Equifax Data Breach Hit Me: Here's How I Protect Myself Now
A financial professional who once paid Equifax to monitor his own personal information outlines the four-step plan he now uses instead to guard his identity, Social Security number and finances from cybercriminals.
As a wealth adviser, I usually write about topics like preparing for retirement, helping your kids fly the nest and making better investment decisions. But in light of the recent Equifax hack, along with similar hacks at Target, Yahoo and others — and the common misperceptions about them — I think it’s important to tackle another issue: the steps you can take to protect your wealth in the digital age.
The biggest mistake you can make right now is to think your information is perfectly safe. Even excluding the many corporate hacks that happen regularly, 145.5 million people were affected in the Equifax breach. There are about 250 million people over the age of 18 in the U.S.
That gives you better than 50-50 odds that your information is out there. If you’re frustrated and angry, I’m with you. I was one of the many who actually paid for Equifax to monitor my personal information, only to have it compromised.
From just $107.88 $24.99 for Kiplinger Personal Finance
Become a smarter, better informed investor. Subscribe from just $107.88 $24.99, plus get up to 4 Special Issues
Sign up for Kiplinger’s Free Newsletters
Profit and prosper with the best of expert advice on investing, taxes, retirement, personal finance and more - straight to your e-mail.
Profit and prosper with the best of expert advice - straight to your e-mail.
But like I tell my kids: You can get angry about a problem or deny that it exists — or you can roll up your sleeves and do something about it.
Here’s what I’m doing.
Step 1: Deal with your credit record
The very first decision you need to make is what to do about your credit record. Do you freeze it, so no one can take credit under your name unless you lift the freeze? Sign up for ongoing credit monitoring?
The answer is that it depends on your needs and your trust level. Monitoring is convenient and usually effective. Of course, a lot of people are concerned about giving Equifax the very same information they already failed to protect.
But if you need your credit record to stay open, a monitoring service could be a good solution. Equifax is offering their monitoring service for free for a year, and other bureaus have a monitoring option as well.
You could potentially improve the security of monitoring if you add a free 90-day fraud alert to your credit report. This will give you an extra layer of protection for three months because it requires every lender to verify your identity before proceeding with any applications. You may even be able to set up an automatic renewal on the 90-day fraud alert. I have this in place, and I think it’s a good combination of simplicity and security.
If you won’t be needing to use your credit report anytime soon, you can also freeze your file with each credit bureau. You’ll likely need to pay for this service.
When a lender has a legitimate request, like a credit check on a car loan, you’ll have a special PIN that you can use to temporarily open the file. You’ll need to know which credit bureau your lender uses, call in to “thaw” your file so they can access it, then freeze your record again afterward. You may need to pay a fee each time you freeze and thaw your report.
This is obviously a little inconvenient, but it could be the best way to ensure that no one can access credit in your name.
If you want to learn more about identity theft and some of the serious issues that can accompany it, click here to see my 3-minute TV segment on the subject.
Step 2. Set up two-factor authentication on every account that you can
This, in my opinion, is a must. Two-factor authentication notices if someone is trying to log into your accounts from an unknown computer, mobile phone or tablet. To make sure it’s really you, the system will send a security code to your phone number (or, sometimes, an email address). Once you’ve logged in from a particular device, you can check a box to remember it if you want to, so that you only have to go through these steps once. Some systems, like Gmail, will automatically remember your device after the first authentication.
Two-factor authentication can seem annoying, but it can also prevent someone from getting into your bank account. That’s why it’s important to set it up on any website that you can. Put together a list of all your bank and investment accounts, insurance agencies and credit cards, and then go to this website to learn how to set up two-factor authentication on each one. I have personally also set it up on all my email and social media accounts.
It only takes a few minutes, and it’s very much worth it.
Step 3. Add a PIN on your phone number (I’m not talking about the PIN to open your phone!)
Next, close another potential gap in security: your cellphone number.
As noted above, one of the most common features of two-factor authentication is a text message that provides you with a temporary security code. So what if someone else was able to compromise your phone number?
This isn’t a stretch: It’s easy to port a phone number from one carrier to another using only some basic personal information. If someone had that information already and just needed to get access to your security codes ... well, let’s just say it’s happened before and it can easily happen again.
Make it harder by putting a PIN on your phone number with your carrier so that it can’t be ported by someone else. Call your phone providers today and make sure you have this extra layer of security in place. It’s an extremely fast and easy way to make sure two-factor authentication always works the way it’s supposed to.
Step 4. Update your passwords
A lot of us are guilty of using the same basic password for all our logins, with a few tweaks here and there. It’s convenient, but it’s also unsafe. Once someone knows part of your password, it becomes a lot easier to figure out the rest of the sequence. This doesn’t just make your password easier to crack: If you reuse your passwords, it gives criminals access to a huge amount of digital information.
That’s why unique passwords are so important. One recent recommendation on passwords is to forget about complicated letters and symbols, and use long sentences for your passwords instead. So, instead of something impossible to remember, like “P@77yW3N7,” you could try “pattywenttothebank.” Although, in my opinion, you should have a different phrase for each login. Reason being, if they hack one website and compromise your password, you don't want them to have access to all of your sites.
The reason a phrase is better because sentences — very long passwords in general — are harder to crack because they’re long. Each character can be one of 26 letters: A password with 18 characters and no numbers, like the one above, has over 1.5 million possible combinations of letters. If you wanted to (or were required to) add a number or a symbol, your possibilities only go higher. However, for the user, they’re still memorable enough to be useful.
Of course, remembering dozens of different passwords can still be hard. To help you manage, you could use a password manager. Again, it depends on your level of trust. These tools are convenient, but they can also be hacked. Consumer Reports has a great introduction to password managers, including how to get the most value from them and some of the more popular products available.
That’s why some people find it more secure and less of a headache to use a more old-fashioned tool: a pen and a piece of paper. Few hackers are going to make that kind of effort, and you know it can’t be compromised online because it’s nowhere to be found. Just make sure you keep it in a very safe place.
The reality of the modern age
Hacking is, unfortunately, here to stay. There’s a high probability your information was compromised in the Equifax hack, and it may have been compromised before (check out this site to learn if your email address and site password were involved in other hacks ‐ all you have to do is enter your email address).
That’s why you need to take these basic security precautions.
I’m not a cybersecurity expert, and none of these tools or methods are foolproof. But much like the way you lock your doors, set the alarm in your house, or install a password to unlock your phone (by the way, you should have one of those too), these tools provide extra layers of protection that make stealing harder.
That alone is worth a lot.
So don’t wait: Take these steps, and start taking control of your information today.
Written by Bradford Pine with Anna B. Wroblewska
Profit and prosper with the best of Kiplinger's advice on investing, taxes, retirement, personal finance and much more. Delivered daily. Enter your email in the box and click Sign Me Up.

Brad Pine is a wealth adviser and president of Bradford Pine Wealth Group, based in Garden City, N.Y. BP Wealth Group assists individuals and entrepreneurs to create wealth, simplify their lives and plan for retirement. Honesty, integrity and reliability are the foundations of Pine's investment philosophy.
-
Flashback Finance: The Cost of Retiring the Year You Were BornJust like groceries, gas and home prices, the cost of retiring is subject to inflation. Here is a look at what it cost to retire in the year you were born.
-
How One Hospital Visit Overseas Could Wreck Your FinancesProper planning can give you peace of mind and protection, regardless of what happens on your trips.
-
It's Time to Rethink What 'Aging Well' MeansDon’t fall into the trap of thinking there is a "right way" to age. Here's how to reframe aging in a healthy, achievable way.
-
Your Guide to Financial Stability as a Military Spouse, Courtesy of a Financial PlannerThese practical resources and benefits can help military spouses with managing a budget, tax and retirement planning, as well as supporting their own career
-
3 Steps to Keep Your Digital Data Safe, Courtesy of a Financial PlannerAs data breaches and cyberattacks increase, it's vital to maintain good data hygiene and reduce your personal information footprint. Find out how.
-
Here's Why You Can Afford to Ignore College Sticker PricesCollege tuition fees can seem prohibitive, but don't let advertised prices stop you from applying. Instead, focus on net costs after grants and scholarships.
-
Today's Senior Living Communities Are Not Your Grandma's 'Old Folks' Home': An Expert Guide to Shopping for the Right FitSenior living facilities have improved and are as diverse as the people who inhabit them. Now, they're more than just a place to go — they're a place to grow.
-
3 Common Misconceptions About Working With a Financial PlannerThink financial planners are only for the wealthy and that AI can replace human advice? Nope. Even people with moderate wealth need professional advice.
-
Should You Consider Investing in the Quantum Computing Sector? This Investment Adviser Has Some SuggestionsInvestors interested in quantum computing could consider ETFs focused on cloud services enabling small businesses to use big technology.
-
I'm an Estate Planning Attorney: These Are the Estate Plan Details You Need to Discuss (And What to Keep Private)Gen Xers and Millennials would like to know if they're going to inherit (and how much), but Baby Boomers in general don't like to talk about money. What to do?
-
I'm a Financial Adviser: This Is How You Can Minimize the Damage of Bad Market Timing at RetirementPoor investment returns early in retirement on top of withdrawals can quickly drain your savings. The ideal plan helps prevent having to sell assets at a loss.