Latest in Gear

Image credit:

Federal prosecutors indict four Chinese military officers over Equifax hack

The stolen data included personal details for almost half of all Americans.
207 Shares
Share
Tweet
Share

Sponsored Links

Smith Collection/Gado via Getty Images

The Justice Department has charged four Chinese People's Liberation Army (PLA) officers in relation to the 2017 Equifax hack in which the personal details of some 145 million US consumers and nearly a million UK and Canadian citizens were stolen. The data included names, addresses, birth dates, Social Security numbers and some drivers license details.

Federal prosecutors alleged in the nine-count indictment that the four defendants hacked Equifax's systems and stole company trade secrets as well as the consumer data. The indictment was filed in federal court in Atlanta, in which Equifax is headquartered.

In March 2017, Apache and the United States Computer Emergency Readiness Team "announced a vulnerability in certain versions of Apache Struts software that permitted unauthorized users to access the Apache Struts Web Framework and perform a remote code execution attack on a target web application," the indictment states. "The vulnerability was not patched on Equifax's online dispute portal."

It's not clear exactly when the hackers gained access to Equifax's systems, but they did so "at least by or on about May 13th," according to the indictment. They allegedly spent at least two months running around 9,000 queries on Equifax's systems to obtain personal data on nearly half of all Americans. Prosecutors also say the hackers stole database designs and data compilations, which are deemed to be trade secret information.

The defendants allegedly tried to cover their tracks by rerouting traffic through dozens of servers in almost 20 countries and using encrypted communication systems in Equifax's network to make their activity seem normal. They also cleaned out log files every day, according to the indictment.

Prosecutors charged the defendants -- Wu Zhiyong, Wang Qian, Xu Ke and and Liu Lei -- with conspiracy to commit computer fraud (three counts), conspiracy to commit economic espionage and conspiracy to commit wire fraud. The indictment also includes a charge of economic espionage, three counts of wire fraud and two counts of unauthorized access and intentional damage to a protected computer.

"This was a deliberate and sweeping intrusion into the private information of the American people," said Attorney General William Barr in a statement. "Today, we hold PLA hackers accountable for their criminal actions, and we remind the Chinese government that we have the capability to remove the Internet's cloak of anonymity and find the hackers that nation repeatedly deploys against us."

Last year, Equifax agreed with the Federal Trade Commission a settlement worth up to $700 million in total. People who were affected by the breach can request credit monitoring or a cash payout. There were suggestions they'd receive up to $125, which might not come close to covering the potential damage they might have suffered if someone exploited their data. But the victims probably won't get anything close to that, because of a large number of claimants for a payout pot of just $31 million.

All products recommended by Engadget are selected by our editorial team, independent of our parent company. Some of our stories include affiliate links. If you buy something through one of these links, we may earn an affiliate commission.
Comment
Comments
Share
207 Shares
Share
Tweet
Share

Popular on Engadget

Roku is giving away 30 days of premium video

Roku is giving away 30 days of premium video

View
SpaceX launches its original Dragon capsule for the last time

SpaceX launches its original Dragon capsule for the last time

View
Facebook's experimental Stories feature lets users cross-post to Instagram

Facebook's experimental Stories feature lets users cross-post to Instagram

View
'Kind Words' is the rare social network where everyone is nice

'Kind Words' is the rare social network where everyone is nice

View
Google pulls Infowars from the Play Store over coronavirus misinformation

Google pulls Infowars from the Play Store over coronavirus misinformation

View

From around the web

Page 1Page 1ear iconeye iconFill 23text filevr