Great Star Tools USA Data Breach

Great Star Tools USA, Inc. has told a group of individuals that someone got into its computer systems without permission and may have viewed or copied files containing personal information. The company says it first noticed suspicious activity on August 17, 2023, and its investigation later determined the intruder had access to its network for roughly two weeks, from August 2 through August 17, 2023. Great Star brought in outside cybersecurity specialists to figure out what happened, then spent months afterward reviewing the accessed files line by line to identify whose data was inside them and how to reach those people — a process the company describes as finalized only recently, which explains why notices are going out well over a year after the intrusion itself.

The letter is addressed to people whose names turned up during that file review. Great Star’s notification doesn’t give a total headcount of affected individuals in the portion filed with California’s Attorney General, and the version of the letter we were able to review left the specific category of exposed data as an unfilled template placeholder next to the word name — meaning we can confirm your name was involved, but not the exact additional data element without seeing your personalized copy.

What exactly did Great Star say was taken?
  • Your name
  • At least one other category of personal information, specific to your record, that the mailed letter should identify by name (this field was not filled in on the sample notification text provided to us)

Even without a filled-in list of data types, the response Great Star is offering is a strong signal: the company is providing complimentary credit monitoring and identity restoration through Equifax Credit Watch Gold, which includes up to $1,000,000 in identity theft insurance coverage. You can activate this by going to www.equifax.com/activate and entering the unique activation code printed on your individual letter; the enrollment deadline field was also left blank in our copy of the template, so check your own letter for the actual cutoff date before it passes.

Steps worth taking if your name showed up in this notice
  • Activate the free Equifax Credit Watch Gold enrollment using the code on your letter before the stated deadline, since it includes daily credit report access and dark-web-style WebScan alerts.
  • Pull your free annual credit reports from all three bureaus at annualcreditreport.com and look over them for accounts or inquiries you don’t recognize.
  • Because the letter doesn’t rule out sensitive identifiers being involved, consider placing a fraud alert or credit freeze with Equifax, Experian, and TransUnion — all three offer free freezes by phone or online.
  • Watch bank and credit card statements over the next several months, and don’t ignore small, unfamiliar charges — they’re sometimes a test run before larger fraud.
  • For ongoing peace of mind, you might also sign up for a service like Aura or LifeLock, which can alert you if your personal details start circulating elsewhere online.
  • Keep the physical letter and any activation code — you’ll need them if you ever have to prove you were part of this incident to a bank or credit bureau.

Questions about the letter can be directed to Great Star’s dedicated line at 855-285-4906 (Monday through Friday, 9 am to 9 pm ET), or by writing to 271 Mayhill Street, Saddle Brook, NJ 07663, Attn: Human Resources.

Leave a Comment