3 ms·
I worked for a big tech company in the Seattle area when the pandemic started. I had previously received notifications of my PII being misappropriated in attack
by steelframe 6y ago
I worked for a big tech company in the Seattle area when the pandemic started. I had previously received notifications of my PII being misappropriated in attacks against my company's medical insurance administrator, as did all of my co-workers.
The Washington State unemployment web site only required that you type in the right PII when registering, which pretty much was just your name and SSN. Maybe the address would need to match too, but regardless it was all the stuff that would have been available to any breach such as the ones that hit Equifax or Anthem.
Several weeks into the pandemic I got a letter in the mail from the Washington State Employment Security Department (ESD) referencing a claim number and giving me advice on how to start up a tech business or something. I was like, "Um, why is there a claim number on this letter?" I went to the ESD website and tried to register with my SSN, only to be greeted with something like, "Sorry, looks like you're already registered with email address *pwned1337@gmail.com."
I knew right away what was going on, and I alerted my co-workers that they should go check out to see if their SSN was associated with some random email address they didn't recognize. Sure enough, about a dozen others in Washington state reported that they were hit too.
From those who weren't popped, we learned that just by providing your name and SSN, the web set would spill out your income to whoever's using it and then let them register for unemployment benefits in your name to whatever random bank account you want to link. The fraudsters probably just went through their Equifax or Anthem dumps and selected the higher-income ones in the tech industry.
A few weeks later my HR department reached out to me with, "Hi, we got a notification that you're collecting unemployment benefits. You're not planning on leaving the company are you?" To which I replied (in more civil terms), "No, you dipstick, it's the same thing that's happening with the dozens of other employees in Washington state right now, of which I'm sure you're aware. Why aren't you mentioning anything about the massive amount of identity fraud going on with your Washington state employees?" It was radio silence from HR from that point on.
I tried calling the ESD fraud hotline, but it was so overwhelmed that it wouldn't even let me get in a queue. It just said, "We're too busy, bye bye" and hung up. I figured the system would work it all out eventually, and about a month ago I got a letter informing me that their investigation into the fraud was completed and that everything was cleared up.
An article on this:
https://www.king5.com/article/news/local/employment-security-department-unemployment-fraud-audit/281-7f82d90a-abec-4bd4-89cf-f130d0b12ed5 https://www.king5.com/article/news/local/employment-security...