By Susan Tompor Detroit Free Press
WWR Article Summary (tl;dr) Beginning Sept. 21, a new federal law will help consumers protect their financial information. The three big credit reporting agencies will be required to offer you a credit freeze, free of charge.
Detroit Free Press
Just one year ago, consumers woke up and discovered that hackers had one heck of a field day with their Social Security numbers and other information in a massive data breach at Equifax.
Equifax's screw-up would forever leave millions just that much more vulnerable to ID theft.
Face it, it's not like you can change the locks on the side door. Once hacked, your Social Security number is out there indefinitely.
Beginning Sept. 21, though, a new federal law will help consumers stop intruders in their tracks. The three big credit reporting agencies, Equifax, Experian and TransUnion, will be required to offer you a credit freeze, free of charge. Such a freeze will restrict access to your credit file and help stop crooks from opening credit cards in your name.
Also starting Sept. 21, parents across the country will be able to get a free credit freeze for children under age 16, too. A child's credit file would be frozen until the child is old enough to use credit.
To be sure, the new law is but a minuscule response to the widespread outrage expressed by consumers just a year ago. Even so, it is a key step for regaining some control over our data.
Yet there's a not-so-small challenge ahead: Many people may have absolutely no idea what a credit freeze actually is and how it works, according to new research conducted by a team at the University of Michigan School of Information in Ann Arbor.
Amazingly, some consumers wrongly think that a credit freeze stops them from using their own credit cards. So what exactly is a credit freeze?
Yixin Zou, a U-M doctoral student, said she was astonished to hear consumers disclose that they somehow associated a freeze with stopping the use of their own credit cards or limiting their own access to their existing credit cards.
"I'm quite surprised," said Zou, 23.
Perhaps some consumers associated a freeze with times that credit card issuers send out new cards and stop us from using old ones because the numbers of the old ones have been breached.
Perhaps others remember tips that once suggested putting your credit card in the freezer in a baggie to control spending.
Instead, a credit freeze stops many but not all businesses and others from reviewing your credit file.
The consumer who signs up for a voluntary credit freeze is given a PIN, a PIN that you want to keep track of, to use when you want to unfreeze that credit file in order to apply for new credit.
Under the new law, if a consumer asks for a freeze online or by phone, the credit reporting agency has to put the freeze in place no later than the next business day, according to a Federal Trade Commission blog.
If the consumer wants to lift the freeze, for example, to finance a new phone or fridge, that has to happen within an hour.
"It's just assumed that people know what a credit freeze is," said Florian Schaub, U-M assistant professor of information, whose research focuses on security and privacy issues.
But Schaub, 35, said too often "credit freeze" is just swept into the jargon in the industry, jargon that many consumers simply do not understand.
Many times, people only fully understand a credit freeze once they're actual victims of ID theft and told that a credit freeze is essential.
And what is a fraud alert?
Some consumers had a hard time understanding the term "fraud alert," as well. Some thought the alerts were when a bank or credit union would text you when fraudulent activity was detected on your account.
Instead, placing a fraud alert on your credit file actually means that you're adding a red flag, if you will, to your credit report to alert a lender to carefully verify your identity before making a loan.
Under the new law, a fraud alert will last one year, instead of 90 days. If a victim of identity theft, you'd still be able to extend a fraud alert for seven years.
We're not talking about buying some service or signing up for some credit lock product that might have certain strings and conditions, as well as a fee. This is a free freeze.
But all that jargon, freezes, locks, alerts, can truly confuse consumers who are already overwhelmed in their financial lives.
Schaub said the credit bureaus don't have much incentive to carefully explain things like credit freezes or fraud alerts. After all, their business model is to collect and aggregate our information to provide to lenders who want to sell us loans.
"We, as citizens, are not their customers," Schaub said. "What makes them money is sharing our credit reports with other businesses."
Everyone has something to lose
Many times, particularly lower-income consumers wrongly believe that they have little reason to worry and don't really need to protect their data after a breach, according to the U-M researchers. Those consumers thought that scammers would target people who were more affluent.
"They would say 'I've got nothing to lose. Why would an identity thief go after me?' " Schaub said. But he said other research has shown that people of low socioeconomic status are disproportionately affected by identity theft.
The U-M research found that most consumers took little to no action to protect themselves despite the risk of identity theft. Some consumers underestimated the likelihood of becoming a victim.
Some consumers reported that they were likely to delay taking the time to handle any security-related tasks until they're actually harmed, even though recovering from ID theft can be far more time-consuming than prevention, researchers said.
Of course, ID thieves can see huge payouts using your stolen Social Security number for all sorts of things, including getting medical care or poaching your medical insurance, filing a fraudulent tax refund (which stops you from getting your refund cash until you take steps to clear up the matter), and filing for unemployment benefits or even Social Security benefits using your number.
Putting a credit freeze won't stop all fraud, of course, including someone who tries to file a fraudulent tax return to collect refund cash.
The Equifax breach was significant because of the kind of data that was involved.
On Sept. 7, 2017, the major credit reporting agency announced a "cybersecurity incident" where crooks gained access to Social Security numbers, birthdates, names and addresses. And in some cases, Equifax noted that some partial driver's license numbers were stolen, too.
The incident involved data for nearly 147 million people.
Without the change in the law, many consumers in several states, including Michigan, had to pay a fee of around $10 or so for each freeze they placed on their credit files, or $30 for putting a freeze with the three agencies. Then there could be a fee of $10 or so for lifting that freeze when you wanted to take out a loan or open a credit card. Fees could be waived under certain circumstances, such as when someone has stolen your identity to open credit.
Under the new law, you can unfreeze your report at no cost, too.
Enabling consumers to get free freezes, of course, should encourage people who don't have a lot of extra cash to consider putting a freeze on their credit.
After the Equifax breach, U.S. consumers, whether they were part of the breach or not, were allowed to sign up to freeze their credit reports at Equifax if they made a move before July 1. But the new law will go much further and offer free freezes indefinitely.