{"id":10451,"date":"2017-11-13T10:18:00","date_gmt":"2017-11-13T18:18:00","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2017\/11\/13\/news-4224\/"},"modified":"2017-11-13T10:18:00","modified_gmt":"2017-11-13T18:18:00","slug":"news-4224","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2017\/11\/13\/news-4224\/","title":{"rendered":"How to Opt Out of Equifax Revealing Your Salary History"},"content":{"rendered":"<p><strong>Credit to Author: BrianKrebs| Date: Mon, 13 Nov 2017 16:55:19 +0000<\/strong><\/p>\n<p>A KrebsOnSecurity <a href=\"https:\/\/krebsonsecurity.com\/?s=talx&amp;x=0&amp;y=0\" target=\"_blank\" rel=\"noopener\">series<\/a> on how easy big-three credit bureau <strong>Equifax<\/strong> makes it to get detailed salary history data on tens of millions of Americans apparently inspired a deeper dive on the subject by <em>Fast Company<\/em>, which examined how this Equifax division has been one of the company&#8217;s best investments. In this post, I&#8217;ll show you how to opt out of yet another Equifax service that makes money at the expense of your privacy.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-40776\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2017\/09\/equifax-hq-580x384.png\" alt=\"\" width=\"580\" height=\"384\" srcset=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2017\/09\/equifax-hq-580x384.png 580w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2017\/09\/equifax-hq-768x509.png 768w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2017\/09\/equifax-hq.png 770w\" sizes=\"auto, (max-width: 580px) 100vw, 580px\" \/><\/p>\n<p>My <a href=\"https:\/\/krebsonsecurity.com\/2017\/10\/equifax-breach-fallout-your-salary-history\/\" target=\"_blank\" rel=\"noopener\">original report<\/a> showed how the salary history for tens of millions of employees at some of the world&#8217;s largest corporations was available to anyone armed with an employee&#8217;s Social Security number and date of birth &#8212; information that was stolen on 145.5 million Americans in the recent breach at Equifax.<\/p>\n<p>Equifax took down their salary portal &#8212; a service from the company&#8217;s <strong>Workforce Solutions<\/strong> division known as <strong>The Work Number<\/strong> (formerly &#8220;<strong>TALX<\/strong>&#8220;) &#8212; just a few hours after my story went live on Oct. 8. The company explained that the site was being disabled for routine maintenance, but Equifax <a href=\"https:\/\/krebsonsecurity.com\/2017\/11\/equifax-reopens-salary-lookup-service\/\">didn&#8217;t fully reopen the portal until Nov. 2<\/a>, following the addition of unspecified &#8220;security improvements.&#8221;<\/p>\n<p><em>Fast Company<\/em> writer <a href=\"https:\/\/www.fastcompany.com\/40485634\/equifax-salary-data-and-the-work-number-database\" target=\"_blank\" rel=\"noopener\">Joel Winston&#8217;s story<\/a> examines how some 70,000 companies &#8212; including <strong>Amazon<\/strong>, <strong>AT&amp;T<\/strong>, <strong>Facebook<\/strong>, <strong>Microsoft<\/strong>, <strong>Oracle<\/strong>, <strong>Twitter<\/strong> and <strong>Wal-Mart<\/strong> &#8212; actually pay Equifax to collect, organize, and re-sell their employees\u2019 personal income information and work history.<\/p>\n<p>&#8220;A typical employee at Facebook (which also owns Instagram and WhatsApp) may require verification of his employment through TALX when he leases an apartment, updates his immigration status, applies for a loan or public aid, or applies for a new job,&#8221; Winston writes. &#8220;If his new prospective employer is among the 70,000 approved entities in Equifax\u2019s verifier network with a \u201cpermissible purpose,\u201d that company can purchase his employment and income information for about $20.&#8221;<\/p>\n<p>While this may sound like a nice and legitimate use of salary data, the point of my original report was that this salary data is also available to anyone who has the Social Security number and date of birth on virtually any person who once worked at a company that uses this Equifax service.<\/p>\n<p>In May 2017, KrebsOnSecurity <a href=\"https:\/\/krebsonsecurity.com\/2017\/05\/fraudsters-exploited-lax-security-at-equifaxs-talx-payroll-division\/\" target=\"_blank\" rel=\"noopener\">broke the story<\/a> of how this same Equifax Workforce portal was abused for an entire year by identity thieves involved in tax refund fraud with the <strong>Internal Revenue Service<\/strong>. Fraudsters used SSN and DOB data to reset the 4-digit PINs given\u00a0to customer employees as a password, and then steal W-2 tax data after\u00a0successfully answering personal questions\u00a0about those employees.<\/p>\n<p>Curiously, Equifax claims they have no evidence that anyone was harmed as a result of the year-long pattern of tax fraud related to how easy it was to coax salary and payroll data out of its systems.<\/p>\n<p>\u201cWe do not know of any specific fraud incidents linked with the Work Number,\u201d Equifax spokeswoman <strong>Marisa Salcines<\/strong> told <em>Fast Company<\/em>.<\/p>\n<p>This statement sounds suspiciously like what big-three credit bureau <strong>Experian<\/strong> <a href=\"https:\/\/krebsonsecurity.com\/2014\/03\/experian-lapse-allowed-id-theft-service-to-access-200-million-consumer-records\/\" target=\"_blank\" rel=\"noopener\">told lawmakers in 2014 after they were hauled up to Capitol Hill<\/a> to explain another breach that was scooped by KrebsOnSecurity: That <a href=\"https:\/\/krebsonsecurity.com\/2013\/10\/experian-sold-consumer-data-to-id-theft-service\/\" target=\"_blank\" rel=\"noopener\">a Vietnamese man who ran an identity theft service<\/a> which catered to tax refund fraudsters <a href=\"http:\/\/krebsonsecurity.com\/2013\/10\/experian-sold-consumer-data-to-id-theft-service\/\" target=\"_blank\" rel=\"noopener\">had access for nine months to more than 200 million consumer records maintained by Experian<\/a>.<\/p>\n<p>Experian&#8217;s suits told lawmakers that no consumers were harmed even as the <strong>U.S. Secret Service<\/strong> was busy <a href=\"https:\/\/krebsonsecurity.com\/2014\/04\/an-allegation-of-harm\/\" target=\"_blank\" rel=\"noopener\">arresting customers<\/a> of this identity theft service &#8212; nearly all of whom were involved in tax refund fraud and <a href=\"https:\/\/krebsonsecurity.com\/2014\/05\/experian-breach-tied-to-ny-nj-id-theft-ring\/\" target=\"_blank\" rel=\"noopener\">other forms of consumer ID theft<\/a>.<span id=\"more-41495\"><\/span><\/p>\n<p>Loyal readers here will know I have long urged consumers to opt out of letting the big credit bureaus resell your credit file to potential lenders (and, by proxy, to ID thieves), by <a href=\"https:\/\/krebsonsecurity.com\/2015\/06\/how-i-learned-to-stop-worrying-and-embrace-the-security-freeze\/\" target=\"_blank\" rel=\"noopener\">placing a freeze on their credit files<\/a> with the Equifax, Experian, <strong>Trans Union<\/strong> and <strong>Innovis<\/strong>.<\/p>\n<p>In the wake of the Equifax breach, one thing I&#8217;ve heard from so many readers that was a big factor in their decision to finally freeze their credit was that the bureaus would no longer be able to profit by selling their credit files.<\/p>\n<p>As it happens, it is possible to opt out of having your salary data sold through Equifax. According to Equifax, this involves placing a free &#8220;freeze&#8221; on your file with the Work Number. These instructions on how to do that come verbatim from Equifax:<\/p>\n<p>To place a security freeze on your The Work Number employment report, send<br \/> your request via mail to:<\/p>\n<p>TALX Corporation<br \/> ATTN: Employment Data Report Dept 19-10<br \/> 11432 Lackland Road<br \/> St. Louis, Missouri 63146<\/p>\n<p>Or, you may contact us on the web at http:\/\/www.theworknumber.com or call 800-996-7566.<\/p>\n<p>It&#8217;s not clear what may be the potential consequences of freezing your file with The Work Number. Fast Company explains the service and its giant database &#8220;helps streamline various processes for employers and other agencies, and it helps employees too, Equifax wrote in an emailed statement. The Work Number provides prospective landlords a way to verify an applicant\u2019s income, for instance, or makes it cheaper for human resources departments to examine an applicant\u2019s background.&#8221;<\/p>\n<p>Here&#8217;s Equifax explaining why consumers might want to leave their files alone:<\/p>\n<blockquote>\n<p dir=\"ltr\">\u201cWithout the Work Number, a lender, property manager or pre-employment screener will call an employer and explain why they need to check on an employee or former employee\u2019s employment or income. That individual has no control over who picks up the phone, whether the right information is actually given out, or if his or her privacy will be respected.\u201d<\/p>\n<\/blockquote>\n<p>Neither does the consumer have any control over to whom Equifax gives this data. I for one am taking my chances and freezing my salary data at Equifax. I&#8217;ll let you know how it goes.<\/p>\n<p dir=\"ltr\">Before you opt out, you may wish to see which lenders, credit agencies and other entities may have received or attempted to pull your Work Number salary history.<\/p>\n<p dir=\"ltr\">To request a free Employment Data Report, you&#8217;ll need to fill out a form at\u00a0<a href=\"http:\/\/www.theworknumber.com\/Employees\/DataReport\/index.asp\" rel=\"noreferrer\" data-ss1510584801=\"1\">the Work Number website,<\/a>\u00a0or <a href=\"http:\/\/www.theworknumber.com\/Employees\/DataReport\/report_request.pdf\" target=\"_blank\" rel=\"noopener\">make a request<\/a> by mail, or through a toll-free phone number (1-866-222-5880).<\/p>\n<p><a href=\"https:\/\/krebsonsecurity.com\/2017\/11\/how-to-opt-out-of-equifax-revealing-your-salary-history\/\" target=\"bwo\" >https:\/\/krebsonsecurity.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2017\/09\/equifax-hq-580x384.png\"\/><\/p>\n<p><strong>Credit to Author: BrianKrebs| Date: Mon, 13 Nov 2017 16:55:19 +0000<\/strong><\/p>\n<p>A KrebsOnSecurity series on how easy big-three credit bureau Equifax makes it to get detailed salary history data on tens of millions of Americans apparently inspired a deeper dive on the subject by Fast Company, which examined how this Equifax division has been one of the company&#8217;s best investments. In this post, I&#8217;ll show you how to opt out of yet another Equifax service that makes money at the expense of your privacy.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10643,10642],"tags":[5588,14182,12310,14598,3589,16583,16584,16585,10516,11548,10644,12316,15651,454,16586],"class_list":["post-10451","post","type-post","status-publish","format-standard","hentry","category-independent","category-krebs","tag-amazon","tag-att","tag-equifax","tag-equifax-breach","tag-facebook","tag-fast-company","tag-joel-winston","tag-marisa-salcines","tag-microsoft","tag-oracle","tag-other","tag-talx","tag-the-work-number","tag-twitter","tag-wal-mart"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/10451","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=10451"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/10451\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=10451"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=10451"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=10451"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}