Chinese Military Hackers Charged in Massive 2017 Equifax Data Breach

US prosecutors charge four members of the Chinese military with hacking Equifax and stealing the personal data of 145 million Americans. The attackers exploit an unpatched software vulnerability to extract sensitive information through thousands of database queries.

The US Department of Justice charges four Chinese military hackers with executing the massive 2017 Equifax data breach that exposes the sensitive personal information of 145 million Americans. Attorney General William Barr identifies the suspects as members of the Chinese People's Liberation Army's 54th Research Institute, marking a significant escalation in US efforts to hold state-sponsored cybercriminals accountable.

The hackers exploit a publicly disclosed vulnerability in Equifax's web application software that remains unpatched for two months. Once inside the network, the attackers run approximately 9,000 SQL queries to extract names, birth dates, and Social Security numbers, ultimately splitting the stolen data into 600MB segments and downloading it to a server located in the Netherlands.

US officials warn that this stolen data holds immense economic value and potentially feeds China's development of artificial intelligence tools and intelligence-targeting packages. This indictment highlights a broader, disturbing pattern of state-sponsored computer intrusions by China aimed at stealing personally identifiable information and corporate trade secrets.

Read More at the original source →