Showing posts with label Credit bureau. Show all posts
Showing posts with label Credit bureau. Show all posts

Thursday, October 5, 2017

This Isn't A Joke: The IRS Just Hired Equifax To Safeguard Taxpayer Data

Just hours after Equifax CEO Rick Smith wrapped up his testimony before the House Energy and Commerce committee – the first in a series of Congressional “fact-finding missions” about the hack - Politico reported that the IRS last week awarded the disgraced credit monitoring bureau with a $7.25 no-bid contract even as the company struggled to address suspicions that it mislead investors and customers by withholding information about one of the most damaging data breaches in US history.


Equifax famously waited more than a month to disclose that hackers had infiltrated its servers and absconded with the sensitive financial information of more than 140 million customers, sparking widespread outrage that only intensified after reporters discovered that several of the company’s senior executives – including its CFO – cashed out of shares and options in the weeks before the company came clean about the hack.



According to the terms of the IRS contract, Equifax would be responsible for verifying taxpayer identities and help prevent fraud under a no-bid contract issued last week.


As if the IRS"s decision to entrust the disgraced credit bureau with sensitive taxpayer data wasn"t galling enough, the agency seemingly fast-tracked the contract by classifying it as a “sole source order” – a designation that allows the agency to circumvent the bidding process by claiming a given vendor is the only one capable of executing the contract. However, the agency"s justification for this designation is baffling, considering that there are two other credit bureaus in the US that offer a nearly identical suite of services.





The notice describes the contract as a "sole source order," meaning Equifax is the only company deemed capable of providing the service. It says the order was issued to prevent a lapse in identity checks while officials resolve a dispute over a separate contract.



Lawmakers from both parties demanded an explanation from the agency, which has endured several memorable data-security lapses – including a 2015 breach that exposed the sensitive financial information of more than 100,000 taxpayers.





Reps. Suzan DelBene (D-Wash.) and Earl Blumenauer (D-Ore.) separately penned letters to IRS Commissioner John Koskinen demanding he explain the agency"s rationale for awarding the contract to Equifax and provide information on any alternatives the agency considered. "I was initially under the impression that my staff was sharing a copy of the Onion, until I realized this story was, in fact, true," Blumenauer wrote.



Senate Finance Committee Chairman Orrin Hatch criticized the agency’s decision as “irresponsible.”





"In the wake of one of the most massive data breaches in a decade, it’s irresponsible for the IRS to turn over millions in taxpayer dollars to a company that has yet to offer a succinct answer on how at least 145 million Americans had personally identifiable information exposed," Senate Finance Chairman Orrin Hatch (R-Utah) told POLITICO in a statement.



Hatch raised concerns about the IRS’s cybersecurity practices in a letter sent to the agency’s head last month. To help the agency improve its data-security safeguards, Congress recently allocated $106.4 million to bolster the agency’s identity theft protections.





Hatch questioned the agency"s security systems in a letter to Koskinen last month. Hatch said he was concerned that the IRS lacked the technology necessary "to safeguard the integrity of our tax administration system."



Ron Wyden said the Finance Committee would seek to verify whether Equifax was really the only company capable of executing the contract, as the agency insisted.





The committee"s ranking member, Sen. Ron Wyden (D-Ore.), piled on: "The Finance Committee will be looking into why Equifax was the only company to apply for and be rewarded with this. I will continue to take every measure possible to prevent taxpayer data from being compromised as this arrangement moves forward.”



In defending its decision, the IRS claimed that Equifax said that none of its data was involved in the data breach.





The IRS defended its decision, saying Equifax has told the agency that none of its data was affected by the breach. The agency also noted that Equifax already provides “similar services” to the agency under a different contract.



"Following an internal review and an on-site visit with Equifax, the IRS believes the service Equifax provided does not pose a risk to IRS data or systems," the statement reads. "At this time, we have seen no indications of tax fraud related to the Equifax breach, but we will continue to closely monitor the situation."



Given that Equifax waited more than a month to disclose the hack to the public – and has bungled seemingly every step in its response to the hack - the fact that the IRS justified its decision by, in effect, saying "they told me everything is fine" is hardly reassuring. As Yahoo demonstrated just last night, the true scope of cyber-security intrusions sometimes takes years to uncover, which is precisely why sticking with Equifax is a risky. Yahoo, of course, revealed yesterday that a 2013 data breach impact all 3 billion of the company’s user accounts – three times the one billion accounts previously reported by the company.


As lawmakers have suggested, when determining which companies should be trusted to safeguard tax payers" most sensitive financial data, the agency should"ve erred on the side of caution.

Thursday, September 21, 2017

Equifax Accidentally Directs 200,000 Customers To Fake Phishing Website

And the hits just keep coming for Equifax, the once-trusted credit-monitoring firm that has been embroiled in one of the biggest corporate public-relations disasters in recent memory since disclosing that hackers had penetrated its cyber security defenses and absconded with sensitive personal and financial data belonging to 143 million Americans. Because of the types of data that were stolen, including drivers" license, social security and credit-card numbers, experts have described the hack as possibly the most damaging corporate hack yet.


As if this weren’t enough to permanently sully the firm’s reputation (amid cries of “you had one job!”) – the staggering irony of a credit monitoring firm inadvertently divulging the sensitive information that it was supposed to safeguard hasn’t been lost on consumers) a series of subsequent disclosures have portrayed the firm’s executives as bungling, at best, and nefarious, at worst.


In the nearly two weeks since the story broke…





  • It was revealed that three of the firm’s executives, including its CFO, cashed out of stocks and options worth some $2 million in the month between when the company first learned about the hack, and when it was disclosed to the public. A federal prosecutor in Atlanta has opened a criminal investigation into Equifax that will focus both on whether the firm was criminally negligent in failing to patch a hole in its cybersecurity systems, as well as whether the suspect stock sales constitute securities fraud.

  • The company’s head of cyber security was revealed to have no background in computer science or security – a fact the company tried to hastily cover up by scrubbing her social-media profiles. Susan Mauldin, Equifax’s chief information security officer, has a bachelor’s degree in music composition and a master’s in fine arts from the University of Georgia.

  • Several Congressional committees have asked the company to turn over information relating to the hack as multiple investigations appear to be getting under way. The attorneys general of a handful of states, including Massachusetts and Rhode Island, have joined a probe into the company’s handling of the breach.

  • The company has been hit with dozens of lawsuits from consumers alleging fraud, abuse and negligence.

  • Equifax CEO Rick Smith has been called to testify before a special House panel early next month.


When Equifax first set up a website to allow consumers to check whether their information was compromised, it carried a waiver stating that by using the service consumers would forfeit the right to sue Equifax. The internet quickly exploded in outrage, and the company quickly clarified that the waiver didn’t apply to this hacking incident, which…sure. Now, The Verge, The New York Times and a handful of other media outlets are reporting that Equifax accidentally tweeted the link to an imposter website set up by a white-hat hacker hoping to expose gllaring errors that the firm had made in setting up its verification website. This happened not once, but three times. And in at least one instance, the tweet with the phony link was left up for a whole day.



Here’s The Verge:





“Today, Equifax ended up creating that exact situation on Twitter. In a tweet to a potential victim, the credit bureau linked to securityequifax2017.com, instead of equifaxsecurity2017.com. It was an easy mistake to make, but the result sent the user to a site with no connection to Equifax itself. Equifax deleted the tweet shortly after this article was published, but it remained live for nearly 24 hours.”



Luckily for consumers, the fake site wasn’t malicious. Instead, it was set up by developer Nick Sweeting to try and expose the glaring security vulnerabilities that the company had embedded in its recovery website, which it set up as a separate domain, rather than making it a subdomain of Equifax’s main website.





“Luckily, the alternate URL Equifax sent the victim to isn’t malicious. Full-stack developer Nick Sweeting set up the misspelled phishing site in order to expose vulnerabilities that existed in Equifax"s response page. “I made the site because Equifax made a huge mistake by using a domain that doesn"t have any trust attached to it [as opposed to hosting it on equifax.com],” Sweeting tells The Verge. “It makes it ridiculously easy for scammers to come in and build clones — they can buy up dozens of domains, and typo-squat to get people to type in their info.”



Sweeting says no data will leave his page and that he "removed any risk of leaking data via network requests by redirecting them back to the user"s own computer," so hopefully data entered on his site is relatively safe. Still, Equifax"s team linked out to his page. That isn"t reassuring.”



Prior to Equifax customer service sharing the imposter site, Sweeting says he emailed the company’s support team and tweeted to Equifax that he spotted a potential vulnerability. By the time the site was taken down, Sweeting says it had received more than 200,000 hits. In the spirit of transparency, Sweeting included a disclaimer on his site warning consumers that it was a fake – and blasting Equifax for its sloppy security practices.


According to the NYT, phishers cannot create a page on the equifax.com domain, so if the website were hosted there instead, it would be easy for users to tell that the page was legitimate.





“Fortunately for the people who clicked, Mr. Sweeting’s website was upfront about what it was. The layout was the same as the real version, complete with an identical prompt at the top: “To enroll in complimentary identity theft protection and credit file monitoring, click here.” But a headline in large text differed: “Cybersecurity Incident & Important Consumer Information Which is Totally Fake, Why Did Equifax Use A Domain That’s So Easily Impersonated By Phishing Sites?”



The legitimate Equifax domain was securityequifax2017.com. Sweeting’s was equifaxsecurity2017.com. And as one cybersecurity expert told the NYT, even the legitimate website looks fake because it’s not a subdomain of the larger Equifax site.





“You would think that would be the obvious place to start,” said Rahul Telang, a professor of information systems at Carnegie Mellon University. “Create a subdomain so that if somebody tries to fake it, it becomes immediately obvious.”



The company’s actions, Telang told the NYT, suggest that it had never anticipated or planned for a breach.


This has become clear in the last few weeks. Now, the only thing left to be decided is whether the fact that the company was almost comically unprepared for a hack rises to the level of criminal negligence.

Thursday, August 31, 2017

Visualizing 5,000 Years Of Consumer Credit Growth

Consumer credit may seem like a fairly new invention – but, as Visual Capitalist"s Jeff Desjardins details below, it’s actually been around for more than 5,000 years!


In fact, many millennia before the credit score became ubiquitous, there is historical evidence that cultures around the world were borrowing for various reasons. From the writings in Hammurabi’s Code to the exchanges documented by the Ancient Romans, we know that credit was used for purposes such as getting enough silver to buy a property or for agricultural loans made to farmers.


CONSUMER CREDIT: 3,500 B.C. TO TODAY


In today’s infographic from Equifax, we look at the long history of consumer credit – everything from the earliest writings of antiquity to the modern credit boom that started in the 20th century.




Consumer credit has evolved considerably from the early days.


Over the course of several millennia, there have been credit booms, game-changing innovations, and even periods such as the Dark Ages when the practice of charging interest (also known as “usury”) was considered immoral by some people.


A TIMELINE OF CONSUMER CREDIT


Below is a timeline of the significant events that have helped lead to the modern consumer credit boom, in which Americans now have over $12.4 trillion borrowed through mortgages, credit cards, student loans, auto loans, and other types of credit.


THE ANCIENTS AND CREDIT


3,500 BC – Sumer
Sumer was the first urban civilization – with about 89% of its population living in cities. It is thought that here consumer loans, used for agricultural purposes, were first used.


1,800 BC – Babylon
The Code of Hammurabi was written, formalizing the first known laws around credit. Hammurabi established the maximum interest rates that could be used legally: 33.3% per year on loans of grain, and 20% per year on loans of silver. To be valid, loans had to be witnessed by a public official and recorded as a contract.


50 BC – The Roman Republic
Around this time, Cicero noted that his neighbor bought 625 acres of land for 11.5 million sesterces.


Did this person literally carry 11.5 tons of coins through the streets of Rome? No, it was done through credit and paper. Cicero writes “nomina facit, negotium conficit” – or, “he uses credit to complete the purchase”.


MORAL CONCERNS ABOUT LENDING


800 – The Dark Ages in Europe
After the collapse of the Western Roman Empire, economic activity grinded to a halt. The Church even banned usury, the practice of charging interest on loans, for all laymen under Charlemagne’s rule (768-814 AD).


1500 – The Age of Discovery
As European explorers and merchants begin trade missions to faraway lands, the need for capital and credit increases.


1545 – England
After the Reformation, the first country to establish a legal rate of interest was England in 1545 during the reign of Henry VIII. The rate was set at 10%.


1787 – England
Philosopher Jeremy Bentham writes a treatise called “A Defense of Usury”, arguing that restrictions on interest rates harm the ability to raise capital for innovation. If risky, new ventures cannot be funded, then growth becomes limited.


THE BIRTH OF MODERN CONSUMER CREDIT


1803 – England
Credit reporting itself originated in England in the early 19th century. The earliest available account is that of a group of English tailors that came together to swap information on customers who failed to settle their debts.


1826 – England
The Manchester Guardian Society is formed, and later begins issuing a monthly newsletter with information about people who fail to pay their debts.


1841 – New York
The Mercantile Agency is founded, and starts systemizing rumors about the character and assets held by debtors through a network of correspondents. Massive ledgers in New York City are made, though these reports were heavily subjective and biased.


1864 – New York
The Mercantile Agency is renamed the R. G. Dun and Company on the eve of the Civil War, and finalizes an alphanumeric system for tracking creditworthiness of companies that would remain in use until the twentieth century.


1899 – Atlanta
The Retail Credit Company was founded, and begins compiling an extensive list of creditworthy customers. Later on, the company would change its name to Equifax. Today, it is the oldest of the three major credit agencies today in the United States.


THE CONSUMER CREDIT BOOM


1908 – Detroit
Henry Ford’s Model T makes automobiles accessible to the “great multitude” of people, but they were still too expensive to buy with cash for most families.


1919 – Detroit
GM solves this problem by loaning consumers the money they need to buy a new car. General Motors Acceptance Corporation (GMAC) is founded and popularizes the idea of installment plan financing. Consumers can now get a new car with just a 35% downpayment at time of financing.


1930 – United States
By this time, efficient U.S. factories are pumping out cheaper consumer products and appliances. Following the lead of GM, now washing machines, furniture, refrigerators, phonographs, and radios can be bought on installment plans. It’s also worth noting that in this period, 2/3 of all autos are bought on installment plans.


THE FIRST IN BIG DATA


1950 – United States
By 1950, typical middle-class Americans already had revolving credit accounts at different merchants. Maintaining several different cards and monthly payments was inconvenient, and created a new opportunity.


At the same time, Diners Club introduces their charge card, which helps open the floodgates for other consumer credit products.


1955 – United States
Early credit reporters use millions of index cards, sorted in a massive filing system, to keep track of consumers around the country. To get the latest information, agencies would scour local newspapers for notices of arrests, promotions, marriages, and deaths, attaching this information to individual credit files.


1958 – United States
BankAmericard (now Visa) is “dropped” in Fresno, California. American Express and Mastercard soon follow, offering Americans general credit for a wide range of purchases.


1960 – United States
At a time when the technology was limited to filing cabinets, the postage meter, and the telephone, American credit bureaus issued 60 million credit reports in a single year.


1964– United States
The Association of Credit Bureaus in the U.S. conducts the first studies into the application of computer technologies to credit reporting. Accuracy of data is also improved around this time by standardizing credit application forms.


1970 – United States
The first Fair Credit Reporting Act is passed in the United States. It establishes a standard legal framework for credit reporting agencies.


1980s – United States
The three biggest credit bureaus attain universal coverage across the country.


1989 – United States
The FICO score is introduced, and quickly becomes a standard system to measure credit scores based on objective factors and data.


2006 – United States
VantageScore is created through a joint-venture between the top three credit scoring agencies. This new consumer credit-scoring model is used by 10% of the market, and 6 of the 10 largest banks use VantageScore.


MODERN CREDIT


The Information Age has enabled a new era in consumer credit and assessing risk – and today, credit reports are used to inform decisions about housing, employment, insurance, and the cost of utilities.


Learn more about how data, the internet, and modern computing is changing credit in Part 2 of this series.