Sunday, March 28, 2021

Experian and Infinity Insurance scam

 Since I have been Security+ exam, I have been reading up on the latest cybersecurity threats. Lately, one came to me in the mail!

I received a letter regarding a data breach and that my information may have been comprised.

However, several things concerned me:

  1. The insurance company: I have never done business with Infinity Insurance Company nor (knock on wood) been in any incident with any of their drivers.
  2. The stamped envelope and return address had different locations.
    return address on first page
    from the first page of the letter

    postmark on the envelope
    from the envelope
    also some other people who stated that this a scam noted the lack of company letterhead on the letter.

  3. Phone number provide 877-316-0057 does not yield a company name when conducting reverse phone number search on https://www.whitepages.com/reverse-phone
    White pages Result from 877-316-0057

  4. Site provided, https://www.experianidworks.com/plus or www.ExperianIDWorks.com/restoration , is not an Experian site. Here is an example of what the other pages on the real Experian site looks like: https://www.experian.com/contact/personal-services-contacts.html#content-04   or https://www.experian.com/consumer-products/identity-theft-and-credit-protection.html which all start with https://www/experian.com not a wholly different domain name.


Also, the letter received has very few typographical errors as the scammer probably copied the actual letter located at https://oag.ca.gov/ecrime/databreach/reports/sb24-539174


If you get a letter like this, please let Experian know:

Email: support@experiandirect.com

Twitter: @Experian_US

Facebook: https://www.facebook.com/experian

Instagram: https://www.instagram.com/experian/



Saturday, March 27, 2021

Language is Changing!

 I have often heard that language is changing. I found it to be true when studying for the CompTIA Security + examination. Every industry has its own terminology or jargon. In 2017, I had taken CompTIA Security+ SY0-501 exam and in the process, learned IT security jargon. Or so I thought! 


Currently, I am preparing for the CompTIA Security+ SY0-601 and decided to freshen up with some LinkedIn Learning courses, CompTIA CertMaster Practice and practice tests.  It was refreshing to know that I had retained some information but frightening to feel stumped. What do I mean? When the answer selection includes pineapple, pixie dust and POODLE. It made me laugh and thought those were obvious wrong answers.


Well, I was wrong! Those were also right answers as a POODLE is a downgrade attack, pixie dust is a type of attack on WPS protocol for WIFI and a pineapple is another type of attack on WIFI. 


I am only halfway through my review but those stuck out to remind me that there is more to come.


What industry’s jargon give words other meaning?