The Equifax Breach: Admin Passwords, a Missed Patch, and China’s Spies

The 2017 Equifax breach exposed the Social Security numbers, birth dates, addresses, and credit histories of over 147 million Americans, plus more than 1.5 million people in the UK. It was not a brilliant attack. A 2015 internal audit had already found a backlog of unpatched vulnerabilities, no complete inventory of the company’s own systems, and a patching process that ran on an honor system. When a critical fix for Apache Struts was released on March 7, 2017, Equifax never applied it to its credit dispute portal.

This episode walks through what followed. Intruders entered on May 12, found internal accounts protected by the username and password admin, and spent 76 days pulling data out in small encrypted archives. It then turns to the response: a 38 day silence, executive stock sales, a help site that security tools flagged as a scam, and a buried arbitration clause. Finally it asks why the stolen data never surfaced for sale, and what the answer says about modern espionage.

  • The theft was caught by accident on July 29, when staff renewed an SSL certificate on a traffic monitoring tool that had been expired for nine months.
  • With no internal network segmentation, attackers who entered through one web portal could roam to the core databases and run over 9,000 queries.
  • Weeks before the public was told, three executives including the chief financial officer sold almost $1.8 million in company stock.
  • Equifax’s own Twitter account linked at least eight times to a spoof of its help site built by software engineer Nick Sweeting, sending around 200,000 people to the wrong page.
  • In February 2020 the Department of Justice indicted four members of China’s People’s Liberation Army. Equifax had agreed in July 2019 to a settlement of over $575 million.

Leave a Reply

Discover more from pplpod

Subscribe now to keep reading and get access to the full archive.

Continue reading