5 ms·
This will be at least my 6th place where this has happened. Yea, it's one more place where identity thieves can get my info. :( What is the fix? Anyone?
by WheelsAtLarge 2y ago
This will be at least my 6th place where this has happened. Yea, it's one more place where identity thieves can get my info. :( What is the fix? Anyone?
- toomuchtodo 2y agoFederal data protection legislation that makes holding onto consumer PI and adjacent data toxic, along with penalties so punitive for failing to properly secure and purge data in accordance with these regulations that it is a corporate death sentence. “Show me the incentives and I’ll show you the outcome.”
- willmadden 2y agoThis problem was created by regulation requiring companies to store ID information. More regulation the answer?
- toomuchtodo 2y agoYou can tokenize the data [1], you can dispose of it after you've used it for the business process [2], you can vault it with a custodian. Lots of solutions. I have implemented more than one in the consumer credit space. Regulation is usually the answer. More? Better. It ain't gonna regulate itself. Storing and processing data securely is not hard. It is work though. Breaches happen because systems and corporations don't care [3], they aren't exposed to the cost of data loss, as there is none. Would you prefer the business not store the data, but the government attests to your identity (as part of a proofing request and flow) and also stores the receipt and AML/KYC metadata? There are legal and compliance requirements in the finance space unfortunately, and those are not going away. If identity is a requirement, a system must attest to it, and logs of some type must be created to document the ceremony. [1] https://en.wikipedia.org/wiki/Tokenization_(data_security) https://en.wikipedia.org/wiki/Tokenization_(data_security) [2] https://en.wikipedia.org/wiki/Crypto-shredding https://en.wikipedia.org/wiki/Crypto-shredding [3] https://en.wikipedia.org/wiki/List_of_data_breaches https://en.wikipedia.org/wiki/List_of_data_breaches
- willmadden 2y agoYou don't think there are brand and reputational risks with data breaches, or cost to notify and provide free credit reporting? Breaches only happen because corporations "don't care"? I guess the US government doesn't care, then? Event Description Date Agency Number of People Affected ------------------------------------------------------------------------------------------------------------------------- SolarWinds Cyberattack December 2020 Multiple federal agencies Approximately 18,000 U.S. Office of Personnel Management (OPM) Breach June 2015 Office of Personnel Management 21.5 million U.S. Department of Veterans Affairs Breach May 2006 Department of Veterans Affairs 26.5 million Georgia Secretary of State Office Breach November 2015 Georgia Secretary of State 6.2 million Virginia Department of Health Professions Breach May 2009 Virginia Department of Health 8.3 million Texas Attorney General Office Breach April 2012 Texas Attorney General 6.5 million Department of Transportation Data Breach May 12, 2023 Department of Transportation 237,000 National Public Data Breach (reported) August 2024 National Public Data Nearly 3 billion
- toomuchtodo 2y agoBased on my experience in the space, I can say with some confidence that there is very low brand or reputational risk (or it is so low as to be immaterial) with regards to a breach. $1M-$3M in most cases, which is cost of business (notification campaigns, buying credit monitoring, etc). Edit: Your examples are outliers, based on the data, and those costs are not brand and reputational, they are settlements or fines (which are rare). If you want to move goal posts, that's a choice. No one is going to stop using Equifax for consumer reporting data or Target because of their cybersecurity posture (ie brand and reputation damage). https://www.ibm.com/reports/data-breach https://www.ibm.com/reports/data-breach https://www.vox.com/the-goods/23031858/data-breach-data-loss-personal-consequences https://www.vox.com/the-goods/23031858/data-breach-data-loss... https://www.idtheftcenter.org/post/itrc-sees-third-most-data-breach-victims-in-quarter/ https://www.idtheftcenter.org/post/itrc-sees-third-most-data...
- Mistletoe 2y agoMake sure you have an identity protection PIN at the IRS. https://www.irs.gov/identity-theft-fraud-scams/get-an-identity-protection-pin https://www.irs.gov/identity-theft-fraud-scams/get-an-identi... It's not a fix but a band-aid so at least people can't file taxes with your SSN.
- deleted 2y ago[deleted]
- kragen 2y agoIt's too far outside the Overton Window: not only should KYC not be mandatory, KYC should be illegal. MoneyGram should not be permitted to collect its customers' personally identifiable information. That's because breaches like this are a national security vulnerability. Privacy is the foundation of civil defense. This policy will remain outside the Overton Window until several more digital Pearl Harbors like the one that just happened in Lebanon, where Israel was able to leverage its surveillance of Hizbullah members into an almost total annihilation of Hizbullah as an organization. Many other armed forces around the world are going to experience the same thing over the next decade, because it's far too late for soldiers' and politicians' family members to avoid ever signing up for Facebook, Zelle, PayPal, MoneyGram, etc. I don't know what the landing looks like, but before we get there, this flight may experience some turbulence.
- sofixa 2y ago> not only should KYC not be mandatory, KYC should be illegal. MoneyGram should not be permitted to collect its customers' personally identifiable information. That's because breaches like this are a national security vulnerability. Privacy is the foundation of civil defense Personal opinion: that's a pipe dream and it's never going to happen. Moving money is an extremely vital part of modern economies, and importantly, of underground ones. You mention Hizbollah - without KYC they would have been able to more easily receive donations from sympathisers and use those funds to buy stuff from everywhere. Their surveillance by Israeili services wasn't online surveillance, because the group has already been burned by advanced Israeli cybersecurity attacks. They were using pagers ffs, do you really think their members were tracked and surveilled online? And the same would apply for stuff like criminal regimes evading sanctions even more, cartels laundering their money, financial scams like Wirecard proliferating even more. Look at the crypto space that promised to change that - outside of the absurd lack of practicality, it led to millions of scams, money laundering operations, North Korea abusing it to fund itself, and the like.
- kragen 2y agoThank you for your brilliantly clear demonstration.
- exogenousdata 2y agoSimple answer: Jail Any company that accesses/uses Personally Identifiable Information (PII) must register a “PII Czar” with the proper authorities. That person (or persons, depending on the size/scope of the PII data) can be held criminally liable in the event of a data breach. If a jury finds that the PII Czar enacted the correct policies/procedures & took the right precautions, a jury could find them innocent. But if there was willful or negligent handling at the company, the PII Czar goes to jail. In the US, one of the big lies told at the corporate level is that no one ever sees jail time because the regulators are too underfunded in comparison with large companies. What’s necessary is clear personal ownership of PII and criminal liability in the event of a data breach.
- avmich 2y ago"Don't you need a chairman?" Funt asked. "What chairman?" Bender exclaimed. "An official one - in a word, the chief of the establishment." "I am the chief myself." "In other words, you expect to do time yourself? Why didn't you say so in the first place? Why did you take up two hours of my valuable time?" The old man in the Passover trousers became exceedingly angry, foamed at the mouth, fumed, emitted explosive noises, but the pauses between his sentences did not diminish. "I am Funt!" he said emphatically. "I am ninety years old! All my life I've done time for others! Such is my profession - to suffer for others!" "Oh, so you're professional figure-head!" "Yes," said the old man, tossing his head boastfully. "I am Substitute-chairman Funt! I've always done time. At the time of Alexander the Second, the Liberator, at the time of Alexander the Third, the Peacemaker, at the time of Nicholas the Second, the Bloody." And the old man slowly bent back his fingers, counting the tsars. "At the time of Kerensky I also did time. At the time of Military Communism, I did no time, to tell the truth, because clean business disappeared and there was no work for me. But how I did time in the days of the NEP! How I did time in the days of the NEP! Those were the best days of my life..." Ilya Ilf and Eugene Petrov, The little golden calf. https://archive.org/details/littlegoldencalf0000unse https://archive.org/details/littlegoldencalf0000unse
- CatWChainsaw 2y agoI hate the double standard where a low level employee can be fired and blacklisted for a black swan mistake, but systemic mistakes get the top levels golden parachutes. So no luxury prisons for execs, either. Data Fiduciary Duty - you have to use the data you have in the best interest of your client (which isn't allowed to be the advertisers that want the data, nope!), and if that means deleting what isn't necessary, so much the better. Also, forced arbitration isn't allowed and class action lawsuits result in more than a reward of $3.97 paid five years later with a free year of credit monitoring thrown in.