SC Social Security numbers hacked; State paying for protection
Gov. Nikki Haley on Tuesday said Experian has agreed to cap the state’s costs at $12 million for a year’s worth of credit monitoring of taxpayers affected by a massive hacking breach at the Department of Revenue.
Haley said that figure was arrived at late Monday night as a result of negotiations. “They are not going to charge us any more than $12 million,” even if all 3.6 million folks whose Social Security numbers were swiped sign up for protection, Haley said.
Officials have said it could be weeks before authorities learn exactly what information was swiped from the database of 3.6 million Social Security numbers and 387,000 credit or debit card numbers from the S.C. Department of Revenue during a series of cyber attacks that date to Aug. 27.
Haley said the attack was indicative of “the world we live in today” and that the lack of much national media interest into the episode shows how commonplace such attacks have become. At the same time, she called the attack “absolutely bizarre” and not something
that happens every day.
Haley stressed that no state employee should be faulted for the breach and that no one in state government did anything wrong that allowed the hacker to enter state computers. Neither she nor State Law Enforcement Division Chief Mark Keel would reveal exactly how the hackers got in, saying they did not want to compromise the ongoing investigation.
“What we do know is that this was no simple breach,” she said. “This was no issue with someone in the agency. This was not a hole that was within DOR. This was a true, sophisticated breach.”
She said the CIA, the White House and Google also have been hacked at one time. Everyone wants to blame someone for the episode but the only person responsible is the overseas hacker who stole the information, Haley said.
“Not one thing or one person on the Department of Revenue that could have avoided this hack,” Haley said.
Keel defended the state’s decision to wait 16 days before telling the public about the intrusion and the theft of personal information. He said investigators needed to reach certain benchmarks in the case before revealing the breach.
“We believe we safeguarded the citizens of this state by doing that,” he said.
State officials have advised anyone who had filed a state tax return since 1998 to take steps to learn if their information had been misused by identity thieves. The state is offering one year of free credit monitoring to worried taxpayers.
Some 533,000 people have contacted the call center to begin the process of registering for that protection, and 287,000 have signed up, Haley said.
The wait time for callers is now under 12 minutes, Haley said.
Haley said hacking experts told her thieves usually wait six to eight months after an attack to put the stolen information to use. “So that is the time frame we are going to be focused on,” she said. “Usually after a year, they don’t see anything.”
Other experts have told The Post and Courier thieves generally wait up to three years to use stolen information to avoid getting caught.
While Experian’s free monitoring will end after a year, the company will provide ongoing help to those who have been victimized by fraud as a result of the breach. “They will go back and hold your hand and make sure you are taken care of,” Haley said.
When the state announced the breach on Friday and urged callers to sign up for monitoring, the call center line was busy and the wait time exceeded an hour for those who could get through.
Haley on Monday blamed that delay on the media calling the number to see it if worked, clogging phone lines.
Bill Rogers, executive director of the South Carolina Press Association, said he found Haley’s statement hard to believe. “That is an ingenious way to blame the media,” he said. “I can’t imagine there are enough reporters in South Carolina to clog that line.”
Dozens of people called The Post and Courier on Friday to complain about their inability to get through to the call center, which officials said was staffed by 300 call-takers. Reporters then called the number but just got a busy signal.
“There are 16 daily newspapers in South Carolina,” Rogers said. “If that is enough to clog up their phone lines, then they have got problems.”
By Glenn Smith
Post and Courier
Notice about comments: