Stolen Consumer Data Is a Smaller Problem Than It Seems
At Target, 40 million customers had their credit card information exposed to hackers. At JPMorgan Chase, personal details associated with 80 million accounts were leaked. In July, a hacker gained access to 4.5 million records from the University of California, Los Angeles, health system. Enormous numbers like these can make it feel as if we’re living through an epidemic of data breaches, in which no one’s bank account or credit card is safe. But the actual effect on consumers is quite different from what the headlines suggest. Only a tiny number of people exposed by leaks end up paying any costs, and for the rare victims who do, the average cost has actually been falling steadily. How could that be?
For starters, several laws protect consumers from bearing almost any financial losses related to hackers (though not the headaches of having to enter new credit card numbers into Amazon and elsewhere). Instead, banks and merchants, like Target, must bear the cost. But even their losses have been dropping in recent years, as data security experts have learned new strategies to prevent intrusions from turning into theft. It’s true that data breaches, particularly those in which Social Security numbers are compromised, can lead to a more devastating sort of identity theft, in which criminals open new financial accounts in a person’s name and do damage that can take years and a lot of work to clean up. But consumers are almost never on the hook for financial losses in these sorts of episodes, which, by the way, have also been on the decline.
Stolen Consumer Data Is a Smaller Problem Than It Seems