September 7, 2017

Equifax discloses massive data breach

Equifax announced on September 7, 2017 that attackers had stolen personal data on 147 million Americans — names, Social Security numbers, and birth dates — via an unpatched Apache Struts flaw.

What it was for

EquifaxThe breach exposed credit-bureau data that cannot be rotated like passwords — fueling identity-theft monitoring services and GDPRGeneral Data Protection Regulation — EU law governing how organizations collect and process personal data.-style breach-notification debates in the U.S. Developers learned that unpatched JavaA portable language running on the JVM — dominant in enterprise servers, Android, and big data. web frameworks on internet-facing apps could leak half the country's PII; Equifax's CISO and CEO resigned amid congressional hearings.

Why it's here

Equifax was the breach that put 147 million SSNs on the dark web.

Why it mattered

It made framework patching and breach disclosure timelines board-level issues.

What it solved

Nothing for consumers — attackers exploited a known Struts CVECommon Vulnerabilities and Exposures — a public dictionary of known security flaw identifiers. Equifax had failed to patch.

Media

  • Equifax
    ImageEquifax

    Equifax, Public domain, via Wikimedia Commons

Related