Skip to main content

Lawsuit alleges Equifax’s stupid password made it super-easy to steal your data

Remember that epic Equifax hack from 2017? As it turns out, the company made it pretty easy for hackers to get in. A recent filing in the United States District Court for the Northern District of Georgia, Atlanta Division points out a few of the company’s missteps that might have led to the breach.

The first of those issues comes in the form of the password the company users to protect a portal used to manage credit disputes. While you might think a major company holding personal information like people’s names, addresses, and social security numbers might use an exceptionally secure password in that instance, it actually went for something a different: It used “admin” as both the username and password for the portal.

Not exactly the most secure move.

Recommended Videos

If the shoddy password wasn’t enough, the company also stored unencrypted user information on a public-facing server. That meant that any attacker that compromised the website’s server would immediately have access to all the personal information stored on it, with no additional work required.

The website also wasn’t the only thing it left unencrypted. The company also failed to encrypt its mobile applications, so not only was it keeping sensitive data unencrypted on its own server, it was transmitting that data unencrypted over the internet.

When it did finally encrypt that data, it “left the keys to unlocking the encryption on the same public-facing servers, making it easy to remove the encryption from the data.”

The court filing suggests that the inadequacies in Equifax’s encryption protocol fell short of industry standards and data security laws, going as far to say that the company “did not know what they were doing with respect to data security.”

The hack on Equifax in 2017 reportedly impacted approximately 147 million people, exposing their personal information and social security numbers.

As part of a settlement from the incident, Equifax is paying more than $300 million toward credit monitoring services for the impacted customers. It’s also compensating customers who paid out-of-pocket expenses as a result of the breach.

If you were impacted, you can apply to receive credit monitoring services or a $125 settlement via Equifax’s site now.

Emily Price
Former Digital Trends Contributor
Emily is a freelance writer based in San Francisco. Her book "Productivity Hacks: 500+ Easy Ways to Accomplish More at…
OnePlus customer data stolen in second data breach in two years
oneplus 7t macro lens iphone 11 lacks cameras

Phone company OnePlus has suffered another data breach, with an undisclosed number of customer names, contact numbers, email addresses, and shipping addresses stolen by an unnamed hacker or group.

This comes less than two years after up to 40,000 customers' private information was stolen from OnePlus, leading to credit card fraud using customers' details. In this case, the breach only came to light when the issue of credit card fraud was raised by a user on the OnePlus forums. An investigation subsequently discovered a malicious script had been gobbling up customer credit card details when they were entered into the OnePlus website.

Read more
Simon Pegg says The Final Reckoning is the best Mission: Impossible movie yet
Tom Cruise stares with a concerned look on his face.

In addition to being one of the longest-running franchises, Mission: Impossible has also managed to retain an impressive level of quality. The teaser for Mission: Impossible – The Final Reckoning suggests that the next installment will keep that trend alive, and now, star Simon Pegg has said that the next chapter may even be the best in the entire franchise.

On Inside of You with Michael Rosenbaum, Pegg said that he had just finished shooting and was ready to hype the film up. "I have just finished shooting. I have one day left of pickups to do," he explained. "I've seen it. It's bananas. It's absolutely bananas. What he does in this one, it boggles the mind. I think this one is the best one ever. And I'm not just saying that because it's like, 'Oh, you've got to say that.' It is going to be great."

Read more
Apple might once again be considering a TV of its own
The Apple TV Siri Remote in hand.

Toward the end of the first decade of the 2000s, rumors swirled that Apple had its sights set on making a TV — a proper set, not a streaming device like what the Apple TV has become. Steve Jobs even claimed to have figured out exactly how to add the product to the company's portfolio, but the idea never came to fruition before his untimely passing. In today's Power On newsletter, Mark Gurman said that Apple "may even revisit the idea of making an Apple-branded TV set."

Gurman didn't mention details beyond that. In fact, the mention of the TV set came on the heels of a discussion around Apple's upcoming smart home device. Gurman's phrasing regarding the TV — "something [Apple] is evaluating" — is the key here. Gurman suggests that revisiting an Apple-branded TV might be dependent on the success of upcoming smart home devices, especially since HomeKit has been the least popular and least-supported platform of the three major choices.

Read more