offers?
 

Pantoot

Golden Member
Jun 6, 2002
1,764
30
91
Something I haven't confirmed yet - does freezing your credit automatically opt you out of pre-screened offers? Or is possible to freeze your credit and still get pre-screened offers?
Good point, ftc says no, it doesn't:
https://www.consumer.ftc.gov/articles/0497-credit-freeze-faqs said:
Does a credit freeze stop prescreened credit offers?
No. If you want to stop getting prescreened offers of credit, call 888-5OPTOUT (888-567-8688) or go online.
 

snoopy7548

Diamond Member
Jan 1, 2005
8,091
5,090
146
Just read this on Ars this morning:

https://arstechnica.com/information...caused-by-failure-to-patch-two-month-old-bug/

"We know that criminals exploited a US website application vulnerability. The vulnerability was Apache Struts CVE-2017-5638. We continue to work with law enforcement as part of our criminal investigation, and have shared indicators of compromise with law enforcement."

Why was such sensitive data accessible via an outside-facing website vulnerability?
 

highland145

Lifer
Oct 12, 2009
43,563
5,966
136
So if you don't freeze your credit and you become an actual victim, is none of it reversible? Are we in any way protected after the fact?

Or are people going through the trouble to freeze because they don't want to go through the hassle later if something does happen?
You can always dispute via annualcreditreport.com. A much easier process than before the govt set that up.
 

rh71

No Lifer
Aug 28, 2001
52,856
1,048
126
"We know that criminals exploited a US website application vulnerability. The vulnerability was Apache Struts CVE-2017-5638. We continue to work with law enforcement as part of our criminal investigation, and have shared indicators of compromise with law enforcement."

Why was such sensitive data accessible via an outside-facing website vulnerability?
Patch was available 2 months prior... that's almost the amount of time a big company takes to test & implement fixes.
 

Linux23

Lifer
Apr 9, 2000
11,303
671
126
could i fake real negative inquiries on my report claiming that i've been hacked from this breach?
 

BudAshes

Lifer
Jul 20, 2003
13,920
3,203
146
Some good information about credit freeze (if you want to go that route), especially the cost of doing so for each state- https://www.usatoday.com/story/mone...e-your-credit-protect-your-identity/657304001

Equifax shares are down 31% since the announcement, $5 billion USD of value is wiped out - http://www.marketwatch.com/story/eq...re-erasing-5-billion-in-market-cap-2017-09-14

Well at least those execs sold their stock. Wouldn't want to hurt their bottom line.
 

Elixer

Lifer
May 7, 2002
10,376
762
126
So, how did she land that position if her background is in music, and no security or IT experience?
 

esquared

Forum Director & Omnipotent Overlord
Forum Director
Oct 8, 2000
23,791
4,971
146

manly

Lifer
Jan 25, 2000
11,367
2,375
136
So, how did she land that position if her background is in music, and no security or IT experience?
casting couch?

OK in (some) seriousness, getting into a C-suite has as much to do with mastering politics than with merit. I certainly would never hire an unqualified person for a senior technical role but then again I'm not a CEO!
 

bob4432

Lifer
Sep 6, 2003
11,695
28
91
Anybody know if Equifax was even running their own web servers? Or were they using a 3rd party to handle that since their main IT person would have no idea how to setup a web server (and in Susan Mauldin's mind - Apache, why do Indians of the southwest keep sending me info about some critical web thingy, guess I will just put them in my spam box, I don't have time for this Indian web nonsense, now back to my best music works) much less keep one up to date .

I would hate to see how their internal machines are setup - wonder how many passwords are "password"?

Just more evidence that is not what you know but who you know.

Since this basically hit nearly every household in the US, 9~400,000 in the UK, and some in Canada, who gets to be held accountable? Or is it not what you know but who you know again?

At least she should be able to make a song to comfort herself knowing we will all be dealing with this for the rest of our lives, way to go Susan Mauldin .
 

sdifox

No Lifer
Sep 30, 2005
96,219
15,788
126
Music major as chief security officer...ftc should look into the possible insider trades as well.
 

drnickriviera

Platinum Member
Jan 30, 2001
2,422
205
116
Yeah, I also think the number of people that are freezing their credit (and opting out of prescreened offers as a result) have to be hurting their bottom lines.

[edit: freeze doesn't opt you out like I thought it did]

I just got a letter from Equifax saying they were opting me out of prescreened offers for 5 years. If I wanted it permanent, fill out this form. I did a freeze the day the story broke.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |