--> 6 Unanswered Questions for Equifax After Massive Data Breach of 143 Million Americans' Personal Information | Top Tech Site

6 Unanswered Questions for Equifax After Massive Data Breach of 143 Million Americans' Personal Information


As has been widely publicized in the media, and as the firm noted on a special website,Equifax, one of the "big three" American credit bureaus, suffered a serious cybersecurity breach that may have jeopardized significant personal information about 143-million Americans, in addition to the credit card information and dispute records of hundreds of thousands of consumers.

While media reports have been quite comprehensive, several significant questions remain unanswered. I contacted Equifax via email and Twitter, but was told that the firm has "no further information to contribute at this point other than what is in the news release," so I decided to share my questions with my readers as food for thought:

Dear Equifax:

1. Why is the firm offering only one year of protection for those whose data was stolen?

We are many years into the era of cybercrime, and criminals who steal personal information already know to wait to use the pilfered data until the expiration of the free credit monitoring services so often offered after breaches. Equifax is offering one year of credit monitoring and identity theft protection - shouldn't the firm be on the hook for a lot longer than one year? Doesn't the present offer sound like more like a ruse to loop in customers who will have to pay Equifax after their trial subscription ends if they want to be protected when it matters most? Worse yet, according to some reports, Equifax requires people to waive their rights to sue in exchange for the one year of protection.

2. Why should people whose data Equifax did not protect trust Equifax to protect them now?

To address the risk to consumers created by Equifax's cyber disaster, Equifax has offered the public its own credit monitoring and identity protection services. Shouldn't folks whose data was jeopardized by Equifax be offered the use of a different company's protection service? Is it really reasonable to expect people to want to protect themselves with a security offering from a firm that just jeopardized their data en masse?

3. Were people's PIN numbers compromised?

Equifax offers a security freeze service that allows people to lock their credit files, with a PIN needed for unlocking. While the PINs are hopefully stored hashed (i.e., encrypted using one-way encryption), a leak of the hash database could put the PINs at risk as well. To date, Equifax appears not to have provided any information as to whether the PIN database's security was breached. Can Equifax please clarify the status of this important information?

4. Why wasn't the breach reported to the public sooner?

Equifax claims to have "recently discovered a cybersecurity incident involving consumer information" but according to its press release it has known about the breach since July. The domain being used by Equifax to house the special breach information website - equifaxsecurity2017.com - was registered in August. If Equifax was aware of the breach in July, and if the pilfered data could be used for identity theft crimes, why did it not disclose the breach to the public sooner? Why did it register the domain in August, but not upload the site's contents until a week into September?

5. What exactly qualifies Equifax as "a leader" in protecting data?

In a statement released to the press, Equifax Chairman and Chief Executive Officer, Richard F. Smith, stated that "We pride ourselves on being a leader in managing and protecting data, and we are conducting a thorough review of our overall security operations." Now that Equifax has potentially suffered what may be the worst ever data breach as far as impact on American consumers, please clarify what Equifax was doing to make it "a leader" in protecting data. There is talk "on the street" that not that long ago the firm did not even have a CISO in place. Also, how exactly did so much data go out the door with nobody noticing?

6. Did Equifax executives sell stock after learning about the breach and before notifying the public?

Three Equifax executives sold almost 2 million dollars of stock shortly after the breach was discovered - and before it was announced to the public; an SEC filing shows that these sale were not pre-planned. According to The Guardian, Equifax claims that these executives had no knowledge of the breach when they made the sale. How exactly does Equifax know that? What type of formal investigation has been made into their actions to assure the public that Equifax executives did not trade based on insider information?

Read the original article on inc

COMMENTS

Popular Posts_$type=three$author=hide$comment=hide$rm=hide$date=hide$snippet=hide$c=3

Name

Android,57,Apple,48,Artificial Intelligence,4,Bing,2,BlackBerry,2,Blogger,7,Blogger Templates,7,Blogger Tips,2,Blogging,7,Business,47,Cameras,2,Cars,9,Computer,2,Computing,5,Culture,1,Domain,2,Downloads,1,Elon Musk,2,EMail,3,Facebook,32,Feature,3,Galaxy Note 20,2,Galaxy Note 4,1,Galaxy Note 7,3,Galaxy Note 8,7,Galaxy Note 9,1,Galaxy S11,1,Galaxy S20,2,Galaxy S8,5,Games,12,Gaming,2,Gmail,2,GoDaddy,1,Google,43,Health,7,Hosting,1,How to,23,Instagram,7,Intel,1,ios,1,iOs 11,1,iOs 13,1,iPad,3,iPhone,69,iPhone 14,2,iPhone 6,1,iPhone 7,1,iPhone 8,19,iPhone 9,1,iPhone X,12,Laptops,8,LG,7,LG V30,6,LinkedIn,2,Meta,1,Microsoft,14,Moto X4,3,Motorola,5,Nasa,5,News,368,Nokia,2,Nokia 8,1,OnePlus,2,OnePlus 3,1,OnePlus 3T,1,p,1,Phones,148,Real Estate,1,Samsung,38,Science,4,SEO,2,Social Media,44,Sony,3,Source: BetaNews,1,Space,12,Success,50,Tablet,1,Technology,344,TVs,1,Twitter,8,WhatsApp,2,WordPress,1,WordPress Themes,1,Xiaomi,4,Xperia,1,Yahoo,1,YouTube,7,
ltr
item
Top Tech Site: 6 Unanswered Questions for Equifax After Massive Data Breach of 143 Million Americans' Personal Information
6 Unanswered Questions for Equifax After Massive Data Breach of 143 Million Americans' Personal Information
As has been widely publicized in the media, and as the firm noted on a special website,Equifax, one of the "big three" American credit bureaus, suffered a serious cybersecurity breach that may have jeopardized significant personal information about 143-million Americans, in addition to the credit card information and dispute records of hundreds of thousands of consumers.
https://2.bp.blogspot.com/-pQUA3QYgXyY/WbNpVlWIGcI/AAAAAAAADac/2xFnq5d-qCcZZs2RpIa-oJX3jspL3jD5wCLcBGAs/s1600/hackr.JPG
https://2.bp.blogspot.com/-pQUA3QYgXyY/WbNpVlWIGcI/AAAAAAAADac/2xFnq5d-qCcZZs2RpIa-oJX3jspL3jD5wCLcBGAs/s72-c/hackr.JPG
Top Tech Site
https://toptechsite.blogspot.com/2017/09/6-unanswered-questions-for-equifax-after-a-massive.html
https://toptechsite.blogspot.com/
https://toptechsite.blogspot.com/
https://toptechsite.blogspot.com/2017/09/6-unanswered-questions-for-equifax-after-a-massive.html
true
7908177386937608306
UTF-8
Loaded All Posts Not found any posts VIEW ALL Readmore Reply Cancel reply Delete By Home PAGES POSTS View All RECOMMENDED FOR YOU LABEL ARCHIVE SEARCH ALL POSTS Not found any post match with your request Back Home Sunday Monday Tuesday Wednesday Thursday Friday Saturday Sun Mon Tue Wed Thu Fri Sat January February March April May June July August September October November December Jan Feb Mar Apr May Jun Jul Aug Sep Oct Nov Dec just now 1 minute ago $$1$$ minutes ago 1 hour ago $$1$$ hours ago Yesterday $$1$$ days ago $$1$$ weeks ago more than 5 weeks ago Followers Follow THIS PREMIUM CONTENT IS LOCKED STEP 1: Share to a social network STEP 2: Click the link on your social network Copy All Code Select All Code All codes were copied to your clipboard Can not copy the codes / texts, please press [CTRL]+[C] (or CMD+C with Mac) to copy Table of Content