Showing posts with label Equifax. Show all posts
Showing posts with label Equifax. Show all posts

Friday, October 13, 2017

IRS Pulls Equifax Contract In "Precautionary Step"

And the hits just keep on coming...


Until today"s headlines indicating the possibility of another breach of Equifax"s security, dip-buyers had been enjoying a few days" relief as analysts clammored to explain how one of the biggest cyberhacks of all time did nothing to hinder Equifax"s business model. Tonight, they might just start questioning that as Politico reports The IRS has temporarily suspended the $7.2 million, no-bid contract it awarded to Equifax to verify the identities of taxpayers.



As Politico reports, the short-term suspension means that taxpayers will not be able to establish new accounts through a program called Secure Access, which grants them access to online records and transcripts. Those taxpayers who already have accounts will not be affected, the agency said.





The IRS plans to continue reviewing the security of Equifax"s systems during the suspension.



The agency had previously said its hands were tied and it had to keep the contract with Equifax.



"The IRS emphasized that there is still no indication of any compromise of the limited IRS data shared under the contract. The contract suspension is being taken as a precautionary step as the IRS continues its review," agency spokesman Matthew Leas said in a statement.



For now the dip-buyers have slowed down...



In letters to IRS Commissioner John Koskinen, some members of Congress questioned whether Equifax could be trusted to handle taxpayer data and suggested the contract should be revoked.


Is Equifax"s business model starting to come into question?

Thursday, October 12, 2017

Equifax Web-Page Goes Offline Amid Reports Of New Breach

Equifax has taken one of its web pages offline as its security team looks into reports of another potential cyber breach, the credit reporting company, which recently disclosed a hack that compromised the sensitive information of 145.5 million people, said on Thursday.






"We are aware of the situation identified on the equifax.com website in the credit report assistance link," Equifax spokesman Wyatt Jefferies said in an email.



"Our IT and security teams are looking into this matter, and out of an abundance of caution have temporarily taken this page offline."



As CBC reports, the move came after an independent security analyst on Wednesday found part of Equifax"s website was under the control of attackers trying to trick visitors into installing fraudulent Adobe Flash updates that could infect computers with malware, the technology news website Ars Technica reported.





When I clicked it (from Gmail on Android) I was redirected to a spam page shortly after seeing the Equifax credit file form.





I thought maybe it was an anomaly because it didn"t happen again. But after reading your article about how sometimes hacks will redirect randomly I tried the link again just now and sure enough I got a spam page again (lucksupply.club saying I won an iPhone X). This is Chrome-in-a-tab from Gmail so i don"t believe there"s any extensions or other malware on my device that could have caused this redirect.



EFX share price is tumbling...


Thursday, October 5, 2017

This Isn't A Joke: The IRS Just Hired Equifax To Safeguard Taxpayer Data

Just hours after Equifax CEO Rick Smith wrapped up his testimony before the House Energy and Commerce committee – the first in a series of Congressional “fact-finding missions” about the hack - Politico reported that the IRS last week awarded the disgraced credit monitoring bureau with a $7.25 no-bid contract even as the company struggled to address suspicions that it mislead investors and customers by withholding information about one of the most damaging data breaches in US history.


Equifax famously waited more than a month to disclose that hackers had infiltrated its servers and absconded with the sensitive financial information of more than 140 million customers, sparking widespread outrage that only intensified after reporters discovered that several of the company’s senior executives – including its CFO – cashed out of shares and options in the weeks before the company came clean about the hack.



According to the terms of the IRS contract, Equifax would be responsible for verifying taxpayer identities and help prevent fraud under a no-bid contract issued last week.


As if the IRS"s decision to entrust the disgraced credit bureau with sensitive taxpayer data wasn"t galling enough, the agency seemingly fast-tracked the contract by classifying it as a “sole source order” – a designation that allows the agency to circumvent the bidding process by claiming a given vendor is the only one capable of executing the contract. However, the agency"s justification for this designation is baffling, considering that there are two other credit bureaus in the US that offer a nearly identical suite of services.





The notice describes the contract as a "sole source order," meaning Equifax is the only company deemed capable of providing the service. It says the order was issued to prevent a lapse in identity checks while officials resolve a dispute over a separate contract.



Lawmakers from both parties demanded an explanation from the agency, which has endured several memorable data-security lapses – including a 2015 breach that exposed the sensitive financial information of more than 100,000 taxpayers.





Reps. Suzan DelBene (D-Wash.) and Earl Blumenauer (D-Ore.) separately penned letters to IRS Commissioner John Koskinen demanding he explain the agency"s rationale for awarding the contract to Equifax and provide information on any alternatives the agency considered. "I was initially under the impression that my staff was sharing a copy of the Onion, until I realized this story was, in fact, true," Blumenauer wrote.



Senate Finance Committee Chairman Orrin Hatch criticized the agency’s decision as “irresponsible.”





"In the wake of one of the most massive data breaches in a decade, it’s irresponsible for the IRS to turn over millions in taxpayer dollars to a company that has yet to offer a succinct answer on how at least 145 million Americans had personally identifiable information exposed," Senate Finance Chairman Orrin Hatch (R-Utah) told POLITICO in a statement.



Hatch raised concerns about the IRS’s cybersecurity practices in a letter sent to the agency’s head last month. To help the agency improve its data-security safeguards, Congress recently allocated $106.4 million to bolster the agency’s identity theft protections.





Hatch questioned the agency"s security systems in a letter to Koskinen last month. Hatch said he was concerned that the IRS lacked the technology necessary "to safeguard the integrity of our tax administration system."



Ron Wyden said the Finance Committee would seek to verify whether Equifax was really the only company capable of executing the contract, as the agency insisted.





The committee"s ranking member, Sen. Ron Wyden (D-Ore.), piled on: "The Finance Committee will be looking into why Equifax was the only company to apply for and be rewarded with this. I will continue to take every measure possible to prevent taxpayer data from being compromised as this arrangement moves forward.”



In defending its decision, the IRS claimed that Equifax said that none of its data was involved in the data breach.





The IRS defended its decision, saying Equifax has told the agency that none of its data was affected by the breach. The agency also noted that Equifax already provides “similar services” to the agency under a different contract.



"Following an internal review and an on-site visit with Equifax, the IRS believes the service Equifax provided does not pose a risk to IRS data or systems," the statement reads. "At this time, we have seen no indications of tax fraud related to the Equifax breach, but we will continue to closely monitor the situation."



Given that Equifax waited more than a month to disclose the hack to the public – and has bungled seemingly every step in its response to the hack - the fact that the IRS justified its decision by, in effect, saying "they told me everything is fine" is hardly reassuring. As Yahoo demonstrated just last night, the true scope of cyber-security intrusions sometimes takes years to uncover, which is precisely why sticking with Equifax is a risky. Yahoo, of course, revealed yesterday that a 2013 data breach impact all 3 billion of the company’s user accounts – three times the one billion accounts previously reported by the company.


As lawmakers have suggested, when determining which companies should be trusted to safeguard tax payers" most sensitive financial data, the agency should"ve erred on the side of caution.

Wednesday, October 4, 2017

The Largest Hack Ever? Yahoo Admits 2013 Data Breach Impacted All 3 Billion Accounts

Is it too late for Verizon to get some more of its money back?


After the entity responsible for selling Yahoo agreed to cut $350 million off the company’s sales price earlier this year following revelations that hackers had stolen sensitive  account information of as many as 1.5 billion user accounts during two separate data breaches, the Wall Street Journal is now reporting that the scale of one of those intrusions was much larger than initially believed.


A 2013 data breach that was initially believed to have impacted 1 billion, actually impacted all of Yahoo"s 3 billion user accounts, Verizon announced on Tuesday. Verizon’s acquisition of Yahoo formally closed in June after contentious negotiations that were complicated by the discovery of the hacks. The smaller of the two incidents, which took place in 2014, was first disclosed to the public last September. It reportedly involved 500 million user accounts. Three months later, in December, the company publicized the 2013 hack.



The stolen data included names, email addresses, dates of birth, telephone numbers and encrypted passwords, Yahoo has said. In October, before the second breach was even disclosed, Verizon signaled that it would likely consider the data breach to be a “material event”, allowing it to change the terms of its deal to buy Yahoo, which it did in February.


As WSJ pointed out, the disclosure shows that executives are still coming to grips with Yahoo"s myriad security problems.


Even before the number of affected user accounts was revised higher to 3 billion, the breach was still the largest on record by number affected. However, most experts consider the Equifax breach, which involved sensitive financial and personal information like credit card, social security and drivers’ license numbers, more damaging than the Yahoo breach.


A spokesman for Oath, the new name of Verizon’s Yahoo unit, said the company determined last week that the break-in was much worse than thought, after it received new information from outside the company. He declined to elaborate on the source of that information. Compromised customer information included usernames, passwords, and in some cases telephone numbers and dates of birth, the spokesman said.


Fortunately for Yahoo executives, as part of the revised deal, Verizon agreed to forfeit the right to sue Yahoo for allegedly covering up the hacks. Meanwhile, the entity selling Yahoo has retained liability for an SEC investigation that was launched in January, as well as any shareholder lawsuits related to the deal itself.
 

Tuesday, September 26, 2017

Massive Hack At Deloitte: Entire Internal Email System Compromised, Client Emails Exposed

Another day, another major hacking.


The Guardian reports that in the latest corporate cyber breach, one of the world’s “big four” accounting and consultancy firms, Deloitte, was been targeted by a sophisticated hack that "compromised the confidential emails and plans of some of its blue-chip clients." And just like Equifax, New York-headquartered Deloitte was similarly the victim of a cybersecurity attack that went unnoticed for months. The Guardian understands Deloitte discovered the hack in March this year, but it is believed the attackers may have had access to its systems since October or November 2016.


Responding to questions from the Guardian, Deloitte confirmed it had been the victim of a hack but insisted only a small number of its clients had been “impacted”. It would not be drawn on how many of its clients had data made potentially vulnerable by the breach. Alas, the company has yet to provide a full disclosure of just who and which clients were violated: an estimated 5 million emails were in the hacked email cloud and could have been been accessed by the hackers. Deloitte said the number of emails that were at risk was a fraction of this number but declined to elaborate.


While unlike Equifax Deloite is not a public public company and is not accountable to countless shareholders, with $37 billion in revenue last year and over 263,000 worldwide employees, Deloitte is a corporate behemoth which provides auditing, tax consultancy and - like Equifax - high-end cybersecurity advice to some of the world’s biggest banks, multinational companies, media enterprises, pharmaceutical firms and government agencies.  Here the Guardian reports that Deloitte clients "across all of these sectors had material in the company email system that was breached. The companies include household names as well as US government departments."





So far, six of Deloitte’s clients have been told their information was “impacted” by the hack. Deloitte’s internal review into the incident is ongoing.



The hacker compromised the firm’s global email server through an “administrator’s account” that, in theory, gave them privileged, unrestricted “access to all areas”.



Embarrassingly, the administrator level hack required only a single password and did not have “two-step“ verification, much like Deloitte and other companies strongly urge everyone to do.


As the Krebs on Security blog separately notes, "according to a source close to the investigation, the breach dates back to at least the fall of 2016, and involves the compromise of all administrator accounts at the company as well as Deloitte’s entire internal email system"





The source told KrebsOnSecurity they were coming forward with information about the breach because, “I think it’s unfortunate how we have handled this and swept it under the rug. It wasn’t a small amount of emails like reported. They accessed the entire email database and all admin accounts. But we never notified our advisory clients or our cyber intel clients.



This same source said forensic investigators identified several gigabytes of data being exfiltrated to a server in the United Kingdom. The source further said the hackers had free reign in the network for “a long time” and that the company still does not know exactly how much total data was taken.



Penetrating the unknown number of emails involved breaching the Microsoft cloud used the by the company. Emails to and from Deloitte’s 244,000 staff were stored in the Azure cloud service, which was provided by Microsoft. This is Microsoft’s equivalent to Amazon Web Service and Google’s Cloud Platform.


In addition to emails, the Guardian adds the hackers had "potential access to usernames, passwords, IP addresses, architectural diagrams for businesses and health information. Some emails had attachments with sensitive security and design details."


Until today"s report, the hack had been disclosed to the public: the breach, which was US-focused, was regarded as so sensitive that only a handful of Deloitte’s most senior partners and lawyers were informed.





The team investigating the hack is understood to have been working out of the firm’s offices in Rosslyn, Virginia, where analysts have been reviewing potentially compromised documents for six months.



It has yet to establish whether a lone wolf, business rivals or state-sponsored hackers were responsible.



Translation: while Putin wasn"t accused of hacking Equifax, he may yet get the blame this time.


Making this breach even more complicated, it is still unknown what information the hackers acquired: Guardian sources said if the hackers had been unable to cover their tracks, it should be possible to see where they went and what they compromised by regenerating their queries. This kind of reverse-engineering is not foolproof, however.





“In response to a cyber incident, Deloitte implemented its comprehensive security protocol and began an intensive and thorough review including mobilising a team of cybersecurity and confidentiality experts inside and outside of Deloitte,” a spokesman said. “As part of the review, Deloitte has been in contact with the very few clients impacted and notified governmental authorities and regulators.



“The review has enabled us to understand what information was at risk and what the hacker actually did, and demonstrated that no disruption has occurred to client businesses, to Deloitte’s ability to continue to serve clients, or to consumers. We remain deeply committed to ensuring that our cybersecurity defences are best in class, to investing heavily in protecting confidential information and to continually reviewing and enhancing cybersecurity. We will continue to evaluate this matter and take additional steps as required."



“Our review enabled us to determine what the hacker did and what information was at risk as a result. That amount is a very small fraction of the amount that has been suggested.”



Deloitte declined to say which government authorities and regulators it had informed, or when, or whether it had contacted law enforcement agencies.


Of course, as noted above, the breach is a deep embarrassment for Deloitte, which offers clients advice on how to manage the risks posed by sophisticated cybersecurity attacks. If only the company had followed its own advice.  Even more awkward, in 2012 Deloitte was ranked the best cybersecurity consultant in the world and has a “CyberIntelligence Centre” to provide clients with “round-the-clock business focussed operational security." It is unclear if that unit was also hacked.


While we await an official statement from Deloitte, what comes next is lots of lawsuits and even more settlements. According to the Guardian, on 27 April Deloitte hired US law firm Hogan Lovells on “special assignment” to review what it called “a possible cybersecurity incident”. The Washington-based firm has been retained to provide “legal advice and assistance to Deloitte LLP, the Deloitte Central Entities and other Deloitte Entities” about the potential fallout from the hack.

Thursday, September 21, 2017

Equifax Accidentally Directs 200,000 Customers To Fake Phishing Website

And the hits just keep coming for Equifax, the once-trusted credit-monitoring firm that has been embroiled in one of the biggest corporate public-relations disasters in recent memory since disclosing that hackers had penetrated its cyber security defenses and absconded with sensitive personal and financial data belonging to 143 million Americans. Because of the types of data that were stolen, including drivers" license, social security and credit-card numbers, experts have described the hack as possibly the most damaging corporate hack yet.


As if this weren’t enough to permanently sully the firm’s reputation (amid cries of “you had one job!”) – the staggering irony of a credit monitoring firm inadvertently divulging the sensitive information that it was supposed to safeguard hasn’t been lost on consumers) a series of subsequent disclosures have portrayed the firm’s executives as bungling, at best, and nefarious, at worst.


In the nearly two weeks since the story broke…





  • It was revealed that three of the firm’s executives, including its CFO, cashed out of stocks and options worth some $2 million in the month between when the company first learned about the hack, and when it was disclosed to the public. A federal prosecutor in Atlanta has opened a criminal investigation into Equifax that will focus both on whether the firm was criminally negligent in failing to patch a hole in its cybersecurity systems, as well as whether the suspect stock sales constitute securities fraud.

  • The company’s head of cyber security was revealed to have no background in computer science or security – a fact the company tried to hastily cover up by scrubbing her social-media profiles. Susan Mauldin, Equifax’s chief information security officer, has a bachelor’s degree in music composition and a master’s in fine arts from the University of Georgia.

  • Several Congressional committees have asked the company to turn over information relating to the hack as multiple investigations appear to be getting under way. The attorneys general of a handful of states, including Massachusetts and Rhode Island, have joined a probe into the company’s handling of the breach.

  • The company has been hit with dozens of lawsuits from consumers alleging fraud, abuse and negligence.

  • Equifax CEO Rick Smith has been called to testify before a special House panel early next month.


When Equifax first set up a website to allow consumers to check whether their information was compromised, it carried a waiver stating that by using the service consumers would forfeit the right to sue Equifax. The internet quickly exploded in outrage, and the company quickly clarified that the waiver didn’t apply to this hacking incident, which…sure. Now, The Verge, The New York Times and a handful of other media outlets are reporting that Equifax accidentally tweeted the link to an imposter website set up by a white-hat hacker hoping to expose gllaring errors that the firm had made in setting up its verification website. This happened not once, but three times. And in at least one instance, the tweet with the phony link was left up for a whole day.



Here’s The Verge:





“Today, Equifax ended up creating that exact situation on Twitter. In a tweet to a potential victim, the credit bureau linked to securityequifax2017.com, instead of equifaxsecurity2017.com. It was an easy mistake to make, but the result sent the user to a site with no connection to Equifax itself. Equifax deleted the tweet shortly after this article was published, but it remained live for nearly 24 hours.”



Luckily for consumers, the fake site wasn’t malicious. Instead, it was set up by developer Nick Sweeting to try and expose the glaring security vulnerabilities that the company had embedded in its recovery website, which it set up as a separate domain, rather than making it a subdomain of Equifax’s main website.





“Luckily, the alternate URL Equifax sent the victim to isn’t malicious. Full-stack developer Nick Sweeting set up the misspelled phishing site in order to expose vulnerabilities that existed in Equifax"s response page. “I made the site because Equifax made a huge mistake by using a domain that doesn"t have any trust attached to it [as opposed to hosting it on equifax.com],” Sweeting tells The Verge. “It makes it ridiculously easy for scammers to come in and build clones — they can buy up dozens of domains, and typo-squat to get people to type in their info.”



Sweeting says no data will leave his page and that he "removed any risk of leaking data via network requests by redirecting them back to the user"s own computer," so hopefully data entered on his site is relatively safe. Still, Equifax"s team linked out to his page. That isn"t reassuring.”



Prior to Equifax customer service sharing the imposter site, Sweeting says he emailed the company’s support team and tweeted to Equifax that he spotted a potential vulnerability. By the time the site was taken down, Sweeting says it had received more than 200,000 hits. In the spirit of transparency, Sweeting included a disclaimer on his site warning consumers that it was a fake – and blasting Equifax for its sloppy security practices.


According to the NYT, phishers cannot create a page on the equifax.com domain, so if the website were hosted there instead, it would be easy for users to tell that the page was legitimate.





“Fortunately for the people who clicked, Mr. Sweeting’s website was upfront about what it was. The layout was the same as the real version, complete with an identical prompt at the top: “To enroll in complimentary identity theft protection and credit file monitoring, click here.” But a headline in large text differed: “Cybersecurity Incident & Important Consumer Information Which is Totally Fake, Why Did Equifax Use A Domain That’s So Easily Impersonated By Phishing Sites?”



The legitimate Equifax domain was securityequifax2017.com. Sweeting’s was equifaxsecurity2017.com. And as one cybersecurity expert told the NYT, even the legitimate website looks fake because it’s not a subdomain of the larger Equifax site.





“You would think that would be the obvious place to start,” said Rahul Telang, a professor of information systems at Carnegie Mellon University. “Create a subdomain so that if somebody tries to fake it, it becomes immediately obvious.”



The company’s actions, Telang told the NYT, suggest that it had never anticipated or planned for a breach.


This has become clear in the last few weeks. Now, the only thing left to be decided is whether the fact that the company was almost comically unprepared for a hack rises to the level of criminal negligence.

Tuesday, September 19, 2017

More Equifax Lies? Company Originally Hacked Five Months Earlier Than It Disclosed

When Equifax first disclosed the shocking news on September 7 that its servers and some 143 million private account had been hacked, leaking everything from names, to addresses, to social security numbers, it stated in its press release that it had "learned of the incident on July 29, 2017" adding that "at which point it reported the intrusion to law enforcement and contracted a cybersecurity firm to conduct a forensic review: based on the company’s investigation, the unauthorized access occurred from mid-May through July 2017."


As we commented then, it "oddly enough took shareholders and over a third of America, more than a month longer to learn that all their personal data may have been compromised."


And now, according to Bloomberg, it appears the company had lied again as it wasn"t "only one month" but nearly six that the company was aware that its systems had been violated without acting on the information::





Equifax Inc. learned about a major breach of its computer systems in March -- almost five months before the date it has publicly disclosed, according to three people familiar with the situation



While the March breach was reportedly not related to the hack that exposed the personal and financial data on 143 million U.S. consumers, "one of the people said the breaches involve the same intruders. Either way, the revelation that the 118-year-old credit-reporting agency suffered two major incidents in the span of a few months adds to a mounting crisis at the company, which is the subject of multiple investigations and announced the retirement of two of its top security executives on Friday." That one of the top security executives also happened to be a music major who desperately tried to scrub her public background has not helped the company"s case.


Some further details from Bloomberg:





Equifax hired the security firm Mandiant on both occasions and may have believed it had the initial breach under control, only to have to bring the investigators back when it detected suspicious activity again on July 29, two of the people said.



Equifax’s hiring of Mandiant the first time was unrelated to the July 29 incident, the company spokesperson said. Vitor De Souza, senior vice president for global marketing at FireEye Inc., Mandiant’s parent company, declined to comment.



As Bloomberg hedges, "there’s no evidence that the publicly disclosed chronology is inaccurate, but it leaves out a set of key events that began earlier this spring, the people familiar with the probe said."


In any even, while the company"s lawyers are surely looking for just the right explanation to justify sitting on news of cyberbreach for months before it was too late, the revelation of the March hack will complicate the company’s efforts to explain a series of unusual stock sales by Equifax executives.





If it’s shown that those executives did so with the knowledge that either or both breaches could damage the company, they could be vulnerable to charges of insider trading. 



As reported earlier, the U.S. Justice Department has opened a criminal investigation into the stock sales, according to people familiar with the probe. As a reminder, Equifax originally disclosed that it discovered the security breach on July 29, and shortly after - in early August - the three executives sold shares worth almost $1.8 million.


The company has said the managers didn’t know of the breach at the time they sold the shares, although in light of the latest news that appears rather inconceivable.


Insider trading charges aside, there is the question of all those piling lawsuits:





new questions about Equifax’s timeline are also likely to become central to the crush of lawsuits being filed against the Atlanta-based company. Investigators and consumers alike want to know how a trusted custodian of so many Americans’ private data could let hackers gain access to the most important details of financial identity, including social security and driver’s license numbers, and steal credit card numbers.



Meanwhile, far from keeping the original hack a secret, "in early March Equifax began notifying a small number of outsiders and banking customers that it had suffered a breach and was bringing in a security firm to help investigate. The company’s outside counsel, Atlanta-based law firm King & Spalding, first engaged Mandiant at about that time. While it’s not clear how long the Mandiant and Equifax security teams conducted that probe, one person said there are indications it began to wrap up in May."


The revelation of an earlier breach - and one which comes from the press instead of the company itself - will likely raise questions for the company’s executives over whether that investigation was sufficiently thorough or if it was closed too soon, and also why it wasn"t disclosed as part of the Sept. 7 press release.





For example, Equifax has said that the hackers entered the company’s computer banks the second time through a flaw in the company’s web software that was known in March but not patched until the later activity was detected in July.



For now, however, what will get the most
scrutiny in light of the new timeline is the stock sales by company insiders: on Aug. 1 and Aug. 2, regulatory
filings show that three senior Equifax executives sold shares worth
almost $1.8 million, with none of the filings listing the transactions
as being part of scheduled 10b5-1 trading plans.
Equifax’s Chief
Financial Officer John Gamble sold shares worth $946,374; Joseph
Loughran, president of U.S. information solutions, exercised options to
dispose of stock worth $584,099; and Rodolfo Ploder, president of
workforce solutions, sold $250,458 of stock.





Equifax has said the executives “had no knowledge that an intrusion had occurred at the time,” and the company spokesperson declined to make them available for comment.



Now, under the new timeline, the insider sales come several months after the March breach but before the public had any knowledge of major security issues at one of the country’s three big credit-reporting agencies. The new timeline is also likely to focus scrutiny on an earlier sale by Gamble of 14,000 shares on May 23. According to a regulatory filing, which didn’t indicate that the sale was part of a scheduled trading plan, the value of that transaction was $1.91 million, more than twice the size of his Aug. 1 disposal of 6,500 shares for $946,374.


Another question is who is behind the hack, and whether these were two separate incidents, or one organized breach:





If the two hacks are unrelated it could be that different hacking teams had different goals. One clue has emerged that suggests one goal of the attackers was to use Equifax as a way into the computers of major banks, according to a fourth person familiar with the matter.



This person said a large Canadian bank has determined that hackers claiming to sell celebrity profiles from Equifax on the dark web -- information that appears to be fraudulent, or recycled from other breaches -- did in fact steal the username and password for an application programming interface, or API, linking the bank’s back-end servers to Equifax.



According to Bloomberg, the discovery suggests that the attackers may have been trying to piggyback off of Equifax’s connections to large banks and other financial institutions as a backdoor way to hack those entities and gain access to sensitive partner systems. The company spokesperson said Equifax is “working diligently with our bank partners to assess and mitigate any impact to their operations.”


Equifax has yet to disclose that March breach to the public.

Monday, September 18, 2017

The Equifax Hack Is The Most Disastrous Data Breach In History Because Now Hackers Have The Credit Information Of 143 Million Americans

This report was originally published by Michael Snyder at The Economic Collapse


hack


Talk about a nightmare. It is being reported that criminals were able to hack into Equifax and make off with the credit information of 143 million Americans. We are talking about names, Social Security numbers, dates of birth, home addresses and even driver’s license numbers. If this data breach was an earthquake, we would be talking about a magnitude-10.0 on the identity theft scale. We have never seen anything like this before, and to say that this will be “disastrous” for the credit industry would be a massive understatement.


What really disturbed me about this story is that this hack reportedly occurred between “mid-May and July of this year”



Credit monitoring company Equifax has been hit by a high-tech heist that exposed the Social Security numbers and other sensitive information about 143 million Americans. Now the unwitting victims have to worry about the threat of having their identities stolen.


The Atlanta-based company, one of three major U.S. credit bureaus, said Thursday that “criminals” exploited a U.S. website application to access files between mid-May and July of this year.



So why didn’t we learn about this until September?


Somebody out there really needs to answer that question for us.


And even though the “143 million” number is being thrown around constantly, according to USA Today we may never know the true number of victims…



When asked if there’s a way to quantify how many people have been harmed, John Ulzheimer, a credit expert and former employee at Equifax and credit score firm FICO, said: “There’s no way to know, and there may never be a way to know.”



Personally, I don’t see how Equifax can possibly survive after this. Their stock price is already crashing, and now it has come out that they had put a “music major” in charge of data security…



When Congress hauls in Equifax CEO Richard Smith to grill him, it can start by asking why he put someone with degrees in music in charge of the company’s data security.


And then they might also ask him if anyone at the company has been involved in efforts to cover up Susan Mauldin’s lack of educational qualifications since the data breach became public.


It would be fascinating to hear Smith try to explain both of those extraordinary items.



Also, we are now finding out that Equifax has not just had security problems here in the United States.


According to the New York Post, data breaches have been taking place all over the globe…



Hackers had access to the names, dates of birth and e-mail addresses of nearly 400,000 people in the United Kingdom, said Equifax’s British subsidiary in a statement last week.


In Canada, sensitive data belonging to 10,000 consumers may have been hacked in the breach, said a statement from the Canadian Automobile Association.


In Argentina, one of the company’s portals was so easily accessible that it allowed quick exposure to the personal information of more than 14,000 people.



As noted above, the public didn’t learn about any of this until September.


But once top Equifax officials learned what had happened, some of them started dumping their shares of Equifax very rapidly



Three Equifax executives — not the ones who are departing — sold shares worth a combined $1.8 million just a few days after the company discovered the breach, according to documents filed with securities regulators.


Equifax shares have lost a third of their value since it announced the breach.



Needless to say, the SEC is going to be looking into this very closely.


As we move forward, there is a tremendous amount of concern as to how much this data breach will affect the U.S. economy.


Only time will tell, but without a doubt it will have an impact. For example, according to Bloomberg this data breach could potentially have an absolutely disastrous impact on store-branded credit cards…



Equifax Inc.’s massive data breach could make an already tough market outlook even more daunting for the firms behind Gap Inc.’s and Ann Taylor’s store-branded credit cards.


Those retailers’ banking partners, including Synchrony Financial and Alliance Data Systems Corp., could see fewer account originations as more consumers freeze their credit to avoid hack-related fraud. Consumers have to take extra steps — including calling the credit bureau, going online or paying fees — to lift a block and get a new card.


“If people are defaulting to credit freezes, then if you’re a Macy’s retailer trying to sell credit cards, you can’t get that done at the point of sale,” said Vincent Caintic, an analyst at Stephens Inc. “It could become a regular thing, these freezes. It does slow down the origination process and it’s probably going to increase acquisition costs.”



If you believe that your data may have been compromised in this breach, there are some things that you can do right away to help protect against identity theft. You can sign up for 24 hour a day credit monitoring, you can request fraud alerts, you can enable “two factor authentication” and beyond all of that you could go as far as to freeze your credit.


But if everybody in America suddenly started freezing their credit, that would slow down economic activity dramatically. So needless to say authorities are hoping that does not happen.


In this case, Equifax needs to step up and do the right thing. They need to inform all of the victims (even if that means reaching out to 143 million different people), and they should automatically provide free credit monitoring for all of those that were affected.


I seriously doubt that Equifax will take these measures, and I also seriously doubt that Equifax will be able to survive much longer.


When you bungle something as badly as Equifax has done, it is nearly impossible to restore faith in an organization. The credit information of 143 million Americans is now in the hands of criminals, and the potential damage that could be done is absolutely off the charts.

Muddy Waters' Carson Block Sues Equifax For $500,000

Disgraced credit-monitoring company Equifax, which has seen its stock drop by nearly 40% since disclosing what will likely be remembered as one of the most damaging data breaches in US history, eliciting dozens of class-action lawsuits, calls for investigations by at least one state attorney general, and requests from multiple Congressional committees for more information about the exact timeline of when Equifax learned about the hack, and when it was disclosed – because somewhere between those two events, several of the company’s executives, including its CFO, cashed out of some $2 million in stock and options.



In the latest humiliating blow to a company that failed at its only job – safeguarding Americans’ sensitive personal and financial data – famed short-seller Carson Block has announced that he has decided to sue the company over its “abysmal” handling of the hack.


And here’s the kicker: He doesn’t even have an open short position against the company. In other words: There’s no profit motive here. Block – like millions of Americans - is just really, really pissed.


Here’s the Financial Times:





“Veteran short-seller Carson Block has launched a private lawsuit against Equifax, accusing the credit-reporting company of an “abysmal” handling of one of the worst cyber security incidents in history. Equifax said on September 7 that its systems were breached by criminals in a raid that went on for more than two months — an admission that has prompted a flood of regulatory inquiries, dozens of private lawsuits and a more than one-third collapse in the company’s share price. The data of up to 143m Americans was compromised, the company said, along with up to 400,000 people in the UK.



One of those was Mr Block, whose suit filed on Friday accuses Equifax of negligence in failing to safeguard and protect his personal identifying information from criminals, as well as a failure to disclose the breach in a timely fashion.”


Apparently, Block has learned that his personal information was compromised in the hack because he’s suing for personal damages. He has also accused the company of failing to disclose the breach in a timely fashion. The company’s CEO, Rick Smith, who is expected to deliver Congressional testimony early next month, has said that the company at first believed the hack was relatively minor."



According to the FT, the famed short sellers is seeking $500,000 in damages, a paltry sum considering Muddy Waters reportedly produced double-digit returns last year.





“Mr Block’s firm, Muddy Waters, has no short position that would benefit from a fall in the stock. In the suit, filed in the Northern District of California, San Francisco division, he seeks damages of at least $500,000 for the “stress, nuisance and annoyance” of dealing with issues stemming from the breach.



The suit notes that Equifax’s business revolves around being a “secure storehouse” for data and providing a clear financial profile of consumers that lenders and other businesses can rely on. According to its own description, Equifax organises, assimilates and analyses data on more than 820m consumers and more than 91m businesses worldwide.



Equifax could not be reached for comment at the time of publication.”



As the FT explains, hackers gained access to the company’s systems by exploiting a vulnerability in Apache Struts, a popular open-source framework for developing web applications in the Java programming language. On Friday, Equifax said that it had patched the hole on July 30, one day after it had detected strange activity on its servers. But cybersecurity experts note that the fix had been available since March, when the Apache Foundation put out an update which had been widely disseminated in tech circles. In short, the company’s cybersecurity experts committed an unforced error by neglecting to invest the meager resources required to patch the fix.



Amid the firestorm of controversy that has engulfed the company in the aftermath of the hacking disclosure, Equifax has actively tried to cover up the fact that Susan Mauldin, Equifax’s chief information security officer, and the person who was responsible for keeping the highly confidential and secret information of over 100 million Americans, has zero security or technology credentials…in fact, she was a music major at the University of Georgia.


Smith, Mauldin and nine other executives are named in Block’s lawsuit.  Mauldin, Equifax said, would retire immediately from the company on Friday, along with David Webb, chief information officer.


According to the suit, Equifax should’ve been more careful following two big breaches in 2016. In one of those, 430,000 names and other vital pieces of information were lost as a result of the company using “alarmingly poor” security for the generation of PINs from the last four digits of a social-security number and the four-digit year of birth.


Of course, with North Dakota Democrat Heidi Heitkamp calling for a criminal investigation into securities fraud, Block’s lawsuit for a meager half a million is probably the least of the company’s worries…
 

Sunday, September 17, 2017

Here's What Your Identity Sells For On The Dark Web

Millions of Americans who trusted Equifax with sensitive personal and financial data, including social security numbers and credit-card information, are now nervously wondering whether they will be among the unlucky minority of affected customers whose identities are successfully “repurposed” by online criminal groups.


One researcher from security firm SecureWorks shared some details about today’s burgeoning marketplace for stolen data with Bloomberg, and the conclusion is clear: It is now easier – and cheaper – for criminals to access and abuse illicit data than ever before. In fact, a high-limit American express card with a high chance of working can be purchased online for less than $20. Criminals can buy files with thousands of low-limit card numbers for pennies on the dollar.


According to Bloomberg, “verified” high-limit credit cards from developed countries like the US, Japan, and South Korea are selling on the dark web for the bitcoin equivalent of about $10 to $20.



“Verified” means the seller has tested out transactions on the card and found it hasn’t been canceled yet. For scammers on a budget, there’s unverified stolen credit card data, which comes out to pennies a card when bought in bulk.


Here’s a screengrab from one dark-web marketplace.



Luckily for criminals, cards generally aren’t selling any cheaper on the dark web these days, said Alex Tilley, a researcher at Secureworks. Today’s buyers are more likely to get higher-quality cards, ones with sizable limits that can be used fraudulently with ease. It isn’t as hit-or-miss as it used to be, a welcome change for criminals, chilling news for most of us.


Criminals have even set up sophisticated “rating systems” to help value the data. Business cards are preferred, Tilley said, because they don’t have a limit. Those and high-end personal cards—say, a Platinum American Express that has been verified and has an 85 percent rating (judged by the seller to have an 85 percent chance of being successfully used in a fraud)—will go for $15 to $20. A regular Mastercard that doesn’t have a high limit might go for $9.



One underground hacker market inexplicably called Trump’s Dumps is selling full identities of individuals just like you for as little as $10 apiece. They’re called fullz, “dossiers that provide enough financial, geographic and biographical information on a victim to facilitate identity theft or other impersonation-based fraud.” Fullz can help a criminal get past those irritating “secret questions” that sites ask to verify your identity.


Recently, Secureworks’ researchers have seen more offers of bulk pre-verified card details, along with more identifying information about the owners. In some cases, offers even include the cardholder’s mother’s maiden name. Still, they cost just $10 to $12. Below is a fullz offer with a lot of personal identification on a Korean consumer.


In a massive breach like Equifax, hackers can easily walk away with hundreds of millions of dollars in profits from selling the data. Meanwhile, the identity thieves who purchased it can reap their own fortune running their scams.


Congress, the FTC and Equifax customers – enraged by both the company’s reluctance to initially disclose the breach and its carelessness (some would say tight-fistedness) concerning its cybersecurity defenses – have buried the company in lawsuits and official inquiries.


As USA Today revealed yesterday, hackers took advantage of an Equifax security vulnerability two months after an industry group discovered the coding flaw and shared a fix for it, raising questions about why Equifax didn"t update its software successfully when the danger became known.


We’re looking forward to hearing the whole story from CEO Rick Smith when he testifies before Congress early next month. Whether Smith manages to hang on to his job remains to be seen - calls for his resignation after a 12-year-long scandal-free tenure are mounting. CNBC"s Jim Cramer said last night that Smith "should be fired today."


But perhaps more worrying for Smith and his C-Suite companions are calls from North Dakota Sen. Heidi Heitkamp, who has demanded a criminal investigation into whether the company"s executives - several of whom sold stock during the period between when the company first learned about the hack and when it disclosed it to the public - commited securities fraud.


"If that happened, then somebody needs to go to jail," she said.

Friday, September 8, 2017

Equifax Hit With $70 Billion Lawsuit After Leaking 143 Million Social Security Numbers

One day after Equifax announced (more than one month after it itself had learned) that its systems had been hacked, resulting in up to 143 million social security numbers, names, addresses, driver’s license data, birth dates, some credit card numbers and pretty much all other critical personal data being leaked and currently for sale somewhere on the dark web, the company whose job is, ironically, to protect the credit and personal information of hundreds of millions of Americans has been hit with a monster class-action lawsuit seeking as much as $70 billion.


In retrospect, we find it surprising that it wasn"t multi-trillion lawsuit in light of the galactic stupidity exhibited by a company whose server apparently had zero firewalls from the internet and where any hacker could get access to the most confidential information available.


And while for the most part class action lawsuits are filed by ambulance-chasing lawyers seeking a recovery for a class of plaintiffs in exchange for a juicy 25-40% of the final amount, in this case In the complaint filed in Portland, Ore., federal court has every single merit to ultimately crush Equifax for what is nothing less than unprecedented carelessness in handling precious information.


In the lawsuit, plaintiffs alleged Equifax was negligent in failing to protect consumer data, choosing to save money instead of spending on technical safeguards that could have stopped the attack, Bloomberg reports. Imagine how much angrier they would be if they found that instead of "saving" the money, the company used it instead to buy back its own stock (in this case from selling executives).





“In an attempt to increase profits, Equifax negligently failed to maintain adequate technological safeguards to protect Ms. McHill and Mr. Reinhard’s information from unauthorized access by hackers,” the complaint stated. “Equifax knew and should have known that failure to maintain adequate technological safeguards would eventually result in a massive data breach. Equifax could have and should have substantially increased the amount of money it spent to protect against cyber-attacks but chose not to.” 



The plaintiffs in the lawsuit are Mary McHill and Brook Reinhard. Both reside in Oregon and had their personal information stored by Equifax. Tens of millions more will join the lawsuit shortly once they realize their data has similarly been hacked. Readers can find out if they have been affacted by the leak at the following site.


According to Bloomberg, the case was filed by the firm Olsen Daines PC along with Geragos & Geragos, a celebrity law firm known for blockbuster class actions. Ben Meiselas, an attorney for Geragos, said the class will seek as much as $70 billion in damages nationally.


Finally, as one social media commentator put it, "In retrospect it seems like a really dumb idea to give three random companies access to the entire financial records of every American."

Massive Data Breach At Equifax: As Many As 143 Million Social Security Numbers Hacked

Credit-reporting company Equifax shocked investors, and more than a third of America, when it announced on Thursday afternoon that hackers had breached its data systems, compromising the personal information of approximately 143 million U.S. consumers. The information accessed "primarily includes names, Social Security numbers, birth dates, addresses and, in some instances, driver’s license numbers." In other words, pretty much everything that should have been hidden behind an n-number of firewalls, is now available to the dark net"s highest bidder. 


The company, which in delightful irony offers credit-monitoring and identity-theft protection products to "guard consumers’ personal information", said that it had learned of the incident on July 29, 2017, at which point it reported the intrusion to law enforcement and contracted a cybersecurity firm to conduct a forensic review: based on the company’s investigation, the unauthorized access occurred from mid-May through July 2017. Oddly enough, it took shareholders and over a third of America, more than a month longer to learn that all their personal data may have been compromised.


As if 143 million leaked social security numbers wasn"t enough, Equifax said that criminals also accessed credit card numbers for approximately 209,000 U.S. consumers, and certain dispute documents with personal identifying information for approximately 182,000 U.S. consumers. But wait, there"s more: the company also identified unauthorized access to limited personal information for certain UK and Canadian residents.


The good news, is that according to Equifax, "this issue has been contained." The bad news is that, well, as many as 143 million social security numbers have been hacked. So no, it"s not contained.


“This is clearly a disappointing event for our company, and one that strikes at the heart of who we are and what we do,” Equifax Chief Executive Richard Smith said in prepared remarks. “I apologize to consumers and our business customers for the concern and frustration this causes.”


In a Q&A posted on the company"s website, the management team revealed what"s really important with the following question and answer:





Does this cybersecurity incident impact your capital allocation priorities going forward?



Our capital allocation priorities are unchanged at this time. As we have previously indicated, our investment
priorities in order of importance are: (1) internal investment; (2) dividends; (3) acquisition; and (4) share
repurchase. We do, however, expect to increase our capital spending in an effort to further accelerate IT
infrastructure, systems and data security and resiliency improvement actions
.



Oh, good, because a hack involving 143 million SSNs is one of those cases where capex probably should have taken precedence over stock buybacks.  Don"t worry though, because as it explains in the same quesionnaire, "Equifax remains committed to delivering on the long term financial model of 7-10% revenue growth and 11%- 14% growth in Adjusted EPS on average over a business cycle. Equifax’s long term financial model reflects our continuing fundamental ability to utilize our unique and differentiated data assets and leading analytical capability to deliver high value products and services to our customers."


Uhm, after this... what customers?


After falling as much as 12% in the after hours, EFX stock stabilized... then fell as much as 19%.



And now the best news: with Putin clearly behind this hack - as "all 17 intelligence agencies", WaPo and NYT will shortly "confirm" - the US economy is about to undergo a renaissance as hundreds of millions of (unsolicited) purchases prompt a golden age for US retailers while sending Amazon market cap into the $1 trillions...  even if the shipping address for said purchases happen to be small, frigid villages deep in the Russian taiga.


Full statement from Equifax here.


Update:


In appears there was a reason why EFX decided to hold on to the hacking news a little longer than seems reasonable. As Bloomberg reports, "three Equifax Inc. senior executives sold shares worth almost $1.8 million in the days after the company discovered a security breach that may have compromised information on about 143 million U.S. consumers."





The credit-reporting service said late Thursday in a statement that it discovered the intrusion on July 29. Regulatory filings show that three days later, Chief Financial Officer John Gamble sold shares worth $946,374 and Joseph Loughran, president of U.S. information solutions, exercised options to dispose of stock worth $584,099. Rodolfo Ploder, president of workforce solutions, sold $250,458 of stock on Aug. 2. None of the filings lists the transactions as being part of 10b5-1 pre-scheduled trading plans.



Surely, it was all purely a coincidence, even though had they waited until today, their proceeds would be well over 10% lower...