Open cardosec

Case 181C95 · Famous breaches · L2 Practitioner

Equifax 2017

Practise as: Explain it · Interview · Deep dive

Interview questionWhat went wrong at Equifax in 2017, and what is the main lesson?

  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Attackers exploited Apache Struts CVE-2017-5638 in the ACIS dispute portal; a patch had existed since March 2017
  2. Unpatched for about two months; intruders were inside from mid-May to late July 2017
  3. Data on about 147 million people exposed: names, SSNs, birth dates, addresses, some licence numbers
  4. An expired SSL cert on a traffic inspection device blinded monitoring for 19 months; renewing it revealed the attack
  5. Lessons: asset inventory and patch SLAs, segmentation, and monitoring your monitoring; settlement up to $700M

If the interviewer pushes back

  • Equifax's scanner missed the vulnerable app. What does that say about relying on vulnerability scanning alone?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.