Equifax’s breach shows why it’s so important to patch systems on time and renew security certificates. One missed update can expose millions of people’s data.
Sensitive data such as passwords and credit cards details should be hashed not saved with plain texts
Day 8/31 One Patch Missed, Millions Exposed (Equifax, 2017)
In 2017, one of the largest credit reporting agencies in the world, Equifax became the stage for one of the most significant cyber incidents in history.
The attackers gained initial access to Equifax’s network by exploiting the CVE-2017-5638 vulnerability in the company’s online dispute portal, which relied on the Apache Struts framework.
A few months later, the attackers moved laterally to other servers within the network due to a lack of proper network segmentation. Once on additional machines, they discovered plaintext credentials, which allowed them to access even more systems.
Although Equifax had network monitoring tools designed to decrypt, inspect, and re-encrypt traffic, these tools failed to detect the breach because a TLS certificate had expired.
As a result, the breach exposed sensitive personal information of approximately 147.9 million Americans, along with tens of thousands of residents in Canada and the United Kingdom.
Community Challenge:
What lessons can other organizations learn from Equifax’s failure to patch the vulnerability?