Credit monitoring agency Equifax revealed shocking news late September 7: A data breach of the company’s servers from mid-May through July 2017 resulted in the theft of the personal information of up to 143 million U.S. consumers—a huge chunk of the country’s 324 million population. Equifax says the breach leaked highly sensitive information, too, including “names, Social Security numbers, birth dates, addresses and, in some instances, driver’s license numbers.”
That’s everything crooks need to open up credit lines in your name, or worse. And now it’s in nefarious hands.
Editor’s note: This article was originally published September 8, 2017, but has been updated with information about Equifax waiving credit freeze fees and the FTC’s warning about fraudulent phone calls.
Equifax hack: Was I affected?
Shamefully, Equifax won’t be contacting most of the 143 million victims directly to let them know they’ve fallen prey to data hackers. The hackers also swiped credit card numbers for 209,000 people, and “certain dispute documents with personal identifying information” for 182,000 more. Equifax will mail those particular victims—far less than 1 percent of everyone affected—a notice that they were affected by the breach.
Finding out if you were affected by the Equifax hack is trickier (and murkier) if you’re not part of that sliver. Equifax created the www.equifaxsecurity2017.com website for U.S. consumers to “see if your personal information is potentially impacted.” Let’s be frank: It looks like a fraud site. It’s frighteningly bare-bones and runs on WordPress, the URL differs from Equifax’s main site, some browsers were throwing up phishing warnings due to back-end configuration issues, and Equifax even asks for your social security number to confirm whether it leaked your social security number. Those are all classic signs of a malicious phishing site, but fear not: equifaxsecurity2017.com is legitimate.
Head to the Potential Impact page of the Equifax Security website to find out if you were affected. Simply click the “Check potential impact” button and supply your last name and the last six digits of your social security number.
If the credit agency doesn’t believe you were impacted, it’ll tell you so and pitch you to register for Equifax’s “TrustID Premier” credit monitoring service, which the company will provide for free for one year regardless of whether or not your data was stolen.
Alternatively, the site may report that “We believe that your personal information may have been impacted by this incident” and again prompt you to enroll for TrustID Premier. Equifax has confirmed that signing up for TrustID Premier will not prevent you from joining a class-action suit over this issue.
Equifax has also set up a dedicated call center at 866-447-7559 for additional questions. It’s open from 7 a.m. to 1 a.m. Eastern time every day, including weekends.
Update: If you receive a call that claims to be from Equifax, don’t provide any personal information. “They’re not from Equifax. It’s a scam. Equifax will not call you out of the blue,” the U.S. FTC warns. Report the con artists to the FTC.
Equifax hack: Monitor your credit report
Regardless of whether you accept TrustID Premier, it’s a good idea to keep an eye on your credit report for fraudulent activity—even if Equifax “believes that your personal information was not impacted.” Experts poking at Equifax’s data breach checker discovered it may be spitting out inaccurate records.
You can get a copy of your credit report online at www.annualcreditreport.com. You can request a free copy of your credit report once per year from each of the major credit monitoring agencies: Equifax, TransUnion, and Experian. Stagger the requests for every few months and you can keep an eye on things throughout the year.
The FTC warns that www.annualcreditreport.com is the only site “authorized to fill orders for the free annual credit report you are entitled to under law,” so steer clear of others making similar claims. If you see any fraudulent activity on your credit report, notify your bank or credit card company immediately.
You may also want to put a fraud alert or credit freeze on your account to thwart would-be identity thieves. Equifax is waiving its usual fee for credit freezes through November 21, Lifehacker reports. If you decide to take preventative action, be sure to read the FTC’s guide to credit freezes versus fraud alerts.
Brad Chacos spends his days digging through desktop PCs and tweeting too much. He specializes in graphics cards and gaming, but covers everything from security to Windows tips and all manner of PC hardware.