September 7, 2017
Equifax discloses massive data breach
Equifax announced on September 7, 2017 that attackers had stolen personal data on 147 million Americans — names, Social Security numbers, and birth dates — via an unpatched Apache Struts flaw.
What it was for
The breach exposed credit-bureau data that cannot be rotated like passwords — fueling identity-theft monitoring services and GDPRGeneral Data Protection Regulation — EU law governing how organizations collect and process personal data.-style breach-notification debates in the U.S. Developers learned that unpatched JavaA portable language running on the JVM — dominant in enterprise servers, Android, and big data. web frameworks on internet-facing apps could leak half the country's PII; Equifax's CISO and CEO resigned amid congressional hearings.
Why it's here
Equifax was the breach that put 147 million SSNs on the dark web.
Why it mattered
It made framework patching and breach disclosure timelines board-level issues.
What it solved
Nothing for consumers — attackers exploited a known Struts CVECommon Vulnerabilities and Exposures — a public dictionary of known security flaw identifiers. Equifax had failed to patch.
Media
- ImageEquifax
Equifax, Public domain, via Wikimedia Commons
Related
- Ashley Madison user data leakedAugust 18, 2015
- Heartbleed OpenSSL vulnerability disclosedApril 7, 2014
- EU General Data Protection Regulation takes effectMay 25, 2018