The Borneo Post

US indicts 4 Chinese military ‘hackers’ for Equifax breach

-

WASHINGTON: The US Justice Department announced indictment­s of four members of China’s People’s Liberation Army for alleged involvemen­t in the massive 2017 hack of the database of giant US credit rating agency Equifax.

The hackers are accused of stealing the sensitive personal informatio­n on some 145 million Americans, in one of the world’s largest ever data breaches, said Attorney General Bill Barr.

“This was a deliberate and sweeping intrusion into the private informatio­n of the American people,” he said.

Four members of the Chinese army’s 54th Research Institute – Wu Zhiyong, Wang Qian, Xu Ke and Liu Lei – were charged with multiple counts of hacking, computer fraud, economic espionage and wire fraud.

Officials said it took well over a year to track them through the 34 servers in 20 countries they allegedly used to hide their tracks.

The hack stunned US intelligen­ce officials, following a similar intrusion on the civil service database of the Office of Personnel Management (OPM), also blamed on the Chinese.

Since then, as well, hotels giant Marriott lost data on some 500 million global customers to hackers believed to be Chinese.

US officials believe the Chinese military and security service are collecting personal data on Americans for strictly intelligen­ce purposes. After the OPM hack there were worries that Beijing could use the informatio­n to identify US spies working under the cover of non-intelligen­ce jobs.

FBI deputy director David Bowdich said there was no evidence yet of the Equifax data having been used, for example to hijack a person’s bank account or credit card.

But he added: “If you get the personal identifyin­g informatio­n of people, you can do a lot with that.”

Atlanta-based Equifax is one of three giant, little-regulated creditrate­rs who sweep up financial data on all Americans – their credit cards and banking activity especially – that necessaril­y comes with identifyin­g data like their addresses and social security numbers.

The hackers allegedly took advantage of a vulnerabil­ity in the Apache Struts web-applicatio­n software that Equifax had on its systems.

While Apache notified clients of the problem in March 2017, Equifax didn’t fix it for months.

They infected Equifax’s computers with ‘ web shells’ that gave them the ability to remotely manipulate the systems and to steal identities that expanded their access.

Newspapers in English

Newspapers from Malaysia