Connect with us

Business

Hackers may have stolen the Social Security numbers of every American. How to protect yourself

Published

on

Hackers may have stolen the Social Security numbers of every American. How to protect yourself

About four months after a notorious hacking group claimed to have stolen an extraordinary amount of sensitive personal information from a major data broker, a member of the group has reportedly released most of it for free on an online marketplace for stolen personal data.

The breach, which includes Social Security numbers and other sensitive data, could power a raft of identity theft, fraud and other crimes, said Teresa Murray, consumer watchdog director for the U.S. Public Information Research Group.

“If this in fact is pretty much the whole dossier on all of us, it certainly is much more concerning” than prior breaches, Murray said in an interview. “And if people weren’t taking precautions in the past, which they should have been doing, this should be a five-alarm wake-up call for them.”

According to a class-action lawsuit filed in U.S. District Court in Fort Lauderdale, Fla., the hacking group USDoD claimed in April to have stolen personal records of 2.9 billion people from National Public Data, which offers personal information to employers, private investigators, staffing agencies and others doing background checks. The group offered in a forum for hackers to sell the data, which included records from the United States, Canada and the United Kingdom, for $3.5 million, a cybersecurity expert said in a post on X.

The lawsuit was reported by Bloomberg Law.

Advertisement

Last week, a purported member of USDoD identified only as Felice told the hacking forum that they were offering “the full NPD database,” according to a screenshot taken by BleepingComputer. The information consists of about 2.7 billion records, each of which includes a person’s full name, address, date of birth, Social Security number and phone number, along with alternate names and birth dates, Felice claimed.

National Public Data didn’t respond to a request for comment, nor has it formally notified people about the alleged breach. It has, however, been telling people who contacted it via email that “we are aware of certain third-party claims about consumer data and are investigating these issues.”

In that email, the company also said that it had “purged the entire database, as a whole, of any and all entries, essentially opting everyone out.” As a result, it said, it has deleted any “non-public personal information” about people, although it added, “We may be required to retain certain records to comply with legal obligations.”

Several news outlets that focus on cybersecurity have looked at portions of the data Felice offered and said they appear to be real people’s actual information. If the leaked material is it what it’s claimed to be, here are some of the risks posed and the steps you can take to protect yourself.

The threat of ID theft

The leak purports to provide much of the information that banks, insurance companies and service providers seek when creating accounts — and when granting a request to change the password on an existing account.

Advertisement

A few key pieces appeared to be missing from the hackers’ haul. One is email addresses, which many people use to log on to services. Another is driver’s license or passport photos, which some governmental agencies rely on to verify identities.

Still, Murray of PIRG said that bad actors could do “all kinds of things” with the leaked information, the most worrisome probably being to try to take over someone’s accounts — including those associated with their bank, investments, insurance policies and email. With your name, Social Security number, date of birth and mailing address, a fraudster could create fake accounts in your name or try to talk someone into resetting the password on one of your existing accounts.

“For somebody who’s really suave at it,” Murray said, “the possibilities are really endless.”

It’s also possible that criminals could use information from previous data breaches to add email addresses to the data from the reported National Public Data leak. Armed with all that, Murray said, “you can cause all kinds of chaos, commit all kinds of crimes, steal all kinds of money.”

How to protect yourself

Data breaches have been so common over the years, some security experts say sensitive information about you is almost certainly available in the dark corners of the internet. And there are a lot of people capable of finding it; VPNRanks, a website that rates virtual private network services, estimates that 5 million people a day will access the dark web through the anonymizing TOR browser, although only a portion of them will be up to no good.

Advertisement

If you suspect that your Social Security number or other important identifying information about you has been leaked, experts say you should put a freeze on your credit files at the three major credit bureaus, Experian, Equifax and TransUnion. You can do so for free, and it will prevent criminals from taking out loans, signing up for credit cards and opening financial accounts under your name. The catch is that you’ll need to remember to lift the freeze temporarily if you are obtaining or applying for something that requires a credit check.

Placing a freeze can be done online or by phone, working with each credit bureau individually. PIRG cautions never to do so in response to an unsolicited email or text purporting to be from one of the credit agencies — such a message is probably the work of a scammer trying to dupe you into revealing sensitive personal information.

For more details, check out PIRG’s step-by-step guide to credit freezes.

You can also sign up for a service that monitors your accounts and the dark web to guard against identity theft, typically for a fee. If your data is exposed in a breach, the company whose network was breached will often provide one of these services for free for a year or more.

As important as these steps are to stop people from opening new accounts in your name, they aren’t much help protecting your existing accounts. Oddly enough, those accounts are especially vulnerable to identity thieves if you haven’t signed up for online access to them, Murray said — that’s because it’s easier for thieves to create a login and password while pretending to be you than it is for them to crack your existing login and password.

Advertisement

Of course, having strong passwords that are different for every service and changed periodically helps. Password manager apps offer a simple way to create and keep track of passwords by storing them in the cloud, essentially requiring you to remember one master password instead of dozens of long and unpronounceable ones. These are available both for free (such as Apple’s iCloud Keychain) and for a fee.

Beyond that, experts say it’s extremely important to sign up for two-factor authentication. That adds another layer of security on top of your login and password. The second factor is usually something sent or linked to your phone, such as a text message; a more secure approach is to use an authenticator app, which will keep you secure even if your phone number is hijacked by scammers.

Yes, scammers can hijack your phone number through techniques called SIM swaps and port-out fraud, causing more identity-theft nightmares. To protect you on that front, AT&T allows you to create a passcode restricting access to your account; T-Mobile offers optional protection against your phone number being switched to a new device, and Verizon automatically blocks SIM swaps by shutting down both the new device and the existing one until the account holder weighs in with the existing device.

Your worst enemy may be you

As much or more than hacked data, scammers also rely on people to reveal sensitive information about themselves. One common tactic is to pose as your bank, employer, phone company or other service provider with whom you’ve done business and then try to hook you with a text or email message.

Banks, for example, routinely tell customers that they will not ask for their account information by phone. Nevertheless, scammers have coaxed victims into providing their account numbers, logins and passwords by posing as bank security officers trying to stop an unauthorized withdrawal or some other supposedly urgent threat.

Advertisement

People may even get an official-looking email purportedly from National Public Data, offering to help them deal with the reported leak, Murray said. “It’s not going to be NPD trying to help. It’s going to be some bad guy overseas” trying to con them out of sensitive information, she said.

It’s a good rule of thumb never to click on a link or call a phone number in an unsolicited text or email. If the message warns about fraud on your account and you don’t want to simply ignore it, look up the phone number for that company’s fraud department (it’s on the back of your debit and credit cards) and call for guidance.

“These bad guys, this is what they do for a living,” Murray said. They might send out tens of thousands of queries and get only one response, but that response could net them $10,000 from an unwitting victim. “Ten thousand dollars in one day for having one hit with one victim, that’s a pretty good return on investment,” she said. “That’s what motivates them.”

Advertisement

Business

How Iran War Is Threatening Global Oil and Gas Supplies

Published

on

How Iran War Is Threatening Global Oil and Gas Supplies

Ships near the Strait of Hormuz before and after attacks began

Advertisement

Note: Times shown are in Iran Standard Time. Some ships in the region transmit false positions and others sometimes stop broadcasting their locations, and may not be reflected in the animation. Ships with sparse location data are shown in a lighter shade. Source: Kpler and Spire.

Every day, around 80 oil and gas tankers typically pass through the Strait of Hormuz, the narrow waterway off Iran’s southern coast that carries a fifth of the world’s oil and a significant amount of natural gas.

Advertisement

On Monday, just two oil and gas tankers appear to have crossed the strait, according to a New York Times analysis of shipping activity from Kpler, an industry data firm. Since then, one tanker passed through.

“It’s a de facto closure,” said Dan Pickering, chief investment officer of Pickering Energy Partners, a Houston financial services firm. “You’ve got a significant number of vessels on either side of the strait but no one is willing to go through.”

Advertisement

Tankers have been staying away from Hormuz since the U.S.-Israeli attacks on Iran that began on Saturday. A prolonged conflict could ripple broadly across the global economy, threatening the energy supplies of countries halfway around the world and stoking inflation.

International oil prices have climbed 12 percent since the fighting began, trading Tuesday around $81 a barrel, and natural gas prices have surged in Europe and in Asia.

A senior Iranian military official threatened on Monday to “set on fire” any ships traveling through the Strait of Hormuz. Vessels in the region have already come under attack. Several oil and gas facilities have also been struck or affected by nearby shelling, though the damage did not initially appear to be catastrophic.

Advertisement

Where ships and energy facilities have been damaged

Advertisement

Note: Damage as of 2 p.m. Eastern time Tuesday. Source: Kpler, Kuwait National Petroleum Company, Saudi Arabian Ministry of Energy, Planet Labs, QatarEnergy, United Kingdom Maritime Trade Operations and Vanguard Tech.

Advertisement

A fire broke out Tuesday at a major energy hub in Fujairah, United Arab Emirates, from the falling debris of a downed drone, the authorities said. On Monday, Qatar halted production of liquefied natural gas, or fuel that has been cooled so that it can be transported on ships, after attacks on its facilities.

Advertisement

Facilities at Ras Tanura oil refinery in Saudi Arabia were on fire on Monday after two Iranian drones were intercepted, according to Saudi Arabia’s Ministry of Energy, causing fragments to fall. Vantor

The sharp reduction in tanker traffic is reducing the supply of oil and gas to world markets, pushing up prices for both commodities. And the longer that ships stay away from the Strait of Hormuz, the less oil and gas get out to the world, which could raise prices even more.

Shipping companies have paused their tankers to protect their crew and cargo, and because insurance companies are charging significantly more to cover vessels in the conflict area.

Advertisement

On Tuesday, President Trump said that “if necessary,” the U.S. Navy would begin escorting tankers through the strait. He also said a U.S. government agency would begin offering “political risk insurance” to shipping lines in the area.

In addition to tankers, other large vessels regularly go through the strait, including car carriers and container ships. In normal conditions, nearly 160 make the trip each day.

Advertisement

Some ships in the region turn off the devices that broadcast their positions, while others transmit false locations — making it hard to give a full picture of the traffic in the strait.

The Shiva is a small oil tanker that has repeatedly faked its location, according to TankerTrackers.com, which tracks global oil shipments. It is suspected of carrying sanctioned Iranian oil, according to Kpler. The Shiva was one of the two tankers that crossed the strait on Monday.

The oil and gas that typically move through the strait come from big producing countries like Saudi Arabia, Iraq, Iran and United Arab Emirates, and are exported around the world.

Advertisement

Where tankers moving through the Strait have traveled

Advertisement

Note: Tanker paths are since Jan. 1 and include all tankers and gas carriers. Source: Kpler and Spire.

In 2024, more than 80 percent of the oil and gas transported through the Strait of Hormuz went to Asia. China, India, Japan and South Korea were the top importers, according to the U.S. Energy Information Administration.

Advertisement

Countries have energy stockpiles that could last them into the coming months, but a continued shutdown of the strait could damage their economies.

Several big disruptions have roiled supply chains in recent years, but the tanker standstill in the Strait of Hormuz could have an outsize impact.

Advertisement
Continue Reading

Business

Paramount credit downgraded to ‘junk’ status over debt worries

Published

on

Paramount credit downgraded to ‘junk’ status over debt worries

Paramount Skydance’s jubilation over its come-from-behind victory to claim Warner Bros. Discovery has entered a new phase:

Call it the deal-debt hangover.

Two major ratings agencies have raised concerns about Paramount’s credit because of the enormous debt the David Ellison-led company will have to shoulder — at least $79 billion — once it absorbs the larger Warner Bros. Discovery, bringing CNN, HBO, TBS and Cartoon Network into the Paramount fold.

Fitch Ratings said Monday that it placed Paramount on its “negative” ratings watch, and downgraded its credit to BB+ from BBB-, which puts the company’s credit into “junk” territory. Fitch said it took action due to “uncertainty” surrounding Paramount’s $110-billion deal for Warner Bros. Discovery, which the boards of both companies approved on Friday.

S&P Global Ratings took similar action.

Advertisement

To finance the Warner takeover, Ellison’s billionaire father, Larry Ellison, has agreed to guarantee the $45.7 billion in equity needed. Bank of America, Citibank and Apollo Global have agreed to provide Paramount with more than $54 billion in debt financing.

“Potential credit risks include the prospective debt-funded structure, Fitch’s expectation of materially elevated leverage and limited visibility on post-transaction financial policy and capital structure,” Fitch said.

Late last week, Paramount sent $2.8 billion to Netflix as a “termination fee” to officially end the streaming giant’s pursuit of Warner Bros. That payment paved the way for Warner and Paramount’s board to enter into the new merger agreement.

Paramount hopes the merger will be wrapped up by the end of September. It needs the approval of Warner Bros. Discovery shareholders and regulators, including the European Union.

Paramount executives acknowledged this week the new company would emerge with $79 billion in debt — a considerably higher total than what Warner Bros. Discovery had following its spinoff from AT&T. That 2022 transaction left Warner Bros. Discovery with nearly $55 billion of debt, a burden that led to endless waves of cost-cutting, including thousands of layoffs and dozens of canceled projects.

Advertisement

Warner still has $33.5 billion in debt, a lingering legacy that will be passed on to Paramount.

Paramount plans to restructure about $15 billion in Warner Bros. Discovery’s existing debt.

Paramount CEO David Ellison at a 2024 movie premiere for a Netflix show.

(Evan Agostini / Invision / AP)

Advertisement

Paramount told Wall Street it would find more than $6 billion in cost cuts or “synergies” within three years — a number that has weighed heavily on entertainment industry workers, particularly in Los Angeles.

Hollywood already is reeling from previous mergers in addition to a sharp pullback in film and television production locally as filmmakers chase tax credits offered overseas and in other states, including New York and New Jersey.

Some entertainment executives, including Netflix Co-Chief Executive Ted Sarandos, have speculated that Paramount will need to find more than $10 billion in cost cuts to make the math work. More recently, Sarandos went higher, telling Bloomberg News that Paramount may need $16 billion in cuts.

Cognizant of widespread fears about additional layoffs, Paramount Chief Operating Officer Andrew Gordon took steps this week to try to tamp down such concerns.

Gordon is a former Goldman Sachs banker and a former executive with RedBird Capital Partners, an investor in Paramount and the proposed Warner Bros. deal. He joined Paramount last August as part of the Ellison takeover.

Advertisement

During a conference call Monday with analysts, Gordon said Paramount would look beyond the workforce for cuts because the company wants to maintain its film and TV production levels.

Paramount plans to look for cost savings by consolidating the “technology stacks and cloud providers” for its streaming services, including Paramount+ and HBO Max, Gordon said. The company also would search for reductions in corporate overhead, marketing expenses, procurement, business services and “optimizing the combined real estate footprint.”

It’s unclear whether Paramount would sell the historic Melrose Avenue lot or simply centralize the sprawling operations onto the Warner Bros. and Paramount lots in Burbank and Hollywood.

Workers are scattered throughout the region.

HBO, owned by Warner Bros. Discovery, maintains its West Coast headquarters in Culver City; CBS television stations operate from CBS’ former lot off Radford Avenue in Studio City; and CBS Entertainment and Paramount cable channels executive teams are located in a high-rise off Gower Street and Sunset Boulevard, blocks from the Paramount movie studio lot.

Advertisement

“The combination of PSKY and WBD could create a materially stronger business than either individual entity,” Standard & Poor’s said in its note to investors. “However, this transaction presents unique challenges because it would involve the combination of three companies, with the smallest, Skydance, being the controlling entity.”

David Ellison’s production firm, Skydance Media, was the entity that bought Paramount, creating Paramount Skydance.

Ellison has not announced what the combined company will be called.

Paramount shares closed down more than 6% Tuesday to $12.45.

Warner Bros. Discovery fell 1% to $28.20. Netflix added less than 1% to close at $97.70.

Advertisement
Continue Reading

Business

Commentary: Trump Media’s financial report revives doubts for investors

Published

on

Commentary: Trump Media’s financial report revives doubts for investors

So much Trump-related news has appeared lately on the airwaves and in web pixels — what with Iran and Epstein and Minnesota and so on — that inevitably a nugget will fall between the cracks.

That seems to have been the fate of the most recent annual financial report of Trump Media and Technology Group, which covered calendar year 2025 and was issued Friday.

Trump Media, which is 52% owned by Donald Trump and trades on Nasdaq with a ticker symbol based on his initials (DJT), is the holding company for Trump’s social media platform, Truth Social.

The value of TMTG’s brand may diminish if the popularity of President Donald J. Trump were to suffer.

— A risk factor disclosed by Trump Media

Advertisement

The annual financial disclosure has garnered minimal press coverage. That’s a pity, because it makes fascinating reading, though not in a good way.

Here are the top and bottom lines from the 10-k annual report: Trump Media lost $712.1 million last year on revenue of about $3.7 million. That’s quite a bit worse than its performance in 2024, when it lost $409 million on revenue of about $3.6 million. The company attributed most of the flood of red ink to “loss from investments,” of which more in a moment.

Truth Social isn’t an especially strong keystone of this operation. The platform is chiefly an outlet for Trump’s social media ramblings and the occasional official White House statements. But no one has to sign in to Truth Social to see them — they’re almost invariably picked up by the news media or reposted by users on other platforms such as X.

That might explain Truth Social’s relatively scrawny user base. The platform is estimated to have about 2 million active users, according to the analytical firm Search Logistics. By comparison, X has about 450 million monthly active users and Facebook has more than 2.9 billion.

Advertisement

It’s no mystery, then, why TMTG disdains “traditional performance metrics like average revenue per user, ad impressions and pricing, or active user accounts, including monthly and daily active users,” according to its annual report.

Relying on those metrics, which are used to judge TMTG’s social media rivals, “might not align with the best interests of TMTG or its stockholders, as it could lead to short-term decision-making at the expense of long-term innovation and value creation.”

Instead, the company says it should be evaluated based on “its commitment to a robust business plan that includes introducing innovative features, new products, new technologies.” But it also acknowledges that, at its heart, TMTG is a proxy for “the reputation and popularity of President Donald J. Trump.” The company warns that “the value of TMTG’s brand may diminish if the popularity of President Donald J. Trump were to suffer.”

How has that played out in real time? Trump Media notched its highest closing price as a public company, $66.22, on March 27, 2024, the day after its initial public offering. In midday trading Monday, the shares were quoted at $11.08, for a loss of 83% since the IPO.

One can’t quibble with stock market price quotes; nor can one finagle annual profit and loss statements, at least not without receiving questions, and perhaps lawsuit complaints, from attentive investors and the Securities and Exchange Commission.

Advertisement

In recent months, TMTG has engaged in a number of baroque financial transactions.

In May, the company announced that it was planning to raise $3.5 billion from institutions to invest in bitcoin, with the money to come from issues of common and preferred shares. The goal was to climb onto the cryptocurrency train, which Trump himself was fueling by, among other things, issuing an executive order promoting the expansion of crypto in the U.S. and denigrating enforcement efforts by the Biden administration as reflecting a “war on cryptocurrency.”

Under Trump, federal regulators have dropped numerous investigations related to cryptocurrencies. Trump has also talked about creating a government crypto strategic reserve, which would entail large government purchases of bitcoin and other cryptocurrencies; a March 3 announcement on that subject briefly sent bitcoin prices soaring by nearly 20%, though they promptly fell back.

Then there’s TMTG’s relationship with Crypto.com, a Singapore-based crypto “service provider” best known to Angelenos unfamiliar with the crypto world as the firm with naming rights to the Los Angeles arena that hosts the NBA Lakers and Clippers, WNBA Sparks and NHL Kings.

In August, Crypto.com and TMTG announced a deal in which TMTG would pursue a crypto treasury strategy consisting mostly of Cronos tokens, a cryptocurrency sponsored by Crypto.com. The initial infusion would consist of 6.4 billion Cronos valued at $1 billion, or about 15.8 cents per Cronos.

Advertisement

As of Dec. 31, TMTG said in its 10-K, it owned 756.1 million Cronos, acquired at a cost of about $114 million, or 15 cents each. By year’s end, they were worth only about nine cents each, for a paper loss of about $46 million. In trading this week, Cronos was quoted at about 7.6 cents, producing a paper loss for TMTG of about $56.5 million, or roughly half the investment.

The financial maneuvering involved in this trade is a little dizzying. The initial transaction was a 50% stock, 50% cash trade in which Crypto.com bought $50 million in TMTG stock and TMTG bought $105 million in Cronos. Who gained in this deal? It’s almost impossible to say.

Crypto.com did gain, if not purely in cash, then arguably through the Trump administration’s good graces.

On March 27, the SEC formally closed an investigation of the company that it had launched during the Biden administration, when the agency was headed by a known crypto skeptic, Gary Gensler. Trump appointed a crypto-friendly regulator, Paul Atkins, as Gensler’s successor.

It’s reasonable to note that as a business model, crypto treasuries have been in vogue over the last year or so, allowing investors to play the crypto market without all the complexities of actually buying and holding the digital assets by buying shares in treasury companies.

Advertisement

I asked Crypto.com whether the steady decline in Cronos’ price suggested that the hookup with TMTG wasn’t bearing fruit. “The fluctuation in value during this time period is consistent with the entire crypto market, which is typical in a bear market,” company spokeswoman Victoria Davis told me by email.

Davis also asserted that the SEC’s investigation of the company had been closed by Gensler, “not the current administration” (i.e., Trump). That’s misleading, at best. Gensler put the investigation on hold after the 2024 election, when it became clear that Trump was going to be in charge.

Crypto.com’s March 27 announcement of the formal end of the case attributed the action to “the current SEC leadership” and blamed the case on “the previous administration.” I asked Davis to explain the discrepancy but got no reply.

TMTG, like Crypto.com, attributed the decline in Cronos’ value to the secular bear market raging in the entire cryptocurrency space, a reflection of “temporary price swings across the crypto market,” said TMTG spokeswoman Shannon Devine. She said the price decline “will not diminish our enthusiasm for the enormous potential of the [CRONOS] ecosystem.”

Trump’s coziness with crypto companies hasn’t gone unnoticed by Democrats on the House Judiciary Committee, who issued a scathing report on the topic in November. (The White House scoffed at the report, saying in response to the report that Trump “only acts in the best interests of the American public.”)

Advertisement

In mid-December, TMTG launched yet another remaking — this time, plunging into the business of fusion power. The instrument is TAE Technologies, a Foothill Ranch-based company working to develop the technology of nuclear fusion as a clean energy source. According to a Dec. 18 announcement, TMTG and TAE will merge, creating what they say is a $6-billion company.

According to the announcement, TMTG will contribute $200 million to the merged company when the deal closes in mid-2026, and an additional $100 million subsequently. Following the merger, TMTG said last month, it will consider spinning off Truth Social into a new publicly traded company.

These arrangements are murky. TAE is privately held and the value of Truth Social is conjectural at best, so TMTG shareholders could be hard-pressed to assess their gains or losses from the merger and spin-off.

What makes them even murkier is the speculative nature of fusion as an electrical power source. Although numerous companies have leaped into the field — and TAE, which has been backed by Alphabet, the parent of Google, is among the oldest — none has shown the capability of generating electrical power at commercial scale with the elusive technology.

Although some researchers say that fusion could become a technically and economically feasible power source within 10 years, only in 2022 did fusion researchers (at Lawrence Livermore National Laboratory) achieve the goal of using fusion to produce more energy than is required to sustain a reaction. They were able to do so only for less than a billionth of a second.

Advertisement

Others working on the technology have expressed doubts that fusion could become a viable power source before the 2040s. The technical challenges, including how to convert the energy produced by a fusion reactor into electricity, remain daunting.

All this points to the fundamental question of what TMTG is supposed to be. TMTG’s original mission, according to its own publicity statements, was to build Truth Social into an alternative social media platform “to end Big Tech’s assault on free speech by opening up the Internet.”

Spinning off Truth Social would place that goal on the side. TMTG is on its way too becoming a hodgepodge of crypto, fusion and other investments selected without regard to whether they fit together or are even achievable. The only constant is Trump himself.

If you want to invest in him, TMTG may be the best way to do it. But judging from its latest financial disclosure, that’s not the same as being a good way to do it.

Advertisement
Continue Reading

Trending