The news just keeps getting worse for Equifax. The company has already had to revise their estimates of how many people were impacted by last year’s breach more than once, and now, they’re having to revise their estimate yet again. This latest revision comes after company officials had to testify before Congress, which has been formally investigating the matter.
Prior to the release of Equifax’s latest “statement of record,” here’s a snapshot of how bad the data breach was:
5 million consumers had their Social Security numbers compromised
99 million consumers had address information exposed
3 million consumers had gender information exposed
3 million consumers had their phone numbers exposed
209,000 consumers had their credit card numbers exposed
97,500 consumers had their Tax Identification numbers exposed
Now, in addition to all of that, the company is adding the following:
6 million consumers had their driver’s license numbers exposed
12,000 had their Social Security and Taxpayer ID cards exposed
3200 consumers had their passports exposed
An additional 3000 had other documents, such as military and state ID’s compromised
As bad as it looks that the company has to keep revising their estimates upward, there’s a logical reason for it. The data that was stolen didn’t come from a single database. On top of that, the databases themselves all had highly variable structures, which has made it exceedingly difficult for forensic analysts to accurately assess the extent of the damage. All that to say, since the process is still ongoing, we may see yet another upward revision of the scope and scale of the breach.
Of course, the company is doing what most companies do in cases like these: They’re offering a year’s worth of free credit monitoring to impacted customers. The ironic part of their offer though, is the fact that Equifax is offering their own credit monitoring service free for a year, which converts to a paid monitoring service after the year is up. As Congressional officials rightly pointed out, this means that the company is essentially profiting off of its own breach, which is disturbing to say the least.
Security researchers at the Electronic Frontier Foundation (EFF) have discovered a dangerous new email vulnerability called “Efail.” Exploiting this new email vulnerability would allow hackers to decrypt emails encrypted with either PGP or S/MIME – including emails that were sent several years earlier. Both of these encryption tools are commonly used by politicians, journalists and other professionals who need a secure means of electronic communication. Since the standards are so well established, they’re used widely and regarded as fool-proof. Sadly, that’s no longer the case.
Big changes are in the works in the SSD-based storage ecosystem. It includes three different vendors all making similar announcements regarding designs to help companies that rely on SSD-based storage systems to reduce duplication and control data creep.
Brinker International (the parent company of the Chili’s restaurant chain) formally announced that on May 11, they discovered malware on an undisclosed number of their point of sales terminals. Details are sketchy at this point, because the investigation is still ongoing, but the company had the following to say about the incident:
An identity threat company called 4iQ has recently published a report called “Identities in the Wild: The Tsunami of Breached Identities Continues.” Unfortunately, the information in the report contains all bad news. Some of the details are simply confirmations of things we already knew, and some are shocking statistics that will leave you feeling dismayed.
There’s a new security threat to be worried about, and security professionals are warning that it could be very bad indeed. The new malware is known as the “Vega Stealer,” and is currently being used in a relatively simplistic phishing campaign designed to harvest financial data that has been saved in both Google Chrome and Firefox browsers. Unfortunately, based on an analysis of the code, it could be a much more serious threat.
Depending on which side of the privacy debate you’re on, you’re either going to love or hate this announcement:
Hulu recently announced that it would join both Netflix and Amazon Prime in allowing its users to download content to watch offline, but in Hulu’s case, it comes with a twist.
In terms of toys, what could possibly be better than LEGOS? How about LEGOS, combined with Alexa? That’s the latest idea from Amazon, who has paired the unlikely duo in a newly announced service called “LEGO Duplo Stories.” The new service (“skill,” in the parlance of Alexa) will be available on any device that offers Alexa support including Echo Dot and Amazon Echo. It provides a selection of stories with audio prompts that guide children in the construction of something with their LEGO Duplos that ties in with the story being told.
Before Google released its Chrome browser, Firefox felt pretty good about their arrangement. They got a handsome reward in exchange for making Google.com their default search engine. It was a win-win.