Hey! Thank you for the information. Several news outlets are recommending https://npd.pentester.com/ I have never heard of the service and, thus, I am skeptical of it. Do you happen to be familiar...
Hey! Thank you for the information. Several news outlets are recommending https://npd.pentester.com/ I have never heard of the service and, thus, I am skeptical of it. Do you happen to be familiar with the site? If not, could you please check if a couple of the records leaked match the information showed by that site to at least confirm its validity?
Thanks for that site link. I figured I'd try it since it doesn't really require me to put anything personal in there (although at this point, for most people even personal information isn't...
Thanks for that site link. I figured I'd try it since it doesn't really require me to put anything personal in there (although at this point, for most people even personal information isn't personal anymore). I checked myself and a few others I know, and I wasn't in there my some other family members were.
You should freeze your credit at all three major credit bureaus: Equifax, Experian, and Transunion. Nerd Wallet has a guide. The bureaus don't like to make it easy, and will try and get you to...
You should freeze your credit at all three major credit bureaus: Equifax, Experian, and Transunion. Nerd Wallet has a guide. The bureaus don't like to make it easy, and will try and get you to sign up for a paid membership, but keep declining and opting out of that stuff, as it isn't required. You will need (or should) make an account with each bureau and securely record your security questions and pin information so you can quickly add temporary "thaws" on your report for when you do need a "hard" credit check like to get approved for a loan or a credit card.
Solid work with the script and analysis. The article mentioned the breach may include Canadian and UK data as well. Did any of your results look to show results in that vein, Canadian or UK...
Solid work with the script and analysis. The article mentioned the breach may include Canadian and UK data as well. Did any of your results look to show results in that vein, Canadian or UK formatted "social security" numbers for example?
Thanks for putting in the effort. That's not the method I'd have thought to use but sounds like a good one. It's useful that Canada Post and USPS have agreed to not use the same two letters...
Have you tried throwing it in a database? It might take a bit of time to ingest the data, but SQLite with a handful of indexes should churn through searches like this without a problem. I’m at...
Have you tried throwing it in a database? It might take a bit of time to ingest the data, but SQLite with a handful of indexes should churn through searches like this without a problem. I’m at work right now, but I’ll be trying this when I get home.
Thanks for the links! I wanted to share that I've found several false negatives between the search at Pentester and the actual leaked data. I can't say for sure, but I think that the pentester...
Thanks for the links!
I wanted to share that I've found several false negatives between the search at Pentester and the actual leaked data. I can't say for sure, but I think that the pentester data might have been lightly deduped in a hurry, indexed wrong, or something. I've found it most reliable to search the raw data using current and former street addresses like "### North Street ST" as it would appear on your driver's license, bank, or credit reports. That seems to reliably catch cases where you have multiple people with the same name and address, etc. Not sure why social wouldn't disambiguate those cases in the pentester data, but I've had a few friends and family searches, get no hits, and then do a full search of the raw data and find records.
They're just text files, so not from that part, but they're in 7z compressed archives, so theoretically someone could have private knowledge of a vulnerability that would affect anyone who opens...
They're just text files, so not from that part, but they're in 7z compressed archives, so theoretically someone could have private knowledge of a vulnerability that would affect anyone who opens or extracts them. I'd say that's unlikely, but we had something similar in xz recently...
It's not unreasonable to think, especially because 7z also had some security issue 2 years back: https://nvd.nist.gov/vuln/detail/cve-2022-29072 I decompressed the 7z archives using a pure-rust...
I decompressed the 7z archives using a pure-rust lzma implementation just to see if it would do anything unusual and for what it's worth it didn't. I don't think it's a 7z 0-day.
I think WinRAR and XZ can beat it out in some use cases, but if your goal is compressing mindboggling amounts of text, it's hard to beat 7z. Especially if you're trying to be cross-platform...
I think WinRAR and XZ can beat it out in some use cases, but if your goal is compressing mindboggling amounts of text, it's hard to beat 7z. Especially if you're trying to be cross-platform because XZ is basically unheard of on Windows.
If anyone is trying to get their hands on the files and wants to know if they have the right stuff here are the sha256 checksums: 5d4ab848129e55042c5b6bd3f74a115b26472a184b0f4d0d4b0728e00e1d08ec...
If anyone is trying to get their hands on the files and wants to know if they have the right stuff here are the sha256 checksums:
I calculated these from the files I downloaded from the magnet link, and someone else who downloaded them from the original source (not the magnet link) also claims those hashes are correct.
I haven't had time to do a whole lot of data crunching yet as I'm having a wee bit of trouble working with 276 GB of data, but I count 272,541,507 distinct SSNs in 2,695,681,513 rows. That's 10% of rows with a unique SSN.
Curiously, that's quite different from Troy Hunt's estimate of 899M distinct SSNs.
I don't have the data myself and some of that seems beyond my capabilities to figure out without putting in a lot of effort, but I've often just assumed my SSN is already in all of this, even...
I don't have the data myself and some of that seems beyond my capabilities to figure out without putting in a lot of effort, but I've often just assumed my SSN is already in all of this, even though I checked that npd.pentester.com site and didn't see myself in there.
I think I'll find it a little more interesting if it turns out things like driver's license numbers and such are more private than SSNs, because I rarely have to give out my DLN, but frequently have to use my SSN.
The US population is ~333M and with 273M distinct SSNs in the dataset (some unknown number of which are for deceased individuals) there's decent odds that any given person isn't in there. There's...
The US population is ~333M and with 273M distinct SSNs in the dataset (some unknown number of which are for deceased individuals) there's decent odds that any given person isn't in there. There's also definitely some garbage data in the dataset, so there's some unknown percentage of those SSNs that are just wrong. But yeah, this breach is quite large.
In a twisted way I was actually hoping this breach would be larger, because we really need something to get companies to stop using SSN as an ID number when it was never built to be secure. CGP Grey has a video on this topic that while 7 years old is still accurate https://www.youtube.com/watch?v=Erp8IAUouus
Question for the crowd: what are the current best practices for people whose data has been breached? I was just notified that I was included in a major breach (not this one) that included...
Question for the crowd: what are the current best practices for people whose data has been breached?
I was just notified that I was included in a major breach (not this one) that included significant amounts of my personal information. I'm just going to go ahead and assume I'm included in this one as well.
What should I be doing, if anything? It's frustrating that my data gets leaked from companies I've never even heard of nor done any sort of direct business with, and the most I get from them is "oops!"
The author mentions a tweet in the writeup:
The database DOES NOT contain information from individuals who use data opt-out services. Every person who used some sort of data opt-out service was not present.
My view of opt-out companies is that they're pretty scummy and that I'm basically increasing my attack surface by turning over personal information to yet ANOTHER company. Am I wrong? If they actually work then are they something I should look into paying for?
Also, while looking up info, I found this list of data breaches from the US Department of Health and Human Services. It looks like it's only healthcare related ones? Still, the amount of them is genuinely staggering. I had no idea it was this bad.
Freeze your credit if it isn't already. You'll need to go to each of the big three and request it. It is free. If needed, you can temporarily unfreeze it for a timed period. Going forward,...
Freeze your credit if it isn't already. You'll need to go to each of the big three and request it. It is free. If needed, you can temporarily unfreeze it for a timed period.
Going forward, consider how this info could be linked to security questions with respect to password resets and account access. Also be vigilant for scams that can leverage this info to try and make themselves seem more legitimate.
I'm sure there's more but that's what I've got off the top of my head.
Security questions are accessory passwords which the managing entity has encouraged you to make insecure. Treat them as passwords: generate long, random values and store them in a password...
consider how this info could be linked to security questions
Security questions are accessory passwords which the managing entity has encouraged you to make insecure. Treat them as passwords: generate long, random values and store them in a password manager. (In particular, the value you enter for a security question should absolutely never be an answer to that question.)
Yes, my mother's maiden name is "99BppyiprbOXfk1Yoyhcnamjh0LDirw6", thank you very much for asking.
I've stopped doing this because on two occasions I've had phone support staff say something to the effect of "it looks like there's something wrong with your security questions so I'll skip them...
I've stopped doing this because on two occasions I've had phone support staff say something to the effect of "it looks like there's something wrong with your security questions so I'll skip them for this call". One of them even asked if I wanted to "fix" it right then.
So now what I do is generate fake and obscure but plausible answers to these questions. First pets name? Bojangleboy. Favorite teacher? Mrs. Tornicholson. Etc.
I mean if the support staff can change it right then and there, while it might be more secure to make more plausible sounding answers, it still seems like it's incredibly susceptible to social...
I mean if the support staff can change it right then and there, while it might be more secure to make more plausible sounding answers, it still seems like it's incredibly susceptible to social engineering. The plausible answers just might make it so that it's a little harder to social engineer a support staff, but that's just downright horrible training and security in place for those companies. If that's how they operate, then I don't know if there's anything you could do that would change a relatively skilled person in social engineering from duping them into giving them access to your account.
I guess if they're not offering to 'fix' it right then and there without doing anything more to verify your identity and they're just using it as an extra check to know you're the account holder, that in itself isn't the worst in the world and it does highlight that using randomized passwords of characters, symbols etc. is a little problematic but at that point just using randomly generated sequences of words that can be pronounced would alleviate that, even if they don't look like plausible or real answers. It would at least allow you to answer a question verbally more easily than the random characters and symbols. It would still require the staff to have proper training and not have the ability to just change answers without actually having followed proper procedures.
Perhaps a better approach would be to use a non-sensical but readable answer? Something like "Where was your father born? Betelgeuse" OR "What was your elementary school mascot? The Aasgard...
I've stopped doing this because on two occasions I've had phone support staff say
Perhaps a better approach would be to use a non-sensical but readable answer? Something like "Where was your father born? Betelgeuse" OR "What was your elementary school mascot? The Aasgard Aardvarks".
"Real" answers, that someone can read and pronounce, but that no one would guess as a factual answer.
I personally have frozen my credit reports so they can't be used maliciously, and I've also looked at the final dates for voter registration should I be unregistered from the voting pool.
I personally have frozen my credit reports so they can't be used maliciously, and I've also looked at the final dates for voter registration should I be unregistered from the voting pool.
Update, for anyone curious: Using the Pentester site, I learned that I'm also included in this breach. It only had two of my previous addresses -- everywhere else I lived was missing. It,...
Update, for anyone curious:
Using the Pentester site, I learned that I'm also included in this breach. It only had two of my previous addresses -- everywhere else I lived was missing. It, surprisingly, did not have my husband's information at all.
I made accounts in order to freeze my credit at Equifax, Experian, and TransUnion. After being burned before, I now use 1Password and Fastmail to generate masked email addresses for new accounts that forward to my main email address.
I'm thinking that Equifax and TransUnion didn't like this. Both of them let me go through the sign-up process but then told me that I needed to call customer support. Equifax didn't say why, but TransUnion told me that I'd failed the identity verification.
Experian let me sign up fully. They have an easy to use but hard to find credit freeze toggle on the site. Everything else on the site is an upsell to try to get you to sign up for a subscription service for credit monitoring/identity protection, and I had to browse around a bit before I actually found the freeze option buried in text under some other option they were trying to sell me.
I've currently been on hold with Equifax for 45 minutes. No telling when I'll actually get to speak to someone. I'm thinking their "currently experiencing unexpectedly high call volume" disclaimer might actually be true, as even their website is non-responsive. They might be getting slammed in the wake of this breach. I'm at the sunk-cost part of being on hold where I've been on this long enough that I don't want to walk away, but I don't want to waste my time by waiting even longer -- potentially over an hour.
The worst part is that once I do finally get through, I get to call TransUnion and do the same thing all over again.
I appreciate the tip from @Carrow and @whbboyd about security question answers. I had my password generator create random strings for me, so the high school I went to/the first street I lived on is something like "CULVERT runny smiles ARCHIPELAGO."
Additional update: TransUnion's phone support opens an hour earlier than Equifax's. So I called TransUnion first, right when they opened. They gave me the obligatory "unexpectedly high call...
Additional update:
TransUnion's phone support opens an hour earlier than Equifax's.
So I called TransUnion first, right when they opened. They gave me the obligatory "unexpectedly high call volume" disclaimer that I assume is just an automatic part of any call service script now, but they also gave me the option to receive a callback instead of waiting on hold, which is a great convenience. I was entering my callback number when I was put through to an agent. He confirmed some information with me and then unlocked my account. Took less than five minutes.
I then called Equifax right when they opened. Same "high call volume" disclaimer, which, again, is hard to believe when your phone lines have been open for all of a minute. Their hold has no quality of life features: no offer for a callback, no notification of your place in line -- you simply listen to the same music loop and have an automated voice tell you that all their agents are busy at the moment. I spent an hour on hold yesterday before hanging up, but thankfully(?) this morning the hold was only ten minutes(!).
The Equifax rep didn't actually confirm any information with me (although the automated system before had asked me for a lot of my identifying information) -- he simply asked me if I used a VPN with the account. I normally do use a VPN, but I had turned it off before signing up yesterday because I figured it would probably flag me as fraudulent. I told him I didn't, and he said okay and then asked me to login, which I was able to do.
For both TransUnion and Equifax it seems like there was some automated block on my account that a human had to clear. I assume it's because I used an email address separate from my regular one, and their automated "is this person who they say they are?" check failed. I could be wrong though -- that's just supposition on my part. I also forgot to turn off uBlock Origin so maybe the lack of trackers pinged for them. Or it could be because I was signing on on Linux. Or it could be I was just unlucky? Or maybe it's because I was included in the recent breach so they had additional safeguards on people signing up with that information? I don't know.
Freezing credit:
With regards to freezing, both TransUnion and Equifax have simple dashboards that make finding the freeze option very easy. I can second @ebonGavia's experience with Experian though. They are quite scummy, with lots of dark patterns to try to get you to sign up for monetized services with them.
Here's how I currently can find the freeze option on Experian (there might be a better way but this is the best I can figure out at the moment, which says something about how bad it is):
Log in
Skip the upsell by clicking No, keep my current membership
Click Protection in the header
Click Experian credit file in the blue banner at the top of the page
A sidebar pops up with information about Experian CreditLock
Ignore all of that and look at the small text at the bottom that says Experian CreditLock is a separate service from security freeze.
Click the "security freeze" link, which takes you to the actual toggle.
The direct URL for that is this, which at present does take me directly to the freeze page after I log in. However, they also have this freeze page that does NOT take you to the freeze after you log in and instead dumps you on your dashboard.
On the other hand, one point in favor of Experian is that they were the only site of the three that seems to have 2FA (but only through SMS). I could not find that option for Equifax or TransUnion.
Conclusion:
As annoying as this whole process was, I'm glad I went through it and would recommend other people do it even if your data hasn't yet been breached.
In theory, if your signups don't get flagged like mine did, signing up and freezing your credit with the three main bureaus should only take five to ten minutes tops, with everything done online and no phone calls needed.
I saw a comment elsewhere that said something like "yes, it's a bit of a pain but it's WAY less of a pain than having to deal with everything that happens after someone does steal your identity" which helped me put things in perspective.
Additionally, the information I needed to make my accounts was, well, exactly the same information that was leaked: name, social, phone number, current zip code, numbers on my current address. The furthest confirmation any of them went was TransUnion, which asked me to confirm a previous address, but that information was, of course, also included in the leak, so someone easily could have passed that. In theory, someone could have made all these accounts in my name using now publicly available information, and I would be effectively helpless.
As such, I feel like a big part of this wasn't just freezing my credit but actually claiming those accounts in the first place. I do hate having to do that with companies that take and make money off of my data for free (especially one with a significant breach history). I also hate that all of them that have a vested financial interest in selling me "security" for my own data that I didn't choose for them to have in the first place. Still, I'm glad I control the accounts rather than finding out someone else was doing it in my name. It does feel a bit like I'm shaking hands with a demon so I don't have to do it with the actual devil though.
I went to this link many years ago https://www.usa.gov/credit-freeze Obviously it still exists and it is mostly the same as I remember, links to credit freeze for each credit bureau, except back...
Obviously it still exists and it is mostly the same as I remember, links to credit freeze for each credit bureau, except back then they were direct links to the page and you didn't even have to make an account for them. They gave randomized numbers as your a pin code of sorts, or you could choose a pin code. It used to be that easy. I just checked each link now, Experian seems to be the worst as it takes you to what appears like a blog post. As you mentioned, you had a more direct link which works when logged in, but seemingly not otherwise, which tells me it's not just a government website where they don't update the links but rather Experian is just shady like that.
There was a story that came out a few years ago where all these credit bureaus seemingly changed their process to making accounts and some, or one of them at least, had left a backdoor in where someone like me who had previously frozen credit with just a pin could have had someone else bypass this by making an account. So I ended up going to each website and making an account.
I just double checked mine, and Transunion seems to do 2fa through email, because when I went to login they sent me an email with a 20 minute time sensitive 6 digit code.
My own experience is that Equifax is absolutely slammed, but TransUnion and Experian's websites let me get through setting up an account and freezing my credit easily this morning. I'll be trying...
My own experience is that Equifax is absolutely slammed, but TransUnion and Experian's websites let me get through setting up an account and freezing my credit easily this morning. I'll be trying Equifax's website again later, when it's hopefully eased up a bit.
I gave up on Equifax after an hour on hold. I then got hung up on in the middle of TransUnion's automated identity verification. I'm giving up on them for today and will call tomorrow when their...
I gave up on Equifax after an hour on hold. I then got hung up on in the middle of TransUnion's automated identity verification. I'm giving up on them for today and will call tomorrow when their support lines open.
Transunion's password reset system is down right now, which is fucking me up. Experian and Equifax I got in very quick to freeze. EDIT: It's back up, was easy after that.
Transunion's password reset system is down right now, which is fucking me up. Experian and Equifax I got in very quick to freeze.
One thing to keep in mind with the HHS list of breaches is the specific definition of breach. Because of the definition and rules around HIPAA it can be surprisingly easy to trigger a breach...
One thing to keep in mind with the HHS list of breaches is the specific definition of breach. Because of the definition and rules around HIPAA it can be surprisingly easy to trigger a breach through inadvertent disclosure that is unlikely to result in information being used maliciously. E.g., if a researcher at a covered entity sends an encrypted file of research data to a collaborator at a non-covered entity that inadvertently includes an identifier that should have been stripped out, it could qualify as a breach. In that case, the recipient would likely have a data use agreement in place, and would securely destroy the data they should not have received. It get's even more fraught when you have integrated EMR's with multiple data sources, where sometimes you pull data on a human subject, and it pulls from all sources instead of just the source you wanted, triggering a disclosure.
So not every breach means the data was publicly disclosed or taken by malicious parties, just that it was inadvertent.
With regard to the opt-out services, I use Incogni and Onerep, despite some of the criticisms they face. I find that Incogni targets behind-the-scenes brokers, such as employment data brokers, and Onerep targets more public people finder sites. I find that they work, though their necessity is annoying.
I know that every opt-out service comes packaged with discourse on whether it’s actually productive, but there’s a pretty substantive case to be wary of Onerep specifically, since its CEO is also...
In terms of alternatives, the particularly privacy minded/paranoid tend to favor a DIY approach, which has the additional benefit of being free, though it is a MASSIVE time sink.
I remember when the news came out about the founder of One rep possibly running people search sites. I would suggest people read the CEOs response to form their own take on the situation....
I remember when the news came out about the founder of One rep possibly running people search sites. I would suggest people read the CEOs response to form their own take on the situation.
Personally, I just don't want to spend the time manually opt-ing out of hundreds of portals. I've manually done it, and it isn't always as simple as that guide makes out. Many of the worst offenders at sharing your data make it difficult to opt out, or have broken or semi broken processes. The only information you need to provide the opt out services are permutations on your name, emails, and state (I think). It's less information than a paid Spotify account.
For what it's worth, searches on my name no longer shows any results other than my LinkedIn and I'm not getting could called at home or work from possible vendors, head hunters, etc, that I had been. And some of the removed profiles had comprehensive data on home and work contact information that wasn't publicly listed, but was being sold to marketers.
You can search the NPD leak for your info at Pentester. If you're in there, and you're concerned, freeze your credit. Edit: I see someone else already linked to Pentester but was wondering if...
You can search the NPD leak for your info at Pentester.
If you're in there, and you're concerned, freeze your credit.
Edit: I see someone else already linked to Pentester but was wondering if they're legit... yep, solid reputation afaik. Also they don't ask for anything too sensitive in order to do the search.
Thank you so much for sharing this. I was able to search through all of it, and only found ONE person who was breached. So I feel better, but I might still freeze my credit to be safe.
Thank you so much for sharing this. I was able to search through all of it, and only found ONE person who was breached. So I feel better, but I might still freeze my credit to be safe.
Reminder: be sure to check for the proper/full name! Someone I know goes by a nickname that's really close to their proper name (to the point people think it IS their name), so I searched that...
Reminder: be sure to check for the proper/full name! Someone I know goes by a nickname that's really close to their proper name (to the point people think it IS their name), so I searched that first out of habit before realizing and checking again. (Think: Matt and Matthew, John and Jonathon, Julie and Julia, etc.) This should be obvious, but when you're used to the short form it can throw you off.
What should someone do if they want to search this data but they have no idea what you are saying? Asking for myself.
Hey! Thank you for the information. Several news outlets are recommending https://npd.pentester.com/ I have never heard of the service and, thus, I am skeptical of it. Do you happen to be familiar with the site? If not, could you please check if a couple of the records leaked match the information showed by that site to at least confirm its validity?
Thanks for that site link. I figured I'd try it since it doesn't really require me to put anything personal in there (although at this point, for most people even personal information isn't personal anymore). I checked myself and a few others I know, and I wasn't in there my some other family members were.
Seconding for the data illiterate!
You should freeze your credit at all three major credit bureaus: Equifax, Experian, and Transunion. Nerd Wallet has a guide. The bureaus don't like to make it easy, and will try and get you to sign up for a paid membership, but keep declining and opting out of that stuff, as it isn't required. You will need (or should) make an account with each bureau and securely record your security questions and pin information so you can quickly add temporary "thaws" on your report for when you do need a "hard" credit check like to get approved for a loan or a credit card.
https://npd.pentester.com/search will let you do a search, no account or download shenanigans required.
Solid work with the script and analysis. The article mentioned the breach may include Canadian and UK data as well. Did any of your results look to show results in that vein, Canadian or UK formatted "social security" numbers for example?
Thanks for putting in the effort. That's not the method I'd have thought to use but sounds like a good one. It's useful that Canada Post and USPS have agreed to not use the same two letters (wikipedia info on the changes over time to make sure they don't overlap).
Have you tried throwing it in a database? It might take a bit of time to ingest the data, but SQLite with a handful of indexes should churn through searches like this without a problem. I’m at work right now, but I’ll be trying this when I get home.
Thanks for the links!
I wanted to share that I've found several false negatives between the search at Pentester and the actual leaked data. I can't say for sure, but I think that the pentester data might have been lightly deduped in a hurry, indexed wrong, or something. I've found it most reliable to search the raw data using current and former street addresses like "### North Street ST" as it would appear on your driver's license, bank, or credit reports. That seems to reliably catch cases where you have multiple people with the same name and address, etc. Not sure why social wouldn't disambiguate those cases in the pentester data, but I've had a few friends and family searches, get no hits, and then do a full search of the raw data and find records.
Was thinking of looking at the same files, any concern that the files could be a honeypot or similar?
They're just text files, so not from that part, but they're in 7z compressed archives, so theoretically someone could have private knowledge of a vulnerability that would affect anyone who opens or extracts them. I'd say that's unlikely, but we had something similar in xz recently...
It's not unreasonable to think, especially because 7z also had some security issue 2 years back: https://nvd.nist.gov/vuln/detail/cve-2022-29072
I decompressed the 7z archives using a pure-rust lzma implementation just to see if it would do anything unusual and for what it's worth it didn't. I don't think it's a 7z 0-day.
I think WinRAR and XZ can beat it out in some use cases, but if your goal is compressing mindboggling amounts of text, it's hard to beat 7z. Especially if you're trying to be cross-platform because XZ is basically unheard of on Windows.
If anyone is trying to get their hands on the files and wants to know if they have the right stuff here are the sha256 checksums:
I calculated these from the files I downloaded from the magnet link, and someone else who downloaded them from the original source (not the magnet link) also claims those hashes are correct.
I haven't had time to do a whole lot of data crunching yet as I'm having a wee bit of trouble working with 276 GB of data, but I count 272,541,507 distinct SSNs in 2,695,681,513 rows. That's 10% of rows with a unique SSN.
Curiously, that's quite different from Troy Hunt's estimate of 899M distinct SSNs.
I don't have the data myself and some of that seems beyond my capabilities to figure out without putting in a lot of effort, but I've often just assumed my SSN is already in all of this, even though I checked that npd.pentester.com site and didn't see myself in there.
I think I'll find it a little more interesting if it turns out things like driver's license numbers and such are more private than SSNs, because I rarely have to give out my DLN, but frequently have to use my SSN.
The US population is ~333M and with 273M distinct SSNs in the dataset (some unknown number of which are for deceased individuals) there's decent odds that any given person isn't in there. There's also definitely some garbage data in the dataset, so there's some unknown percentage of those SSNs that are just wrong. But yeah, this breach is quite large.
In a twisted way I was actually hoping this breach would be larger, because we really need something to get companies to stop using SSN as an ID number when it was never built to be secure. CGP Grey has a video on this topic that while 7 years old is still accurate https://www.youtube.com/watch?v=Erp8IAUouus
Question for the crowd: what are the current best practices for people whose data has been breached?
I was just notified that I was included in a major breach (not this one) that included significant amounts of my personal information. I'm just going to go ahead and assume I'm included in this one as well.
What should I be doing, if anything? It's frustrating that my data gets leaked from companies I've never even heard of nor done any sort of direct business with, and the most I get from them is "oops!"
The author mentions a tweet in the writeup:
My view of opt-out companies is that they're pretty scummy and that I'm basically increasing my attack surface by turning over personal information to yet ANOTHER company. Am I wrong? If they actually work then are they something I should look into paying for?
Also, while looking up info, I found this list of data breaches from the US Department of Health and Human Services. It looks like it's only healthcare related ones? Still, the amount of them is genuinely staggering. I had no idea it was this bad.
Freeze your credit if it isn't already. You'll need to go to each of the big three and request it. It is free. If needed, you can temporarily unfreeze it for a timed period.
Going forward, consider how this info could be linked to security questions with respect to password resets and account access. Also be vigilant for scams that can leverage this info to try and make themselves seem more legitimate.
I'm sure there's more but that's what I've got off the top of my head.
Security questions are accessory passwords which the managing entity has encouraged you to make insecure. Treat them as passwords: generate long, random values and store them in a password manager. (In particular, the value you enter for a security question should absolutely never be an answer to that question.)
Yes, my mother's maiden name is "99BppyiprbOXfk1Yoyhcnamjh0LDirw6", thank you very much for asking.
I've stopped doing this because on two occasions I've had phone support staff say something to the effect of "it looks like there's something wrong with your security questions so I'll skip them for this call". One of them even asked if I wanted to "fix" it right then.
So now what I do is generate fake and obscure but plausible answers to these questions. First pets name? Bojangleboy. Favorite teacher? Mrs. Tornicholson. Etc.
I mean if the support staff can change it right then and there, while it might be more secure to make more plausible sounding answers, it still seems like it's incredibly susceptible to social engineering. The plausible answers just might make it so that it's a little harder to social engineer a support staff, but that's just downright horrible training and security in place for those companies. If that's how they operate, then I don't know if there's anything you could do that would change a relatively skilled person in social engineering from duping them into giving them access to your account.
I guess if they're not offering to 'fix' it right then and there without doing anything more to verify your identity and they're just using it as an extra check to know you're the account holder, that in itself isn't the worst in the world and it does highlight that using randomized passwords of characters, symbols etc. is a little problematic but at that point just using randomly generated sequences of words that can be pronounced would alleviate that, even if they don't look like plausible or real answers. It would at least allow you to answer a question verbally more easily than the random characters and symbols. It would still require the staff to have proper training and not have the ability to just change answers without actually having followed proper procedures.
Perhaps a better approach would be to use a non-sensical but readable answer? Something like "Where was your father born? Betelgeuse" OR "What was your elementary school mascot? The Aasgard Aardvarks".
"Real" answers, that someone can read and pronounce, but that no one would guess as a factual answer.
Do you use unique answers for each different service? If not, isn't this basically the same risk if your data gets leaked somewhere?
Yeah a new one is made up on the spot every time and saved back into my password manager for that particular service.
I have been grabbing a phrase from a pdf on my computer or wikipedia page for my answers to security questions. It all goes into my keepass file.
I personally have frozen my credit reports so they can't be used maliciously, and I've also looked at the final dates for voter registration should I be unregistered from the voting pool.
Update, for anyone curious:
Using the Pentester site, I learned that I'm also included in this breach. It only had two of my previous addresses -- everywhere else I lived was missing. It, surprisingly, did not have my husband's information at all.
I made accounts in order to freeze my credit at Equifax, Experian, and TransUnion. After being burned before, I now use 1Password and Fastmail to generate masked email addresses for new accounts that forward to my main email address.
I'm thinking that Equifax and TransUnion didn't like this. Both of them let me go through the sign-up process but then told me that I needed to call customer support. Equifax didn't say why, but TransUnion told me that I'd failed the identity verification.
Experian let me sign up fully. They have an easy to use but hard to find credit freeze toggle on the site. Everything else on the site is an upsell to try to get you to sign up for a subscription service for credit monitoring/identity protection, and I had to browse around a bit before I actually found the freeze option buried in text under some other option they were trying to sell me.
I've currently been on hold with Equifax for 45 minutes. No telling when I'll actually get to speak to someone. I'm thinking their "currently experiencing unexpectedly high call volume" disclaimer might actually be true, as even their website is non-responsive. They might be getting slammed in the wake of this breach. I'm at the sunk-cost part of being on hold where I've been on this long enough that I don't want to walk away, but I don't want to waste my time by waiting even longer -- potentially over an hour.
The worst part is that once I do finally get through, I get to call TransUnion and do the same thing all over again.
I appreciate the tip from @Carrow and @whbboyd about security question answers. I had my password generator create random strings for me, so the high school I went to/the first street I lived on is something like "CULVERT runny smiles ARCHIPELAGO."
Additional update:
TransUnion's phone support opens an hour earlier than Equifax's.
So I called TransUnion first, right when they opened. They gave me the obligatory "unexpectedly high call volume" disclaimer that I assume is just an automatic part of any call service script now, but they also gave me the option to receive a callback instead of waiting on hold, which is a great convenience. I was entering my callback number when I was put through to an agent. He confirmed some information with me and then unlocked my account. Took less than five minutes.
I then called Equifax right when they opened. Same "high call volume" disclaimer, which, again, is hard to believe when your phone lines have been open for all of a minute. Their hold has no quality of life features: no offer for a callback, no notification of your place in line -- you simply listen to the same music loop and have an automated voice tell you that all their agents are busy at the moment. I spent an hour on hold yesterday before hanging up, but thankfully(?) this morning the hold was only ten minutes(!).
The Equifax rep didn't actually confirm any information with me (although the automated system before had asked me for a lot of my identifying information) -- he simply asked me if I used a VPN with the account. I normally do use a VPN, but I had turned it off before signing up yesterday because I figured it would probably flag me as fraudulent. I told him I didn't, and he said okay and then asked me to login, which I was able to do.
For both TransUnion and Equifax it seems like there was some automated block on my account that a human had to clear. I assume it's because I used an email address separate from my regular one, and their automated "is this person who they say they are?" check failed. I could be wrong though -- that's just supposition on my part. I also forgot to turn off uBlock Origin so maybe the lack of trackers pinged for them. Or it could be because I was signing on on Linux. Or it could be I was just unlucky? Or maybe it's because I was included in the recent breach so they had additional safeguards on people signing up with that information? I don't know.
Freezing credit:
With regards to freezing, both TransUnion and Equifax have simple dashboards that make finding the freeze option very easy. I can second @ebonGavia's experience with Experian though. They are quite scummy, with lots of dark patterns to try to get you to sign up for monetized services with them.
Here's how I currently can find the freeze option on Experian (there might be a better way but this is the best I can figure out at the moment, which says something about how bad it is):
No, keep my current membershipProtectionin the headerExperian credit filein the blue banner at the top of the pageExperian CreditLock is a separate service from security freeze.The direct URL for that is this, which at present does take me directly to the freeze page after I log in. However, they also have this freeze page that does NOT take you to the freeze after you log in and instead dumps you on your dashboard.
On the other hand, one point in favor of Experian is that they were the only site of the three that seems to have 2FA (but only through SMS). I could not find that option for Equifax or TransUnion.
Conclusion:
As annoying as this whole process was, I'm glad I went through it and would recommend other people do it even if your data hasn't yet been breached.
In theory, if your signups don't get flagged like mine did, signing up and freezing your credit with the three main bureaus should only take five to ten minutes tops, with everything done online and no phone calls needed.
I saw a comment elsewhere that said something like "yes, it's a bit of a pain but it's WAY less of a pain than having to deal with everything that happens after someone does steal your identity" which helped me put things in perspective.
Additionally, the information I needed to make my accounts was, well, exactly the same information that was leaked: name, social, phone number, current zip code, numbers on my current address. The furthest confirmation any of them went was TransUnion, which asked me to confirm a previous address, but that information was, of course, also included in the leak, so someone easily could have passed that. In theory, someone could have made all these accounts in my name using now publicly available information, and I would be effectively helpless.
As such, I feel like a big part of this wasn't just freezing my credit but actually claiming those accounts in the first place. I do hate having to do that with companies that take and make money off of my data for free (especially one with a significant breach history). I also hate that all of them that have a vested financial interest in selling me "security" for my own data that I didn't choose for them to have in the first place. Still, I'm glad I control the accounts rather than finding out someone else was doing it in my name. It does feel a bit like I'm shaking hands with a demon so I don't have to do it with the actual devil though.
I went to this link many years ago
https://www.usa.gov/credit-freeze
Obviously it still exists and it is mostly the same as I remember, links to credit freeze for each credit bureau, except back then they were direct links to the page and you didn't even have to make an account for them. They gave randomized numbers as your a pin code of sorts, or you could choose a pin code. It used to be that easy. I just checked each link now, Experian seems to be the worst as it takes you to what appears like a blog post. As you mentioned, you had a more direct link which works when logged in, but seemingly not otherwise, which tells me it's not just a government website where they don't update the links but rather Experian is just shady like that.
There was a story that came out a few years ago where all these credit bureaus seemingly changed their process to making accounts and some, or one of them at least, had left a backdoor in where someone like me who had previously frozen credit with just a pin could have had someone else bypass this by making an account. So I ended up going to each website and making an account.
I just double checked mine, and Transunion seems to do 2fa through email, because when I went to login they sent me an email with a 20 minute time sensitive 6 digit code.
But yeah, Equifax has no 2fa as you mentioned.
Experian's website is so fucking scammy and shitty. It's unbelievable.
My own experience is that Equifax is absolutely slammed, but TransUnion and Experian's websites let me get through setting up an account and freezing my credit easily this morning. I'll be trying Equifax's website again later, when it's hopefully eased up a bit.
I gave up on Equifax after an hour on hold. I then got hung up on in the middle of TransUnion's automated identity verification. I'm giving up on them for today and will call tomorrow when their support lines open.
Transunion's password reset system is down right now, which is fucking me up. Experian and Equifax I got in very quick to freeze.
EDIT: It's back up, was easy after that.
One thing to keep in mind with the HHS list of breaches is the specific definition of breach. Because of the definition and rules around HIPAA it can be surprisingly easy to trigger a breach through inadvertent disclosure that is unlikely to result in information being used maliciously. E.g., if a researcher at a covered entity sends an encrypted file of research data to a collaborator at a non-covered entity that inadvertently includes an identifier that should have been stripped out, it could qualify as a breach. In that case, the recipient would likely have a data use agreement in place, and would securely destroy the data they should not have received. It get's even more fraught when you have integrated EMR's with multiple data sources, where sometimes you pull data on a human subject, and it pulls from all sources instead of just the source you wanted, triggering a disclosure.
So not every breach means the data was publicly disclosed or taken by malicious parties, just that it was inadvertent.
With regard to the opt-out services, I use Incogni and Onerep, despite some of the criticisms they face. I find that Incogni targets behind-the-scenes brokers, such as employment data brokers, and Onerep targets more public people finder sites. I find that they work, though their necessity is annoying.
I know that every opt-out service comes packaged with discourse on whether it’s actually productive, but there’s a pretty substantive case to be wary of Onerep specifically, since its CEO is also the founder of several people search companies which expose personal information.
In terms of alternatives, the particularly privacy minded/paranoid tend to favor a DIY approach, which has the additional benefit of being free, though it is a MASSIVE time sink.
The “gold standard” for this approach is the Extreme Privacy opt-out workbook
though I’ve also seen shorter lists for the less paranoid such as here:
https://github.com/yaelwrites/Big-Ass-Data-Broker-Opt-Out-List?tab=readme-ov-file
Which also has a Consumer Reports on opt out services report on other opt out services if you didn’t want to go through that list yourself.
I remember when the news came out about the founder of One rep possibly running people search sites. I would suggest people read the CEOs response to form their own take on the situation.
Personally, I just don't want to spend the time manually opt-ing out of hundreds of portals. I've manually done it, and it isn't always as simple as that guide makes out. Many of the worst offenders at sharing your data make it difficult to opt out, or have broken or semi broken processes. The only information you need to provide the opt out services are permutations on your name, emails, and state (I think). It's less information than a paid Spotify account.
For what it's worth, searches on my name no longer shows any results other than my LinkedIn and I'm not getting could called at home or work from possible vendors, head hunters, etc, that I had been. And some of the removed profiles had comprehensive data on home and work contact information that wasn't publicly listed, but was being sold to marketers.
So for me they are worth it.
You can search the NPD leak for your info at Pentester.
If you're in there, and you're concerned, freeze your credit.
Edit: I see someone else already linked to Pentester but was wondering if they're legit... yep, solid reputation afaik. Also they don't ask for anything too sensitive in order to do the search.
Thank you so much for sharing this. I was able to search through all of it, and only found ONE person who was breached. So I feel better, but I might still freeze my credit to be safe.
Reminder: be sure to check for the proper/full name! Someone I know goes by a nickname that's really close to their proper name (to the point people think it IS their name), so I searched that first out of habit before realizing and checking again. (Think: Matt and Matthew, John and Jonathon, Julie and Julia, etc.) This should be obvious, but when you're used to the short form it can throw you off.
Funny, Pentester doesn't let you search APO.