Equifax and the Latest Round of Identity Theft Roulette Flashcards
What data was leaked in the Equifax breach?
The personal data on 145 million people
What was the nature of the vulnerability?
Resulted from a known vulnerability in the Apache Struts server software
What was the specific attack vector?
Execute commands via the #cmd in content-type HTTP headers
According to Forbes Magazine, what penalties did the CEO of Equifax receive from the Board of Directors?
63 cents for every customer whose data was potentially exposed
To what extent was information about the Struts vulnerability known before the attack?
To the full extent. They knew of the vulnerability
Was Equifax aware that a patch was available for the Struts vulnerability? If so, how much time did they delay in applying the patch?
Yes. For 3 months
What was the educational and training background of the Equifax CIO?
Music major
What was the education and training background of the Equifax CISO?
Music composition
Describe the “too big to fail era”?
When the accused institution is so large that its failure might damage the economy
Are credit reporting companies held liable for PII data loss?
No