Government and Anthem data breaches pose indefinite threat of future harm as birthdate, full name, and SSN remain integral to identity in many systems
Data Theft Today Poses Indefinite Threat of “Future Harm” — Benjamin Nuss was one of the nearly 80 million people whose social security number … Tweets: @digiphile Tweets: Alex Howard / @digiphile : TIL that you *can* get a new @SocialSecurity number, for free: http://www.consumer.ftc.gov/ ... Demand rising: http://firstlook.org/...
Context & Ripple Effects
This piece lands two days after the federal worker union confirmed that [[a:830067|SSNs and personnel data on every federal employee were taken in the Office of Personnel Management hack]] — so 'government' in the headline means OPM, and together with Anthem's nearly 80 million affected members, the same three fields (name, birthdate, SSN) leaked from both a health insurer and the state within one month.
What makes the story durable rather than dated is the follow-on record: Equifax's 2017 breach repeated the exposure at a credit bureau itself, the FAFSA site was still letting SSN-plus-birthdate pull additional records in late 2017, an Experian flaw allowed full credit-report pulls into late 2022, and by 2024 National Public Data confirmed a leak of millions more SSNs. The 'indefinite future harm' framing has held up.
First-order effects
- Benjamin Nuss and the other ~80 million Anthem members, plus all federal employees hit via OPM, now carry exposed SSNs they cannot practically rotate — the FTC path to a new number exists but is not a realistic remedy at population scale.
- Anyone whose data was taken faces indefinite risk precisely because these identifiers remain valid authentication inputs across government and financial systems.
Second-order effects
- Sites that authenticate users with just name, birthdate, and SSN — FAFSA after the IRS tool with the same flaw was disabled, and Experian's credit-report endpoint until late 2022 — become the conversion point where stolen breach data turns into account access.
- Health-sector exposure compounds: HHS counted 40M+ people affected by US health-data breaches in 2021, up from 26M in 2020, meaning insurers' breached records overlap with the same identifier set.
Third-order effects
- If the pattern holds, the pressure points toward retiring the SSN as a unique digital identifier — a case Wired made explicitly at Equifax — and forcing agencies and bureaus toward verification methods that do not treat unchangeable personal facts as secrets.
- Breach liability shifts from one-time notification toward long-tail 'future harm': once name-birthdate-SSN triples circulate permanently, each new leak adds to a standing pool that no single company's remediation can retire.
The trend: A decade of breaches at OPM, Anthem, Equifax, Experian, and background-check firms shows static identifiers like the SSN functioning as permanent liabilities, steadily building the case for replacing them as authentication keys.