15 ms·
Experian Sold Consumer Data to ID Theft Service
- tonyfelice 13y agoSort of insinuates that ID theft is not meant to be a core focus of Experian.
- carbocation 13y ago> Sort of insinuates that ID theft is not meant to be a core focus of Experian. The post is saying that a service that aids scammers purchased data from Experian. Seeing the title, I initially thought it meant that Experian sold data to an ID Theft-prevention service, which would be less bad.
- greenyoda 13y agoI read it the same way, but that would have been pretty bad in and of itself. Why should an ID theft prevention service have data on me unless I have a business relationship with them?
- carbocation 13y agoGoing back a step, why should Experian have data on you?
- sliverstorm 13y ago... Because they are one of the three major credit-scoring agencies that maintain records on every person with a credit history?
- carbocation 13y agoWell, sure, that's a description of what they do, but it doesn't explain why they should have access to this information. In a marketplace, perhaps there doesn't really need to be a "why". But the same "why" should apply to Experian as it would to an ID Theft-Prevention service (the hypothetical thing that we were discussing in this comment thread, and the reason I asked this question in the first place). That is, Experian's longevity and importance makes them more reputable. Their function as a business, certainly, is to collect, analyze, and repackage this data. But these things should not give them a free pass on the "why" question that greenyoda posed, if the question is going to be asked at all.
- DigitalJack 13y agoThey said "should" not "would."
- troyk 13y agoAnd they can sell what they call the "header" of your credit report without regulation (such as the FCRA). This info includes your name, address, ssn and dob. Or at least it did when I bought it in the 90's to build a service to find dead-beat dads. I've heard they are more restrictive on the SSN, but I also would bet that's the #1 data element for the ID thefters.
- GFischer 13y agoI don't understand why the U.S. is so opposed to a nationwide ID, and yet obviously need one, and end up treating other documents less suited to the task as one. Here in Uruguay (and almost everywhere else) we have a national ID number (Cédula de Identidad). It's not supposed to be secret (although it's not a great idea to divulge it freely). http://en.wikipedia.org/wiki/National_identification_number http://en.wikipedia.org/wiki/National_identification_number
- ams6110 13y agoI don't see how a new id number will solve anything. We already have a de-facto national id number, the SSN.
- GFischer 13y agoBecause a new ID number can have security measures. The ID number in my country has photograph, fingerprints, signature, several security measures (difficult to fake). Not so easy to steal (of course there are forgeries, but identity theft becomes much harder)
- kd0amg 13y agoHold on, do you mean an ID number or an ID card? As far as I can tell, the Cédula de Identidad you mention is a card, not just a number. Numbers are pretty much always trivial to duplicate. Checking a physical document kind of requires a face-to-face transaction.
- johntb86 13y agoHow else would credit history (and credit in general) work?
- Silhouette 13y agoVoluntarily? If you want to use credit, you have to let lenders collaborate to determine whether they're willing to lend to you, if that's their criteria for making decisions. If you don't want to use credit, they get no special pass to store and use personal data about you. I'm from Europe, where generally personal privacy gets more emphasis than it seems to in some places, notably the US. We have explicit laws about collecting and processing personal data, but certain organisations seem to get a free pass for no apparent reason. As this story demonstrates, the risks are still there. That said, perhaps we shouldn't be too worried. The last time I paid a little real money to get hold of my personal credit report from one of these credit reporting organisations, it was so riddled with obvious errors, including more than a few wildly inaccurate data points, that I was on the phone to them for something like half an hour to get them to correct everything. At that point (I kid you not) the woman on the phone asked if I would be much longer because it was the end of the day and time for her to go home.
- dingaling 13y agoI'm convinced that those 'errors' on reports are actually phishing. When I ordered my reports I paid with postal orders, so as not to leak any financial information back to the agencies. I'm glad I did so, as the details ( other than my mortgage ) were laughably incorrect. I was on the verge of writing to correct them and then caught myself - that's exactly what they want, isn't it? So hopefully by now they've diverged even further from the truth.
- pc86 13y agoWere they negative elements or just factually incorrect neutral/positive elements? Correct or not, if your credit report is pulled and there is wildly inaccurate (negative) information you can still be declined, and not many people know that you are entitled to a free report if you're declined based on what's in that report.
- olefoo 13y agoExperian is one of the big three credit reporting agencies; their databases are used to determine whether you qualify for a loan. They are your credit record... So, yeah; this is pretty bad.
- 3327 13y agoWell, is it fair to say that the credit system in the US is fued up? Oligopoly of 3 agencies have pretty much entire control of your fate. Yes Fate. Purchasing power means cash and since credit = cash these companies control the cash that you have at disposal. Which means your FATE. Its insanely difficult to pierce oligopolistic structures and Cartels because of obvious reasons. But some day some startup needs to tackle this. The system works for most but doesn't work for many.
- deleted 13y ago[deleted]
- callmeed 13y agoYes absolutely. I currently cannot buy a house despite having a six-figure income for 4 years, money in savings, and having no debt save my student loan. All because of bad decisions I made in years past.
- dangrossman 13y agoActual bad decisions you made in the past are a valid reason not to risk underwriting a large loan to you. There are valid criticisms of the credit agencies, but that doesn't seem like one of them. If you want a mortgage and you feel you have a convincing reason a bank should risk entrusting you with their money despite a bad credit history, try an in-person appointment with a lender at a local credit union. Be prepared to show your bank statements, several years of tax returns, and if you're self-employed, a signed letter from your business's accountant about the health of your cash flow. You'll definitely need enough cash on hand for a downpayment of at least 30% the house's value; good strategy even if it weren't required. If you really want to look credit-worthy, use that six figure income to pay off those student loans before you take on an even larger debt obligation.
- callmeed 13y agoI don't disagree with you–but it can be frustrating to know you've improved both your responsibility and your earning power yet only be judged by the past. For example, I've paid cash for the last 5 cars our family has purchased over the last 6 years. Why doesn't my ability to do that apply to my credit-worthiness? Small things like that annoy me about the agencies/system. Also, the median home price where we live is $500-600K (depending on the city/neighborhood). 30% of that is quite a down-payment.
- afreak 13y agoThis Dilbert comic is 100% apt today: http://dilbert.com/strips/comic/2010-10-14/ http://dilbert.com/strips/comic/2010-10-14/
- NIL8 13y agoPerfect.
- f902370 13y agoThe world should calm down. Take a few years to review what we've done in last 50 years.
- skrebbel 13y agoYeah. Let's rent a holiday cottage with all of us and talk it though.
- mindslight 13y agoExcept there's actually no such thing as "identity theft" - it's a mere figment of the credit industry's (tracking industry's) fantasy in which they're omniscient, and an attempt to slowly push the responsibility for bank fraud onto uninvolved third parties. In reality, some would-be bank fraudsters got ahold of some non-secret information.
- Amadou 13y agoI agree. Identity theft is just a particular method of fraud with a name that mitigates the responsibility of the institutions that enabled the fraudsters. I don't know if it is one one of those terms that was invented by one of those PR agencies that invented terms like "climate change" to mitigate the visceral impact of "global warming."[1] But it certainly has ended up as a term that obfuscates the responsibility of banks to stop treating public information like passwords. [1] https://en.wikipedia.org/wiki/Frank_Luntz https://en.wikipedia.org/wiki/Frank_Luntz
- davvolun 13y agoI think 'climate change' is generally used now because 'global warming' implies the entire globe will become warmer, when in fact some areas, due to complex interactions, will actually become cooler. That, combined with the political posturing (on both sides), has made it useful to use a more general term. IMHO.
- malandrew 13y agoI wonder if you could mount a class-action lawsuit against multiple financial institutions on behalf of all the "identity theft victims".
- summerdown2 13y agoI think this is relevant: it's a sketch from the show "Mitchell and Webb about identity theft. http://www.youtube.com/watch?v=CS9ptA3Ya9E http://www.youtube.com/watch?v=CS9ptA3Ya9E
- dredmorbius 13y agoGoogle's NGram viewer is a neat way to track phrases. This one seemed to emerge in the late 1990s (with some very light earlier mentions in the 1960s). By the late 1970s there were statutes on the topic. http://goo.gl/VvBCHL http://goo.gl/VvBCHL http://goo.gl/i1KFtF http://goo.gl/i1KFtF
- icu 13y agoThanks cylo for the post. Sadly we can't seem to trust the credit agencies or Government agencies with data protection. We need a politician who will champion some sort of legal offence (Federal?) for digital data protection breaches whatever the industry/company (above anything that already exists) that will scare companies enough that they start taking digital identity seriously. Maybe that's a pipe dream but I get the sense after reading this article that regulators just don't carry a big enough stick or have too light a touch when punishing serious infractions.
- Zenst 13y agoAgreed and I'm somewhat supprised (UK peep here) that no data protection act is in place. UK had first version of the act in 1984 (oh the ironic choice of dates, govermental humour maybe). With that I'm amazzed there is nothing in the USA, must be something beyond class action suits?
- ams6110 13y agoI think protecting data is a hopeless goal. The penalties need to be for fraud, and the responsibility for identity verification needs to be the creditors. Hospital admissions and discharges used to be published every day in the paper. People used to have their social security number printed on their checks. Someone's birthday was a day of celebration, not a personal secret. I want to get back to a place where routine facts about me do not need to be secret or something I worry about. The onus should be on anyone granting credit to verify that the person is who they claim to be, and it should take more than a few bits of public information to do that.
- icu 13y agoams6110, I wish for a world where your quote "I want to get back to a place where routine facts about me do not need to be secret or something I worry about" were true. However, pandora's box is open and we can never ever go back. When you say, "The onus should be on anyone granting credit to verify that the person is who they claim to be" I couldn't agree more. This goes to the heart of my argument, you cannot trust those granting the credit. The invisible hand isn't working here. The only other option is to use fear to keep them in line... fear of a regulator that has teeth.
- bediger4000 13y agoDo "underground" credit rating agencies exist? I don't mean credit rating agencies for carders and scammers, I mean agencies that track things they're not supposed to track. Agencies that keep the data on file for longer than they're supposed, keep track of how many times a particular ID asks for refunds, or to get their security deposit back, material like that. It would have to be out of the Caribbean or some place with lax data privacy laws, and strict confidentiality laws.
- gergles 13y agoThere's a ton of those that are fully aboveboard, you just don't hear about them. One exists for return tracking, one exists for how many applications you've filed for credit cards, one exists for landlord/tenant court entries that saves them forever (they insist they aren't a CRA but under the law they clearly are) -- there's a ton of them other than the Big 3 and there's almost no effective regulation around them.
- cptskippy 13y agoI did a double take when I saw this because I've been in contact with Equifax recently because I started receiving SPAM form a non-existent email address that I shared with them. I have a Catch-all address setup on my Domain so that I can give every site I interact with their own custom email address. In this case it was equifax.com@mydomain.com. Since the email address doesn't exist, and they're the only company I've shared it with, they're the only ones with a record of it's existence. When I emailed them asking if they'd had a security breach or if they were selling email addresses they responded saying they would opt me out of marking emails. When I responded with the context and header info of the emails I received and asked if this was in fact from them things turned. About an hour later I got a response, the tone had changed significantly and they indicated that the incident had been escalated to their security department and that they would be in contact with me as their investigation progressed. I can say this has been the best response to the dozens of emails I've sent to companies about the same issue. The worst was Best Buy whose response was something along the lines of "Eat Dk, we do what we want."
- nwh 13y agoHeh, same. The excuses I get from companies are hilarious. In my case they're just the domain, but encoded and obfuscated. The company will claim anything to get out of it, that my account was compromised, all the way to someone guessing it. Irritatingly, when I signed up for the utilities at my apartment I used a single address "utilities@domain.com" for simplicity. One of my three suppliers leaked my details with that address, and they all deny it. Took less than a week from moving in to getting penis pump advertisements at that address.
- GFischer 13y agoI worked for an Equifax subsidiary for a time, and I can vouch that at least there they took security very seriously, and always worked with the best practices. The downside was that changes were veery slow to implement :)
- hnriot 13y agothat's not exactly a difficult email address to guess, I would think that in this case (specifically this case) equifax would have a very good claim that it wasn't them that leaked it. If instead you had used a hash or something unguessable then you might have a case, but I could easily go and sign up to my favorite nigerian viagra supplier with all the usual suspects facebook@yourdomain.com, airbnb@yourdomain.com... and you'd go right on blaming the facebook, airbnb, etc.
- arca_vorago 13y agoFor those of you interested in learning how the cough scam cough system of credit scores works and how to maximize the system, here is a talk I have found very informative. It's a dirty business and industry... http://www.youtube.com/watch?v=5gFDnQGr6WU http://www.youtube.com/watch?v=5gFDnQGr6WU