I didn't really want to have to write this, but given how many readers have asked, it seemed wise to see this one through:

Millions of people likely just received an email or snail mail notice saying they’re eligible to claim a class action payment in connection with the 2017 megabreach at consumer credit bureau Equifax. Given the high volume of reader inquiries about this, it seemed worth pointing out that while this particular offer is legit (if paltry), scammers are likely to soon capitalize on public attention to the settlement money.

https://krebsonsecurity.com/2022/12/the-equifax-breach-settlement-offer-is-real-for-now/

More important, from my view anyway, is the info at the bottom of the piece:

Equifax surpassed Wall Street’s expectations in its most recent quarterly earnings: The company reported revenues of $1.24 billion for the quarter ending September 2022.

Of course, most of those earnings come from Equifax’s continued legal ability to buy and sell eye-popping amounts of financial and personal data on U.S. consumers. As one of the three major credit bureaus, Equifax collects and packages information about your credit, salary, and employment history. It tracks how many credit cards you have, how much money you owe, and how you pay your bills. Each company creates a credit report about you, and then sells this report to businesses who are deciding whether to give you credit.

Americans currently have no legal right to opt out of this data collection and trade. But you can and also should and freeze your credit, which by the way can make your credit profile less profitable for companies like Equifax — because they make money every time some potential creditor wants a peek inside your financial life. Also, it’s probably a good idea to freeze the credit of your children and/or dependents as well. It’s free on both counts.

The Equifax Breach Settlement Offer is Real, For Now – Krebs on Security

@briankrebs Time to start monitoring spoofy domain names...

@briankrebs For example, the following all look like they don't have any connection to Equifax itself:

equifaxbreachsettlement,com
equifaxbriefsettlement,com
equifaxbreachsettlementbreach,com
equifaxsettlements,co
eportsupport-equifax,com
equifaxbreechsettlement,com
ecuifax,co.uk
equifaxfreecreditscore,com
indianaequifaxclaim,com

...and others

Shields up!

@ColonelPanic @briankrebs the annoying part is that EquifaxBreachSettlement./com is legit. https://www.ftc.gov/enforcement/refunds/equifax-data-breach-settlement
Equifax Data Breach Settlement

Federal Trade Commission
@aaronh @briankrebs They certainly aren't doing themselves (or the public) any favors by registering the domain in the same manner as malicious actors do (smallish registrar [Bodis], full privacy, registrar-based nameservers)