Slashdot Mirror


Experian Breached, 15 Million T-Mobile Customer's Data Exposed

New submitter Yuuki! writes: The Washington Post reports that T-Mobile's Credit Partner, Experian, has been breached revealing names, addresses, Social Security numbers, birth dates and driver's license and passport numbers for any customer who has applied for device financing or even services from T-Mobile which required a credit check. Both parties were quick to point out that no no credit card or banking data was stolen as part of the attack. The attack started back in September 2013 and was only just discovered on September 16, 2015. Both Experian and T-Mobile have posted statements on their websites and Experian is offering credit for two free years of identity resolution services and credit monitoring in the wake of the breach.

161 comments

  1. Two Free Years! by Anonymous Coward · · Score: 5, Insightful

    Two free years of credit monitoring after the bad guys had two free years of access! Great work, Experian!

    1. Re:Two Free Years! by Bob+the+Super+Hamste · · Score: 2

      I just want to know if the credit monitoring is going to be through Experian? Also do I get to decide when the credit monitoring starts as I already have a couple of other services monitoring my credit and I don't think I need another concurrent one. It would be nice if these things stacked instead of ran concurrent.

      --
      Time to offend someone
    2. Re:Two Free Years! by CaptainLard · · Score: 4, Insightful

      I currently have 3 separate free credit monitoring services from prior breaches in other companies. I'm confident that I'll have perpetual free credit monitoring since the credit monitoring lobby is now rich enough to force congress to maintain the status quo.

    3. Re:Two Free Years! by easyTree · · Score: 1

      Two free years of credit monitoring after the bad guys had two free years of access! Great work, Experian!

      I read their offer as "This is not the incompetence you're looking for; we're still relevant; no-one's worth may be judged without our say-so! dammit!!"

    4. Re:Two Free Years! by squiggleslash · · Score: 2

      I'm sure if we protest enough, they'll also give us a coupon for 20% off at Bed, Bath, and Beyond

      --
      You are not alone. This is not normal. None of this is normal.
    5. Re:Two Free Years! by Anonymous Coward · · Score: 0

      Think about it this way: Congress isn't having to fund these competing, free-market-based agencies that compete on surveilling your financial transactions and checking into your identity. It's like Big Brother didn't even have to be outsourced but arose in the market, no tax dollars needed, as the Invisible Hand masturbated onto the crisis of identity theft.

      All those people with data stolen... are now *volunteering* to be monitored. It's like the Facebook of the financial world. And you think three-letter-agencies don't have a direct line in to their servers?

    6. Re:Two Free Years! by MoarSauce123 · · Score: 1

      Not only that, they got apparently 15 million SSNs...what good does a two year protection do when the identity is hosed for life? Companies that are that careless with personal data should be mandated to provide free identity theft protection for life. Even more important, why the heck does Experian need the SSN? Did they plan to pay into the federal retirement accounts of people? The rampant abuse of the SSN needs to stop!

  2. Electronic footsteps on the Breaches by rmdingler · · Score: 0
    Honestly, this has the unfortunate, identical taste of the latest school shooting.

    What a shame, but nothing will really change once this is all hashed out.

    --
    Happiness in intelligent people is the rarest thing I know.

    Ernest Hemingway

    1. Re:Electronic footsteps on the Breaches by jedidiah · · Score: 2

      ...there won't even be the same sort of mass outrage associated with this. Only a few geeks will even notice or pay attention. Making it even less likely that anything will change.

      --
      A Pirate and a Puritan look the same on a balance sheet.
    2. Re:Electronic footsteps on the Breaches by rmdingler · · Score: 1

      ...there won't even be the same sort of mass outrage associated with this. Only a few geeks will even notice or pay attention. Making it even less likely that anything will change.

      Quite right. Even now (as millions of hard-earned credit ratings are threatened) the school shooting, the Vatican's elaboration on the Pope meeting Ms. Davis, and latest thing Trump said are bigger news stories.

      --
      Happiness in intelligent people is the rarest thing I know.

      Ernest Hemingway

    3. Re:Electronic footsteps on the Breaches by lgw · · Score: 2

      I can at least understand the shooting becoming the top story for a while (if it bleeds it leads), but it's obvious how far the news media has fallen when "the Pope is Catholic" is headline news.

      --
      Socialism: a lie told by totalitarians and believed by fools.
  3. Phew, I was worried there for a second. by EmagGeek · · Score: 5, Insightful

    Thank God my Credit Card numbers weren't breached, because those are impossible to cancel and replace. I'm so thankful it was only my Passport number, Driver's License number, social security number, full legal name, birth date, and address that were stolen, because those are a snap to cancel and replace.

    1. Re:Phew, I was worried there for a second. by Anonymous Coward · · Score: 3, Insightful

      I take it you are a foreigner who doesn't understand sarcasm.

    2. Re:Phew, I was worried there for a second. by Anonymous Coward · · Score: 5, Funny

      I was born in Sarcastistan, you insensitive clod!

    3. Re:Phew, I was worried there for a second. by markdavis · · Score: 1

      Yep, and you know, it was so necessary for that easily changed and security irrelevant information to be recorded and saved on their servers FOR YEARS.

    4. Re:Phew, I was worried there for a second. by easyTree · · Score: 3, Funny

      I was born in Sarcastistan, you insensitive clod!

      So.... you were...(nt?) born there? I'm confused.

    5. Re:Phew, I was worried there for a second. by easyTree · · Score: 1

      What better investment could they make when they need future control of their stock price?
      [x] Blends in with their nominal business practices?
      [x] Will have drastic effect on their stock price?
      [x] Can be blamed on (unknown! :))) third party?
      [_] Will have a permanent effect on the stock price?
      [x] Should do it?

      </paranoia-mode>

  4. inadequate by harvey+the+nerd · · Score: 4, Insightful

    They need to make more reparations than that, as actual remedy, compensation and punitive damages with a positive, non govt funding goal.

    In corporatese, "I'm sorry" are empty words with no meaning without restitution and money.

    1. Re:inadequate by gstoddart · · Score: 5, Insightful

      And as long as they have no legal liability for keeping this stuff safe, an insincere "I'm sorry" is all you will ever get. If corporations can hold your private data and have no consequences for having shit security, they will continue to do so.

      For a credit agency to store that much personally identifying information and be hacked tells me that agencies like this need to have some pretty severe penalties for shit like this ... because they have pretty much everything required to steal your identify.

      If we're going to entrust this data to these entities, we should sure as hell make certain we can actually trust them with it. And I would say that Experian has more or less demonstrated themselves to be incompetent to hold this information.

      It really is time to stop letting companies treat this as "their" data, and realize they have an obligation to safeguard our data, and to be legally responsible when they fail to do so.

      --
      Lost at C:>. Found at C.
    2. Re:inadequate by ITRambo · · Score: 1

      There is no remedy for laziness/ineptness. Anything done will probably be short term due to management priorities changing over time. Experian has been advertising their credit monitoring services on TV in the US. A bit ironic, I think.

    3. Re: inadequate by Anonymous Coward · · Score: 0

      What do you mean, "if we're going to entrust our data to...."? You say that as if we had a choice.

    4. Re:inadequate by Anonymous Coward · · Score: 0

      I'm in favor of prison for the CEO. A year for every person affected.

    5. Re: inadequate by Sarten-X · · Score: 2

      We do have a choice. We can either trust others with our information, or we can live without the modern services they provide.

      You can live without telephone or Internet service. You can live without credit. You can live without running water, electricity, cable TV, or any other privatized "public" utility. There's your alternative choice.

      For most of the last century, America has been opposed to widespread government control. Out of a fear of "socialism", we campaign against raising the government-supplied standard of living. We say we don't want the government to take away our choice, without realizing that the only other option in the choice we have is to return to a standard of living set shortly after the Civil War.

      --
      You do not have a moral or legal right to do absolutely anything you want.
    6. Re: inadequate by operagost · · Score: 0

      Thanks to the federal reserve act of 1913, we couldn't return to your Civil War-era standard of living, Captain Hyperbole. But thanks for the diatribe, Mr. Marx.

      Your misguided, fascist signature is all anyone needs to red before putting you on their foes list.

      --

      Gamingmuseum.com: Give your 3D accelerator a rest.
    7. Re:inadequate by Anonymous Coward · · Score: 0

      Its not your private data. Its theirs. Which you willingly gave up.

    8. Re:inadequate by Anonymous Coward · · Score: 0

      Prison is only part of the punishment. Freeze their assets for the duration of their prison term.

    9. Re:inadequate by Anne+Thwacks · · Score: 1
      Freeze their assets for the duration of their prison term.

      I presume by "assets" you mean their "wedding tackle" - yes freeze with liquid Nitrogen.

      --
      Sent from my ASR33 using ASCII
    10. Re: inadequate by Anonymous Coward · · Score: 0

      Not to mention that the government is among the worst at securing personal data about their own citizens.

    11. Re:inadequate by wasteoid · · Score: 1

      How about sourcing the credit / identity from something other than the data elements that keep getting stolen - and I'm not delusional enough to suggest biometric data.

    12. Re:inadequate by HiThere · · Score: 1

      But what are you suggesting?

      The problem is, if they can transmit the validating information, it can be stored and copied...and thus lost. That's the real reason all biometrics are an inherently bad idea.

      --

      I think we've pushed this "anyone can grow up to be president" thing too far.
  5. Identity Theft by Jason+Levine · · Score: 5, Informative

    As an identity theft victim, let me say that "no credit card or banking data was stolen" means nothing. With name, address, SSN, and birth date compromised (as well as driver's license and passport numbers), anyone can now open new lines of credit in the names of any of the 15 million people whose information was accessed. And the two years of "credit monitoring" will do almost nothing. Fraud alerts won't either - those are voluntary.

    My recommendation if you are one of the 15 million people is to freeze your credit. This will stop ANYONE from opening a new line of credit under your name unless you first thaw your credit file. It's a royal pain in the rear when you need to do things like refinance a loan, but it's better than having a collections agency banging down your door because you owe $5,000 on a credit card that "you" opened.

    --
    My sci-fi novel, Ghost Thief, is now available from Amazon.com.
    1. Re:Identity Theft by gtall · · Score: 5, Interesting

      I second this advice, I did this several years ago. It should be noted, however, that the three credit record agencies cannot prevent someone from getting credit in your name. The system relies on the intuition, and it is only that, that any self-respecting credit issuing entity will require a credit record (and a good one, at that) before issuing credit. If Joe's Bank and Bait Shop wants to issue someone a credit card in your name and doesn't give a flying rat's ass about your credit history, they are free to do this.

      There is no national system to prevent credit from being authorized in your name, even to aliens from other worlds.

    2. Re:Identity Theft by drinkypoo · · Score: 3, Interesting

      It should be noted, however, that the three credit record agencies cannot prevent someone from getting credit in your name.

      Yep. A shady car dealer in Nevada City gave an illegal with my SSN written on a check cashing card credit in my name, and now it's on my credit report. The whole idea that this can even happen is proof that the system is broken. I shouldn't have to appear to fight this, no court should have granted a judgement on the basis of a CHECK MART card with my SSN written on it in pen.

      --
      "You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
    3. Re:Identity Theft by cdrudge · · Score: 1

      It should be noted, however, that the three credit record agencies cannot prevent someone from getting credit in your name.And apparently for 15m people, at least one of the three credit record agencies may be assisting others getting credit in your name...

    4. Re:Identity Theft by mrchaotica · · Score: 4, Insightful

      My recommendation if you are one of the 15 million people is to freeze your credit.

      You know the best part? The best part is that in order to do that, you get to PAY A FEE TO THE SAME GODDAMN FUCKERS WHO LOST THE INFORMATION IN THE FIRST PLACE!

      1. Step 1: Collect everyone's personal information
      2. Step 2: Lose said information, forcing the victims to freeze their credit
      3. Step 3: Charge the victims $5-10 each to do that freeze, and another $5-10 each time each victim needs to thaw or re-freeze it, forever
      4. Step 4: profit, over and over again!

      (There is no "..." step; this is actually Experian's business plan!)

      --

      "[Regarding the 'cloud,'] ownership was what made America different than Russia." -- Woz

    5. Re:Identity Theft by Anonymous Coward · · Score: 0

      The problem with freezing credit is that the credit reporters don't want you doing that. I'd refer you to the recent cases with credit protection services where the reporters try to offer competing services. I think the thing that gets flung around most is that "credit monitoring services can't enact a freeze on your behalf"...that there's something underhanded about that. Of course it was a front for Experian offering their own credit monitoring service because apparently they 'can' freeze your credit on your behalf. They also don't like the extra human bandwidth required to process all the "was this you?" phone calls while you're sitting in the bank.

      But they can't have it both ways. You don't get to cry about how expensive it is to service fraud alerts whilst simultaneously BEING the cause of all the fraud. Also, I can't see how having my drivers license and passport number is anything to do with handling my credit. Actually...y'know...I don't even have a business relationship with Experian, they kinda force that on me. To me it's just a credit reporting agency that siphons up my data from anywhere they can find it so they can tell lenders how I'm a bad person for missing that $20 payment on a chair 28 years ago. I didn't ask for their service and I certainly didn't sign anything that said "sure, you can collect all my data, whatever". I actually never told them they could collect *any* data about me, they took that upon themselves. Now I'm paying for it.

      This plague we're facing now is as bad as nuclear energy. The harvesting of PII from every organization on the planet comes to a head when someone gets burned by this data - usually several months later when the debt collectors come banging on the door. The crime is too far removed from the original hack to prove that anyone in particular was involved. Just like cancers after a nuclear accident it's hard to prove that "this" caused "that" and these companies get to hide behind a cloak of uncertainty. WE certainly don't get to call that same uncertainty card though, and you're damn right you're gonna have to fight HARD to NOT pay that bill that YOU never racked up. The onus is on you. See how this works?

      The buck stops with me only long enough for them to figure out if the buck belongs to them.

    6. Re:Identity Theft by easyTree · · Score: 1

      There is no national system to prevent credit from being authorized in your name, even to aliens from other worlds.

      Agreed; indeed both my immediate neighbours were recently granted credit and they're gelatinous CO2-respiring life-forms from out of town. Curiously, I've been repeatedly turned down, despite paying-off every one (of fifteen credit records) loan, hp agreement etc. with only two missed payments since my credit history began.

      I'm more interested in their ability to perform their core task of determining someone's creditworthiness than anything as ancillary as preventing credit theft although that is a close second.

      It disturbs me that these agencies are seen to be infallible (certainly with respect to credit-scoring) and are free to operate without oversight, despite there being no logical manner to derive their decisions from their available data!

      Surely, someone (else, tm) should be looking in to this given that ability to obtain credit is so crucial to one's flexibility in the modern world.

    7. Re:Identity Theft by operagost · · Score: 1

      Yours isn't the scenario we're talking about. If your credit record were frozen, they wouldn't be able to pull a report and thus wouldn't be able to put a ding on it. If you did freeze it and they let some random person put this on it, you should be suing that credit agency for libel.

      --

      Gamingmuseum.com: Give your 3D accelerator a rest.
    8. Re:Identity Theft by Anonymous Coward · · Score: 0

      With name, address, SSN, and birth date compromised (as well as driver's license and passport numbers), anyone can now open new lines of credit in the names of any of the 15 million people whose information was accessed

      The T-Mobile statement includes additional information, stating that the SSN, driver's license and passport fields were encrypted, so (hopefully) it will be less of an issue. Experian's statement doesn't say anything about this, so for now, I'm treating this as unreliable information.

    9. Re:Identity Theft by Anonymous Coward · · Score: 0

      D'oh. In my rush to reply, I failed to read the very next sentence in the statement, which says "Experian has determined that this encryption may have been compromised."

    10. Re:Identity Theft by Anonymous Coward · · Score: 0

      Every victim of this type of fraud should be able to go after the issuer for punitive damages, seeing as the issuer was an active participant (co-conspirator) to the financial fraud committed against you.

      It's not uncommon for identity theft victims to spend thousands of hours and take many years to try to recover. That's many years where they can't buy a house, car, etc due to the damage to their credit.

    11. Re:Identity Theft by Jason+Levine · · Score: 1

      Don't forget that you need to pay each of the three major credit agencies. Also, if you're married and applying for a loan, your spouse and you need to pay separately. If my wife and I want to thaw our credit, it costs us $30. Awhile back there was a bill in Congress that would have made it free to freeze your credit, but the credit agencies, credit card companies, etc all lobbied against it. They see frozen credit as lowered profits (since you can't open new lines of credit on a whim). The rash of identity theft, to them, is just a corporate write-off at worst.

      --
      My sci-fi novel, Ghost Thief, is now available from Amazon.com.
    12. Re:Identity Theft by Anonymous Coward · · Score: 0

      Given that the freeze is the 'best' option, how would an affected individual obtain a copy of the police report for this data breach, so as to have the 3 credit monitoring bureaus waive their fees for implementing a credit freeze? These fees appear to range from $5-10 to implement the freeze, and another $5-10 to lift it, recurrently, as needed.

    13. Re:Identity Theft by Anonymous Coward · · Score: 0

      I just froze my credit at all three agencies this morning. It is now free.

    14. Re:Identity Theft by Anonymous Coward · · Score: 0

      Did they require proof that you were an identity theft victim, as they all state they require?
      What did you provide?

      Fees listed vary by state, and range from $5-10 with each change in status.

      https://www.experian.com/ncaconline/freeze#fees

      https://help.equifax.com/app/answers/detail/a_id/75/search/1

      http://www.transunion.com/personal-credit/credit-disputes/credit-freezes.page?tab=freezefees

    15. Re:Identity Theft by Anonymous Coward · · Score: 0

      When I attempted a credit freeze with the big 3 creditors a few months ago, Experian was the only one that denied my online application. They said I had to print forms, fill them out, mail them in, etc. Experian is a PITA.

    16. Re:Identity Theft by Alumoi · · Score: 1

      With name, address, SSN, and birth date compromised (as well as driver's license and passport numbers), anyone can now open new lines of credit in the names of any of the 15 million people whose information was accessed.

      And that's why in backworld countries you are required to provide some government issued photo ID when you open a bank account. Just saying.

    17. Re: Identity Theft by Anonymous Coward · · Score: 0

      The commercials that seek idiots to give up their info so they can see their 'score' are beyond pathetic. Worrying about what some scumbag bank thinks of your finances and them wanting to score you reminds me of the stars given out in grade school classes. The better your work the more the stars. I never liked the star system and I despise the banks as well as the 3 deadbeat faggot agencies who think I gaff about their credit rating system.
      Experian and your other two but buddies can go fuck each other in the ass in hell permanently.

    18. Re:Identity Theft by Anonymous Coward · · Score: 0

      You are missing the point. Shady dealer didn't bother to check any credit reports. Thus freeze didn't do anything. Then when payments weren't paid, they reported the non payment to the credit bureau.

    19. Re:Identity Theft by Anonymous Coward · · Score: 0

      Oy vey. You are wise about rackets.

      "sell Windows all week, break them on weekends"

      And then when Experian pockets a bunch of cash... wow... Experian is a great company. They have a lot of money in their pockets for a reason. Ohhh and the market share wow damn they're good.

      Substitute Microsoft for Experian.

      Also consider taxpayers. Rackets are some b.s. huh.

    20. Re:Identity Theft by Anonymous Coward · · Score: 0

      As an identity theft victim, let me say that "no credit card or banking data was stolen" means nothing. With name, address, SSN, and birth date compromised (as well as driver's license and passport numbers), anyone can now open new lines of credit in the names of any of the 15 million people whose information was accessed. And the two years of "credit monitoring" will do almost nothing. Fraud alerts won't either - those are voluntary.

      My recommendation if you are one of the 15 million people is to freeze your credit. This will stop ANYONE from opening a new line of credit under your name unless you first thaw your credit file. It's a royal pain in the rear when you need to do things like refinance a loan, but it's better than having a collections agency banging down your door because you owe $5,000 on a credit card that "you" opened.

      It's actually quite simple for this entire problem to go away. O nevermind that would require people to live within their means. Carry on with this fuckin fake consumer credit economy. I for one don't have a dog in the fight. I opted out in 2007 by simply stopping paying and using credit cards. Yes I have an awful credit score and don't care. Steal my identity and get a $500.00 credit line. I stopped using or caring.

  6. 8ts by Impy+the+Impiuos+Imp · · Score: 1, Offtopic

    Experian Breached, 15 Million T-Mobile Customer's Data Exposed

    The apostrophe should go after the 's'.

    --
    (-1: Post disagrees with my already-settled worldview) is not a valid mod option.
    1. Re:8ts by sexconker · · Score: 1

      No, it should go between the two esses.

  7. Experian by internerdj · · Score: 4, Interesting

    One of the three major credit rating services? I'm a little bit impressed that this breach was limited to only everyone who has ever applied for T-Mobile service.

    1. Re:Experian by jhecht · · Score: 3, Insightful

      How do we know it WAS limited to people who applied for T-Mobile service? It took Experian two years to find the breach in the first place.

    2. Re:Experian by wasteoid · · Score: 1

      It wasn't limited to T-Mobile customers, although those accounts were the majority of what was stolen from Experian.

  8. Fuck You, Experian by drinkypoo · · Score: 5, Insightful

    Guess what they're not giving you? Your actual credit report. You just get the abbreviated version, so you can't actually look it over and see if this generally corrupt industry is fucking you. They will, however, sell you your credit report at a special members-only price. So what's happened here basically is that Experian is getting free advertising and T-Mobile is going to get off without punishment.

    Fuck you Experian, and fuck you T-Mobile.

    I already said fuck T-Mobile since they cancelled the PAYG plans I've been using, but fuck them twice now.

    Are there ANY US mobile providers from whom I can buy a PAYG SIM which are not total fucks?

    --
    "You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
    1. Re:Fuck You, Experian by swb · · Score: 4, Insightful

      None of this should be surprising. The credit reporting services are in business to please their customers, the credit issuers. People who apply for credit are part of the product.

      I would even go so far as to argue that the credit reporting agencies have an incentive to make your credit report as bad as possible, since the worse the report, the higher the interest rate you get charged for borrowing money. And the good news for creditors is that it doesn't force them to be more competitive, since they're all competing against the same view of your creditworthiness. Erring on the side of reduced creditworthiness lets creditors charge a higher interest rate for a risk that isn't elevated.

      My conspiracy minded side says this is why erroneous credit data is hard to remove and why credit reporters want to use non-financial correlates (like driving records) as part of your credit score -- something you can't ever get removed yet makes your credit report look marginally worse, thus making you a more profitable creditor via higher interest rates.

    2. Re:Fuck You, Experian by Anonymous Coward · · Score: 0

      So far, I've had good luck with ting.com

    3. Re:Fuck You, Experian by drinkypoo · · Score: 1

      So far, I've had good luck with ting.com

      They only support 2G for my phone, but I might try them for a non-internet plan since that's effectively what I have now.

      --
      "You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
    4. Re:Fuck You, Experian by operagost · · Score: 1

      Each of the major credit reporting agencies must supply you a complete credit report annually upon request. Come on, this is not new.

      https://annualcreditreport.com...

      --

      Gamingmuseum.com: Give your 3D accelerator a rest.
    5. Re:Fuck You, Experian by ftobin · · Score: 2

      Lenders want to lend. If the credit-worthiness data does not correlate well with ability to repay, lenders cannot efficiently lend and will look for a different service. The number of participants in this space might make this a slow change, but normal market competitiveness has the opportunity to have effect.

    6. Re:Fuck You, Experian by Sir+Holo · · Score: 1

      Each of the major credit reporting agencies must supply you a complete credit report annually upon request. Come on, this is not new.

      https://annualcreditreport.com...

      Technically, that is true. I've got mine in the past this way. But is there a penalty if they do not comply?

      The Credit Agenccies make it a total pain to get the free report, and try to up-sell you crap left and right. I've had them give me "high traffic; try again later" a few times, too.

      I ordered mine, on paper, two months ago. None have yet arrived.

    7. Re:Fuck You, Experian by slinches · · Score: 1

      Are there ANY US mobile providers ... which are not total fucks?

      No.

      There are only varying degrees of total fuckishness and, as far as I can tell, T-Mobile is the best of the bunch. Maybe you can find a trustworthy local MVNO, but even then most of the money you pay them will still be supporting one of the big 4.

      --
      Knowledge Brings Fear
    8. Re:Fuck You, Experian by Anne+Thwacks · · Score: 1
      Lenders want to lend. If the credit-worthiness data does not correlate well with ability to repay, plausible deniability is a perfectly adequate substitute

      FTFY

      --
      Sent from my ASR33 using ASCII
    9. Re:Fuck You, Experian by Anonymous Coward · · Score: 0

      I know people seem to hate them, but I have ATT for PAYG and it has been perfect for me.

      Data plan is relatively cheap if you don't use a lot of data. Including unlimited minutes messages, blah blah, 1.5 gigs is 40 dollars a month (45 if you don't autopay.. note this isn't a contract, just a normal setup to charge a CC or Debit at monthly intervals). After the data runs out you still connect, just at a slower speed. Data also rolls over for one month, so if you don't use the full amount, it gets added to the next month. International calling and texting is supported by default-- I live near canada so I just toss 5 dollars on the phone before I cross the border and I can text / call as normal. Sends an update after each call / message to let you know balance but I think you can disable that if you find it annoying... I like it since I don't like to keep more than 5 bucks or so in the account in case I decide to drop it. It IS prepay afterall-- being able to walk away is half the point.

      If you are NOT using data, visual voice mail, etc, will still function since ATT allows that traffic to go through and not count as "data". In short, you don't get the internet, but you'll have access to any functions that may require data anyway-- free of charge.

      I know a lot of people that HATE ATT, but I've used them for about a decade, prepay for probably the last 6 years, and I've had no problems.

      Oh, and since it's PAYG you can use whatever phone you want. My phone died and I borrowed an old 1 gen iphone for a week from a friend (It was a while ago...). No issues, no hassle, just pop the sim in and go.

    10. Re:Fuck You, Experian by Anonymous Coward · · Score: 0

      I still use a pay-as-you-go SIM from T-Mobile. My phone works. I don't pay monthly fees. What's the problem?

    11. Re:Fuck You, Experian by swb · · Score: 1

      If the credit-worthiness data does not correlate well with ability to repay,

      None of this changes the desire of the lenders to charge more profitable interest rates nor the desire of credit reporting agencies to have their scoring seen as more profitable. Since lenders are inherently risk-averse and profit-oriented, they have an incentive to lend at the interest rate that represents the highest possible risk and highest possible profit.

      There's almost no way for a credit reporter to lose by reporting clients as worse risks than they really are. If a lender has a loan go bad and they see that the borrower was assigned the worst of three possible credit scores, they can't blame the credit reporting agency who reported it. If a loan was repaid correctly, the credit reporting agency was ALSO right AND the lender made more money.

    12. Re:Fuck You, Experian by msimm · · Score: 1

      Are there ANY US mobile providers from whom I can buy a PAYG SIM which are not total fucks?

      Cricket Wireless (subsidiary of AT&T) and MetroPCS (partnered with T-Mobile) provide pay-as-you go service for both companies.

      I've used both since I bought a off-contract phone and had no problem with either. I settled with Cricket because of coverage where I'm living in central Texas.

      --
      Quack, quack.
    13. Re:Fuck You, Experian by drinkypoo · · Score: 1

      Yeah, I ordered one once, I never got it, I didn't bother to try again. It's all just a scam to sell you shit.

      --
      "You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
  9. T-Mobile breached? by willworkforbeer · · Score: 0

    I sense a disturbance in the Magenta Force, as though millions of teenage girls cried out at once and then, nothing.

    --
    Pretending this is my office full of bitter coworkers..
    1. Re:T-Mobile breached? by willworkforbeer · · Score: 1

      Geez, the Magenta Mafia downmodding is harsh... But I stand by it, because as we know, Real Men (TM) use Sprint, just to prove they can suffer like Sisyphus and by God take it like men.

      --
      Pretending this is my office full of bitter coworkers..
    2. Re:T-Mobile breached? by cbhacking · · Score: 1

      Does this actually have anything to do with T-Mobile? From the sounds of it, it's Experian that was breached, and the attackers mostly (though not exclusively) took TMo subscriber info. TMo's own security wasn't compromised.

      I suppose you could argue that TMo should have gone with somebody more responsible / secure than Experian, but is there actually any such entity that provides the necessary services? As low as Experian sets the "not complete shit" bar, are the other credit agencies actually any better? They all suck.

      It would be nice to have a not-shit option here, of course. Naively, one would expect the free market to take care of it, but in practice there seems to only be the three agencies, all in a race to the bottom, with nobody actually interested in providing good service instead.

      --
      There's no place I could be, since I've found Serenity...
  10. Re:Who is monitoring us here at Slashdot? by Anonymous Coward · · Score: 0

    The almighty google:

    "Taboola | Drive Traffic and Monetize Your Site"

    "Ooyala | Deliver Content that Connects
    www.ooyala.com/
    Ooyala goes beyond traditional online video platforms, offering best-of-breed online video analytics and monetization solutions that boost revenues from video."

    So as per usual it's someone trying to make money from your traffic.

  11. Requirement to be forgotten by Anonymous Coward · · Score: 5, Insightful

    One of the best things that can be done to prevent data breaches is require that data be deleted after a certain time. I don't see a good reason why 15 million customers should have their data retained after the credit check is complete. It won't stop breaches, but it would limit their scope. There also needs to be severe penalties for negligent security or failing to notify customers in a timely manner. Better yet, eliminate social security numbers for identification altogether outside of social security and (maybe) tax purposes. And it's no surprise that a credit bureau was attacked. They're gold mines of information waiting to be compromised. I'd like to see particularly strong regulation of these companies. Consumers don't really get to opt in, but this personal information is stored and can be compromised easily. That doesn't seem fair at all to me.

    1. Re:Requirement to be forgotten by Archwyrm · · Score: 2

      Does it really matter how long the data is being stored when it's being actively stolen over the course of two fucking years?

      --
      Fascism should more properly be called corporatism because it is the merger of state and corporate power. -- Mussolini
    2. Re:Requirement to be forgotten by Anonymous Coward · · Score: 0

      In this case, no, it wouldn't have made a difference. However, in other cases, it might. The university I attended had a massive data breach back in 2012. Data was compromised for anyone who attended there or even applied dating back all the way to 1985. It included social security numbers and grades. If you ever applied for financial aid there, your data was compromised. If you had any bank account information on file, that was compromised. It's ridiculous that 27 years of data was retained including social security numbers and bank account information, even if all you ever did was apply and maybe try to get financial aid, even if you never attended there. If you were a parent of a child who applied there and you had to supply information for financial aid purposes, your data was also compromised. In total, this affected about 650,000 people. Not a huge number compared to other breaches, but a massive number for a university. There is no fucking excuse for keeping that much data around. None. While it might not have limited the scope of the Experian breach too much, it's a common sense measure that would mitigate the damage from some other breaches. Data encryption, transmission, and retention practices are awful probably in most places.

    3. Re:Requirement to be forgotten by Anonymous Coward · · Score: 0

      We check every server for SSNs and DL#s quarterly and scrub every one we don't need. It's a process that takes several days, but I like knowing we don't have the data at all.

    4. Re:Requirement to be forgotten by ftobin · · Score: 1

      One of the best things that can be done to prevent data breaches is require that data be deleted after a certain time. I don't see a good reason why 15 million customers should have their data retained after the credit check is complete.

      Credit scores reasonably include attempts to acquire more credit (which is what most phone contract really are, even if month-to-month), so it wouldn't be possible to delete data after a credit check is complete.

      Note: it is possible escape the credit-check part of the equation by using pre-paid phones.

    5. Re:Requirement to be forgotten by david_thornley · · Score: 1

      The credit bureaus need to keep identifying information on everyone. Otherwise, they couldn't keep credit ratings up to date, and they couldn't even give my score to anyone as they wouldn't know that that was my score.

      It appears that what was leaked was identifying information, which they really have to keep.

      My Social Security number is fine for identifying me. It really, really sucks at verifying that I'm me. The idea that someone who knows the number I am required to tell many different people must be me has to go.

      The big problem is that institutions don't actually verify who they're dealing with before granting credit, talking to credit bureaus, working with collection agencies, and so on. They accept identification at face value. If they required some sort of verification (and I'm not saying that's necessarily easy to work out), there'd be no problem.

      It's really unfortunate that this is known as "identity theft" rather than "fraudulent misrepresentation".

      --
      "When you have eliminated the unacceptable, whatever is left, however improbable, must be the truthiness" - Holmes
    6. Re: Requirement to be forgotten by Anonymous Coward · · Score: 0

      I'm in IT at a university. Now that you mention it, I don't think we purge any of that kind of information. Security isn't the best despite my complaints. We're a data breach just waiting to happen. Sad.

  12. so there will be even more iphones on craiglist? by known_coward_69 · · Score: 1

    seems every year the thing to do is open a T-Mo account, "buy" an iphone and resell it before it's bricked for not paying the bill

  13. The best defense against fraud by Anonymous Coward · · Score: 0

    is to maintain a truly horrific credit score.

  14. There is ONLY one thing to do! by jjhues7676 · · Score: 1

    Go to all 3 reporting agencies and lock them down. It only takes a little time per agency and will save you years of headaches later. If you need to apply for credit unlocking is just as easy. You can choose a time frame or a specific company to allow through.

    1. Re:There is ONLY one thing to do! by CimmerianX · · Score: 1

      "Fees vary based on where you live, but commonly range from $5 to $10'

      Wonderful how these Aholes can charge us to freeze our credit, and then charge us to unfreeze it.

  15. Experian Credit Breach by Anonymous Coward · · Score: 5, Insightful

    Experian is offer a two year free credit monitoring in connection with the breach of their system. In order to sign up for the two year credit monitoring they require you to provide your full identity; SS number, birth date, etc. Isn't that just the information that was just compromised in their system??? How do they think they can be trusted??? This does not resolve the problem of their lack of network security with sensitive information.

    1. Re:Experian Credit Breach by Anonymous Coward · · Score: 0

      This would be bumped to +5 Insightful. It's ridiculous that a company shares with hackers the key to make it extremely easy to steal from 15 million people, and as remediation, they ask you the same information the lost to hackers, to be stored AGAIN in their servers, in order to notify you how much harm digital fraudsters are doing on the client behalf.

      Is there no dignity in T-Mobile, other than offering clients to trust them to watch their accounts, if they can't even guard basic data that they should have not kept on record? T-Mobile forced me to a credit check, and now information I trusted them is in the hands of people that make a living out of stealing my identity and money. And they best they do is offer me to submit the information to the party that they chose to for them to see if I am worhy of their mobile service? It's a shame T-Mobile! Step up your effort and I am not happy about this Un-Carrier thing!

      Federico

  16. Re:Who is monitoring us here at Slashdot? by Anonymous Coward · · Score: 0

    Get Ghostery...

  17. Re:Who is monitoring us here at Slashdot? by CimmerianX · · Score: 0

    Don't forget Janrain, Nativo and scorecard. Thank you Ghostery.

  18. Make PII Go Away by Archwyrm · · Score: 4, Insightful

    It is high time the abuse of the Social Security Number ended. SSNs should be used for one thing: Social Security. Using a single "secret number" is an archaic system that for increasing numbers of people is no longer secret. Let's not forget all your other details which are used to identify you but aren't really that secret (your full name, your birthday, etc).

    This information is used for identifying a person or proving identity so it's an authentication problem. We can do better! We have public key encryption. The government issues you a key pair (say, embedded into a photo ID, which we all have already) and now you can prove your identity without giving someone an irrevocable secret.

    Authentication is also two factor: You have an ID and you know a PIN (or passphrase). If you lose your card, then your identity is not immediately compromised because it is protected by your PIN. This gives you time to have the gov't revoke your old key pair and issue you a new one.

    In the case of the credit bureaus (I think we can all safely assume credit isn't going away any time soon), they associate your credit history with your public key and nothing else. If the key is revoked (by the gov't), then they move your file to the new key. No one can take out credit using the old key. In fact, any attempt could be reported to law enforcement.

    The entire US Department of Defense has been using a system like this for years now and has by and large done away with things like passwords and hand signatures, especially for the things that matter most.

    Is this completely foolproof to prevent someone impersonating you? No, but it is much better than having your SSN and other PII out on some forum where just anyone can use it for nefarious purposes and would be well worth its cost and complexity. The greatest obstacle is the credit bureaus having nothing to gain in actually protecting their "customers'" data because then to whom will they sell credit monitoring?

    --
    Fascism should more properly be called corporatism because it is the merger of state and corporate power. -- Mussolini
    1. Re:Make PII Go Away by david_thornley · · Score: 1

      Most people can deal with a number on a piece of paper. Most people are going to have real problems with handling a private key, having it available whenever desired while keeping it secret even if their computer is taken over and not losing it.

      --
      "When you have eliminated the unacceptable, whatever is left, however improbable, must be the truthiness" - Holmes
    2. Re:Make PII Go Away by Archwyrm · · Score: 1

      The key pair is embedded on a chip in your ID. The circuitry does the decryption, so the private key is never exposed to any computer that it is used with. This is also the point of the passphrase/PIN. The chip won't decrypt without it. This is how the smart cards used by DoD function and they double as a military ID (which is supposed to be kept on the owner at all times practical). They really are Idiot Resistant.

      The drawback is that most computers these days do not have a smart card reader. USB would be better but doesn't not fit nicely into something as thick as a credit card.

      --
      Fascism should more properly be called corporatism because it is the merger of state and corporate power. -- Mussolini
  19. KA-BOOM by Anonymous Coward · · Score: 0

    Give us one other value add.... The ability to meaningfully challenge our record and purge items which aren't ours. And give it to everyone. And make it stick across all credit services. That would go a lot further than your free identity protection and whatever other bullshit you think will mollify us.

  20. soon we'll all be Anonymous! by Anonymous Coward · · Score: 2, Funny

    All told, I have 17,300 years of credit monitoring due to various corporate negligence.
    There's no way they're going to steal my identity again!

  21. Still too much uncertainty of the size of exposure by idontgno · · Score: 4, Insightful

    "15 million". Huge number. It usually takes the power of the US Federal Government to screw up this big.

    But one thing is not clear from TFA, let alone from the slightly misleading TFS.

    This is an Experian hack, not a T-Mobile hack. What makes any "expert" think the exposure is limited to someone who interacted with T-Mobile? Experian is one of the awful ubiquitous unavoidable facts of life, much like the Government (see above). If you have participated in any non-cash financial transaction, they probably have a file on you.

    What are the particulars of this breach that make it strictly an "Experian interacting with T-Mobile" risk? Experian is huge, and if you're counting on some kind of strict internal data partitioning within the company to restrict the attack area to "T-Mobile applicants" you're too naive to sit with the grown-ups.

    Seriously. Why the fuck isn't this a maximal-sized no-holds-barred every-file-Experian-holds breach?

    --
    Welcome to the Panopticon. Used to be a prison, now it's your home.
  22. Good news, everyone! by operagost · · Score: 1

    Good news everyone! The bad guys only got things like your SSN, which can never be changed and which will haunt you forever, but not the credit card numbers which can easily be replaced and you probably wouldn't be liable for any illicit charges on, anyway.

    --

    Gamingmuseum.com: Give your 3D accelerator a rest.
  23. Thank you! by Anonymous Coward · · Score: 0

    that's all

  24. This is a good thing, and inevitable. by choke · · Score: 1

    These breaches are a good thing, because they are forcing evolution.

    Something we in IT have always known, is that security cannot be solely applied through obscurity. There will always be opportunity, tools and motivation that expose it.

    This has never translated into other information sensitive disciplines, and right at this moment we have a tremendous amount of fragility in our financial and personal identification infrastructures because there is no concept of authentication.

    That has to change. More of these breaches, which are not in and of themselves exceptions but rather the rule, will raise awareness to the reality of the situation - that attempting to protect oneself by hoping that ever more widely distributed sensitive information isn't disclosed, is not feasible.

    --
    "No good deed goes unpunished"
    1. Re:This is a good thing, and inevitable. by Jason+Levine · · Score: 1

      No matter how many times these breaches happen, we won't "evolve" a response because there are big financial companies whose profits rely on accumulating and easily accessing our credit files. Those companies will use their lobbying might to kill any reform bills that even slightly smell like they might slightly inconvenience them in the pursuit of protecting people. They might allow some useless "feel good" legislation to pass, but you can be sure they won't let any consumer protections "evolve" because that would mean less profits. So what if 15 million more people become identity theft victims? They can just write off the credit monitoring service they "generously" provide and that's the end of that. (For them. For the 15 million people, the pain is just starting.)

      --
      My sci-fi novel, Ghost Thief, is now available from Amazon.com.
  25. "...but the world didn't explode" by Anonymous Coward · · Score: 0

    There should be a logical fallacy formalized for this style of argument: "We really fucked up... but at least the world didn't explode!"

  26. What I want to know is .. by nickweller · · Score: 0

    "T-Mobile's Credit Partner, Experian, has been breached revealing names, addresses, Social Security numbers, birth dates and driver's license and passport numbers"

    What I want to know is - in this day and age - what this data was doing on a server, connected to the Internet in an unencrypted form.

    1. Re:What I want to know is .. by Anonymous Coward · · Score: 0

      monetizing you...

    2. Re:What I want to know is .. by Anonymous Coward · · Score: 0

      What makes you think it was connected to the internet?
      It probably was though - how the fuck else do T-Mobile check your identity before giving you several hundred dollars of high tech electronics?
      What makes you think it was unencrypted? T-Mobile state that it was encrypted. Experian state that the encryption may have been compromised.

      You don't know shit.

  27. No Ting for Me by drinkypoo · · Score: 1

    "numbering services not available for that area"

    whatever the shit that means

    --
    "You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
  28. Perfect irony by argStyopa · · Score: 1

    I went to the Tmobile site and what happened?

    I got a popup saying "T-Mobile wants to know your location"

    How fucking ironic.

    --
    -Styopa
  29. Morons in Charge by Anonymous Coward · · Score: 0

    Took two years to discover the breach! Great security checks there Experian. They didn't get the credit card and bank account info, just everything they need to steal a person's identity, and open their own credit accounts. If I were CEO of Experian, the IT department, especially the security division would be finding their heads on the proverbial chopping block.

  30. 2 years? by DewDude · · Score: 1

    It seems to me if it's been going on for 2 years, Experian hasn't been doing the job to secure our data. They should be facing some criminal charges or fines over this. Better yet; they should shut down. This is very gross incompetence. What's the two years going to do? "Oh, someone is using your data. LOL. Sorry." That's pretty much all they're going to do. They're not going to help solve a problem they are responsible for. They need to be held responsible; by someone. 2 days I could understand; 2 years is just plain incompetence.

    1. Re:2 years? by Anonymous Coward · · Score: 0

      The washington post article might be misleading. If you read the posts on the Experian and T-mobile sites the article references, what happened was a server was accessed that contained data from between those dates, not that Experian was hacked for two years and didn't notice.

    2. Re:2 years? by Anonymous Coward · · Score: 0

      The breach was not going on for 2 years. The server had 2 years of data on it.

      http://www.experian.com/data-breach/t-mobilefacts.html

      "The unauthorized access was in an isolated incident over a limited period of time. It included access to a server that contained personal information for consumers who applied for T-Mobile USA postpaid services between Sept. 1, 2013 and Sept. 16, 2015."

  31. That brings us up to almost 2/3rds of SSNs exposed by Anonymous Coward · · Score: 0

    Between Anthem, OPM, and Experian, we're nudging up on "almost everyone's SSN has been leaked" territory.

  32. This is good news by Anonymous Coward · · Score: 0

    Now I don't have to worry about my lost tablet or my Ashley-Madison account.

  33. The information actually stolen is far worse... by ethanms · · Score: 1

    The Washington Post reports that T-Mobile's Credit Partner, Experian, has been breached revealing names, addresses, Social Security numbers, birth dates, driver's license and passport numbers

    ...

    Both parties were quick to point out that no no credit card or banking data was stolen as part of the attack

    Great, so the banking and credit card data--which would only lead to fraud for which the individual would not be held accountable--wasn't stolen. But all the most valuable data for applying for fake credit and identity theft was! Much harder to fight off fake accounts then fake charges on a valid account.

    This should go beyond just two years of free monitoring... what do I do when someone is out there impersonating me? Hope I have an alibi when they come looking for mr, but that's sort of tough to do when you're a basement dwelling hermit...

    1. Re:The information actually stolen is far worse... by Jason+Levine · · Score: 1

      This should go beyond just two years of free monitoring... what do I do when someone is out there impersonating me? Hope I have an alibi when they come looking for mr, but that's sort of tough to do when you're a basement dwelling hermit...

      I'm an identity theft victim, albeit a lucky one who caught it early before too much damage was done, and it was scary when someone opened a credit card in my name. What's scarier, though, is if a criminal is arrested and gives your name/SSN/DOB. I used to read the blog of someone who was going through just that. He was fired from his job because he failed a background check, couldn't find a new job, and had police stalk him because they considered him a criminal (despite the fact that "his" mugshot looked nothing like him). Even when he got one department to remove his "conviction" from their records, it just flowed back from another police database. It took years before anyone would listen and years more before he started to make any real progress.

      Unfortunately, you can't stop this with a simple credit freeze like you can stop normal identity theft. In fact, there's no way to stop this at all. Any criminal with your name/SSN/DOB could give that information when they are arrested and pass their arrest record on to you.

      --
      My sci-fi novel, Ghost Thief, is now available from Amazon.com.
    2. Re:The information actually stolen is far worse... by HiThere · · Score: 1

      The hideous thing is that identity theft doesn't even need to be intentional. My wife got hit with the bill for a MAN who died in a hospital in a different city. They had the same name, but no other similar characteristics. And it STILL took years to fight through. The bank the hospital used sold the debt to a collection agency (well, more than one, actually) who wouldn't even take a death certificate as proof that she wasn't him.

      Say something bad about the financial credit system and I'll believe it without checking, after that experience. Say something good, and you'll need to prove exactly what you mean and the limits of your claim and provide very good evidence as to why I should believe you.

      --

      I think we've pushed this "anyone can grow up to be president" thing too far.
    3. Re:The information actually stolen is far worse... by Cederic · · Score: 1

      The bank the hospital used sold the debt to a collection agency (well, more than one, actually) who wouldn't even take a death certificate as proof that she wasn't him.

      Why bother to prove it to them? You've told them, they ignored you, what are they going to do next? Absolutely nothing unless they want suing into oblivion.

    4. Re:The information actually stolen is far worse... by HiThere · · Score: 1

      Because it goes into your credit history...and to get them to stop calling every half hour. (I exaggerate, but that's what it felt like.)

      --

      I think we've pushed this "anyone can grow up to be president" thing too far.
    5. Re:The information actually stolen is far worse... by Cederic · · Score: 1

      If it goes in your credit history, they've told lies about you. Sue them.

      If they keep harassing you, ask the police to arrest them for harassment.

    6. Re:The information actually stolen is far worse... by HiThere · · Score: 1

      I don't have a lawyer on retainer, so suing them would have cost me quite a bit. And it did, eventually, get straightened out. (I *was* thinking of suing them before we finally straightened things out, though. But collection agencies are in a different state...if they tell you where they are. They intentionally don't make things easy, as if you just pay them off they win.)

      --

      I think we've pushed this "anyone can grow up to be president" thing too far.
  34. Re:Still too much uncertainty of the size of expos by Anonymous Coward · · Score: 2, Informative

    Experian partitioned clients apart from one another. The breach hit their T-Mobile systems, which is why they are mentioning it only affects T-Mobile customers. But, you are right not to trust Experian, if it happened to one of their systems it could be happening as we speak to any other of their clients. It could also be happening to any of the other credit partners or banks as well and we'll find out in the coming years. My father used to work for a large bank, he would always tell me stories of breaches that occurred like people faking checks who were from Nigeria, etc. And, I asked why the banks weren't more proactive with their security procedures. He said it was because they do a cost analysis on and determine that there is an acceptable amount of risk, because securing your accounts is costly compared to the losses. I think that as these breaches increase in frequency in the digital age, that cost benefit analysis graph is going to turn upside down and not look as rosy anymore.

  35. NOT TWO YEARS by Anonymous Coward · · Score: 1

    I read the Experian notification of the breach.

    The _hack_ occurred over a "limited period of time". The _data_ that was exposed was from a two year time period.

    So, no one has been hacking Experian for two years continuously.

    Odds are really good that I'm affected, and believe me I know this doesn't make any difference :)

  36. Ironically by Anonymous Coward · · Score: 0

    I just received a letter from the IRS saying my personal information was inadvertently released (employee took a laptop home which they subsequently lost? I can't remember the specifics of this data breach and the letter didn't say), and they were going to pay for a year of Experian credit monitoring if I wished. Only it was up to me to contact Experian and give them some case number that was included in the letter to get the "free" year (note: not actually free, but using my own tax money to pay for it). So their solution to their lax security in storing my data, is for me to also give that data to another entity, not even a government entity, who apparently has equally lax security!

  37. Passport numbers?!?!? by cayenne8 · · Score: 1
    I'm puzzled at one blurb in the synopsis...PASSPORT numbers?

    WTF would they have passport numbers for a T-Mobile phone?!?

    It seems strange they'd even have a slot to store US passport numbers, considering that the vast majority of US citizens don't have or need a passport, eh?

    That just struck me as odd that they'd have this stored associated with a mobile phone credit application.

    --
    Light travels faster than sound. This is why some people appear bright until you hear them speak.........
    1. Re:Passport numbers?!?!? by Anonymous Coward · · Score: 0

      How can one not have a passport?

    2. Re:Passport numbers?!?!? by cayenne8 · · Score: 1

      How can one not have a passport?

      Well, not everyone travels out of the country, I'd dare say a LARGE majority of folks never leave their state much less leave US soil.

      If you're not leaving the country, why would you need a passport? And until the past couple years, you didn't even need a passport to run to Mexico or the Caribbean for the most part, just a drivers license and copy of your birth certificate, but after 9/11 that changed and you now need a passport. But I haven't left the country since those rules came to be, so I don't have a passport and don't foresee a need for one any time soon.

      --
      Light travels faster than sound. This is why some people appear bright until you hear them speak.........
    3. Re:Passport numbers?!?!? by rwa2 · · Score: 1

      Yeah, looked this up recently. Only about 1/3rd of US citizens even have a passport issued ever. That's no guarantee that they've even used it.

    4. Re:Passport numbers?!?!? by Anonymous Coward · · Score: 0

      Thanks for the explanation. It's interesting how different this is in the U.S. compared to Europe. It's propably a consequence of the U.S. being such a vast country and almost everyone having a driving licence.

    5. Re:Passport numbers?!?!? by Anonymous Coward · · Score: 0

      US is a pretty big country, and you can find environments ranging from arctic tundra to tropical rainforest. Used to be that you could cross the land borders (Canada and Mexico) with nothing more than a driver's license or birth certificate. Not like other parts of the world where the next country over is as close as the next state would be in the US.

    6. Re:Passport numbers?!?!? by cayenne8 · · Score: 1

      Thanks for the explanation. It's interesting how different this is in the U.S. compared to Europe. It's propably a consequence of the U.S. being such a vast country and almost everyone having a driving licence.

      Interesting. So, I take it many more people in Europe have passports? If so, I'm guessing because some of the countries over there are so small and from what I understand in one day you can drive and cross 2 or more country borders.

      For some reason, however, I'd thought with the EU formation, that you could freely travel between those countries over there pretty much like we do between states here.

      Also, are you saying that the majority of people in Europe don't have drivers licenses?? How do they all get around if they don't' have cars to drive?

      --
      Light travels faster than sound. This is why some people appear bright until you hear them speak.........
    7. Re:Passport numbers?!?!? by Anonymous Coward · · Score: 0

      Yes, having a passport (or an EU identity card, which is basically a credit card-sized passport) is more or less necessary. EU citizens can indeed freely travel between EU countries that have ratified the Schengen agreement, but most countries have laws stating that foreigners are required to carry identification at all times (although it is very rare that people actually have to show it). When travelling to countries outside the Schengen area (e.g. the UK, Ireland and many popular holiday destinations), presenting a passport at the airport is also required.

      The majority of people in Europe do have a driving licence, but it is not as universal as it is in the U.S. A significant fraction of adults do not have one. I suppose there are two main reasons. The first is that public transport is generally acceptable to good, especially in urban areas, so driving is not really required (though it is usually faster). The second reason is that driving tests are tough and driving lessons by a certified instructor are mandatory in most European countries, which makes it expensive to get a driving licence. Also, cars and fuel are more expensive than in the U.S. Many people, especially in urban areas, don't start driving learning to drive until well in their twenties or sometimes never at all.

    8. Re:Passport numbers?!?!? by Applehu+Akbar · · Score: 1

      The universal document in the US is the driving license. Even people who don't drive get an ID card issued through the licensing agency.

    9. Re:Passport numbers?!?!? by chilenexus · · Score: 1

      Also, the countries that get the highest number of American visitors didn't require a passport to visit until after the 9/11 fiasco. I've been to Mexico and Canada several times each where all that was needed was a drivers license. Today you need a passport to do the same.

    10. Re:Passport numbers?!?!? by Albanach · · Score: 1

      They have this thing where they demand a second form of ID - they ask for a driver's license number, or a passport number. I protested and they settled for a student ID number, which in hindsight was a smart move.

    11. Re:Passport numbers?!?!? by Cederic · · Score: 1

      from what I understand in one day you can drive and cross 2 or more country borders

      In one step I've left one country, crossed another and ended up in a third.

      But there are plenty of places in Europe where the quickest route from country A to B is via C, some countries so small that it takes a bad traffic jam to stop you crossing lengthways in a morning and generally it's pretty common to visit neighbouring countries on holiday, or even to go shopping or to visit friends.

    12. Re:Passport numbers?!?!? by khellendros1984 · · Score: 1
      Traveling between countries in Europe is generally similar to traveling between US states (at least at the borders I've crossed). You would still want to carry internationally-recognized ID, and a passport would fit that purpose.

      and from what I understand in one day you can drive and cross 2 or more country borders.

      Yep. Imagine driving across the Eastern states. There's been more than one day in my life where I've briefly visited three countries.

      How do they all get around if they don't' have cars to drive?

      Public transportation is pretty awesome, when well-implemented. A lot of people in Europe have cars, but a lot of them don't. If trains, streetcars, buses, and such suffice to get you where you need to go, why pay for the upkeep of your own vehicle?

      --
      It is pitch black. You are likely to be eaten by a grue.
  38. Thank God by Iniamyen · · Score: 1

    Thank God that only things like Social Security numbers were stolen - easily replaceable things like credit card numbers are still safe. Whew!

    1. Re:Thank God by Jason+Levine · · Score: 1

      Whenever I talk to my father about my identity theft and subsequent credit freeze, he tells me I should just change my SSN. Apparently, you *can* do that. However, it's not an easy process and I'd need to contact anyone who legitimately* has my SSN to update that. Once again, a criminal can do damage in one hour that the victim will be cleaning up for years.

      * SSNs shouldn't be used as unique identifiers at all so read "legitimately" to mean "they shouldn't need it, it shouldn't be a unique identifier, but the system is set up to require it and good luck trying to force them to change."

      --
      My sci-fi novel, Ghost Thief, is now available from Amazon.com.
  39. Oh boy. by ArylAkamov · · Score: 1

    Shit. I guess this might have something to do with a number of places telling me my SS# is either invalid or "has multiple names attached" (Why are multiple names attached to a single number even allowed? I would think it should return an error since there is no legitimate use for multiple names tied to a single number).

    1. Re:Oh boy. by Anonymous Coward · · Score: 0

      Hey, look at is an opportunity. You just have to steal an even better identity to use instead. Good luck!

    2. Re:Oh boy. by rickb928 · · Score: 1

      "there is no legitimate use for multiple names tied to a single number"

      They are called 'aliases'. I have three IRL, all caused by misspellings in the past.

      One on a store credit app, somehow they could not get my five-letter last name correct. Ignats.

      One on a debt collection report for a university in a state I had never set foot in. When I asked for my academic records and diploma in exchange for a $200 bookstore bill, they relented and only called me every three years.

      One on a mortgage app, which to this day persists despite being changed. They sold my data before the loan was even approved.

      Oh, and I use both my full first name and the contracted version that you can figure out. Maybe a fourth alias?

      There are lots of reasons to have more than one name recorded for your social security number and not all of them are within your power to even correct. Data has a life of its own./

      --
      deleting the extra space after periods so i can stay relevant, yeah.
    3. Re:Oh boy. by Anonymous Coward · · Score: 0

      That's nothing. Idiot Experian merged my database and my father's database over a decade ago. This has me working at Boeing when I was 10 years old and simultaneously dead and alive. Letters and phone calls have been fruitless.

      It's an interesting life....

    4. Re:Oh boy. by ArylAkamov · · Score: 1

      Thanks for the explanation, nobody else I have asked has been able to explain to me why there can be multiple names on a single SS#.

      What have you done to try and correct this?

      I went to the social security office and waited in line for ages only for them to tell me that this isn't their department (What?) and they can't help me. The only advice I have received is to file a police report and expect nothing to be done unless this starts seriously affecting my life.

    5. Re: Oh boy. by rickb928 · · Score: 1

      My sister and I have SSNs that are one digit apart; sequential; lsd.

      This causes problems. We cannot ever have accounts at the same damned bank, nor the same sort of credit at the same issuer.

      And no, this should not be a problem. Data is data.

      --
      deleting the extra space after periods so i can stay relevant, yeah.
    6. Re: Oh boy. by rickb928 · · Score: 1

      That is a good as it will get. SSA can't prevent those errors or criminal acts.

      --
      deleting the extra space after periods so i can stay relevant, yeah.
  40. Get NoScript by Anonymous Coward · · Score: 0

    Get NoScript, if you don't already have it.

  41. How about by TsuruchiBrian · · Score: 1

    How about 2 years of high credit scores.

  42. No big deal by tehlinux · · Score: 1

    >revealing names, addresses, Social Security numbers, birth dates and driver's license and passport numbers for any customer

    but no credit card numbers or banking data (other than your names, addresses, Social Security numbers, birth dates and driver's license and passport numbers)

    >Experian is offering credit for two free years of identity resolution services and credit monitoring

    Were you really planning on living longer than that?!

    --
    Most linux users don't know this, but the man pages were named after Chuck Norris. Chuck Norris fsck'ing hates noobs!
  43. The Unforgiven by Sir_Eptishous · · Score: 1
    --
    We play the game with the bravery of being out of range
  44. Re:Who is monitoring us here at Slashdot? by Anonymous Coward · · Score: 0

    Plus the unholy G-fecta of Google DoubleClick, Google AdWords, and Google Analytics. Slashdot has really started piling on the ads and trackers lately. Ghostery doesn't block the player.ooyala.com junk yet, so I've done that at my edge name server (which handles wildcards and is far better than a h-sts file, lest our resident spamming kook get any ideas).

  45. Re:Still too much uncertainty of the size of expos by Anonymous Coward · · Score: 0

    working in financial industry, many B2B transactions use dedicated accounts... so T-M uses a different account than XYZ, when transferring data with Experian.

  46. Can't log into slashdot by Anonymous Coward · · Score: 0

    There is no obvious button to log into slashdot now so here I am anon. Maybe this has something to do with /. being up for sale? I wanted to comment on this story but not as anon. Don't believe me? Log out, then log back in if you can and tell me about it.

  47. Re:Still too much uncertainty of the size of expos by idontgno · · Score: 1

    Ah, "dedicated accounts." That's just exactly like physical isolated network and storage architectures, right? So that if a cracker has, let's pretend*, a whole two years to poke around, they can't get through the impenetrable internal partitions between accounts.

    *facepalm*

    Air gap or GTFO.

    *And by "pretend", I mean "since they actually had two years undetected"...

    --
    Welcome to the Panopticon. Used to be a prison, now it's your home.
  48. My "Experiance" by Anonymous Coward · · Score: 1

    I am posting anonymously because my company just cancelled a project with Experian. It started bad, and got worse and worse.

    You may not know this, but Experian is trying to start a mailing list service, like Mailchimp. I work for a large broadcasting company, and we signed up to switch to their mailing lists. What scared the crap out of me is that we weren't just giving Experian an email address and subscribe/unsubscribe information for each mailing list. We were handing over pretty much all of the demographic data we had collected.

    Think about this for a minute. Experian, the credit rating company, was being given information about your personal likes and dislikes. I could already imagine them saying, "This person likes rap music. Lower their credit rating." or, "This person only reads conservative news. Looks like a good ol' boy to me."

    Fortunately, for now, Experian turned out to be totally incompetent. Their "API" was a joke, and the beautiful, fully featured front-end interface that the had "demonstrated" turned out to not exist at all. We dropped the project after converting one station, and now we are fighting to get out of the contract we signed.

  49. Free credit reports for 6 years by alteran · · Score: 1

    It's now been 6 years since I've had to pay for credit reports because of all the breaches my data has been involved in.

    --
    Who is RTFM and when will he help me with Unix?
  50. well by superwiz · · Score: 1

    At least, they have a sense of humor about it. "But no credit card numbers were stolen"? Who would need that after they have your SSN, full name, address, birthday, driver's license and PASSPORT NUMBER? That's enough to have any credit card you want. Wait, they don't have a sense of humor, do they? They are not kidding, are they? They really do think this cloud has a silver lining? Oh, what the hell. If the Secretary of State can send emails through an unsecured server, and the IRS has a 6-month's data retention policy and can get away with claiming 6 simultaneous employees' harddrives crashed right after receiving subpoenas, maybe Experian does get to get away with "but no credit card numbers were stolen" bull shit.

    --
    Any guest worker system is indistinguishable from indentured servitude.
  51. It's bank fraud, not identity theft by Anonymous Coward · · Score: 0

    There is no national system to prevent credit from being authorized in your name, even to aliens from other worlds.

    Nor should there be, because it should not be your fault that someone has lax rules for giving out money to people. The fault lies squarely with the institution extending the credit, no one else.

    The industry has framed this issue in the wrong way. It is not identity theft. It is BANK FRAUD, pure and simple. It should not be people who need to protect their "identity" or fight to prove they were not parties to a contract that they were not even aware of being made in their name. It should be banks and financial institution who should bear the burden and loss.

    Why is identity theft not such a big deal in Europe or other countries ?

  52. Received 700+ job offers by most top companies for by Anonymous Coward · · Score: 0

    Data Talent is almost non existent in the US. Google, YouTube, Yahoo, Facebook, ADP, Twitter, Rakuten, Eucalyptus, Tesla, Auction.com, Pythian, Accenture and most major companies all have been desperately searching for data architects. Eg: Yahoo remained in negotiations for three years for rearchitecting their Yahoo Mail and Messenger. The recruiters these companies have and the top bosses all get overwhelmed when they do find a qualified candidate, scared they may lose their job if they hire the qualified person. If 700 companies approach the same data guy what does that tell you? in Maryland, thousands of data and network security jobs remain unfulfilled for years now. Data is misunderstood. I know this because I am the only one to claim having scaled a failing company to top 10 world ranking and having recovered from a $100M disaster when the storage company responsible (3par) and database software creator (Mysql) both gave up. See the number of data breaches in CA (the seemingly place of innovation in data and tech) and you will be surprised. Read the Verizon's annual data breach report and that will show you that data and network admins are just filling 9-5 time and not taking their jobs seriously. There is no company that provides data and security audit to protect against breaches like this. The CE*s have fallen too far behind to be aware of handling and running companies that handle personal data in large amounts.

    Take this case and ask (yourself or experian):
    What were the network/data/system admins doing for these two years?
    What about monitoring services? How can experian provide monitoring service for your credit protection if it can't monitor its own systems. Experian is not in credit business , it's in data business. There ought to be severe penalties for providing what seems like fraudulent data protection service. Laws governing companies like this and data auditing requirements (but there are no companies qualified to do that). The consequences of this breach are grossly misunderstood. These 15,000,000 people will be dealing with consequences for a long time since you can't just change your social security number or passport or birth date. The breached data is going to be sold, resold and used for an indefinite period of time. Expect similar breach reports from all major companies in the coming months and years. Personal data is an oil like accountable asset according to World Economic Forum. Sadly Experian is just going to walk away with no major changes in its tech or data leadership. At most they will hire someone from academia with no real world experience. Remember a different experience set is required for building a car, racing that car, repairing that car and architecting the race course where race will happen. Google at one point offered me three choices: join their YouTube, Adwords, or search division stating that they are like a car that's going really fast and needs a change of all its tires as it prepares to go faster and while keeping passengers safe. They told me to not post these words but I am doing so anonymously without pointing the person out to communicate one point: data talent is almost non-existent and recruitment plus insecurity of the ones recruiting are preventing companies from getting the talent they so desperately need.

  53. It's a lifetime of damage... by Anonymous Coward · · Score: 0

    And if you're one of the bad guys, you know to wait two years now.