Yahoo Customer Data Security Breach Litigation Settlement
yahoodatabreachsettlement.com
yahoodatabreachsettlement.com
yahoodatabreachsettlement.com just looks scammy as hell. It's a pity there's not a .gov domain set up for this sort of thing - when there's a settlement, a court order gets issued for yahoo.settlements.gov to get set up.
From: info@service.comms.yahoo.net
Subject: Yahoo Security Breach Proposed Settlement
If you had a Yahoo account anytime in 2012 through 2016, a pending class action settlement may affect you.
A Class Action Settlement has been proposed in litigation against Yahoo! Inc. (“Yahoo”) and Aabaco Small Business, LLC (together, called “Defendants” in this notice), relating to data breaches (malicious actors got into system and personal data was taken) occurring in 2013 through 2016, as well as to data security intrusions (malicious actors got into system but no data appears to have been taken) occurring in early 2012 (collectively, the “Data Breaches”).
....
I know that. It makes me twitchy every time.
After the big Equifax breach, someone made a spoof site of their informational page, and Equifax themselves accidentally linked to it. (https://www.nytimes.com/2017/09/20/business/equifax-fake-web...)
> there doesn't seem to have been many issues before.
Again, sure. I'm surprised scammers haven't changed that yet.
Also FWIW the damage figures are also nonsense, how much can the equifax leak hurt anyone if their data was already for sale on ssndob? Almost all Americans have had their information compromised in hacks they’ve never heard of.
Am I wrong?
Source: my wife is an attny & worked at a top class-action firm for over a decade. Without breaking confidentiality, I still heard all kinds of interesting stories about the mechanics & internals of how the system works - how multiple firms work together, how cases are started, etc., but never anything remotely related to such a "targeted revenue" concept. Of course there's the obvious requirement that any case specify damages at the outset, but even this number can increase or decrease as the case proceeds.
A law firm can of course make big money with a big case, but it is a big risk that can take many years to return, and it can fail.
What we really need is to shift the burden of proof from the consumer to the lender. If the lender cannot establish beyond a reasonable doubt that they entered into a contact with the consumer, then the consumer can sue them. Just having the SSN, name, address of the consumer, etc. shouldn't be enough to prove the lender entered into a contact with the consumer.
For what? The consumer isn’t responsible anyway if the lender gets defrauded.
Is the fraud in itself not enough of a punishment for the lender?
I’d argue that the real problem here are the regulators who have shaped this broken system. Not the lack of punishments for existing within it.
>Just having the SSN, name, address of the consumer, etc. shouldn't be enough to prove the lender entered into a contact with the consumer.
It isn’t. The lender enters into a contract with a fraudster and gets fucked. The lender is the victim, not the consumer.
For the hours of phone calls over several weeks/months/years it takes to clear it all up?
Maybe I’ve been lucky but every time I’ve had to do a chargeback it’s been this smooth.
Credit reporting should be the same. I should get a statement in the mail every month from these agencies showing all credit activity and inquiries, and have a simple and painless way to dispute fraudulent data.
I should also be able to opt out and not participate in the credit reporting system but that’s a topic for a different thread.
Here's a pretty entertaining peek (by Micheal Lewis) into what happens because of fraud that the consumer had literally nothing to do with and how the lender (bank) is able to put the onus on him to fix. It's not life or death, at least in this example, but it really shows how obviously unfair the system is. Apparently this happens quite a bit.
https://atrpodcast.com/episodes/the-seven-minute-rule-s1!1c9...
Isn't that just the fault of the system, not the individual participant being defrauded?
Since they aren't lifting a finger to remedy the issue, we can assume that either the consequences are insignificant to them or they're just bad at business.
It seems to defy logic unless you look at the system as a whole.
The bank creates a separate set of consequences for the consumer, but does not transfer any consequences. The bank still suffers the costs of the fraud, the consumer suffers the costs of an inaccurate report.
>we can assume that either the consequences are insignificant to them or they're just bad at business.
It is just not possible for the banks to solve this problem. What do you think they could do?
It's just a pita and an interesting story for Micheal Lewis, but this can have a pretty extreme impact on completely innocent law abiding working class families who depend on their credit for housing, groceries, etc. There's a real infuriating injustice to it.
The bank isn't trying to punish the consumer. This is just an unfortunate consequence of fraud that the bank is often entirely unaware of.
And big bad banks aren't the only victims of "identity theft", local small businesses are just as capable of messing up your credit.
If the regulators wanted to stop this they'd create a better ID system, but they don't want to do that.
I also don't really like the language "big bad banks". I believe you have a bunch of self-interested people (aren't we all?) and a corrupt system. People who go home and kiss their kids. If regulators aren't doing something that's in societies best interest, we should be figuring out why (corporate capture perhaps?).
> For what?
For sending a bad report about the consumer they claim to have entered into a contract with to the credit bureaus.
> The consumer isn’t responsible anyway if the lender gets defrauded.
That's true, but the lender is responsible for what they report to the credit bureaus.
> Is the fraud in itself not enough of a punishment for the lender?
If they don't involve the actual consumer in their lack of due diligence, then sure.
> It isn’t. The lender enters into a contract with a fraudster and gets fucked. The lender is the victim, not the consumer.
If the lender involves the consumer by sending a bad report to the bureaus, then they have harmed the consumer.
That's true, but I was proposing holding the creditor/lender liable for filing a bad report with the credit bureaus, not the bureaus themselves.
The basic problem is that lenders/creditors are not exercising due diligence when extending credit or loaning money to an individual. While this is currently referred to as "identity theft", it's really a problem with the lender/creditor and they should be held accountable if they cause harm to the actual consumer by filing a bad report with the bureaus.
https://www.law.cornell.edu/uscode/text/15/1681h (e).
I wouldn't be surprised if this immunity were the primary cause of the current situation. Getting immunity from negligence means it makes sense to take advantage of being negligent.
What should be enough? What documentation should banks have to collect before opening, say, a credit card with a $1000 limit for a customer?
In my experience, having a passport makes it much easier to do various things that require identification.
Can I set up a “virtual” credit monitoring that provides that type of service in name only to cover that requirement? Imagine paying $5 to claim you have credit monitoring for settlement purposes.
Credit monitoring, like antivirus, is something you should have, but should not be paying for.
Experian.
The company responsible for possibly the biggest data leak in history. Advertising data protection services.
The balls of some companies
But the reality is: These companies already have your data, so being signed up so you can also see it isn't giving them any more information.
For "credit monitoring" specifically, individuals should not be doing the surveillance bureau's work for them. If lenders don't think it is necessary to do diligence when issuing credit, then why should I make up for it by half-policing [0] use of my public identifiers? The more painful fraud is for lenders, the more incentive they have to actually do some diligence rather than trying to push their lack of responsibility onto everyone else.
[0] If I had total legal control over the use of my public identifiers, I would simply tell the surveillance bureaus to delete all data kept on me. But we are not given this option, which indicates how the surveillance bureaus do not work for us. The less we give them, the better.
Absolutely. https://creditkarma.com/ is free, and counts.
The one thing most District Court judges like least is being overruled on appeal.
But the real blame falls on Congress. They ought to adopt a real regulatory apparatus and put away the class action (vice mass action).
I haven't tried it but it looks ripe for attack. A security noob could try using SQLMap and Nikto. If that were to happen though, would there be a class action lawsuit against the class action settlement team?