Case 181C95 · Famous breaches · L2 Practitioner
Equifax 2017
Practise as: Explain it · Interview · Deep dive
Interview questionWhat went wrong at Equifax in 2017, and what is the main lesson?
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- Attackers exploited Apache Struts CVE-2017-5638 in the ACIS dispute portal; a patch had existed since March 2017
- Unpatched for about two months; intruders were inside from mid-May to late July 2017
- Data on about 147 million people exposed: names, SSNs, birth dates, addresses, some licence numbers
- An expired SSL cert on a traffic inspection device blinded monitoring for 19 months; renewing it revealed the attack
- Lessons: asset inventory and patch SLAs, segmentation, and monitoring your monitoring; settlement up to $700M
If the interviewer pushes back
- Equifax's scanner missed the vulnerable app. What does that say about relying on vulnerability scanning alone?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.