Equifax linked customers to my fake phishing version of their site by accident
twitter.com
twitter.com
Ideally Equifax will listen and either move it to equifax.com, or take down the site altogether. Since the real version seems to be answering randomly, they may as well just shut the whole thing down.
But seeing as they're a massive, bumbling, bureaucratic organization, there's probably a non-zero change they'll try to sue me instead.
If there are any lawyers here, am I in potential legal hot water for making this site?
https://techcrunch.com/2017/09/08/psa-no-matter-what-you-wri...
Why? This seems like clear and compelling evidence that the site was not designed to actually phish.
- The site contains Equifax's heading, uses their branding, and is highly similar to the actual website
- The site is hosted on a domain that is very similar to the actual website and uses Equifax's name
- The site instructs users to enter PII on it under the guise of being Equifax.
It could be argued that the creator of the site created this to determine whether people were being phished by it before activating the actual collection of data.
Additionally, in Chrome, when I fill out the form and get the alert box, when I dismiss the alert box, two requests are made to the domain:
https://securityequifax2017.com/eligibility/images/favicon-3... https://securityequifax2017.com/eligibility/images/favicon-1...
If an onSubmit handler is attached to the form submit that sets a cookie with this information before showing the alert, then the phished details are transmitted to securityequifax2017.com.
Lawyers will C&D this extremely hard, a very reasonable case can be made that this is impersonation, and a phishing site with malicious intent.
NB: I DO NOT BELIEVE THAT THIS IS THE CREATOR'S INTENT. So do not jump at me thinking that I do believe that. I'm just saying that it could be very reasonably and successfully argued, and that nuance and intent could do very little to spurn allegations of impersonation or actual phishing.
"What if"s don't produce convictions.
(Plus, Cloudflare's flagging it as phishing now, haha.)
Why in the world wouldn't they just put it on their own domain?
You're right of course, but I'm betting that was the motivation.
Basically, the request signals all the little fiefdoms that it's their chance to weigh in.
Something like https://breach.equifax.com
Agreeing with everyone though, it's a wrong reason, but I can fathom why someone would do it.
<tangent>
A few days ago, got a mail from PayPal about "changes in account". Go to my account was linked to https://www.secureserverpaypal.ssvahan.com/home. I've forwarded the mail to PayPal spoofing address, they replied it's legit. Why would a legit PayPal activity be linked to an arbitrary domain - I don't get it. It makes zero sense.
>Hi there. Thanks for the quick response. I do have a question. Why would PayPal refer me to a form not hosted under PayPal domain? How can I tell it's a legit PayPal communication?
Expectedly, never got a response.
I would be confident to say that it was actively killed. Neat. Which is either a clear indication that PayPal finally did internally report the domain, or that some other source of noise got it shut down.
- Has "security" in its name
- Has the current year
I can't explain exactly why I think those factors make it suspicious, however.I think I have an idea of why, though I haven't been able to articulate it properly yet.
I've been thinking about it a lot recently because I co-work with a bunch of digital marketers, and some of them have affiliate marketing sites with domains that follow the pattern http://yourexactsearchterm.com.
The best I can come up with is the Uncanny Valley of SEO, where it feels like a website was made and over-optimized specifically for people making my exact search query. Maybe this is unfair or confirmation bias, but I feel like those websites are the most likely to be low quality content farms (e.g. paying content writers pennies to regurgitate content they have no experience with and/or don't understand). Either that, or they are outright scams.
Do any digital marketers here have opinions about this?
It's not just domain names, but the paths in URLs too --- an entry with your-exact-search-term.html almost subconsciously gets skipped over when scanning search results, unless the search term is extremely specific and somewhat obscure or I'm specifically looking for a file/path (e.g. spc4r37.pdf)
Even worse would have been if they had used dashes equifax-security-2017.com.
(plausible for those without the experience of "suspicious impression", of course)
The website: https://archive.is/PjlIK
At this point Equifax has repeatedly demonstrated nothing but contempt for people whose information they have compromised. When are the authorities going to padlock their doors and shut down this continuing criminally reckless enterprise?
I'm with you, it's more criminal that after all they've flubbed, this company is even still allowed to operate, than that they lost all of our information to begin with.
Don't we have at least 3 major credit bureaus? Equifax should be shuttered immediately and with prejudice, the American credit system will be immediately better off and we can all live without this one. Shareholders be damned.
Our system of credit operates on these bureaus, and we have two others that appear to be functioning properly. If I had one server that was obviously infested with hackers, but two others that were not obviously infested, assuming that I had isolated them properly and they did not have major parts that were in common, I'd start by unplugging the one that was already confirmed to be hacked.
I think it works the same way when corporations that surveilled 50% or more of the population demonstrate systematic incompetence basically without remorse, as in this case. They just need to be unplugged, immediately. (I'm not advocating we shut down the entire credit system, in other words, although I am terrified it may yet come to that.)
What'd the tweet say?
Never attribute to malice that which is adequately explained by stupidity.
They've completely demonstrated incompetence, no contempt needed.
The feeling that a person or a thing is beneath consideration, worthless, or deserving scorn. "he showed his contempt for his job by doing it very badly"
Combine that info with https://techcrunch.com/2017/09/08/psa-no-matter-what-you-wri... and it's enough to throw one into paroxysms.
This chaos is maddeningly absurd, and in a just world their business would be completely shut down by the government.
Just a note, this most likely is not what happened. Identify verification questions typically will ask questions like "Who is your current house mortgage with?" when you have none and they will include a "None of the above" answer, which you're supposed to pick. It's totally intentional.
Basically, it's like a web script that's not hooked up to anything in the backend... Like their recent "has your information been leaked" web forms.
I suspect that's the case across the entire industry.
It does ask for your sort code as a third question though, that's a one in four chance if you were picking randomly.
Or, hopefully, just sued into bankruptcy.
Edit: I would like to know at this point, which got taken down faster after it was first reported on... This tweet, or the perfectly fine video interview of CISO Susan Mauldin with the Cazena CEO from 2016 before the breach? That one went down quickly after it was reported on by Hollywood LA News.
It's gotta be close. I believe that both were taken down in less than 24 hours.
They should apply HIPAA rules to data that can be used for identity theft.
Page 24 specifies “Amount of a civil money penalty”.
https://www.experian.com/ncaconline/freezepin
We are so screwed by these laggards!
According to my research [0], this is the second time in New York Times history that the word "wget" has appeared in the NYT.
The first time was in 2014:
https://www.nytimes.com/2014/02/09/us/snowden-used-low-cost-...
> Evidence presented during Private Manning’s court-martial for his role as the source for large archives of military and diplomatic files given to WikiLeaks revealed that he had used a program called “wget” to download the batches of files. That program automates the retrieval of large numbers of files, but it is considered less powerful than the tool Mr. Snowden used.
[0] http://query.nytimes.com/search/sitesearch/#/wget/since1851/...
Sadly the search is not case sensitive, so a lot of the recent hits are hurricane paths curling...
We initially asked them if they had an updated version of this API using XML or JSON, and it turned into a call with several of their salespeople trying to upsell us on some complicated drag and drop rules engine that happened to return data as JSON. So we just stuck to the legacy API. They struck me as a pretty incompetent organization.
<?xml version="1.0">
<enterprise>[the octets of an access database, interpreted as latin-1 and then encoded into utf-8]</enterprise>It troubles me how true this is.
<enterprise><no-really-enterprise> ...Care to post a mini-example with fake data so we can better understand what you are describing?
First name
Last name
Credit score
Debtor bank
Debts
Bank balance
but: First name
Middle name
Last name
Credit score
Bank balance
So subsequent fields change depending on what fields came before. Something like that.Image backup/mirror of the tweet for when they eventually (?) delete it. As of this comment, it's still up, nearly 20 hours later.
It definitely looks like ol’ Barb in accounting has a nephew that builds web pages. “I bet he’d build it on the cheap!!1!!”
It’s time for this company to go away.
Not sure exactly how long it took OpenDNS to fix that but the false positive is cleared up now. Funnily enough, I switched from ISP (Verizon) DNS to OpenDNS to avoid their NXDOMAIN shenanigans, only to end up with other protective shenanigans.
The constant bungling on Equifax's part would be hilarious if the potential impacts weren't so sad.
The NYT writing it up certainly helps his case, but there were probably more tactful ways of going about this.
There just isn't! It's perfect. Many people who are professional security types said on Day 1 that this would happen, and sagely advised that it might be unwise for anyone to put part of their SSN into a two-day old website on a previously unknown domain that looked like Baby's first PHP, just as news of the breach was still breaking.
And that it was similarly unwise to ask them to do so! So can we just unplug Equifax already? Please? It should be clear who the guilty party is here, and it starts with an Equifax.
There's no relief forthcoming that is possible. The only way things get better now is if we dismantle the entire credit system as we know it, the cat is out of the bag. I'm not interested in punishment. I want to see more serious attention given to prevention.
First, I want to see the license and the keys taken away from the repeat offending drunk driver. Who gave them keys anyway? I sure as hell didn't sign up for this, I want to get off Mr. Bones Wild Ride.
A website doesn't need to have a "backend" or make a POST request or use a submit button to transmit data that you enter on it to another party. You should assume that ANY ACTION you take on any website is being transmitted to the server or to any third party. Key strokes, mouse moves, time on page, info about your browser and location, all of it.
A bad actor could mimic this sort of "prove a point" site and actually harvest information from unwitting people, all while feigning concern and saying they're proving a point, but carefully disguised JS could be encrypting page events and sending them in cookies to other parties. If we normalize this kind of security grandstanding, we open the the door a little bit wider to phishers.
Browser maintainers were right to mark the site as a phishing site. Because it is. It doesn't matter if it transmitted data or not. I guess you could call that "catch and release".
That being said, your concern is warranted, I think Cloudflare and browsers did the right thing by blocking my site. It served its purpose, and as of 4pm CT today I took it down and destroyed the droplet it was running on. I collected no analytics while it was running off Cloudflare, and kept no logs.
Hopefully Equifax doesn't sue me in the next few months.
For the record, the favicon requests that went out after "submitting" your site's data did not appear to transmit any form data to that server. I just noticed that it'd be trivially easy to do that if someone else emulated this as a bad actor.
I think we can all agree that Equifax chose extremely poorly with a separate domain name, one that is just crassly phishy-sounding already, and opening itself up to actual bad actors.
I’m not sure it’s Equifax suing you that you should be most concerned about. Equifax’s giant fuckup has already stirred up the prosecutorial wasps, they’re all looking for something to sting.
“Larry... did you accidentally link to a phishing site instead of our company’s site?”
“Uuhhh...”
(Audience laughs)
“Dammit Larry!”
(Audience laughs)
Subsequently, each time I had to go to the site - to check if my data was hacked, to enroll for the TrustedID protection (had to try multiple times), I would always first go to equifax.com and then follow the links from there.
It's sad to see that my fears of the site being easily cloned is true (although this was a proof of concept to show Equifax that they were wrong but who knows if there isn't a real malicious site that had already collected people's information).
Not only can you not enroll immediately they tell you that . your data was stolen, even when you return on your given enrollment date, you don't get to complete it that same day. You still have to wait for a few more days to get an email.
Equifax has really really messed up. I hope the other companies are using this as a learning experience and are fixing any flaws they have.
All jokes aside, every time I try to explain to a "normal" what is going on in "computer security" I feel like shit. The entire industry is a tire fire. And it's getting worse.
At least we have DRM in the browsers now, eh?
Also - don't be fooled - using the CMM as a metric, the Amish are probably one of the more technologically mature societies around, since they have a clearly defined process around technology usage...
https://en.wikipedia.org/wiki/Capability_Maturity_Model
" There are five levels defined along the continuum of the model and, according to the SEI: "Predictability, effectiveness, and control of an organization's software processes are believed to improve as the organization moves up these five levels. While not rigorous, the empirical evidence to date supports this belief".[15]
Initial (chaotic, ad hoc, individual heroics) - the starting point for use of a new or undocumented repeat process.
Repeatable - the process is at least documented sufficiently such that repeating the same steps may be attempted.
Defined - the process is defined/confirmed as a standard business process
Capable - the process is quantitatively managed in accordance with agreed-upon metrics.
Efficient - process management includes deliberate process optimization/improvement.
Within each of these maturity levels are Key Process Areas which characterise that level, and for each such area there are five factors: goals, commitment, ability, measurement, and verification. These are not necessarily unique to CMM, representing — as they do — the stages that organizations must go through on the way to becoming mature.The model provides a theoretical continuum along which process maturity can be developed incrementally from one level to the next. Skipping levels is not allowed/feasible. "
This talk is both interesting, more or less correct, and absolutely hilarious.
When they notified law enforcement well after the legal requirement to notify law enforcement had come and gone, that would have been a good time for the government to step in and say "hands off the wheel, we're handling this now." Would we be any better off today? I don't know, but my gut says no.
If I had to guess, the answer is that we don't just take companies and put them under state control here in the United States. It just does not happen that I am aware of. Can you name a time this happened?
I certainly can't think of a time when it would have made more sense to do this, but I am struggling to think of even one example of a company that was taken over by the state without searching.
It says here[1] the US government nationalized railroads and the Smith & Wesson company during WWI, and it also nationalized the railroad system and coal mines during WWII, and that Amtrak was the product of another time the government nationalized railroads in the 70's, but was re-privatized in the 80's...
[1]: https://www.cbsnews.com/news/a-history-of-corporate-national...
If the law enforcement agencies had taken some kind of stand, we might still have video interviews with CISO Susan Mauldin from 2016, that have now been erased since September 10, but for some reason there does not seem to be much interest in that. Everyone understands the company is "saving face" by removing those interviews. Nobody is saying it, but it's pretty clear.
There is probably no legal requirement to keep those interviews online, even if they might provide some insight into the mindset of the CISO and how she was influenced in the months leading up to the breach by the other executives and the board members of Equifax. The fact that this is not a bigger story probably owes mostly to the fact that this is already such a big story.
140MM Americans impacted, likely every last person in the country with a credit history's personal information exposed, quite possibly enough to shutter the credit system as we know it for good. What's a little cover-up compared to that?
After the OPM breach, I have zero confidence that the United States have any more competence at this than Equifax.
[0] https://en.wikipedia.org/wiki/Office_of_Personnel_Management...
Pretty much the only way to verify that's the right site is the fact that Equifax.com links to it, although this tweet indicates even that isn't necessarily a reason to trust it.
Why it's not a subdomain of Equifax.com is completely beyond me.
(Even better, the eligibility / credit monitoring signup takes you to another domain, https://trustedidpremier.com/)
Haha, just kidding, their certificate is DV.
/s
You know it's real because it's http.
ERROR
The request could not be satisfied.
The Amazon CloudFront distribution is configured to block access from your country. Generated by cloudfront (CloudFront) Request ID: ZU-LJh21L1Px18Bz5n20R3Nb1aApdzyce_Q6ZeeSIZ0OYiJk2v0eIA==
I don't know where to send you, but I would advise against sending at this point any additional responsibility or personal information to Equifax if you haven't already.
Obviously this does nothing for the information that's already compromised, but if enough people do it, it would help kill off Equifax (lenders will rely less and less on it, thus depriving them of revenue).
They'll say no.
Nothing. Your request would be ignored because we don't have legislation like the GDPR in this country to protect the rights of individuals to the privacy of the information collected about them.
Upon receiving queries about security, they insisted that Equifax Canada wasn't compromised and that the clients insist on using them.
It really irks me that we have no control over whether or not our data gets sent to Equifax.
I hope they aren't big to be held responsible.
I suppose you don't care, but it should be "lose" :-)
(transitive) To let loose, to free from restraints. (intransitive) Of a grip or hold, to let go.
...
No, Equifax, apologies are not spendable currency in the real world. You can't apologize for your horrific and criminal errors.
This isn't business school. You don't fail the test and then apologize to the professor and beg for a C.
You guys are laughably incompetent and it is a shame that the government hasn't found a way to forcibly shut you down yesterday.
If you weren't a big and powerful corporation, you would all be in "pre-trial detention" like the rest of us.