Data leak
CSO Online / Wikipedia / Apache Software Foundation
Primary Source βIncident Details
Apache disclosed CVE-2017-5638 March 7 2017 and patched same day. Equifax security scans failed to identify the vulnerable system. Attackers exploited Apache Struts flaw in Equifax’s online dispute portal starting March 10. Exfiltrated ~147.9 million Americans’ SSNs, DOBs, addresses, driver’s license numbers, and ~200K credit card numbers from May-July 2017. Detected July 29 2017. No encryption for data at rest. $700M FTC/state settlement. Total cost ~$1.38B. Chinese military (PLA Unit 54891) indicted in 2020.
Technical Details
- Initial Attack Vector
- CWE-20: Improper Input Validation / Apache Struts OGNL injection
- Vendor / Product
- Equifax online dispute portal
- Software Package
Apache Struts- CVE / GHSA References
- CVE-2017-5638
Timeline
- 2017-03-10 Breach occurred
- 2017-09-07 Publicly disclosed
- 2017-09-08 Customers notified