Another Massive Credit Reporting Database Breached By Criminals
from the 'opting-in'-by-existing dept
Lots of companies like gathering lots of data. Many do this without explicit permission from the people they're collecting from. They sell this info to others. They collect and collect and collect and it's not until there's a problem that many people seem to feel the collection itself is a problem.
The Equifax breach is a perfectly illustrative case. Lenders wanted a service that could rate borrowers quickly to determine their trustworthiness. This required a massive amount of data to be collected from numerous creditors, along with personally-identifiable information to authenticate the gathered data. The database built by Equifax was a prime target for exploitation. That this information would ultimately end up in the hands of criminals was pretty much inevitable.
But Equifax isn't the only credit reporting service collecting massive amounts of data but failing to properly secure it. TransUnion not only collects a lot of the same information, but it sells access to cops, lenders, private investigators, landlords… whoever might want to do one-stop shopping for personal and financial data. This includes criminals, because of course it does.
From January to June 2018, seven members of [Tony] Da Boss’ gang pleaded guilty to various identity theft charges. In total they had caused about $1.2 million in damage, using stolen identities to buy luxury cars and iPhones and to lease apartments in Charlotte. Both they and their crimes would have been quickly forgotten as garden variety larceny were it not for the way they stole those identities.
Cops alleged Da Boss and his co-conspirators had access to the Holy Grail for any Internet-age scam artist: a surveillance technology that police and debt collectors use to track most of the United States’ 325 million inhabitants via their Social Security numbers, license plates, address histories, names and dates of birth. The mass-monitoring tech, called TLO, is a product of the Chicago-based credit reporting giant TransUnion, which last year had revenues of nearly $1.9 billion. One brochure for the service promises access to a startling amount of personal data drawn from myriad sources: more than 350 million Social Security numbers of dead and living Americans, 225 million employment histories and four billion address records. Add to that billions of vehicle registrations and call records and you have one of the largest commercial surveillance databases in existence.
The only thing surprising about this is that it only resulted in $1.2 million in damage. The database -- originally designed to help hunt down child predators -- promises users a "360-degree profile of virtually any person, business or location in the US." In addition to the wealth of personal and financial data, the database also includes surveillance cam photos and license plate numbers, which makes it even more attractive to government agencies and the occasional criminal.
One of the charged suspects worked for a debt collection firm, selling off personal info to criminals for $100/victim. The rest of the gang's access relied on swiped credentials. TransUnion is making millions authenticating US residents who can't even opt out of its collection. But it's not doing much to ensure only authorized users are accessing its system.
Live by the tech, die by the tech.
In June last year, Postal Service investigator Berkland obtained a warrant ordering Google to hand over all the data related to [the gang's Nest] cameras. The company complied, shipping surveillance footage back, along with personal details of its owners. It’s the first known case in the United States in which a federal law enforcement agency has demanded information from a Nest provider, and it has obvious implications for anyone who has purchased a smart home appliance that contains a camera or a microphone.
Unhappily, TransUnion told Forbes this wasn't the first time criminals have gained access to its TLO database. And it certainly won't be the last, either. The privacy and security of Americans is in the hands of companies who collect this information without their permission and which can seldom be bothered to treat this massive stash of personal info with the respect it deserves.
Thank you for reading this Techdirt post. With so many things competing for everyone’s attention these days, we really appreciate you giving us your time. We work hard every day to put quality content out there for our community.
Techdirt is one of the few remaining truly independent media outlets. We do not have a giant corporation behind us, and we rely heavily on our community to support us, in an age when advertisers are increasingly uninterested in sponsoring small, independent sites — especially a site like ours that is unwilling to pull punches in its reporting and analysis.
While other websites have resorted to paywalls, registration requirements, and increasingly annoying/intrusive advertising, we have always kept Techdirt open and available to anyone. But in order to continue doing so, we need your support. We offer a variety of ways for our readers to support us, from direct donations to special subscriptions and cool merchandise — and every little bit helps. Thank you.
–The Techdirt Team
Filed Under: breach, credit, database, tlo, tony da boss
Companies: transunion
Reader Comments
Subscribe: RSS
View by: Time | Thread
Equifax
as I got a nice mail for Dish..and decided to ask them to QUIT sending me this crap..
I looked up the fine print and to be removed for the mailing list..
I had to call EQUIFAX..
Nuff said.
[ link to this | view in chronology ]
Re: Equifax
.... you know what to do.
[ link to this | view in chronology ]
Re: Re: Equifax
Do they still do that? It was fun for a while, and then all the postal spammers targeting me stopped including reply envelopes. And of course they're sending it at bulk rates so "return to sender" won't work.
[ link to this | view in chronology ]
To be a bit pedantic, should it be called identity THEFT? It's not really taken. More like copied.
[ link to this | view in chronology ]
Re:
A better term would be “identity fraud”, but banks and other institutions prefer “identity theft” because it implictly puts the blame on the victim for having their identity “stolen” rather than the institutions being defrauded for not doing due diligence to prevent the fraud.
[ link to this | view in chronology ]
Re: Re:
[ link to this | view in chronology ]
Re: Re: Re:
[ link to this | view in chronology ]
I can’t give you a “sad but true” vote, so have an Insightful vote instead.
[ link to this | view in chronology ]
Re: Re: Re: Re:
[ link to this | view in chronology ]
Re: Re: Re: Re: Re:
[ link to this | view in chronology ]
These corporations make tons of money from having our data & they treat it like toilet paper leaving citizens to deal with the shit that gets stuck to them.
[ link to this | view in chronology ]
Re:
[ link to this | view in chronology ]
break it
[ link to this | view in chronology ]