Skip to main content

Equifax reopens salary search site, security expert says it’s still vulnerable

cfpb investigation equifax hack headquarters
Smith Collection/Gado/Getty Images
A salary lookup service provided by recently compromised credit bureau Equifax came back online after it was taken down for “security enhancements” on October 8. The service allows anyone to look up your salary and employment history going back at least 10 years by providing a few pieces of personal information: Your Social Security number and your date of birth.

It’s designed to provide income verification to employers, banks, and other “credentialed verifiers” but after the Equifax hack, the sensitive information you need to access someone’s even more sensitive information was out there, ripe for the taking. When security expert Brian Krebs brought attention to the issue in a post on his blog, Equifax took the site down.

Recommended Videos

Now, however, the website is back up and despite Equifax’s claims to the contrary, the security enhancements the company made to the Work Number, haven’t exactly enhanced security all that much.

Please enable Javascript to view this content

“The only ‘security enhancements’ I saw that my source encountered was a prompt to enter his full name, date of birth, Social Security number, address, phone number and email, followed by the usual retinue of four multiple-guess ‘knowledge-based authentication’ (KBA) questions. I’ve long been a critic of these KBA questions, because the answers usually are available using sites like Zillow and Spokeo, to say nothing of social networking profiles,” Krebs wrote.

So, in short, you can still access someone’s income and employment history with readily available information — and a handful of less readily available information, illicitly procured from the dark corners of the internet. Krebs goes on to describe how even a credit freeze — the recommended course of action after your information has been compromised — won’t protect you entirely.

Those knowledge-based authentication questions, generated from your credit and income history, will still pop up when attempting to access your income history through the Work Number, but the questions won’t use financial information — they will be generated from other bits of information Equifax has about you, like your address history, and the names of lenders you’ve used in the past.

“What’s interesting is that these types of questions tend to be easier to answer than, say, ‘What was the amount of your most recent car loan payment?’” Krebs continues, describing how a credit freeze just might make it easier for identity thieves to access the sensitive personal information contained on the Work Number.

The best defense, Krebs says, is to sign into the Work Number yourself, set up a secure PIN, and add at least a half dozen security questions and answers to your account. The questions, he advises, should have answers only you would know that cannot be found via social media.

Jayce Wagner
Former Digital Trends Contributor
A staff writer for the Computing section, Jayce covers a little bit of everything -- hardware, gaming, and occasionally VR.
You’ll never guess what Google’s ‘biggest focus’ will be in 2025
Sundar Pichai stands in front of a screen showing the Google logo.

Google plans to prioritize scaling its Gemini AI for consumers in the new year, CEO Sundar Pichai told employees during a strategy meeting held earlier this month. The company is facing increased competition from rivals like Perplexity and OpenAI as emerging AI technologies reinvent web search. The company has come under added scrutiny from federal regulators as well this year.

“I think 2025 will be critical,” Pichai remarked to employees assembled at Google’s headquarters in Mountain View, California, as well as those attending virtually. “I think it’s really important we internalize the urgency of this moment, and need to move faster as a company. The stakes are high. These are disruptive moments. In 2025, we need to be relentlessly focused on unlocking the benefits of this technology and solve real user problems.”

Read more
LG’s new Gram Pro finally looks like a serious MacBook Pro rival
An LG Gram laptop on a table.

Just ahead of CES, LG has announced a refresh to its Gram Pro lineup, as well as launched a budget-friendly Gram Book. The tweaked Gram Pro laptops are the most exciting, though, with the the LG Gram Pro 17 catching my eye.

First off, it's been thinned out a bit, dropping down to 0.62 inches thick, which is almost the same thickness as the 16-inch MacBook Pro. The LG Gram Pro 17 is also a full pound and a half lighter than the MacBook Pro, both of which are striving to be one of the best laptops you can buy.

Read more
Nvidia’s new GPUs show up in prebuilts, but the RTX 5090 is missing
iBUYPOWER RTX for AI PCs side view of pre-built on sale hero

Nvidia's upcoming RTX 5080 and RTX 5070 Ti just appeared in several iBUYPOWER gaming PCs. This is the first U.S. retailer to list Nvidia's RTX 50-series in prebuilt systems. The listings are interesting, with performance figures that really don't add up. Still, the biggest question is: Where's the GPU that's bound to beat all the current best graphics cards? Yes, we're talking about RTX 5090.

The listings have already been taken down, but they were preserved by VideoCardz. A total of five systems were listed by iBUYPOWER, but they all contained the same two GPUs -- either the RTX 5080 or the RTX 5070 Ti. Both cards are said to come with 16GB of memory, and we expect them to be announced on January 6 during the CES 2025 keynote held by Nvidia's CEO, Jensen Huang.

Read more