In wake of Equifax breach, government shines light on entire industry
Full article684 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
While law enforcement agents were sent to immediately investigate how and why hackers broke into Equifax, other federal agencies, like the Homeland Security Department, were focusing on understanding the threat posed to the larger industry, a senior U.S. official said.
Government agencies have contacted Equifax’s largest competitors to learn more about the potential for cyberattacks on the credit monitory industry as a whole, a senior federal official told CyberScoop.
The recently revealed breach at Equifax — one of three multinational corporations that rely on comparable software to manage consumers’ credit reports and other highly sensitive records — caused upwards of 143 million records to be compromised and drew immediate attention by federal law enforcement.
But other federal agencies, like the Department of Homeland Security, have been focusing on understanding the threat posed to the larger industry, according to the senior federal official, who spoke to CyberScoop on condition of anonymity to discuss an ongoing government investigation.
The official said that because Equifax’s biggest competitors — namely TransUnion and Experian — also rely on software like Apache Struts, a popular web server application, the outreach was necessary in order to learn more about the industry’s overall vulnerability.
CyberScoop first reported that an outdated, unpatched Apache Struts vulnerability allowed for hackers to break into Equifax over the summer — a fact that was later publicly confirmed by Equifax.
“Because they all sort of use these same programs, we needed to contact them too,” the official told CyberScoop. “It’s necessary.”
Security researcher Kevin Beaumont found that both Experian and TransUnion relied on Apache Struts. It’s not clear, however, if or when Experian or TransUnion updated their existing systems that may have been running older versions of the software. Little is known about how the broader industry has reacted — from a security perspective — to the historic breach of Equifax.
Requests for comment sent to TransUnion and Experian regarding their communications with government officials went unanswered.
More Scoops
CFPB proposes new rule to regulate expansive data broker industry
The rule would force data brokers to adhere to the same standards as established credit agencies.
CFPB’s proposed data rules would improve security, privacy and competition
Personal data from T-Mobile breach still spreading on dark web, state governments warn
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/equifax-breach-industry-transunion-experian/