#equifax — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #equifax, aggregated by home.social.
-
“Canadian researchers at Univ of #Winnipeg and #Concordia in #Montreal write about a quieter form of protest taking place—the fight against #Trump’s expanding surveillance apparatus.
Palantir buying up data such as credit reports from #Equifax have helped #ICE raids.
Where surveillance has powerful institutions watching people from above, ‘sousveillance’ is ordinary people and grassroots groups watching, mapping, and documenting those institutions from below.”
-
“Canadian researchers at Univ of #Winnipeg and #Concordia in #Montreal write about a quieter form of protest taking place—the fight against #Trump’s expanding surveillance apparatus.
Palantir buying up data such as credit reports from #Equifax have helped #ICE raids.
Where surveillance has powerful institutions watching people from above, ‘sousveillance’ is ordinary people and grassroots groups watching, mapping, and documenting those institutions from below.”
-
Among the latest data-breach villains: the Washington Post
Members of the Washington Post’s extended diaspora, meaning both former employees as well as past freelancers, have begun getting an unwelcome reminder of that chapter in their professional lives: a letter from the Post, sent from an address not in the District but in West Sacramento, Calif., informing them of a “Data Security Incident.”
That inefficient phrase is defensive legalese for “data breach,” which the letter says, in comparably defensive passive voice, happened between July 10 and Aug. 22, 2025, when “certain data was accessed and acquired without authorization” from unspecified Oracle E-Business Suite applications.
In my case and others, to judge from reports from fellow recipients of this joyless notice, the “certain data” included names and Social Security numbers.
The letter may not spark any more joy at Oracle, since it describes the vulnerability exploited as a “previously unknown and widespread” flaw. Oracle’s own warning red-flags it as “remotely exploitable without authentication.” But the paper’s disclosure does not address another cause of the data breach: how the Post chose to retain this sort of sensitive data long after it should have stopped being regularly business-relevant.
Consider my example: The last time I had any ongoing transactions with the Post that should have involved my SSN was 15 years ago. I rolled over my 401(K) after leaving the paper, and Jeff Bezos buying the Post in 2013 resulted in the company transferring my pension and those of other ex-Posties to former publisher Don Graham’s firm Graham Holdings.
For the handful of freelance pieces I’ve sold to my old shop since then (such as the Jan. 28, 2019 opinion piece headlined “Big tech firms still don’t care about your privacy”), I’ve used the Employer Identification Number I obtained shortly after I started freelancing.
Yet apparently my SSN was still sitting unencrypted in a network-accessible database last summer, contrary to basic security advice, along with the digits of thousands of other current and former Post employees and contractors. Some had banking details compromised too.
That’s “thousands” as in 9,720 people, per a filing the Post made with Maine’s Attorney General in November that a few security publications covered at the time. A month later, a former Post employee named Jun Hee Kim filed a class-action lawsuit against the Post on behalf of those nearly 10,000 individuals.
I have yet to get a notice inviting me to join that class, and the Post’s letter does not mention the litigation. Instead, it offers the usual paltry remedy of a year of identity-theft monitoring, in this case from a firm called IDX.
I know that’s the standard act of apology not only from covering data breaches but from having my data exposed in them, over and over. I know the drill well enough to have turned “Equifax” into the verb “Equifaxed” and to have frozen my credit more than once.
So at some level, I’m not surprised at the news of the Post’s data breach so much as I’m surprised that it took this long. Throughout my time working at 15th and L, I saw the Post treat SSNs as carelessly as anybody else did decades ago–even using them as employee IDs, as seen in some of my own admin paperwork from early in this century showing the full nine digits. But it’s still stupid and sloppy that this particular data breach happened not in 2005 or 2015 but in 2025, well past the point when management at the Post should have known better.
#Cl0p #CVE202561882 #dataBreach #dataMinimization #DataSecurityIncident #EIN #EmployerIdentificationNumber #Equifax #Equifaxed #IDX #Oracle #OracleEBusinessSuite #personallyIdentifiableInformation #PII #SocialSecurityNumber #SSN #TaxIDNumber #wapo #washingtonPost -
Among the latest data-breach villains: the Washington Post
Members of the Washington Post’s extended diaspora, meaning both former employees as well as past freelancers, have begun getting an unwelcome reminder of that chapter in their professional lives: a letter from the Post, sent from an address not in the District but in West Sacramento, Calif., informing them of a “Data Security Incident.”
That inefficient phrase is defensive legalese for “data breach,” which the letter says, in comparably defensive passive voice, happened between July 10 and Aug. 22, 2025, when “certain data was accessed and acquired without authorization” from unspecified Oracle E-Business Suite applications.
In my case and others, to judge from reports from fellow recipients of this joyless notice, the “certain data” included names and Social Security numbers.
The letter may not spark any more joy at Oracle, since it describes the vulnerability exploited as a “previously unknown and widespread” flaw. Oracle’s own warning red-flags it as “remotely exploitable without authentication.” But the paper’s disclosure does not address another cause of the data breach: how the Post chose to retain this sort of sensitive data long after it should have stopped being regularly business-relevant.
Consider my example: The last time I had any ongoing transactions with the Post that should have involved my SSN was 15 years ago. I rolled over my 401(K) after leaving the paper, and Jeff Bezos buying the Post in 2013 resulted in the company transferring my pension and those of other ex-Posties to former publisher Don Graham’s firm Graham Holdings.
For the handful of freelance pieces I’ve sold to my old shop since then (such as the Jan. 28, 2019 opinion piece headlined “Big tech firms still don’t care about your privacy”), I’ve used the Employer Identification Number I obtained shortly after I started freelancing.
Yet apparently my SSN was still sitting unencrypted in a network-accessible database last summer, contrary to basic security advice, along with the digits of thousands of other current and former Post employees and contractors. Some had banking details compromised too.
That’s “thousands” as in 9,720 people, per a filing the Post made with Maine’s Attorney General in November that a few security publications covered at the time. A month later, a former Post employee named Jun Hee Kim filed a class-action lawsuit against the Post on behalf of those nearly 10,000 individuals.
I have yet to get a notice inviting me to join that class, and the Post’s letter does not mention the litigation. Instead, it offers the usual paltry remedy of a year of identity-theft monitoring, in this case from a firm called IDX.
I know that’s the standard act of apology not only from covering data breaches but from having my data exposed in them, over and over. I know the drill well enough to have turned “Equifax” into the verb “Equifaxed” and to have frozen my credit more than once.
So at some level, I’m not surprised at the news of the Post’s data breach so much as I’m surprised that it took this long. Throughout my time working at 15th and L, I saw the Post treat SSNs as carelessly as anybody else did decades ago–even using them as employee IDs, as seen in some of my own admin paperwork from early in this century showing the full nine digits. But it’s still stupid and sloppy that this particular data breach happened not in 2005 or 2015 but in 2025, well past the point when management at the Post should have known better.
#Cl0p #CVE202561882 #dataBreach #dataMinimization #DataSecurityIncident #EIN #EmployerIdentificationNumber #Equifax #Equifaxed #IDX #Oracle #OracleEBusinessSuite #personallyIdentifiableInformation #PII #SocialSecurityNumber #SSN #TaxIDNumber #wapo #washingtonPost -
RE: https://zeroes.ca/@ndrwy/116840202514387974
I had done Equifax a couple weeks ago, now did the credit freeze for Transunion
It's also a good exercise to have an account with those 2 services (even if you don't credit freeze) as it associates yourself with an account and you reduce the chance of a fraudster claiming your account.
-
RE: https://zeroes.ca/@ndrwy/116840202514387974
I had done Equifax a couple weeks ago, now did the credit freeze for Transunion
It's also a good exercise to have an account with those 2 services (even if you don't credit freeze) as it associates yourself with an account and you reduce the chance of a fraudster claiming your account.
-
Americans now owe a staggering $18.19 trillion as credit card debt keeps climbing
https://fed.brid.gy/r/https://nerds.xyz/2026/05/us-consumer-debt-2026/
-
Americans now owe a staggering $18.19 trillion as credit card debt keeps climbing
https://web.brid.gy/r/https://nerds.xyz/2026/05/us-consumer-debt-2026/
-
🔥 TRENDING
📢 Equifax and GBG Expand Global Partnership - Sahm
#Equifax #Expand #Global #Partnership #GlobalFeed #News #ARABIC
*Automatically posted by Global Feed Bot*
-
@zackwhittaker no “forethought to the future consequences of amassing vast banks of personal information” is required here, merely hindsight. We all know how this is going to play out. Think #Equifax.
-
@zackwhittaker no “forethought to the future consequences of amassing vast banks of personal information” is required here, merely hindsight. We all know how this is going to play out. Think #Equifax.
-
This is such a cunning, shameless, beautiful scam.
Got an email from Equifax (who exposed zillions of records to hackers not long ago if memory serves), the gist of which was:
'Nice credit rating you got there. Be a shame if something happened to it...'
I took the bait and logged in.
The images tell the story.
It's a sublime shakedown.
-
This is such a cunning, shameless, beautiful scam.
Got an email from Equifax (who exposed zillions of records to hackers not long ago if memory serves), the gist of which was:
'Nice credit rating you got there. Be a shame if something happened to it...'
I took the bait and logged in.
The images tell the story.
It's a sublime shakedown.
-
A look at how tri-merge credit reduces credit uncertainty. https://hackernoon.com/how-tri-merge-reduces-credit-uncertainty #equifax
-
A look at how tri-merge credit reduces credit uncertainty. https://hackernoon.com/how-tri-merge-reduces-credit-uncertainty #equifax
-
Those Austrians who are concerned about their personal data they provide for the purpose of age verification leaking are overreacting. There is no reason to worry.
That's because a subsidiary of the Austrian Broadcasting Corporation (#ORF) already leaked every single Austrian's birthdate a few years ago, so your data is already out there. The Austrian data protection agency stated that that company "did everything right“, and there were no repercussions.
I am being sarcastic, of course. When you upload a copy of your personal id, keep in mind that the company processing it will face little to no consequences in case they leak that data. So there isn't much of an incentive to waste money on protecting it. Also, don't expect any compensation from that company (how much did you get from #equifax?) in case you incur any damages because of that leak - the onus will be on you to prove that the damages are a direct consequence of that specific leak.
Oh, and in case you think that that's not going to happen, it already did: https://www.bbc.com/news/articles/c8jmzd972leo
-
Those Austrians who are concerned about their personal data they provide for the purpose of age verification leaking are overreacting. There is no reason to worry.
That's because a subsidiary of the Austrian Broadcasting Corporation (#ORF) already leaked every single Austrian's birthdate a few years ago, so your data is already out there. The Austrian data protection agency stated that that company "did everything right“, and there were no repercussions.
I am being sarcastic, of course. When you upload a copy of your personal id, keep in mind that the company processing it will face little to no consequences in case they leak that data. So there isn't much of an incentive to waste money on protecting it. Also, don't expect any compensation from that company (how much did you get from #equifax?) in case you incur any damages because of that leak - the onus will be on you to prove that the damages are a direct consequence of that specific leak.
Oh, and in case you think that that's not going to happen, it already did: https://www.bbc.com/news/articles/c8jmzd972leo
-
Equifax got hacked. Nearly 150 million people's data stolen. And the executives' first move was to quietly sell their shares. 🤦
This is The Facepalm Files.
Check out my podcast "Smashing Security" for more stories like this.
#facepalm #cybersecurity #equifax #databreach #infosec #hacking
-
Equifax got hacked. Nearly 150 million people's data stolen. And the executives' first move was to quietly sell their shares. 🤦
This is The Facepalm Files.
Check out my podcast "Smashing Security" for more stories like this.
#facepalm #cybersecurity #equifax #databreach #infosec #hacking
-
Find out what kinds of data banks and other financial institutions collect about you and their intended use by diving into the series What Everybody Knows About You. ⬇️
#LPI #financialdata #bankingdata #creditscore #SIN #taxpayer #creditreport #Equifax
-
Find out what kinds of data banks and other financial institutions collect about you and their intended use by diving into the series What Everybody Knows About You. ⬇️
#LPI #financialdata #bankingdata #creditscore #SIN #taxpayer #creditreport #Equifax
-
Solteros lideran tramo de mayor morosidad, con deudas promedio de $12 millones | vía #UChileRadio
-
Edmonton woman frustrated by 18-month battle with Equifax and TransUnion to fix credit rating
https://www.cbc.ca/news/gopublic/credit-ratings-fraud-9.7099030
- - -
Une femme d’Edmonton frustrée par une bataille de 18 mois avec Equifax et TransUnion pour corriger sa cote de crédit// Article en anglais //
-
Edmonton woman frustrated by 18-month battle with Equifax and TransUnion to fix credit rating
https://www.cbc.ca/news/gopublic/credit-ratings-fraud-9.7099030
- - -
Une femme d’Edmonton frustrée par une bataille de 18 mois avec Equifax et TransUnion pour corriger sa cote de crédit// Article en anglais //
-
@Cdespinosa yeah, right. Did anyone ever get their $125 from #equifax ? Even the #FTC advised consumers in the end to not even ask for it.
-
@Cdespinosa yeah, right. Did anyone ever get their $125 from #equifax ? Even the #FTC advised consumers in the end to not even ask for it.
-
Equifax rolls out AI-driven synthetic identity fraud detection as lenders feel the pressure
-
Equifax rolls out AI-driven synthetic identity fraud detection as lenders feel the pressure
-
@camless You're welcome. And if people have children or relatives who may not know about this, you may want to check for them and opt them out of nationalpublicdata.com, too (see https://nationalpublicdata.com/optout.html).
Then also help them create security freezes.
Parents of young children: Check to make sure your kids' info isn't in the nationalpublicdata.com site. Opt them out if they are. Then:
Your kids should not have a credit report unless you authorized them to use a credit card or something. But they may also have a credit report if their identity info was obtained and misused.
Check to see if they have a credit report by contacting the major credit reporting firms. You may have to mail the request for Equifax, but you should be able to check online for Experian and TransUnion .
To be proactive: freeze your young child's credit report.
#security #creditreports #Experian #TransUnion #Equifax #NPD #optout
-
@camless You're welcome. And if people have children or relatives who may not know about this, you may want to check for them and opt them out of nationalpublicdata.com, too (see https://nationalpublicdata.com/optout.html).
Then also help them create security freezes.
Parents of young children: Check to make sure your kids' info isn't in the nationalpublicdata.com site. Opt them out if they are. Then:
Your kids should not have a credit report unless you authorized them to use a credit card or something. But they may also have a credit report if their identity info was obtained and misused.
Check to see if they have a credit report by contacting the major credit reporting firms. You may have to mail the request for Equifax, but you should be able to check online for Experian and TransUnion .
To be proactive: freeze your young child's credit report.
#security #creditreports #Experian #TransUnion #Equifax #NPD #optout
-
Vollautomatisierte #KI-#Cyberangriffe als Prototyp: Wissenschaftler von der Carnegie Mellon University haben den 2017er Datenskandal bei der US-Wirtschaftsauskunftei #Equifax nachgestellt, indem sie ein LLM vollautomatisiert einen Cyberangriff koordinieren und durch #AI Agents durchführen ließen.
Das Ergebnis war erfolgreich. Obgleich unter nicht replizierbaren Laborbedingungen durchgeführt, zeigt das Szenario auf, in welche Richtung Cyberangriffe künftig gehen könnten:
-
Vollautomatisierte #KI-#Cyberangriffe als Prototyp: Wissenschaftler von der Carnegie Mellon University haben den 2017er Datenskandal bei der US-Wirtschaftsauskunftei #Equifax nachgestellt, indem sie ein LLM vollautomatisiert einen Cyberangriff koordinieren und durch #AI Agents durchführen ließen.
Das Ergebnis war erfolgreich. Obgleich unter nicht replizierbaren Laborbedingungen durchgeführt, zeigt das Szenario auf, in welche Richtung Cyberangriffe künftig gehen könnten:
-
I was excited to get notice of my share of a distribution in a class action against Equifax.
My share: $0.03.
Maybe that will make affordable that nice Romanée Conti at Auberge de l'Ill in Alsace. I'm almost there. Just another $28,693.97.
-
I was excited to get notice of my share of a distribution in a class action against Equifax.
My share: $0.03.
Maybe that will make affordable that nice Romanée Conti at Auberge de l'Ill in Alsace. I'm almost there. Just another $28,693.97.
-
Fin de la surveillance Equifax gratuite pour les clients Desjardins. #equifax demande $30 / mois pour ça, idem pour #transunion. Au Québec une loi force les agence de crédit à geler notre dossier de crédit ce qui devrait empêcher un fraudeur d'obtenir du crédit sous notre nom. On peut aussi accéder au dossier gratuitement pour le vérifier périodiquement. Il faut se créer un compte sur les 2 agences: https://my.equifax.ca/dashboard et https://secure-ocs.transunion.ca/secureocs/home.html?lang=fr. C'est bien expliqué: https://lactualite.com/finances-personnelles/fin-de-la-surveillance-equifax-de-desjardins-voici-une-option-de-rechange-gratuite/
-
Fin de la surveillance Equifax gratuite pour les clients Desjardins. #equifax demande $30 / mois pour ça, idem pour #transunion. Au Québec une loi force les agence de crédit à geler notre dossier de crédit ce qui devrait empêcher un fraudeur d'obtenir du crédit sous notre nom. On peut aussi accéder au dossier gratuitement pour le vérifier périodiquement. Il faut se créer un compte sur les 2 agences: https://my.equifax.ca/dashboard et https://secure-ocs.transunion.ca/secureocs/home.html?lang=fr. C'est bien expliqué: https://lactualite.com/finances-personnelles/fin-de-la-surveillance-equifax-de-desjardins-voici-une-option-de-rechange-gratuite/
-
I don’t ever remember opting in to having #Equifax or any other #credit #reporting agency collect my information and then sharing it with others.
-
Woohoo!
The company we didn't elect and can't opt out of empowering to determine our financial futures and credit worthiness was breached and all I got was $8
Worst T-Shirt ever.
-
Woohoo!
The company we didn't elect and can't opt out of empowering to determine our financial futures and credit worthiness was breached and all I got was $8
Worst T-Shirt ever.
-
Well my faith in the system is renewed. Surely this is a sufficient penalty to incentivize #Equifax to keep my financial information properly secured.
-
Well my faith in the system is renewed. Surely this is a sufficient penalty to incentivize #Equifax to keep my financial information properly secured.
-
oh hey, 20 whole dollars in damages from all my PII leaked to the world in the #Equifax #databreach settlement.
-
oh hey, 20 whole dollars in damages from all my PII leaked to the world in the #Equifax #databreach settlement.
-
Change Healthcare Breach Hits 100M Americans – Source: krebsonsecurity.com https://ciso2ciso.com/change-healthcare-breach-hits-100m-americans-source-krebsonsecurity-com/ #USDepartmentofHealthandHumanResources #rssfeedpostgeneratorecho #CyberSecurityNews #UnitedHealthGroup #KrebsonSecurity #KrebsOnSecurity #LatestWarnings #TheComingStorm #SenMarkWarner #DataBreaches #HIPAAJournal #SenRonWyden #AnthemInc. #TransUnion #RansomHub #BlackCat #Experian #Equifax #alphv #IDX
-
Change Healthcare Breach Hits 100M Americans – Source: krebsonsecurity.com https://ciso2ciso.com/change-healthcare-breach-hits-100m-americans-source-krebsonsecurity-com/ #USDepartmentofHealthandHumanResources #rssfeedpostgeneratorecho #CyberSecurityNews #UnitedHealthGroup #KrebsonSecurity #KrebsOnSecurity #LatestWarnings #TheComingStorm #SenMarkWarner #DataBreaches #HIPAAJournal #SenRonWyden #AnthemInc. #TransUnion #RansomHub #BlackCat #Experian #Equifax #alphv #IDX
-
CW: US credit agencies
I have a daughter who is about 8 years old. By living in the US, she has been a victim of at least a few data breaches that we know of....because....yeah.
So it's safe to assume that her identity has been compromised. My wife and I both have our credit reports frozen. I decided to see what it takes to monitor or freeze hers.
Holy fuck! Here's the dystopian hellscape I saw.
All 3 agencies claim that they don't keep records for minors unless they're co-signed on an adult's credit card. Of course, they also admit (as little as possible) that bad data about the child's date of birth can lead to them having a file.
Ok. Cool. How do I check that they have the right information? Transunion has a web form that I can fill out. Experian and Equifax both require me to MAIL copies of documents including birth certificate, social security card, my ID, and a LETTER STATING WHY I THINK MY CHILD'S IDENTITY MAY HAVE BEEN COMPROMISED.
I have to tell EQUIFAX why a US citizen's identity may have been compromised.
That's not enough, though. All 3 agencies and the CFPB (gov't agency) then decide to lecture me on protecting my child's identity. Hey, assholes, I'm not the one who left my daughter's SSN open on the internet!
-
Change Healthcare Breach Hits 100M Americans
https://krebsonsecurity.com/2024/10/change-healthcare-breach-hits-100m-americans/
#U.S.DepartmentofHealthandHumanResources #UnitedHealthGroup #LatestWarnings #TheComingStorm #Sen.MarkWarner #DataBreaches #HIPAAJournal #Sen.RonWyden #AnthemInc. #TransUnion #RansomHub #BlackCat #Experian #Equifax #ALPHV #IDX
-
Change Healthcare Breach Hits 100M Americans https://krebsonsecurity.com/2024/10/change-healthcare-breach-hits-100m-americans/ #USDepartmentofHealthandHumanResources #UnitedHealthGroup #LatestWarnings #TheComingStorm #SenMarkWarner #DataBreaches #HIPAAJournal #SenRonWyden #TransUnion #AnthemInc #RansomHub #BlackCat #Experian #Equifax #ALPHV #IDX