CYSE 300 Research Project Related to Introduction to Cybersecurity

Artifact #7

About 148 million Americans’ personal information was compromised in a devastating 2017 data breach at Equifax, one of the three largest credit reporting companies in the US. Because of its scope, the sensitivity of the compromised data, and the mistakes that made it possible, this breach remains among the most catastrophic cybersecurity events in history. By analyzing the Equifax incident’s vulnerabilities, dangers, and consequences, it becomes clear how avoidable it was and how better cybersecurity procedures may have lessened its effects. 

The Apache Struts web application framework issue, known as “CVE-2017-5638”, was the main vulnerability that caused the intrusion. On March 7, 2017, a fix was made available to address this issue, but Equifax did not implement it right away. (2019, CSO Online). This patch management error gave attackers a crucial window of opportunity. Equifax had systemic flaws in addition to the unpatched software, such as inadequate internal asset tracking, shoddy encryption procedures that exposed private information in plaintext, and the usage of default or weak credentials in certain systems (Wired, 2020). These weaknesses combined to create a situation where a single exploited weakness may trigger a national emergency.

By exploiting remote code execution to take advantage of the Apache Struts vulnerability, attackers were able to access Equifax’s internal systems without authorization. In order to evade detection, they then proceeded laterally across the network, took out private credentials, and exfiltrated data in tiny, encrypted packets (U.S. House Oversight Committee, 2018). The attackers had plenty of time to compromise extremely important data because the hack remained undiscovered for 76 days. The incident was linked to state-sponsored cyber operations when the U.S. Department of Justice indicted four members of China’s People’s Liberation Army in February 2020 (Wired, 2020)..

The incident had serious and lasting consequences. Names, Social Security numbers, birth dates, residences, and driver’s license numbers were among the private information that was made public. In the immediate aftermath of the incident, Equifax’s stock value fell sharply, and public confidence in credit reporting organizations was damaged. There were also significant legal and financial repercussions: Equifax consented to a settlement with the Federal Trade Commission, the Consumer Financial Protection Bureau, and 50 states and territories in the United States worth up to $700 million (Federal Trade Commission, 2019). A number of executives also quit or were fired, including the CEO, chief information officer, and chief security officer of the business.

The hack may have been avoided or lessened by a number of cybersecurity measures. First, the Apache Struts vulnerability would have been fixed before it was exploited if patch management and vulnerability screening had been done on time. Second, the utility of stolen data would have been decreased by removing the unencrypted storage of credentials and encrypting sensitive data while it was at rest. Third, it would have been more difficult for attackers to escalate privileges after they were inside the network if multi-factor authentication and other better authentication procedures had been in place. Improved monitoring systems and network segmentation may have reduced lateral movement and raised the likelihood of early detection. Lastly, the length and severity of the breach might have been decreased by creating a strong incident response plan and encouraging a security accountability culture at all organizational levels.

To sum up, the 2017 Equifax hack demonstrates how ignoring fundamental cybersecurity procedures can have disastrous effects on people, businesses, and national security. The incident emphasizes the significance of proactive monitoring, encryption, access constraints, and prompt patch management. Organizations can obtain important insights to improve their defenses against future cyberthreats by analyzing the vulnerabilities, risks, consequences, and preventive measures. 

REFERENCES

CSO Online. (2019, July 22). Equifax data breach FAQ: What happened, who was affected, what was the impact? Retrieved from https://www.csoonline.com/article/567833/equifax-data-breach-faq-what-happened-who-was-affected-what-was-the-impact.html

Federal Trade Commission. (2019, July 22). Equifax to pay $575 million as part of settlement with FTC, CFPB, and states related to 2017 data breach. Retrieved from https://www.ftc.gov/news-events/news/press-releases/2019/07/equifax-pay-575-million-part-settlement-ftc-cfpb-states-related-2017-data-breach

U.S. House Committee on Oversight and Government Reform. (2018, December). The Equifax data breach. Retrieved from https://oversight.house.gov/wp-content/uploads/2018/12/Equifax-Report.pdf

Wired. (2020, February 10). US charges Chinese military officers in 2017 Equifax hack. Retrieved from https://www.wired.com/story/equifax-hack-china