Reported difficulties getting help on Equifax's phone lines
washingtonpost.com
washingtonpost.com
Suggestion, from https://www.reddit.com/r/personalfinance/comments/6yv4gb/off...
If you do nothing else, place an initial 90 day fraud alert on your file. This is free and will require lenders to contact you if someone (including yourself) tries to apply for credit. Government info. You only have to do this with one bureau in order for the alert to be placed on all three, and it should take less than 5 minutes:
Equifax https://www.alerts.equifax.com/AutoFraud_Online/jsp/fraudAle...
Experian https://www.experian.com/fraud/center.html
Transunion https://www.transunion.com/fraud-victim-resource/place-fraud...
Edit: Experian displays a grey screen that says "Loading"
Edit: TransUnion requires I set up an account.
Our system is currently unavailable
We are currently unable to add initial 90 day fraud alert or active duty alert to credit file online. Please try again later or click here to print a request form. If you need to install Adobe Acrobat click here
https://www.linkedin.com/pulse/settling-score-taking-down-eq...
These credit agencies have shown how archaic they're operating..
http://www.equifax.com/credit/fraud-alerts/&
3 Main Types of Alerts and Length of Effectiveness:
Initial Fraud Alert: 90 days
Active Duty Alert: 1 year
Extended Fraud Alert: 7 years
Extended Fraud Alert Request FormTo place an extended fraud alert on your credit file please send to Equifax – via Fax or US Mail - a valid police report, law enforcement agency report, or US Postal service report that allege mail theft. In addition, please provide a photocopy of one item from each of the categories below in order to verify your identification and address. The item you select from the identity category must contain your Social Security number and the item you select from the address category must contain your current mailing address.
Why do I need a police report when I have every major newspaper supporting my case?
On the other hand, the US Military does not take lightly misrepresentation of serving...
[0] https://www.reddit.com/r/personalfinance/comments/6zrwdd/soo...
https://www.experian.com/ncaconline/freeze
https://www.freeze.equifax.com/Freeze/jsp/SFF_PersonalIDInfo...
https://freeze.transunion.com/sf/securityFreeze/landingPage....
I bet millions of Americans, who are suddenly aware of their vulnerability to credit fraud and learning about these options, are paying for requests and freezes.
I take no action now. Scammer gets a $10k loan from BigBank using my info. I get the bill and report it as fraud. Write a few letters to clear it up (http://www.kalzumeus.com/2017/09/09/identity-theft-credit-re...). BigBank will be out $10k and is now motivated to figure out a better way to make loans.
For the others, I had to pay - Transunion and Experian - $5.00 each; ChexSystems and Innovis were free also.
[0] https://www.nytimes.com/2017/09/12/your-money/equifax-fee-wa...
Equifax link is dated 2008 and hijacks the back button (wtf)
TU is an account creation page
I've never heard of Innovis :)
Which is not snark at you for posting these links, just a sad commentary on these important pages.
The other sites are practically being DDoS'd by people trying to freeze their credit. Glad I did mine before it became a fad. :)
Curious whether there will be a measurable impact on new credit approvals as a result of this apparent mass freezing. Equifax's breach leading to second order effect of retail credit gumming up would piss off Equifax's actual clients in a big way.
The other thing I found confusing was that the website for doing this was different from the core Transunion website which was also different for Transunion's TrueIdentity website.
Overall, it's simply been confusing trying to figure out what steps to take and where/how to do them to abate negative effects of this data breach. It feels 'weird'/frustrating spending this amount of time/effort to fix issues which are due to someone else's laxity and when it seems like the responsible party is not doing as much but then I guess this is one sure and hard way to learn the lesson - you can't control what happens to you but you can control how you react to things.
I kinda feel sorry for the people in the trenches who had nothing to do with this. So much overtime and stress.
Anyhow, this doesn't excuse them, nor absolve them. I'm not sure if I'd have the moral fortitude to quit, where I just a peon there.
It is better to think from THEIR angle.
Equifax customer service reps are very poorly trained. The singular goal of all Equifax employees with whom I interacted was to make me Someone Else's Problem. To that end, they deployed several tactics:
* Telling me I'm calling the wrong Equifax customer service phone number
* Telling me I'm calling the wrong new Equifax customer service phone number
* Telling me to mail in just one more piece of identification
* Telling me they never received snail-mailed documents
* Telling me received snail-mailed documents "were not yet in the system" (over a week after receipt)
* Telling me to fax documents, not mail them
* Telling me the fax number I have is old, wrong, and no longer used
* Telling me the new fax number I have is old, wrong, and no longer used
* Telling me to call the bank providing my credit card, and get them to send my info to Equifax
* Mysteriously hanging up
* Again telling me the identification documents provided were insufficient
Finally I just sat on the phone for several hours with a customer service agent who had not yet discovered the complete lack of consequences for hanging up, asking what additional information would be provided by whatever additional piece of ID they were requesting. It escalated up the supervisor chain a few times, went on hold for half an hour, then I was just suddenly told the problem was taken care of and disconnected.
The problem wasn't taken care of, and the perpetual complimentary credit monitoring service subscription I have from some past data breach other another continued to fail its Equifax enrollment. Finally, a year, later, the problem fixed itself.
This company is trash.
I sometimes have a bad time with a call center but often I call a call center and get prompt and efficient service. If you tar them all with one brush, you are giving the bad ones a pass.
http://www.kalzumeus.com/2017/09/09/identity-theft-credit-re...
Rule #1 is never try to fix things over the phone. Do it in writing and keep a record of everything you send and receive.
All that was accomplished was that he placed an automated fraud alert, even though his original question was whether or not he was affected by the Equifax breach.
But be assured that their behaviour isn't much better towards the once paying them.
The only reason they talk to you, with overt disdain and reluctance, is the government says they have to.
They are trying to fix that.
I think you're misunderstanding these credit companies. We (american citizens) are not their customers, we are the product. The customers are the businesses who use them to lookup our credit.
Back to credit checks, the laws are a bit weird as well. Someone can simply pay their bills - phone, power, rent, and so on - on time for years and live within their means... and not be able to get good rates on loans and stuff because they have no credit. However, if they move and forget to pay their last electric bill from their old address, they'll suddenly have bad credit because it will be reported to the credit companies eventually. There is no requirement for the same places to report positives. Oh, and I might mention the actual scoring is a secret, though they'll give tips on improving it (like making sure to have a credit card and actually use it, have auto loans, and so on).
Their customers are other businesses - mainly banks/credit card companies/lenders as well as background checking services. They have no reason to provide customer service to individuals in their database - they are required to provide minimum services by law.
[1] Actually, now some offer "credit monitoring services" to individuals, which are a cash hog because these services are absurdly overpriced and kinda scammy.
Called the day after the news broke, and successfully setup a fraud alert on my account using a automated phone system in 3 minutes and 44 seconds.
So thrilled with this easy process, I call my Mom/Dad and instructed them to do the same.
About a day later I call again to do the same process for my wife. Got almost to the end (after giving them her SS#), but then something changed ... TransUnion started listing extensive documentation I had to snail mail to them - it took several minutes for this message to play out, after which I received no confirmation that the fraud alert was successfully activated. It seemed as though I was "kicked over" to the identify theft reporting line, because the documents they asked for seemed like something you would send to them, if your identify had already been stolen.
Called Experian immediately after, hoping their system might be working better. Their automated system failed to even start the process - I gave up.
Now my wife is convinced I gave her SS# to some random stranger. FML
TL;DR: TransUnion telephone fraud alert worked on Monday, but now is fucked.
When I got home, I then put freezes thru "the big three", then after reading a couple of articles, on Sunday I put freezes in with Innovis and ChexSystems. I also ran my credit report using TransUnion (leaving me with two more runs from the other two during the year).
That's basically all you can do. You can also do this, I suppose:
https://www.zanderins.com/idtheft2
I've read anecdotes saying that it's legit and good insurance (but LifeLock already offers a similar thing on the level I signed up for).
I guess part of what I am saying is that the story broke, and there was a small rush, but I got in - then when Monday rolled around and the story grew legs - well, we're now seeing DDOS-like failures...
This should be the default, for everyone, for free. If banks don't want to do the bare minimum to verify your identity, the liability for identity theft should be on them and not you.
The problem is using not-secret information as an authenticator.
Banks use a lot of information to correlate and verify customer identity. The process is called KYC, Know Your Customer [0]. The problem is that this process relies on exactly the information present in a database like Equifax's. If they did perform verification calls, they would be using the same information to verify your identity over the phone, meaning that anyone with that same information could still impersonate you.
The problem, as often pointed out, is that much of this information is much more akin to a username than a password, but is often used as the latter. I mean, someone with my drivers license has my name, address and date of birth, which is often enough to verify with most systems that don't keep SSNs.
From a technical perspective, modern cryptography would seem to give us some opportunity here. The downside here is that its usage becomes absolute -- you either have the key or you don't, regardless of the reality of your identity. The reality is that identity is a very hard problem, with many confounding issues.
1. The government would have to invalidate all SSN numbers and re-issue them.
2. To re-issue, you have to go down to a govt office to pick up a smart-card like device (let's call it a "multi-pass" for s&g's) that would have built into it a keypad and a fingerprint scanner.
3. This person would validate you as you (perhaps you present your driver's license/id/passport/birth certificate), and issue you one of these cards and a reader device (for home).
4. The card device itself would have a unique value embedded in it, but otherwise be "blank". Perhaps the government might also have a copy of this value matched to your other info, for tax purposes (so, it would act like your SSN for tax purposes and such).
5. This value would come from a one-time programming, where in front of the official, you would scan your fingerprint, and enter your pin. The card would hash everything together, and burn the hashed value into the card's read-only memory.
6. So now - to verify your identity, you would need: The card (something you have), the pin (something you know), and your fingerprint (something you are). If one of these isn't present, you can't identify yourself.
7. To do a transaction, you'd need to slot the card in to your reader (if at home doing something online), or into a vendor's or bank's reader - then put in your pin and scan your fingerprint. It'll hash the values again, and compare with what is on the card, and output (the only output, mind you) "yes" or "no" for the question of "identification".
The downside to all of this is that if you lose your card, or your fingerprint changes, or you forget your pin (or some combo), getting a new card will be tough. But really all it should take would be another in-person visit to the same govt office - more or less.
I also admit that there are very likely other glaring flaws with this idea (beyond the fact that it won't ever be implemented because of the costs to switch over, and other issues). But I think it comes close to a potential solution.
As long as you have to be physically present and always use a reader of some sort, if you don't have any one of the pieces of info, you can't verify your identity:
1) You need the card, if you don't have that - no dice of course.
2) You need the fingerprint that was originally used - that's only going to belong to the person who originally picked and configured the card at the govt office.
3) You need the pin number - presumably only known by the proper owner of the card.
So if the card is stolen, that doesn't matter. If they chop off your hand or finger, that won't help. They'd basically have to beat the pin code out of your, chop off your finger, and steal the card. I'm not saying there aren't criminals who would do that, but they'd have to be in the minority. Plus, such criminals are not likely id thieves anyhow.
* A private cryptography key. (Something you have)
* Which is PIN protected. (Something you know)
* With a photo on the front. (Something you are)
Of course, photo identification can't be easily replicated remotely. So remote use maybe only gives you two of the three.
Upside is that there's already existent card readers, along with all the infrastructure required to manage the cards and keys.
Less sarcastically, we need a political reformation focused on effective, pro citizen government, instead of politics focused on holding or reversing the status quo on divisive issues. So good luck.
Call your Representative.
It was never designed to be an ID Number and now that's how it is used. We should really go to a different system. I am not a security expert, but I think voting, paying taxes and credit scores would all be much easier than they are now.
Their entire operation is optimized to sell products and services to creditors, with no regard for actual consumers. They are a B2B company. They treat their employees poor, and their call center operations are outsourced to third party firms on a cost-basis whom are poorly trained and purely exist to field consumer contacts as required by law, but not actually resolve any issues.
I truly believe credit reporting agencies need to be heavily regulated and operated as a non-profit consumer institution, similar to the BBB.
While they might be a non-profit, that doesn't mean they aren't still looking for money.
In particular, it's well known that businesses who pay money to the BBB tend to receive a better overall rating score. And conversely, businesses who refuse to pay the BBB tend to have their scores go down.
See: https://en.wikipedia.org/wiki/Better_Business_Bureau#Critici...
https://news.ycombinator.com/newsguidelines.html
In this case I suspect the mods agreed with 'XR0CSWV3h3kZWg that the given title wasn't very good (and not obscure in the intriguing sense, maybe whimsical sense). Personally I find the "I did x. This is what happened"-type quite click-baity. As an aside, I wonder how far one could go using only "this" as a filter for click-bait titles.
- Call membership number -> makes some noise and then hangs up
- Use their website that they promote in their automated messages -> when trying to set up an alert, it takes you to a loading page that does nothing (looking at the requests being made in the network tab, it fails to load bootstrap and then just sits there, I am able to download the script it fails to download)
- Call automated fraud number -> nothing happens after being transferred to their automated alert system, so I hung up -> called again and waited for a few minutes after being transferred to their automated alert system, finally a voice starts talking asking for info (a dark pattern if I've ever seen one). After going through the process, apparently my info wasn't correct, so they asked me to 'leave a voicemail' with my SSN and DOB, after providing that info, it said they couldn't save my info and to try again, then promptly hung up.
so haven't been able to set up a fraud alert yet
If enough people do that to make it a national issue, Equifax will at a minimum notice, and possibly go out of business (because no bank will work with them) sending a very strong message to everyone who deals with private data.
Anyone know how to start Viral Activism?
Consumers are no longer really customers of the banks, either. Their customers are businesses, investment houses and lenders. Sure, they write you a loan, but they really package it up and sell it off to a lending company. Depositors just provide banks with cash assets to invest.
That's what it would take for that to have any impact.
Different agents on different hotlines bounced him around.
After 30+ minutes, an automated system took his SSN and signed him for a trial. Sort of.
Because they kept getting disconnected from the system, they aren't sure if it actually worked.
Seems Equifax is using the "plug fingers in ears and scream la la la la la" method.
Not sure why you're getting downvoted here.
I have no idea either. Luckily it wasn't much, but maybe my tone was off.
It couldn't possibly be my assessment of the story- everyone else commented the same thing!
Maybe the site wants those sweet sweet clicks and time on page metrics :)
"We finally got to a point where the system asked for our information in order to set up a 90-day alert. I provided my Social Security number, two phone numbers where I can be reached for verification, and a “please hold while we process your request” message."
What if someone who got a hold of another person's SSN call the number, and gave them a bogus number to contact? Any lender then tries to call the bogus number and they get a "YES, I ALLOW THAT TRANSACTION TO HAPPEN" brings more problems then.
Equifax could have made a system that performs this option and then it would be the person whose SSN has been exposed to provide the authentic number which they can be reached at to alert them of any transaction happening with their SSN number being used.
To be fair, he didn't get the answer he was looking for, so this could have dragged on much longer if he persisted in the phone-only route. I actually would have preferred that instead.
Sounds like it's time for a new ISP. I get impatient with XS4ALL after more than a minute or two, but then they've been spoiling me with sub-minute answering times for years. They scored extremely well in ratings, I figured they went "well we can do a little less well and save some money". Still great service -- but to come back to your situation, 42 minutes is ridiculous. Snail mail is faster at that point.
... I didn't click the link on principle.
Our system is currently unavailable We are currently unable to add initial 90 day fraud alert or active duty alert to credit file online. Please try again later or click here to print a request form. If you need to install Adobe Acrobat click here
Email your congressperson and complain. This works. It takes time and it takes a critical mass of complaints. Tweet your Congresspeople too.