The Equifax breach of 2017 was a disastrous failure of security on many levels, resulting in the exfiltration of up to 145.5 million people. This breach was costly to Equifax, between lawsuits, fines, and reputational damage, as they didn’t take their security measures seriously.
In March of 2017, Chinese cybersecurity researcher Nike Zheng exposed a flaw in a popular backend software called Apache Struts. The vulnerability was later named CVE-2017-5638. If attackers sent HTTP requests with malicious code in the content-type header, Struts could be tricked into executing that code and potentially opening up the system Struts was running on to further intrusion. He provided this information to Apache, which published the flaw and the fix for it on March 6th. Apache showed how the flaw could be used to steal data from any company using Apache Struts. This caught the attention of the global hacking community. Within 24 hours, the information was posted to Freebuf[.]com, a Chinese security website, and on Metasploit. On March 9th, Equifax administrators were told to apply the patch to any affected systems, but the employee tasked with the updates didn’t run them. On March 10th, threat actors started scanning the web for vulnerable systems when they got a hit on an Equifax server in Atlanta.
From there, the threat actors that got the hit went in through Equifax’s online dispute portal and installed a web shell. Eventually, the intruders installed more than 30 web shells, each on a different web address, so they could continue operating if some of the web shells were discovered. According to the investigation reports, the first intrusion was likely done by an entry crew and then handed off to a more sophisticated team of threat actors.
Equifax’s IT department ran a series of scans to identify unpatched systems on March 15th; at that time, there were multiple vulnerable systems including the web portal, but none of the vulnerable systems were flagged or patched.
Once Equifax discovered the intrusion, they hired Mandiant to help them find the issues that caused the intrusion. Mandiant scanned Equifax’s network and reported back on the issues. However, just as the threat actors were securing their foothold on the network, Equifax and Mandiant got into a large dispute. This dispute quashed any possibility of a broader look at Equifax’s security posture. Due to this dispute, Equifax focused on refuting the information supplied by Mandiant, rather than fixing the vulnerabilities, which allowed the threat actors to continue the intrusion. Eventually, the threat actors customized their tools to work more efficiently within Equifax’s network and on its software.
From May-July 2017, the threat actors worked their way through the Equifax systems, gaining access to multiple databases containing information on millions of people. They exfiltrated as much of this information as they could.
The threat actors found and extracted the financial data—Social Security numbers, birth dates, addresses, and more—of at least 143 million Americans. This was a massive amount of data to move and it should have been detected. Like many cyberthieves, Equifax’s attackers encrypted the data they were moving to make it harder for admins to spot. Similar to many large enterprises, Equifax had tools that decrypted, analyzed, and then re-encrypted internal network traffic, specifically to sniff out data exfiltration events like this. A caveat is that to re-encrypt traffic, these tools need a public-key certificate, which is purchased from third parties and must be renewed annually. Equifax had failed to renew one of their certificates nearly ten months prior, which meant that encrypted traffic wasn’t being inspected. The expired certificate wasn’t discovered and renewed until July 29, 2017, at which point Equifax administrators almost immediately noticed all of the previously obfuscated suspicious activity. This was when Equifax first knew about the breach. It took another month of internal investigation before Equifax publicized the breach on September 8, 2017.
There’s evidence that the threat actors were working for Chinese Intelligence. Many of the tools used were Chinese, and the Equifax breach has the hallmarks of similar intrusions at Anthem Inc., a health insurance company, and the U.S. Office of Personnel Management. Both of these intrusions were attributed to threat actors working for Chinese Intelligence. However, the attackers avoided using tools that investigators can use to fingerprint known groups. One of the tools used—China Chopper—has a Chinese-language interface, but it’s also used outside of China. Groups known to exploit web shells most effectively include teams with links to Chinese Intelligence, including one nicknamed the Shell Crew. Years later, none of the information exfiltrated has shown up for sale on the dark web, indicating that the information stolen was simply for keeping. This furthers the idea that state-sponsored threat actors were responsible for the breach.
Equifax’s negligence wound up costing the company far more than the price of updating its systems as advised. The lawsuits that Equifax faced totaled $575 million. Additionally, they won and then lost a $7.25 million contract with the IRS. Two years after the breach, the company said it had spent $1.4 billion on cleanup costs, including upgrading security systems and the Equifax network. In June 2019, Moody’s downgraded the company’s financial rating, partially because of the massive amount Equifax would need to spend on infosec in years to come. In July 2019, Equifax settled with the FTC, which wrapped up an ongoing class action lawsuit that required Equifax to spend at least $1.38 billion to resolve consumer claims. Missing from these figures is the amount of money spent notifying consumers, as well as the loss of future business due to the lack of consumer trust.
Equifax’s breach was bad enough because they didn’t update their security systems promptly, but the continued neglect of their systems cost the company in the long run. Learn from Equifax - integrate security, update your systems, and hire the best people to run your infosec teams.
References:
CSO Online: Siciliano, R. (n.d.). Equifax data breach FAQ: What happened, who was affected, what was the impact. CSO Online. Retrieved from https://www.csoonline.com/article/567833/equifax-data-breach-faq-what-happened-who-was-affected-what-was-the-impact.html
U.S. Senate: Warren, E. (2018, September 6). GAO Equifax report. United States Senate. Retrieved from https://www.warren.senate.gov/imo/media/doc/2018.09.06%20GAO%20Equifax%20report.pdf
Bloomberg: Riley, M., Robertson, J., & Brustein, J. (2017, September 29). The Equifax hack has all the hallmarks of state-sponsored pros. Bloomberg. Retrieved from https://www.bloomberg.com/news/features/2017-09-29/the-equifax-hack-has-all-the-hallmarks-of-state-sponsored-pros
Dig8ital: Author Unknown. (n.d.). Poor application security can increase costs by 3000%. Dig8ital. Retrieved from https://dig8ital.com/post/poor-application-security-can-increase-costs-by-3000/
Editors Note About Kara:
Kara Federow, is a seasoned supervisor leading a team of malware remediation analysts, diligently hunts down and eradicates malicious software on clients’ websites. With precision and expertise, she ensures digital landscapes remain secure, safeguarding businesses and users alike. Beyond her cyber-defender role, Kara immerses herself in the realms of sci-fi and fantasy, drawing inspiration from otherworldly tales. When not battling virtual foes, she engages in epic Dungeons & Dragons campaigns, weaving magic both online and offline.
No posts

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.