Equifax’s hack, one year later: A look back at how it happened – CNET

Google wifi and iCloud illustration

It’s been a full year since Equifax announced that it suffered a hack affecting 147 million Americans.

Jaap Arriens/NurPhoto via Getty Images

On the anniversary of Equifax’s major breach, lawmakers released a report (PDF) detailing exactly how the credit-monitoring company was hacked.

The report comes from the Government Accountability Office, a watchdog organization from the federal government. The GAO reviewed documents from Equifax as well as files from the company’s cybersecurity consultant to figure out how the company was hacked and what credit-monitoring services should do to protect itself.

The watchdog group also discovered that Equifax turned down assistance from the Department of Homeland Security, opting instead for a private, third-party cybersecurity company to help manage its breach response.

screen-shot-2018-09-06-at-5-34-49-pm

screen-shot-2018-09-06-at-5-34-49-pm

A chart describing how Equifax was breached.

Government Accountability Office

The attack process started on March 10 when hackers searched the web for any servers with vulnerabilities that the US-CERT warned about just two days earlier. Two months later, on May 13, they hit the jackpot with Equifax’s dispute portal — a section where people could go to argue claims from the credit-monitoring service.

There, hackers used an Apache Struts vulnerability, a months-old issue that Equifax knew about but failed to fix, and gained access to login credentials three servers. They used those login credentials from the dispute portal and found that it allowed them to access another 48 servers containing personal information.

The thieves spent 76 days within Equifax’s network before they were detected. According to the report, the hackers stole the data piece by piece from 51 databases so they wouldn’t raise any alarms.

Equifax didn’t know about the attack until July 29, more than two months later, and cut off access to the thieves on July 30.

Since then, Equifax said that it’s implemented a new management system to handle vulnerability updates and to verify that the patch has been issued.

Sen. Ron Wyden, a Democrat from Oregon, Sen. Elizabeth Warren, a Democrat from Massachusetts, Rep. Elijah Cummings, a Democrat from Maryland, and Rep. Trey Gowdy, a Republican from South Carolina, were the four lawmakers who requested the report.

“Today’s report highlights the breakdowns and failures at Equifax that led to one of the largest and most consequential data breaches in United States history,” Cummings said in a statement. “Now that we know even more about what led to the Equifax breach, it is critical that we develop serious and concrete proposals to help the American people.”

Security: Stay up-to-date on the latest in breaches, hacks, fixes and all those cybersecurity issues that keep you up at night.

Blockchain Decoded: CNET looks at the tech powering bitcoin — and soon, too, a myriad services that will change your life.


🕐 Top News in the Last Hour By Importance Score

# Title 📊 i-Score
1 Small boat migrants in UK telling pals in France how good they've got it and to join them 🔴 78 / 100
2 CSF President Dave Cavossa Testifies Before the U.S.-China Economic and Security Review Commission 🔴 72 / 100
3 UK bees are dying out – gardening tips to help them and flowers they love 🔴 65 / 100
4 'I've visited all 195 countries in the world – these are my favourite three cities' 🔵 60 / 100
5 Trump's third term strategy 'exposed' on HIGNFY – it's out of Putin's playbook 🔵 52 / 100
6 PGA Tour winner owned £7.2m mansion which includes saltwater pool and five-car garage 🔵 45 / 100
7 KwikFit boss admits ‘prices will rise’ with consumers to feel sting of Labour NI hike 🔵 45 / 100
8 Cinderella fans say one thing about remake as Disney original celebrates 75 years 🔵 45 / 100
9 You’re Probably Not Machine-Washing Your Sheets and Bedding the Right Way 🔵 45 / 100
10 European football: Müller to leave Bayern after 25 trophy-laden years 🔵 32 / 100

View More Top News ➡️