
Image Source: Unsplash
Data breaches, ransomware, and other cyberattacks that may cost millions keep filling the news. You'll also often hear the term Personally Identifiable Information (PII). In fact, PII is the main prize the crooks are after!
Why is that? What is PII? Who collects it? How can bad actors use it to harm you? Find insightful answers to these questions and more below.
What is Personally Identifiable Information?
PII is any type of information viewed alone or in a context that can be used to identify a unique individual. Some of this information is publically available, like one’s name and address or phone number in business directories or phone books. Companies may also create PII that helps them identify clients but doesn't make sense outside their systems. For example, they could tie a customer's profile to a number or other means of classification.
Different organizations collect different kinds of PII. The banking and health sectors are responsible for the bulk of it. Banks know everything about your account access details and transaction histories. Health-related institutions can access your medical records, possibly including highly vulnerable data like patient histories and psychiatric evaluations.
Due to its sensitive nature, any organization that handles PII must have robust systems to safeguard it. On the one hand, they must protect the physical devices and digital databases that store such information. On the other hand, PII also needs protection while it's in transit, i.e., while organizations are communicating.
The challenge is to ensure continued PII safety through best practices. PII doesn’t only reside in databases. It can become accessible via internal memos, temporary files, or human negligence. The shift to working from home also impacts PII security if employees don’t connect to company networks securely. Thankfully, employing cybersecurity measures like using VPN makes all easy by protecting them from threats and malicious actors on the network.
What Is the Most Common PII?
More personally identifiable information is out on us now than ever. Moreover, the scope of what constitutes PII keeps expanding. For example, one’s name, birthday, (email) address, SSN, driver’s license, banking details, medical records, and credit card information are all long-standing examples.
Scientific advances, the prevalence of digitization, and individuals' increased online presence have given birth to new forms of PII. These include biometric scans & genetic data, race & gender, online handles & passwords, and security questions & answers.
One’s online activities can become the source of much insidious PII. For instance, your social media posts may say a lot about your political and religious views or your sexual orientation. While these aren’t enough to identify someone independently, they help shoehorn them into functional categories.
What Dangers Does Exposed PII Pose?
The consequences of improperly protected PII vary in severity. A data breach may uncover millions of email addresses and associated names. The fact that the breach happened is enough to cause reputational loss and financial damages to the targeted organization. Cybercriminals might use those emails to orchestrate phishing attacks and try to coerce recipients into giving them money or valuable info.
Identity theft and fraud are among the most serious consequences for individuals. Someone with access to a combination of one's credentials, SSN, and banking info could start taking out loans or opening new accounts in their name. This may harm your credit score, saddle you with debt, and even involve the authorities or IRS. Proving you didn't commit the crimes can become a prolonged and expensive ordeal.
Data brokers make a profit by using publically available PII legally. Most create customer profiles based on the data. They group them into similar sets based on factors like ZIP code, income bracket, age, etc., and sell those sets to advertisers. These then send you targeted ads in hopes of making a sale. Data brokers may also run people's search sites containing information on people's place of residence, marital status, and more.
Yet, this doesn’t mean the data brokers have your data forever. You can take action to reduce spam, prevent scam attacks, and keep your PII safe. A strategy you might consider is utilizing tools that connect with data brokers and guide them to exclude your personal information from their databases.
Who Is Responsible for Protecting PII?
Studies suggest that almost half of the participants believe organizations that collect PII are solely responsible for its safekeeping. However, the reality is that we all need to do our part. Robust organizational protection can’t help if you’re careless with social media posts, use weak passwords, or fall for social engineering scams. Taking individual responsibility for one's PII is an effective security measure you should start practicing.




Comments
Log in or sign up to join the conversation.