Baltimore Sun

Chinese state hackers get blame for Equifax breach

US indicts four members of People’s Liberation Army

- By Eric Tucker and Michael Balsamo

WASHINGTON — Four members of the Chinese military have been charged with breaking into the networks of the Equifax credit reporting agency and stealing the personal informatio­n of tens of millions of Americans, the Justice Department said Monday, blaming Beijing for one of the largest hacks in history to target consumer data.

The 2017 breach affected more than 145 million people, with the hackers successful­ly stealing names, addresses, Social Security and driver’s license numbers and other personal informatio­n stored in the company’s databases.

The four — members of the People’s Liberation Army, an arm of the Chinese military — are also accused of stealing the company’s trade secrets, law enforcemen­t officials said.

The accused hackers exploited a software vulnerabil­ity to gain access to Equifax’s computers, obtaining login credential­s that they used to navigate databases and review records. The indictment also details efforts the hackers took to cover their tracks, including wiping log files on a daily basis and routing traffic through dozens of servers in nearly 20 countries.

“The scale of the theft was staggering,” Attorney General William Barr said Monday. “This theft not only caused significan­t financial damage to Equifax, but invaded the privacy of many millions of Americans, and imposed substantia­l costs and burdens on them as they have had to take measures to protect against identity theft.”

Equifax, headquarte­red in Atlanta, maintains a massive repository of consumer informatio­n that it sells to businesses looking to verify identities or assess creditwort­hiness. All told, the indictment says, the company holds informatio­n on hundreds of millions of Americans in the U.S. and abroad.

The case is the latest Justice Department accusation against Chinese hackers suspected of breaching networks of American corporatio­ns. It comes as the

Trump administra­tion has warned against what it sees as the growing political and economic influence of China, and efforts by Beijing to collect data on Americans and steal scientific research and innovation.

The administra­tion has also been pressing allies not to allow Chinese tech giant Huawei to be part of their 5G wireless networks due to concerns that the equipment could be used to collect data and for surveillan­ce.

The accused hackers are based in China, and none is in custody. But U.S. officials nonetheles­s view criminal charges like the ones brought in this case as a powerful deterrent to foreign hackers and a warning to other countries that American law enforcemen­t has the capability to pinpoint individual culprits behind hacks.

Equifax last year reached a $700 million settlement over the data breach, with the bulk of the funds intended for consumers affected by it. Equifax didn’t notice the intruders targeting its databases for more than six weeks. Hackers exploited a known security vulnerabil­ity that Equifax hadn’t fixed.

Newspapers in English

Newspapers from United States