Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Cybersecurity
    • Cybersecurity

    Equifax Data Breach Fallout Continues as Lawsuits Are Filed

    Written by

    Sean Michael Kerner
    Published September 8, 2017
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      The impact of the breach at credit reporting and monitoring agency Equifax will likely be felt for months and years to come, as the full scope of the security incident is uncovered. Equifax publicly disclosed on Sept. 7 that attackers gained unauthorized access to it systems, exposing personally identifiable information on 143 million American consumers. The breach has also led to multiple legal actions, including at least one class-action lawsuit.

      At this point in the investigation, Equifax has not publicly disclosed the root cause of the data breach. The only insight the company has provided is that the attackers were able to exploit a U.S. website application vulnerability to gain access to certain files.

      While web application vulnerabilities can be found by internal corporate security teams, third-party security researchers are also capable of discovering flaws. There is a challenge, however, in that not all organizations make it easy for security researchers to responsibly disclose vulnerabilities.

      “We looked at Equifax’s website and found no easy way for hackers to disclose anything,” HackerOne CEO Marten Mickos wrote in an email statement sent to eWEEK. HackerOne is in the business of running managed bug bounty programs for organizations.

      Mickos noted that several Equifax bugs have been disclosed via the Open Bug Bounty, which is a nonprofit project designed to connect hackers with website owners to resolve bugs in a transparent and open manner. 

      “One of [the bugs] was disclosed for their UK website and took nearly five months to resolve and the second is for the U.S. website, which has yet to be resolved,” he said.

      It is unknown if the unresolved bug that was reported to the Open Bug Bounty is related to the Equifax breach.

      Identity Theft Protection

      As part of its breach response, Equifax is providing free identity and credit monitoring to impacted consumers via its own TrustedID service. However, on both Sept. 7 and 8, there were widespread reports that consumers were unable to access the identity protection enrollment site.

      Aside from the likely high volume of traffic, the site (EquifaxSecurity2017.com) was temporarily blocked by Cisco’s OpenDNS web filtering service. In a Twitter post, OpenDNS founder David Ulevitch confirmed that the Equifax site initially triggered the criteria for identifying a site that is potentially malicious, including volume of traffic spiking from zero and the fact that it was a new domain.

      For those who have been able to reach the identity protection enrollment site, there have been multiple reports of concerns about the legal terms of use. As part of the enrollment terms for TrustedID, consumers must waive their rights to sue Equifax or participate in any class-action lawsuit against Equifax.

      At least one class-action lawsuit has already been filed against Equifax over the data breach incident.

      “Plaintiffs file this complaint as a national class action on behalf of over 140 million consumers across the Country harmed by Equifax’s failure to adequately protect their credit and personal information,” the class-action suit filed in Oregon federal court on Sept. 7 states.

      Investors

      Equifax consumers aren’t the only ones taking legal action, as investors are also now looking at potential wrongdoing by the company as well. Multiple executive officers of Equifax allegedly sold Equifax stock days after the company first became aware of the breach on July 29. Corporate litigation firm Bronstein, Gewirtz & Grossman stated in a press release that it’s investigating whether there was a violation of U.S. securities law.

      “The investigation concerns whether Equifax and certain of its officers and/or directors have violated Sections 10(b) and 20(a) of the Securities Exchange Act of 1934,” the company stated.

      Following the Equifax data breach disclosure on Sept. 7, Equifax stock has declined by at least 13 percent as of 1 p.m. ET on Sept. 8.

      Sean Michael Kerner is a senior editor at eWEEK and InternetNews.com. Follow him on Twitter @TechJournalist.

      Sean Michael Kerner
      Sean Michael Kerner
      Sean Michael Kerner is an Internet consultant, strategist, and writer for several leading IT business web sites.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.