DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Experian denies that database up for sale on dark web is their data

Posted on December 5, 2016 by Dissent

It was only last week that Experian released a white paper on what it sees as data breach risks for 2017.  Perhaps ironically, then, it was only days later when a dark web vendor claimed to have Experian’s database for sale.  HackRead reported on “DoubleFlag’s” listing:

The hacker claims he has access to the Experian database which contains information of some 203,419,083 accounts and has set the price for this database at Bitcoin 0.8082 (USD 600.00).

The database as per his claim includes customer’s full name, address, apartment number, city, state, zip code, gender details, telephone numbers, date of birth, marital status, delivery point barcode, Fips state code, Fips county code, Single Family Dwelling, Apartment with unit designator, Rural Route, Community Reinvestment Act (CRA) income classification code, income details, credit rating details, mail delivery records, Assimilation code, details about customer’s ethnicity, religion, language and other personal and financial information of Experian customers.

Waqas was clear to report this only as a claim and he stated that the database had not been confirmed as an Experian database. DataBreaches.net reached out to Experian for either a confirmation or refutation of Doubleflag’s claim. Today, a spokesperson for Experian sent the following statement:

“We’ve seen this unfounded allegation and similar rumors before. We investigated it again – and see no signs that we’ve been compromised based on our research and the type of data involved. Based on our investigations and the lack of credible evidence, we consider this an unsubstantiated claim intended to inflate the value of the data that they are trying to sell – a common practice by hackers selling illegal data.”

The reference to seeing this “before” likely refers to another database that was being offered earlier this year that was supposedly another Experian database linked to the T-Mobile hack. That database, while appearing to contain what might be legitimate demographic information, did not come from Experian, the company had stated.

Experian’s denial that the data are theirs may explain Doubleflag’s reported unwillingness to answer any of Waqas’s questions as to when and where the data were stolen from Experian.

If Doubleflag would like to provide more details about the alleged hack and some actual proof to support his claim that the data came from Experian, he is welcome to contact DataBreaches.net on Jabber at [email protected].

Category: Breach IncidentsBusiness SectorHackOf Note

Post navigation

← DailyMotion Allegedly Hacked, 85 Million User Accounts Stolen
Eir warns broadband customers of modem security breach →

2 thoughts on “Experian denies that database up for sale on dark web is their data”

  1. Anonymous says:
    December 6, 2016 at 8:38 am

    The credit reporting agencies have always touted that “it’s not their data”, which is why they’re not responsible for what they report or for ensuring its accuracy and places the burden of proof on the consumer. Why would they now say it’s their data?

    1. Dissent says:
      December 6, 2016 at 9:10 am

      There’s a difference between claiming they are not responsible for the accuracy of data they collect from other sources and claiming that data did not come from a database on their server or system.

Comments are closed.

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Ransomware Attack on ADP Partner Exposes Broadcom Employee Data
  • Anne Arundel ransomware attack compromised confidential health data, county says
  • Australian national known as “DR32” sentenced in U.S. federal court
  • Alabama Man Sentenced to 14 Months in Connection with Securities and Exchange Commission X Hack that Spiked Bitcoin Prices
  • Japan enacts new Active Cyberdefense Law allowing for offensive cyber operations
  • Breachforums Boss “Pompompurin” to Pay $700k in Healthcare Breach
  • HHS Office for Civil Rights Settles HIPAA Cybersecurity Investigation with Vision Upright MRI
  • Additional 12 Defendants Charged in RICO Conspiracy for over $263 Million Cryptocurrency Thefts, Money Laundering, Home Break-Ins
  • RIBridges firewall worked. But forensic report says hundreds of alarms went unnoticed by Deloitte.
  • Chinese Hackers Hit Drone Sector in Supply Chain Attacks

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Massachusetts Senate Committee Approves Robust Comprehensive Privacy Law
  • Montana Becomes First State to Close the Law Enforcement Data Broker Loophole
  • Privacy enforcement under Andrew Ferguson’s FTC
  • “We would be less confidential than Google” – Proton threatens to quit Switzerland over new surveillance law
  • CFPB Quietly Kills Rule to Shield Americans From Data Brokers
  • South Korea fines Temu for data protection violations
  • The BR Privacy & Security Download: May 2025

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.