(MONROE, WA) — That hacker break-in into Target’s computer system, as well as the intrusion into Neiman Marcus’s operation may be just the first shoe to drop for consumers.
Last week Target’s CEO Gregg Steinhafel sent an email to more than 70 million people who had either their credit card or personal information stolen from Target’s databases over the holidays.
After initially reporting that credit or debit card information from about 40 million shoppers was stolen from late November to mid-December in a hacking of Target’s in-store network, the company said this month that systems housing personal data on 70 million customers – with some overlap with the first group – also had been compromised.
Information on the second group, which includes people who may not have shopped at Target recently, included street addresses, telephone numbers and email addresses.
Steinhafel warned Target customers in his email to take steps to protect themselves against possible scams resulting from the data breach by not responding to any emails or text messages requesting personal information.
If you get an email or a phone call alerting you to a data breach, don’t assume that the notification is legit and do not use any contact information provided without verifying it first. Do an online search for the company’s public phone number and call it yourself to confirm the notification you got is real.
The reason for Steinhafel’s warning: right around the same time that email went out, so did look-alike emails – some looking very real, as though they came from Target – claiming to be a “warning” from the company and asking the recipients to protect themselves by clicking on a link in the email.
And once the recipient clicked the link, that opened the door to potential malware being delivered directly to the consumer’s computer.
A report Tuesday by National Public Radio (NPR) noted that privacy experts are warning about those “phishing “scams that show up in an email box offering ” help to those whose information was stolen.”
The report quotes William Pelgrin, the president and CEO for the non-profit Center for Internet Security as saying he can see a lot of people falling prey to these phishing probes because they look, “Legitimate. They’re very realistic.”
A co-founder of BitSight, a cyber security firm that tracks malware told NPR he expects the scams, resulting from both the Target and Neiman Marcus data breaches, to be “especially well-crafted.”
The same report says Target confirmed it has identified and, working with social media companies, “taken down” a dozen related online phishing scams.
Over the weekend two Mexican citizens were arrested in Texas near the U.S.-Mexico border after they were found to have in their possession credit card information which is believed to be related to the Target breach.
WHAT TO DO
The Center for Internet Security (CIS) says if you’re a victim of the recent Target data breach your should:
· If you have used a debit card, change your pin.· Call your bank or credit card company and request a new card(s).
Keep in mind that when you cancel your card(s), any automatic payments you have scheduled through them will be stopped, so you will need to contact those organizations as well.
· Freeze your credit.
Contact all three major credit bureaus (Equifax, Experian, and TransUnion) to have a fraud alert or a credit freeze placed on your credit to prevent accounts from being opened without your permission.
· Continue to monitor all of your accounts for any suspicious activity. Criminals might not try to access your account for several months or more, attempting to avoid detection during the time of high profile attention to the breach.
TIPS TO MINIMIZE THEFT RISKS:
· Guard your personal information, including your social security number. Don’t carry your social security card with you, and don’t provide your social security number to anyone unless they have a legitimate need for it.
· Don’t put your social security number or driver’s license number on your checks.
· Check your credit reports from all three major credit bureaus (Equifax, Experian, and TransUnion) at least once a year. You are entitled to one free credit report from each bureau every year. Consider staggering your requests to check a different credit bureau every four months.
· Properly discard hard copy documents containing personal information. A crosscut paper shredder works best.
Data Breaches
CIS says as of December 17, 2013 — 621,955,664 records have been breached in the US since state data breach notifications laws went into effect in 2005. These are only the reported ones; the actual number is most likely much larger. (Source: Privacy Rights.org: http://www.privacyrights.org/data-breach)
