درباره این اپیزود
It starts with a strange letter in the mail. A car loan you never applied for. A credit card you don't own. A digital ghost is quietly living your life, and you have no idea how it got the keys. When you turn to one of the silent guardians of your financial identity for help, you find only chaos, confusion, and a company that seems to be a danger to itself.
This week on Digital Fallout, we tell the true story of one of history's most catastrophic data breaches. It's a tale of staggering corporate negligence, a botched public response that became a dark comedy, and a 76-day silent heist where the identities of 147 million people were stolen.
What happens when the keepers of our most valuable secrets simply forget to lock the door?
Show Notes: Sources
This story was pieced together from numerous public records, government reports, and in-depth investigative journalism. For those who want to learn more about the 2017 Equifax breach, these are the key sources we consulted:
- The official report from the U.S. Government Accountability Office (GAO) titled "Data Protection: Actions Taken by Equifax and Federal Agencies in Response to the 2017 Breach," which provides a definitive timeline and analysis of the failures.
- Federal Trade Commission (FTC) public statements and court filings related to the landmark global settlement with Equifax.
- In-depth reporting from security journalist Brian Krebs (KrebsOnSecurity), who meticulously covered the botched response, including the fake phishing sites promoted by Equifax's own Twitter account.
- Technical explainers from outlets like WIRED magazine that broke down the Apache Struts vulnerability and how it was exploited.
- Ongoing coverage of the corporate and financial fallout from The New York Times and The Wall Street Journal during September and October 2017.
- The public testimony of former Equifax CEO Richard Smith before the U.S. House Committee on Energy and Commerce, where many of the internal failures were brought to light.
یادداشت ها را نشان دهید 🔗
رونوشت 🔗
00:00:00.381 --> 00:00:02.329
Hi, welcome back to Privacy, Please.
00:00:02.329 --> 00:00:07.091
I'm Cameron Ivey, and this is the second episode of our series, Digital Fallout.
00:00:07.091 --> 00:00:12.612
Before we begin, the story you're about to hear is a true story based on extensive public reporting.
00:00:12.612 --> 00:00:15.669
We've dramatized certain elements to bring the story to life.
00:00:15.669 --> 00:00:18.588
For a full list of our resources, please see the show notes.
00:00:18.588 --> 00:00:21.489
With that being said, let's get into the story.
00:00:21.489 --> 00:00:22.560
Let's get into the story.
00:00:26.123 --> 00:00:39.417
Have you ever had the strange feeling, that prickle on the back of your neck that tells you something is wrong, A feeling that someone somewhere knows something about you they shouldn't?
00:00:39.417 --> 00:00:50.523
For a 32-year-old woman from Ohio named Sarah, that feeling began in the summer of 2017.
00:00:50.523 --> 00:00:53.225
Sarah and her husband had been saving for years to buy their first house.
00:00:53.225 --> 00:00:58.631
They had good jobs, they paid down their debts and their credit scores were pristine.
00:00:58.631 --> 00:01:00.853
They were finally ready.
00:01:00.853 --> 00:01:12.962
In late August, they walked into their bank to get pre-approved for a mortgage, a moment they had been dreaming about for years.
00:01:12.962 --> 00:01:14.204
The loan officer typed their information into the computer.
00:01:14.204 --> 00:01:23.388
He looked at his screen, looked back at them and then he had five words that made Sarah's blood run cold I'm sorry, I've been denied.
00:01:23.388 --> 00:01:26.713
Confused, Sarah asked why.
00:01:26.713 --> 00:01:36.058
The loan officer explained that her credit report showed a brand new car loan taken out in her name just three weeks prior from a dealership in California.
00:01:36.058 --> 00:01:39.944
Sarah had never been to California.
00:01:39.944 --> 00:01:40.906
She hadn't bought a car.
00:01:40.906 --> 00:01:48.503
It was the first sign that a digital ghost was now living her life.
00:01:48.522 --> 00:01:55.028
While Sarah was frantically trying to prove that she was in fact herself, a press release went out that shook the country.
00:01:55.028 --> 00:02:08.084
One of the nation's three great credit bureaus the silent keepers of our financial identities announced that they had been the victim of a cybersecurity incident.
00:02:08.084 --> 00:02:09.026
They didn't say much more.
00:02:09.026 --> 00:02:11.731
The announcement was vague, clinical.
00:02:11.731 --> 00:02:19.126
They assured the public they had the situation under control and directed everyone to a special website to see if they had been affected.
00:02:19.126 --> 00:02:23.866
But when people like Sarah visited the site, the mystery only deepened.
00:02:23.866 --> 00:02:26.968
The website looked amateurish.
00:02:26.968 --> 00:02:33.532
It asked for the last six digits of your social security number, which felt like walking into a trap.
00:02:33.532 --> 00:02:37.069
Worse, the website itself seemed to be guessing.
00:02:37.069 --> 00:02:42.712
It would tell a person they were likely impacted one day and not impacted the next.
00:02:42.712 --> 00:02:45.168
And then came the truly absurd.
00:02:45.168 --> 00:02:58.252
The company's own official Twitter account, trying to be helpful, began sending its scared and confused customers to the wrong website, A fake phishing site that a security researcher had set up to prove a point.
00:02:58.252 --> 00:03:04.951
The very institution that held the keys to their financial kingdom was now leading them astray, but the public still didn't know the full story.
00:03:04.951 --> 00:03:05.612
They didn't know it was stolen.
00:03:05.612 --> 00:03:09.120
The institution that held the keys to their financial kingdom was now leading them astray, but the public still didn't know the full story.
00:03:09.120 --> 00:03:14.602
They didn't know it was stolen and they didn't know how the thieves got in.
00:03:14.641 --> 00:03:21.788
Behind the scenes, a team of digital investigators was piecing together the timeline, and what they found was chilling.
00:03:21.788 --> 00:03:24.692
The intrusion hadn't just happened.
00:03:24.692 --> 00:03:27.533
It had been going on for months.
00:03:27.533 --> 00:03:34.550
They discovered that back in March, a known vulnerability in a common piece of web software had been announced to the world.
00:03:34.550 --> 00:03:36.044
A patch was issued.
00:03:36.044 --> 00:03:42.384
It was a simple fix, but for some reason, at this one company, the memo was ignored.
00:03:42.384 --> 00:03:44.038
The patch never applied.
00:03:44.038 --> 00:03:58.147
It was the equivalent of a bank being told about a faulty lock and then leaving the door wide open for the entire summer, and for 76 days, from mid-May to the end of July, hackers had walked right through the open door.
00:03:58.147 --> 00:04:08.971
They roamed the company's network completely undetected, mapping out the databases, locating the most sensitive information and then slowly, methodically siphoning it all out.
00:04:09.941 --> 00:04:13.450
And when the investigators finally determined what exactly had been taken.
00:04:13.450 --> 00:04:16.870
They understood the true scale of this disaster.
00:04:16.870 --> 00:04:20.369
This wasn't just usernames and passwords.
00:04:20.369 --> 00:04:33.761
The thieves had taken the crown, jewels Names, birthdates, addresses, driver's license numbers and, in most cases, social security numbers Everything someone would need to become you.
00:04:33.761 --> 00:04:36.427
And who were the victims?
00:04:36.427 --> 00:04:46.211
The company's final analysis revealed that the number was 147 million people, nearly half of the entire adult population of the United States.
00:04:47.120 --> 00:04:51.211
This was not a sophisticated, state-of-the-art hack that no one could have prevented.
00:04:52.021 --> 00:05:08.148
This was a catastrophic failure of the most basic security practices A failure to perform a single routine software update, A failure to notice that nearly half of the country's most sensitive data was walking right out the front door for two and a half months.
00:05:08.148 --> 00:05:16.788
It was a breach of trust so profound, so complete, that it changed the landscape of privacy forever.
00:05:16.788 --> 00:05:24.454
For people like Sarah, the mystery car loan was just the beginning of a lifelong battle to protect her own identity.
00:05:24.454 --> 00:05:26.360
The mystery car loan was just the beginning of a lifelong battle to protect her own identity.
00:05:26.360 --> 00:05:39.380
The damage was permanent and the name of this silent guardian, the keeper of secrets that failed.
00:05:39.380 --> 00:05:40.581
Its one single duty was Equifax.
00:05:40.581 --> 00:05:43.802
That brings us to the end of this episode of Digital Fallout.
00:05:43.802 --> 00:05:52.225
Thank you so much to the journalists and researchers who meticulously documented the failures and fallout of this historic breach.
00:05:52.225 --> 00:05:56.065
For a list of our primary sources, please check out the show notes.
00:05:56.065 --> 00:06:03.088
Until next time, everyone, thank you so much for tuning in to Privacy, Please, and stay curious and safe out there.
00:06:03.088 --> 00:06:06.000
No-transcript.