LexisNexis and Other Major Data Brokers Hacked By ID Theft Service
gewalker writes "Have we reached the point where it is time to admit that the ID thieves are winning and will continue to win as long as their incentives are sufficient to make it lucrative for them? According to Krebs On Security an analysis of a database pilfered from commercial identity thieves identified breaches in 25 data brokers including the heavyweights Dun and Bradstreet and LexisNexis."
And they had access for months to most of them. From the article: The botnet’s online dashboard for the LexisNexis systems shows that a tiny unauthorized program called nbc.exe was placed on the servers as far back as April 10, 2013, suggesting the intruders have had access to the company’s internal networks for at least the past five months. The program was designed to open an encrypted channel of communications from within LexisNexis’s internal systems to the botnet controller on the public Internet." The companies compromised aggregated data for things like "credit decisions, business-to-business marketing and supply chain management. ... employment background, drug and health screening."
This company and every one like it shouldn't even exist.
They collect all this data about us without out our permission. They offer me no service.
Just remember kiddies, things were quite fine without these services. But with the demise of local business, consolidation into massive organizations spread all over the World, these businesses were created for their use, convenience and to lower their costs. It gives then the edge on knowledge about us and how to market shit to us - and it's all shit - especially in financial services.
I had a credit bureau problem. THEIR information was wrong and as a result, I failed the authentication. They gave me a 800 number to call and I got this woman with a heavy accent (Indian?) who asked me a bunch of personal questions.
When I asked her what country she was in, she responded that she couldn't answer because of "Security reasons."
So, MY security means nothing to TransUnion but where their off shored call center is does.
Corporations are the only ones who have a right to privacy and security.
So how do I opt-out? Where do I get away from companies releasing my information to third parties that track my identity or other things to allow other corporations to peruse at their leisure? Not only do you not get to tell companies where they can and can't store your personal information, you also can't dispute that information when someone uses it for the wrong reasons or enters things that you're not allowed to know about.
For example, let's say LexisNexis had an entry that said I caused a major auto accident involving 15 cars, because an insurance clerk pressed the wrong button that said I was at fault rather than being involved in the accident? How do I correct that data? How do I dispute that entry? How do I even find out about that information?
And how do I get them to delete my personal data rather than allowing their poor network security policies to expose my life to risk? Answer: I can't. I have no agreement with them to host my personal data. I'm not just upset about the breach, I'm upset about the lack of ownership and consequence of such regarding my own life.