Equifax lost data on people who never signed up

A credit bureau, an unpatched tool, and why a unique password would not have saved you.

Article · 0 clicks

Equifax lost data on people who never signed up

A credit bureau, an unpatched tool, and why a unique password would not have saved you.

In 2017 Equifax, a credit bureau, announced a breach that reached something like 147 million people. Names, dates of birth, Social Security numbers, some licences and cards. The company had left a hole in a web tool unpatched after a fix was available. That sentence is the whole technical plot. The rest is what happens when a firm that exists to store identity stores it badly.

You did not have an Equifax account

A lot of the victims never signed up. Bureaus collect. That is the business. So the usual advice “use a unique password on that site” does not even apply. The data was about you because you had a financial life in the US, not because you clicked a bad coupon.

If you live elsewhere, similar piles exist under other names. The feeling is the same: a stranger lost a file that can open credit in your name.

What “be aware” looks like after a bureau leak

Freeze credit where that exists. Treat unexpected loans and SIM swaps as related, not random. Tax season scams love the year after a big identity dump. Anyone who emails “we are Equifax, click to check if you were affected” is running the second crime on the back of the first.

Use a password manager going forward anyway. It will not un-dump a Social Security number. It will stop the next forum leak from opening your mail.

Equifax paid fines and ran a tired compensation site. Your job is narrower: assume those identifiers are out, watch for new accounts you did not open, and do not hand extra copies of ID to a helper who only exists because the news is hot.

Back to Learn