/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Reports of hijacked accounts and analysis of Experian's authentication flow reveal poor security at the credit bureau, after PIN reset flaws were found in 2021

Krebs on Security Brian Krebs

Context & Ripple Effects

This is the third act of a long-running authentication failure at Experian. In 2017, Krebs documented that the bureau's credit freeze PIN retrieval tool authenticated users with just four pieces of basic personal information — exactly the data already circulating in breach dumps. Former employees had earlier said security investment slipped after CIO John Finch's departure, and by late 2022 hackers were exploiting a site flaw to pull anyone's full credit report from name, address, birthday, and SSN alone.

Today's reporting on hijacked accounts shows the same pattern persisting inside Experian's account-recovery flow itself: the credentials meant to lock down a consumer's file can be reset by whoever knows the consumer's static identifiers. That matters because Experian is not an isolated case — the IRS built its victim-protection PINs on the same knowledge-based authentication model, and Brian Krebs' own PayPal takeover demonstrated how static identifiers fail against determined identity thieves.

First-order effects

  • Consumers who relied on Experian accounts and credit freeze PINs as their primary defense face immediate exposure: an attacker armed only with leaked personal data can seize the very controls meant to protect their file.
  • Experian must re-engineer its authentication and PIN-reset flows again, after the 2021 reset flaws, or accept that its own recovery path is the attack surface.

Second-order effects

  • Every institution leaning on the same knowledge-based authentication stack — the IRS's victim PIN system among them — faces pressure to justify a mechanism repeatedly shown to be bypassable with breached data.
  • Identity-verification vendors and competitors gain a selling point: demonstrating authentication that does not depend on SSN, DOB, and address becomes a competitive differentiator against Experian's record of social-engineering losses, including the South Africa incident where a fake client yielded data on millions of citizens.

Third-order effects

  • If the pattern holds, knowledge-based authentication gets structurally retired across credit bureaus and government programs, replaced by verification methods that assume all static personal data is already public — a shift regulators may eventually force given how long each fix has lagged each failure.
  • Credit freezes and bureau accounts stop functioning as consumer-controlled safeguards unless bureaus decouple account recovery from the same leaked identifiers used to open fraudulent files in the first place.

The trend: Knowledge-based authentication built on static personal identifiers is steadily collapsing under breach-driven data leakage, pushing credit bureaus and agencies toward verification methods that assume the old secrets are already public.

Discussion

  • @jstrauss @jstrauss on x
    This is exactly what we experienced and it's a ridiculous failure of basic account security! Thanks @briankrebs https://twitter.com/...
  • @cathcam Mark Cathcart on x
    Please remember, where your privacy or credit details or other PII is leaked the only legal remedy through class action is yet another monitoring service through... Experian. Dear @GovofCO @COAttnyGeneral time for statutory penalties! https://twitter.com/...
  • @briankrebs @briankrebs on x
    Heard from 2 readers who had the email addresses changed on their Experian accounts, freezes lifted. Research suggests ID thieves were able to hijack the accounts just by signing up for new accounts using the victim's personal info & a different email. https://krebsonsecurity.com…
  • @briankrebs @briankrebs on x
    As @TXCyberLawyer confirmed, it's way too easy for someone to assume control over your Experian account, lift a freeze, and go to town on your identity. Story here: https://krebsonsecurity.com/ ... https://twitter.com/...
  • @ncweaver Nicholas Weaver on x
    Experian's real customers are the lenders. Since, in the end, the lenders eat the cost of identity theft, and the lenders have a choice, they should vote with their feet and use Transunion or Equifax instead. https://twitter.com/...
  • @adam_k_levin Adam Levin on x
    “Research suggests identity thieves were able to hijack the accounts simply by signing up for new accounts at Experian using the victim's personal information and a different email address.” https://krebsonsecurity.com/ ...