BankThink

Equifax breach is a 'lifetime risk' for victims

The massive Equifax breach has captured the headlines for days, and for good reason.

The magnitude of this breach is unprecedented and unlike a breach that involves credit card data, these millions of victims will be at increased risk of fraud for the rest of their lives.

You cannot get a replacement Social Security number because your service provider had inadequate security measures.

Equifax logo
A monitor displays Equifax Inc. signage on the floor of the New York Stock Exchange (NYSE) in New York, U.S., on Friday, Sept. 8, 2017. The dollar fell to the weakest in more than two years, while stocks were mixed as natural disasters damped expectations for another U.S. rate increase this year. Photographer: Michael Nagle/Bloomberg
Michael Nagle/Bloomberg

Given the frequency of major breaches, it’s understandable if consumers are suffering from breach fatigue and not paying a lot of attention.

But this breach is especially alarming and serious. Almost all the data that credit reporting companies like Equifax hold is sensitive, and much of it is used to establish identity, such as birth dates, addresses and driver's licenses, and other data types are routinely used to verify identity.

It’s one thing to ask a consumer to change a password, but how do you change your birth date?

This also highlights that web applications remain a major vector of attack. Even as vulnerabilities are found and patched, hackers are developing new fileless techniques to fly under the radar of most security tools. It’s no longer adequate to base security defenses on past attacks. We need to shift to real-time monitoring and security for web applications and all the processes that support them.

It’s clearly early days for this news, and we can expect to learn more about the details in the future. With nearly every publicly announced breach, there’s new information discovered after the initial disclosure.

The best time to develop a response plan for a breach is well before one occurs. Information security teams at other organizations should use this incident as an opportunity to evaluate their own plans. All organizations that collect and store sensitive data are targets.

Doing the basics right, such as ensuring secure configurations, managing vulnerabilities and capturing log data, is the most effective way to prevent breaches.

A breach isn’t a single point in time, but a span of time in which an organization is compromised. Prevention is primary, but detection and response are absolutely necessary as well.

For reprint and licensing requests for this article, click here.
Data breaches Digital payments Retailers Equifax PayThink Conference ISO and agent
MORE FROM AMERICAN BANKER

Acting CFPB Director Russ Vought has managed to neuter the Consumer Financial Protection Bureau through a series of actions. Senate Banking Committee Chairman Tim Scott, R-S.C., played a major role by cutting funding in half.

3h ago
7 Min Read
CFPB exterior no signage 4

Federal Reserve Chair Jerome Powell said there was a "high degree of unity" among committee members during this week's Federal Open Market Committee vote. Out of 12 FOMC members, 11 voted for a 25 basis point cut.

September 17
4 Min Read
Jerome Powell

The Federal Open Market Committee's decision to reduce interest rates for the first time in nine months lifted bank stocks Wednesday. The 25-basis-point reduction could lead to net interest income headwinds now, but loan growth later, analysts said.

September 17
4 Min Read

Community Financial in Syracuse has made its biggest investment ever in an outside company, taking a $37.4 million equity stake in an insurance provider that focuses on the rental housing market.

September 17
4 Min Read
syracuse, new york

St. Cloud Financial Credit Union will be issuing its own stablecoin at the end of this year, becoming one of the first U.S. credit unions to do so.

September 17
4 Min Read
BankThink on increased need for AML with stablecoins

The two BNPL giants' pay-over-time loans will now be available for in-store purchases on Apple Pay in a move to capture more sales at brick and mortar stores.

September 17
3 Min Read
Apple Pay