Every time that there is a leak like this it’s infinitely aggravating how the spin department tries to downplay what happened. If you are using SMS based MFA you probably want to stop doing that now.
Every time that there is a leak like this it’s infinitely aggravating how the spin department tries to downplay what happened. If you are using SMS based MFA you probably want to stop doing that now.
Edit: sorry, app didn’t show the entire image by default, they DO list exactly what was lost, not a bad email tbh (although better if they didn’t lose it)
Isn’t it saying that they didn’t have those bits so couldn’t loose them?
It would have been more useful (but look worse for them!) If they just listed what was lost…
Isn’t the bulleted list the stuff that was lost? They say “we don’t have govt id stuff so that can’t be stolen, the CC info wasn’t affected, here’s the info that was potentially hit”
This seems like a great email to get. They know what subsystem was hit and are telling people.
I don’t think people understand the impact of IMEI and SIM serial being compromised. I’m not sure I fully do, either. This feels like when a mechanic gives you too much technical information that you don’t know how to process.
I thought it was a nice tidy list too.
How is it so hard for people to read?
My bad, app wasn’t showing the entire image. I need to try the other apps.
People really, really hate clicking past the post, even if it’s just to a screenshot.
Heaven forbid its an article
Yup and that’s the infuriating part. It’s not helpful or useful, it 100% a cya.
The reality is they may not know exactly what was obtained, but they do know it wasn’t anything they don’t collect (like DOB, SSN, etc listed in the message). Instead of looking at this purely as a CYA message, instead looking at it as informing you as soon as they had any idea your information may have been impacted instead of waiting weeks/months to inform you. Don’t let perfect be the enemy of good.
Your title implies they lost all the bad stuff though
With the IMEI and SIM card information they now have the details needed to take over MFA. I share my birthdate with people that I casually know, I try not to do that with MFA codes. Credit card details would be bad, but at this point with the number of people who have leaked it, I would be 100% surprised if you couldn’t find our CC data via a google search.
Setup TOTP NOW. Mint added proper TOTP authentication as MFA a while back that should block sms based MFA. Might be a good way to prevent sim swapping attacks.