US charges four Chinese military members over Equifax hacking breach

10 February 2020, 16:34

US attorney general William Barr during a news conference at the Justice Department in Washington
Chinese Hackers Equifax. Picture: PA

The 2017 breach affected roughly 145 million people.

Four members of the Chinese military have been charged with breaking into the networks of the Equifax credit reporting agency and stealing the personal information of tens of millions of Americans, the Justice Department said.

The US department blamed Beijing for one of the largest hacks in history.

The 2017 breach affected roughly 145 million people, with the hackers successfully stealing names, social security numbers and other personal information stored in the company’s databases.

The four – members of the People’s Liberation Army (PLA), an arm of the Chinese military – are also accused of stealing the company’s trade secrets, including database designs, law enforcement officials said.

The alleged hackers exploited a software vulnerability that enabled them to obtain login credentials and navigate the company’s network while searching for personal information.

The case comes as the Trump administration has warned against what it sees as the growing political and economic influence of China, and efforts by Beijing to collect data on Americans and steal scientific research and innovation.

The administration has also been pressing allies not to allow Chinese tech giant Huawei to be part of their 5G wireless networks due to cybersecurity concerns.

The accused are based in China and none is in custody.

But US officials nonetheless view the criminal charges as a powerful deterrent to foreign hackers and a warning to other countries that American law enforcement has the capability to pinpoint individual culprits behind hacks.

“This was a deliberate and sweeping intrusion into the private information of the American people,” attorney general William Barr said in a statement.

US attorney general William Barr during a news conference at the Justice Department in Washington
US attorney general William Barr during a news conference at the Justice Department in Washington (Jacquelyn Martin/AP)

“Today, we hold PLA hackers accountable for their criminal actions, and we remind the Chinese government that we have the capability to remove the internet’s cloak of anonymity and find the hackers that nation repeatedly deploys against us,” he added.

The case is one of several the Justice Department has brought over the years against members of the PLA.

The Obama administration in 2014 charged five Chinese military hackers with breaking into the networks of major American corporations to siphon trade secrets.

The criminal charges were filed in federal court in Atlanta, where Equifax is based.

The company last year reached a 700 million dollar (£540 million) settlement over the data breach, with the bulk of the funds intended for consumers affected by it.

The indictment details efforts the hackers took to cover their tracks, including wiping log files on a daily basis and routing traffic through dozens of servers in nearly 20 countries.

It includes charges of conspiracy to commit computer fraud, conspiracy to commit economic espionage and conspiracy to commit wire fraud.

Equifax did not notice the intruders targeting its databases for more than six weeks.

The headquarters of Equifax in Atlanta
The headquarters of Equifax in Atlanta (Mike Stewart/AP)

Hackers exploited a known security vulnerability that Equifax had not fixed.

Once inside the network, officials said, the hackers were able to download and exfiltrate data from Equifax to computers outside the United States.

According to the Government Accountability Office (GAO), the investigative arm of Congress, a server hosting Equifax’s online dispute portal was running software with a known weak spot.

The hackers jumped through the opening to reach databases containing consumers’ personal information.

Equifax officials told the GAO the company made many mistakes, including having an outdated list of computer systems administrators.

When the company circulated a notice to install a patch for the software vulnerability, the employees responsible for installing the patch never got it.

Equifax’s 700 million dollar settlement with the US government gives affected consumers free credit monitoring and identity restoration services, plus money for their time or reimbursement for certain services.

However, because so many people made claims, officials said some consumers would get far less than the eligible amounts because of caps in the settlement pool.

By Press Association

Happening Now