Equifax exposes salary history data on tens of millions of Americans

In May 2017, Equifax advised a number of customers that between April 2016 and March 2017 criminals had been able to steal income tax data from the service The Work Number provided by its TALX subsidiary.  The Work Number provides online payroll, human resources, and tax services to companies for their employees. Criminals were able to reset the four-digit PINs given to customers' employees as passwords and then successfully answer personal questions about those employees. The stolen payroll data is used by criminals to file fraudulent tax refund requests with the federal and state tax authorities. Among the affected organisations was the defence contractor Northrop Grumman.

https://krebsonsecurity.com/2017/05/fraudsters-exploited-lax-security-at-equifaxs-talx-payroll-division/

tags: Equifax, data breach, security, identity fraud, TALX

Writer: Brian Krebs

Publication: Krebs on Security