"If the two hacks are unrelated it could be that different hacking teams had different goals. One clue has emerged that suggests one goal of the attackers was to use Equifax as a way into the computers of major banks, according to a fourth person familiar with the matter.Equifax Suffered a Hack Almost Five Months Earlier Than the Date It Disclosed - Bloomberg
This person said a large Canadian bank has determined that hackers claiming to sell celebrity profiles from Equifax on the dark web -- information that appears to be fraudulent, or recycled from other breaches -- did in fact steal the username and password for an application programming interface, or API, linking the bank’s back-end servers to Equifax.
According to the person and a Sept. 14 internal memo reviewed by Bloomberg, the gateway linked a test and development site used by the bank’s wealth management division to Equifax, allowing the two entities to share information digitally."
Tuesday, September 19, 2017
Equifax Suffered a Hack Almost Five Months Earlier Than the Date It Disclosed - Bloomberg
Looking like a multifaceted IT worst-practices case study