When entering your personal information or credit card number on a website, do you hesitate for a moment? An uneasy feeling of vulnerability brought on by the parade of headlines about data breaches and hacking? If so, you're probably pushing those feelings aside and hitting send because, well, you need to shop, apply for that job, file an insurance claim, apply for that loan, or do whatever other sensitive activity is going on. online these days.
First, the bad news. If you regularly enter sensitive information online, chances are that some of your data has been stolen somewhere. According to one estimate, the average American's data was stolen at least four times in 2019. And the hits keep coming. For example, the data breach at wireless carrier T-Mobile reported in August 2021 affected 100 million people.
Now for some good news. Not all hacks are the same and there are steps you can take to protect yourself. The Conversation has collected four articles from our archives that shed light on the types of threats to your online data, what data thieves are doing with your stolen information, and what you can do about it.
1. Consider your risk
Not all cyber attacks are the same and not all personal data is the same. Has the organization that has your information fallen victim to a ransomware attack? Chances are your information won't be stolen, even if the organization's copy of it could become unusable.
If the organization you are dealing with has had customer data stolen, what kind of data did the thieves get? Merrill Warkentin, a professor of information systems at Mississippi State University, writes that you should ask yourself a few questions to assess your risk. If the stolen data was your purchase history, it may not be used to injure you. But if it was your credit card number, that's a different story.
Data breaches are a good opportunity to "change your passwords, especially at banks, brokerage firms, and any site that stores your credit card number," he wrote. In addition to using unique passwords and two-factor authentication, "you should also consider closing old unused accounts so that the information associated with them is no longer available."
2. Market for your stolen data
Most data breaches are financial crimes, but hackers generally don't use the stolen data themselves. Instead, they sell them on the black market, usually through websites on the dark web, for other criminals and fraudsters to use.
This black market is flooded with personal data so much so that your information is probably worth a lot less than you'd guess. For example, stolen PayPal account information costs $30.
Buyers use stolen data in several ways, writes Ravi Sen, associate professor of information and operations management at Texas A&M University. A common use is to steal your money or identity. "Credit card numbers and security codes can be used to create clone cards to conduct fraudulent transactions," he writes. "Social security numbers, home addresses, full names, dates of birth and other personal information can be used in identity theft."
You must be logged in to post a comment.