Submit Your Claim in the Equifax Breach Settlement
equifaxbreachsettlement.com
equifaxbreachsettlement.com
After all this site links to the law firm JND, but nowhere does JND mention this site. So any of us could have made this site.
Use the form below to find out if your information was impacted and if you are a class member.
Last Name _______
Last 6 Digits of Social Security Number ________
Edit: As another commenter pointed out, this site is linked to from the FTC site about the breach.
This site is using godaddy presumably because the law firm also does, though they do use different certs!
https://www.ftc.gov/enforcement/cases-proceedings/refunds/eq...
>I just entered "Smith" and 6 digits. (Not real) I was eligible.
So either I'm a great last digit guesser (Though I'm usually not lucky in things like gambling....) I'll update my original comment.
If we assume every possible SSN could be handed out, a trailing six digit entry could have anywhere up to 999 possible SSNs, so you're firing out a shotgun with a pretty big number of potential targets each time you guess an SSN.
https://www.annualcreditreport.com/
https://www.optoutprescreen.com/
You can tell these two are legit because they are listed on official government sites:
https://www.ftc.gov/faq/consumer-protection/get-my-free-cred...
https://www.consumer.ftc.gov/articles/0262-stopping-unsolici...
However, I can see how some people wouldn't think to go through .gov sites and there's really nothing stopping me from registering a phishing site with a similar domain and hosting it in Russia or something to confuse people into using mine rather than the official one.
I think freecreditscore.com has been confused with annualcreditreport.com in the past. Freecreditscore.com is owned by Experian now and it actually does offer a real free no strings attached credit score NOW, but in the past it used to be one of those sites that tricked you into signing up for a subscription.
Then, of course, there was the Equifax data breach site that totally looked like a phishing site.
For example:
>OptOutPrescreen.com is a joint venture among Equifax Information Services, LLC, Experian Information Solutions, Inc., Innovis Data Solutions, Inc., and TransUnion, LLC (collectively the "Consumer Credit Reporting Companies").
>[annualcreditreport.com] is maintained by Central Source, LLC. Central Source, LLC is sponsored by Equifax, Experian and TransUnion so you have a single site where you can ask for all three of your free credit reports.
That site looks super sketchy.
I don't understand why companies do this. I completely understand that my health insurance is through "Empire Blue Cross Blue Shield" or whatever. So I expect to go to your corporate website and click "log in". If you think your website is so bad that it will damage your corporate brand... well maybe you should work on that.
If it's an SEO thing, that's also shady. If Bank A has "myonlinebillpay.com" and Bank B has "easyonlinebillpay.com"... how am I going to end up at the right one?
It makes me mad.
They had a virtual keyboard with only 16 choices of chars to type your password in on there at one point.
https://www.google.ca/amp/s/www.nytimes.com/2017/09/20/busin...
https://www.ftc.gov/enforcement/cases-proceedings/refunds/eq...
https://eligibility.equifaxbreachsettlement.com/en/eligibili...
It's not exactly the same, but work the same way.
I want Equifax as a company to be dissolved for incompetency with private data, and I want a way to legally opt out of other such companies collecting and aggregating private data about me.
this is what I want too at the end of the day.
Compare a desire to legally opt out (after checking a box, agreeing to a privacy policy you never read, having your data from 10 years ago - with a chain of custody/dispersal that's probably untenable, if not impossible, to map by now - synthesized by a third party) to GDPR's concept of consent:
"The key point is that all consent must be opt-in consent, ie a positive action or indication – there is no such thing as ‘opt-out consent’. Failure to opt out is not consent as it does not involve a clear affirmative act. You may not rely on silence, inactivity, default settings, pre-ticked boxes or your general terms and conditions, or seek to take advantage of inertia, inattention or default bias in any other way. All of these methods also involve ambiguity – and for consent to be valid it must be both unambiguous and affirmative. It must be clear that the individual deliberately and actively chose to consent."
Source: https://ico.org.uk/for-organisations/guide-to-data-protectio...
[0]: Until opt in becomes mandatory for use of critical services like having a bank account or paying your power bill.
When you take out a loan or credit card you sign a legal document agreeing to all of the various terms. You don't sign anything when visiting a website.
"It's a stretch to call something opt-in when it's unavoidable in modern life."It's also pretty much impossible to get through modern society without a credit card if you want to do anything crazy like, rent a car or reserve a hotel room.
I discuss issues with renting cars and hotel rooms in sibling threads.
It's no longer 2001, we live in the era of big data now.
I don't really understand why you are being defensive of bad practices and policies with the "nobody makes you sign up" argument. I never understand why people defend these things and blame the victims of them.
I'm not being defensive. I just honestly do not understand what point you are trying to make. I think that the things that you think are self evident are not self evident to me. Perhaps that is my failing. shrug
Now, it's nearly impossible unless you want a slumlord.
Maximum security deposits are set by the state. In my state it's illegal to require more than two months rent as a security deposit. Security deposit is defined by statute, you can't just call it "rent prepayment."
Even my last apartment required a cosigner because of my lack of credit history. I don't have any family to turn to so I had to rely on the family of someone else. Many people don't even have that good fortune.
Less directly, I was illegally evicted from my first apartment (3 days to move out over burst pipes in a multi-unit dwelling which caused our unit to flood) and due to not having the credit to get a loan to hire a lawyer to defend me against a clear cut case, I was blacklisted by my vengeful landlord and banned from renting anywhere in that city. Only lease I managed to get in that city after that was because I was friends with the leasing agent. I also lost hundreds of dollars in furniture including some vintage pieces due to getting only 3 days notice to vacate.
This set me back tremendously; as you can see it's a bit of a feedback loop between bad credit and bad rental experiences.
Wait, I think it's _disproof_ that relies on one _counter_ example. I guess it's easy to get confused.
Plus, all that being said, you can still do all those things without a credit card. It'll just be somewhat more complicated.
You certainly can't show up at a hotel and check in without a credit card at any hotel I'd consider stay at
You also can't rent a car from a major carrier without someone's credit card securing it
You can also definitely rent a car some some of the major carriers without a credit card. See: https://www.bankrate.com/personal-finance/smart-money/can-yo...
Definitely not all locations all the time (see: "somewhat more complicated").
With a credit card it's not money you intended to use so you don't care - unlike cash in your debit account.
Heading off a routine objection to this observation: I've had a family with kids since I was 22, and spent most of the years prior to the Matasano acquisition living, if not paycheck-to-paycheck, at least pretty close to it.
I'll add: I don't know what my credit score is now --- it's probably better than it was, since I've had that dumb car-renting card for 6+ years --- but, knowing that my credit was bad enough that I couldn't get a non-secured card, including from my own bank after the wires for the Matasano acquisition cleared, and knowing that I had at the time a house and a car and all that stuff, and really no trouble ever getting a lease for any place I could afford the rent for, I find myself wondering a lot how much credit scores actually matter. If I'd thought that when I was 22, I'd say, "welp, I just don't have enough life experience to know". But I'm 42 now, and I have a bit of a hard time projecting to a point where I can see a clear reason to give a shit what number Equifax generates for me. Like, maybe I'll care a lot when I'm 62? I kind of doubt it, though.
There are also people who are below the income line of paycheck-to-paycheck, people with addictions, people who have jobs or lives with risk of injury and thus medical bills or unpaid leave for recovery, people who have a big family with needs they have to pay or travel for... and I feel people can use CCs because rich people culture pressures them to cling to things and the idea of being "successful" to attract peers and love interests... but that's just my subjective analysis.
Booking travel online? All credit cards.
Renting a hotel or car can be next to impossible without a credit card to put down. Once I had to pay a $500 deposit to stay in a hotel for 1 night because I didn't have a credit card they could put on file.
It is absolutely not impossible to book a hotel room or rent a car without a credit card. This is a weird thing that HN seems to believe about consumer finance that has not all that much basis in reality. I book rooms exclusively on debit cards, and doubt there is really a hotel that will refuse to do that. You might not be able to book a car with Hertz, but who cares? Other major rental car companies take debit cards.
I'm not sure about the sentiment on HN, but I'm speaking from personal experience. Any time I've tried to use a Debit/Visa when checking into a hotel they've required me to pay a deposit that was returned on checkout.
Cash back and other rewards. They can add up if planned for properly—they aren't a life-changing amount of money or anything, but they're nice. Effectively, if you aren't using a high-fee card like American Express, you're subsidizing those of us who do use them (much to the chagrin of merchants). It's better to be on the receiving end of that subsidy, not the giving end.
> I find myself wondering a lot how much credit scores actually matter
Here's a well-sourced WaPo article on how credit scores affect mortgage rates: https://www.washingtonpost.com/news/get-there/wp/2016/11/17/...
That seems pretty reasonable.
What’s less reasonable is that you also have to participate in the system if you want a bank account or electricity or such. Or, heck, you don’t even need that; just have some fraudster open an account with your info and you’re in.
If a fraudster does something in your name, you can get things corrected. I agree that this can be more work than it should be, and would support regulations to make dealing with this easier.
You can get your info corrected if you’re the victim of fraud. Can you get it deleted entirely, such that the credit bureau has no record of you, as if you never existed? Or is participation in the system not actually voluntary at all?
If the data is required for providing the service, no consent is needed, but you must be able to clearly show that the data is indeed an absolute requirement to provide the service.
It's certainly a requirement if you don't want the interest rates on loans to be much higher.
Credit reporting is an immensely valuable institution, and a lot of that value gets passed down to borrowers.
The only thing that's in there outside of financial information is my name and a list of places I have lived.
I have to laugh a little at the naivete of thinking that a credit reporting company shows you everything they know about you on a credit report. They don't even show you everything they show loan companies who pull your report.
Subprime loan products already exist. They do typically run your credit, but they don't need to: the fact that you would pay for one says all that needs to be said. They're also typically offered under different branding from a respectable financial institution's loan products for people with good credit. An opt-in requirement for credit reporting only changes these basically cosmetic facts.
Better-than-worst-case credit history is immensely valuable. So valuable that a lender will cut you in on tens of thousands of dollars in savings for sharing it. Of all the things you could need opt-in consent for, it's an easy sell. Everyone would buy it. We'd be in the same position.
The problem is this also means you will be completely opting out of the credit system. No more morgtgages, no more credit cards, no more car loans.
I'm afraid it's kind of a necessary evil.
There is already a good number of lending options available to the many (millions?) of people disenfranchised from the traditional banking system. Usually that means offering strong collateral.
But the terms of those options aren’t too great because trustworthiness and risk have a strong negative correlation. And those who can prove their trustworthiness almost always prefer to do that rather than pay extra.
Isn't this the definition of a red flag? All you are is a profile to them so any unusual activity is going to draw scrutiny whether it's warranted or not. They have to do due diligence.
Finance isn’t the only area that uses reputation judge people. I imagine we’ve all been asked for references when applying for a job or an apartment. Jobs and apartments manage to get by without a centralized score.
Mortgages predate credit scores by centuries. It’s demonstrably not necessary.
As for getting a loan from a banker you’ve never met, my point exactly. They’re a convenient evil.
I want the system to be changed such that the burden of proof is on the lender that they actually interacted with the person they claimed they did. That is, if someone who is not you uses your information to get a credit card, then the bank loses their money for not following due diligence.
That's pretty much how credit card issuing goes, but the risk is not in someone stealing from a bank under your name, but rather your file now looking so bad that you can't legitimately get credit if you want it. I think what we want here is "the bank has to pay you money if they reject your credit card application / home loan because someone else hacked Equifax."
I doubt that will ever happen.
Yes, but under the new system, the bank can't just tell a credit reporting agency that a person they never interacted with failed to make a timely payment. If the bank can't prove beyond a reasonable doubt that they actually entered a contract with you, then they can't affect the actual person's credit rating.
What the actual F. Who does that?
Edit: also, no content security policy, no subresource integrity for 3rd party scripts. Is there such a thing as filing a class action against the party handling the class action? This is downright irresponsible.
Edit: I see a couple of the 3rd party scripts have integrity, but most don't.
Please correct me if my explanation of the parent comment is wrong here.
Note that many free credit monitoring services exist, and most credit cards nowadays have this feature available. These qualify you for the $125 payout.
Up to 10 hours effort ($250) can be claimed without documentation, for time spent battling or preventing ID theft. Preventing is probably key here, and could cover a lot of activities.
Yup. Reading news about the breach. Researching credit monitoring options. etc.
https://blog.legalist.com/i-won-8-000-from-equifax-in-small-...
an update about winning the appeal afterwards (edit: apparently they got it reduced to $5500):
https://blog.legalist.com/i-fought-equifaxs-lawyer-in-court-...
https://civilprocedure.uslegal.com/class-action/binding-natu...
It's mentioned in the FTC site.
Are they expecting very few people to file claims? Or what am I missing?
In the Canadian version of Equifax you can set how much of a score change send an email.
> If there are more than $31 million claims for Alternative Reimbursement Compensation, all payments for Alternative Reimbursement Compensation will be lowered and distributed on a proportional basis.
No one is going to get $125, we’ll maybe get $5–without doing the math.
That's just wild. Where's the rest of the money going?
1) It must be a third party service that you have entered into a business arrangement with, where the arrangement in clear and specific terms provides you with credit monitoring.
2) It must hold up in a court of law if challenged.
That second one is the anti-loophole provision of law, and protects against the kind of loopholes people try to find to get around the clear intent of the requirement.
You can choose to use any service that would hold up in a court of law. There are no clear answers on whether "any" service would. Time established, diversity of customers, active or inactive business, frequency of credit report inspection; all could be factors in a judicial evaluation of whether you complied with the terms or not. Capital One? Yes, they plausibly do offer credit monitoring as a service. Joe Bloe's Credit Woes? Entirely possible, if they've been around a while and can demonstrate that they pull credit reports on a regular basis and audit them in some manner.
Can you monitor it yourself? Only if you already operate a credit monitoring business. Otherwise, it'll fail the plausible test, and you lose your $125 + lawyer fees + risk angering a judge.
Significant other has mint, credit karma, different credit union, boa, cap one.
[1] https://www.reddit.com/r/personalfinance/comments/ch9tcj/cla...
"If a company handles people’s sensitive financial data, then I would like the CEO to be the type of person who wakes up in the morning thinking about security, goes to sleep at night thinking about security, and never has security far from their mind during the day. So to hire a security company, and then act as if security is a solved problem, is troubling. There are many other ways for a company to be hacked. Social engineering is a danger, and most company hacks are inside jobs. Hiring a firm such as ReliaQuest does not protect you from having one of your own employees steal data and sell it to the Russians. Protecting against internal attacks requires hard thinking by the top leadership of the company. The job can not be outsourced."
http://www.smashcompany.com/business/if-a-company-is-serious...
The lawyers are the real winner here.
if SSN/birthdate/name is gone, then anyone can fake me online, apply credit card under my name.
am I missing something? what was stolen from me?
so yes I can say I worried for 10+ hours and Equifax will pay me $250 no questions asked, but this is not exactly what I want to have.
This is scam
https://www.ftc.gov/enforcement/cases-proceedings/refunds/eq...
So I strongly doubt it is a scam.
Healthy paranoia :)