A Boston news station recently interviewed a local man who had his Experian account hijacked after he'd frozen his credit with the big three consumer reporting bureaus. It's unbelievable that Experian still hasn't done jack about this problem that I've written about ad nauseum for years now. (try to ignore the many typos and grammar errors in this story).
Experian's system will allow anyone to assume control over your credit file and freeze merely by re-registering as you using your name, SSN, DoB but a different email address than the one on file. Experian has no problem approving that request, and instead of seeking approval from the existing email address and or phone number, they just say okay. Thieves can then unlock your credit, pull your file, apply for credit, etc. But they will send an automated email to the legitimate account holder's email, saying the account's email address has been changed. No "this wasn't me" option, no asking for approval. Nope. They just say hi we changed your email. Have a nice day!
Experian's response to the Boston news outlet is particularly infuriating, because they're basically saying the system operated as designed. Nevermind that the system is batshit crazy from a security in 2025 perspective.
"A spokesperson told us their protocols worked since Deyoe got that notification when his account was changed. In a written statement Experian said “Protecting consumers’ identities is among our highest priorities. We believe this is an incident of fraud using stolen consumer information.”
Past coverage of this:
https://krebsonsecurity.com/2022/07/experian-you-have-some-explaining-to-do/
https://krebsonsecurity.com/2023/11/its-still-easy-for-anyone-to-become-you-at-experian/
Experian, You Have Some Explaining to Do
Twice in the past month KrebsOnSecurity has heard from readers who've had their accounts at big-three credit bureau Experian hacked and updated with a new email address that wasn't theirs. In both cases the readers used password managers to select…krebsonsecurity.com
Nick Danger
in reply to BrianKrebs • • •birdpoof
in reply to BrianKrebs • • •Chewie
in reply to BrianKrebs • • •25 Investigates: Sutton man turned to credit bureau for credit protection, it led to identity theft
Kerry Kavanaugh (Boston 25 News)Fi 🏳️⚧️
in reply to BrianKrebs • • •Given how all that information - name, DOB, SSN, etc. - is now presumed "in the wild" due to the massive ongoing breach of federal systems,
I would dearly like to see a class action suit start against Experian for those of us who are suffering the consequences of their negligence in system design and non-conformance with extant industry standards for IAM.
Rupert
in reply to BrianKrebs • • •Otte Homan - remember Geordie
in reply to BrianKrebs • • •Iris Young (he/they/she) (PhD)
in reply to BrianKrebs • • •Jim Luther
in reply to BrianKrebs • • •BrianKrebs
in reply to BrianKrebs • • •Dan Hugo (แดน)
in reply to BrianKrebs • • •It´s the 21st century (in some places), why are we (in the US anyway) tied to the ol´ SSN, never intended for any of this, which cannot (per policy) be changed 99.9% of the time?
Report your credit card compromised/lost/stolen and you have a new one in a week.
Though, I suppose now we can just tweet Elon and have his interns make those changes…
Jeff Atwood
in reply to BrianKrebs • • •Designing For Evil
Jeff Atwood (Coding Horror)hallunke23 🇺🇦
in reply to BrianKrebs • • •Katrina Katrinka :donor:
in reply to BrianKrebs • • •You can freeze your credit for free and then temporarily unfreeze it when you need to use it.
https://www.consumerfinance.gov/ask-cfpb/what-does-it-mean-to-put-a-security-freeze-on-my-credit-report-en-1341/
What does it mean to put a security freeze on my credit report? | Consumer Financial Protection Bureau
Consumer Financial Protection BureauZippoman924
in reply to BrianKrebs • • •Mathaetaes
in reply to BrianKrebs • • •Jeff Atwood
in reply to BrianKrebs • • •Phil Stevens :tinoflag:
in reply to BrianKrebs • • •hallunke23 🇺🇦
in reply to BrianKrebs • • •Petesmom
in reply to BrianKrebs • • •#Experian
#CreditReport
#Ransomware ?
SpaceLifeForm
in reply to BrianKrebs • • •I notice that the preview is blocked for my instance.
Not that I need to go there anyway, because I know the story. The credit reporting agencies are all a scam to collect updated PII from people that get magically get awarded 2 free years of credit monitoring via some class action lawsuit you were not aware of in the first place.
If you get an offer for this free credit monitoring, throw it in the trash.
It is not free. They will sell your PII.
#infosec
Red Hood
in reply to BrianKrebs • • •h4nd / UntouchedCupOfTea
in reply to BrianKrebs • • •Axel Hartmann
in reply to BrianKrebs • • •Louise Auerhahn 🏳️🌈
in reply to BrianKrebs • • •I filed a complaint against them with the CFPB last December, but with Elon Musk and his frat boys running amuk with our public dollars and data, that likely isn't going anywhere.
Cat West
in reply to BrianKrebs • • •