• Welcome to the FREE TUGBBS forums! The absolute best place for owners to get help and advice about their timeshares for more than 32 years!

    Join Tens of Thousands of other owners just like you here to get any and all Timeshare questions answered 24 hours a day!
  • TUG started 32 years ago in October 1993 as a group of regular Timeshare owners just like you!

    Read about our 32nd anniversary: Happy 32nd Birthday TUG!
  • TUG has a YouTube Channel to produce weekly short informative videos on popular Timeshare topics!

    All subscribers auto-entered to win all free TUG membership giveaways!

    Visit TUG on Youtube!
  • TUG has now saved timeshare owners more than $24,000,000 dollars just by finding us in time to rescind a new Timeshare purchase! A truly incredible milestone!

    Read more here: TUG saves owners more than $24 Million dollars
  • Wish you could meet up with other TUG members? Well look no further as this annual event has been going on for years in Orlando! How to Attend the TUG January Get-Together!
  • Now through the end of the year you can join or renew your TUG membership at the lowest price ever offered! Learn More!
  • Sign up to get the TUG Newsletter for free!

    Tens of thousands of subscribing owners! A weekly recap of the best Timeshare resort reviews and the most popular topics discussed by owners!
  • Our official "end my sales presentation early" T-shirts are available again! Also come with the option for a free membership extension with purchase to offset the cost!

    All T-shirt options here!
  • A few of the most common links here on the forums for newbies and guests!

I am getting REALLY tired of this... [account hacking]

GetawaysRus

TUG Review Crew
TUG Member
Joined
Aug 15, 2006
Messages
1,769
Reaction score
1,311
Location
Southern California
Resorts Owned
Marriott Desert Springs Villas 2
Marriott Grand Chateau
You are probably affected as well, so let's vent together.

My health insurer contracts out certain services. So yesterday I received a letter from one such subcontractor. Guess what? They were hacked and my personal information exposed. And guess what? As compensation, they are offering me one year of an identity protection service. Well, we already currently have a bunch of these services that resulted from hacks of a variety of companies that we've done business with as a consumer. And ever since the great Equifax hack a number of years ago, we already have such a service that we pay for monthly.

Then there's this item in today's news, yet another major hack: https://www.foxnews.com/tech/healthcare-data-breach-exposes-3-75m-patient-records

We try to be very careful about our financial affairs. For example, our credit is frozen. I have an IRS PIN number for filing Federal income tax. If I receive a call claiming to be from a financial institution, I won't speak to the caller and instead find their 800 number and call back. I have different crazy passwords for all of the websites I use.

But the businesses are sloppy. The story is always the same. They hire a software security firm after the fact to contain the breach and then throw affected customers a bone in the form of one year of identity theft monitoring. With the rise of AI, I fear that it will only get worse.

I don't know the solution, if there is one. But I'd like to see some real, far more significant penalties on businesses with lax security. And I don't understand why these businesses don't improve their security prior to a breach. (At least one positive thing so far is that the financial institutions I deal with, such as banks and brokerages, have so far seemed to be pretty secure, unless of course they haven't told me. Willie Sutton robbed banks because that's where the money is, so I'm sure that the hackers are trying hard to get into the bank and brokerage computer systems. A breach of a major financial institution would potentially be a significant disaster.)
 
I think you are correct, we probably all have some of our personal info out there on the dark web.

We had exposure from the Anthem Blue Shield of CA hack. My wife kept getting someone trying to open Chase credit cards until we froze her accounts with all three credit agencies. Chase seems to have easy online credit card applications, that's one vector that needs to be shut down.

I just opened the Alaska ATMOS card with BofA and at least they required my freeze lifted for 24 hrs to check my rating.

I think you have done everything you can to protect yourself, credit freeze, Identity pin.

Unfortunately any kind of penalty would just get passed on to consumers so it's difficult to punish them.
 
The reason businesses are lax is because it costs money to do anything, so they always do the minimum allowed. They're always weighing "is the do it better" going to cost more than "pay the fine + reputation cost". And this is for everything, not just cyber security. Part of this is businesses also don't want to pay more to get more resistant employees. What I mean is - if your employees don't care then they're easy to exploit via phishing and also are unlikely to consider security while doing their jobs, they just will want to do the minimum to not get fired.

The mass market businesses are also focusing on price points and there's not an obvious consumer benefit to 90% less likely to have a data breach because they invest in systems and people. Because this is the other problem - you cannot get to 100%. I'm not even sure you can get to 96% - defenders have to succeed every time, attackers just need to succeed once for a given company or org and "they win". With the sheer number of attacks the statistics mean everyone will get breached eventually.
 
The reality is that the current system is just not secure. If Marriott, Equifax, Yahoo, Ticketmaster, Facebook/Meta, etc. can be breached, who spend hundreds of millions on security, what do you expect of much smaller businesses?
 
Yes it is a ROYAL PITA all around. Just accept this as part of life in the modern era. I will continue to lock credit with all 3 credit bureaus, Chex systems, use a Yubikey where possible, OTP codes /MFA where possible, IRS PIN. Use keepass. Avoid using mobile apps where possible. Avoid using pay apps on mobile devices. Stay away from Zelle. Keep your attack surface and lean as possible. The Objective is to keep attack vectors as off your digital access.

Yes it is a Pain. But I would rather suffer the minor pain that the cutting pain of an financial or identity theft. Also always be on guard.

I avoid clicking on embedded links in emails. I avoid using QR codes.
Yes there are times when I must click on embedded links. However always validate the link before using.

I use QR codes only when I absolutely trust the source.

Anyone can create a QR code and direct the link to a malicious look alike site like your financial institution.
 
Last edited:
The reason businesses are lax is because it costs money to do anything, so they always do the minimum allowed. They're always weighing "is the do it better" going to cost more than "pay the fine + reputation cost". And this is for everything, not just cyber security. Part of this is businesses also don't want to pay more to get more resistant employees. What I mean is - if your employees don't care then they're easy to exploit via phishing and also are unlikely to consider security while doing their jobs, they just will want to do the minimum to not get fired.

The mass market businesses are also focusing on price points and there's not an obvious consumer benefit to 90% less likely to have a data breach because they invest in systems and people. Because this is the other problem - you cannot get to 100%. I'm not even sure you can get to 96% - defenders have to succeed every time, attackers just need to succeed once for a given company or org and "they win". With the sheer number of attacks the statistics mean everyone will get breached eventually.
Why am I so paranoid? My PII has been breached that's why. I get attack attempts daily. Calls, emails, texts. Most of them I can filter out. Some do poke thru the virtual firewalls I have set up.
 
Calls, emails, texts. Most of them I can filter out. Some do poke thru the virtual firewalls I have set up.
Even people who've not suffered a breach receive all those same things. Though I suspect most people have had their PII breached. It's just some have suffered a financial loss or issue because of it and many haven't.
 
Last edited:
Even people who've not suffered a breach get receive all those same things. Though I suspect most people have had their PII breached. It's just some have suffered a financial loss or issue because of it and many haven't.
Remember when it was just simple tech support from fake Microsoft or Apple. The attempts are sophisticated these days and usually the victims are not savvy to pick up on the nuanced clues. Sad.
 
This does suck. Unfortunately, there is not much you can do. However, you can prevent data brokers from profiting off of your personal data.

Norton has a paid service which removes or if you have Norton 360 you can do it yourself.

California state just enacted a free DROP program https://privacy.ca.gov/drop/ where their program will continuously monitor hundreds of data broker sites and automatically request removal if it finds your name there. I signed up and a few companies notified me that I would be removed from their listings unless I notify them otherwise (why would I do that?) This doesn't help dark web but could help with spam and keep dark web from accessing info from data broker sites. I am signing up other family members since it seems to be working.
 
Reply
This does suck. Unfortunately, there is not much you can do. However, you can prevent data brokers from profiting off of your personal data.

Norton has a paid service which removes or if you have Norton 360 you can do it yourself.

California state just enacted a free DROP program https://privacy.ca.gov/drop/ where their program will continuously monitor hundreds of data broker sites and automatically request removal if it finds your name there. I signed up and a few companies notified me that I would be removed from their listings unless I notify them otherwise (why would I do that?) This doesn't help dark web but could help with spam and keep dark web from accessing info from data broker sites. I am signing up other family members since it seems to be working.
Yeah I am sure you have also seen the endless ads on YouTube for similar services.
 
The strangest warning about a breach was from the American contract bridge league. Apparently some hackers are sending out enticing letters to bridge players . I don’t know what the end goal would be
 
I was the victim of bank fraud where someone charged my account numerous times. I actually found it before anything happened. They sent a one cent deposit and I notified my bank. Sadly my bank's fraud department isn't open on weekends but Monday morning they froze my account before the charges started arriving. They were all refused. We opened a new bank account. Various debt collectors are still trying to collect this fraudulent debt, charge me fees, interest, etc. I am able to "win" my disputes but it's taken hours of my time. The debit collection machine is undeterred and relentless. It's just a bunch of computers and there's no reason for them to stop.
 
This does suck. Unfortunately, there is not much you can do. However, you can prevent data brokers from profiting off of your personal data.

Norton has a paid service which removes or if you have Norton 360 you can do it yourself.

California state just enacted a free DROP program https://privacy.ca.gov/drop/ where their program will continuously monitor hundreds of data broker sites and automatically request removal if it finds your name there. I signed up and a few companies notified me that I would be removed from their listings unless I notify them otherwise (why would I do that?) This doesn't help dark web but could help with spam and keep dark web from accessing info from data broker sites. I am signing up other family members since it seems to be working.
Thanks for posting. I'll check it out.

@CalGalTraveler have you used this yourself and do you think it works?

I remember a few years ago when there was a California data breach and they published all of the names and addresses of people who had a concealed carry permit. Hopefully, the information that we'll be providing to the privacy.ca.gov won't be similarly hacked.
 
Thanks for posting. I'll check it out.

@CalGalTraveler have you used this yourself and do you think it works?

I remember a few years ago when there was a California data breach and they published all of the names and addresses of people who had a concealed carry permit. Hopefully, the information that we'll be providing to the privacy.ca.gov won't be similarly hacked.
I signed up. This thought crossed my mind but state has info anyway through taxes. So far so good. Time will tell.

I like the weight of the state and state prosecutors providing this against data brokers vs. industry with no power or incentive except to sell more of their product.
 
Last edited:
Thinking back, in retrospect some of the fraud has been amusing. But only in retrospect.

My wife and I were driving along Route 12 in Utah (thanks to TUG - I learned about traveling Utah Route 12 from TUG posts). Fortunately we had cell service, and we got a phone call from Citibank that we had just charged over $1000 in wigs on one of our credit cards. Citi was suspicious, and rightly so. Neither of us wears a wig. But Route 12 was fabulous.

I read above that CalGal trusts the State of California. I don't. It seems that I successfully applied for California state disability insurance a number of years ago when I was working full time and quite able-bodied. It took some doing to unravel that. California also likes to assess me penalties for underpayment of estimated income tax, but then has to reverse their error a few months later. That has happened at least twice.

The most recent one involved Walmart. I live in California, but earlier this year it seems that I decided to order a tent using a credit card I don't own for delivery to Florida. Fortunately Walmart sent an email thanking me for my order, so I phoned them. We're not campers.
 
Thinking back, in retrospect some of the fraud has been amusing. But only in retrospect.

My wife and I were driving along Route 12 in Utah (thanks to TUG - I learned about traveling Utah Route 12 from TUG posts). Fortunately we had cell service, and we got a phone call from Citibank that we had just charged over $1000 in wigs on one of our credit cards. Citi was suspicious, and rightly so. Neither of us wears a wig. But Route 12 was fabulous.

I read above that CalGal trusts the State of California. I don't. It seems that I successfully applied for California state disability insurance a number of years ago when I was working full time and quite able-bodied. It took some doing to unravel that. California also likes to assess me penalties for underpayment of estimated income tax, but then has to reverse their error a few months later. That has happened at least twice.

The most recent one involved Walmart. I live in California, but earlier this year it seems that I decided to order a tent using a credit card I don't own for delivery to Florida. Fortunately Walmart sent an email thanking me for my order, so I phoned them. We're not campers.
What's the alternative? Enabling data brokers to continue to profit and propagate your personal information across the internet to more nefarious parties?
 
Actually, there's more to that California tax penalty story. To get the complete picture on how incompetent California is, I'll fill in the details.

I actually overpay my estimated tax, so I'm generally due a refund (which I then apply to the 1st quarter estimate for the following year). Some time in the Fall, I receive a penalty notice. I phone the tax board and the phone rep agrees that the penalty is an error, but the rep can't fix it. I'm advised to send in a letter explaining the state's error.

A few months later I receive another notice from the state. Good, I think, they fixed the error. But no, notice #2 advises me that California is now assessing interest on top of the still unpaid penalty. At this point I give up. This is taking too much time and effort. I pay the penalty + interest. The most recent penalty fee was somewhere between $25-30.

Finally, a few months after that, I receive a check from the state for the amount of the penalty + interest. They don't explain and they don't apologize.

Yup, that's California.
 
Recently, I have been getting online party invitations a few times a week from people on my contact list who apparently got their email hacked.

The worst hack we've had is when someone filed a tax return with our info and got several thousand dollars from the IRS. This came to our attention when we received an active debit card from T-Mobile that we hadn't applied for. Somehow, they had transferred the tax refund to the debit card and then cashed it out. However, we weren't getting a tax refund, so it wasn't our money!
 
What's the alternative? Enabling data brokers to continue to profit and propagate your personal information across the internet to more nefarious parties?

I have tried (via a different pathway) to have our info deleted from data brokers, but it doesn't seem to have made a significant difference. Are you familiar with that expression about pissing in the ocean?

Oh, and we're also signed up with the National Do Not Call registry. I'd say the phone rings nearly a dozen times a day from phone numbers that we don't recognize. We don't answer.
 
Recently, I have been getting online party invitations a few times a week from people on my contact list who apparently got their email hacked.

The worst hack we've had is when someone filed a tax return with our info and got several thousand dollars from the IRS. This came to our attention when we received an active debit card from T-Mobile that we hadn't applied for. Somehow, they had transferred the tax refund to the debit card and then cashed it out. However, we weren't getting a tax refund, so it wasn't our money!
@DeniseM Look up IRS PIN. Get one. As a matter of fact. Everyone needs to get one.
 
I have tried (via a different pathway) to have our info deleted from data brokers, but it doesn't seem to have made a significant difference. Are you familiar with that expression about pissing in the ocean?

Oh, and we're also signed up with the National Do Not Call registry. I'd say the phone rings nearly a dozen times a day from phone numbers that we don't recognize. We don't answer.
The DNC registry is a real comedy act! The toothless tiger.
 
We have the pins - we've had to use them every year since this incident.
 
My information has been compromised so many times its ridiculous. I feel they know my information better than I do.
 
Top