How to protect yourself after the Equifax data breach

equifax data breachFollowing the news of the hurricanes, news of the Equifax security breach has been all over the news. Financial data of 143 million Americans has been stolen, and in many cases it means that the victims are at-risk of becoming victims of identity theft for the remainder of their lives. That’s right, you, and if you have them, your children, could be at risk for the rest of your life. The hackers got names, Social Security numbers, birth dates, addresses, credit card numbers, and some driver’s license numbers.

The breach ticks me off – this never should have happened. Clearly Equifax has some major vulnerability in their system which they should have known about and protected. A credit bureau should be utilizing the highest level of security at every level. Your information with them should be as secure as a vault. On top of that, to add insult to injury, three of Equifax’s executives (including the CFO) sold nearly $2 million worth of stock after the breach, but before they told the public about it. That’s right – here’s a timeline for you:

  • Between mid-May and July, 2017 – breach happens
  • July 29, 2017 – the hack was discovered
  • Aug 1-2, 2017 – executives sell almost $2 million worth of stock
  • Sept 7, 2017 – the public is informed of the breach (thank you, Equifax, for waiting more than a month before letting us know)
  • Sept 8, 2017 – Equifax stock drops by double-digits

Equifax cliams that these executives had no knowledge of the hack when they sold their shares, but I don’t buy it. You’re telling me the CFO didn’t know about this? If he didn’t know, then who did? I’m sure that the timing of the sale will be part of any investigation.

The breach has happened, though, and you need to take specific steps to be sure you protect yourself. Let me warn you now, the few hours you spend on this are not going to be the most fun, but it is critical you take care of it now. It will be much, much worse if you wait and are a victim of identity theft.

I’ll try to make it as easy as possible for you with links and instructions.

  • First, don’t sign up for the protection that Equifax is offering. It’s garbage and only lasts a year, and, unless you opt-out of it, means you can’t be part of suing Equifax later on. I also don’t trust the company that just had the biggest data breach in history to be able to protect my data. Pass. Due to the severity of the breach, they should offer identity theft protection for life.
  • Sign up for Credit Karma (https://www.creditkarma.com/). You will get free credit scores and free monitoring of your credit reports. If anything unusual happens, they will contact you. It’s a free service and you should sign up for all adult members of your family.
  • Credit Karma logo

  • Place a credit freeze on all three of your credit bureau files. A credit freeze is THE SINGLE MOST IMPORTANT THING YOU CAN DO TO PROTECT YOURSELF. It literally locks your credit bureau files so NO ONE, including you, will be approved for new credit. A thief could have your information and they will apply rapidly for credit, all of which will be denied. They will eventually move on. Depending on the state you live in, there will be a $0-$15 fee to set this up, and you need to do this for each adult member of your family.Here are the links:
    https://www.freeze.equifax.com/Freeze/jsp/SFF_PersonalIDInfo.jsp
    https://www.transunion.com/credit-freeze/place-credit-freeze
    https://www.experian.com/freeze/center.html

    Because millions of people are setting these up the systems are not all working. I was able to set up Equifax and Experian, but not TransUnion. I will keep trying throughout the next day or so, and if it doesn’t work I will take care of it via mail.If you need to apply for credit later, you can un-freeze your reports for a limited period of time, after which is will re-freeze.

  • Place a fraud alert on your accounts. This is simply an extra step that puts an alert on your credit report that you might be a victim of identity theft, and that they need to call you before any transactions can be approved. It only lasts 90 days, but you can put the alert on there repeatedly. I already have a note on my calendar 90 days from today to renew the alert. You only need to place the alert with one company then they will place the alert with the other two. I recommend you use TransUnions fraud alert system – I found it to be the easiest one: https://www.transunion.com/fraud-victim-resource/place-fraud-alert
  • fraud alert

  • Sign up for Zander Insurance identity theft insurance. For $145 a year it protects your entire family, including your children. They have a 100% recovery success rate and protect you against all types of ID theft, including tax fraud, medical ID theft, and, of course, financial fraud. If your identity is stolen as a result of the Equifax, or any other breach or identity theft, they will take over and fix everything. It is well worth every penny. You can sign up for that here: https://www.zanderins.com/idtheft2
  • logo_zander

  • Speaking of children, does it make sense to freeze their reports? The credit bureaus don’t want you to be able to do that, but some states have made it mandatory. All three bureaus are falling in line, but none will allow you to do it online. TransUnion will do a search, for free, to see if your children have credit reports. You can find that here: https://www.transunion.com/credit-disputes/child-identity-theft-inquiry-form.
  • Utah is taking things one step further – they have set up a Child Identity Protection Program through the Attorney General’s office that registers your children’s Social Security numbers as a number belonging to a minor, which will help protect their data. You can find that program here: https://cip.utah.gov/cip/SessionInit.action. If you live in a different state encourage your attorney general to create a similar program. Because I live in Utah and have this option, along with the Zander protection, I don’t feel that I need to freeze their credit, but if I lived outside of Utah I would absolutely take that step.
  • utah cip

  • Because credit card numbers were stolen, I recommend calling the toll-free number on the back of each credit card you have and requesting a new number. It’s a pro-active step you can take to prevent unauthorized charges in the future.

Again, I realize this isn’t fun – it’s a lot of work to set these things up, but I wouldn’t delay. Take a couple of hours today and get all of this done. Taking these steps is like building a brick wall between you and identity thieves.

Share this:
Facebooktwitterpinterestlinkedinmail

Are You Financially Fragile?

What would happen to you and your family if:

  • your fridge broke down?
  • your car transmission went out?
  • the primary breadwinner in your family dies?
  • the primary breadwinner in your family becomes disabled?
  • the Social Security fund goes bankrupt and you will no longer receive a Social Security check?

As many as 76% of Americans live paycheck-to-paycheck – they have little to no savings and they spend more than they earn each month. These people are the Financially Fragile.

Financially FragileWhen one of the above events happens it can be challenging for anyone, but it is devastating for the Financially Fragile.

If you are living this way, you can take a few steps to become Financially Resilient. Being Financially Resilient means that you are able to withstand or recover quickly from difficult financial conditions, such as your car transmission going out. Again, that can be difficult for anyone, but the Financially Resilient will recover quickly while it can destroy the Financially Fragile.

Here are some things I recommend to start down the path to becoming Financially Resilient:

  • Have an emergency fund – start out with $1,000
  • Use a budget[i]
  • Spend less than you earn
  • Have adequate insurance
  • Pay off debt
  • Use a Revolving Savings account[ii]
  • Have some “fun money” or “mad money”
  • Pay attention to your credit score[iii]

For more information on these topics, see the links below. I encourage you to take steps to become more Financially Resilient.


[i] http://blog.ryanhlaw.com/wp-content/uploads/2017/02/MFH-Guide-to-Budgeting.pdf

[ii] http://blog.ryanhlaw.com/revolving-savings/

[iii] http://blog.ryanhlaw.com/know-your-score/

Share this:
Facebooktwitterpinterestlinkedinmail

Identity Theft Monitoring and Insurance Plans

In my last post I discussed identity theft – what it is and how to prevent it.

What about identity theft monitoring or insurance? Does it make sense to purchase it?

An important note up front – no product or company can protect you from having your information stolen. The most common way your data is stolen is through data breaches. If you have a Yahoo account, for example, some of your data has already been stolen and, as we have learned recently, it has probably been sold several times over.

That doesn’t mean there aren’t steps you can take to secure your information better (see last post for ideas), but having identity theft “insurance” doesn’t prevent your data from being stolen any more than having auto insurance keeps you from being involved in an accident.

Let’s take a look at each of the various types of identity theft protection – monitoring, insurance and recovery.

MONITORING SERVICES

Monitoring services alert you when someone else might be using your information. Services generally include:

  • Tracking activity on your credit report
  • Sending you an alert when your personal information (bank account, Social Security number, driver’s license number, passport or medical ID) is being used
  • Access to credit reports and/or scores

No company or service can monitor all activity on all websites and merchants, but most of these companies do their best to monitor your personal information at as many places as possible.

IDENTITY THEFT INSURANCE

Identity theft insurance pays for out-of-pocket expenses incurred for recovery, which may include:

  • Postage, copying and notary fees
  • Less often, lost wages and legal fees

A few important notes about identity theft insurance:

  • This type of insurance almost never covers stolen money or other financial losses
  • There is generally a deductible
  • There is no payout if the loss is covered by any other types of insurance, such as homeowner’s or renter’s insurance
  • The majority of people who are involved in identity theft have almost no out-of-pocket losses. Most people pay little to nothing to copy or print things at home, postage is cheap and notary services are usually free at your bank. By the time your deductible kicks in you are unlikely to gain anything.

RECOVERY SERVICES

Recovery services help you deal with the effects of identity theft after it happens. Services generally include:

  • Assigning a case manager to help you work through the process
    • With some plans you actually grant authority for the case manager to act in your name, with others they guide you through the process
  • Placing a fraud alert on your credit file
  • Placing a security freeze on your credit file
  • Helping you prepare letters to send to collectors
  • Closing any tampered or fake accounts and opening new ones

Let’s take a look at two specific companies – LifeLock and Zander Insurance.

LifeLock[i]

Standard protection is $10 a month or $109 annually. Prices go up to $29.95 a month for premium services.

Basic services include:

  • Website surveillance
  • Cancel credit cards if stolen
  • Send alerts when your information is being used
  • Replace stolen funds up to $250,000 (only what the bank won’t replace)
  • Spend up to $1,000,000 on lawyers, accountants or others to restore your previous status

Zander Insurance

Zander is $75 year ($6.76 a month) for an individual or $145 a year ($13 a month) for family protection.

Zander operates their protection plan on the premise that financial identity theft is only one of more than 15 types of identity theft. There is also Social Security, criminal, employment, medical, tax refund and other types of fraud, many of which won’t be discovered by monitoring. In many cases you won’t know you have been a victim until you get a letter from the IRS or a doctor bill or even a warrant for your arrest.

Their focus is on identity theft recovery. Services provided include:

  • Up to $1,000,000 reimbursement for any stolen bank funds or unauthorized electronic funds transfer (only what the bank won’t replace)
  • Unlimited legal fees if needed
  • $0 deductible
  • Contact banks, bureaus, insurance companies and doctors for you

What I Recommend

No strategy is perfect, but this is my plan:

  • Use CreditKarma.com for monitoring (they send me an e-mail anytime something changes on my credit report)
  • Use YNAB (youneedabudget.com) to review my bank and credit card transactions daily
  • Shred any documents with financial or personal information
  • Use https://www.optoutprescreen.com/ to stop receiving most pre-screened credit card offers
  • Put a security freeze on my credit bureau reports
  • Check one credit report every 4 months on annualcreditreport.com
  • Copy the front and back of all cards in my wallet
  • Use a service such as LastPass.com to manage and use different, secure passwords on each website
  • If my wallet is stolen or I am a victim of a breach place a 90-day fraud alert on my credit bureau accounts
  • Sign up for Zander’s plan for recovery services (I believe it is worth the $145 a year for the services they will provide)

If you have taken all of these steps but choose not to sign up for recovery services, the FTC has created a new website that will help you recover. It generates pre-filled letters and walks you through exactly what you need to do to recover. You can find the website at http://www.identitytheft.gov.

 

 

Identity Theft Protection

[i] For both LifeLock and Zander be sure to review their services before signing up. Services may have changed since this article was written.

Share this:
Facebooktwitterpinterestlinkedinmail