Yahoo Data Breach: Another Reason for Free Credit Freeze

Yahoo data breach affects more than 1 billion consumers. We must have better solutions. 

Statement by MASSPIRG Education Fund, on latest announced Yahoo data breach.

“The latest announcement of a data breach affecting more than one billion Yahoo accounts over three years after the fact raises even more troubling questions about how the breach was able to take place, especially after a breach of at least 500,000 accounts in 2014, and why it took so long to discover and announce. Although it failed its responsibility to protect its users, Yahoo has an opportunity to provide the most consumer friendly response to likely the largest breach of its kind by alerting its users to the benefits of credit freezes and offering to pay for credit freezes with all three major national credit bureaus.

The types of stolen information, which appear to include names, emails addresses, telephone numbers, dates of birth, passwords, and in some cases, encrypted or unencrypted security questions and answers, do not appear to be the types of information that can directly be used to commit existing or new account identity theft.

However, the information stolen in this breach could be used to “phish” or gather additional information that can be used to access existing credit accounts or create new credit accounts. Everybody, whether they have a Yahoo account or not, should be on the lookout for suspicious emails asking for verification of or submission of even more personal information.

 

It is imperative that Yahoo’s response to this breach not fall through the cracks as its acquisition by Verizon Communications is finalized. We agree with Yahoo in recommending its users change passwords and security questions they might have reused for other online accounts and be on the lookout for suspicious activity on other online accounts.

 

Yahoo should also alert its users to the benefits of credit freezes and offer to pay for credit freezes with all three major national credit bureaus. Such a response would be the most consumer friendly response to a major data breach and would be a huge advancement for identify theft prevention in our country. Due to huge marketing pushes by credit monitoring services that only alert consumers to fraud after the fact, most Americans are not aware that they can actually prevent id thieves from opening new credit accounts in their names in the first place by placing freezes on their credit accounts at all three national credit bureaus.  Credit freezes help prevent new account identity theft because they keep potential creditors from seeing consumer credit history, without which new accounts are typically not opened.

 

More information about placing credit freezes is available at http://uspirg.org/reports/usf/why-you-should-get-security-freezes-your-information-stolen

 

 

-30-

MASSPIRG Education Fund is a non-profit, non-partisan public interest advocacy organizations that stand up to powerful interests whenever they threaten our health and safety, our financial security, or our right to fully participate in our democratic society. On the web at MASSPIRG.org

 

 

Authors

Deirdre Cummings

Legislative Director, MASSPIRG

Deirdre runs MASSPIRG’s public health, consumer protection and tax and budget programs. Deirdre has led campaigns to improve public records law and require all state spending to be transparent and available on an easy-to-use website, close $400 million in corporate tax loopholes, protect the state’s retail sales laws to reduce overcharges and preserve price disclosures, reduce costs of health insurance and prescription drugs, and more. Deirdre also oversees a Consumer Action Center in Weymouth, Mass., which has mediated 17,000 complaints and returned $4 million to Massachusetts consumers since 1989. Deirdre currently resides in Maynard, Mass., with her family. Over the years she has visited all but one of the state's 351 towns — Gosnold.