FREE NEWSLETTER

Forum › Behavior

Another Data Breach

My wife and I received letters in the mail today from Conduent, and underneath this name Return to Kroll.

I was suspicious so Googled it. This is what I found:

In early 2025, Conduent experienced a cyberattack where hackers accessed their systems, stealing personal data (names, SSNs, medical info) of over 10 million people, impacting users of various state agencies and health insurers like BCBS.

This is the fourth such data breach affecting me in the past few years.

As I posted recently this will not stop until congress passes a law the results in painful fines for companies’ lack of taking the security of our data seriously and these hacks become rare.

This is also why I feel a paper list of my passwords in a fire safe is more secure than password manager. All I hear is about how password manager are secure due to encryption

More On This Topic

Email Alerts for this Comment Thread
Notify of
11 Comments
Newest
Oldest Most Voted
quan nguyen
9 months ago

Evolving technology makes going back to papers an inadequate defense against identity theft in the AI era. We live in a world where digital footprint with our identity is inescapable, but there are technologies to protect us too. The strongest ones
1) Foundation: Vigilance, Safety Mindset / online habit – Scam avoidance is top priority. Credit Freeze.
2) Physical layer:
Our phones, iPad, computer – more critical than cash and wallet
Physical security keys – Google Titan Security key, Yubikey with backup: fast, convenient, durable protection
3) Digital layer:
Authenticator App for 2 Factor Authentication – not SMS texting to phone
Passkey?
ID theft protection? maybe Companies like LifeLock, Aura, and Identity Guard

Last edited 9 months ago by quan nguyen
Mike Gaynes
9 months ago
Reply to  quan nguyen

I thought 2 factor authentication was a set of numbers texted to your phone. Not so?

parkslope
9 months ago
Reply to  Mike Gaynes
  • There are multiple forms of 2FA. SMS texts, while much safer than passwords alone, are considered less secure than Authenticator apps for the following reasons:
  • Vulnerability to SIM swapping: Attackers can trick your mobile carrier into porting your phone number to a phone they control, allowing them to receive your 2FA codes. You can mitigate this risk by setting up a PIN with your mobile provider.
  • Lack of encryption: SMS messages are not encrypted, which means a threat actor with access to the telecommunication network could potentially intercept them.
  • Dependence on cell service: The service requires your phone to have a cellular signal to receive the text message.
  • Compromise of phone number: If an attacker gains access to your phone number through other means, they can potentially bypass the SMS 2FA
OldITGuy
9 months ago

Security is a complex topic requiring a clear perspective of the threat one is trying to mitigate. I use a fee based password manager with an excellent reputation, independent security audits, and the vendor doesn’t have the ability to decrypt my password repository. Plus the product uses a 2 key system so access to my repository is restricted to devices it was preinstalled upon, the installation of which requires access to both keys (neither of which the password manager company has access to). Plus if the product is compromised I believe it is highly likely it will be detected and the customers notified. Who will notice and report to the owner if the paper copy of their password list is compromised in their house, safe deposit box, or wherever? Thanks for raising the concern, but I’m sticking with a modern, mature, and well vetted password manager. Gene

rgscl