People create fake versions of big companies’ websites all the time, usually for phishing purposes. But the companies do not usually link to them by mistake.
Equifax, however, did just that after Nick Sweeting, a software engineer, created an imitation of equifaxsecurity2017.com, Equifax’s page about the security breach that may have exposed 143 million Americans’ personal information. Several posts from the company’s Twitter account directed consumers to Mr. Sweeting’s version, securityequifax2017.com. They were deleted after the mistake was publicized.

By Wednesday evening, the Chrome, Firefox and Safari browsers had blacklisted Mr. Sweeting’s site, and he took it down. By that time, he said, it had received about 200, 000 hits.
The Series Addressability Summit Recap
Fortunately for the people who clicked, Mr. Sweeting’s website was upfront about what it was. The layout was the same as the real version, complete with an identical prompt at the top: “To enroll in complimentary identity theft protection and credit file monitoring, click here.” But a headline in large text differed: “Cybersecurity Incident & Important Consumer Information Which is Totally Fake, Why Did Equifax Use A Domain That’s So Easily Impersonated By Phishing Sites?”
It would be just as easy for phishers to create their own versions of the Equifax page, and that would be bad news for anyone entering the information required to enroll in identity theft protection: their surname and the last six digits of their Social Security number. (In Mr. Sweeting’s version, the form was disabled so that no information was saved.)
“Their site is dangerously easy to impersonate, ” Mr. Sweeting said in an email, noting that he had created the site solely to draw attention to the weakness of Equifax’s security. “It only took me 20 minutes to build my clone. I can guarantee there are real malicious phishing versions already out there.”
Someone Made A Fake Equifax Site. Then Equifax Linked To It.
“It’s in everyone’s interest to get Equifax to change this site to a reputable domain, ” he added. “I knew it would only cost me $10 to set up a site that would get people to notice, so I just did it.”
“We apologize for the confusion, ” the statement said. “Consumers should be aware of fake websites purporting to be operated by Equifax. Our dedicated website for consumers to learn more about the incident and sign up for free credit monitoring is https://www.equifaxsecurity2017.com, and our company homepage is equifax.com. Please be cautious of visiting other websites claiming to be operated by Equifax that do not originate from these two pages.”
An Equifax spokeswoman, Marisa Salcines, did not respond when asked why the company had created a separate website rather than a subdomain of equifax.com.
Examining The Past To Understand The Future
That, cybersecurity experts said, was the key mistake. Phishers cannot create a page on the equifax.com domain, so if the website were hosted there instead, it would be easy for users to tell that the page was legitimate.
“You would think that would be the obvious place to start, ” said Rahul Telang, a professor of information systems at Carnegie Mellon University. “Create a subdomain so that if somebody tries to fake it, it becomes immediately obvious.”
“Equifaxsecurity2017.com, ” on the other hand, looks so unofficial that Mr. Telang said even he had been unsure at first whether it was safe to enter his information.

Narrative Partners With Equifax To Enable Easy Customization Of Differentiated Financial Datasets
Mr. Sweeting explained in his email that a Linux command, “wget, ” allows anyone to download the contents of a website, “including all images, HTML, CSS, etc.”
“It was super easy to just suck their whole site down with wget and throw it on a $5 server, ” he wrote. “It currently has the same type of SSL certificate as the real version, so from a trust perspective, there’s no way for users to authenticate the real one vs. my server.”
“If you don’t have a plan in place, you will find different ways to screw it up, ” he said. “Equifax is just a perfect example of that.”
Congress Report: Equifax Breach 'entirely Preventable,' Blames 'culture Of Cyber Security Complacency'
All of the incorrect tweets ended with “-Tim, ” indicating the name of the Equifax employee who wrote them. The Equifax spokeswoman did not say whether any disciplinary action had been taken, and Mr. Sweeting said he hoped the employee had not been fired.
“They probably just Googled for the URL and ended up finding the fake one instead, ” he said. “The real blame lies with the people who originally decided to set the site up badly.”UKRAINE - 2021/06/13: In this Photo illustration an Equifax logo is seen on a smartphone and a pc ... [+] screen. (Photo Illustration by Pavlo Gonchar/SOPA Images/LightRocket via Getty Images)

In 2017, an Equifax data breach took place in which the private records of 148 million Americans were compromised. It was reported to be one of the largest cybercrimes related to identity theft.
Equifax Data Breach: Is Your Info Better Protected Since 2017 Hack?
The Wall Street Journal reported on Tuesday that earlier this year the company sent lenders inaccurate credit scores on millions of consumers earlier this year which led to higher interest rates and rejected applications for consumers.
In a statement on its website, Equifax blamed the situation on “a coding issue within a legacy, on-premise server environment in the U.S. slated to be migrated to the new Equifax Cloud infrastructure. This issue, which was in place over a period of a few weeks, resulted in the potential miscalculation of certain attributes used in model calculations. Credit reports were not changed as a result of this issue.”
The company said, “We know that businesses and consumers depend on our data and Equifax takes this technology coding issue very seriously. We can confirm that the issue has been fixed and that we’ve been working closely with our customers on analysis to best meet the needs of consumers. As part of this extensive analysis, we have determined that there was no shift in the vast majority of scores during the three-week timeframe of the issue. For those consumers that did experience a score shift, initial analysis indicates that only a small number of them may have received a different credit decision.”
Equifax Or Equiphish?
“At first glance, Equifax has handled everything completely wrong in this situation, ” commented Michelle Mastrobattista, the founder and marketing strategist at Brand Paradise. “There have been numerous missteps, from the response time to the original WSJ article to apparently being aware of this coding issue since May and not addressing it proactively.”

“There is growing negative sentiment on Equifax's social media channels. People want them to address the coding issue and be transparent with how many people were affected and how they plan to rectify the situation. Not only have they not posted a statement to social media, but it also appears that the past few days of social posts were auto-scheduled and completely tone deaf, ” she said.
“If Equifax does not immediately pin a statement to the top of their social media channels, the negative comments will continue under every post having more reach and impact. Posting a statement would allow them to contain most of the comments under that thread, reducing the virality. If not, every time there is a new negative comment on other posts, everyone who ‘likes’ those posts will be notified, , ’’ Mastrobattista predicted.
Lessons From The Equifax Data Breach Report
“Americans are already dealing with rising prices on consumer goods, record inflation, and the constant fear of an impending recession. Now more than ever people need to feel a strong sense of trust in their financial institutions and agencies, Matt Weaver, senior vice president of PR firm Actual Agency, said via email.
“Equifax needed to lead with empathy here instead of leaning on the technical side of the error. I expect a stronger public backlash to mount in the coming days which will require the company to publicly walk back its initial response, ” he speculated.
“One of the pillars of responding to a crisis is truth and transparency, it’s important to acknowledge mistakes and take responsibility for the actions while providing options and resources to those who have been affected quickly and efficiently, ” advised Ronn Torossian, founder and chairman of the 5WPR public relations agency via email.

Equifax, Inc News — Nyse:efx — Tradingview
“It’s disheartening that Equifax waited until a report on their mistakes was released, ultimately forcing them to respond, instead of when they first were alerted to the coding issue. Even if they were working with individual lenders, they should have released a public statement. Even more unnerving is they continue to withhold vital information, such as specific date rages or how users can learn whether they were among those who received wrong information, from their users, ” he noted.
“What other businesses can learn from Equifax’s response is if you choose to reach with truth as transparency publicly from the first moment you were alerted to the issue, you can better control the narrative. Don’t let others write your business history for you, ” Torossian concluded.

0 Response to "Equifax Narrative Changed"
Posting Komentar