Emily Scarr
Senior Advisor, Maryland PIRG
Senior Advisor, Maryland PIRG
Maryland PIRG
“Yesterday’s announcement of a data breach affecting at least 500 million Yahoo! accounts two years after the fact raises troubling questions about how the breach was able to take place, especially after a breach of 450,000 of its accounts in 2012, and why it took so long to discover and announce. It is troubling that the breach was only discovered after a review of its security systems in response to an unconfirmed claim of a separate breach. Although it failed its responsibility to protect its users, Yahoo has an opportunity to provide the most consumer friendly response to one of the largest breaches of its kind by alerting its users to the benefits of credit freezes and offering to pay for credit freezes with all three major national credit bureaus.
A credit freeze is the only way to prevemt identity theft before it happens. All other types of identity theft and fraud, at best, can only be detected after the fact. The services and steps that are most offered and recommended to consumers, like credit montiroty, only detect identity theft or fraud but don’t stop it.
The types of stolen information, which appear to include names, emails addresses, telephone numbers, dates of birth, and in some cases, encrypted or unencrypted security questions and answers, do not appear to be the types of information that can directly be used to commit existing or new account identity theft.
However, the information stolen in this breach could be used to “phish” or gather additional information that can be used to access existing credit accounts or create new credit accounts. Everybody, whether they have a Yahoo account or not, should be on the lookout for suspicious emails asking for verification of or submission of even more personal information.
It is imperative that Yahoo’s response to this breach not fall through the cracks as its acquisition by Verizon Communications is finalized. We agree with Yahoo in recommending its users change passwords and be on the lookout for suspicious activity on other online accounts.
Yahoo should also alert its users to the benefits of credit freezes and offer to pay for credit freezes with all three major national credit bureaus. Such a response would be the most consumer friendly response to a major data breach and would be a huge advancement for identify theft prevention in our country. Due to huge marketing pushes by credit monitoring services that only alert consumers to fraud after the fact, most Americans are not aware that they can actually prevent id thieves from opening new credit accounts in their names in the first place by placing freezes on their credit accounts at all three national credit bureaus. Credit freezes help prevent new account identity theft because they keep potential creditors from seeing consumer credit history, without which new accounts are typically not opened.
In the 2016 session of the Maryland General Assembly, Senator Lee and Delegate Waldstreicher introduced legislation to provide free credit freeze’s to security breach vicitms. Maryland Attorney General Brian Fosh supported the bill.Just as Maryland was among the first states, in the 1990s, to provide free access to credit reports, it should also provide more consumers more free access to credit freezes as the bill would provide to security breach victims (identity theft victims already can obtain free freezes).