Ok, so the second half of that title is a joke. But I for one would not be surprised considering how Equifax has handled the rest of the fall out from their huger than huge data breach that exposed the lives of 143 million Americans to the financial and emotional ruin of identity theft.
Equifax CEO Richard Smith was not fired, however. He decided to retire, much like the politician in the middle of a huge scandal that suddenly wants to spend more time with his or her family.
Paulino do Rego Barros, Jr., the president of Equifax's Asia Pacific region, has been named interim CEO until a new Sith Lord can be found to replace Smith.
Custom Search
Showing posts with label Equifax. Show all posts
Showing posts with label Equifax. Show all posts
September 26, 2017
September 21, 2017
Lord Have Mercy! Equifax has been sending consumers to fake site for 2 weeks
As my momma used to say "when it rains, it pours". If that's the case, Equifax is in the middle of a Hurricane Harvey-esque Cat 5 hurricane of pouring rain.
After "forgetting" to install a security patch to its website which led to the largest data breach in the history of ever, then "forgetting" to tell their 143 million victims that they are and will forever be at risk for identity theft for nearly two months, then "forgetting" to tell anyone about an earlier data breach that Equifax has now confirmed did indeed happen, but "remembering" to let their top execs know about both breaches so they could several million dollars worth of Equifax stock before Equifax stock priced dropped by over a third of its price and "remembering" to donate to their favorite Congressman Barry Loudermilk so he would propose a completely idiotic bill that would provide immense protection to Equifax and the other credit bureaus at the expense of his constituents and the rest of America, NOW it has come to light that, for approximately two weeks, Equifax has been sending victims to a fake website.
Yes, a fake website. A spoof. One that puts those victims at even greater risk of identity theft.
Instead of using its own website to help victims of its data breach, Equifax created a whole new site equifaxsecurity2017.com. Guess that added the year so they can keep their breaches straight. The problem with using a new website instead of their existing one is that phishers and scammers can much more easily create fake websites using variations of the legitimate website's address. This would include reversing the order of the words or making sites with common typos of the real site name. In this instance, a mere day after the launch of the legitimate site, scammers had created 194 phishing websites that used addresses similar to the legitimate site.
What's worse than Equifax's boneheaded move in creating a new site instead of using its own Equifax.com site? Equifax directed victims of its data breach to the WRONG site. On three separate occasions, Equifax tweeted the incorrect URL securityequifax2017.com for its victims to use. Two of the tweets occurred on September 9 and the last on September 18 (i.e. three days ago!).
The Fair Credit Reporting Act requires consumer reporting agencies such as Equifax to follow reasonable procedures to assure maximum possible accuracy of the credit reports they generate regarding consumers. I have been suing Equifax for 18 years for violating that section by failing to have, much less follow, reasonable procedures to assure maximum possible accuracy. Now the public is getting a taste of what I have been seeing for years ... ignorance on top of ineptitude.
Please remember this if and when your Congressman or Senator votes in favor of Barry Loudermilk's bill designed to harm consumers by protecting Equifax from its own gross negligence and boneheadedness.
After "forgetting" to install a security patch to its website which led to the largest data breach in the history of ever, then "forgetting" to tell their 143 million victims that they are and will forever be at risk for identity theft for nearly two months, then "forgetting" to tell anyone about an earlier data breach that Equifax has now confirmed did indeed happen, but "remembering" to let their top execs know about both breaches so they could several million dollars worth of Equifax stock before Equifax stock priced dropped by over a third of its price and "remembering" to donate to their favorite Congressman Barry Loudermilk so he would propose a completely idiotic bill that would provide immense protection to Equifax and the other credit bureaus at the expense of his constituents and the rest of America, NOW it has come to light that, for approximately two weeks, Equifax has been sending victims to a fake website.
Yes, a fake website. A spoof. One that puts those victims at even greater risk of identity theft.
Instead of using its own website to help victims of its data breach, Equifax created a whole new site equifaxsecurity2017.com. Guess that added the year so they can keep their breaches straight. The problem with using a new website instead of their existing one is that phishers and scammers can much more easily create fake websites using variations of the legitimate website's address. This would include reversing the order of the words or making sites with common typos of the real site name. In this instance, a mere day after the launch of the legitimate site, scammers had created 194 phishing websites that used addresses similar to the legitimate site.
What's worse than Equifax's boneheaded move in creating a new site instead of using its own Equifax.com site? Equifax directed victims of its data breach to the WRONG site. On three separate occasions, Equifax tweeted the incorrect URL securityequifax2017.com for its victims to use. Two of the tweets occurred on September 9 and the last on September 18 (i.e. three days ago!).
The Fair Credit Reporting Act requires consumer reporting agencies such as Equifax to follow reasonable procedures to assure maximum possible accuracy of the credit reports they generate regarding consumers. I have been suing Equifax for 18 years for violating that section by failing to have, much less follow, reasonable procedures to assure maximum possible accuracy. Now the public is getting a taste of what I have been seeing for years ... ignorance on top of ineptitude.
Please remember this if and when your Congressman or Senator votes in favor of Barry Loudermilk's bill designed to harm consumers by protecting Equifax from its own gross negligence and boneheadedness.
September 19, 2017
It Just Keeps Getting Deeper - Equifax Suffered Second Undisclosed Data Breach
Bloomberg.com is reporting that the gigantically huge data breach that Equifax disclosed less than two weeks ago is not the only hack the consumer reporting agency suffered this year. There was allegedly a hack in March, two or more months before the big data breach that has put 143 million Americans at risk of having their identities stolen and their lives ruined.
According to Bloomberg, Equifax notified a small number of outsiders and banking customers in early March that it had suffered a breach. At that time, Equifax brought in a security firm to determine the scope of the breach. What Equifax did not do was tell the general public about the first data breach, either then or in July when it learned of the second, larger breach.
The second, big breach occurred (according to Equifax) when hackers gained access to Equifax's computer system through a known flaw in the company's web software that somehow was not patched until after the breach was discovered in late July. Was the flaw in the system discovered by the security firm in March and Equifax negligently failed to implement the patch to fix the vulnerability?
While the Bloomberg article focuses on the first hack's implications for the three executives that dumped Equifax stock after the second breach was known by Equifax but before the public was informed and the subsequent stock price drop, one thing the article does not mention is how the timing of the first hack completely undermines Representative Loudermilk's claim that his Equifax protection bill was drafted before the Equifax data breach, not in response to it. I posted about Loudermilk's position yesterday.
Loudermilk introduced his bill designed to protect Equifax and the other credit bureaus and hurt consumers (such as his constituents) in May, a few weeks before the second breach allegedly occurred. However, now that we know that Equifax knew of the first breach in March, why would we think that Loudermilk was not attempting to shield Equifax, a donor to his campaign, from liability from the first breach by pushing a bill that does nothing but protect the credit bureau from having to pay for its malfeasance? The timeline is looking very bad for both Equifax and Loudermilk. If I were a citizen of the 11th Congressional District of Georgia, I would have some very serious doubts about where my congressman's loyalties lie.
According to Bloomberg, Equifax notified a small number of outsiders and banking customers in early March that it had suffered a breach. At that time, Equifax brought in a security firm to determine the scope of the breach. What Equifax did not do was tell the general public about the first data breach, either then or in July when it learned of the second, larger breach.
The second, big breach occurred (according to Equifax) when hackers gained access to Equifax's computer system through a known flaw in the company's web software that somehow was not patched until after the breach was discovered in late July. Was the flaw in the system discovered by the security firm in March and Equifax negligently failed to implement the patch to fix the vulnerability?
While the Bloomberg article focuses on the first hack's implications for the three executives that dumped Equifax stock after the second breach was known by Equifax but before the public was informed and the subsequent stock price drop, one thing the article does not mention is how the timing of the first hack completely undermines Representative Loudermilk's claim that his Equifax protection bill was drafted before the Equifax data breach, not in response to it. I posted about Loudermilk's position yesterday.
Loudermilk introduced his bill designed to protect Equifax and the other credit bureaus and hurt consumers (such as his constituents) in May, a few weeks before the second breach allegedly occurred. However, now that we know that Equifax knew of the first breach in March, why would we think that Loudermilk was not attempting to shield Equifax, a donor to his campaign, from liability from the first breach by pushing a bill that does nothing but protect the credit bureau from having to pay for its malfeasance? The timeline is looking very bad for both Equifax and Loudermilk. If I were a citizen of the 11th Congressional District of Georgia, I would have some very serious doubts about where my congressman's loyalties lie.
September 18, 2017
Representative Loudermilk is STILL trying to protect Equifax instead of consumers
U.S. Representative Barry Loudermilk is still trying to give immunity to Equifax for its utter failure to protect the private information of over 143 million Americans and its subsequent bungling of the data breach it allowed to happen.
Prior to the breach (allegedly, since we really don't know when the breach actually happened since we only have Equifax's word that the breach occurred in late May through early June), Representative Loudermilk, who is a U.S. Representative from Georgia, the home state of Equifax, proposed legislation that, if passed, would gut the protections afforded consumers by the Fair Credit Reporting Act. The proposed legislation, H.R. 2359, would change the Fair Credit Reporting Act in two ways, both of which are very damaging to consumers and, not by coincidence, very favorable to Equifax and the other credit bureaus.
First, it would eliminate punitive damages. Yes, the one thing that big corporations like Equifax are scared of is a punitive damage award. Their profits are soooo great that an award of just compensatory damages will never be enough for them to really notice in the long term. Punitive damages, however, are used to punish a corporation for its wrongdoing. Equifax, as seen by its shenanigans of first hiding the data breach and then trying to pull a fast one to get its victims to give up their right to sue, is up to its eyeballs in wrongdoing. Equifax's conduct is the type of conduct that deserves a punitive damages award against it, since their conduct is willful, intentional and not just a mere accident or negligent mishap. So H.R. 2359 would benefit Equifax in that way.
Further, and more importantly in the context of consumers getting justice for Equifax's negligently allowing the data breach to happen, H.R. 2359 caps what consumers can get via a class action at $500,000. Not per consumer, per class action. And, since all of the approximately 100 class actions filed against Equifax for the data breach will ultimately be merged into one big class, that means 143 million plus victims of the data breach (less those who wisely opt out and file individual lawsuits) will have to split a measly $500,000 if Representative Loudermilk's bill becomes law. If my math is correct, that is roughly 3 cents per victim. Yes, three cents. Three shiny pennies. How is that justice?!
And, instead of backing away from his bill like its a grenade about to explode, Representative Loudermilk released the following statement:
"The data breach at Equifax has placed an unimaginable number of Americans’ personal information at serious risk. Not only must Equifax be held accountable for the breach of their systems, they must also be held accountable for their failure to notify the public of the breach in a timely manner. Businesses such as Equifax that obtain and store massive amounts of information on individuals must be held to the highest data protection standards. I will be working with the Financial Services Committee on investigating this data breach and the inadequate response of Equifax executives. Furthermore, we have already begun working on legislation mandating businesses to notify consumers affected by data breaches in a timely manner.
"Unfortunately, the outrage that followed the announcement by Equifax caused a gross mischaracterization of a bill that I have been working on since early this year. It was falsely reported that this bill (H.R. 2359) was introduced to give immunity to Equifax from any liability over this data breach. This couldn't be further from the truth. The FCRA Liability Harmonization Act (H.R. 2359) was introduced back in May, and is aimed at curbing frivolous class action lawsuits against businesses under the Fair Credit Reporting Act (FCRA). The businesses affected by FCRA lawsuits include community banks, credit unions, auto dealerships, retailers, and many other small businesses that extend credit to consumers.
"Reports that this bill would grant any immunity to Equifax for liability in this data breach are completely false. The bill does not give any immunity from prosecution or civil lawsuits for wrongdoing to any business. Furthermore, data breaches are governed by state laws, not the FCRA, so this bill would not apply to Equifax in this case at all with respect to the 143 million people whose personally identifiable information was compromised.
"Finally, given the unfounded attacks on me and the rampant misinformation circulating about this legislation, the Financial Services Committee has not scheduled further action on any bill at this time."
So Representative Loudermilk is claiming that his bill would not grant immunity to Equifax? While technically true, being capped at paying three cents a victim is about as close to immunity as one can get. For Representative Loudermilk to make this grossly misleading statement is deplorable. He obviously cares more about Equifax, his campaign donor, than he does about consumers, including his constituents. I hope the people of the 11th Congressional District of Georgia are paying attention to whose side Mr. Loudermilk is one, because it sure isn't theirs.
Prior to the breach (allegedly, since we really don't know when the breach actually happened since we only have Equifax's word that the breach occurred in late May through early June), Representative Loudermilk, who is a U.S. Representative from Georgia, the home state of Equifax, proposed legislation that, if passed, would gut the protections afforded consumers by the Fair Credit Reporting Act. The proposed legislation, H.R. 2359, would change the Fair Credit Reporting Act in two ways, both of which are very damaging to consumers and, not by coincidence, very favorable to Equifax and the other credit bureaus.
First, it would eliminate punitive damages. Yes, the one thing that big corporations like Equifax are scared of is a punitive damage award. Their profits are soooo great that an award of just compensatory damages will never be enough for them to really notice in the long term. Punitive damages, however, are used to punish a corporation for its wrongdoing. Equifax, as seen by its shenanigans of first hiding the data breach and then trying to pull a fast one to get its victims to give up their right to sue, is up to its eyeballs in wrongdoing. Equifax's conduct is the type of conduct that deserves a punitive damages award against it, since their conduct is willful, intentional and not just a mere accident or negligent mishap. So H.R. 2359 would benefit Equifax in that way.
Further, and more importantly in the context of consumers getting justice for Equifax's negligently allowing the data breach to happen, H.R. 2359 caps what consumers can get via a class action at $500,000. Not per consumer, per class action. And, since all of the approximately 100 class actions filed against Equifax for the data breach will ultimately be merged into one big class, that means 143 million plus victims of the data breach (less those who wisely opt out and file individual lawsuits) will have to split a measly $500,000 if Representative Loudermilk's bill becomes law. If my math is correct, that is roughly 3 cents per victim. Yes, three cents. Three shiny pennies. How is that justice?!
And, instead of backing away from his bill like its a grenade about to explode, Representative Loudermilk released the following statement:
"The data breach at Equifax has placed an unimaginable number of Americans’ personal information at serious risk. Not only must Equifax be held accountable for the breach of their systems, they must also be held accountable for their failure to notify the public of the breach in a timely manner. Businesses such as Equifax that obtain and store massive amounts of information on individuals must be held to the highest data protection standards. I will be working with the Financial Services Committee on investigating this data breach and the inadequate response of Equifax executives. Furthermore, we have already begun working on legislation mandating businesses to notify consumers affected by data breaches in a timely manner.
"Unfortunately, the outrage that followed the announcement by Equifax caused a gross mischaracterization of a bill that I have been working on since early this year. It was falsely reported that this bill (H.R. 2359) was introduced to give immunity to Equifax from any liability over this data breach. This couldn't be further from the truth. The FCRA Liability Harmonization Act (H.R. 2359) was introduced back in May, and is aimed at curbing frivolous class action lawsuits against businesses under the Fair Credit Reporting Act (FCRA). The businesses affected by FCRA lawsuits include community banks, credit unions, auto dealerships, retailers, and many other small businesses that extend credit to consumers.
"Reports that this bill would grant any immunity to Equifax for liability in this data breach are completely false. The bill does not give any immunity from prosecution or civil lawsuits for wrongdoing to any business. Furthermore, data breaches are governed by state laws, not the FCRA, so this bill would not apply to Equifax in this case at all with respect to the 143 million people whose personally identifiable information was compromised.
"Finally, given the unfounded attacks on me and the rampant misinformation circulating about this legislation, the Financial Services Committee has not scheduled further action on any bill at this time."
So Representative Loudermilk is claiming that his bill would not grant immunity to Equifax? While technically true, being capped at paying three cents a victim is about as close to immunity as one can get. For Representative Loudermilk to make this grossly misleading statement is deplorable. He obviously cares more about Equifax, his campaign donor, than he does about consumers, including his constituents. I hope the people of the 11th Congressional District of Georgia are paying attention to whose side Mr. Loudermilk is one, because it sure isn't theirs.
September 17, 2017
Don't Answer Calls from Equifax
As if the damage done by Equifax's negligence in allowing the massive data breach and its subsequent shenanigans in delaying publication of the data breach and its efforts to further screw consumers by stealing their right is not enough, now scammers (other than Equifax) are trying to profit off the data breach at the expense of consumers.
I have been told that scammers are placing calls to consumers posing as employees of Equifax attempting to "help" after the data breach. These "employees" then ask for the consumers' personal identifiers (Social Security number, date of birth, full name, etc.) in an alleged effort to verify the identity of the consumer. However, they really use want your information to use against you, so DO NOT GIVE IT TO THEM!
First of all, Equifax will never call you about anything. This scam has been around for years but usually the scammers claim to work for the IRS. Just like the IRS, Equifax will only deal with you in writing, so a call from someone claiming to be from Equifax is a big red flag that a scam is happening.
Secondly, after Equifax's blatant interest in only helping and protecting itself in the wake of the data breach its negligence allowed to happen, why would anyone think Equifax would go out of its way to call a consumer to help. Equifax never helps. It only hurts consumers and does its best to profit from selling all of our information. Just like Experian and Trans Union, Equifax only cares about profits and avoiding liability for its wrongdoing and malfeasance.
So if Equifax or the IRS is calling, hang up. It's a scam.
I have been told that scammers are placing calls to consumers posing as employees of Equifax attempting to "help" after the data breach. These "employees" then ask for the consumers' personal identifiers (Social Security number, date of birth, full name, etc.) in an alleged effort to verify the identity of the consumer. However, they really use want your information to use against you, so DO NOT GIVE IT TO THEM!
First of all, Equifax will never call you about anything. This scam has been around for years but usually the scammers claim to work for the IRS. Just like the IRS, Equifax will only deal with you in writing, so a call from someone claiming to be from Equifax is a big red flag that a scam is happening.
Secondly, after Equifax's blatant interest in only helping and protecting itself in the wake of the data breach its negligence allowed to happen, why would anyone think Equifax would go out of its way to call a consumer to help. Equifax never helps. It only hurts consumers and does its best to profit from selling all of our information. Just like Experian and Trans Union, Equifax only cares about profits and avoiding liability for its wrongdoing and malfeasance.
So if Equifax or the IRS is calling, hang up. It's a scam.
September 08, 2017
Too Little, Too Late - Equifax Adds Opt Out to Arbitration Provision regarding Data Breach
After a flurry of bad press and social media outrage (including from yours truly), Equifax has now added an opt out provision to the arbitration provision it snuck into the fine print for anyone accepting Equifax's "offer" of "free" credit monitoring and identity theft protection.
Couple of problems. No one reads the fine print so they don't know about the arbitration clause, much less the opt out provision. Why can't they just make it an opt in, if arbitration is such a great thing? Of course, its not and they won't.
Second, the opt out provision is only available for a measly thirty days from when the data breach victim signs up for the "free" credit monitoring. Equifax kept the data breach secret for longer than that! Thirty days is way too short.
And, a common ploy on these opt out provisions for arbitration clauses is that, amazingly, the company whose arbitration clause it is almost always denies that the consumer ever opted out and then still try to force the consumer into proving that he or she opted out, instead of the burden being on the company to prove that the consumer agreed to arbitration. Equifax will likely try the same ploy since, as you can see, the play fast and loose with the rules. Just do a pacer search for lawsuits where they have allegedly violated the Fair Credit Reporting Act.
The data breach is a very bad thing. But Equifax's reaction to the data breach (i.e. keeping it secret for almost two months and then trying to screw the data breach victims out of their rights) is the worst of all. Equifax and its executives should pay and pay dearly for this.
Couple of problems. No one reads the fine print so they don't know about the arbitration clause, much less the opt out provision. Why can't they just make it an opt in, if arbitration is such a great thing? Of course, its not and they won't.
Second, the opt out provision is only available for a measly thirty days from when the data breach victim signs up for the "free" credit monitoring. Equifax kept the data breach secret for longer than that! Thirty days is way too short.
And, a common ploy on these opt out provisions for arbitration clauses is that, amazingly, the company whose arbitration clause it is almost always denies that the consumer ever opted out and then still try to force the consumer into proving that he or she opted out, instead of the burden being on the company to prove that the consumer agreed to arbitration. Equifax will likely try the same ploy since, as you can see, the play fast and loose with the rules. Just do a pacer search for lawsuits where they have allegedly violated the Fair Credit Reporting Act.
The data breach is a very bad thing. But Equifax's reaction to the data breach (i.e. keeping it secret for almost two months and then trying to screw the data breach victims out of their rights) is the worst of all. Equifax and its executives should pay and pay dearly for this.
Equifax based in Georgia; Georgian Congressman seeks to gut FCRA. Coincidence? I think not!
Equifax is based in Atlanta, Georgia. Three guesses which state's congressman proposed HR 2359, i.e. the Kill the FCRA bill. Yep, that's right, Congressman Loudermilk of Georgia. I wonder who put him up to it?
Representative Loudermilk is now being called on to withdraw his Equifax protecting bill by the National Association of Consumer Advocates (of which I am a proud member) and The Georgia Watch. Their press release reads:
"NACA, Georgia Watch Call on Rep. Loudermilk of Georgia to Withdraw His Bill That Favors Equifax, Credit Bureaus Over Harmed Consumers
In light of the astonishing announcement of credit reporting agency Equifax’s security breach which impacts the personal information of more than 140 million consumers, National Association of Consumer Advocates and Georgia Watch call on Rep. Barry Loudermilk (R-Ga.) to withdraw his legislation, H.R. 2359, that would drastically reduce remedies for consumers who are victims of credit reporting abuses.
On the same day that Equifax announced the massive data breach, a subcommittee of the U.S. House Financial Services Committee held a hearing to consider legislation, including Loudermilk’s bill that would amend the federal Fair Credit Reporting Act to essentially shield credit reporting agencies from full accountability for willful and reckless conduct that upends individuals’ employment and financial lives.
Specifically, the “FCRA Liability Harmonization Act” would eliminate punitive damages, a tool used to punish the worst actors, and would impose an arbitrary $500,000 limit on statutory and actual damages in class actions. These illogical blocks on consumer remedies would obstruct individuals’ legal rights.
“Instead of running to Congress to seek a “get out of jail free” card to avoid accountability for its reckless handling of consumers’ personal and financial information, Equifax and its counterparts in the credit reporting industry should focus on protecting information from identity thieves,” said Christine Hines, legislative director at National Association of Consumer Advocates (NACA).
At Thursday’s hearing, witnesses for the credit reporting industry claimed that their violations of federal protections were merely technical and do not harm anyone despite evidence that consumers have been blocked from accessing credit, housing, and jobs due to industry’s irresponsible handling of consumer information. Industry representatives also used the hearing to bash a rule issued by the Consumer Financial Protection Bureau that would restore consumers’ ability to band together in class actions when harmed by unlawful financial industry practices.
Currently Equifax is rightly being criticized for its handling of the massive data breach. One of many of its missteps – it has inserted forced arbitration clauses in the terms and conditions of various credit monitoring services that it is encouraging affected consumers to enroll in.
“Equifax’s use of forced arbitration clauses and class action bans means that consumers cannot band together in court to seek remedies against it,” said Liz Coyle, executive director of Georgia Watch. “This is unacceptable and will have disastrous effects on the marketplace.”
NACA and Georgia Watch insist that Rep. Loudermilk withdraw his bill and support consumers’ right to hold bad actors like Equifax fully accountable through the justice system."
Representative Loudermilk is now being called on to withdraw his Equifax protecting bill by the National Association of Consumer Advocates (of which I am a proud member) and The Georgia Watch. Their press release reads:
"NACA, Georgia Watch Call on Rep. Loudermilk of Georgia to Withdraw His Bill That Favors Equifax, Credit Bureaus Over Harmed Consumers
In light of the astonishing announcement of credit reporting agency Equifax’s security breach which impacts the personal information of more than 140 million consumers, National Association of Consumer Advocates and Georgia Watch call on Rep. Barry Loudermilk (R-Ga.) to withdraw his legislation, H.R. 2359, that would drastically reduce remedies for consumers who are victims of credit reporting abuses.
On the same day that Equifax announced the massive data breach, a subcommittee of the U.S. House Financial Services Committee held a hearing to consider legislation, including Loudermilk’s bill that would amend the federal Fair Credit Reporting Act to essentially shield credit reporting agencies from full accountability for willful and reckless conduct that upends individuals’ employment and financial lives.
Specifically, the “FCRA Liability Harmonization Act” would eliminate punitive damages, a tool used to punish the worst actors, and would impose an arbitrary $500,000 limit on statutory and actual damages in class actions. These illogical blocks on consumer remedies would obstruct individuals’ legal rights.
“Instead of running to Congress to seek a “get out of jail free” card to avoid accountability for its reckless handling of consumers’ personal and financial information, Equifax and its counterparts in the credit reporting industry should focus on protecting information from identity thieves,” said Christine Hines, legislative director at National Association of Consumer Advocates (NACA).
At Thursday’s hearing, witnesses for the credit reporting industry claimed that their violations of federal protections were merely technical and do not harm anyone despite evidence that consumers have been blocked from accessing credit, housing, and jobs due to industry’s irresponsible handling of consumer information. Industry representatives also used the hearing to bash a rule issued by the Consumer Financial Protection Bureau that would restore consumers’ ability to band together in class actions when harmed by unlawful financial industry practices.
Currently Equifax is rightly being criticized for its handling of the massive data breach. One of many of its missteps – it has inserted forced arbitration clauses in the terms and conditions of various credit monitoring services that it is encouraging affected consumers to enroll in.
“Equifax’s use of forced arbitration clauses and class action bans means that consumers cannot band together in court to seek remedies against it,” said Liz Coyle, executive director of Georgia Watch. “This is unacceptable and will have disastrous effects on the marketplace.”
NACA and Georgia Watch insist that Rep. Loudermilk withdraw his bill and support consumers’ right to hold bad actors like Equifax fully accountable through the justice system."
Congressional Committee to hold Hearing Regarding Equifax Data Breach
Yesterday, the House Financial Services Committee held a hearing on a bill that would gut the protections of the Fair Credit Reporting Act, which is the only law protecting Americans from the ridiculously inept consumer reporting agencies such as Equifax.
Today, the public learned of a massive data breach of Equifax's treasure trove of secret information regarding consumers, including the full names, Social Security numbers, dates of birth and addresses of approximately 143 Americans.
Now, the House Financial Services Committee released the following press release:
"WASHINGTON – House Financial Services Committee Chairman Jeb Hensarling (R-TX) said his committee will hold a hearing on the Equifax data breach that has potentially compromised the personal information of roughly 143 million Americans.
“This is obviously a very serious and very troubling situation and our committee has already begun preparations for a hearing. Large-scale security breaches are becoming all too common. Every breach leaves consumers exposed and vulnerable to identity theft, fraud and a host of other crimes, and they deserve answers,” said Chairman Hensarling.
A date for the hearing will be announced at a later time."
Chairman Hensarling, if you want to protect Americans from data breaches and the damage caused by identity theft, your first step should be to kill HR 2359. Only the Fair Credit Reporting Act stands in the way of Equifax and the other credit bureaus harming Americans by willfully and knowingly reporting erroneous information on Americans' credit reports. That is the "answer" you seek. Have you hearing, but start with killing HR 2359 and let the Fair Credit Reporting Act continue to protect Americans.
Today, the public learned of a massive data breach of Equifax's treasure trove of secret information regarding consumers, including the full names, Social Security numbers, dates of birth and addresses of approximately 143 Americans.
Now, the House Financial Services Committee released the following press release:
"WASHINGTON – House Financial Services Committee Chairman Jeb Hensarling (R-TX) said his committee will hold a hearing on the Equifax data breach that has potentially compromised the personal information of roughly 143 million Americans.
“This is obviously a very serious and very troubling situation and our committee has already begun preparations for a hearing. Large-scale security breaches are becoming all too common. Every breach leaves consumers exposed and vulnerable to identity theft, fraud and a host of other crimes, and they deserve answers,” said Chairman Hensarling.
A date for the hearing will be announced at a later time."
Chairman Hensarling, if you want to protect Americans from data breaches and the damage caused by identity theft, your first step should be to kill HR 2359. Only the Fair Credit Reporting Act stands in the way of Equifax and the other credit bureaus harming Americans by willfully and knowingly reporting erroneous information on Americans' credit reports. That is the "answer" you seek. Have you hearing, but start with killing HR 2359 and let the Fair Credit Reporting Act continue to protect Americans.
Equifax's data breach just keeps getting worse!
As if it is not bad enough that Equifax exposed 143 million Americans to the hellacious ordeal of identity theft, now its becoming crystal clear just how inept their response to the data breach was.
For instance, the website ARS Technica (www.arstechnica.com) reported the following:
"What's more, the website www.equifaxsecurity2017.com/, which Equifax created to notify people of the breach, is highly problematic for a variety of reasons. It runs on a stock installation WordPress, a content management system that doesn't provide the enterprise-grade security required for a site that asks people to provide their last name and all but three digits of their Social Security number. The TLS certificate doesn't perform proper revocation checks. Worse still, the domain name isn't registered to Equifax, and its format looks like precisely the kind of thing a criminal operation might use to steal people's details. It's no surprise that Cisco-owned Open DNS was blocking access to the site and warning it was a suspected phishing threat.
Another indications of sloppiness: a username for administering the site has been left in a page that was hosted here. ... That by itself wouldn't allow for unauthorized access, but it's still something that should never have happened.
Meanwhile, in the hours immediately following the breach disclosure, the main Equifax website was displaying debug codes, which for security reasons, is something that should never happen on any production server, especially one that is a server or two away from so much sensitive data. A mistake this serious does little to instill confidence company engineers have hardened the site against future devastating attacks."
So Equifax's attempt to "fix" the damage done by its data breach doesn't just take away the rights of consumers to get justice for the damage caused by Equifax's negligence, it now opens those victims up to more potential privacy problems by using a website with obvious security holes to collect the names and Social Security numbers of the victims. Sheeeeesh!
Equifax's unwillingness to investigate consumer disputes properly is starting to look like the lesser of their sins.
For instance, the website ARS Technica (www.arstechnica.com) reported the following:
"What's more, the website www.equifaxsecurity2017.com/, which Equifax created to notify people of the breach, is highly problematic for a variety of reasons. It runs on a stock installation WordPress, a content management system that doesn't provide the enterprise-grade security required for a site that asks people to provide their last name and all but three digits of their Social Security number. The TLS certificate doesn't perform proper revocation checks. Worse still, the domain name isn't registered to Equifax, and its format looks like precisely the kind of thing a criminal operation might use to steal people's details. It's no surprise that Cisco-owned Open DNS was blocking access to the site and warning it was a suspected phishing threat.
Another indications of sloppiness: a username for administering the site has been left in a page that was hosted here. ... That by itself wouldn't allow for unauthorized access, but it's still something that should never have happened.
Meanwhile, in the hours immediately following the breach disclosure, the main Equifax website was displaying debug codes, which for security reasons, is something that should never happen on any production server, especially one that is a server or two away from so much sensitive data. A mistake this serious does little to instill confidence company engineers have hardened the site against future devastating attacks."
So Equifax's attempt to "fix" the damage done by its data breach doesn't just take away the rights of consumers to get justice for the damage caused by Equifax's negligence, it now opens those victims up to more potential privacy problems by using a website with obvious security holes to collect the names and Social Security numbers of the victims. Sheeeeesh!
Equifax's unwillingness to investigate consumer disputes properly is starting to look like the lesser of their sins.
NCLC's statement regarding the Equifax data breach
Below is a statement from the National Consumer Law Center regarding the Equifax data breach. NCLC fights for the rights of you, the consumer, every day, even though you probably didn't know it and, for a large segment of America, vote for the very politicians that are doing their best to strip you of your rights and protect the big businesses that trample your rights every day.
Statement of National Consumer Law Center Staff Attorney Chi Chi Wu on the Equifax Data Breach that Affected 143 Million Consumers
The massive Equifax data breach is one of the largest in our country’s history, affecting half of the United States population and nearly three-quarters of consumers with credit reports. Chances are, this affects YOU. Plus, the stolen information is the mother lode of sensitive personal data that can be used for identity theft: Social Security numbers, dates of birth, and in some cases, driver’s license numbers. Also, was highly revealing credit reporting account information stolen, such as student loan or mortgage payment account numbers and payment histories? This information could be used for phishing schemes or other fraud.
Equifax should immediately pay or reimburse fees for security freezes to affected consumers at all three of the major credit bureaus, i.e. Experian and TransUnion in addition to Equifax. A security freeze is the most effective measure against “new account” identity theft, because it stops thieves from using the consumer’s stolen information. Equifax is offering one year of its credit monitoring and identity theft prevention product in response to the security breach, which it states includes “the ability to lock and unlock Equifax credit reports.” That is a first step, as the ability to lock Equifax reports is better than credit monitoring alone. Credit monitoring only informs consumers after the fact when there has been an attempt to open a fraudulent new account using the consumer’s personal information. However, consumers need the ability to “lock down” or freeze their credit reports at all three major credit bureaus, and for more than one year, because the stolen information could still be used to fraudulently apply for credit using a report from Experian or TransUnion as well.
Equifax should immediately remove the forced arbitration clause and class action ban from the Terms of Use for its website and any credit monitoring or identity theft prevention services it offers. The arbitration clause does give consumers the ability to opt out of forced arbitration by notifying Equifax in writing within 30 days, which consumers should do. However, most consumers will not see that fine print and will be forced to give up their access to the courts. Through those terms, Equifax is purporting to prevent affected customers from access to the courts or the right to join together with the other hundreds of millions of injured consumers to jointly pursue claims against Equifax. A new rule by the Consumer Financial Protection Bureau would bar such forced arbitration clauses with class action bans, but members of Congress have threatened to block the rule.
Consumers affected by the breach should not wait to see if Equifax will pay for freezes at the other two credit bureaus; they should get freezes immediately if they are worried about identity theft. If consumers do not want to get a freeze, there is also the option of putting a 90-day “initial fraud alert” in their credit report that tells businesses they should verify your identity before they issue credit. The initial fraud alert must be renewed every 90 days.
Another risk of this massive data breach is tax identity theft, where crooks file phony tax returns in the consumers’ name. The Internal Revenue Service (IRS) had previously made available Identify Theft PINs for consumers in Florida, Georgia, and the District of Columbia, and consumers in those states should consider getting the pin (which they should do before getting a freeze). The IRS should make Identity Theft PINS available to all affected breach victims.
It’s ironic that, on the same day that Equifax announced this data breach, Congress was considering a bill that would dramatic reduce the consequences of violating the Fair Credit Reporting Act (FCRA) for the credit bureaus and other industry players. H.R. 2359, the so-called FCRA Liability Harmonization Act, was just heard yesterday by the House Financial Services Committee and would eliminate punitive damages plus limit class action damages under the FCRA. While the FCRA may or may not be directly implicated by the Equifax data breach, we need stronger, not weaker, consequences when companies violate long-standing privacy laws, such as the FCRA. Credit bureaus, such as Equifax, should not be rewarded with reductions in legal accountability given these recent events
###
Since 1969, the nonprofit National Consumer Law Center® (NCLC®) has used its expertise in consumer law and energy policy to work for consumer justice and economic security for low-income and other disadvantaged people, including older adults, in the United States. NCLC’s expertise includes policy analysis and advocacy; consumer law and energy publications; litigation; expert witness services, and training and advice for advocates. NCLC works with nonprofit and legal services organizations, private attorneys, policymakers, and federal and state government and courts across the nation to stop exploitative practices, help financially stressed families build and retain wealth, and advance economic fairness.
Statement of National Consumer Law Center Staff Attorney Chi Chi Wu on the Equifax Data Breach that Affected 143 Million Consumers
The massive Equifax data breach is one of the largest in our country’s history, affecting half of the United States population and nearly three-quarters of consumers with credit reports. Chances are, this affects YOU. Plus, the stolen information is the mother lode of sensitive personal data that can be used for identity theft: Social Security numbers, dates of birth, and in some cases, driver’s license numbers. Also, was highly revealing credit reporting account information stolen, such as student loan or mortgage payment account numbers and payment histories? This information could be used for phishing schemes or other fraud.
Equifax should immediately pay or reimburse fees for security freezes to affected consumers at all three of the major credit bureaus, i.e. Experian and TransUnion in addition to Equifax. A security freeze is the most effective measure against “new account” identity theft, because it stops thieves from using the consumer’s stolen information. Equifax is offering one year of its credit monitoring and identity theft prevention product in response to the security breach, which it states includes “the ability to lock and unlock Equifax credit reports.” That is a first step, as the ability to lock Equifax reports is better than credit monitoring alone. Credit monitoring only informs consumers after the fact when there has been an attempt to open a fraudulent new account using the consumer’s personal information. However, consumers need the ability to “lock down” or freeze their credit reports at all three major credit bureaus, and for more than one year, because the stolen information could still be used to fraudulently apply for credit using a report from Experian or TransUnion as well.
Equifax should immediately remove the forced arbitration clause and class action ban from the Terms of Use for its website and any credit monitoring or identity theft prevention services it offers. The arbitration clause does give consumers the ability to opt out of forced arbitration by notifying Equifax in writing within 30 days, which consumers should do. However, most consumers will not see that fine print and will be forced to give up their access to the courts. Through those terms, Equifax is purporting to prevent affected customers from access to the courts or the right to join together with the other hundreds of millions of injured consumers to jointly pursue claims against Equifax. A new rule by the Consumer Financial Protection Bureau would bar such forced arbitration clauses with class action bans, but members of Congress have threatened to block the rule.
Consumers affected by the breach should not wait to see if Equifax will pay for freezes at the other two credit bureaus; they should get freezes immediately if they are worried about identity theft. If consumers do not want to get a freeze, there is also the option of putting a 90-day “initial fraud alert” in their credit report that tells businesses they should verify your identity before they issue credit. The initial fraud alert must be renewed every 90 days.
Another risk of this massive data breach is tax identity theft, where crooks file phony tax returns in the consumers’ name. The Internal Revenue Service (IRS) had previously made available Identify Theft PINs for consumers in Florida, Georgia, and the District of Columbia, and consumers in those states should consider getting the pin (which they should do before getting a freeze). The IRS should make Identity Theft PINS available to all affected breach victims.
It’s ironic that, on the same day that Equifax announced this data breach, Congress was considering a bill that would dramatic reduce the consequences of violating the Fair Credit Reporting Act (FCRA) for the credit bureaus and other industry players. H.R. 2359, the so-called FCRA Liability Harmonization Act, was just heard yesterday by the House Financial Services Committee and would eliminate punitive damages plus limit class action damages under the FCRA. While the FCRA may or may not be directly implicated by the Equifax data breach, we need stronger, not weaker, consequences when companies violate long-standing privacy laws, such as the FCRA. Credit bureaus, such as Equifax, should not be rewarded with reductions in legal accountability given these recent events
###
Since 1969, the nonprofit National Consumer Law Center® (NCLC®) has used its expertise in consumer law and energy policy to work for consumer justice and economic security for low-income and other disadvantaged people, including older adults, in the United States. NCLC’s expertise includes policy analysis and advocacy; consumer law and energy publications; litigation; expert witness services, and training and advice for advocates. NCLC works with nonprofit and legal services organizations, private attorneys, policymakers, and federal and state government and courts across the nation to stop exploitative practices, help financially stressed families build and retain wealth, and advance economic fairness.
Equifax Data Breach Puts 143 Million Consumers at Risk
On July 29 (yes, nearly two months ago), Equifax discovered that it had suffered a data breach between mid-May and July. The massive data breach exposed the personal identifiers of approximately 143 million Americans. That means approximately half of the population of the United States just became even more likely to have their identities stolen.
The information that Equifax allowed to be stolen is the holy grail for identity thieves. The names, Social Security numbers, dates of birth, addresses and, in some cases, driver's license numbers of 143 million Americans were pilfered from Equifax. Even worse, Equifax sat on this information for nearly two months before alerting the public of Equifax's malfeasance putting them at risk.
Equifax is one of the last companies that should allow something like this to happen. Equifax chose to enter the business of collected and disseminating the most private of information on nearly all Americans. Equifax's credit reports are used nationwide for obtaining home loans, car loans, credit cards, bank loans and lines of credit.
Equifax's credit reports are used by many employers to decide whether to hire someone, particularly if there is any responsibility for financial accounts involved in the job description.
Equifax's credit reports are used by government agencies to determine whether you can have or keep a security clearance. I have had many clients lose their security clearances (and thus their jobs) due to Equifax reporting erroneous information about them and the willfully refusing to correct the errors.
Equifax's credit reports are used by insurance companies to determine if you qualify for car insurance and homeowner's insurance. And, if you do qualify, you may find that your premiums are higher because of the contents of your Equifax credit report.
Now, all of that uber sensitive information entrusted to Equifax (not that the consumer is given an option) has been exposed to identity thieves and hackers and is no doubt going to be sold on the dark web and used to victimize consumers across the country.
But what is even worse than Equifax allowing this tragedy to happen and then keeping its misdeeds secret for nearly two months? Now, Equifax is offering free identity theft protection and credit monitoring to the victims of its data breach. Sounds good, right? Wrong! Included in the sign up for that "free" identity theft protection are arbitration clauses that take away your rights to sue Equifax for the damage its data breach causes you.
When my wife woke me up this morning at 2:00 a.m. when she read about the Equifax data breach and then told me that Equifax was offering free credit monitoring and identity theft protection, I mumbled in my half awake state "do not sign up for it, they'll have something bad in the fine print". How did I know this? Well, for one, I have been suing Equifax for consumers they have wronged for nearly 18 years now. Second, Equifax has done this type stuff before. For instance, consumers are entitled under the Fair Credit Reporting Act to one free credit report per year. But Equifax thought it right to make consumers agree to give up their right to a lawsuit to be able to exercise their right to a free credit report. So Equifax stuck some arbitration language in the fine print of anyone accessing their free credit report online. I warned you about this all the way back in 2009 - fcralawyer.blogspot.com/2009/05/truly-free-credit-report.html. So it was no surprise that they would pull something like this again, especially since they are the root cause of the problem this time.
So, if Equifax's data breach causes your identity to be stolen which then causes your life to become a financial hell when your legitimate credit cards get closed, you lose your job and your home and auto insurance and then, due to the stress of it all, your health goes kaput, Equifax skates by free and clear because your only option is to bring an arbitration proceeding to be decided by Equifax's arbiter. Talking about heaping injustice on top of tragedy!
So, whatever you do, do not sign up for Equifax's "free" monitoring or identity theft protection. To do so will cause irreparable harm to any potential lawsuit you may have if, God forbid, Equifax's data breach leads to theft of your identity. And, if you do become the victim of identity theft, contact the Kittell Law Firm at 662-298-3456 or at ckittell@kittell-law.com. I will sue Equifax in any jurisdiction in the United States for any victim of identity theft whose credit report is damaged as a result of Equifax's data breach provided that you have not agreed to throw your rights away by falling for Equifax's trap of "free" credit monitoring.
The information that Equifax allowed to be stolen is the holy grail for identity thieves. The names, Social Security numbers, dates of birth, addresses and, in some cases, driver's license numbers of 143 million Americans were pilfered from Equifax. Even worse, Equifax sat on this information for nearly two months before alerting the public of Equifax's malfeasance putting them at risk.
Equifax is one of the last companies that should allow something like this to happen. Equifax chose to enter the business of collected and disseminating the most private of information on nearly all Americans. Equifax's credit reports are used nationwide for obtaining home loans, car loans, credit cards, bank loans and lines of credit.
Equifax's credit reports are used by many employers to decide whether to hire someone, particularly if there is any responsibility for financial accounts involved in the job description.
Equifax's credit reports are used by government agencies to determine whether you can have or keep a security clearance. I have had many clients lose their security clearances (and thus their jobs) due to Equifax reporting erroneous information about them and the willfully refusing to correct the errors.
Equifax's credit reports are used by insurance companies to determine if you qualify for car insurance and homeowner's insurance. And, if you do qualify, you may find that your premiums are higher because of the contents of your Equifax credit report.
Now, all of that uber sensitive information entrusted to Equifax (not that the consumer is given an option) has been exposed to identity thieves and hackers and is no doubt going to be sold on the dark web and used to victimize consumers across the country.
But what is even worse than Equifax allowing this tragedy to happen and then keeping its misdeeds secret for nearly two months? Now, Equifax is offering free identity theft protection and credit monitoring to the victims of its data breach. Sounds good, right? Wrong! Included in the sign up for that "free" identity theft protection are arbitration clauses that take away your rights to sue Equifax for the damage its data breach causes you.
When my wife woke me up this morning at 2:00 a.m. when she read about the Equifax data breach and then told me that Equifax was offering free credit monitoring and identity theft protection, I mumbled in my half awake state "do not sign up for it, they'll have something bad in the fine print". How did I know this? Well, for one, I have been suing Equifax for consumers they have wronged for nearly 18 years now. Second, Equifax has done this type stuff before. For instance, consumers are entitled under the Fair Credit Reporting Act to one free credit report per year. But Equifax thought it right to make consumers agree to give up their right to a lawsuit to be able to exercise their right to a free credit report. So Equifax stuck some arbitration language in the fine print of anyone accessing their free credit report online. I warned you about this all the way back in 2009 - fcralawyer.blogspot.com/2009/05/truly-free-credit-report.html. So it was no surprise that they would pull something like this again, especially since they are the root cause of the problem this time.
So, if Equifax's data breach causes your identity to be stolen which then causes your life to become a financial hell when your legitimate credit cards get closed, you lose your job and your home and auto insurance and then, due to the stress of it all, your health goes kaput, Equifax skates by free and clear because your only option is to bring an arbitration proceeding to be decided by Equifax's arbiter. Talking about heaping injustice on top of tragedy!
So, whatever you do, do not sign up for Equifax's "free" monitoring or identity theft protection. To do so will cause irreparable harm to any potential lawsuit you may have if, God forbid, Equifax's data breach leads to theft of your identity. And, if you do become the victim of identity theft, contact the Kittell Law Firm at 662-298-3456 or at ckittell@kittell-law.com. I will sue Equifax in any jurisdiction in the United States for any victim of identity theft whose credit report is damaged as a result of Equifax's data breach provided that you have not agreed to throw your rights away by falling for Equifax's trap of "free" credit monitoring.
August 14, 2017
Equifax Continues to Profit from Identity Theft
Equifax has purchased identity theft protection company ID Watchdog for approximately $63 million. ID Watchdog is a company similar to LifeLock that consumers and/or businesses pay to monitor their credit and "protect" them from identity theft.
Once again, Equifax is turning identity theft into a profit center for its bottom line.
Equifax is charged by the Fair Credit Reporting Act to perform reasonable investigations of disputes made to it by consumers regarding inaccuracies on their Equifax credit reports. Many times these errors are actually credit cards, car loans or mortgages opened fraudulently as a result of the theft of the consumer's identity. Sometimes they are collection accounts placed on the consumer's credit report for the purpose of collecting a debt that was fraudulently incurred by the identity thief in the consumer's name.
Unfortunately for the victims of identity theft, Equifax often does not properly investigate the disputes it receives, particularly those resulting from identity theft. Instead of investing in its investigation department to make it better and thereby possibly comply with the Fair Credit Reporting Act and eliminate a lot of the problems caused by identity theft, Equifax instead turns identity theft into a means to profit by investing in a company that sells identity theft protection.
If Equifax consistently did the job that it is required by the Fair Credit Reporting Act to do and actually investigate the disputes it receives, consumers would not need to pay for additional identity theft protection or pay for multiple credit reports per year or monitoring services to monitor their credit. But instead of doing what it is required to do, Equifax instead chooses to profit from the misery of identity theft victims.
Equifax makes millions each year from the sale of credit monitoring services and the sale of extra credit reports to consumers worried about the contents of their credit report because their identities have been stolen. A quick glance at Equifax's website makes it clear that Equifax's emphasis is on profiting from credit monitoring rather than properly investigating consumer disputes. Equifax sells no less than 5 different plans to "monitor" and "protect" the contents of your credit report. They give these plans catchy names like Premier Plans, Advantage Plans, Family Plans, Patrol and even Patrol Premier, but they all have the same goal, to play on consumers' fear of identity theft to line Equifax's pockets.
The purchase of ID Watchdog provides Equifax with another mechanism to use to prey on consumers' fears. Instead of fixing the problem by deleting fraudulent accounts when disputed, Equifax wants consumers scared so they will buy more credit reports and purchase more monitoring plans. Not that Equifax is likely to delete any fraud accounts found by the consumers using Equifax's monitoring products.
Equifax needs to be held accountable for its decision to put its profits over the well being of consumers. The government has put in place the mechanism to hold Equifax accountable when it passed the Fair Credit Reporting Act. Now it is up to juries and judges to show Equifax and the other credit bureaus that putting profits over people will not be tolerated.
Once again, Equifax is turning identity theft into a profit center for its bottom line.
Equifax is charged by the Fair Credit Reporting Act to perform reasonable investigations of disputes made to it by consumers regarding inaccuracies on their Equifax credit reports. Many times these errors are actually credit cards, car loans or mortgages opened fraudulently as a result of the theft of the consumer's identity. Sometimes they are collection accounts placed on the consumer's credit report for the purpose of collecting a debt that was fraudulently incurred by the identity thief in the consumer's name.
Unfortunately for the victims of identity theft, Equifax often does not properly investigate the disputes it receives, particularly those resulting from identity theft. Instead of investing in its investigation department to make it better and thereby possibly comply with the Fair Credit Reporting Act and eliminate a lot of the problems caused by identity theft, Equifax instead turns identity theft into a means to profit by investing in a company that sells identity theft protection.
If Equifax consistently did the job that it is required by the Fair Credit Reporting Act to do and actually investigate the disputes it receives, consumers would not need to pay for additional identity theft protection or pay for multiple credit reports per year or monitoring services to monitor their credit. But instead of doing what it is required to do, Equifax instead chooses to profit from the misery of identity theft victims.
Equifax makes millions each year from the sale of credit monitoring services and the sale of extra credit reports to consumers worried about the contents of their credit report because their identities have been stolen. A quick glance at Equifax's website makes it clear that Equifax's emphasis is on profiting from credit monitoring rather than properly investigating consumer disputes. Equifax sells no less than 5 different plans to "monitor" and "protect" the contents of your credit report. They give these plans catchy names like Premier Plans, Advantage Plans, Family Plans, Patrol and even Patrol Premier, but they all have the same goal, to play on consumers' fear of identity theft to line Equifax's pockets.
The purchase of ID Watchdog provides Equifax with another mechanism to use to prey on consumers' fears. Instead of fixing the problem by deleting fraudulent accounts when disputed, Equifax wants consumers scared so they will buy more credit reports and purchase more monitoring plans. Not that Equifax is likely to delete any fraud accounts found by the consumers using Equifax's monitoring products.
Equifax needs to be held accountable for its decision to put its profits over the well being of consumers. The government has put in place the mechanism to hold Equifax accountable when it passed the Fair Credit Reporting Act. Now it is up to juries and judges to show Equifax and the other credit bureaus that putting profits over people will not be tolerated.
February 20, 2013
Ten Things the Credit Bureaus WON'T Say
The lastest blog post from the Kittell Law Firm website:
Kudos to AnnaMaria Andriotis at MarketWatch.com for penning a very detailed, in depth article about ten things the Credit Bureaus won't say. I have taken her ten items (in quotes below) and added my thoughts for each one. I even added an eleventh thing you won't hear the Credit Bureaus dare say.
Ms. Andriotis' ten things include:
1. "We track a lot more than just your credit." What else do the credit bureaus track? Pretty much anything they can. Like how often you change addresses, your income, your neighbors' income, your city's average credit score, how often you change jobs.
2. "Selling your secrets is how we make our money." That's right. We are not their customers. We are the credit bureaus' inventory. And they get that inventory virtually for free (and sometimes even paid to receive it). Our creditors provide our payment history to the credit bureaus, sometimes paying a fee to do so. The credit bureaus then turn around, compile the information provided by thousands of creditors into your credit report, then sell it to you and to your potential creditors. If they assign the oh so magical "credit score" to your report, you pay even more just to have this number (which is not even uniform among the credit bureaus, creditors, or any one else). Craziness. Even crazier ... the credit bureau industry raked in about $4 billion in 2011 selling you to your potential creditors. Bet you did not see a dime of what your information was sold for.
3. "What we know could cost you a new job." That's right. Your credit report is not just used to determine your credit eligibility. Its also used by many employers (roughly 47%) during the hiring process. That often leads to a catch 22 type situation that I have talked about before, where you can't pay your bills because you are unemployed but no one will hire you because your credit score dropped when you didn't pay your bills. Again I say ... craziness.
4. "Good thing no one's reporting on our mistakes. Oh, wait." That's right, the credit bureaus sure wish there was no one paying attention to their accuracy level, or lack thereof. But watchdog organizations and even governmental entities are watching and keeping track. US PIRG releases a report on the credit bureaus every few years. And, recently, the Federal Trade Commission issued a very damning report that showed that one in five (20%) of consumers had at least one error on one of their credit reports. 13% had errors serious enough to effect their credit score (i.e. making their interest rates go up or their credit limits lessen) and 5% had errors so bad that the errors would cause them to be denied credit in their entirety. 5% may not sound like a big number but that equates to about 10 million consumers. Crazy scary.
The Fair Credit Reporting Act requires the credit bureaus to follow reasonable procedures to assure maximum possible accuracy of the credit reports they create (and profit off of). Obviously, a 20% error rate is not "maximum possible accuracy" or anything close. Add that to an investigation procedure that does not come close to cutting it, and you have a recipe for a disaster for hardworking consumers.
5. "You all look so much alike..." This one hits on the faulty matching logic used by the credit bureaus. When the credit bureaus generate credit reports about you, they use the personal identifying information inputted by the entity seeking your credit report to match you to your accounts. At least that's how its supposed to work. But the credit bureaus do not require an exact match of your identifiers to the identifiers on an account before putting that account on your report and publishing it as your history, good bad or ugly. This leads to what us consumer lawyers call mixed files.
I once represented a man whose brother had bad credit. They shared the same last name (most brothers do). Their first names started with the same first initial (again, a lot of parents name their kids like that). Seven out of nine numbers of their SSN match, but that's not uncommon. If they got their SSNs in the same state and at the same time, its very likely the first five numbers match, since (back then) the first three numbers identified the state where the SSN was obtained and the middle two numbers indicate the grouping of SSNs. So if their parents got their SSNs at the same time (again, not uncommon), the first five numbers are very likely to match. The two brothers in my case also shared the same address at one point in time (about 10 years before, again not uncommon for brothers to at one point live at the same address). And their dates of birth were within ten years of each other, again not unusual for brothers. So the only personal identifier that match was the brothers' last name. But that was enough for one of the credit bureaus to merge their credit histories together, ruining my client's stellar credit with his deadbeat brother's terrible credit history. And, even worse, the credit bureau refused to fix the problem, despite years of dispute from my client, until he finally hired me and we sued. Crazy crazy.
6. "... its tough to tell you apart from someone pretending to be you." Ahhhh, identity theft. The reason I got into this area of law to begin with. While its often the fraudulent credit grantors that are to blame for the problems caused by identity theft, the blame also rests with the credit bureaus. What the credit bureaus want to ignore is the Fair Credit Reporting Act's requirement that they perform reasonable investigations of disputes lodged with them. They want to pretend that only the furnisher of the disputed information has such a duty (the furnisher does have such a duty, but its in addition to the credit bureaus' duty to investigate). So all the credit bureaus do to "investigate" is forward your dispute to the furnisher of the erroneous data and then ... wait for it ... the credit bureaus believe whatever the furnisher tells them, no matter what proof you have provided of your innocence. Unlike in baseball, where "a tie goes to the runner", in the credit bureau's world, you are out no matter how much you beat the throw, simply because the umpire says you are. And the umpire gets paid if he calls you out. Twice as crazy as crazy crazy.
7. "Your 'credit dispute' doesn't quite capture our attention." This ties into number 6. The Fair Credit Reporting Act requires the credit bureaus to forward all relevant information provided to them by the disputing consumer to the furnisher of the information being disputed. But what's nuts (I've run out of ways to say crazy)? The credit bureaus do not even have a system in place that allows them to forward any documentation or other proof from consumers to the furnishers. All they provide is a two digit code that is translated on the furnisher's end to a basic dispute like "identity theft" or "not mine" or "never late". So send proof that you were never late, including bank statements and cancelled checks. But don't expect your proof to make it to that umpire waiting to get paid by calling you out.
8. "But bypass us on a dispute, and it'll cost you." This is one of the main weaknesses of the Fair Credit Reporting Act. There is no liability on the part of the credit bureaus or the furnishers of erroneous information if you do what most think is natural - dispute directly to the furnisher. For the duties to perform reasonable investigations under the FCRA to be triggered, the dispute must be made to the credit bureau, even though all they are going to do is pass the buck on to the furnisher. Many consumers do not know this and end up with no claim because they went straight to the furnisher instead of disputing to the credit bureaus.
But disputes to furnishers are important. See number 6 and 7. Because the credit bureaus do not pass on your proof to the furnishers and do a lack luster job translating your two page dispute letter to a two digit dispute code, sometimes it is up to you to let the furnisher know what your dispute really is. And disputing to the furnisher in addition to the credit bureaus eliminates a common defense I see from the furnishers where they claim ignorance as to a consumer's dispute because they did not know what the credit bureaus meant by their two digit dispute code. So, all you consumers out there, be sure to lodge your disputes with both the credit bureaus (to trigger the FCRA) and with the furnishers (so they can't avoid the FCRA by claiming ignorance).
9. "By the time you're done fighting us, your toddler could be a teen." This one I don't necessarily agree with but only because the author of the Marketwatch.com article did not mention that you can stop the errors in most cases by suing the credit bureaus and/or furnishers. So, consumers, dispute the errors. Dispute them often. Give the credit bureaus and the furnishers multiple opportunities to do the right thing and fix their errors. And, if and when they don't, hire a consumer lawyer like me and sue the bureaus and furnishers for all the heart ache their refusal to follow the law caused.
10. "Be careful what you pay for." I've blogged on this topic multiple times at my blog located at www.fcralawyer.blogspot.com. The credit score that the credit bureaus so eagerly want to sell you is not even a score that is used by your potential creditors in most instances. It can be enlightening to see what your score is, but that's about it. Creditor use different scoring models than what the credit bureaus sell. The most common used score is the FICO score which consumers can buy, but not from the credit bureaus. To see your FICO score, go to http://www.myfico.com.
All in all, a very informative and well researched and written article about the true story of the credit bureaus. But I will add a number 11 of my own:
11. "We spend top dollar to investigate your disputes." Not only do they not pay top dollar, the credit bureaus do not even pay minimum wage to its investigators. Your disputes are being handled by outsourced investigators in such places as Chile, Jamaica and the Philippines, where the credit bureaus do not even have to pay minimum wage. And they work their third world work force by placing quotas on how many investigations they perform a day. One such credit bureau expected its investigators to perform an investigation every two minutes. That's simply not enough time to "reasonably" investigate anything. Craziness to the nth degree.
Please read the full article at http://www.marketwatch.com/story/10-things-credit-bureaus-wont-say-2013-02-15. Again, the article is very well written and a must read.
February 02, 2013
Equifax is selling your private employment info - including how much you make!
Think your income is a secret? Think again! Equifax, one of the big three national credit bureaus, has accumulated a database of over 190 million employment and salary records (including income) and is in the business of selling it without the consent of the consumers to which the information relates.
Equifax calls this database the "Work Number" database, which is comprised of what many until now considered private information. The Work Number database contains week to week pay stub information dating back years. It also contains information about whether a consumer ever filed an unemployment claim, information about their health care providers and whether the consumer has dental insurance.
How does Equifax obtain this information? Directly from thousands of U.S. businesses, who actually pay Equifax to accept the private information of their employees. These businesses should be ashamed of themselves for disclosing this private information of their employees. The businesses involved in this nefarious scheme include many of the Fortune 500. Some even allow Equifax direct access to their data so Equifax always has the most up to date information.
Equifax sells your personal income data to various types of buyers, including debt collectors and student loan issuers. Doing so enhances the debt collectors ability to coerce consumers into paying.
January 08, 2013
New FCRA Lawsuit Against Equifax
The Kittell Law Firm filed a new Fair Credit Reporting Act lawsuit today against Equifax for mixing the credit file of our client with that of his father. As a result, three of the father's tax liens were reported by Equifax on our client's credit report. What's even worse than that? Equifax failed to remove the father's tax liens from the son's credit report, even after the son provided documentation that the tax liens belonged to the father. Equifax continued reporting the father's tax liens on the son's credit report, causing the son to be denied credit on at least three occasions.
Its bad enough to mix up two people with different names, different Social Security numbers, different addresses and different dates of birth. What's worse is that Equifax still could not get it right even after being told to fix the obvious error. Good thing the Fair Credit Reporting Act exists to provide consumers with the opportunity to obtain justice for the aggravation and other damages caused by the credit bureaus' callous disrespect for the accuracy of the credit reports they generate.
December 31, 2012
Equifax buys CSC
Credit bureau Equifax recently purchased CSC Credit Services, Inc. for the price of $1 Billion. CSC was one of the last (if not THE last) of the affiliate bureaus to the big three credit bureaus. Back when I started suing credit bureaus using the Fair Credit Reporting Act, there were several affiliate bureaus to the credit bureaus, including CSC and one right up the road from here called Memphis Consumer Credit Bureau.
The affiliate bureaus basically "owned" the credit files of consumers living in certain geographical areas, even though the data comprising the credit files were stored on one of the big three bureaus' computer systems. CSC owned consumers' Equifax credit files from Texas to Indiana (I know because I have sued them in both states and many in between).
This led to a lot of confusion for consumers, who would buy their Equifax credit reports, find an error, then dispute the error to Equifax. At first, Equifax would just write the consumer back and say that Equifax did not own their file and they would have to contact CSC to dispute the error. They stopped this practice eventually, probably because lawyers (myself included) kept arguing that Equifax, when it receives a dispute, has to investigate it, particularly when the disputed data is housed on Equifax's computer system. Equifax never did agree, but started forwarding the disputes themselves to CSC to "investigate", instead of relying on the consumer to re-send the dispute.
The Equifax/CSC relationship made for trickier lawsuits, since Equifax retained the duty to "follow reasonable procedures to assure maximum possible accuracy" of the credit reports it generated, but shifted the responsibility for performing reasonable procedures to CSC since they owned the data that Equifax was publishing for the consumers located in CSC's ownership area. So, in some cases you would need to sue both Equifax and CSC but in some (those involving only botched investigations) you could sue just CSC.
At least the purchase of CSC will possibly do away with some of the confusion, both for consumers and lawyers suing Equifax.
Funny side note - I got word of the purchase of CSC by Equifax a couple of weeks ago (I'm slow to blog about it thanks to the holidays and a busy work schedule). After hearing the news, I received a call from an Equifax attorney on the other side of one of my FCRA cases. I told him about it and he had not even heard yet. Then, a week or so later, he calls and leaves me a message to "let me know" that Equifax had purchased CSC. Funny, I thought I had let him know, not the other way around. Guess even Equifax's attorneys do not follow reasonable procedures to assure maximum possible accuracy.
May 15, 2012
Equifax says pay day lenders not reporting correctly
According to Julian Knight at The Independent, Equifax issued an alert recently indicating that some pay day lenders are failing to report all of their lending transactions. This causes the credit histories provided by Equifax about consumers who utilize pay day lenders to be incomplete. As a result, when a potential creditor accesses such a consumer's credit report, the creditor will be unaware of the pay day loans and the subsequent payment history of the consumer on those loans.
Pay day lenders are short term lenders that lend short term with huge interest rates. Interest rates on the short term loans can be as much as 4,000 percent (yes, you read that right). The loans are so short term that the interest on them seems small, even though its actual yearly percentage is huge. The pay day loan industry is accused of targeting the poor and the young and forcing them into a debt ridden lifestyle.
Pay day lenders should report their account histories correctly, thereby rewarding those that pay timely with good reporting that could improve the consumer's credit score and hopefully allow him or her to escape the pay day loan trap. Unfortunately, pay day lenders do not have much incentive to do this, since it could conceivably cost them future business.
My advice - avoid pay day loans like the plague.
Pay day lenders are short term lenders that lend short term with huge interest rates. Interest rates on the short term loans can be as much as 4,000 percent (yes, you read that right). The loans are so short term that the interest on them seems small, even though its actual yearly percentage is huge. The pay day loan industry is accused of targeting the poor and the young and forcing them into a debt ridden lifestyle.
Pay day lenders should report their account histories correctly, thereby rewarding those that pay timely with good reporting that could improve the consumer's credit score and hopefully allow him or her to escape the pay day loan trap. Unfortunately, pay day lenders do not have much incentive to do this, since it could conceivably cost them future business.
My advice - avoid pay day loans like the plague.
October 01, 2011
New scam involving Equifax
The Better Business Bureau serving eastern North Carolina is warning consumers on its website about a new scam involving Equifax. Business are apparently receiving faxes that appear to be from Equifax, one of the three major consumer reporting agencies, but are actually from scammers. The faxes seek sensitive financial information and asks the businesses to fax the information back to "Equifax" - but its not Equifax who is sending the faxes. The faxes are fraudulent and should be ignored.
Just an FYI - before you ever respond to any solicitation for personal or private information, confirm with the alleged source that the request is legitimate.
Just an FYI - before you ever respond to any solicitation for personal or private information, confirm with the alleged source that the request is legitimate.
July 18, 2011
The Fourth Credit Bureau?
If you have been reading this blog much, you have probably seen me refer to Equifax, Experian and Trans Union as the Big Three. They could also be called the Three Stooges, but I'd hate to insult Moe, Larry and Curly.
But what a lot of people don't realize is that there are many, many consumer reporting agencies outside of the Big Three. I was reminded of this recently when I read a Washington Post article entitled "Five Facts about the Fourth Bureau". At first I thought there might be a new bureau emerging (kind of like Shemp, the fourth stooge). Instead, the article lumps together all the smaller, unorthodox consumer reporting agencies as the "fourth bureau".
The other bureaus tend to cover topics that are missed by the Big Three. Some can be seen as niche market CRAs, such as the ones that collect information about rent paying history, which they then sell to potential landlords. Other types of information collected by the "fourth bureau" are payment histories regarding utilities payments, cellphone bills, magazine subscriptions and gym memberships. Some even keep up with whether consumers return their rental movies on time. Others include companies that compile investigative consumer reports and that provide criminal history type reports that can be used for background checks.
These smaller bureaus can play important roles as over 30 million U.S. consumers don't show up in the Big Three's databases. These consumers are in a credit morass, as they can not get a loan without a credit history and can not get a credit history without getting loans. But they can rent apartments, rent movies, sign up for utilities, etc. The payment histories generated by these actions can sometimes be used in place of a more traditional credit report.
But these types of payment histories can also hurt a consumer's chances of getting credit if they do not reflect a responsible payment pattern, or if they contain damaging errors, which they are apt to contain. Approximately 25% or more of the Big Three's reports contain damaging errors, so the other bureaus are likely to have a similar error rate. The good news ... even though these companies are not the "Big Three", they are still subject to the vast majority of the requirements of the Fair Credit Reporting Act, including the requirement that they provide to consumers upon request a complete report of all information in their database about the consumer and 15 U.S.C. 1681i's requirement that they reasonably investigate consumer's disputes of inaccurate information.
The down side ... to get your report from the small bureaus will cost you some money (approximately $11) since the yearly free credit report requirement only applies to the Big Three. Consumers can also get a free credit report from any CRA if they are denied credit (or suffer some other adverse action) as a result of the contents of the CRA's report.
The same rules regarding disputing errors also apply to the "fourth bureau" ... namely disputing in writing and dispute often. If that doesn't work, hire someone like me to sue for damages resulting from the errors (which usually also includes the benefit of a corrected credit report. Funny how a lawsuit will do things that a multitude of even the best dispute letters can not.) If any of you need help with the Big Three or the "fourth bureau", I'm only an e-mail away.
But what a lot of people don't realize is that there are many, many consumer reporting agencies outside of the Big Three. I was reminded of this recently when I read a Washington Post article entitled "Five Facts about the Fourth Bureau". At first I thought there might be a new bureau emerging (kind of like Shemp, the fourth stooge). Instead, the article lumps together all the smaller, unorthodox consumer reporting agencies as the "fourth bureau".
The other bureaus tend to cover topics that are missed by the Big Three. Some can be seen as niche market CRAs, such as the ones that collect information about rent paying history, which they then sell to potential landlords. Other types of information collected by the "fourth bureau" are payment histories regarding utilities payments, cellphone bills, magazine subscriptions and gym memberships. Some even keep up with whether consumers return their rental movies on time. Others include companies that compile investigative consumer reports and that provide criminal history type reports that can be used for background checks.
These smaller bureaus can play important roles as over 30 million U.S. consumers don't show up in the Big Three's databases. These consumers are in a credit morass, as they can not get a loan without a credit history and can not get a credit history without getting loans. But they can rent apartments, rent movies, sign up for utilities, etc. The payment histories generated by these actions can sometimes be used in place of a more traditional credit report.
But these types of payment histories can also hurt a consumer's chances of getting credit if they do not reflect a responsible payment pattern, or if they contain damaging errors, which they are apt to contain. Approximately 25% or more of the Big Three's reports contain damaging errors, so the other bureaus are likely to have a similar error rate. The good news ... even though these companies are not the "Big Three", they are still subject to the vast majority of the requirements of the Fair Credit Reporting Act, including the requirement that they provide to consumers upon request a complete report of all information in their database about the consumer and 15 U.S.C. 1681i's requirement that they reasonably investigate consumer's disputes of inaccurate information.
The down side ... to get your report from the small bureaus will cost you some money (approximately $11) since the yearly free credit report requirement only applies to the Big Three. Consumers can also get a free credit report from any CRA if they are denied credit (or suffer some other adverse action) as a result of the contents of the CRA's report.
The same rules regarding disputing errors also apply to the "fourth bureau" ... namely disputing in writing and dispute often. If that doesn't work, hire someone like me to sue for damages resulting from the errors (which usually also includes the benefit of a corrected credit report. Funny how a lawsuit will do things that a multitude of even the best dispute letters can not.) If any of you need help with the Big Three or the "fourth bureau", I'm only an e-mail away.
December 11, 2010
$1 million verdict against Equifax won't be reduced
This man's story reminds me of a client I represented a while back against ... you guessed it ... Equifax. More about my case below:
Unfortunately, just like Mr. Drew, my client's story did not end there. Equifax and the other three bureaus refused to believe my client's disputes regarding the scores of accounts opened in his name, despite the conviction of the identity thief that opened the accounts. In fact, the identity thief served his entire sentence before Equifax and the other bureaus finally fixed my client's credit reports and then only after I had sued the bureaus on behalf of my client. In other words, the conviction of the identity thief was not good enough proof for Equifax, Experian and Trans Union. But my federal lawsuit ironically got the job done, but not before my client suffered very, very significant emotional distress. At his lowest point, he was sitting in his closet with a gun in his mouth because of the sheer shambles that this life had been turned into after the complete loss of his financial independence caused by the credit bureaus' failure to do their job.
Luckily, he did not pull the trigger and eventually fought back through his lawsuit, which led to his credit reports being corrected. Equifax should be ashamed to claim that Mr. Drew's damages did not justify an award of $315,000 in light of their intentional and flagrant disregard for their statutory duties. I'm glad the judge saw through Equifax's sham of an argument. But I'm sure they will appeal to the next level.
As for my client, his case never went to trial as Equifax and the other bureaus settled for a "confidential" sum after suit was filed.
By Maria DinzeoNow, about my case. Just like Eric Drew, my client helped the authorities nab his identity thief who, among other things, had opened scores of accounts in my client's name and had even bought 2 or 3 vehicles, including a Harley, using my client's identity. Thanks to the persistence of my client, the authorities (the FBI if I remember right) caught the identity thief while riding the ill-gotten Harley. The identity thief was tried, convicted and sentenced.
SAN FRANCISCO (CN) - A cancer survivor who won more than $1 million from Equifax for improperly handling his identity theft report can keep the full award, a federal judge ruled.
U.S. District Judge Susan Illston rejected the credit reporting agency's motions for a new trial or to set aside so-called "excessive" damages.
Eric Drew, who was twice referred to hospice care by hospitals that said they could not treat his cancer, had his identity stolen in 2003 by a phlebotomist working at the cancer center where he had undergone treatment.
Drew discovered that multiple fraudulent credit accounts had been opened in his name with thousands of dollars in balances.
"Plaintiff testified that, while he was away from home being treated for near fatal cancer, he singlehandedly caught the individual who had stolen his identity even though the police and hospital personnel had not believed him or wanted to help him," Illston wrote.
Fearing that his life was in danger, Drew called newspapers, the FBI, police and his hometown mayor in Los Gatos, Calif.
When a local television station picked up his story, the identity thief was caught and convicted of criminal violation of the Health Insurance Portability and Accountability Act.
Over the next two years, however, Equifax and a number of other credit reporting agencies and banks allegedly thwarted Drew's attempts to repair his credit and reinvestigate his claims of identity theft.
After a nine-day trial, a jury awarded Drew $6,326.69 in economic damages, $315,000 in noneconomic compensatory damages and $700,000 in punitive damages.
Among Equifax's requests on appeal, the company argued to reduce "excessive" compensatory and punitive damages to $200,000 and $50,000, respectively.
"Here, defendant leaves the court to speculate where its $200,000 figure comes from," Illston wrote. "It does not explain why $315,000 is shocking to the conscience or unsupported by the evidence while $200,000 is a proper number."
Illston refused to grant remittance, finding that Drew had "presented significant evidence of emotional distress that he suffered as a result of his unique circumstances."
"The evidence strongly supports a finding that the harm plaintiff suffered was not the result of mere accident," the ruling states.
Against all odds, Drew identified the man who stole his identity, beat cancer and launched an unprecedented criminal HIPAA prosecution, "but he couldn't navigate the system that defendant had set up to correct his credit report," Illston wrote.
Unfortunately, just like Mr. Drew, my client's story did not end there. Equifax and the other three bureaus refused to believe my client's disputes regarding the scores of accounts opened in his name, despite the conviction of the identity thief that opened the accounts. In fact, the identity thief served his entire sentence before Equifax and the other bureaus finally fixed my client's credit reports and then only after I had sued the bureaus on behalf of my client. In other words, the conviction of the identity thief was not good enough proof for Equifax, Experian and Trans Union. But my federal lawsuit ironically got the job done, but not before my client suffered very, very significant emotional distress. At his lowest point, he was sitting in his closet with a gun in his mouth because of the sheer shambles that this life had been turned into after the complete loss of his financial independence caused by the credit bureaus' failure to do their job.
Luckily, he did not pull the trigger and eventually fought back through his lawsuit, which led to his credit reports being corrected. Equifax should be ashamed to claim that Mr. Drew's damages did not justify an award of $315,000 in light of their intentional and flagrant disregard for their statutory duties. I'm glad the judge saw through Equifax's sham of an argument. But I'm sure they will appeal to the next level.
As for my client, his case never went to trial as Equifax and the other bureaus settled for a "confidential" sum after suit was filed.
Subscribe to:
Posts (Atom)