# Equifax data breach

**URL:** https://forums.speedlife.net/t/equifax-data-breach/274882
**Category:** NYSpeed Off Topic
**Created:** [September 15, 2017, 6:53am UTC](https://forums.speedlife.net/t/equifax-data-breach/274882 "2017-09-15T06:53:47Z")
**Posts on this page:** 20
**Page:** 1

<div class="post-metadata">

### Author: ![JayS](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/jays/32/15375_2.png) [@JayS](https://forums.speedlife.net/u/JayS)
#### Post date: [September 15, 2017, 6:53am UTC](https://forums.speedlife.net/t/equifax-data-breach/274882/1 "2017-09-15T06:53:47Z")

</div>

So I’m guessing you’ve all seen the massive data breach over at Equifax in the news/social media/coworker chat about how they lost 143 million people’s critical data. If not, go google it and stop living under a rock :). Cliffs, if you’ve done anything with credit or insurance in the last 10 years there’s a real good chance Equifax just lost your SSN, license number, date of birth, name, address and credit score.

[https://www.equifaxsecurity2017.com/](https://www.equifaxsecurity2017.com/)

^ You can check there if you’re affected.

Curious what steps you guys are taking? For now I’m taking their year of free monitoring and hoping the lawyers/government get involved and mandates some longer term solution. A year of monitoring doesn’t do much good now that they’ve compromised your SSN, license number and DOB that don’t change the rest of your life.

Hopefully this also forces a conversation about SSN’s in general. The concept of a number you get when you’re born that you can’t change that’s critical to your credit and financial life really doesn’t work in this age of massive data breaches. It needs to be more like a credit card number that when it gets compromised you simply cancel it and get a new one.

---

<div class="post-metadata">

### Author: ![LZ1](https://avatars.discourse-cdn.com/v4/letter/l/7ab992/32.png) [@LZ1](https://forums.speedlife.net/u/LZ1)
#### Post date: [September 15, 2017, 6:58am UTC](https://forums.speedlife.net/t/equifax-data-breach/274882/2 "2017-09-15T06:58:44Z")

</div>

I use CreditKarma which gives me alerts when any new accounts get opened…I had considered freezing all mine but it seems like a giant pain since im going to be looking for a new house shortly.

Surprised they didn’t do a better job at security their CISO was rated like [#5](http://www.nyspeed.com/usertag.php?do=list&action=hash&hash=5) in the country :lol:

I’m also waiting for Mandiant who is doing IR for this to claim it was China.

---

<div class="post-metadata">

### Author: ![BigRon](https://avatars.discourse-cdn.com/v4/letter/b/58956e/32.png) [@BigRon](https://forums.speedlife.net/u/BigRon)
#### Post date: [September 15, 2017, 6:59am UTC](https://forums.speedlife.net/t/equifax-data-breach/274882/3 "2017-09-15T06:59:59Z")

</div>

I have not done anything yet. But based on my research; I will probably freeze all the bureaus for ~$15 and have the peace of mind.

---

<div class="post-metadata">

### Author: ![LZ1](https://avatars.discourse-cdn.com/v4/letter/l/7ab992/32.png) [@LZ1](https://forums.speedlife.net/u/LZ1)
#### Post date: [September 15, 2017, 7:04am UTC](https://forums.speedlife.net/t/equifax-data-breach/274882/4 "2017-09-15T07:04:20Z")

</div>

isn’t today the deadline for them to pay?

---

<div class="post-metadata">

### Author: ![JayS](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/jays/32/15375_2.png) [@JayS](https://forums.speedlife.net/u/JayS)
#### Post date: [September 15, 2017, 7:11am UTC](https://forums.speedlife.net/t/equifax-data-breach/274882/5 "2017-09-15T07:11:18Z")

</div>

I guess in NY you can freeze your credit for free. Still debating that one. I don’t think we’ll be doing anything soon that will require a credit pull so it’s probably a good idea.

Also, I saw a meme today showing the CSO over at Equifax has a BA and Masters in Music Composition and assumed it was a photoshop but no, here’s her linkedin page.

[https://www.linkedin.com/in/susan-m-93069a/](https://www.linkedin.com/in/susan-m-93069a/)

I realize IT security is one of those constant learning things but man, it looks bad when the person at the top of your security pyramid is a music major and you just committed the worst data breach the country has ever seen.

---

<div class="post-metadata">

### Author: ![BigRon](https://avatars.discourse-cdn.com/v4/letter/b/58956e/32.png) [@BigRon](https://forums.speedlife.net/u/BigRon)
#### Post date: [September 15, 2017, 7:16am UTC](https://forums.speedlife.net/t/equifax-data-breach/274882/6 "2017-09-15T07:16:33Z")

</div>

> [@LZ](#):
>
> isn’t today the deadline for them to pay?

> You can sign up at the same site listed above, and the deadline to do so is Nov. 21.

> Initially, though, there was a catch — signing up would also commit you to binding arbitration with the credit monitor, which would mean giving up your right to sue. Several politicians and consumer groups have criticized this provision. Democrats in the House and Senate called on the company to pull back that requirement. Late Friday, Equifax said the arbitration language that appears on its website “will not apply to this cybersecurity incident.”

[https://www.washingtonpost.com/business/technology/what-you-need-to-know-about-the-equifax-data-breach/2017/09/09/46d20dc4-957d-11e7-8482-8dc9a7af29f9\_story.html?utm\_term=.cf882f173064](https://www.washingtonpost.com/business/technology/what-you-need-to-know-about-the-equifax-data-breach/2017/09/09/46d20dc4-957d-11e7-8482-8dc9a7af29f9_story.html?utm_term=.cf882f173064)

---

<div class="post-metadata">

### Author: ![LZ1](https://avatars.discourse-cdn.com/v4/letter/l/7ab992/32.png) [@LZ1](https://forums.speedlife.net/u/LZ1)
#### Post date: [September 15, 2017, 7:17am UTC](https://forums.speedlife.net/t/equifax-data-breach/274882/7 "2017-09-15T07:17:40Z")

</div>

Vulnerabilities in Apache Struts have been the cause for a handful of other very large breaches over the past few years.

Security has vastly improved in the last few years for fortune 100 companies. If someone was motivated enough they could still get into most major companies and obtain some sort of goal(transfer money out, steal trade secrets, etc) just depends on how well your funded and what kind of time you have.

- 
  - 
    - Updated - - -

> [@BigRon](#):
>
> [https://www.washingtonpost.com/business/technology/what-you-need-to-know-about-the-equifax-data-breach/2017/09/09/46d20dc4-957d-11e7-8482-8dc9a7af29f9\_story.html?utm\_term=.cf882f173064](https://www.washingtonpost.com/business/technology/what-you-need-to-know-about-the-equifax-data-breach/2017/09/09/46d20dc4-957d-11e7-8482-8dc9a7af29f9_story.html?utm_term=.cf882f173064)

I meant the people who hacked them gave Equifax a dead line to pay for the data or they would release it.

---

<div class="post-metadata">

### Author: ![JayS](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/jays/32/15375_2.png) [@JayS](https://forums.speedlife.net/u/JayS)
#### Post date: [September 15, 2017, 7:20am UTC](https://forums.speedlife.net/t/equifax-data-breach/274882/8 "2017-09-15T07:20:59Z")

</div>

> [@LZ](#):
>
> Vulnerabilities in Apache Struts have been the cause for a handful of other very large breaches over the past few years.

Am I wrong in thinking this is the biggest breach ever though? At least one that leaked so much critical info including SSN, DOB, Name, Address. Basically all the ingredients you need to really fuck up someone’s financial life.

Target had a huge breach but it was basically just credit card numbers. Couple minutes at [americanexpress.com](http://americanexpress.com) and 2 days later I had a new card and that problem was solved. This is SOOOO much worse because there isn’t an easy fix for 143 million people.

---

<div class="post-metadata">

### Author: ![LZ1](https://avatars.discourse-cdn.com/v4/letter/l/7ab992/32.png) [@LZ1](https://forums.speedlife.net/u/LZ1)
#### Post date: [September 15, 2017, 7:23am UTC](https://forums.speedlife.net/t/equifax-data-breach/274882/9 "2017-09-15T07:23:45Z")

</div>

> [@JayS](#):
>
> Am I wrong in thinking this is the biggest breach ever though? At least one that leaked so much critical info including SSN, DOB, Name, Address. Basically all the ingredients you need to really fuck up someone’s financial life.
> 
> Target had a huge breach but it was basically just credit card numbers. Couple minutes at [americanexpress.com](http://americanexpress.com) and 2 days later I had a new card and that problem was solved. This is SOOOO much worse because there isn’t an easy fix for 143 million people.

Amount of records it has to the biggest.

OPM was worse since it was basically data on everyone one with secret/top secret clearance.

---

<div class="post-metadata">

### Author: ![bing](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/bing/32/7211_2.png) [@bing](https://forums.speedlife.net/u/bing)
#### Post date: [September 15, 2017, 7:28am UTC](https://forums.speedlife.net/t/equifax-data-breach/274882/10 "2017-09-15T07:28:48Z")

</div>

in addition to this a number of their senior execs sold a total of $1.8M of their stock holdings after the company became aware of the breach…

i dont have a US credit card and only one US bank account so not sure i’ll need to do much here.

this is good for IT security professionals though 🙂

---

<div class="post-metadata">

### Author: ![LZ1](https://avatars.discourse-cdn.com/v4/letter/l/7ab992/32.png) [@LZ1](https://forums.speedlife.net/u/LZ1)
#### Post date: [September 15, 2017, 7:30am UTC](https://forums.speedlife.net/t/equifax-data-breach/274882/11 "2017-09-15T07:30:32Z")

</div>

> [@bing](#):
>
> this is good for IT security professionals though 🙂

It’s been good for a while now…If I had to guess it will be that way for another 10+ years for enterprise security.

The nice thing is you can really branch out now since everything has a computer and is hooked to the internet. I did a full car security assessment for a vendor earlier this year.

Medical Equipment  
Cars  
Home Appliances  
Industrial Control Systems  
Home automation  
Smart Phones  
etc

The place im at now we mainly focus on long term(3 months or more) threat simulations. For example you’re a major bank and you want to know if someone can hack you and wire transfer money out or if you’re in oil and gas and want to see if someone can blow up an oil rig. The oil rig deal we got far enough to access and use the control system that managed the rig and then built a lap with the same equipment to prove out being able to blow stuff up and change the data reporting back to look normal.

---

<div class="post-metadata">

### Author: ![JayS](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/jays/32/15375_2.png) [@JayS](https://forums.speedlife.net/u/JayS)
#### Post date: [September 15, 2017, 7:35am UTC](https://forums.speedlife.net/t/equifax-data-breach/274882/12 "2017-09-15T07:35:11Z")

</div>

> [@LZ](#):
>
> OPM was worse since it was basically data on everyone one with secret/top secret clearance.

I forgot all about that one since I wasn’t affected.

---

<div class="post-metadata">

### Author: ![1QIKZ](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/1qikz/32/6112_2.png) [@1QIKZ](https://forums.speedlife.net/u/1QIKZ)
#### Post date: [September 15, 2017, 9:09am UTC](https://forums.speedlife.net/t/equifax-data-breach/274882/13 "2017-09-15T09:09:43Z")

</div>

> [@JayS](#):
>
> Also, I saw a meme today showing the CSO over at Equifax has a BA and Masters in Music Composition and assumed it was a photoshop but no, here’s her linkedin page.
> 
> [https://www.linkedin.com/in/susan-m-93069a/](https://www.linkedin.com/in/susan-m-93069a/)
> 
> I realize IT security is one of those constant learning things but man, it looks bad when the person at the top of your security pyramid is a music major and you just committed the worst data breach the country has ever seen.

FROM HER LINKED IN PROFILE:

_“I highly recommend Susan, she is outstanding at directing and motivating people to achieve solid results. Susan has a strength in building relationships throughout an enterprise in support of the overall goal. During our work together she continued to produce outstanding teams and great results. As a sidenote, you might want to keep an eye on her as she’s a fucking train wreck when it comes to the security of your company’s data archives and the sensitive personal information of millions upon millions of your client’s. Other than that, she’s a fucking gem who can carry a tune like nobody’s business”._

> [@LZ](#):
>
> Vulnerabilities in Apache Struts have been the cause for a handful of other very large breaches over the past few years.

I’ve been proactive long ago in avoiding this situation by installing a Dilithium crystal re-digitizer piggybacked onto a Furian Flux capacitor with dual quad mastificators. It’s proven to be more than effective in plugging the vulnerabilities in Apache Struts.

---

<div class="post-metadata">

### Author: ![bing](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/bing/32/7211_2.png) [@bing](https://forums.speedlife.net/u/bing)
#### Post date: [September 15, 2017, 10:38am UTC](https://forums.speedlife.net/t/equifax-data-breach/274882/14 "2017-09-15T10:38:13Z")

</div>

LinkedIn trolls are a special kind of troll

---

<div class="post-metadata">

### Author: ![ubengineering](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/ubengineering/32/5171_2.png) [@ubengineering](https://forums.speedlife.net/u/ubengineering)
#### Post date: [September 15, 2017, 8:53pm UTC](https://forums.speedlife.net/t/equifax-data-breach/274882/15 "2017-09-15T20:53:15Z")

</div>

My info was breached but I haven’t seen any fraudulent activity anywhere, Yet.

And what is a credit freeze? You just can’t get new lines of credit I assume and cards still work?

---

<div class="post-metadata">

### Author: ![JayS](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/jays/32/15375_2.png) [@JayS](https://forums.speedlife.net/u/JayS)
#### Post date: [September 16, 2017, 5:23am UTC](https://forums.speedlife.net/t/equifax-data-breach/274882/16 "2017-09-16T05:23:17Z")

</div>

Existing companies you have accounts with can still access your credit but nothing new is allowed. It’s a great way to keep your credit safe but it’s kind of a pain in the ass if you’re expecting to apply for any loans, credit cards or even shop around for insurance in the near future.

---

<div class="post-metadata">

### Author: ![Wahoo](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/wahoo/32/8265_2.png) [@Wahoo](https://forums.speedlife.net/u/Wahoo)
#### Post date: [September 17, 2017, 12:01pm UTC](https://forums.speedlife.net/t/equifax-data-breach/274882/17 "2017-09-17T12:01:15Z")

</div>

I plan to get an auto loan in the next month or so, DAMN this sucks. What should I do?

---

<div class="post-metadata">

### Author: ![LZ1](https://avatars.discourse-cdn.com/v4/letter/l/7ab992/32.png) [@LZ1](https://forums.speedlife.net/u/LZ1)
#### Post date: [September 17, 2017, 6:36pm UTC](https://forums.speedlife.net/t/equifax-data-breach/274882/18 "2017-09-17T18:36:39Z")

</div>

> [@Wahoo](#):
>
> I plan to get an auto loan in the next month or so, DAMN this sucks. What should I do?

Nothing? Like the majority of people…

---

<div class="post-metadata">

### Author: ![LZ1](https://avatars.discourse-cdn.com/v4/letter/l/7ab992/32.png) [@LZ1](https://forums.speedlife.net/u/LZ1)
#### Post date: [September 21, 2017, 10:11am UTC](https://forums.speedlife.net/t/equifax-data-breach/274882/19 "2017-09-21T10:11:16Z")

</div>

They seem to be handling the situation really well…

> **[Equifax has been directing victims to a fake phishing site for weeks](https://mashable.com/2017/09/20/equifax-twitter-phishing-site-facepalm/)**
>
> It's a site that looks almost exactly like Equifax's, but it is definitely not Equifax's.

“Equifax has been directing victims to a fake phishing site for weeks”

---

<div class="post-metadata">

### Author: ![BigRon](https://avatars.discourse-cdn.com/v4/letter/b/58956e/32.png) [@BigRon](https://forums.speedlife.net/u/BigRon)
#### Post date: [September 21, 2017, 10:25am UTC](https://forums.speedlife.net/t/equifax-data-breach/274882/20 "2017-09-21T10:25:56Z")

</div>

Anyone gotten a response from Equifax after signing up for their monitoring service? I think they said it would be a couple days, but still no response after a week.

[Next page](https://forums.speedlife.net/t/equifax-data-breach/274882.md?page=2)
