Big_Bear
10 years ago
Why the Experian-T-Mobile Hack May Bring Financial Doom to Millions

Robert McGarvey

10/05/15 - 11:43 AM EDT

NEW YORK (MainStreet) — The ugly news exploded last week: 15 million applicants for credit at T-Mobile have had their personal information stolen by hackers from a server maintained at Experian, the credit reporting agency. But then the news gets worse: very bad times are ahead for many of those 15 million, due to the nature of the stolen data.

And nobody knows exactly how the hack occurred. “There is not a ton of info on this,” admitted Christopher Budd, a security expert with Trend Micro.

For its part, T-Mobile has busied itself throwing mud at Experian. Said T-Mo CEO John Legere in a letter to consumers: “I am incredibly angry about this data breach, and we will institute a thorough review of our relationship with Experian.”

Experian, right now, shapes up as the bigger loser. Said Clay Calvert, director of cybersecurity for MetroStar Systems: “There are other two other companies [Equifax and Transunion] that monitor credit. Experian will be hurt more than T-Mobile.”


http://www.thestreet.com/story/13312302/1/why-the-experian-t-mobile-hack-may-bring-financial-doom-to-millions.html 



.
Big_Bear
10 years ago
Authorities reviewing possible hack of CIA director's personal email

WASHINGTON — Federal authorities are reviewing the possible hack of personal email accounts connected to CIA Director John Brennan and Homeland Security Secretary Jeh Johnson.

The review follows a New York Post report that an American high school student had gained access to personal accounts used by Brennan and Johnson.

Two U.S. officials, who were not authorized to comment publicly on the nature of the inquiry, said no classified information was compromised.

Secret Service spokeswoman Nicole Mainor said Monday the agency is reviewing the claims.

http://www.usatoday.com/story/news/politics/2015/10/19/cia-director-email-hack-brennan/74217564/ 



Although this isn't identity theft, I think it helps prove that the Federal Trade Commission was right. They said that identity theft can't be detected or prevented.






.



.
Big_Bear
10 years ago

000WebHost gets hacked, exposes 13 million emails and passwords

By Alan Buckingham
Published Oct. 29, 2015 10:46am

The high profile company attacks keep coming these days with Target, Home Depot and, most recently, TalkTalk. Now word comes out that a major web hosting service has also fallen victim, spewing a generous amount of information to anyone interested.

000WebHost is working to resolve the problems, which led to 13 million emails and passwords being made public, but in the meantime it is trying to take precautions to protect users, though it seems a bit late for that.

Visiting the site now defaults to error.000webhost.com and displays information of how to reset your login and password. A message appears at the top reading "Important: Due to security breach, we have set www.000webhost.com website on maintenance until issues are fixed. Thank you for your understanding and please come back later".

Australian security researcher Troy Hunt obtained the data and confirmed its authenticity. In a blog post he wrote "It was very apparent that if this was legitimate, it was indeed a very serious data breach and one that had the potential to impact a very large number of people". In fact, he claims the 13 million estimate is a bit on the low side.

Meanwhile 000WebHost has issued a statement on its Facebook page "We have witnessed a database breach on our main server. A hacker used an exploit in old PHP version to upload some files, gaining access to our systems. Although the whole database has been compromised, we are mostly concerned about the leaked client information".

Accusations have been made that both security researchers and a journalist from Forbes gave 000WebHost ample warning, but the company failed to follow up on these. Now 13 million-plus user names and plaintext passwords are out there.



.
Big_Bear
10 years ago
200,000 Comcast accounts locked down

Elizabeth Weise, USATODAY 5:27 p.m. EST November 9, 2015

SAN FRANCISCO — Comcast said on Monday it was forcing 200,000 customers to reset their passwords and information after the company discovered its information was being sold online by black market brokers.

The force-reset of the stolen accounts info, which did not come from a breach in Comcast's network but from past, shared hacks of of other companies, shows how commodified stolen data has become.

The Comcast customers' email addresses and the passwords associated with those email addresses were offered for sale on the dark web over the weekend.

The dark web consists of networks not available via the public Internet which can only be accessed through specific software. They are often used for the buying and selling of contraband goods and services.

The names were being sold as a list of 590,000 email-password combos the unnamed seller claimed belonged to Comcast customers, security website CSO reported.

http://www.usatoday.com/story/tech/2015/11/09/comcast-200000-hackers-breach-lockdown/75470608/ 



.
Pedros lawn service
10 years ago
I needed a social security number to get a job,,,

pedro,
Big_Bear
10 years ago
U.S. states probe VTech hack, experts warn of more attacks

Tue Dec 1, 2015 12:22am EST

U.S. states said they will investigate a massive breach at digital toy maker VTech Holdings Ltd as security experts warned that hackers are likely to target similar companies that handle customer data.

Attorneys general in the U.S. states of Connecticut and Illinois said on Monday that they would probe the breaches, though their representatives declined comment on the focus of their inquiries.

The Hong Kong-based toymaker disclosed the attack on Friday, saying information about nearly 5 million adults and children had been stolen in an attack on a portal used to download games to its computer tablets.

shttp://www.reuters.com/article/2015/12/01/us-vtech-cyberattack-idUSKBN0TJ0B620151201#krscZjSAMtoUo5tP.99 


.
Big_Bear
10 years ago
LifeLock will pay a record $100M to settle FTC allegations it didn’t protect customer data

by Bob Sullivan on December 18, 2015 at 9:06 am

LifeLock has agreed to pay the largest FTC enforcement case settlement ever. The case involves allegations that LifeLock didn’t do enough to protect consumer data — remember, consumers were paying the firm to protect them from ID theft.

On Thursday, LifeLock agreed to pay $100 million to settle accusations that it violated the provisions of an earlier settlement with the FTC.


http://www.geekwire.com/2015/lifelock-will-pay-a-record-100-million-to-settle-ftc-allegations-it-didnt-protect-customer-data/ 





.
CruzJ
10 years ago
I had the same thing happen to me when I was in Afghanistan. Some @$$hole in Dallas decided to use my Social for his taxes. It's hard enough getting a hold of the IRS stateside....imagine doing it halfway across the world. It all got worked out, though. Now I have PIN sent to me from the IRS for the next 7 years. Good times...
Big_Bear
10 years ago
Street Gangs Credit Card Fraud

Chris Tyler December 22, 2015

Gangs have changed the way they do things these days, no more of the days of slinging drugs on the streets and robbing people, they have moved on to credit card fraud which takes a lot less risk of getting caught, makes exponentially more money, and if they get caught, carries a lot less prison time for the gang members.

They have gotten a lot smarter, a lot better with their time, and a lot more educated. They make anywhere from upper six figures to millions of dollars everyday.

They pay employees at banks and stores to steal credit card information from customers and also buy people’s identities from various people on the internet, this is becoming gangs newest crime of choice. This money is also used to buy and sell guns to other gangs and they do this all over the world.

This kind of crime is costing the people of this country hundred of millions each year.

http://www.dbtechno.com/entertainment/2015/12/22/street-gangs-linked-to-credit-card-fraud/ 


.
Mr. Jones
10 years ago
^^^sounds like a
"white collar crime spree"
by high school dropouts...
Big_Bear
10 years ago
Time Warner Cable Admits 320,000 Customer Passwords May Have Been Stolen

Jamie Condliffe, January 7, 2016

If you’re a Time Warner Cable customer, now is a very good time to change your password. The company admitted late yesterday that it believes personal data belonging to as many as 320,000 customers may have been stolen.

The news came to light after the FBI alerted Time Warner Cable to the fact that it believed that user data, including email addresses and passwords, “may have been compromised.” Reuters reports that it’s unclear how the data was collected, though “there were no indications that Time Warner Cable’s systems were breached.” Instead, data could have been siphoned directly from users via phishing attacks or perhaps obtained from other companies in possession of some Time Warner Cable data, the news organization speculates.

http://gizmodo.com/time-warner-cable-admits-320-000-customer-passwords-may-1751532359 



.
Big_Bear
10 years ago

I've come across this quite alot.

Here's the plan.

1) Get someone's critical info
2) File taxes in his/her name (a. alter income and b. submit the tax form with address of thief)
3) Wait for the refund check.

I've heard this story countless times.

BTW, most (all?) copy machines have a hard drive in them. They do not copy the page, instead they scan it and then print from the scan.

When the company ditches or trades in the machine, every document that was "copied" is available to the new owner.

Did you copy your tax forms at work? Did your accountant? Did your preparer?

So guess where ALL of your identifying information is?

That's right: stored on some copy machine.


.

Big_Bear wrote:



Hi guys, Just a reminder. 'Tis the season id thieves love!

Taxpayer Guide to Identity Theft

For 2016, the IRS, the states and the tax industry joined together to enact new safeguards and take additional actions to combat tax-related identity theft. Many of these safeguards will be invisible to you, but invaluable to our fight against these criminal syndicates. If you prepare your own return with tax software, you will see new log-on standards. Some states also have taken additional steps. See your state revenue agency’s web site for additional details.

https://www.irs.gov/uac/Taxpayer-Guide-to-Identity-Theft 

BTW, as of Jan 1, 2016, I've been able to secure about 50 memberships that I can offer at a discount.

[email protected] for details




.
Big_Bear
10 years ago
FYI

These are the 25 internet passwords you must not use

Internet security software firm SplashData has released its annual list of passwords of the worst and most common passwords that you absolutely must not use. If you use any of the ones we list below, you must change them immediately.

They might be easier for you to remember, but they are also equally as easy for hackers to guess. Indeed, many of them are probably preset by malicious software algorithms looking to get into your accounts.

FULL STORY
http://www.msn.com/en-us/news/technology/these-are-the-25-internet-passwords-you-must-not-use/ar-BBoqcLp?ocid=ansmsnnews11 
DrafterX
10 years ago
Is it similar to Carlin's list..?? 😕
Big_Bear
10 years ago
Centene Discloses Search for Hard Drives Containing Member Data

Health insurer says six drives with sensitive information of about 950,000 members are missing

By Ezequiel Minaya
Jan. 25, 2016 6:37 p.m. ET

Health insurer Centene Corp. said on Monday that six hard drives containing sensitive information of about 950,000 members are “unaccounted for,” leading the company to launch an internal search.

The Medicaid-focused insurer said that while it doesn’t believe this information has been used inappropriately, it is disclosing the search “out of abundance of caution.” Centene said it had started the process of notifying all affected individuals and appropriate regulatory agencies.

http://www.wsj.com/articles/centene-discloses-search-for-hard-drives-containing-member-data-1453765029?mod=rss_Technology 

= = = = = = = = = = = = = = = = = = = = = = = = = = = = =

I wouldn't worry about it. More than likely, none of these nearly constant data breaches will affect any of us.

[sarcasm]
Big_Bear
10 years ago
Wendy's Is Looking Into Reports of a Credit Card Breach

by Reuters - January 27, 2016, 2:16 PM EST

Burger chain operator Wendy's said on Wednesday it was investigating reports of unusual activity with payment cards used at some of its 5,700 locations in the U.S.

“Reports indicate fraudulent charges may have occurred elsewhere after payment cards were legitimately used at some restaurants,” Wendy‘s spokesman Bob Bertini told Reuters in an email statement.

Large retailers such as Target and Home Depot have been victims of security breaches in recent years. Gourmet sandwich chain Jimmy John’s was also breached in 2014.

http://fortune.com/2016/01/27/wendys-credit-card-breach/ 
Mr. Jones
10 years ago
Hey Big_Bear....

do some research on these new RFID CHIPPED
credit cards and US Passports:

supposedly they can all be read by theives w/ hand held devices purchased on the internet for around $100 bucks or FREE DOWNLOADED APPS onto cell
phones....all the theives have to do is get near your purse and wallet to read all your C.C. card #'s
5' to 25' away.... depending on what device they use?
Supposedly, manufacturer's are selling blocking sleeves or just one card that blocks your whole
wallet...$15 each-$100 for multiples...not all sleeves block all signals..."STEALTH" brand supposedly does???
Big_Bear
10 years ago
Yes.

Those readers are widely available.

Credit card fraud, however, is just one small part of the problem.

A friend of mine was denied a CFO position because he was serving time in Arizona. He wasn't, but the guy who is incarcerated got himself booked using my friends identity. By the time things were straightened out they gave the job to someone else. Someone less "complicated" and "messy."

What about the kid who turns eighteen and gets denied a credit card because he defaulted on a yacht he purchased in Florida three years prior. Children are 51times more likely to get hit.


Then there's the mom who had her identity stolen (let's call her A). Another woman on crack (B) used her identity, had her baby, and went home. Testing later revealed the substance. The cops and HHS went to A's house to take her children. Thousands of dollars later everything got straightened out, but who wants to have their family taken for "just a few nights" because of an identity theft. Think about that from A's perspective. She and her husband had a baby and went home. A few weeks later the government came to confiscate their children.

Most people can handle credit card fraud which is what you're describing. The banks and credit card companies usually let you off the charge(s) with just a phone call.

It's the medical and criminal id theft that concerns most people.

Make no mistake, most (but not all) problems can get straightened out after spending hours and hours on the phone and thousands of dollars in legal fees.

I'd just rather have the membership that'll straighten everything out without my having to get invlolved in the details.

I can do my own taxes, but I'd rather spend the money on an accountant who knows what she's doing.




.
Mr. Jones
10 years ago
^^^ yea,

I know all about medical fraud...

My parents were robbed ( pick pocted w/ diversion tatics) in an elevator at a hosiptal while my Dad was terminally ill....
It takes a " special kind of LOW LIFE SCUM BAG TAG TEAM" to pull that off and then proceed to take $6K-$10K within 3 hours of robbing a sick person at a hospital.
My dad passed away...then 5-6 yrs later , the same LOW LIFE SCUM sold his SSN# to a degenerate who got a
"free" 5 figure operation at a distant hosiptal under my deceased dads SSN #...
friggin scumbags....
tonygraz
10 years ago

...I can do my own taxes, but I'd rather spend the money on an accountant who knows what she's doing.

Big_Bear wrote:



Male accountant outrage ! [ram27bat]




56
Users browsing this topic