Homepage / Technology / Equifax used 'admin' for the login and password of a non-US website
Menyelami Dunia Slot Thailand: Keseruan dan Peluang Kemenangan Besar Menyelami Dunia Slot Thailand: Pengalaman Bermain yang Tak Terlupakan Website Resmi UIN SMH Banten Abebet Slot Sitelerinde Hoþgeldin Bonusunun Avantajlarý Maltcasino: Yeni Üyeler Ýçin Hoþgeldin Bonuslarý Opiniones sobre 1xSlots Lee las opiniones sobre el servicio de 1xslot com What you’ll want to know Take step one towards love and pleasure today Take control of your love life in order to find bbw mature lesbians today Bahis Sitelerinde Ücretsiz Deneme Bonusları Nasıl Kullanılır? Rulet Masalarında Bonuslarla Daha Fazla Kazanın Player women online dating| discover single video games women at Masalbet: En Çok Kazandýran Casino Sitesi Gambling in Australia and Modern Settlement Methods: The Rise of PayID TUAN88 Situs Main Game Online dengan Aman dan Nyaman Brit Cam Place — Singles From British Look For Pleasant Companions And Dating 1xbet Registration ᐉ 1xbet Sign Up برنامج المراهنات الرياضية تحميل التطبيق العميل Eg 1xbet Com Cassino Kto Jogos Para Cassino Online No Brasil” 1xbet Apk 1xbet للموبايل حمل تطبيق 1xbet لأنظمة أيفون و أندرويد 1xbet مصر Eg 1xbet Com Melhores Casas Sobre Apostas No País Brasileiro 2024 Casa-apostas Apresentando” قم بتنزيل 1xbet على جهاز الكمبيوتر ، وكيفية تنزيل تطبيق سطح المكتب على جهاز الكمبيوتر برنامج المراهنات الرياضية تحميل التطبيق العميل 1xbet Com How To Try Out Roulette Rules & Guide How To Win From Slots: Top Ideas To Boost Your Own Chances How To Win The Car In Gta 5 Casino Win The Particular Gta Online Scène Vehicle How To Win The Car In Gta 5 Casino Win The Particular Gta Online Scène Vehicle How To Perform Slot Machines Najlepsze kasyna bez depozytu 2025 The Best Different Roulette Games Strategy Tips In Order To Win At Roulette Promozioni effettive di 22Bet in Italia Отзывы о казино Stake от реальных игроков 2025 о выплатах и игре The Best Different Roulette Games Strategy Tips To Win At Roulette Cassinos legais no Brasil: novas regras e melhores sites Top 10 Biggest Casinos In The Usa 1xbet 보너스 받는법 및 출금 롤링조건 등 사용법 총정리 온라인카지노 Kr Your Current Reliable Partner Regarding Tent Manufacturing Online Kaszinó Játékok És Élő Kaszinó Játékok History Of Las Vegas Casinos Who Else Built It & How Sin City Emerged To Be En Güvenilir Canlı Bahis Empieza Casino Sitesi Игровые Автоматы На мнимые Деньги Играть Онлайн В Лучшие Слоты How To Available A Casino: A Detailed Six-steps Guide Gaming Paradise Is Just Around The Corner: Top Ten Casinos Throughout Las Vegas Find the right person: tips for effective singles dating over 60 10 Regarding The World’s Largest Casinos: The Greatest Casinos Ever! Gamification : la limite entre jeu vidéo et casino en ligne se brouille Ufc 302 Gdzie Oglądać Za Darmo I Na Żywo? 2 06 24 ‎Casino ua online casino club on the App Store 1xbet تسجيل الدخول للجوال قم بتسجيل الدخول إلى حساب 1xbet الخاص بك “원엑스벳1xbet 프로모션 코드 2024: Jbmax Vip! Sweet Bonanza Ücretsiz Demonstration İle Oyun Deneyimi Verde Kaszinó: Új Kaszinó Oldal Rendkívüli Bónuszokkal! Türkiye Casino Sitelerinin Adresi 2024 En Iyi Türk Online Casino En Güncel Ve Güvenilir On Line Casino Ve Bahis Sitelerinin Adresi 2024 Listesi 1xbet 모바일 앱-어플 2024, 버전, 다운로드, 설치, Ios, 안 Diocesan Development Services To The Particular North Karamoja Dds-n Sai Dwaraka In Nessun Caso Tours & Travels Pin-up On Line Casino Türkiye En İyi Canlı Casino Oyunları Ve Slot Makineleri Strategies for making a bisexual woman feel very special and loved Diamond Casino Heist The Big Disadvantage Walkthrough Play 17, 800+ Cost-free Us Online On Line Casino Games No Get” Jouez au casino en ligne numéro un dans le monde 1xbet Login Guide » The Way To Sign Inside To Your 1xbet Account 2024 Better United kingdom Casinos One Undertake Credit card 1вин Бесплатно нет Регистрации Играть и Игровые Автоматы 1win Top Tips For Just How To Beat Slot Machines: Become A New Winner! 원엑스벳 도메인 주소 1xbet 우회접속 가입방법 안내 토크 Deneme Bonusu ile Ücretsiz Oyun Deneyimi Bahis Dünyasında Sıkça Yapılan Hatalar ve Çözümleri 1win Мобильное Приложение На Ios И Android бесплатно Скачать Ücretsiz Slot Oyunları Silvergames’te Çevrimiçi Oynayın ️ Επίσημη Ιστοσελίδα Στην Ελλάδα Casino Bahis Siteleri Ara 2024 Yasal Casinoların Listesi ️” Türkiye’nin En İyi Bahis Şirketi Ve On-line Casino 짱구카지노 공식 평생 도메인 주소 Demo Slot Sweet Bonanza’yı Oynayın: Arkadaşlarınızla Eğlenceli Anlar Yaşayın Meet sexy milfs who’re selecting fun 1вин Игровые Слоты Казино Играть Бесплатно Без Регистрации 1вин Игровые Слоты Казино Играть Бесплатно Без Регистрации لماذا يجذب كازينو 1xbet كبار اللاعبين المصريين؟ 1xbet 독점 프로모션 코드 2024년 1월: Xnumxxcompletesports 1xbet 독점 프로모션 코드 2024년 1월: Xnumxxcompletesports

Taya365 Casino Login⁚ A Comprehensive Guide

Isle Gambling Establishment Hotel Black Hawk Now Under Horseshoe Brand, Changes Label” Top True Money Casino Apps For 2025: Twelve Best Online Casinos Resmi Sitesi Çevrimiçi Oyna, Para İle Oyna 6 Ways To Start An Online Casino تنزيل تطبيق 1xbet قم بتثبيت تطبيق 1xbet للهاتف المحمول Get ready for the ultimate craigslist sex experience Stake Casino Russia официальный Сайт Для Онлайн Игр И Бонусов “bukmacherskie Zakłady Sportowe Najlepsze Oferty W Ggbet Sports Welcome on ultimate dating platform for ssbbw lesbians 1вин Казино ᐉ Вход а Регистрация На 1win Официальный Сайт 1win Encouraged Bonuses As Well As How To Work With Them In Bangladesh 1win Encouraged Bonuses As Well As How To Work With Them In Bangladesh 1win: Spor Bahisleri Ve Internet Casino Bonus 500% Glory Casino On-line ️ Play With The Authorized Web Site In Bangladesh Тотал В Ставках На Спорт%3A не Такое И только Рассчитать Ставка Tv Mostbet Türkiye: En Iyi Oranlar Ve Spor Bahisleri Καζίνο Και Στοιχηματική Σε Έναν Ιστότοπο “1xbet App 1xbet Cellular ᐊ تنزيل 1xbet Apk Android و Iphone ᐊ 1xbet Com Get started on mature sex dating sites now “horseshoe Casino Baltimore Wikipedia Judi Online, Kenali Bahaya, Ciri-Ciri Kecanduan, dan Penanganannya Cassino Apresentando Bônus De Boas-vindas: Veja As Opções Disponíveis

Technology

Equifax used 'admin' for the login and password of a non-US website

Scores of accounts on Equifax‘s website in Argentina allegedly were protected by the same generic username and password: “admin.”

Researchers at Hold Security, a Milwaukee-based cybersecurity firm, found that after some guesswork, they were able to uncover personal employee information housed on Equifax’s South American site, including names, emails, and Social Security equivalents of over 100 individuals.

The researchers easily acquired administrative access and quickly discovered consumer complaint records, complete with the Argentine equivalent of Social Security numbers, known as Documento Nacional de Identidad (National Identity Document).

“You don’t expect anything like that,” said Alex Holden, Hold Security’s chief information security officer. “An ability to lookup cases for individuals based on a single numeric ID and gender drew our attention.”

The research came as Equifax sank deeper into a controversy over its handling of a data breach that could affect 143 million people.

The credit reporting company is now facing multiple investigations. In a rare public acknowledgement, the Federal Trade Commission announced Thursday that it has opened a probe into Equifax’s breach in the United States.

What Hold Security found is not related to the breach in the U.S., which Equifax disclosed last week. But Equifax promptly shut down the website after the research was made public by a security blogger named Brian Krebs.

In a statement to CNBC on Thursday, Equifax said:

“We learned of a potential vulnerability in an internal portal in Argentina which was not in any way connected to the cybersecurity event that occurred in the United States last week. We immediately acted to remediate the situation, which affected a limited amount of public information strictly related to consumers who contacted our customer service center and the employees who managed those interactions.”

“What I can tell you is that we fixed the vulnerability immediately upon learning of it, and that this internal portal has not been in use since 2013. The Argentine consumer dispute information that was mentioned in the Krebs article is all publicly available, searchable and not confidential. Additionally, our consumer credit and commercial databases were not accessed or affected.”

Since it announced the U.S. data breach last Thursday, Equifax shares have fallen more than 30 percent through Wednesday’s close. But that’s just the beginning of Equifax’s woes.

The FTC’s spokesman, Peter Kaplan, said Thursday, “In light of the intense public interest and the potential impact of this matter, I can confirm that FTC staff is investigating the Equifax data breach.”

In addition, Massachusetts announced plans Wednesday to file a lawsuit, which will maintain that the company failed to adopt appropriate safeguards to protect the sensitive data. New York, Illinois, Pennsylvania and Connecticut and other states are also investigating, while nearly two dozen class-action lawsuits have already been filed.

Massachusetts Attorney General Maura Healey said Tuesday the Equifax breach “may be the most brazen failure to protect consumer data” her office has seen. Eric Schneiderman, New York’s attorney general, warned people to be vigilant about hacking and other online and email attacks.

The disclosure of the U.S. data breach prompted Holden to take a look at Equifax’s web security outside the U.S., he said. After first exploring the Argentine website, which initially required a national identification number, the researchers arrived at a different login interface after shortening the site’s URL.

“We put in admin, admin [as credentials] and to our surprise we were in,” he continued.

“We obviously did not state that there was a breach. We highlighted a horrendous security practice which, perhaps, was indicative of the overall data care that led to the breach in the US. But in my professional opinion, if any hacker would look at this part of the website, it would be breached,” Holden told CNBC.

After making the initial discovery, Holden turned to security researcher Brian Krebs to assess his findings.

“Worse still,” Krebs said, “each employee’s username appears to be nothing more than their last name, or a combination of their first initial and last name. In other words, if you knew an Equifax Argentina employee’s last name, you also could work out their password for this credit dispute portal quite easily.”

Krebs is a widely followed blogger on security issues. “I don’t have much advice for Argentinians whose data may have been exposed by sloppy security at Equifax,” he said in a blog post on Tuesday. “But I have urged my fellow Americans to assume their SSN and other personal data was compromised.”

Source: Tech CNBC
Equifax used 'admin' for the login and password of a non-US website

Comments are closed.