{"id":17282,"date":"2017-10-02T12:56:52","date_gmt":"2017-10-02T08:56:52","guid":{"rendered":"http:\/\/www.intelligentcio.com\/eu\/?p=17282"},"modified":"2017-10-02T12:56:52","modified_gmt":"2017-10-02T08:56:52","slug":"equifax-breach-the-impact-for-enterprises-and-consumers","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/eu\/2017\/10\/02\/equifax-breach-the-impact-for-enterprises-and-consumers\/","title":{"rendered":"Equifax breach: The impact for enterprises and consumers"},"content":{"rendered":"<p>Article by: Rick Holland, VP Strategy at Digital Shadows<\/p>\n<p><strong>WHAT WE KNOW ABOUT THE EQUIFAX BREACH<\/strong><br \/>\nOn September 7th, credit reporting agency Equifax announced \u201ca cybersecurity incident potentially impacting approximately 143 million U.S. consumers.\u201d To put this in context, at this time, this incident is almost seven times larger than the Office of Personnel Management breach of 2015. Equifax discovered the unauthorised access on July 29th and determined that the intrusion began in mid-May. Equifax stated that \u201cthe information accessed primarily includes names, Social Security Numbers (SSNs), birth dates, addresses and, in some instances, driver\u2019s license numbers. In addition, credit card numbers for approximately 209,000 U.S. consumers, and certain dispute documents with personal identifying information for approximately 182,000 U.S. consumers, were accessed.\u201d In addition, the \u201climited personal information\u201d for Canadian and United Kingdom citizens was all accessed. The initial attack vector was reported as a \u201cweb application vulnerability.\u201d<\/p>\n<p><strong>WHAT WE DON\u2019T KNOW ABOUT THE EQUIFAX BREACH<\/strong><br \/>\nWhenever doing any sort of analysis, it is important to state what we don\u2019t know. Simply put, there is a great deal we don\u2019t know and most of the public will never know (despite what some talking heads might claim). As a former incident responder, I know that investigations aren\u2019t completed in the time it takes to complete an episode of TV drama Scorpion. (Did you know that Scorpion is starting its fourth season?) Equifax stated that the investigation is \u201csubstantially complete,\u201d but wisely added that \u201cit remains ongoing and is expected to be completed in the coming weeks.\u201d<br \/>\n\u2022 We don\u2019t actually know how many SSNs were compromised.<br \/>\n\u2022 We don\u2019t know if all 143 million individual\u2019s SSNs were impacted.<br \/>\n\u2022 We don\u2019t know the threat actor responsible for this intrusion. Equifax claimed that \u201ccriminals exploited\u201d a web application, but attribution is always a challenge. Structured Analytic Techniques, like the Analysis of Competing Hypothesis we did for WannaCry, can be useful for considering attribution.<br \/>\n\u2022 Speaking of web applications, although we don\u2019t know the specific vulnerability that was exploited, I\u2019d bet 1,000 Gold Dragons it was SQL injection.<br \/>\n<strong><br \/>\nWHAT IS MOST LIKELY TO HAPPEN NEXT<\/strong><br \/>\nThere are a wide range of possibilities depending on the goals of the threat actor responsible for the Equifax intrusion. By the way, did I mention that attribution is challenging? Attribution aside, one thing is certain though, regardless of the motivations of the attackers, this data is perfect for social engineering attacks. <\/p>\n<p><strong>Tax Return Fraud<\/strong><br \/>\nSSNs are highly valuable for criminals looking to commit tax refund fraud. Fraudsters use SSNs to file a tax return claiming a fraudulent refund and it can be hard to find out if you\u2019re a victim until it is too late. There is some good advice from the IRS about what to do should you suffer from this form of fraud. You can read more about tax fraud in a blog we wrote earlier this year.<\/p>\n<p><strong>Opening fraudulent accounts<\/strong><br \/>\nThere is no shortage of alternative finance companies, such as those who provide short term loans. Fraudsters can successful open accounts in another individual&#8217;s name, using a combination of SSNs, fraudulent gas statements and other personally identifiable information (PII). Individuals should be extra vigilant for any evidence of accounts being opened in their name.<\/p>\n<p><strong>Carding<\/strong><br \/>\nPII is valuable to payment card fraudsters, who require such information to bypass security controls such as \u201cVerified by Visa\u201d, which sometimes ask for digits of cardholders\u2019 SSNs. There are plenty of high-quality cards that criminals use which do not require extra validation, but the lower-level carders must turn to SSNs to enrich lower-quality card dumps. It\u2019s important to remember that SSNs and payment card fraud are inextricably linked.<\/p>\n<p>Benefits Fraud and Medical care fraud<br \/>\nAlthough less glamorous than tax return fraud and carding, benefit and medical care fraud is a real risk. As with tax return fraud, this is hard to detect when it happens, but individuals can be vigilant when checking their Explanation of Benefits statement and flag any unfamiliar activity to their insurance provider.<\/p>\n<p><strong>Resale of data<\/strong><br \/>\nIt\u2019s important to note that the individuals responsible for the breach are unlikely to be the same criminals conducting the day-to-day fraud. In the case of the Experian breach, this stolen data soon made its way on the (now defunct) Hansa marketplace. As I\u2019ve previously mentioned; there\u2019s already a market for SSNs to enrich credit card information, so it\u2019s likely that many actors could end up getting a piece of the pie.<\/p>\n<p>For lower level criminals, the expenses associated with criminal activities will get even lower. SSNs are already cheap; on one AVC (Automated Vending Cart) site (shown in Figure 3), there are over 3.4 million SSNs for sale at only $1. This includes full names, addresses, and &#8211; for a large number of accounts &#8211; dates of birth. In California alone, there were 334,000 SSNs for sale.<\/p>\n<p>With tens (and potentially hundreds) of millions more SSNs potentially entering the market, the opportunities for criminals to commit fraud will increase and the price will decrease even more.<\/p>\n<p>So far, I\u2019ve focused heavily on SSNs &#8211; but credit card information was also accessed. However, in the breach, while this number is hundreds of thousands (209,000), it is unlikely to have a significant impact on an already burgeoning black market for card credit information.<\/p>\n<p><strong>Enablement of nation state campaigns<\/strong><br \/>\nAlthough Equifax claimed this intrusion was conducted by a criminal threat actor, it is possible that this was a nation state actor. (Quick reminder to re-read my note from above \u201cattribution is always a challenge.\u201d) In the event that a nation state actor is responsible for the intrusion, then like the OPM breach, we won\u2019t see the data being monetised in the criminal underground. The stolen data will be leveraged to enable nation states\u2019 campaigns against their intelligence targets.<\/p>\n<p><strong>Enablement of hacktivist campaigns<\/strong><br \/>\nIf we are going to consider nation state actors, we should also consider hacktivist threat actors and their activities around the stolen data. If hacktivists were responsible (I think this is a pretty unlikely scenario, let\u2019s call it #OPunlikely) you could expect to see them use the data to target organisations and individuals that run counter to their world views. Embarrassment and dox\u2019ing, hacktivist go-tos, would come into play. <\/p>\n<p><strong>WHAT ENTERPRISES CAN LEARN FROM THE EQUIFAX BREACH<\/strong><br \/>\n1. <strong>Incident response takes time and eradication in particular takes time.<\/strong> Equifax said that the intrusion was discovered on July 29th and that they \u201cacted immediately to stop the intrusion.\u201d Equifax\u2019s goal was to contain the adversary that first day, but that true eradication took much longer. It is important that you set expectations with your leadership into how long eradication could actually take.<br \/>\n2. <strong>3rd party risks raise their ugly head once again.<\/strong> Some aspects of this intrusion remind me of the September 2015 T-Mobile breach. In this intrusion, Experian was hosting T-Mobile data that an unauthorised party accessed and this resulted in the loss of 15 million individual\u2019s records. Any organisation with a business to business relationship with Equifax needs to find out the scope of any potential loss of their employee or customer data. This 3rd party exposure also highlights the need for 3rd party risk monitoring.<br \/>\n3. <strong>Crisis communication is key.<\/strong> Effectively communicating during an intrusion is important, it won&#8217;t absolve you of your sins, but doing it wrong could make the situation far worse. Understanding when and what to communicate is also important. Equifax discovered the intrusion on July 29th and notified on September 7th. Some might ask why did it take so long for the notification, but I don\u2019t think that a month is that long. The investigation needs to be far enough along so that you can confidently communicate the situation. A CEO that comes out 2 days after a breach and then minimises what is a much more significant threat will be performing a mea culpa in little time.<br \/>\n4. <strong>GDPR will change the breach notification game.<\/strong> Now let me really trip you up, how would this situation play out if it was after May 25, 2018 and Equifax lost European Union citizen\u2019s data? General Data Protection Regulation changes everything with 72-hour breach notification windows. GDPR states, \u201cThis must be done within 72 hours of first having become aware of the breach.\u201d When the fines do come into place, the timing of the communication will have a significant impact.<\/p>\n<p><strong>WHAT CONSUMERS CAN LEARN FROM THE EQUIFAX BREACH<\/strong><br \/>\n1. <strong>Consider taking advantage of Equifax\u2019s offer.<\/strong> Although the irony is not lost to me, taking advantage of credit file monitoring and identity theft protection offers is important. Check out equifaxsecurity2017[.]com for more. If you don\u2019t want to use Equifax for these services, I get it, look for at alternatives with someone like Transunion or Experian.<br \/>\n2. <strong>Be vigilant about your payment card activity.<\/strong> Use email\/SMS alerts to notify of account transactions ($100) over and under ($5) a specific amount. If an unauthorised transaction occurs you can be notified immediately, and can quickly take action. Be vigilant about your card activity and alert your bank about any suspicious activity.<br \/>\n3. <strong>Address tax fraud with IRS Form 14039.<\/strong> If you find out you are a victim of tax return fraud, there are still things you can do. Victims can file and send a IRS Form 14039. Further details are available <a href=\"https:\/\/www.irs.gov\/newsroom\/taxpayer-guide-to-identity-theft\" rel=\"noopener\" target=\"_blank\">here<\/a>.<br \/>\n4. <strong>Check your Explanation of Benefits (EOB) statement.<\/strong> It might look like another piece of spam mail, but it is important to reconcile the EOB statements that your insurance sends you. This your best bet to monitor for medical card fraud. Make sure to report any unfamiliar activity as soon as you observe it.<br \/>\n5. <strong>Assume breach.<\/strong> In the corporate cyber security world, we have learned to \u201cassume breach\u201d. Consumers should also operate under the impression that their confidential data has been compromised.    \t<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Article by: Rick Holland, VP Strategy at Digital Shadows WHAT WE KNOW ABOUT THE EQUIFAX BREACH On September 7th, credit reporting agency Equifax announced \u201ca cybersecurity incident potentially impacting approximately 143 million U.S. consumers.\u201d To put this in context, at this time, this incident is almost seven times larger than the Office of Personnel Management [&hellip;]<\/p>\n","protected":false},"author":21,"featured_media":17283,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1233,57,14],"tags":[2421,2422,2423,564,2424,2425,2426,2427,2428,2429,2430,2431,2432,2433,2434,2435,2436,2075],"class_list":["post-17282","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blogs","category-enterprise-security","category-more-news","tag-automated-vending-cart","tag-avc","tag-black-market","tag-cybersecurity","tag-eob","tag-equifax","tag-explanation-of-benefits","tag-fraudulent-refund","tag-hacktivist","tag-hacktivist-campaigns","tag-hansa","tag-pii","tag-social-security-numbers","tag-ssns","tag-structured-analytic-techniques","tag-tax-fraud","tag-tax-refund-fraud","tag-wannacry"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/17282","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/users\/21"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/comments?post=17282"}],"version-history":[{"count":0,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/17282\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media\/17283"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media?parent=17282"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/categories?post=17282"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/tags?post=17282"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}