DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Experian notifies consumers of a breach. Again.

Posted on May 24, 2014 by Dissent

Once again, Experian is notifying some consumers of a breach that resulted in their credit reports being accessed by criminals. The breach occurred on May 14.

In this case, the client whose login credentials were compromised and used to access Experian’s database was the Bluegrass Community Federal Credit Union in Ashland, Kentucky. Experian and law enforcement are reportedly investigating how that compromise occurred.

The consumers being notified were advised to check their credit reports, remove their name from mailing lists for pre-approved offers for six months, and add a security alert to their credit report with the three major brokers: Experian, TransUnion, and Equifax.

The four New Hampshire residents who were notified were also offered two years’ complimentary enrollment in Experian’s own product, ProtectMyID.

What’s notably missing from Experian’s notification to the state and those affected is any statement as to what Experian is doing or will do to prevent this type of thing from happening again.

As regular readers here know, this type of breach – where client login credentials are compromised and used to access Experian’s credit report database – has happened over 100 times by now. And that’s just the cases this blogger knows about; there may be many more that I will have not and would not uncover because many states have no centralized repository for data breach reports and/or do not mandate reporting of such breaches to the state.

In April 2012, this blogger/privacy advocate filed a complaint with the FTC over Experian’s repeated data security breaches. That complaint also mentioned – and has been updated to include other Experian breaches since then.

The FTC has yet to announce any action or response to that complaint.

 

 


Related:

  • Little Rock Psychologist Indicted by Federal Grand Jury for Defrauding Medicare and Arkansas Blue Cross Blue Shield
  • Software companies must be held liable for British economic security, say MPs
  • UK privacy regulator has seen ‘collapse in enforcement activity,’ rights coalition says
  • SEC Voluntarily Dismisses SolarWinds Litigation
  • Cyberattack disables Onsolve Code Red emergency alert system across St. Louis region (1)
  • Des Moines Man Charged with Computer Fraud
Category: Business SectorCommentaries and AnalysesOf NoteU.S.

Post navigation

← Colleges Remain Big-Game Targets for Hackers
Government Seeks Seven-Month Sentence – Time Served – for LulzSec Leader ‘Sabu’ →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Defense Bill Would Require New Cyber Requirements for Some DoD Telecom Contracts
  • Tell the truth, or someone will tell it for you — Trumbull County, Ohio edition
  • US Posts $10 Million Bounty for Iranian Hackers
  • South Korea police raid e-commerce giant Coupang over data leak; govt schedules hearing
  • FinCEN Report: Reported Ransomware Incidents and Payments Reached All-Time High in 2023
  • Leavenworth, Kansas cyberattack disrupts city services
  • They’ve escaped a lot of media attention, but Anubis RaaS is a threat to the medical sector (1)
  • “In the most expedient time possible…”
  • Portugal updates cybercrime law to exempt security researchers
  • LockBit 5’s “new secure blog domain” infra leaked already

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • FTC Denies Petition from SpyFone App CEO to Vacate 2021 Order
  • Privacy concerns raised as Grok AI found to be a stalker’s best friend
  • PRIVACY—S.D. Cal.: Employee did not waive privacy right in personal email data on company provided laptop, (Dec 5, 2025)
  • EU justice chief draws red line on privacy reforms
  • Kaiser Permanente to Pay Up to $47.5M in Web Tracker Lawsuit

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net
Security Issue: security[at]databreaches.net
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: Dissent.73
DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.