• Coldgoron@lemmy.worldOP
      link
      fedilink
      English
      arrow-up
      60
      ·
      8 months ago

      Haven’t clicked any link yet but it could be possible phishing. Maybe log into my legit discover account first.

      • AFK BRB Chocolate@lemmy.world
        link
        fedilink
        English
        arrow-up
        96
        ·
        edit-2
        8 months ago

        It is for sure phishing. Discover isn’t going to send you an email like that. Even loading the graphics was a bad idea.

        Edit: apparently I stand corrected. I’ve gotten security alerts from my credit card companies before, but never with a link like that, and never saying something like “dark web.” Sorry to hear it

        • mipadaitu@lemmy.world
          link
          fedilink
          English
          arrow-up
          89
          ·
          8 months ago

          It’s not “for sure phishing” Discover does send emails like that. They have a service where they scan the internet for your personal information, and they sell you credit monitoring, and other stuff to reduce the impact.

          Here’s a screenshot of part of their website for this monitoring.

          Of course it’s ALWAYS a good idea to go to the website, and never click a link on an email from your financial institution, but I’m like 80% sure that this is a legit email.

          Also, your SSN and other financial details have likely been compromised dozens of times, so just having your SSN floating around out there isn’t surprising. It’s a fault in the system for using an unsecured SSN as an identify instead of what it was initially used for.

          • snooggums@midwest.social
            link
            fedilink
            English
            arrow-up
            34
            ·
            8 months ago

            It’s a fault in the system for using an unsecured SSN as an identify instead of what it was initially used for.

            It is alao the fault of the government for not putting a halt to and punishing those corporations who decided to hijack SSNs and treat them as some kind of secret code.

            • teft@lemmy.world
              link
              fedilink
              English
              arrow-up
              13
              ·
              8 months ago

              They’d have to start with the army. We used our social on everything as an identifier while I was in. I’d honestly be more surprised if my SSN wasn’t compromised.

              • snooggums@midwest.social
                link
                fedilink
                English
                arrow-up
                8
                ·
                8 months ago

                When i was in college in the 90s they used socials when they posted test scores.

                One thing I noticed was that since it was a state college 90% of them started with the same 3 numbers because of how they issued SSNs.

            • franzfurdinand@lemmy.world
              link
              fedilink
              English
              arrow-up
              3
              ·
              8 months ago

              I cannot imagine the shit fit that people would throw if we tried to implement a secure national identity number. Even the SSN got a lot of backlash for being “the mark of the beast”, and that was introduced a little under a hundred years ago.

            • cm0002@lemmy.world
              link
              fedilink
              English
              arrow-up
              1
              ·
              8 months ago

              It was the government that started that in the first place lmao and then corporations went “Well the US gov can do it, why not us?”

          • mipadaitu@lemmy.world
            link
            fedilink
            English
            arrow-up
            7
            ·
            8 months ago

            Oh great, I clicked too many of their links on their website and now I’m getting targeted ads for their “super special identity protection”

          • AFK BRB Chocolate@lemmy.world
            link
            fedilink
            English
            arrow-up
            3
            ·
            8 months ago

            Okay, I made an edit. Like I said there, the alerts I’ve gotten have never had links for the reasons you mentioned - they say things like “call the number on the back of your card.”

            • Coldgoron@lemmy.worldOP
              link
              fedilink
              English
              arrow-up
              3
              ·
              8 months ago

              I think I was with their service once a long time ago and I did an application to see if I could get a phone plus service package. This probably got my social in the process for credit score reasons.

            • Artyom@lemm.ee
              link
              fedilink
              English
              arrow-up
              3
              ·
              8 months ago
              1. They’ll give you a $1000 phone under the guarantee of a 2-year contract. That can be considered a type of loan and they can repo the phone if you stop paying.
              2. If you stop paying monthly bills, they can only really force you to pay the balance if they have your SSN and can affect your credit score.

              I’m not endorsing the practice of ruining people’s chances of buying a home over unpaid phone bills, but it’s a pretty good deal from AT&T’s perspective.

          • rhythmisaprancer@kbin.social
            link
            fedilink
            arrow-up
            2
            ·
            edit-2
            8 months ago

            Hmm dang I got an email from ATT about this, and the last I had them was for a landline in 2013… Can’t believe they keep data for this long.

            Sorry this happened to you.

        • XeroxCool@lemmy.world
          link
          fedilink
          English
          arrow-up
          39
          ·
          8 months ago

          Discover offers monitoring. How are you so sure it’s phishing? An abundance of caution and logging in directly is certainly a safe route to verify, but convincing OP this is phishing and that the graphics are risky is unnecessarily alarming

          • AFK BRB Chocolate@lemmy.world
            link
            fedilink
            English
            arrow-up
            1
            ·
            8 months ago

            See my edit - apparently I was wrong. My credit card companies never put a link on security alerts, and they’ve said they never will, so that customers know alerts with links are bogus. They always say to call the number on the card or login to your account, without providing a number or link. Discover must work differently.

        • AlphaAutist@lemmy.world
          link
          fedilink
          English
          arrow-up
          19
          ·
          8 months ago

          Are you sure? Discover does have free identity monitoring and I get emails every month saying whether they found anything or not. I have never gotten an email saying they found my ssn though so can’t say for sure if this is legit. Either way I would still check through the app or their website without opening the link.

        • wander1236@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          10
          ·
          8 months ago

          They absolutely do send emails like this. They’ve got a monitoring service if you have a credit card with them to check for data breaches, and most credit cards and even banks I’ve seen do the same. I just got my monthly monitoring update email this morning from Discover, thankfully telling me they didn’t find anything.

  • n1ckn4m3@lemmy.world
    link
    fedilink
    English
    arrow-up
    69
    ·
    8 months ago

    I mean, let’s be real – 50% of the USA’s SSN is on a dark web site due to the Equifax breach.

    Freeze your credit, it’s the only way to protect yourself. All of the ID protection services are just overpriced insurance and don’t actually prevent ID theft.

    • Vanon@lemmy.world
      link
      fedilink
      English
      arrow-up
      23
      ·
      8 months ago

      Yes. Just FYI: All three have free “freeze” option, hidden somewhere (probably thanks to federal law). They also have very similar paid option, which they heavily advertise; That’s not the one. They do all require free accounts, but probably worth it to be able to freeze/unfreeze instantly online.

      I just received “dark web” alert about SSN, phone, name, and email… that I only used at AT&T many years ago. So AT&T has definitely leaked our data as well. Add 'em to the list…

    • doctordevice@lemmy.ca
      link
      fedilink
      English
      arrow-up
      6
      ·
      8 months ago

      Yep, I’m in the unlucky half. It’s good practice anyway, but now I keep my credit frozen at all three credit bureaus unless I’m submitting an application. Doesn’t stop all fraud, but stops most of the kind that can fuck up my credit.

      • DrWeevilJammer@lemmy.ml
        link
        fedilink
        English
        arrow-up
        3
        ·
        8 months ago

        You may also want to freeze Lexis Nexis and Innovis as well - they buy and sell your data as well

        • doctordevice@lemmy.ca
          link
          fedilink
          English
          arrow-up
          4
          ·
          8 months ago

          Fuck, I’ve never even heard of those. This whole system is garbage, how am I supposed to know how to protect myself from fraud when these companies just somehow automatically have authority to let thieves steal my identity? At the very least we should have a centralized government agency that you can issue a blanket freeze with. Better would be an actual proper ID system.

    • lagomorphlecture@lemm.ee
      link
      fedilink
      English
      arrow-up
      4
      ·
      8 months ago

      That’s only from one breach. I’d wager that at least 75% of our SSNs are out there since this is constantly happening.

    • FiniteLooper@lemm.ee
      link
      fedilink
      English
      arrow-up
      3
      ·
      8 months ago

      I mean, it’s not like an SSN is secure at all. Add 1 to your SSN and that’s most likely a completely valid number for someone else

  • XeroxCool@lemmy.world
    link
    fedilink
    English
    arrow-up
    21
    ·
    8 months ago

    Your info was probably already out there, somewhere. It’s most likely in a massive list with thousands of others. It’s still not great, but you’re not being targeted. This is why it’s important to freeze your credit with each bureau.

    Just another reminder that using your SSN for ID verification purposes and acting like it’s a secret code only you could ever know is a dumb fucking system. Even the “verify with your last 4 digits” is a dumb fucking system. If you have a date of birth and a decent idea of birthplace, you can take a pretty good guess about the first 5 digits because they’re sequential from known blocks. It wasn’t until about 20 years ago that the government randomized the first 5 to stop that.

  • SendMePhotos@lemmy.world
    link
    fedilink
    English
    arrow-up
    21
    ·
    8 months ago

    I found that my ssn was leaked because I got multiple attempts to take put credit loans. Incidentally, my middle initial is not I, but l. Joke’s on them. Every time I see the incorrect middle initial, it’s an easy way to tell.

    Needless to say, my stuff has been locked for years and only unlocked when I need to take out a loan or open a new account which is extremely rare.

  • Midnight Wolf@lemmy.world
    link
    fedilink
    English
    arrow-up
    17
    ·
    edit-2
    8 months ago

    This amuses me that it’s talking about a “Dark Web site” while itself is a dark website.

    Spiderman pointing at Spiderman meme

  • dohpaz42@lemmy.world
    link
    fedilink
    English
    arrow-up
    13
    ·
    edit-2
    8 months ago

    Eh, it’s probably been on the dark web for a while now given how frequent and massive data leaks have become. Worry more about unauthorized use/access to your credit and/or identity.

    1. Place freezes on your credit for Experian, TransUnion, and Equifax (it’s free)
    2. Lock any credit cards you don’t use regularly
    3. Pull your credit reports from each agency (you get one a year for free) and verify activity
    4. Enable balance notifications for your credit cards and bank accounts (eg, high transaction amount = $0.00 will alert you to every purchase made)
    5. Opt out of Data Brokers like LexusNexus
    6. Don’t use the same password for multiple websites. If you don’t already, use a password manager like KeePass and let it generate new passwords for you

    It’s all about the diligence these days. Your morning should be fine. The worst thing you can receive is a high transaction amount alert you didn’t authorize. But card companies and banks have gotten good about dealing with those when they happen.

    • localme@lemm.ee
      link
      fedilink
      English
      arrow-up
      2
      ·
      8 months ago

      The link you shared says only in specific circumstances can someone opt out of LexusNexus:

      Opting out of LexisNexis can be more complex than removing your data from other people-search sites. To have your information taken down, you must meet specific criteria, and LexisNexis may request additional documentation:

      • Victim of identity theft: you need to provide a police report documenting the identity theft or similar documentation.
      • Law enforcement officers or public officials facing threats of severe bodily harm or death:** **you must submit a letter from their supervisor confirming the nature of their position and the threats.
      • At risk of physical harm but not in law enforcement: you’ll need to submit a protective order from the court, a police report, or similar documentation.
      • dohpaz42@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        8 months ago

        I believe that the wording is awkward in that you will need additional information if you’re one of the three listed criteria. If you’re just removing it from public view, you only need to provide your name, address, phone and social security number.

  • Possibly linux@lemmy.zip
    link
    fedilink
    English
    arrow-up
    4
    ·
    edit-2
    8 months ago

    Not surprising. I am thinking about creating a foss self hosted scrapper that detects breaches

    I probably won’t though

  • snooggums@midwest.social
    link
    fedilink
    English
    arrow-up
    4
    ·
    8 months ago

    I would be surprised if anyone’s SSN isn’t on a dark web site. Being combined with other personal data is a problem, although the biggest problem is that credit companies treat easily found information as secret and let criminals easily impersonate people by knowing those few easily shared pieces of information without some kind of real security or easy way for people to contest fraud.