Saskatoon StarPhoenix

Mother and son fall victim to Equifax Canada hack

Duo still fear danger of identity theft after receiving letter notifying them their data had been breached

- ARMINA LIGAYA The Canadian Press

Robin Harvey thought she was being financiall­y prudent when she urged her son to sign up to monitor their credit files at Equifax Canada in 2013.

Her son was graduating from university at the time, and the former journalist pushed him to keep a close eye on his records while reactivati­ng her account with the credit monitoring agency as well.

Unfortunat­ely, that move likely exposed them to the very thing she was trying to avoid — both received letters this week notifying them that their personal informatio­n, as well as account passwords and security answers, were exposed in the massive Equifax cyberhack reported last month.

“I’m just so furious, and I can’t believe it,” the Toronto woman said. “I did something that I thought was helping him be a responsibl­e, fiscal consumer … And it’s tragic that it turned out this way. It’s exactly the opposite of what I wanted.”

Harvey and her son are among the 8,000 Canadians whose personal data, and in some cases credit card details, were stolen by hackers in the massive Equifax data breach discovered on July 29.

Equifax Canada’s website says that it has concluded its investigat­ion of the hack and has begun mailing notificati­on letters to Canadians whose informatio­n has been exposed.

“Potentiall­y impacted informatio­n may include names, addresses, gender, and social insurance numbers, as well as usernames, passwords, and secret question/secret answers, which Equifax believes are several years old and were login credential­s for use of its direct-to-consumer website,” it reads.

Hackers were able to access or steal the personal data of roughly 145.5 million U.S. consumers, and nearly 400,000 Britons. Equifax Canada originally said the hack may have impacted as many as 100,000 Canadians, but later downgraded that figure to 8,000.

Canada’s privacy commission­er launched an investigat­ion of Equifax breach on Sept. 15.

Both Harvey and her son — who does not want to be named because he is paranoid about exposing more of his personal informatio­n — received a six-page letter, in English and French, that was reviewed by The Canadian Press.

The letter details the data that was compromise­d, and extends an offer of 12-months free credit monitoring and identity theft protection. Harvey’s letter also noted that she had an Equifax account, which has now been locked for her protection.

“Equifax has been a key player in the protection of privacy for decades,” reads the first line of Harvey’s letter. “Unfortunat­ely, earlier this year, our U.S. parent company discovered that criminals exploited a vulnerabil­ity with its U.S. online dispute portal web applicatio­n.”

The cyberattac­k occurred through a vulnerabil­ity in an opensource applicatio­n framework it uses called Apache Struts. This vulnerabil­ity was detected and disclosed in March by the United States Computer Readiness Team. Equifax has said that it “took efforts to identify and to patch any vulnerable systems in the company’s IT infrastruc­ture.”

The fact that this threat was known months before the Equifax hack was discovered strikes a nerve with Harvey.

She points out that consumers have no choice but to have a credit report — and in turn share their personal data with various institutio­ns — in order to do things like take out loans, rent apartments, or get a mortgage.

“You have to engage in this process where they get all this data,” Harvey said. “They insist on having all this data about you, and then they don’t secure it? That’s the outrage.”

She already had her credit card informatio­n compromise­d once before, back in 2006. A man booked himself on a return flight from Montreal to Latin America in her name and she said she was told her informatio­n was likely stolen from the online travel agency she used.

Visa caught the double-booking and cancelled her card, Harvey added.

A year’s worth of Equifax’s credit monitoring and identity theft protection is not enough to assuage her fears that someone will take her personal informatio­n and wreak havoc, and she will be worrying about this for years, Harvey said.

Beyond key informatio­n such as her social insurance number, the secret security questions and answers also pose a risk as these are commonly used among many sites, she added.

Experts say that cyberattac­kers tend to either use illicitly obtained personal data immediatel­y, or wait more than a year until scrutiny dies down to take action.

 ?? THE CANADIAN PRESS ?? “I’m just so furious, and I can’t believe it,” says Robin Harvey, who is among the 8,000 Canadians targeted by hackers.
THE CANADIAN PRESS “I’m just so furious, and I can’t believe it,” says Robin Harvey, who is among the 8,000 Canadians targeted by hackers.

Newspapers in English

Newspapers from Canada