How to stay safe after the Equifax data breach

Equifax disclosed last week that the personal financial information of up to 143 million users had been exposed in a massive hack last July. This represents roughly two-thirds of all credit card holders, so you may be affected.

The delay in disclosing is troubling, and the hack raises questions about oversight of the credit bureaus and even about the impact on their management. We can see the impact on investors: the Equifax share price has dropped over 20%

While we can discuss these issues and more, the priority is shoring up your personal credit.

Impact

Was your data taken? There are links from Equifax, Norton and others where you can attempt to determine the impact on you personally. However, these sites seem to default to “you may be affected,” even if you put in bogus information.

The good news is that Equifax has responded to consumer pressure to make certain services free.

Act now

You will want to act as soon as possible to keep your financial information safe.

“There are so many entities who need to check your credit: when you’re renting an apartment, getting insurance, a new cell phone, utilities,” Liz Weston, a financial planner and columnist at NerdWallet, told BuzzFeed News. “But at this point the breach is so great” that taking measures to safeguard your identity is worth it. She recommends instituting credit freezes.

Equifax free service – sign up on line for the complimentary service being provided by Equifax, which provides the following:

  • three-bureau credit file monitoring with alerts,
  • credit report lock,
  • scanning of suspicious sites for use of your social security number,
  • Equifax credit reporting, and
  • $1 million identity theft insurance covering certain out-of-pocket expenses.

Monitor your cards – review your monthly credit card, bank and loan statements for suspicious activity. You have a right to free credit reports so obtain them and review for unauthorized activity.

Also, watch for unexpected calls or mail, such as debt collectors or people posing as IRS agents, because these may be signs that your information may be in the hands of thieves.

Credit freeze – request a freeze on your credit from all three agencies: Equifax, TransUnion, and Experian. Equifax will not charge you but the others will.

Requesting a credit freeze prevents thieves from using your identity to get loans or credit cards in your name, even if your personal information was compromised by the hack. You essentially pay to bar each of three credit reporting agencies — Equifax, TransUnion, and Experian — from providing a credit report without both your explicit permission and a personal identification number (PIN) that temporarily lifts the freeze. (Freezes do not affect financial institutions or companies you have an existing relationship with, only new ones.)

Make sure to place the freeze with all three bureaus and to keep your PINs for unlocking the freezes in a safe place.

“A credit freeze with only one bureau is incomplete protection,” Mike Litt, the consumer program advocate at the US Public Interest Research Group, a consumer group, said. Consumer experts recommended getting a freeze with all three agencies.

There are companies such as LifeLock that provide bundled services. If cost is not an object, that may be the best course of action. Here is the Lifelock response on Equifax.

Fraud alert – if you are certain that your information has been taken, place alert all three credit bureau websites. You can access the TransUnion site here. Some protection is free, but their premium package costs $9.95

If you are the subject of identity theft, there are many resources now that help you report and recover. The Federal Trade Commission website can help devise a recovery plan to implement.

PINs and passwords – the passwords and PINs you use could be the next issue. You may want to change what you use now and update annually, if not more often.

Updates – Equifax continues to provide updates on the status of the hack and their response.

And news sites continue to report on the hack – see this NY Times article.

Summary

There are many steps to take, and the information taken may not be used for some time. So, you will want to take some if not all the steps outlined above. If you have trouble doing so, or if you have questions, let us know.

And for more reading, the Better Business Bureau is one resource for tips on avoiding scams. And, the FTC is a good resource for identity theft.

Good luck and stay safe!

Scam update for more on Cyber-Attackers, Cloud Computing – be Vigilant!

We wrote before about the need for vigilance to protect you from cybercriminals. We drew on input from Norton Antivirus about social media scams. In this post, we draw upon the Kiplinger’s Tax Letter and SingleHop.com site.

IRS e-mails – You might not think that tax preparers would fall for e-mail scams, but some do. The 2-27-15 Kiplinger’s Tax Letter describes use of bogus e-mails asking professionals to “update their IRS e-services accounts and their electronic filing ID numbers plus provide personal data.” As we have said in prior posts, the IRS categorically states that they do not send out e-mails.

Cloud Computing – SingleHop is a company endeavoring to be private cloud experts. They champion users holding cloud servers accountable for maintaining high level, monitored and updated security for all client files. Their recent newsletter notes that over 250,000 complaints were filed with the FBI’s Internet Crime Complaint Center (ic3.gov) in 2013 alone, of which over 20% were under age 30. (For more on how “private cloud” computing fits in the internet infrastructure, here is a helpful SingleHop page: [[https://www.singlehop.com/private-cloud-hosting/|SingleHop site]])

They caution you not to rely on links from e-mails to the websites you frequent. Instead, they encourage you to create bookmarks for these websites to ensure that you are logging onto the site you intend. They also favor sites that use two levels to authenticate you before granting access to personal information. “With such methods, after logging in with your password, the site will text or email you a single-use code that must be entered. Only the registered phone number or email address will receive the code, making it that much harder for hackers to gain unauthorized access to your accounts.”

Scam Update – With the cautions from both sources in mind, we updated our post, to help you remain vigilant:

//Hidden URLs// – Those shortened URLs are convenient, but they may be links to websites you don’t want to visit, or worse, they could install malware on your computer. SingleHop admonishes, “Especially look out for slightly misspelled words or words that use unexpected characters, such as substituting a “0” (number) for a “0” (letter) — for example, HOME DEPOT. If something looks even a little bit fishy, delete the email or close the site immediately.”

//Phishing Requests// – When you get an invitation to click on any link, think twice. When you click, you may be taken to a fake Twitter or Facebook or to a bank, credit card issuer, or another financial institution login page. SingleHop says “Phishers will design their sites to look exactly like the website of your” institutions. If you fall for the fake website, and enter you username and password, the cybercriminals can use your information on the real website to gain complete control of your account.

//Hidden Charges// – Be wary of those online quizzes that offer to tell you interesting information about yourself like which 1960s sitcom star you resemble. If the quiz asks you for personal information, such as your phone number, stop. If you continue, you many end up subscribing to some service that charges a recurring monthly fee.

//Cash Grabs// – It’s great to make new friends, but maybe not by “friending” strangers on Facebook. That person you just friended on Facebook may soon be asking you for money. You can avoid this situation by limiting your social media connections to people you know personally. Ignore friend requests when you do not know the person and have no friends in common.

//Chain Letters// – Sure, you want to be sure that Microsoft will donate the millions it promised to some worthy charity if you keep the online chain letter going. However, such “chain letter” e-mails are a way for spammers to access your friends to connect with them later. Also, you never know to whom your friends will forward the letter.

Sites that are popular with users are popular with criminals, so remain vigilant when you are on line, and, of course, keep your antivirus and anti-malware software up to date. Be wary and think twice before clicking on a suspicious link!

On-line Scams – some to look out for to protect your finances

Our society today has growing appetite for social media and most of us use it for legitimate purposes: connecting with our friends, pursuing our hobbies or building our businesses. Unfortunately, part of the population has a more insidious use for social media: they want to scam you. Thankfully, a little vigilance can go a long way in protecting you from these cyber criminals. Here is one list you can use, from Norton Antivirus, showing the top five social media scams:
1. **Hidden URLs** – Those shortened URLs are convenient, but they may be links to websites you don’t want to visit, or worse, they could install malware on your computer.
2. **Phishing Requests** – When you get an invitation to click on a link to see a picture of yourself at some wild party, think twice. Once you click, you’re taken to a fake Twitter or Facebook login page where you enter you user name and password. Doing this gives the cyber-criminals complete control of your account.
3. **Hidden Charges** – Be wary of those on-line quizzes that offer to tell you interesting information about yourself like which 1960s sitcom star you resemble. If the quiz asks you for personal information, such as your phone number, stop. If you continue, you many end up subscribing to some service that charges a recurring monthly fee.
4. **Cash Grabs** – It’s great to make new friends, but maybe not by “friending” strangers on Facebook. That person you just friended on Facebook may soon be asking you for money. You can avoid this situation by limiting your social media connections to people you know personally.
5. **Chain Letters** – Sure, you want to be sure that Microsoft will donate the millions it promised to some worthy charity if you keep the on-line chain letter going. However, such “chain letter” e-mails are a way for scammers to access your friends to connect with them later.
Sites that are popular with users are popular with criminals, too. Be vigilant, keep your anti-virus and anti-malware software up to date and think twice before clicking on a suspicious link!