yahoodatabreachsettlement.com just looks scammy as hell. It's a pity there's not a .gov domain set up for this sort of thing - when there's a settlement, a court order gets issued for yahoo.settlements.gov to get set up.
From: info@service.comms.yahoo.net
Subject: Yahoo Security Breach Proposed Settlement
If you had a Yahoo account anytime in 2012 through 2016, a pending class action settlement may affect you.
A Class Action Settlement has been proposed in litigation against Yahoo! Inc. (“Yahoo”) and Aabaco Small Business, LLC (together, called “Defendants” in this notice), relating to data breaches (malicious actors got into system and personal data was taken) occurring in 2013 through 2016, as well as to data security intrusions (malicious actors got into system but no data appears to have been taken) occurring in early 2012 (collectively, the “Data Breaches”).
....
I know that. It makes me twitchy every time.
After the big Equifax breach, someone made a spoof site of their informational page, and Equifax themselves accidentally linked to it. (https://www.nytimes.com/2017/09/20/business/equifax-fake-web...)
> there doesn't seem to have been many issues before.
Again, sure. I'm surprised scammers haven't changed that yet.
Also FWIW the damage figures are also nonsense, how much can the equifax leak hurt anyone if their data was already for sale on ssndob? Almost all Americans have had their information compromised in hacks they’ve never heard of.
Am I wrong?
What we really need is to shift the burden of proof from the consumer to the lender. If the lender cannot establish beyond a reasonable doubt that they entered into a contact with the consumer, then the consumer can sue them. Just having the SSN, name, address of the consumer, etc. shouldn't be enough to prove the lender entered into a contact with the consumer.
What should be enough? What documentation should banks have to collect before opening, say, a credit card with a $1000 limit for a customer?
For what? The consumer isn’t responsible anyway if the lender gets defrauded.
Is the fraud in itself not enough of a punishment for the lender?
I’d argue that the real problem here are the regulators who have shaped this broken system. Not the lack of punishments for existing within it.
>Just having the SSN, name, address of the consumer, etc. shouldn't be enough to prove the lender entered into a contact with the consumer.
It isn’t. The lender enters into a contract with a fraudster and gets fucked. The lender is the victim, not the consumer.
Here's a pretty entertaining peek (by Micheal Lewis) into what happens because of fraud that the consumer had literally nothing to do with and how the lender (bank) is able to put the onus on him to fix. It's not life or death, at least in this example, but it really shows how obviously unfair the system is. Apparently this happens quite a bit.
https://atrpodcast.com/episodes/the-seven-minute-rule-s1!1c9...
For the hours of phone calls over several weeks/months/years it takes to clear it all up?
> For what?
For sending a bad report about the consumer they claim to have entered into a contract with to the credit bureaus.
> The consumer isn’t responsible anyway if the lender gets defrauded.
That's true, but the lender is responsible for what they report to the credit bureaus.
> Is the fraud in itself not enough of a punishment for the lender?
If they don't involve the actual consumer in their lack of due diligence, then sure.
> It isn’t. The lender enters into a contract with a fraudster and gets fucked. The lender is the victim, not the consumer.
If the lender involves the consumer by sending a bad report to the bureaus, then they have harmed the consumer.
Source: my wife is an attny & worked at a top class-action firm for over a decade. Without breaking confidentiality, I still heard all kinds of interesting stories about the mechanics & internals of how the system works - how multiple firms work together, how cases are started, etc., but never anything remotely related to such a "targeted revenue" concept. Of course there's the obvious requirement that any case specify damages at the outset, but even this number can increase or decrease as the case proceeds.
A law firm can of course make big money with a big case, but it is a big risk that can take many years to return, and it can fail.
Can I set up a “virtual” credit monitoring that provides that type of service in name only to cover that requirement? Imagine paying $5 to claim you have credit monitoring for settlement purposes.
Absolutely. https://creditkarma.com/ is free, and counts.
The one thing most District Court judges like least is being overruled on appeal.
But the real blame falls on Congress. They ought to adopt a real regulatory apparatus and put away the class action (vice mass action).
Credit monitoring, like antivirus, is something you should have, but should not be paying for.
For "credit monitoring" specifically, individuals should not be doing the surveillance bureau's work for them. If lenders don't think it is necessary to do diligence when issuing credit, then why should I make up for it by half-policing [0] use of my public identifiers? The more painful fraud is for lenders, the more incentive they have to actually do some diligence rather than trying to push their lack of responsibility onto everyone else.
[0] If I had total legal control over the use of my public identifiers, I would simply tell the surveillance bureaus to delete all data kept on me. But we are not given this option, which indicates how the surveillance bureaus do not work for us. The less we give them, the better.
Experian.
The company responsible for possibly the biggest data leak in history. Advertising data protection services.
The balls of some companies
I haven't tried it but it looks ripe for attack. A security noob could try using SQLMap and Nikto. If that were to happen though, would there be a class action lawsuit against the class action settlement team?