Albuquerque Journal

WAKE-UP CALL

Equifax’s massive personal-data breach could be just the tip of the iceberg

- BY KEVIN ROBINSON-AVILA JOURNAL STAFF WRITER

Cybersecur­ity experts say the massive breach of creditrepo­rting company Equifax Inc.’s data systems may be a needed wake-up call to galvanize business and government into much more aggressive action to protect online data in today’s hyperconne­cted cyber world.

Fallout from the breach, which could impact about 143 million U.S. consumers, is mounting, as federal and state-level agencies assess the full extent of the damage. Larger data breaches have occurred in recent years, but the Equifax breach exposed sensitive personal data — names, Social Security numbers, birth dates, and addresses for fully half of the U.S. population.

Equifax faces congressio­nal investigat­ions, class-action lawsuits, inquiries by the Federal Trade Commission and the Consumer Financial Protection Bureau, and action by attorneys general from around the country.

That includes New Mexico Attorney General Hector Balderas.

“Equifax needs to make right by our families,” Balderas said in a public statement last week. “We launched an immediate investigat­ion into Equifax, the circumstan­ces surroundin­g the breach, and the delay in disclosure to New Mexicans. Our office is working to hold Equifax accountabl­e.”

Equifax is under fire for its actions before and after the data breach, particular­ly its decision to wait six weeks to publicly disclose the attack after discoverin­g it on July 29.

Details are still scarce, but apparently hackers broke into Equifax through a flaw in the Apache Struts software package that runs one of its online web portals. That generated even more intense criticism, because that software vulnerabil­ity had already been publicly known since March, with a software patch available to fix it, but Equifax didn’t apply it until after its website was breached.

That apparently lax security, plus the immense damage cybercrimi­nals could now inflict on consumers and businesses, may convert Equifax into a watershed event that pushes government and industry into much more aggressive efforts to fight cybercrime, according to industry experts.

“Awareness unfortunat­ely comes from attacks like these,” said John Yun, marketing director for California-based cybersecur­ity firm ZingBox. “They almost need to happen to wake up to the possibilit­ies of hacking. It brings a lot more awareness to the industry and security vendors themselves, as well as consumers.” An epidemic Cybercrime had already reached epidemic proportion­s. Nearly 1.1 billion identities were stolen worldwide through data breaches last year, almost double the 2015 tally, according to the latest annual Internet Security Threat Report released last spring by global cybersecur­ity firm Symantec Corp.

In the last eight years, such breaches have exposed more than 7.1billion identities worldwide.

Attacks are radically escalating on all fronts, including massive heists with billions of dollars stolen, and chronic blackmail of businesses and consumers through ransomware that, in the U.S., is forcing victims to pay an average of $1,077 each time to retrieve control of their systems, according to Symantec. The number of ransomware attacks grew 36 percent worldwide last year, and Symantec estimates one in every 131 emails today contain a malicious link or attachment.

Apart from cybercrime, sabotage potentiall­y linked to cyberwarfa­re by nation states is growing exponentia­lly in frequency and reach, such as the alleged Russian hacking of U.S. elections last year.

And hackers may be gaining control over critical infrastruc­ture. Just days before the Equifax breach, Symantec warned that a group called Dragonfly 2.0 targeted dozens of energy companies last spring and summer. They gained access to utility

networks, and in a handful of cases in the U.S. and elsewhere, the intruders had potential control over grid operations, enabling them to cause blackouts if they had actually flipped the power switches.

Also, last Thursday, the U.S. Securities and Exchange Commission revealed that its Electronic Data Gathering, Analysis and Retrieval system was hacked last year. EDGAR processes more than 1.7 million electronic filings annually, including sensitive financial disclosure­s that can cause enormous movements in the market, sending billions of dollars in motion on stock exchanges in fractions of a second.

A hyperconne­cted world

Industry experts say the cybercrime tidal wave is less a reflection of hackers becoming more sophistica­ted than of the explosion of Internet connection­s and data sharing in today’s hyperconne­cted world.

“Growing hacker sophistica­tion is a factor, but it’s the evolution in online data sharing that’s creating havoc,” said Srinivas Mukkamala, co-founder and CEO of Albuquerqu­e-based cybersecur­ity firm RiskSense. “There’s more and more computing and consolidat­ion of big data all in one location, and attackers need minimal skills to break in, while companies need real sophistica­tion to protect themselves.”

In recent years, local data management has given way to national and internatio­nal management, with data continuous­ly shared across the globe, Mukkamala said. And many of the companies managing or handling that data are startups without the resources and technology to protect against hackers.

The evolution toward an Internet of Things, which refers to thousands of online devices connecting everything from appliances and security cameras to heating and cooling systems in homes and businesses, is creating a whole new cyber world ripe for hacking. In some cases, such as devices in hospitals, that can give criminals control over life and death, said Yun of ZingBox, which is developing new tools to monitor those connection­s.

At this year’s Def Con hacker convention last July in Nevada, one ZingBox expert demonstrat­ed ability to hack into a widely used brand of IV infusion pump, allowing him to alter medicine flow to a patient.

“There are just so many more devices and services now available online, and they weren’t designed to fend off hackers,” Yun said.

As a result, cybersecur­ity’s traditiona­l focus on teaching employees what to do and not to do to protect systems is inadequate, said Jack Miller, chief informatio­n security officer for cybersecur­ity firm SlashNext, which created hardware to monitor all traffic on a company’s network.

“We’ve relied too much on training employees, when what we need is better technology to protect systems,” Miller said. “We need tools that rely on artificial intelligen­ce to track and fix things.”

That includes the new technologi­es being developed by firms like ZingBox and SlashNext. It’s also the foundation on which RiskSense built its business, creating a software-as-a-service platform that constantly monitors and analyzes networks for customers.

It’s the interface between artificial intelligen­ce and humans, plus the sharing of lessons learned among everybody, that will allow industry and government to get ahead of cybercrime, Mukkamala said.

“We have to look at the entire ecosystem,” he said. “Maybe you as an entity are not vulnerable, but who are you connected to and what are you sharing? We don’t operate in silos, but in an ecosystem that creates seamless data sharing and, as a result, seamless data breaches.”

Federal regulation is also critical, Miller said.

“The public needs to push the government and industry leaders to have policy conversati­ons,” Miller said. “We need real transparen­cy with regulation­s that are prescripti­ve enough to follow through and implement them. We need much clearer, detailed guidelines on what needs to be done.”

 ??  ??
 ??  ??
 ??  ??
 ??  ?? ABOVE LEFT: RiskSense CEO Srinivas Mukkamala says consolidat­ion of big data leaves companies vulnerable to attackers who need minimal skills to break in.
ABOVE LEFT: RiskSense CEO Srinivas Mukkamala says consolidat­ion of big data leaves companies vulnerable to attackers who need minimal skills to break in.
 ?? DEAN HANSON/JOURNAL ?? RiskSense employees at work in Albuquerqu­e. The cybersecur­ity company markets a software-as-a-service platform that constantly monitors and analyzes networks for customers.
DEAN HANSON/JOURNAL RiskSense employees at work in Albuquerqu­e. The cybersecur­ity company markets a software-as-a-service platform that constantly monitors and analyzes networks for customers.

Newspapers in English

Newspapers from United States