Equifax deny sharing my email address

This made me LOL. How can they deny it when there's no other possible
explanation? Caught
red handed and they bloody know it.
Dear Mr [deleted]
Thank you for your recent correspondence.
We would advise that we do not sell onto third parties the information
that is provided to us as part of the credit file application process,
which includes email addresses.
We treat data security extremely seriously and the concerns you have
raised have been communicated to our
Information Security Director.
Should we wish to contact you regarding this matter, we would be
grateful if you could provide a daytime telephone number on which you
can be reached.
I hope the above details are of assistance to you.
Kind Regards
Neil White
MyEquifax Customer Care Team
Bitstring , from the wonderful person nick said
Actually there are other possible explanations, like a dictionary attack ... however the balance of probabilities is definitely with you.
GSV Three Minds in a Can
"GSV Three Minds in a Can" wrote
I think this is possibly quite likely.
Nick said he'd given them the email address "equifax @ mydomain".
I have actually given them two different email addresses - one of which was also "equifax @ mydomain" (obviously a different domain to nick's!).
Interestingly, I received exactly the same spam sent to the address "equifax @ mydomain", but *not* to the other address which I had given to Equifax. Looks like some spammer is sending their rubbish to email addresses starting "equifax @ ", but quite why, I wouldn't know...
I think a more reasonable explanation is that Equifax share with 3rd parties but deny it. Just think of the value of that information they hold. The spam I've received is all financial related, not your typical viagra spam. AND, its all UK based, and how would they know my .org domain that is actually based in the USA, is UK? Interestingly, I only started receiving spam after I told equifax to stop sending me email on that address.
Using a similar system to yourself to track "leaks" of information, i`ve only ever had two places release the email address to spammers over a period of about 4 (?) years - uktv and ticketmaster.
This is despite having probably several hundred "unique" email addresses in circulation now, under several domain names.
I had ticketmaster bang to rights, as it was all their own affiliated tickety/venue spamvertising sites sending the sh*te.
I`m cynical, but I believe I would have been the recipient of a lot more spam via dictionary attacks rather than by the unauthorised release of data if they were that effective.
I check 7 email addresses a day, and used to get ~580 spam mails per day (my current spamlegit mail ratio is 95%+ spam), so I think I have a reasonable grasp of the proliferation of spam.
Colin Wilson
AAMOI I also gave a unique e-mail address to Equifax and I've received no spam to that address, except *from* Equifax of course.
Mike Barnes
Why would they need your daytime phone number? What urgent matter that could possibly be? Surely, everything they could ever want to tell you they'd put in writing, wouldn't they?
Joe R
Joe Random
"nick" wrote
Then can you explain why the other email address I gave them received *no* spam?
"nick" wrote
Two different visits to their website.
But you didn't answer my question - if they have sold the email addresses, then why did I only get spam to " equifax @ mydomain " and not to the other email address I gave?
