Data leak

CSO Online / Wikipedia / Apache Software Foundation

πŸ“… 2017-03-10 🏒 Equifax online dispute portal πŸ”Ž CVE-2017-5638
Primary Source β†—

Incident Details

Apache disclosed CVE-2017-5638 March 7 2017 and patched same day. Equifax security scans failed to identify the vulnerable system. Attackers exploited Apache Struts flaw in Equifax’s online dispute portal starting March 10. Exfiltrated ~147.9 million Americans’ SSNs, DOBs, addresses, driver’s license numbers, and ~200K credit card numbers from May-July 2017. Detected July 29 2017. No encryption for data at rest. $700M FTC/state settlement. Total cost ~$1.38B. Chinese military (PLA Unit 54891) indicted in 2020.

Technical Details

Initial Attack Vector
CWE-20: Improper Input Validation / Apache Struts OGNL injection
Vendor / Product
Equifax online dispute portal
Software Package
Apache Struts
CVE / GHSA References
CVE-2017-5638

Timeline

  1. 2017-03-10 Breach occurred
  2. 2017-09-07 Publicly disclosed
  3. 2017-09-08 Customers notified